“We apologise for the previous apology” – NZ gov dept in email CC: double-blunder
Written by v2r on March 30, 2013 – 11:02 pm -A government department in New Zealand has had to apologise twice after mixing up CC: and BCC: when apologising for mixing up CC: and BCC:. It's a really easy mistake to make, so take a moment to remind yourself why it's a bad idea......
READ MORE >>Tags: bcc, C&C, computer security, data leakage, email, Featured, Malware, malware remove, Scam, spam, virus remove
Posted in Virus removal tools |
Anatomy of a targeted attack – SophosLabs explores an Adobe zero-day "malware experiment"
Written by v2r on February 14, 2013 – 4:52 am -SophosLabs was contacted recently to help investigate malware from an unusual sort of targeted attack. What our researchers found was intriguing, to say the least, so we thought we'd share our discoveries with you... ...
READ MORE >>Tags: 0-day, Adobe, APT, bot, Botnet, C&C, computer security, downloader, Exploit, Featured, flash, Malware, malware remove, virus remove, Vulnerability, zero-day, zombie
Posted in Virus removal tools |
Walking through Win32/Jabberbot.A instant messaging C&C
Written by v2r on January 30, 2013 – 1:51 pm -Malware authors have a solid track record in regards to creative Command and Control protocols. We've seen peer-to-peer protocols, some custom (Sality), some standard (Win32/Storm uses the eDonkey P2P protocol). We've seen binary protocols (Win32/Peerfrag, aka Palevo). We've seen other custom protocols that leverage oth...
READ MORE >>Tags: Botnet, C&C, computer security, General, jabber, Malware, malware remove, virus remove, xmpp
Posted in Virus removal tools |
Botnets Are Everywhere – See How They Spread in the Trend Micro Global Botnet Map
Written by v2r on January 15, 2013 – 2:53 am -Cybercriminals today create and use botnets to perpetrate their criminal activities. Whether it is to send out Blackhole Exploit Kit spam or to use as entry points into organizations, the one constant is that most bots (victim computers) communicate back and forth with command and control (C&C) servers. Trend Micro’s Glob...
READ MORE >>Tags: Botnet, botnets, C&C, computer security, malware remove, map, virus remove
Posted in Virus removal tools |
Flamer Analysis: Framework Reconstruction
Written by v2r on August 2, 2012 – 9:34 pm -From the very beginning of our analysis of Win32/Flamer it was clear that this was an extremely sophisticated piece of malware which we had never seen before. It implements extremely elaborate programming logic and has an intricate internal structure. At the heart of Flame’s modularity lies a carefully designed architecture allow...
READ MORE >>Tags: Aleksandr Matrosov, C&C, Command executors, computer security, consumers, Delayed Task, Duqu, Eugene Rodionov, Flame, Flamer, malware remove, Standard Template Library, Stuxnet, vectors, virus remove
Posted in Virus removal tools |
OS X Lamadai: Flashback isn’t the only Mac malware threat
Written by v2r on April 25, 2012 – 2:27 pm -The Flashback trojan has been all over the news lately, but it is not the only Mac malware threat out there at the moment. A few weeks ago, we published a technical analysis of OSX/Lamadai.A, the Mac OS X payload of a multi-platform attack exploiting the Java vulnerability CVE-2011-3544 to infect its victims. OSX/Lamadai.A has buil...
READ MORE >>Tags: Alexis Dorais-Joncas, Apple, Botnet, C&C, computer security, Flashback, General, information stealer, mac, malware remove, Marc-Étienne M. Léveillé, OS X, OSX/Lamadai, Tibet, Trojan, virus remove
Posted in Virus removal tools |
Drive-by FTP: a new view of CVE-2011-3544
Written by v2r on March 17, 2012 – 1:47 pm -[Some interesting research reported by Aleksandr Matrosov] [Update: minor edits to graphics] [Update 2: two additional FTP server graphics added at the end.] Not long ago we received interesting information from an independent security researcher from Russia, Vladimir Kropotov. (We will be presenting our joint research with him at ...
READ MORE >>Tags: Aleksandr Matrosov, Black Hat SEO, C&C, CARO, click-jacking, computer security, context ads, CVE-2011-3544, David Harley, drive-by, Exploit, exploit kit, FTP, IFRAME, Java, Java/Exploit.CVE-2011-3544, JavaScript, malware remove, virus remove, Vladimir Kropotov, Win32/TrojanClicker.Agent.NII
Posted in Virus removal tools |
Kelihos: not Alien Resurrection, more Attack of the Clones
Written by v2r on March 10, 2012 – 11:01 am -Our colleagues at ESET UK drew my attention to another article on the resurrection of the Kelihos botnet (Win32/Kelihos). The article is based on the abuse.ch analysis of a particular sample. The analysis is interesting and well executed, but the reappearance of Kelihos isn’t exactly hot off the press: there were severa...
READ MORE >>Tags: ;cz.cc, abuse.ch, AV, botnets, C&C, computer security, David Harley, EU, FTP, Kaspersky, Kelihos, LNK, malware remove, Microsoft, nuwar, P2P, peer-to-peer, Pierre-Marc Bureau, Sébastien Duquette, sinkhole, sinkholing, spam, Storm, takedown, TLD, v3.co.uk, virus remove, Waledac, Win32/Kelihos
Posted in Virus removal tools |
Facebook Fakebook: New Trends in Carberp Activity
Written by v2r on January 26, 2012 – 5:33 pm -Aleksandr Matrosov, one of my colleagues in Moscow, writes: This month we discovered some new facts relating to Win32/Carberp trojan activity. We have spent a lot of time writing about Carberp already, but interesting information is still coming to light. The first interesting information to attract our attention recently concerned...
READ MORE >>Tags: Aleksandr Matrosov, bootkit, Botnet, C&C, Carberp, computer security, David Harley, DDoS, Delphi, Facebook, Fake Facebook Lockout, fraud, Global Infection Statistics, information, malware remove, RBS, Russia, Russian Federation, statistics, virus remove, Win32 Carberp, Win32/Carberp
Posted in Virus removal tools |
TDL4 rebooted
Written by v2r on October 19, 2011 – 6:50 am -ESET researchers have been tracking the TDL4 botnet for a long time, and now we have noticed a new phase in its evolution. Based on the analysis of its components we can say that some of those components have been rewritten from scratch (kernel-mode driver, user-mode payload) while some (specifically, some bootkit compone...
READ MORE >>Tags: Aleksandr Matrosov, bootkit, Botnet, C&C, computer security, David Harley, Eugene Rodionov, hidden file system, malware remove, TDL4, TDSS, virus remove
Posted in Virus removal tools |