Monthly Archives: March 2009

It's Conficker day - so where's the meltdown?

Default image

With April 1st already upon us in some timezones, the much feared meltdown of the world's computer systems, has, as expected. Simply not happened! Yes, the new algorithm for polling websites has started as scheduled, but to quote another blog Read more…

Share

What's the best Conficker news headline you've seen?

Image (1) conficker-headlines.jpg for post 12036

The hours are ticking down to April 1st - in fact, in some parts of the world it's already April Fool's Day. (Wave to our friends in eastern Australia and New Zealand!) But Conficker works at its own pace, and Read more…

Share

Conficker's impact on Google Search

Image (1) conficker-effect.jpg for post 12035

No, don't worry - I'm not saying that Conficker has some secret payload that interferes with Google. :) Instead I wanted to point out how a hystericane (also known as a hysteria hurricane, or a frenzy generated by a media Read more…

Share

Video: Conficker and April 1st - what's all the fuss about?

Video: Conficker and April 1st - what's all the fuss about?

Sean Richmond and Duck in our Sydney office recorded a podcast all about Conficker and April Fool's day. For a bit of fun we added some graphics and fairy dust and turned it into a movie. (Enjoy this video? You Read more…

Share

Facebook's hot body dance videos lead to malware

Image (1) fbookmalware-email.jpg for post 12033

Maybe when you received the email you didn't think it was suspicious, or even if you did maybe you thought it was worth the risk. Subject: Facebook message: Cute Girl Top Model Dancing Message body: News from Facebook - Facebook Read more…

Share

Where do all these Russian brides come from anyway?

Image (1) elena.jpg for post 12032

Regular readers of the Clu-blog will know that recently I have been receiving a number of invitations from Eastern European women hoping to make friends with me. Natalya and Oksana didn't tell me how old they were, but from their Read more…

Share

MSN weight-loss spamming

Image (1) msn_spam_me.png for post 23408

Just after my colleague posted a blog about "Skype Me/Spam Me" a few days back, I received a MSN spam message from one of my friends. The message claimed to be a "risk free" weight loss program and contained a Read more…

Share

GhostNet: Who is really behind it?

Image (1) ghostnet-nyt.jpg for post 12031

Today saw the publication of a fascinating research paper by the Information Warfare Monitor project. The paper, entitled "Tracking GhostNet: Investigating a Cyber Espionage Network", investigates claims of alleged Chinese spying against Tibetan organisations including the Tibetan government-in-exile and the Read more…

Share

Conficker's virtual machine detection

Image (1) conficker-other-vm-detection.png for post 20008

The Internet Storm Centre blogged back in February about how the startup code of Conficker would do a quick check, using the SLDT instruction, to see if it was running in a virtual machine. If so, it would Sleep() forever Read more…

Share

Hype, April fool's day, and the Conficker worm

Image (1) conficker-sun.jpg for post 12030

"Millions of computers around the world could go into meltdown on April 1 because of a deadly virus." Those are the words from a report in today's soaraway Sun, a British tabloid newspaper. With that kind of talk in a Read more…

Share

Don't open dhl_n756512.zip

Image (1) dhl-tracking-malware.jpg for post 12029

We have been watching a large scale malicious spam campaign posing (once again) as an email from courier firm DHL. Just like last time the messages claim that DHL tried to deliver a parcel from you on the 14th of Read more…

Share

Memories of the Melissa virus

Image (3) david-l-smith-collage.jpg for post 13894

It all started with just one file being uploaded to the internet. An infected Word document was posted to the alt.sex usenet newsgroup on March 26 1999. Most people probably thought a Word .DOC file was harmless, even though simple Read more…

Share

AOL phisher jailed for four years

Image (1) phishing-170.jpg for post 12027

Earlier this week I blogged about how Thomas Taylor Jr, a member of an ecard identity theft gang that targeted users of AOL, had managed to escape a spell in prison. One of Taylor's co-conspirators, Charlie Blount Jr, wasn't so Read more…

Share

SMS message saying bank details on the internet are malicious

Image (3) cdnpharm200.png for post 2785

SophosLabs has received a disturbing report from a UK Local Government customer which we feel need a wider audience. People are receiving SMS messages saying that their bank details are on the internet. These text messages are 100% malicious in Read more…

Share

Conficker: Why I can't tell you what it will do on April 1st

Conficker: Why I can't tell you what it will do on April 1st

There's been a lot of media interest in the last few days regarding what the Conficker worm might do on April Fool's Day. Well, here's the bad news. I'm afraid it's not possible for us to analyse any potential payload Read more…

Share

Inconsistent treatment for hackers?

Image (1) owen-thor-walker.jpg for post 12025

It is reported that a teenage hacker who made headlines for accessing computers around the world without permission for dishonest purposes, has been given a job by a New Zealand telecoms company. Ninteen year old Owen Thor Walker, from New Read more…

Share

Apple Mac malware: caught on camera

Apple Mac malware caught on video

Pob in our analysis labs blogged earlier this week about a new variant of the RSPlug Trojan horse for Mac OS X that he had written protection against. One of the ways in which the OSX/RSPlug-F Mac Trojan horse is Read more…

Share

My love triangle just became a square

Image (1) evgeniya.jpg for post 12022

As if my life wasn't complicated enough trying to choose between two Russian women, a third has entered the ring. Meet Evgeniya, who has just sent me an email out of the blue. She has carefully chosen me out all Read more…

Share

Help me choose between two Russian women

Image (1) natalya-oksana.jpg for post 12021

Meet Natalya and Oksana. They have separately emailed me (brunette Natalya says she is a fan - presumably of the Clu-blog, and blonde Oksana says she is my new friend) attaching photographs of themselves. They haven't really given me any Read more…

Share

Wal-Mart hoax spreading via SMS text messages

Image (1) walmart.jpg for post 12020

Up and down America, mobile phone users are forwarding SMS messages to each other warning that women and children will be killed at a Wal-Mart store. The cellphone messages claim that the killings will be part of a planned 'gang Read more…

Share