Saturday, May 24, 2008

[Lockergnome] Computer Security ~ May 24, 2008

Lockergnome
Lockergnome's Computer Security ~ May 24, 2008   



Just Buttons Pro: Create outstanding buttons for your site! Just Buttons Pro gives you full control over the creation of your Web buttons. Add custom shadows or highlights to your text or the buttons themselves. Have a favorite button image that you already created in a paint program? Import it as a background and just specify the desired text. In short, Just Buttons allows you to quickly create stunning Web buttons for any site you are working on!... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security

Balloon Blast: Balloons are attacking! Blast the groups of the same color. Collect rockets and mega bombs - and save the day with them at the right moment. Three variations of the game: Mind-Twisting Puzzle, Steady Tactics, and Fast-Paced Arcade deliver fun game play for everybody! [Download]... [Click Here to Download]

Administrivia

Tech Help and How To

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security






» Disk Redactor
» Dr.Web CureIt!
» 3CX Phone System for Windows Free
» SC-DiskInfo
» ProxyChecker.Net (1.0.0.23)


TrendLabs | Malware Blog - by Trend Micro - 2 new articles

 

Your email updates, powered by FeedBlitz

 
Here are the latest updates for security-news@awsoda.net

"TrendLabs | Malware Blog - by Trend Micro" - 2 new articles

  1. Trend Micro Spoofed in Brazilian Info Theft Attack
  2. Then Subpoenas, Now Tax Petitions
  3. More Recent Articles
  4. Search TrendLabs | Malware Blog - by Trend Micro

Trend Micro Spoofed in Brazilian Info Theft Attack

A few hours ago we discovered a spam run in Brazil that uses a trendmicro address in its From field:


Figure 1. Sample of Brazilian spam first seen evening of May 22 by our honeypots.

Our support team in the Latin American region observed some 6,000 samples of this spam since it was first identified. The blast seems to be coming down to approximately 15 samples a minute, according to one of our analysts from the region.

When translated it reads as follows (grammar lapses intact):

Subject: you may loose all your information as well as your e-mail


Our servers have detected a security failure in your email account. for more security without the loose of data or vulnerabilities on your email box we remind you to active your mailbox


or you will loose all your information as well as your email

to activate your mailbox is very easy

1 click on the link below
2 you will see a window with the button execute press execute
3 after that click on the button open and you will be redirected to your activated mailbox
4 write your complete email - full name - city - state - zip.

[link] Activate your email mailbox

remember that you have only from 12 to 24 hour To activate your mailbox
otherwise our system will block your E-mail account.

to obtain more information you can get in touch with our services team through our E-mail
[email address]

This "security failure," ironically, is what happens when the recipient falls for the ruse and clicks on the link to "activate" his/her email inbox.

The link actually leads to hxxp://{BLOCKED}security.bravehost.com/protecao.exe (where hxxp is http). Protecao.exe is detected as TROJ_BANLOAD.FAF. Its main purpose is to connect to another URL in the same domain to download a file named plugin-security.exe. (It also accesses another URL which is inaccessible as of this writing.)

This 3MB file is a Trojan spyware detected by our patterns as TSPY_BANKER.OIZ, and is a bank account info stealing malware. Note that upon clicking the link in the spam, a dialog prompt appears asking the user whether to Open, Run or Save the file. However, upon accepting the file, it goes on to download the spyware without informing the user.

We advise Latin American users to be especially wary of this attack. Sometimes users are more likely to trust an email message written in their native language, but in this case we must chalk this up to targeted social engineering and should, as always, immediately delete such threatening mail. Note that Trend Micro will NEVER send email such as this.

Legitimate communications typically come with the appropriate headings, company logos, and proper language. Another possible tell-tale sign that the email is not legitimate is that the link is connected directly to an executable.

Trend Micro users, on the other hand, need not worry, as our Web Threat Protection technology cuts off infection by both detecting the attack-related files and blocking the malicious URLs. Our antispam definitions already filter this threat.

Thanks to Threats Analyst Jose Lopez Tello for alerting us to this attack.

ShareThis



Then Subpoenas, Now Tax Petitions

The Content Security (CS) team of TrendLabs has come across a new spear phishing incident that’s reminiscent of the whale phishing incident documented last April, wherein bogus subpoenas were sent to CEOs.

The new spam run involves email messages sent to specific organizations as notices of deficiency or tax petitions supposedly coming from the United States Tax Court (refer to Figure 1).

Spammed Email

Figure 1: Sample screenshot of the spammed spear phishing email

Once members of a targeted organization click on the link in the message body, they are directed to the site www.ustax-courts.com—the purported US Tax Court site—and asked to download a higher version of Internet Explorer (IE) onto their system to further view court details (see Figure 2). By string manipulation (in this case, adding a dash to the actual domain name of the actual site), unknowing users are easily made to believe that the bogus site is legitimate, making them most likely to click on the link.

The legitimate US Tax Court site is www.ustaxcourt.gov.

Bogus Web site

Figure 2: Sample screenshot of the bogus US Tax Court Web site

Trend Micro advises users to be cautious in viewing emails and warns against clicking automatically on given links within these messages. As we have advised before, consult with lawyers in case important-looking emails may be valid. But in this case, the concerned Court has declared that it does not send email notices to those with cases before it:

US Tax Court Notice to users

ShareThis



More Recent Articles



Click here to safely unsubscribe now from "TrendLabs | Malware Blog - by Trend Micro" or change subscription settings

 
Unsubscribe from all current and future newsletters powered by FeedBlitz
Your requested content delivery powered by FeedBlitz, LLC, 9 Thoreau Way, Sudbury, MA 01776, USA. +1.978.776.9498

 

Friday, May 23, 2008

[Lockergnome] Computer Security ~ May 23, 2008

Lockergnome
Lockergnome's Computer Security ~ May 23, 2008   



Personal File Server: Wrinc Lab's new Personal File Server is Web-based software that allows Web site visitors to download and upload files using only their favorite browser. It is a very extensible solution in sharing audio/video files, documents or any other file type with ease. Files can be shared with colleagues and friends on a network, intranet or Internet without needing any third party software or a browser plug-in. It is also a very robust solution for customized... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security

DU Meter: DU Meter is a powerful and user-friendly tool that provides an accurate account of the data which is flowing through your computer's network connection at any given moment. Its readout is presented in both numerical and graphical format, in real time. DU Meter includes extensive logging facility, flexible events system, and more. DU Meter works with virtually all types of network connections: phone modems, DSL, cable modems, LAN, satellite, and more. Fully compatible with all... [Click Here to Download]

Administrivia

Tech Help and How To

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security






» Disk Redactor
» Dr.Web CureIt!
» 3CX Phone System for Windows Free
» SC-DiskInfo
» ProxyChecker.Net (1.0.0.23)


Subscribe via email

Enter your email address:

Delivered by FeedBurner

Blog Archive