Amazon

Wednesday, 13 August 2008

MSNBC StormNews Spam

Following on from the CNN virus spam we all know and love...looks like the spammers have got bored with CNN and moved onto MSNBC:




















... but the MSNBC landing page... erm... still shows the CNN logo... ooops:















Exe file info: VirusTotal and ThreatExpert

However, we do now have popups for some free rogue anti-virus scanning software:
















Needless to say, don't even try to download this!

Detection added as: Email.Malware.Sanesecurity.08081300.StormNews.MSNBC

Friday, 8 August 2008

New Fake CNN email

Looks like a new round of CNN News emails are coming in:















Here's the fake landing page:












Virus Total Report

Detection added as: Email.Malware.Sanesecurity.08080800.StormNews.Cnn

Note: if you are using Firefox and the Noscript plugin, won't see the above page

Tuesday, 5 August 2008

0 hour UPS Invoice

There was another spam run of the fake UPS invoice yesterday, this time with a different version of the malware, in the zip attachment:








What was interesting, was that the signatures I'd added to catch the last one, detected the new varient too:









As you can see from the above stats graph, Email_Malware_Sanesecurity_08072227
(in yellow) was being blocked from around 5.30pm to 7pm. ClamAV started detecting the attched file at 7pm (Trojan_Zbot_1737).

What does the exe file do? (contained in the zip)... well, here's what ThreatExpert said

Thursday, 3 July 2008

ClamAV Third-Party Signature names

Just a heads up really, that the next version of ClamAV will automatically add an ".UNOFFICIAL" suffix to ALL 3rd party signatures.

Example 1:

Email.Phishing.Bank.Gen2559.Sanesecurity.08070201 would become Email.Phishing.Bank.Gen2559.Sanesecurity.08070201.UNOFFICIAL

Example 2:

MSRBL-SPAM.Feed.Blaster.2759 would become
MSRBL-SPAM.Feed.Blaster.2759.UNOFFICIAL