... well, apart from hsbc.co.uk with a .hk domain ending:
A hopefully interesting blog from the world of zero hour malware, phishing, scams and spams
Amazon
Monday, 16 July 2007
Phishers go Green!
It's nice to know that even the phishers care about saving the planet, I mean it looks legit:

... well, apart from hsbc.co.uk with a .hk domain ending:
... well, apart from hsbc.co.uk with a .hk domain ending:
Thursday, 5 July 2007
Digg Post
PayPal phish using a word document
Tuesday, 26 June 2007
stock spam evolve: new syle pdfs
Spammers have now come up with a new style of stock emails.
First they used just plain text, next they used static image files. Next, they used random image files, all to avoid filtering.
Due to people starting to use FuzzyOcr, the stock spammers, moved into pdfs.
The pdfs contained plain text, which again using the right tools can be filtered.
This morning, the "next generation" appeared; pdf's with random images embedded in the pdf :(
Firstly, here's the email you receive:

Pdf example 1:

Pdf example 2:

Interestingly, both pdfs would not open in a couple of the free pdf readers but they seem to open fine in Adobe Pdf reader.
Initial detection of this varient has been added as: Email.Stk.Gen538.Sanesecurity.07062600.pdf
Update (12:45): more new varients using random pdf filenames now!
Pdf example 3:

Pdf example 4:

Pdf example 5:
First they used just plain text, next they used static image files. Next, they used random image files, all to avoid filtering.
Due to people starting to use FuzzyOcr, the stock spammers, moved into pdfs.
The pdfs contained plain text, which again using the right tools can be filtered.
This morning, the "next generation" appeared; pdf's with random images embedded in the pdf :(
Firstly, here's the email you receive:
Pdf example 1:
Pdf example 2:
Interestingly, both pdfs would not open in a couple of the free pdf readers but they seem to open fine in Adobe Pdf reader.
Initial detection of this varient has been added as: Email.Stk.Gen538.Sanesecurity.07062600.pdf
Update (12:45): more new varients using random pdf filenames now!
Pdf example 3:
Pdf example 4:
Pdf example 5:
Monday, 18 June 2007
Greeting Card: fun.exe
ISC has an interesting article on an Attack involving .hk domains
So, perhaps this is a related attack.
It starts with a greeting card:

If you've not got Javascript enabled, you'll see this screen, where the file it wan't you do download is on a .hk server and the exe is called fun.exe:

Looking deeper at the code, it's doing something iffy:

If you do click on the link, you are served an exe file, which when submitted to VirusTotal gives you this result:

Again, coverage not too hot :(
Currently detected as: Email.Malware.Sanesecurity.07061701
So, perhaps this is a related attack.
It starts with a greeting card:
If you've not got Javascript enabled, you'll see this screen, where the file it wan't you do download is on a .hk server and the exe is called fun.exe:
Looking deeper at the code, it's doing something iffy:
If you do click on the link, you are served an exe file, which when submitted to VirusTotal gives you this result:
Again, coverage not too hot :(
Currently detected as: Email.Malware.Sanesecurity.07061701
Subscribe to:
Posts (Atom)