Saturday, June 13, 2009

[Lockergnome] Computer Security ~ June 13, 2009

Lockergnome
Lockergnome's Computer Security ~ June 13, 2009   



Shape Solitaire: Play Shape Solitaire, a new unique card puzzler. The goal is to fill all open tiles with cards by one simple rule - place a card on the field next to another card with a value one less or one greater, regardless of the suit. It's simple to learn, but incredibly fun to play! If Billy Idol can make dancing with yourself look like so much fun, Shape Solitaire succeeds in showing how exciting it... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

Just the tips, man for Excel 2000: Finally, a book about Excel that's easy to follow and fun to read. "Just the tips, man" for Excel 2000 is chocked full of hidden but incredibly useful Excel tricks that even long-time users don't know. Whether you're just getting started or have been using Excel for years, this PDF is an essential companion to Excel 2000. [ This is the unabridged version in PDF format of the Nerdy Books flip book of the... [Click Here to Download]

Administrivia

Tech Help and How To


Microsoft Finally Gives A Good Reason to Download IE8!

Six Flag Theme Parks Plummet Into Chapter 11 Bankruptcy

Previx 3.0 - Another Option To Protect Your PC

Psst? Want Some Free Software?

Reduce Your Student Loan Debt With Income Based Reductions

Thirteen Days

LaCie 1 TB USB 2.0 Desktop External Hard Drive for $90 + Free Shipping!

Microsofts Explains European Version Of Windows 7

Intel to (Possibly) Release 6-Core Nehalem, Will AMD Follow W/ Ista »

Do We Really Want Only One Version Of Windows 7 ?

Google Takes a Blow As Facebook Gets a New Director of Engineering

Bring Back MST3K!

The SR-71 Blackbird

Microsoft Morro, FUD, and Coming Late to the Party

Safari 4 - First Look

Lightning Safety And The Weather Total Lightning Network

How Malware Can Be Delivered Efficiently in Twitter

EU To Microsoft - Dropping IE Might Not Be Enough

Phil Jackson Trusted His L.A. Lakers

Yet Another Windows 7 Build, But With a Change


TrendLabs | Malware Blog - by Trend Micro - The Good and the Bad of Being A New Spam Bot

 

Your email updates, powered by FeedBlitz

 
Here are the latest updates for security-news@awsoda.net

"TrendLabs | Malware Blog - by Trend Micro" - 1 new article

  1. The Good and the Bad of Being A New Spam Bot
  2. More Recent Articles
  3. Search TrendLabs | Malware Blog - by Trend Micro

The Good and the Bad of Being A New Spam Bot

It seems like a new spam bot is currently being developed. Few days ago it was posted a pretty good analysis of a relatively simple spam bot, which Trend Micro detects as TROJ_PROXY.AIF.

This spam bot is quite straightforward. On execution the trojan (TROJ_PROXY.AIF) issues a DNS query to a single domain in order to obtain an IP address in order to connects to a C&C (Command and Control ). The C&C traffic is in plain text and one can easily identify how the C&C works (Figure 1).

We say the TROJ_PROXY.AIF is simple because, unlike other spam bots like WALEDAC, the former does not have any C&C command encryption or a robust C&C (takedown the domain and they're out of business).

One saving grace of this spam bot however, is its implementation of certain techniques to avoid spam filters. Take a look at a sample spam mail generated by TROJ_PROXY.AIF (Figure 2).

Click for larger view Click for larger view

A short glance introduces a simple spam email, but a closer look reveals that there are 5 intended recipients of the spam mail. This is quite uncommon for a spam mail since most spam e-mails out there has a 1 spam per target e-mail address format and this technique might actually throw off some spam filters.

Another technique used by this spam bot is it uses a Google group to link in the e-mail body which acts as a middle-man for the actual spam site advertising penis enlargement pills.

Click for larger view Click for larger view

The two techniques mentioned, combined with the usual random lettered words and normal words in the e-mail subject and body gives the spam a better chance at passing through Bayesian filters and anti-spam signatures.

Mentionable is that most of the target e-mail addresses are Yahoo! or other webmail users, which then again slightly increases the spam e-mails chances of passing through since most of these webmails are free services and have slightly lower level of spam protection as compared to corporate networks with a stronger anti-spam product and stringent e-mail policies.


Click for larger view

In all, TROJ_PROXY.AIF may be relatively simple now, but it is possible this spam bot is still in the early stages of development and may one day evolve into something more complex.

Post from: TrendLabs | Malware Blog - by Trend Micro

The Good and the Bad of Being A New Spam Bot



More Recent Articles



Click here to safely unsubscribe now from "TrendLabs | Malware Blog - by Trend Micro" or change your subscription or subscribe

 
Unsubscribe from all current and future newsletters powered by FeedBlitz
Your requested content delivery powered by FeedBlitz, LLC, 9 Thoreau Way, Sudbury, MA 01776, USA. +1.978.776.9498

 

Friday, June 12, 2009

[Lockergnome] Computer Security ~ June 12, 2009

Lockergnome
Lockergnome's Computer Security ~ June 12, 2009   



Tracing and Logging with .NET: In the ideal world, every application and component would be a black box that would work perfectly the first time, and that would fulfill its purpose without any need for human intervention or review. In practice, this ideal is rarely achieved. Real world applications need to be instrumented - meaning that there need to be ways for them to report on how they are working. [ Available in PDF Format for $10 / Download... [Click Here to Download]

Lockergnome help - Antivirus Discussions

Lockergnome help - Trojans/Spyware Discussions

Lockergnome help - Antivirus Discussions - General Discussions

Lockergnome help - Antivirus Discussions - McAfee

Lockergnome help - Antivirus Discussions - Symantec/Norton

Lockergnome help - Antivirus Discussions - AVG

Lockergnome help - Antivirus Discussions - F-PROT

Lockergnome help - Antivirus Discussions - Panda

Lockergnome help - Antivirus Discussions - Free Antivirus

Lockergnome help - Antivirus Discussions - Others

Lockergnome help - Trojans/Spyware Discussions - General Discussions

Lockergnome help - Trojans/Spyware Discussions - Lavasoft Ad-Aware

Lockergnome help - Trojans/Spyware Discussions - Webroot Spy Sweeper

Lockergnome help - Trojans/Spyware Discussions - Spybot S&D

Say The Time: Get organized -- the fun and easy way! Say the Time will keep you on schedule by automatically announcing the date, time or both at specified intervals using a pleasant male or female voice. Keep track of important time commitments with fully-customizable appointment reminders. Transform your boring taskbar time display into a colorful clock that can display both the date and the time. [Get More Information | Download Your Free Trial]... [Click Here to Download]

Administrivia

Tech Help and How To


Bring Back MST3K!

The SR-71 Blackbird

Microsoft Morro, FUD, and Coming Late to the Party

Safari 4 - First Look

Lightning Safety And The Weather Total Lightning Network

How Malware Can Be Delivered Efficiently in Twitter

EU To Microsoft - Dropping IE Might Not Be Enough

Phil Jackson Trusted His L.A. Lakers

Yet Another Windows 7 Build, But With a Change

Symantec And McAfee Fined For Auto Renewal Policies

Microsoft - Windows Without I.E. For Europe

T-Mobile Posts Secret iPhone S Spec?s - Accident Or Planned?

DTV Transition - Chaos, No Matter How Prepared

Spotted: AMD Phenom II TWKR Edition

Internet Poker Funds Seized By Banks

OSS Vs ALSA

No Need To Upgrade Just Yet

A Whole New Way To Linux Desktop

Dell Vostro A90 Netbook For $249 - Only 1,000 Available

The L.A. Lakers Are Asking Kobe to Pass


Subscribe via email

Enter your email address:

Delivered by FeedBurner

Blog Archive