| 

Faceparty password sites really want you to click on things

  • Post author: Omid Farhang
  • Post published: April 14, 2010
  • Reading Time: 3 min
  • Word Count: 523 words

ā€œFaceparty is a UK based social networking site allowing users to create online profiles and interact with each other using forums and messaging facilities similar to emailā€ ā€“ Wikipedia Faceparty does things a little differently to other social networking sites, however. Unlike most places where you register a username and password then start telling people how your farm is doing, to join Faceparty you need to send a text message to the tune of Ā£25 / $38(!) and then enter your one time use password onto this page (warning: quite a few swearwords, because the site is indeed down with the kids). ...

Continue Reading Faceparty password sites really want you to click on things

German spammers broaden their repertoire

  • Post author: Omid Farhang
  • Post published: April 14, 2010
  • Reading Time: 2 min
  • Word Count: 361 words

Last week we received a mass mailing that at first glance appeared no different from the usual mailbox clutter. The messages were in German and advertised an online casino. Nothing out of the ordinary there ā€“ after all, gambling-themed spam is one of the most popular in the German-speaking realms of cyberspace. But after a closer inspection, these messages turned out to be of much more interest ā€“ all the links in the messages led to pages created on legitimate sites that had been compromised. The links looked like this: **\*.com/news_.php or *****.com/1500.php. ...

Continue Reading German spammers broaden their repertoire

There is a Lot of Spam Out Thereā€¦

  • Post author: Omid Farhang
  • Post published: April 10, 2010
  • Reading Time: 3 min
  • Word Count: 511 words

ā€¦and some of it masquerades as ā€œmarketingā€ and ā€œnewsletterā€ emails. In March 2010, spam continued to account for a high percentage of all email traffic, peaking at 93.6% of all messages. The majority of this spam email was sent using certain tactics that were deployed to hijack unsecured computers and hide the sendersā€™ identity. Recently, however, there has been an uptick in spam ā€œmarketingā€ and ā€œnewsletterā€ emails. These spam marketing and newsletter emails share one significant commonality with ā€œregularā€ spam emails, which is that they are unwanted email messages sent to individuals who have no formal relationship with the message sender. ...

Continue Reading There is a Lot of Spam Out Thereā€¦

Singer's Exploit Kit version CVE-2010-0806

  • Post author: Omid Farhang
  • Post published: April 9, 2010
  • Reading Time: 1 min
  • Word Count: 135 words

Well, wellā€¦ looks like someone has been singing along to one of Jay Chowā€™s songs while coding an exploit that corresponds to a vulnerability in Internet Explorer, which was addressed in Microsoft Security Bulletin MS10-018. The exploit that targets on the Peer Object component (iepeers.dll) in IE has been found in the wild, and today it was detected while attempting to exploit on the client browser. After decoding from a shellcode, it will download the payload and will be detected as Trojan:W32/KillAV.LD. ...

Continue Reading Singer's Exploit Kit version CVE-2010-0806

Trojanised Mobile Phone Game Makes Expensive Phone Calls

  • Post author: Omid Farhang
  • Post published: April 9, 2010
  • Reading Time: 1 min
  • Word Count: 157 words

We have received reports of a malicious Windows Mobile game that creates significant phone bills to affected users. The game in question is called 3D Anti-terrorist action, and itā€™s manufactured by Beijing Huike Technology in China. The game itself is a 3D first-person shooter. Apparently some Russian malware author took the game and trojanized it. Then he uploaded the trojanized version to several Windows Mobile freeware download sites. ...

Continue Reading Trojanised Mobile Phone Game Makes Expensive Phone Calls

Benign Feature, Malicious Use

  • Post author: Omid Farhang
  • Post published: April 9, 2010
  • Reading Time: 2 min
  • Word Count: 227 words

An interesting and unknown feature used by sysadmins around the world in some large corporate networks is the use of proxy-auto config (pac) files. This benign feature is accepted by all modern browsers and is described in detail here. It contains a function to redirect your connection to a specific proxy server. Unfortunately this simple and smart proxy technique are being largely used by brazilian malware writers to redirect infected users to malicious hosts serving phishing pages of financial institutions. A .pac script URL is configured in the browser, in the field ā€œUse automatic configuration scriptā€: ...

Continue Reading Benign Feature, Malicious Use

The mobile game with a Trojan thrown in for free

  • Post author: Omid Farhang
  • Post published: April 9, 2010
  • Reading Time: 2 min
  • Word Count: 280 words

TSince 27 March a new game called 3D Antiterrorist has been cropping up on quite a few international freeware sites offering downloads for Windows Mobile smartphones. As well as the game itself, the 1.5 MB archive contains the file reg.exe which is actually a Trojan that calls premium rate international numbers and leaves smartphone owners significantly out of pocket. As of 8 April this malicious program has been detected by Kaspersky Lab as Trojan.WinCE.Terdial.a. Letā€™s take a closer look at what happens. ...

Continue Reading The mobile game with a Trojan thrown in for free

Google has just rewarded me with $1 million!!

  • Post author: Omid Farhang
  • Post published: April 9, 2010
  • Reading Time: 3 min
  • Word Count: 430 words

I donā€™t believe it!! This morning Iā€™ve received an email sent by Google notifying me that IĀ“ve won $950,000,Ā so I think this will be the last post Iā€™m going to write šŸ˜‰ Well, I havenā€™t taken part in any promotion of this kind and Iā€™ve never heard that Google gives prizes just like that, but I can consider it as if I won the lottery. Here you have the content of the message: ...

Continue Reading Google has just rewarded me with $1 million!!

iPad Spam has entered the building

  • Post author: Omid Farhang
  • Post published: April 8, 2010
  • Reading Time: 1 min
  • Word Count: 135 words

It was only a matter of time before the merest of ā€œiPadā€ mentions on sites such as Twitter would result in autospammed messages like this: These bots will fire a message claiming ā€œwe need someone to test and keep one iPadā€ (or simply ā€œFree iPad hereā€) to anyone discussing the latest gadget to hit the streets, sending you to various promotional sites like the one below: ...

Continue Reading iPad Spam has entered the building

FakeAV Gang Targets Farmville ā€“ #1 Facebook Game

  • Post author: Omid Farhang
  • Post published: April 7, 2010
  • Reading Time: 1 min
  • Word Count: 183 words

Farmville has been launch in June 2009 and after month it has been rated at #8 in Top 25 Facebook Games. Farmville has become the most popular games on Facebook. It has been rank at #1 Facebook Game on August 2009 up until now. Farmville users canā€™t get enough of farming. They make impressive hay bales art farm just like the Image below. Fake AV gang launches its attack to the Farmville users by poisoning Yahoo and Google search results using the following keywords (see Image 1): ...

Continue Reading FakeAV Gang Targets Farmville ā€“ #1 Facebook Game