Phishing

Brittany Murphy SEO

Published: December 21, 2009 Reading time: 1 min

Just a quick note – the sudden death of Hollywood celebrity Brittany Murphy last Sunday (BBC report here) has prompted a spike in searches on the subject – and of course, an SEO attack. Users who click on a poisoned search result link will be redirected to a website that will display a scare message trying to panic users into downloading rogue AV software: Screenshots of the rogue AV: ...

Continue Reading

ProtectPCs

Published: December 21, 2009 Reading time: 1 min

ProtectPC’s is a nasty rogue antivirus program, or phony security software, used to scam people out of their money. If your PC is infected with ProtectPC’s you should remove it immediately. ProtecPC’s poses a serious security risk for all PC users. Symptoms of a ProtecPC infection can include: Web Browser redirecting spontaneously System scans that result in reports showing multiple infections Pop-Ups and system alerts stating the PC is infected Programs being shut down or unable to open Click Here to learn how to remove these kind of malware.

Continue Reading

Malware Defense

Published: December 21, 2009 Reading time: 1 min

Malware Defense is a rogue security program, designed to look like legitimate security software. If Malware Defense has been installed on your PC more than likely you did not intentionally download it, it just appeared one day. Malware Defense usually infects a computer system with help from malicious advertising or a trojan found on a shady website. Malware Defense usually infects unsuspecting users PC’s without permission. Malware Defense is a scam, do not buy this software, it should be removed from infected computers immediately. ...

Continue Reading

There's No Such Thing as a Free Movie

Published: December 19, 2009 Reading time: 2 min

Those looking to see the latest 3D blockbuster movie, The Avatar, on the cheap will have to take great care in what they search for. We have become aware of at least one site that has been rigged to redirect users to a page that presents the now-familiar “play video/need codec” screen. In an unusual twist, this time it is offering a new ActiveX update rather than the usual codec or Flash player updates. ...

Continue Reading

Data Doctor 2010 will make you sick

Published: December 19, 2009 Reading time: 1 min

Data Doctor 2010, an encryption trojan via our old “friends” iframedollars. It encrypts the files on your hard drive very rapidly if you’re unfortunate enough to be victimized by it. It arrives through drive by downloads from malicious web sites. It’s also packaged with other malware. The victim receives a message that the system is shutting down due to “Unrecognized disk driver command.” His system is then re-booted to safe mode and a message is displayed: “Windows has recovered from a serious error. Some files can be corrupted. Disk checking is strongly recommended.” ...

Continue Reading

The most phished brands of 2009

Published: December 19, 2009 Reading time: 1 min

Almost the entire year 2009, the battle for the first place on phishing targets took place between Ebay and Chase Bank. Most of the time, the Chase Bank was on top of the most phished brands. In December, the situation was changed: Now PayPal is the most phished brand (32205 unique URLs) followed from far away by the Chase Bank (25901 unique URLs) and Ebay (18738 unique URLs). ...

Continue Reading

Microsoft privacy portal a target of rogue security software

Published: December 19, 2009 Reading time: 2 min

Earlier in 2009, the Microsoft privacy homepage became the target of rogue security software developers looking to make a fast buck. The developers of the rogue security application known as “Privacy Center” even went so far as to include a link to Microsoft to trick users into thinking the rogue is a Microsoft product. Trojan:Win32/PrivacyCenter is a family of programs that claims to scan for malware and displays fake warnings of “malicious programs and viruses”. They then inform the user that they need to pay money to register the software in order to remove these non-existent threats. ...

Continue Reading

Spam for the visually impaired

Published: December 17, 2009 Reading time: 2 min

Starting at ~3:20pm GMT today, Canadian Pharmacy spammers began using attached MP3 files as the call-to-action for their latest campaign. The message had no subject, no “text” body content, just an attached “audio/mpeg” file with a random lower case file name. Upon playing the attached mp3 file, you find out why I called it the “call-to-action”. A robotic sounding woman’s voice reads off the URL they would like recipients to browse to (letter by letter), with porn-like moaning as background noise. I guess they are going for the often used spam tactic of tying ED pills (Viagra, Cialis, etc..) to porn star-like performance in bed. ...

Continue Reading

Who’s the quickest? Only one way to find out…

Published: December 17, 2009 Reading time: 1 min

Earlier on this morning I happened to notice a redirect page used in a meds spam campaign that just happened to also be compromised with a malicious script. You can see the META tag redirect that will instruct the browser to immediately load the page on the target site. And immediately below, it, the obfuscated JavaScript injected into the page. Deobfuscating this script, we can see its payload is also redirection, this time to a malware site. ...

Continue Reading

Merry Christmas, Idiot

Published: December 17, 2009 Reading time: 1 min

It’s not a huge surprise that we are seeing some malware spam runs where the malicious attachment attempts to portray itself as a Christmas Greeting of some sort. Here’s an example from today (md5: C670165AE6DFA8318F0EA795B1D3AD55). This one is actually a Zapchast (IRC bot variant). The “Christmas Card” requires it’s own “special version” of Flash to be installed — flashplayer2009.exe — which is the malware itself. Once ready, it will display this friendly message written in Universal Gibberish. ...

Continue Reading

10 million people will you computers are perfectly safe

Published: December 15, 2009 Reading time: 1 min

New rogue borrows massively from AV company sites Our friend M.N. Bharath drew our attention to this web site associated with the new System Adware Scanner 2010 rogue security product. Although the group claims 10 million users world-wide, oddly enough their site was only registered Nov. 25. It seems they also have recruited the entire management team from AVG anti-virus company as well. Right! Compare the names on the Smart Systems Technologies rogue page. http://sysadscanner.com/about.php ...

Continue Reading

Dangerous web searches

Published: December 15, 2009 Reading time: 1 min

Don’t go there. There are a lot of rogue downloaders hiding in those links. Yahoo CEO Carol Bartz, speaking at the UBS Media and Communications Conference in New York, said the Tiger Woods sex scandal was a better traffic generator than the death of Michael Jackson, according to the ZDNet blog.

Continue Reading

“OH” “OH” “OH”, Santa Delivering FakeAV Presents

Published: December 14, 2009 Reading time: 1 min

Following on from the latest Captcha techniques used by the W32/Koobface worm, it seems that the malware authors have turned to Santa for help to deliver it’s nasty surprise which awaits Facebook users. The infection drops other trojans such as FakeAlert and leaves the user renderless. It all begins with a post on a user’s Facebook Wall. If the user clicks on the link, they are presented with a fake video player with a Christmas greeting as shown below ...

Continue Reading

Tiger still hot stuff

Published: December 14, 2009 Reading time: 1 min

Despite talk of Tiger Woods’ sponsors “limiting his role” in their advertising campaigns, he is still very much hot stuff when it comes to search engine queries which means he’s still a viable target for the malware writers. We can see that Tiger Woods related searches are still being poisoned with malicious results using Search Engine Optimisation techiques: This leads to the familiar: Which when downloaded installs fake AV branded as “Security Tool”. ...

Continue Reading

Rebranded rogue claims to be McAfee Secure certified

Published: December 11, 2009 Reading time: 1 min

Internet Security 2010, It’s a rebranded clone of Advanced Virus Remover, a rogue security product. It’s one of your run-of-the mill rogues, using run-of-the mill scare tactics, except its payment screen contains a static graphic that imitates the McAfee Secure certification. A real “McAfee Secure” certification is a DAILY certification, it contains the date and its logo should look like this: When you click on it, it should take you to the McAfee Secure rating verification page: https://www.mcafeesecure.com/RatingVerify that gives the name of the certified web site and the “Status”. ...

Continue Reading

Search