Archive for 2008

« Previous Entries

More Info on the Castlecops website

December 29th, 2008

Apparently Paul Laudanski, the owner, and main driving force behind the castlecops website has accepted a position at microsoft. We can put away our tin foil hats, Paul stated he simply would not be able to do run Castlecops *and* be in microsoft full time employ.

You can read about it in more detail here courtesy of geek.com

Jean “TinFoilHatMan” Taggart

  • Posted in Uncategorized
  • |
  • (0) comments
  • |
  • Add your comments

‘Tis the Season… for scams!

December 24th, 2008

Scammers are not getting any rest during the holiday season. As always be vigilant when you get an email that sounds too good to be true.

Below are some classic examples I received in my bait email account:

Love:

The “FBI”:

“Lucky winner”

Bill Gate [sic]

Approved Signature

 

Jerome

  • Posted in Malware Trends
  • |
  • (0) comments
  • |
  • Add your comments

Is it the end for Castlecops?

December 24th, 2008

One of the sites that I monitor on a daily, no hourly, basis is Castlecops. Castlecops is a volunteer based security site, where you can report phishing incidents, get help with hijackthis logs, and educate yourself on cybercrime, amongst other things. It has been under Ddos countless times, and is a thorn in many a web criminals side.

Looks like they have suspended activities. Bad guys are probably cheering and uncorking the champagne, while we observe a moment of silence in their memory.

We will monitor this situation closely, and I will try to get used to referring to them in the past tense.

Jean “TinFoilHatMan” Taggart

  • Posted in Uncategorized
  • |
  • (0) comments
  • |
  • Add your comments

VitalSecurity.org is back!!!!!

December 23rd, 2008

That looks like a great Christmas present: Paperghost is back on VitalSecurity.org!

It’s good to see you back Chris. We had missed your humor and insatiable thirst for a good pownage.

Jerome

  • Posted in Uncategorized
  • |
  • (0) comments
  • |
  • Add your comments

Maintenance… clean up… it’s Christmas

December 23rd, 2008

Well, the weather is quite miserable, snow keeps coming and there are less people in the office. Despite that, we’re still analyzing malware and such…
I’m doing some upgrades to my systems as well, trying the new Ubuntu 8.10. My version of 8.04 is getting messy and some apps are giving me trouble.

I’ve noticed it’s been quiet on the blogs… at least security blogs, since it’s pretty much all I read anyways.

I’m planning on making some more videos for the YouTube channel. If you have any special requests feel free to let us know.

Jerome

  • Posted in Uncategorized
  • |
  • (0) comments
  • |
  • Add your comments

Microsoft releases out-of-cycle patch for IE7 exploit

December 17th, 2008

The guys at Microsoft must have been working hard on pushing a patch for this nasty vulnerability.

Shortly after their monthly security updates they released a patch today supposed to fix the issue.

Malware authors were quick to jump on the bandwagon all the while this flaw was discovered. Apparently Chinese researchers had leaked the code for the exploit… by mistake. But, it seems the code was already known to hackers who were selling it for quite a bit of money on the underground markets.

All this confirms that browser-based attacks are the most common infection vector.

Jerome

  • Posted in Malware Trends
  • |
  • (0) comments
  • |
  • Add your comments

We’re snowed in… in Victoria!

December 17th, 2008

Yes, there is quite a bit of snow on the West Coast right now. The forecast is showing some more for the next days.

We’re not used to this here… so commuting is a bit of a pain…

But there’s a bit of fun too… for some old-school snowball fights (that’s me on the pic)

 

Jerome

  • Posted in Uncategorized
  • |
  • (0) comments
  • |
  • Add your comments

The porn trojan is no more

December 16th, 2008

Once there was a nasty Trojan Horse that I nicknamed the “Porn Trojan”. It earned this name because of the massive traffic to porn sites it was generating. I’m talking about gargantuesque downloads of entire adult websites… It ofen came with a bunch of exploits pushing various scareware programs.

Since ICANN shutdown ESTDomains, the servers are no longer there… so here it sits, trying to call home… :(

I captured a video at the time showing is payload.

Jerome

  • Posted in Uncategorized
  • |
  • (0) comments
  • |
  • Add your comments

Lost In Rogue’s Strange Ways…

December 12th, 2008

I’ve been on the hunt for the AntiVirus 360 rogue think everyone’s  talking about…

Well, getting the Trojan that installs it was relatively easy, but the rest was something else.

First off, this sample likes to play tricks with you… it ’sleeps’ for more than 6 minutes before actually doing something… So, if your sandbox only runs the sample for 2 minutes, you will get nothing out of this one.


 Moving on, this sample is actually quite nasty, reminding me of the days of DollarRevenue ahhh…

Check this great EULA: one button, and one only: Accept. Nice!

 And it seems to store more bad stuff on RapidShare… Unfortunately the file is gone already :(

Now, this pic does remind me of DollarRevenue… the classic Command infection… still there after all this time!

Time to proceed to the checkout:

 

No thanks! :-)

Jerome Segura

  • Posted in Rogue software
  • |
  • (0) comments
  • |
  • Add your comments

Offline RSS feeds viewer for the PSP

December 11th, 2008

As some of you may know, I won Sunbelt’s prize at VB 2008, a red PSP.

Well, I’m not a huge gamer, so I decided to turn it into something useful ;-)

There is a RSS feed functionality within the PSP but it has drawbacks:

- incompatible with some blogs
- requires internet connection

So I wrote a script to download my favourite feeds for offline browsing. Then I built a simple html page to link all the blogs together and voila!

P.S. you will notice that most of my RSS feeds are security related… go figure…

Update!

If you want to read your favourite blogs offline, and you happen to have a PSP then this is for you:

Note that this script will only run under Linux (I tested it with Ubuntu 8.10).

What you need to do is:

1. create a folder on your desktop called Blogs.

2. Create a new file and name it rss_info. That file must be under ~/Desktop/Blogs
this file contains: the name of the blog (no space), the URL or XML for RSS2 feeds, 1 or 2
1 stands for regular full page scrape.
2 stands for RSS2 indivudal scrape of each posts for that blog.
This is a comma separated file too.

Sophos,http://feeds.sophos.com/en/rss2_0-sophos-sophoslabs-blog.xml,2
FrenchMAD,http://mad.internetpol.fr/feeds/index.rss2,2
Sunbelt,http://sunbeltblog.blogspot.com,1
CA,http://community.ca.com/blogs/securityadvisor,1
ESET,http://www.eset.com/threat-center/blog,1
StopBadware,http://blog.stopbadware.org,1
Microsoft,http://blogs.technet.com/mmpc,1
VitalSecurity,http://www.vitalsecurity.org,1
ThreatFire,http://blog.threatfire.com,1
TrendMicro,http://blog.trendmicro.com,1
McAfee,http://www.avertlabs.com/research/blog,1
FSecure,http://www.f-secure.com/weblog,1

3. Run the script

4. Copy the Blogs folder onto your PSP under PSP/COMMON/

5. In your PSP, launch the Internet browser (under Network). You do not need an internet connection.

6. Type the address to the blog (address entry): file///PSP/COMMON/Blogs/index.html

add

7. Set it as a bookmark, or homepage so you don’t have to type the address every time.

That’s about it. New features may come in the future.

 

Jerome Segura

  • Posted in Malware Trends
  • |
  • (0) comments
  • |
  • Add your comments

« Previous Entries



Location

You are currently browsing the Malware Diaries weblog archives for the year 2008.




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (33)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (15)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (109)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.