Amazon

Monday, 16 July 2007

Phishers go Green!

It's nice to know that even the phishers care about saving the planet, I mean it looks legit:




















... well, apart from hsbc.co.uk with a .hk domain ending:

Thursday, 5 July 2007

Digg Post

Here's a post on Digg from a user, for a bit of useful sounding software:















When you click on the link, you are taken to a download site:















Scanning the download file:













So, is this just a false positive or a different way of getting malware out to the world ??

PayPal phish using a word document

Here's a phish that came in from PayPal which contained a word document.

As the email used an image for the main text body and a word document, the phisher no doubt thought it would bypass filters.

Here's the main email:















Here's the content of the word document:















Tuesday, 26 June 2007

stock spam evolve: new syle pdfs

Spammers have now come up with a new style of stock emails.

First they used just plain text, next they used static image files. Next, they used random image files, all to avoid filtering.

Due to people starting to use FuzzyOcr, the stock spammers, moved into pdfs.

The pdfs contained plain text, which again using the right tools can be filtered.

This morning, the "next generation" appeared; pdf's with random images embedded in the pdf :(

Firstly, here's the email you receive:















Pdf example 1:















Pdf example 2:















Interestingly, both pdfs would not open in a couple of the free pdf readers but they seem to open fine in Adobe Pdf reader.

Initial detection of this varient has been added as: Email.Stk.Gen538.Sanesecurity.07062600.pdf

Update (12:45): more new varients using random pdf filenames now!

Pdf example 3:














Pdf example 4:














Pdf example 5:

Monday, 18 June 2007

Greeting Card: fun.exe

ISC has an interesting article on an Attack involving .hk domains

So, perhaps this is a related attack.

It starts with a greeting card:
















If you've not got Javascript enabled, you'll see this screen, where the file it wan't you do download is on a .hk server and the exe is called fun.exe:






Looking deeper at the code, it's doing something iffy:








If you do click on the link, you are served an exe file, which when submitted to VirusTotal gives you this result:













Again, coverage not too hot :(

Currently detected as: Email.Malware.Sanesecurity.07061701