01 May 2007

 

Trojan Hides in Postcard

Sophos has just posted a warning about an electronic postcard that is being sent out containing the Trojan Mal/Zapchas-A.
The email's appearance makes one think that it came from a friend and is very similar to any other postcard one might receive asking the users to go the some site to download the postcard. The file is named postcard.exe which should serve as a warning immediately - most e-postcards and e-cards run as a flash animation embedded in the website itself.
Full information and a copy of the actual text of the message can be found here.

Labels: , , , , , ,


23 January 2007

 

Internet Love Email Virus

There is a virus going around email right now with the subject of Internet Love
It claims to be from Symantec and contains an attachment (attachment.dat).
Below is the text of the actual email that was sent.

This message has been processed by Symantec's AntiVirus Technology.

greeting postcard.exe was infected with the malicious virus Trojan.Peacomm and has been deleted because the file cannot be cleaned.


For more information on antivirus tips and technology, visit
http://ses.symantec.com/

Do not go to the above website, as you can see it is obviously not Symantec's website - notice the ses in place of www.

Labels: , , ,


19 January 2007

 

Storm-Worm Blows Through Computers Worldwide

F-Secure has posted a video showing the spread of the so called Storm-Worm.
The Storm-Worm is passing through emails pretending to be a news article about the current storm in Europe. The heading in the email states '230 dead as storm batters Europe'. Attached to the email is a virus and Trojan named Small.damTROJAN. The virus allows the spammer to take control of the infected computer and allows the message to be sent to others. So far it is estimated that this virus has infected over 10,000 computers.

Labels: , , ,


 

Spam Newsletters and News

Spammers have developed a new way of avoiding email filters.
It seems spammers are taking standard newsletters that may be sent by legitimate well-known sources and adding either malware or adware in the message or adding links to malicious websites.
Similarly there are also spam emails emerging with the appearance of breaking news stories to try to get users to open them.
All of these types of spam can carry a Trojan and according to Sophos' monitoring there was a point where up to one in 200 emails contained a Trojan. The spam usually contain files such as Full Clip.exe, Full Story.exe, Full Video.exe, Read More.exe, and Video.exe.

Labels: , , , , , ,


13 January 2007

 

Internet Scam Threatens Lives

A new email scam has started to work its way around the Internet. Rather than offering you money for a small amount of money sent for fees, this time the scam is threatening people's lives.
An email claiming to be from a hitman who has been hired to kill the person is currently being sent out. This email asks recipients for as much as $80000 claiming that the hitman will ignore his contract to kill the person if he receives the money. The hitman claims to have followed the victim around for 10 days and will produce a tap proving that there is a contract to kill the person after the first payment of $20000. The email also warns users not to go to the police or FBI or the hitman may be forced to kill the person.

Labels: , ,


11 January 2007

 

Copying Stubborn Embedded Files from Emails

Have you ever received the email with an embedded file that you wanted to save but just couldn't with a right click?
Evolution users have an option to do so quite easily. When the email is selected a ctrl + u will bring up a window showing the encoding of the email. In this window will be a Base64 form of all embedded files and attachments within the email. Any other email client that allows users to view base64 encoding of the files will work for this too. If you copy that code into a file, you can then use perl to decode it into the binary original again. I would recommend using vi - you need the text with no additional characters (i.e. carriage returns).
From a Linux command line you can then type:
perl -MMIME::Base64 -ne 'print decode_base64($_)' < inputfile > outputfile
You've now got the original image or other file.

Labels: , , ,


25 December 2006

 

Not so Merry Christmas Greeting

A PowerPoint presentation is going around emails right now called Christmas+Blessings-4.ppt which contains a version of the Hupigon (Hupigeon) Trojan. This installs two other files called msupdate.dll and sdfsc.dll.
The Trojan comes in an email with the subject "Merry Christmas to our hero sons and daughters!". There isn't much known about the attack but it is assumed to be based on the MS06-012 exploit in MS Office that lets commands be executed from a remote source.

Labels: , , , ,


15 December 2006

 

Charge For Email Access To You

People who are tired of all the spam mail they receive can now turn to boxbe for help. This service was recently started to combat spam messages and may actually succeed.
The service allows users to list email addresses of their friends and then charge a fee for others to send you any message. This fee is set to whatever value you decide from a few cents to $99. If the sender pays the fee, you receive the message and after confirming either you or your choice of charity will receive the money from the message. Of course you will have to collect a certain amount before any money is sent. Boxbe allows users to provide information about themselves as a way to advertise yourself to advertisers.
How popular this will become is completely unknown, but if it provides a way to stop unwanted spam or at least charge spammers for annoying us, it is definitely a needed service.

Labels: , ,


25 November 2006

 

Free Porn For Your Most Personal Information

Nothing is free these days and that is certainly true of online porn.
It seems the current form of social engineering is to attract Internet Explorer users to sites offering free pornography. Currently, there is a major spam campaign against unpatched versions of Internet Explorer offering free pornography while actually providing the Psyme-DL Trojan. When users open the link, they are taken to a page that automatically installs the Trojan. Firefox users are asked to switch browsers and are unaffected as are fully patched IE users and users of IE 7.
This is just another reminder of why people should practice safe browsing habits, but despite all the warnings many users will find such an email impossible to resist and go to it anyway, which is exactly what the creators of such social engineering schemes are hoping for.

Labels: , , ,


24 October 2006

 

Common Dangerous Activities

DarkReading has released an article describing ten of the most dangerous things that people do online. They begin by stating that no matter how much training users receive, they still do things that compromise their computer's security such as leaving passwords stuck to their monitor or downloading software for personal use.
The number one risky activity that users do is open email attachments from unknown people. Even with all the publicity about this, users still are doing it. Email attachment are the most likely way of getting viruses or other malicious programs. If you look at any site that lists current security attacks, many of the attacks will be conducted via email, even if only a link to a website from the email. While a recent survey found that 93% of UK office workers knew that such links and attachments could contain viruses, 86% claimed to actually have opened them without knowing about the safety involved and 76% do it regularly. How can such activities be combated when users know the risk but do it anyway. People might as well be playing Russian Roulette with their computers.
Of course second comes the users who install personal software. IM software is a double edged sword in this sense, it is very useful for companies to keep in touch, while at the same time poses a security risk when connected to the outside world. Peer-to-peer file sharing programs are far more risky allowing for viruses to easily enter the system or confidential corporate information to worm its way out of the system. Also with file sharing applications there is the included possibility of pirated software or music entering and being stored on a company system. With the current push to stop pirated items, it could be a legal risk to a company as well.
Thirdly is the disabling or rescheduling of security features. Users turn off firewalls to increase their Internet speed or allow certain files to be sent and received. Many users also tend to reschedule or put off changing their passwords or security patch installation claiming that it keeps them from doing their work and is too much of a hassle.
Similarly there are the people who routinely log onto their computers with administrator accounts for very much the same reason. In this case it's usually the private individuals who have their own companies who claim that they need to log on as admin to run applications and install applications. When you tell them of the huge security risk involved in doing that they just state how they cannot run the applications any other way. Of course showing these people how to set the permissions so that they can does nothing because it took a minute to set up.
The article continues to go into other activities such as viewing emails from unknown users, browsing the Internet for gambling, porn and other such sites, giving out passwords, and many more.
The problem is how to convince users to not do these things. Many of them know of the dangers they just do the actions anyway.

Labels: , , , ,


26 September 2006

 

New email worm crawling between computers

Yet another real-world reminder to not open strange attachments in your email is circulating the web. Win32.Warezov.at is the latest email worm to be found in the wild of the Internet.
This worm takes addresses from your address book and then using its own SMTP engine sends emails to those addresses to infect even more computers. There are many different subject lines, but the most common are "Mail System Report", "Mail Delivery System" and "test". Users are safe from the email so long as they don't open the attached file within these messages.
For those interested in details about where the worm copies itself and the changes made to the Windows Registry that information can be found here.

Labels: , , , ,


25 September 2006

 

Free Temporary Email Accounts

Anyone worried about giving their email out on different websites or to certain people, can worry a bit less.
Without any registration or work a person can give an account that can be later accessed to receive the email, while never giving you're personal account. myTrashMail allows people to make up any name @mytrashmail.com to receive a message at. This can be used when you must enter a email address for contests or for other registrations. It of course is not secure at all, but for such situations it may not matter.
If you do need a secure account, you can create such an account on their site with an address beginning with me. and ending the same as the standard accounts. These accounts can be used to receive passwords and other such information.
All of the accounts are completely anonymous and free.
The accounts are temporary though and the email is stored no longer than 30 days. The minimum time you have to access the account is 12 hours, so it does give enough time so you don't have to panic.
One problem you could face with the non-secure account is if someone else chooses the same name, they can access the email you received and possibly delete it, or you could access it first. Out of curtesy I would suggest not viewing other people's mail in such an account and especially not deleting it. I also strongly suggest deleting your own mail after you read it.

Labels: , ,


15 September 2006

 

Spamhaus and a desperate spammer

Oh the depths a spammer will go to say he's not a spammer.
Recently an Illinois company, e360 Insight, linked to a spammer filed a lawsuit against the UK-based Spamhaus. Because Spamhaus ignored the case, the court sided with the Illinois company and fined Spamhaus $11.7 million and ordered e360 Insight be taken off their Register of Known Spam Operations (ROKSO).
Like any intelligent company would do, they have ignored the court completely, as it has no UK jurisdiction and e360 Insight is related to spamming and should be listed on the site. Spamhaus has invited e360 Insight to file lawsuit in England where is says the courts do not accept "'SLAPP' suits and impose penalties for lying to the court."
Spamhaus' full response can be found here.
Spamhaus is a company whose goal is to protect Internet networks by tracking Spammers, Spam Gangs and Spam Services. It provides realtime anti-spam protection and helps Law Enforcement identify and persue spammers.
Their ROKSO list includes 200 "known Spam Operations". The requirements for being listed on the site involve being terminated by at least 3 ISPs for violations. Once on the list all IP addresses being used by the spammers and listed on the Spamhaus Block List. After 6 months of no spam activity, a organization or group will be removed from the list.
This is a very fair list. Anyone who isn't spamming will quickly be removed from the list, but those who continue to spam will stay on the list with as much information about them listed as is known. Other lists are less likely to remove a listing from their lists.
Spamhaus also provides a list of Consumer Alerts which help to educate users on protecting themselves and what not to do.

Labels: , ,


04 September 2006

 

Email - Truth or Hoax

We've all received an email that is about something that appears very important. The question is do you send it to a friend or do you check to see if it's not a hoax.
Hopefully for the sake of your friends and the rest of the Internet that is teaming with such emails constantly being passed from one person to the next you check to see if it is a hoax and not send it.
The next question of course is how to check. Well there are website dedicated to doing just that. One of which is Truth or Fiction. This site has a subject list of all their recorded emails as well as the ability to search for the one you have using unique words from the message. A general idea of the subject of the email is given with the claims of the email and the truth behind it. Also you can find a copy of the email. Of course at the very top they tell you if it's truth, fiction or unproven.
There are of course other sites out there like Hoaxbusters, but Truth or Fiction seems to have the best interface and is the easiest to follow. Although Hoaxbusters does give you information about how to recognize hoaxes and the actions you should follow when you receive one.

Labels: , ,


31 August 2006

 

Strange Name, Useful Email Security System

For people who are very concerned about the security of the email they send, Kablooey Mail helps a lot.
This works with every email program and provider and allows people to take messages they have send back and certify that a message has been read without using a return receipt. Also you can send mail that self-destructs after it has been read and has the ability to prevent it from being forwarded to other people, printed, copied, etc.
I can't imagine most people would need such functionality, but for lawyers and business this can be a very good solution rather than putting a confidentiality clause in the emails. 

Labels: ,


24 August 2006

 

Trojan uses your money to install on your computer

There's another trojan horse that is on the loose. This one has been reported by SophosLabs and is said to come in a spam email claiming that your credit card has been charged £125. This trojan named Troj/Dloadr-AMA comes in a file called paycheck.zip and when the executable in this zip file is run the trojan is installed. Of course like most malicious software this begins downloading more malicious software to your computer. 
While this trojan tries to get users upset enough to not be so cautious and install it without thinking, people should still try to be calm when reading their messages.
When users are reading spam and messages such as this one, they should always first think if something seems strange about this message. Why would a company be emailing you in this situation? Wouldn't they just call? If you have some message like this that you think might be true, but it's not your bank sending it, maybe you should contact your bank to see if they have any record of such an charge.
Secondly, when you see a message that seems to good to be true, it is. There are no such deals. In the lucrative world of spam and malicious sites and software, the most interesting or shocking messages get the most people to run it or go to the site and give their personal information.
And my last tip for email. Don't trust anything. You wouldn't let just anyone into your house. We've all heard of the person who claims to be from some utility or other company who gains access into your house and then robs your house. Well, consider strangers in email exactly like you would at your front door. It will keep you a lot safer.

Labels: , , ,


16 August 2006

 

FDIC isn't going to email you for your bank information

If you receive an email from the Federal Deposit Insurance Corporation don't believe it.
There is a new scam to get your bank and other information by instructing you to file for the FDIC protection system. The email that you would receive also says that your bank sent them an application to secure your account.
Think about the situation for a moment, would the FDIC actually email you or would they send a formal letter? Secondly, if your bank sent the application why does the FDIC need you to complete another form? Lastly, as I recall banks in the US all are insured by the FDIC, if they weren't you probably would have chosen a different bank. 

Labels: , , ,


15 August 2006

 

Two Companies Sued for Spamming

Two companies are being sued by Michigan for luring children to gamble and purchase alcoholic drinks with spam. In Michigan companies are required to ensure that any products that children cannot buy or do legally are not advertised in emails to children.
RR Media and Data Stream Group both face up to $10,000 in fines and possibly other charges if found guilty.
The charges were brought up after an investigation involving complaints of inappropriate emails for alcohol and gambling being sent to address registered as belonging to children.
Parents living in Michigan can go to the Protect MI Child website where they can register their children's email address, instant message address and fax number or file complaints relating to the Michigan Child Protection Registry Act.
Let's hope more people start fighting against spam using whatever means available even if it's only sending messages to ISPs.

Labels: , ,


11 August 2006

 

RNDR Spam increase seen between 1600% and 4000%

Spam has been reported to be up by between 1600% and 4000% by CMS on a corporate level.
Spammers have changed their methods using RNDR (Reverse Non-Delivery Report).This method involves a spammer to send a spam to a fake account on their server and to address it from the actual intended recipient of the spam. Then when their server creates and sends the NDR it sends it to the victim. This bypasses most spam filters by making it seem that the message originated at the victim.
In the past email accounts would be harvested from the Internet and then used to send these spams, but currently there is a trend developing to create random strings to generate valid email addresses. The problem with this is that it can greatly overload an email server and can also be used as a DOS attack. This technique does successfully reach valid email accounts, but it creates a huge increase in email volume as well.
Aside from the extra messages and traffic, companies also run the risk of being blacklisted for generating spam that actually never really came from them. 

Labels: ,


10 August 2006

 

Skype emails don't have to be from Skype

There is a new technique to get you to download an applicaton that will steal the passwords from your computer. An email is sent that claims to be from Skype. It then takes you to a fake Skype page and encourages you to download Skype. The problem is this is not Skype but malware called skypekur.exe. This file installs password recovery tools that then steal the passwords from your computer and send them back to the person who originally sent the email.
Currently there is one advantage that will prevent many people from falling victim, the email and page is in Turkish. That being said it would take no effort to change it into any other language. Most importantly is to be careful where you download Skype or any application from and to never trust emails asking you to download something.  

Labels: , , , ,


This page is powered by Blogger. Isn't yours?