New Viruses

Italy: Political Controversy Spam

Fri, 06/26/2009 - 01:13
As the controversy about Italian Prime Minister Silvio Berlusconi rises, spammers take advantage of the news to lure their victims to their malicious plots. The spammed mail claims to come from YouTube, but checking the domain of the sender reveals that it actually came from youtorube.com, and not from the real youtube.com. Figure 1. Notice the [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Italy: Political Controversy Spam

Categories: New Viruses

Blackhat SEO Quick to Abuse Farrah Fawcett Death

Fri, 06/26/2009 - 01:03
Cybercriminals take the low road once again as they pepper the Internet with blackhat SEO links that are likely to attract users searching for news about the death of Charlie’s Angels star Farrah Fawcett, who, at age 62, finally ended a long struggle with cancer. Figure 1. Blackhat SEO links for Farrah Fawcett searches sets in Hosted [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Blackhat SEO Quick to Abuse Farrah Fawcett Death

Categories: New Viruses

Google Cash Club Makes Headlines in Phishing Attack

Fri, 06/26/2009 - 00:47
We have recently discovered a version, of online fraud that takes the guise of a legitimate-lookng news website. At first glance, the content of the purported news page appears real but after conducting further analysis, one will realize that the news page is actually a spammy site. What’s supposed to be a news article is actually [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Google Cash Club Makes Headlines in Phishing Attack

Categories: New Viruses

"Critical Update" Leads to Critical Info Theft

Mon, 06/22/2009 - 07:40
Microsoft Corporation regularly issues updates to fix bugs and security vulnerabilities in its software products. These updates are meant to protect its users from different attacks that depend mainly on exploiting these documented bugs. Close to the weekend, we identified spam (click Figure 1 thumbnail for larger view) claiming to be a Microsoft Outlook and Outlook [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

"Critical Update" Leads to Critical Info Theft

Categories: New Viruses

Tattletale Spam Reveals Malicious File Instead of Gossip

Fri, 06/19/2009 - 10:02
Cybercriminals pose as tattletales about to reveal something scandalous in a malicious spam run we’ve encountered recently. Cybercriminals crafted the spam messages to look similar to an email from YouTube. It arrives with a link which is supposedly a video posted on the said video-sharing website. The message is written in Portuguese and roughly translates to the [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Tattletale Spam Reveals Malicious File Instead of Gossip

Categories: New Viruses

Australia: Taxpayers Targeted by Phishing Attack

Fri, 06/19/2009 - 09:58
The Australian Taxation Office (ATO) is calling on people to start thinking about lodging their 2008 tax returns. With this significant event on the rise, spammers are using this as bait to promote phishing mails. The email contains a letter stating that it was from ATO. It informs the receiver that he or she is eligible [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Australia: Taxpayers Targeted by Phishing Attack

Categories: New Viruses

Deceitful Advertisement thru Dating Spam

Thu, 06/18/2009 - 07:59
Today we have noticed an increase in the amount of dating spam mails containing phrases such as: I’m emailing you because I like you wanted to let you know about my profile you have been invited to join The link in the spam points to an adult-dating web page that contains pictures of a woman, as well as [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Deceitful Advertisement thru Dating Spam

Categories: New Viruses

Air France Flight 447 Spam Arrives with PowerPoint Exploit

Thu, 06/18/2009 - 01:33
After a blackhat SEO attack, cybercriminals are again using the terrifying catastrophe of Air France Flight 447 or about China-made C919 Jumbo Jets competing with Airbus and Boeing for malicious intent. This time, spam messages are sent with an attached PowerPoint presentation, which is specially crafted to exploit a vulnerability in Microsoft Powerpoint. The spammed [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Air France Flight 447 Spam Arrives with PowerPoint Exploit

Categories: New Viruses

Wholesale Redirects to Malware Averted, For Now

Wed, 06/17/2009 - 11:32
URL redirection services like TinyURL have grown from almost nothing in recent years, due entirely to the success of Twitter and its 140-character limit. For most users, they represent a welcome convenience as they make their tweets, status messages, and other such space-limited posts throughout the day. Unfortunately, cybercriminals have used such services as part of [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Wholesale Redirects to Malware Averted, For Now

Categories: New Viruses

Iran: Street Protests Paralleled by DDoS Attacks

Wed, 06/17/2009 - 06:46
The violent protests by activists unhappy with the results of the recently concluded Iran presidential elections are being paralleled by DDoS attacks organized by hacktivists to bring down Iran government websites. Although it hasn’t been confirmed if the DDoS attacks were indeed successful, several Iranian government websites have been reported inaccessible. Noah Shachtman from Wired expressed [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Iran: Street Protests Paralleled by DDoS Attacks

Categories: New Viruses

Not One but Two New OS X Malware

Tue, 06/16/2009 - 20:44
Two new malware for Mac OS X were recently discovered. Even though there are indeed relatively fewer Mac malware compared with Windows, many Mac users who still believe they are somehow magically immune from attacks may run the risk of encountering any of these two. One of the newest Mac OS X malware, a Trojan detected [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Not One but Two New OS X Malware

Categories: New Viruses

Spammers Celebrate with Father’s Day Early

Tue, 06/16/2009 - 20:22
Father’s Day is a tradition meant for us to show our appreciation for fathers. With the fast changing technology however, people, spammers especially, follow the trend and celebrate the occasion in their own way. Clicking the link in the spam message displays a website that seems to be for the mattress vendor, Tempur-Pedic. It invites users [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Spammers Celebrate with Father’s Day Early

Categories: New Viruses

Another Google Search Feature Abused

Tue, 06/16/2009 - 03:52
A recent set of spam emails was seen abusing yet another Google search feature: The URL in the spam email above uses the search feature q=site: in order to direct the user clicking on the link to a Google results page returning the spam site: What works in the spammers advantage is Google displays the first few [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Another Google Search Feature Abused

Categories: New Viruses

Scammers Ride on H1N1 Global Pandemic

Tue, 06/16/2009 - 01:39
The World Health Organization (WHO) raised the H1N1 global pandemic alert level to phase 6 on June 11. More than 70 countries have now reported cases of human infection. Many of the cases reportedly had links to travel or were localized outbreaks. The WHO designation of a phase 6 pandemic alert reflects the fact that [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Scammers Ride on H1N1 Global Pandemic

Categories: New Viruses

The Good and the Bad of Being A New Spam Bot

Fri, 06/12/2009 - 04:52
It seems like a new spam bot is currently being developed. Few days ago, a fellow researcher posted a pretty good analysis of a relatively simple spam bot, which Trend Micro detects as TROJ_PROXY.AIF. This spam bot is quite straightforward. On execution, the Trojan (TROJ_PROXY.AIF) issues a DNS query to a single domain in order [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

The Good and the Bad of Being A New Spam Bot

Categories: New Viruses

Botnet Research on WALEDAC and PUSHDO

Fri, 06/12/2009 - 03:28
TrendLabs researchers have recently published their research on two of the most prevalent botnets in the threat landscape to date: Infiltrating WALEDAC Botnet’s Covert Operations Spam is not a mere inbox annoyance anymore but is the first step toward executing more dangerous kinds of system infiltration. Malware are no longer discrete executables but a motley group of [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Botnet Research on WALEDAC and PUSHDO

Categories: New Viruses

Stolen FTP Credentials Key to Gumblar Attack

Wed, 06/10/2009 - 09:38
Analysts of the recent Gumblar attack that compromised thousands of legitimate websites stated that the unauthorized modifications in the websites were possibly executed not only through SQL injection. The compromise was also reportedly done through accessing web server files through stolen FTP credentials gathered by one of the final malware payloads of the same attack. The [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Stolen FTP Credentials Key to Gumblar Attack

Categories: New Viruses

June 2009 Microsoft and Adobe Security Updates

Wed, 06/10/2009 - 06:48
Microsoft released ten security advisories yesterday to address at least 31 vulnerability issues in its various Windows operating system (OS) versions and other software. This broke the company’s December 2008 record of releasing patches for 28 vulnerabilities. Six of the said vulnerabilities were categorized as critical, three were important, and one was moderate. This means [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

June 2009 Microsoft and Adobe Security Updates

Categories: New Viruses

Beware of Repackaged HijackThis Downloads

Wed, 06/10/2009 - 00:06
HijackThis™ is one of the well-known free utilities of Trend Micro that quickly scans a user’s Windows computer to find settings that may have been changed by spyware, malware, or other unwanted programs. By itself, it does not determine what is good or bad but it lists registry keys and files system of the scanned [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Beware of Repackaged HijackThis Downloads

Categories: New Viruses

Reconfigure Your Outlook with Malware

Sun, 06/07/2009 - 23:01
A few days ago, we reported about a phishing email that is supposedly a Microsoft Outlook notification, telling users to reconfigure their program by clicking on the link provided. Instead of an update, however, the user is redirected to a phishing Web site, where s/he is asked for his/her account information, including incoming and outgoing [...]

Post from: TrendLabs | Malware Blog - by Trend Micro

Reconfigure Your Outlook with Malware

Categories: New Viruses
Syndicate content