placement for flash
  • RSS Feed

  • Categories

  • Tags

  • Archive

  • Calendar
<<  March 2010  >>
MoTuWeThFrSaSu
22232425262728
1234567
891011121314
15161718192021
22232425262728
2930311234

  • Articles by Author

  • Recent posts

  • Blogroll

1/28/2010 3:50:00 PM

Hackers use a Facebook hoax to plant Rouge Antimalware

by Oren Medini

Hackers are spreading a rumor regarding Facebook, describingit as a botnet that is used it to infect Facebook users with rogueanti-malware.

In the last 48 hours a rumor was spread claiming that an“unnamed app” in Facebook is actually a bot Trojan. The rumor was a hoax, andhackers used it to distribute malicious fake antivirus software (Rougeanti-malware). When Googling for “unnamed app”, people received links to siteswhich pose as security sites but are actually fake antivirus traps – rogueanti-malware sites.

Please be aware.

Be the first to rate this post

  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Tags:

Malweb | Hackers | Web-based Trojans

1/26/2010 6:43:00 PM

Johnny Depp fake death notice - fake ActiveX codec

by Oren Medini

On Jan 25 hackers spread a rumor claiming Johnny Depp died in acar accident. It was like a fire in a field of thorns: Twitter messages were sent talking about the rumor and gossip websites crashed. When trying to findmore information about the death of the actor using Google, some of the resultsled to websites containing a video of the car crash. The problem is that whenyou try to watch the video you will receive a message saying you don't have asupported codec and you need to download one in order to watch it. The socalled codec is actually a Trojan.

Here is a screen shot of the fake CNN page uploaded to Angefirewebsite from the Sky news website: http://tinyurl.com/yh7dsdz

Watch out from rumors! 

Currently rated 3.0 by 1 people

  • Currently 3/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Tags:

Malweb | Hackers | Web-based Trojans

1/25/2010 4:20:00 PM

Top 10 Chinese cyber attacks

by Oren Medini

The malicious activity that comes from Chinese servers isknown for a long time. In many cases we are seeing the use of Chinese serversby bots that being spread over the web. Most of these bots are beingpropagated in order to steal identity, information, backdoor etc’.

But there is also other activity, unlike these bots that arebeing operated by hackers there is also a cyber-war.

We know that countries are using hacking techniques in orderto espionage against other countries, security organizations employing hackersin order to penetrate to other countries servers, and from the Google incidentin China we actually know something that was clear to everybody – the bigbrother is watching you.  

The “Foreign Policy” web site (http://www.foreignpolicy.com/)published a very interesting article that reviews the top 10 Chinese cyberattacks (that we know of) against US government sites:

http://thecable.foreignpolicy.com/posts/2010/01/22/the_top_10_chinese_cyber
_attacks_that_we_know_of

Be the first to rate this post

  • Currently 0/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Tags:

Malweb | Hackers | Web-based Trojans | eCrime

1/21/2010 12:57:00 PM

Out-of-band patch for the Aurora exploit will be released today by Microsoft

by Oren Medini

Many words have been written about the new IE zero-day vulnerability which was used in the China attack. Microsoft will release a patch today to fix the Aurora vulnerability. I recommend to update your windows with the new patch.

Please note that we have checked all the Aurora exploit samples we received and they are all being detected by eSafe.  

 More from MS site: http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx

Currently rated 3.0 by 1 people

  • Currently 3/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Tags: , ,

Malweb | Hackers | Vulnerabilities

10/28/2009 6:41:00 PM

Malware spreading via 'Facebook Password Reset Confirmation' email

by Mahran Amona

Facebook users are once again under attack. A new variant of Bredolab Trojan is spreading through spam email messages appearing to come from Facebook.

The messages pretend to come from the “The Facebook Team”, while the real SMTP from address is in fact spoofed. However, an attached archive file containing an executable file may infect users with a Trojan horse.

The following is an example of the spammed email messages:


Subject: Facebook Password Reset Confirmation.

Hey andi ,

Because of the measures taken to provide safety to our clients, your password has been changed.
You can find your new password in attached document.

Thanks,
The Facebook Team

The attachment may come with the following name:

Facebook_Password_3db40.zip
or
Facebook_Password_[5 random characters].zip

This Bredolab Trojan downloads and executes further malware files on the affected machine such as rogue anti-virus software, and in order to bypass firewalls, it injects its own code into legitimate processes svchost.exe and explorer.exe.

Currently rated 4.5 by 2 people

  • Currently 4.5/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Tags: ,

Malweb | Spam