Monthly Archives: April 2009

RBS, Rapport and OITC anti-virus test results

Image (1) rbs-oitc.jpg for post 12067

An email from a customer today brought my attention to some anti-virus test results that have been published on the website of RBS (Royal Bank of Scotland). At first glance, the test results look quite bad for Sophos (and even Read more…

Share

Who's good at counting?

Default image

I've reported on a wide variety of tests on this blog. Some have been very good whilst others have been very questionable. Today, my attention has been drawn to another testing site that claims to have a new take on Read more…

Share

Sinowal delivery: date-driven redirection scripts

Image (1) sin-o.png for post 23542

Recently, there have been a few reports of new Sinowal (aka Mebroot or StealthMBR) variants having been spotted in the wild [1,2]. We have been seeing this activity ourselves at SophosLabs. In this post I will highlight some interesting characteristics Read more…

Share

Teen hacker who made fake 911 calls punished

Image (1) keypad-buttons.jpg for post 12066

According to media reports, a teenage hacker has been sentenced to almost a year in juvenile detention after admitting running a botnet and bombarding the 911 emergency service with hoax calls. The 17-year-old hacker, from Worcester, Massachusetts, who was referred Read more…

Share

Twitter users swamped by TheSmartECard messages

Image (1) smartecard.jpg for post 14020

It seems that Twitter is becoming a major new playground for spammers and malware authors keen to target social networking users. Today we are seeing a new series of messages being posted to the streams of hundreds of unsuspecting Twitterers: Read more…

Share

Sophos at RSA

Image (1) rsa-conference-2009.jpg for post 12064

Like just about every other security company on the planet, Sophos is exhibiting at the RSA 2009 Conference in San Francisco, California this week. If you happen to in the area of the Moscone Center, do pop by booth 1817 Read more…

Share

Sophos sales magic in Boston

Default image

If you've been following the Clu-blog in the last week or so, you'll notice that it's been dominated by news about the various incarnations of the StalkDaily/Mikeyy Mooney worms that have been hitting users of the Twitter micro-blogging website. But Read more…

Share

Fake AV Now Part of Security Center

Image (1) securityc.png for post 20015

The drudgery of fake antivirus. After countless permutations (Pn, Pn+1....Pn+9999) of these fake AVs, it is very hard to keep the enthusiasm high. Lately, a 'not-another-fake-av' groan came with a slight variation. This time, the authors have figured out a Read more…

Share

I Spy Waled

Image (1) waled-sms-spy-1.jpg for post 23529

This week Waled updated their main payload site again, this time pretending to offer software called "SMS Spy". In March Waled sites pretended to be Reuters reporting about an explosion, February saw them spoof the Couponizer site, and back in Read more…

Share

New Mikeyy worm makes jokes at Twitter's expense

Image (1) mikeyy-womp.jpg for post 14010

Another day, another Twitter worm. After yesterday's attack referencing the likes of Ashton Kutcher and Oprah Winfrey we are now seeing many Twitter users spreading messages on behalf of a new version of the Mikeyy worm, this time their common Read more…

Share

Twitter XSS Strikes Again

Image (1) twitter1.jpg for post 23521

It seems to be a bad week for Twitter as once again they have been targeted by an XSS attack which is spreading quickly across Twitter. It's still not certain as to who wrote it, though "Mikeyy" is being referenced Read more…

Share

Malware unit testing

Default image

Malware analysis can be quite a complex task -- with all the different packing, code obfuscation, anti-emulation, anti-debugging, rootkit techniques, etc. etc. -- one can assume the development of such malware is equally challenging (I'll have to assume, not having Read more…

Share

Mikeyy worm targets Oprah, New York Times and others

Image (1) mikeyy-oprah.gif for post 14006

A new version of the Mikeyy cross-site scripting worm is spreading extremely rapidly across the Twitter micro-blogging network. Messages posted by the worm include: @oprah - sup? welcome to twitter. - mikeyy @TheEllenShow - hey baby, love me long time? Read more…

Share

Sality Goes EPO

Default image

One of the more active families of file infecting viruses, Sality, has this week received a major overhaul in its infection method. Sality has been a major headache to AV companies and their customers due to constant changes in its Read more…

Share

Firm hires Twitter worm author Mikeyy Mooney

Image (1) mikeyy-job1.jpg for post 12060

Mikeyy Mooney, the 17-year old hacker who caused mayhem on Twitter with a series of worms on the micro-blogging website last weekend, has been rewarded with a job in web applications development according to media reports. Frankly, the news that Read more…

Share

What April Fool?

Image (2) aprilfool.jpg for post 23517

Context: I Spoke Too Soon! (But still nothing on Conficker)

Share

Who doesn't like fruit?!

Image (1) justrude.png for post 23512

Especially the ever easy to reach 'low-hanging fruit'. One of the over ripe, yet still tasty, low-hanging fruit of the AV industry, is the ever pervasive inclusion of "flames" or "tags" in ones warez.... These ( typically rude ) phrases Read more…

Share

Perfect Job - Getting Paid to Post in Blogs

Image (1) blog_makingmoney1.png for post 20013

With the sharp rise of unemployment due to global economic crisis, more and more job related spam is found in the internet. This kind of spam usually offers job opportunities which sound very nice. The most recent example is to Read more…

Share

April 2009 Microsoft Security Bulletins

Default image

March seems to have been a busy month for colleagues at Microsoft Security Response Center and the hard work resulted in 8 new Security bulletins of which five have received the rating Critical. Several vulnerabilities have a potential to be Read more…

Share

Beware of PowerPoint boobies traps

Beware of PowerPoint boobies traps

In just a few hours time Microsoft will be releasing its regular month "Patch Tuesday" bundle of security fixes - this month including patches for critical vulnerabilities in the likes of Internet Explorer and Microsoft Excel. But according to the Read more…

Share