| 

My Facebook wall has been viewed X times – viral survey scam spreads rapidly

  • Post author: Omid Farhang
  • Post published: April 4, 2011
  • Reading Time: 3 min
  • Word Count: 570 words

SophosLabs wrote: Do you want to know the total number of times that your Facebook wall has been viewed? Are you curious as to who may be stalking you on Facebook? If so, you’re a prime candidate for scammers who are exploiting that desire to put money into their own pockets. Here are the latest messages spreading virally between thousands of Facebook users who have fallen for the scam: ...

Continue Reading My Facebook wall has been viewed X times – viral survey scam spreads rapidly

Google, Yahoo, Skype targeted in attack linked to Iran

  • Post author: Omid Farhang
  • Post published: March 24, 2011
  • Reading Time: 4 min
  • Word Count: 832 words

Cnet: A malicious attacker that appears to be the Iranian government managed to obtain supposedly secure digital certificates that can be used to impersonate Google, Yahoo, Skype, and other major Web sites, the security company affected by the breach said today. Comodo, a Jersey City, N.J.-based firm that issues digital certificates, said the nine certificates were fraudulently obtained, including one for Microsoft’s Live.com, have already been revoked. A fraudulent certificate allows someone to impersonate the secure versions of those Web sites–the ones that are used when encrypted connections are enabled–in some circumstances. ...

Continue Reading Google, Yahoo, Skype targeted in attack linked to Iran

Spammers Exploit Japan’s Catastrophic State

  • Post author: Omid Farhang
  • Post published: March 14, 2011
  • Reading Time: 2 min
  • Word Count: 394 words

Symantec: Only a few days ago, Japan experienced one of the worst earthquakes in its history. The earthquake registered 8.9 on the Richter scale and triggered an enormous tsunami. The heart-wrenching images on television have left the world shaken. It was the worst earthquake and tsunami in the past century and at least 50 countries have since received related tsunami warnings. As the death and injury tolls continue to rise, one must not forget those who awake to exploit such delicate situations—spammers continue to maintain the guise of charitable institutions and governmental organizations! Don’t be surprised to suddenly see an email message in your inbox marked as URGENT and pleading with you for “monitory help” [sic] or a phishing mail urging you to donate to the rehabilitation of those affected by the quake and tsunami. Use prudence in finding out the genuine intent of email senders before you reach out or respond. ...

Continue Reading Spammers Exploit Japan’s Catastrophic State

Don’t Lie to Me, Angelina!

  • Post author: Omid Farhang
  • Post published: December 15, 2010
  • Reading Time: 2 min
  • Word Count: 376 words

Earlier this year I received a Facebook invite in my Yahoo! Mail account from none other than Angelina Jolie herself. I kid you not. While it’s true that we live in the Digital Age where communicating with anyone is a mere tap of a finger away—whether it’s via email, IM, Facebook, Twitter, etc.—the chances that Ms. Jolie would randomly reach out to a regular Joe, such as myself, is still pretty darn improbable. So, the following questions raced through my mind: ...

Continue Reading Don’t Lie to Me, Angelina!

Spam Carrying WikiLeaks Worm

  • Post author: Omid Farhang
  • Post published: December 7, 2010
  • Reading Time: 2 min
  • Word Count: 226 words

Symantec Connect: WikiLeaks.org is in the news after their recent publications linked to leaked government documents. Spammers are now leveraging the current level of interest with social engineering techniques to infect users’ computers. Symantec is observing a wave of spam spoofing WikiLeaks to lure users into becoming infected with a new threat. The spam email has subject line “IRAN Nuclear BOMB!” and spoofed headers. The “From” header purports to originate from WikiLeaks.org, although this is not in fact the case, and the message body contains a URL. This URL downloads and runs WikiLeaks.jar which has a downloader ‘WikiLeaks.class’ file. The downloader pulls the threat from http://ugo.file[removed].com/226.exe. Symantec detects this threat as W32.Spyrat. ...

Continue Reading Spam Carrying WikiLeaks Worm

Malicious Goo.gl Links Spreading on Twitter [WARNING]

  • Post author: Omid Farhang
  • Post published: December 7, 2010
  • Reading Time: 1 min
  • Word Count: 154 words

Mashable: A large number of messages containing only the link “goo.gl/R7f68” has appeared on Twitter today, redirecting the users to various malware-laden sites. The messages are mostly coming from disposable accounts, but they also appear on some accounts that appear to be genuine, which indicates that there’s a worm spreading and sending the messages from infected accounts. Furthermore, all of the messages containing the link are sent from the mobile version of Twitter. ...

Continue Reading Malicious Goo.gl Links Spreading on Twitter [WARNING]

This isn't a video, it's a phish

  • Post author: Omid Farhang
  • Post published: December 6, 2010
  • Reading Time: 1 min
  • Word Count: 74 words

You might be seeing something on your Facebook wall today: Sadly, it’s not a fun video. It’s just a phish. The link goes to apps. facebook.com/ lookatuhah, which then redirects to a phishing site: In other words, if you’re absent-minded enough to enter your credentials again, they will be used to then send more of these stupid fake videos posts to others — or do any of a number of other rather nefarious things. ...

Continue Reading This isn't a video, it's a phish

Oficla downloads MBR Ransomware

  • Post author: Omid Farhang
  • Post published: December 1, 2010
  • Reading Time: 1 min
  • Word Count: 198 words

Avira TechBlog: We discovered a new ransomware threat which is downloaded by a Trojan of the Oficla family. This downloaded threat replaces the MBR (master boot record) of the hard disk with its own MBR which asks the user for a password and thus blocks the loading of the operating system. Upon starting the Oficla Trojan and successive execution of the downloaded payload the system will be rebooted and the user will be presented the ransom notice. ...

Continue Reading Oficla downloads MBR Ransomware

Windows Vista & Windows 7 Kernel Bug Can Bypass UAC

  • Post author: Omid Farhang
  • Post published: November 30, 2010
  • Reading Time: 4 min
  • Word Count: 744 words

Now this is not the first time Windows UAC has hit the news for being flawed, back in February 2009 it was discovered that Windows 7 UAC Vulnerable – User Mode Program Can Disable User Access Control and after that in November 2009 it was demonstrated that Windows 7 UAC (User Access Control) Ineffective Against Malware. A zero-day for Windows 7 back in July of this year also bypassed Windows UAC. ...

Continue Reading Windows Vista & Windows 7 Kernel Bug Can Bypass UAC

Fake Trojan Removal Kit serves up ThinkPoint Rogue

  • Post author: Omid Farhang
  • Post published: November 30, 2010
  • Reading Time: 1 min
  • Word Count: 133 words

You might want to steer clear of the following fake security program, being promoted as a “Windows Trojan Removal Kit” but actually hijacking your PC in the form of the ThinkPoint rogue with a mixed (24/43) detection rate. The file is currently being offered up by your typical “fake security scan” pages, such as microsoftwindowssecurity152(dot)com. Those familiar with this particular rogue will be aware that it tends to stick with domains similar to the one above. ...

Continue Reading Fake Trojan Removal Kit serves up ThinkPoint Rogue