Billps Tudios

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label storm. Show all posts
Showing posts with label storm. Show all posts

Wednesday, 6 February 2008

Beware the Valentines Day Storm

Posted on 08:26 by Unknown

No, I’m not talking about your spouses reaction if you forget a gift on Thursday, February 14th. Like many past holidays the well known “Storm” Trojan is using the upcoming theme of love to trick users into clicking on malicious sites.

Typical Email subject lines that I’ve already looked into include:
  • Our Love is Free
  • Happy Valentines day
  • I Would Dream
  • Hugging My Pillow
  • Inside My Heart
  • Sending You My Love
  • The Dance of Love
  • Eternal Love
  • A Rose for my Love
You get the idea right? As always, I recommend against clicking on links you’ve received in E-mails. It’s also important that you download new Windows security updates in a timely manner. Most Trojans like Storm depend on security holes which haven’t yet been patched.

Just to be sure it’s clear, this kind of Trojan is a bad thing.
Many of you may think of a Trojan as something that protects you against disease and untimely new family members. A computer Trojan is analogous to the legend of the large wooden horse used by the Trojan army to conquer the city of Troy.


Read More
Posted in SPAM, storm, Trojan, Valentine | No comments

Saturday, 29 December 2007

Winter.exe comes in like a Lion

Posted on 12:39 by Unknown

Earlier this month I started to see an increase in requests for a file name Winter.exe. I didn't have a good feeling about this filename and our follow up research proved I was correct. Our friend Temerc has a good write up on this infiltration at his forum, Temerc Internet Countermeasures. The other exe’s that appear to be included are infos.exe, autos.exe and a few randomly created filename. Fortunately, they all show up in WinPatrols’ startup programs list. The filename bronto.dll showed up in our IE Helpers list.


Google has done a good job at making it easy for people to create Blogs, but in many ways, it’s too easy. A huge number of Google Blogspot, blogs are being created and have become host sites for this file and other malicious programs. I wrote earlier his month that Spamhaus was blocking any Email which included a Google blog in the content of the message. This was a dramatic step but has proved to be necessary.


Trend Micro is referring to these blog traps as “Poisonous Blogs”. There are a number of ways you might get to these blogs including…

  • A link to the Blog is included in a teaser Email.
    (Typically, it’s a greeting card, free product, drug or naked celebrity. This week we’ve frequently seen what claims to be video of Bhutto’s assassination)

  • The blog might show up in a typical Google search.
    (These sites are too new to be validated by programs like SiteAdvisor)

  • You click on the “Next” button on a Blogspot site.
    (This feature is disabled on Bits from Bill)

Our friends at SunbeltBlog have also written about this topic and show how easy it can be to run across these blog traps. Alex at Sunbelt provided some good screen shots and stresses how video “codec” scams are frequently used as an malware entry point.

If you see a message that says “You need to download new version of Video ActiveX Object to play this video file”, run away! Don't press cancel or even trust the red close box in the corner. Press Ctrl-Alt-Del and look at your list of processes. Select your browser( iexplore.exe or firefox.exe) and click on End Process.

Read More
Posted in Blogspot, codec, Google, storm, Winter | No comments

Thursday, 27 September 2007

Biggest Security Hole Continues to be People

Posted on 14:31 by Unknown

In the old days the easiest way to access a computer system was to go directly through a human. It wasn’t always done through the use of wargames dialer which dialed up phone numbers in search of computers with modems. Most time it was as easy as calling a secretary at the computer center and saying…

“Hi, this is Fred from IBM. We found a problem with the computer system and it appears most of your data has disappeared. I’m not sure if you’re responsible but we need your account and password to fix this problem.”

It may sound silly but it worked and the same methods are used today. They’re just a little more sophisticated.

When the storm Trojan was first detected I didn’t give it a lot of consideration. I even suggested that everyone was over reacting.

“Are attachments like this still getting through Email filters? Are people downloading attachments with names like, video.exe, full video.exe, Read More.exe, Full Text.exe or Full Clip.exe to see new stories? I say no. At least not to the extent deserving of this weekends attention.”

I’m willing to admit my evaluation at the time may have been shortsighted. When the attack is this large, it doesn’t take a huge percentage of victims for a problem to become serious.

It’s not as difficult as you might think to get folks to fall prey to a socially engineered attack. I’m sure a large number of intelligent people believed it when “Your family member has sent you an eCard” arrived in their Email.

The most effective attacks I’ve been tracing try to scare readers into taking an action when they think they’ve already had their account or machine compromised.

The following are other examples I’ve seen regularly in my Email. What would you do if you thought someone had purchased a new Dell computer using your PayPal account?


Paypah phish says you've purchased a Dell computer


And how bad would you feel if someone gave you a bad recommendation on eBay?


Phishing Email threatens your eBay reputation


I have a pretty good imagination and it didn’t take me long to think of other examples on my own. Here’s one that targets users in the U.S and I’m guessing it would trick a number of folks into granting full access even pass their firewall.


Example of how easy it could be to trick people into downloading new malware


Obviously, user education will never be 100% effective but don’t panic. A lot of folks like myself will continue to spend time coming up with new ideas on how to reduce and/or prevent damages.

In case you are interested, you really can receive Amber alerts on your computer or mobile device by signing up at http://www.amberalert.gov/



Read More
Posted in amber alert, phishing, SPAM, storm, tricks | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • Support for Downloads without Surprises
    Last week I posted a message about the  packaging of ad supported programs along with popular software. It appears to be a common practice t...
  • Employee Manual to Prevent Cryptolocker and More
    A common way computers are infected or compromised has always been a simple yet well thought out deception. It can happen to anyone and the ...
  • What on Earth is “Cloud” Computing
    The new big buzz word in the computing world is “Cloud” computing. In the past I’ve been critical of the concept and even poked fun at Cloud...
  • SQLite C Code to Read Cookies
    While most of the technology leaking from my brain is for a wide audience, today’s post is very technical in nature. I expected the informat...
  • WinPatrol Cloud Edition Public Beta
    WinPatrol Adds the Newest Technology Available. You’ll now have access the knowledge of thousands of WinPatrol users shared in real-tim...
  • Four Secret Reasons Why Win7 is Ten Times Better
    It’s no secret that I’ve never been a fan of Windows Vista. I really wanted to love it but even as a designated Microsoft MVP I couldn’t dri...
  • Free #1 Tweak to Improve Windows Performance
    Every year billions of dollars are spent by folks just trying to improve the performance of their computers. Over the last couple years ther...
  • Forget the DVD & Save on your New Laptop
    I’ve written before about the coming death of the CD/DVD ’s for data storage.  While that time hasn’t come yet for desktop there is one real...
  • Can Facebook be Trusted?
    Last week Facebook rolled out another round of what they consider easy to use privacy settings. What they’re really doing is trying to appea...
  • TWITTER ALERT
    Anyone who uses Twitter, DO NOT use the Twitter web interface until further notice. There is a code injection vulnerability being used tha...

Categories

  • 2007
  • 3G
  • AAPL
  • ABC
  • accelerometer
  • Achilles
  • Acrobat
  • Activex
  • adobe
  • Ads
  • advertising
  • Adware
  • Adwords
  • Airlines
  • Albany Medical Center
  • algorithm
  • Amazon
  • amber alert
  • AMUST
  • Animation
  • antimalware
  • Antivirus 2009
  • antivirus2008
  • AOL
  • Apple
  • applets
  • AQuantive
  • archive
  • Aruba
  • ASC
  • Ask.com
  • ATI
  • Audio
  • Autorun
  • AutoUpdate
  • autoupdates
  • AVG
  • Azure
  • backup
  • badware
  • Bakugan
  • Baseball
  • battery
  • Ben Edelman
  • Beta
  • BillP
  • Birthdayware
  • Bitlocker
  • Blackberry
  • BlackViper
  • bloatware
  • Blogger
  • Blogs
  • Blogspot
  • Blu-ray
  • Bluehoo
  • bluetooth
  • boinc
  • Bonjour
  • Brazil
  • break
  • Breakaway games
  • Brookman
  • Browser wars
  • C64
  • camera
  • Carpal Tunnel
  • CBS News
  • cell phone
  • CES
  • charity
  • Child Safety
  • chinese
  • Chris Cook
  • Christmas
  • Chrome
  • CIPAV
  • clampi
  • Cloud
  • CNet
  • codec
  • comodo
  • conficker
  • Control Panel
  • copy
  • coupon
  • craplets
  • crapware
  • Crawford
  • credit
  • credit card
  • credit cards
  • ctfmon
  • daylight savings time
  • Dell
  • demo
  • Discount
  • Disney
  • DNS
  • Dollar
  • Domain
  • Donna
  • Doubleclick
  • Downadup
  • Dreamscene
  • droid
  • DVD
  • Dvorak
  • Easter egg
  • eclipse
  • Ed Bott
  • Edelman
  • egreeting
  • Email
  • Environment
  • Epilepsy
  • EU
  • eWeek
  • explorer
  • facebook
  • false positive
  • false-positive
  • FBI
  • file types
  • finnish
  • FiOS
  • Firefox
  • fireworks
  • fix
  • flash
  • Flashpix
  • Fort Drum
  • foxit
  • fraud
  • FTC
  • games
  • garmin
  • Gateway
  • GE
  • George Bush
  • Germany
  • global
  • Godmode
  • Google
  • Google Research
  • GotoMyPC
  • gps
  • green
  • Groceries
  • Habitat
  • Hacks
  • hallmark
  • Halo
  • hard drive
  • Harry McCracken
  • Harry Potter
  • Harvard
  • HD-DVD
  • help
  • hidden files
  • Hijack
  • History
  • Hiton
  • homeland security
  • Honor Flight
  • hosts
  • Hubble
  • IAC
  • ICANN
  • IE
  • IE6
  • IE7
  • IE8
  • installers
  • interface
  • Internet
  • IPAddress
  • iPhone
  • iPod
  • Iraq
  • iTouch
  • iTunes
  • java
  • Kaspersky
  • Kazaa
  • kenmore
  • key logger
  • keygen
  • Keylogger
  • Kosovo
  • LA
  • lady chalupa
  • langa
  • Laptop
  • lawsuit
  • Legoland
  • Levar Burton
  • Linksys
  • Little League
  • Live Writer
  • Live.com
  • localize
  • Logo
  • London
  • LOP
  • lottery
  • Lucasfilm
  • Macintosh
  • Malware
  • Marie Domingo
  • Mary
  • McCracken
  • Media
  • Memorial Day
  • mgrs.exe
  • Micosoft
  • Microsoft
  • Microsoft Surface
  • MiFi
  • mit
  • moon
  • Mossberg
  • Mothers Day
  • MPack
  • MSFT
  • msn
  • MTV
  • Multicore
  • Music
  • MVP
  • MVP09
  • nasa
  • NBC
  • Nero
  • Netbook
  • Network
  • network solution
  • New York
  • newsletter
  • Nintendo
  • Nintendo Wii
  • NNEDV
  • Norton
  • NYAG
  • OAuth
  • obama
  • Office
  • OLPC
  • Olympics
  • OpenDNS
  • oprah
  • optimize
  • optout
  • Paperghost
  • passwords
  • Patch
  • Patriot Flight
  • PC Guy
  • pc pitstop
  • PC World
  • pcmag
  • PCWorld
  • PDC
  • PDF
  • pedipaws
  • performance
  • phishing
  • photos
  • Photoshop
  • Pinnacle
  • Piracy
  • Pirillo
  • pogue
  • Porn
  • pornware
  • postcard
  • prediction
  • prefetch
  • Preview
  • Price
  • privacy
  • Prodigy
  • Programming
  • PSP
  • Public Relations
  • Pytlovany
  • Q-Link
  • Quicktime
  • quotes
  • radio
  • realnetworks
  • realplayer
  • RegCleaner
  • RegCure
  • regedit
  • Registry
  • registry cleaner
  • Release
  • remove
  • Research
  • return policy
  • review
  • RIAA
  • Rivera
  • RMS
  • Road Runner
  • rogue
  • router
  • RTM
  • Rumor
  • safari
  • safety
  • sale
  • Sales
  • Santa Monica
  • scam
  • Schenectady
  • Scoble
  • Scott Dunn
  • Scotty
  • sd
  • Search
  • Sears
  • Security
  • Services
  • seti
  • ShellExecute
  • Shirt
  • SimCity
  • site advisor
  • slingbox
  • snopes
  • social engineering
  • social network
  • solid state disk
  • Sounds
  • Sp3
  • space station
  • SPAM
  • spamhaus
  • Special
  • speedtest
  • Spyware
  • SSD
  • Startup
  • Stats
  • Steve Bass
  • stopbadware
  • storm
  • STS-125
  • Sugar
  • Sunbelt
  • support
  • Symantec
  • tagged
  • Task Catcher
  • Task Scheduler
  • taskbar
  • Tax
  • Techorati
  • techwatch
  • teens
  • temp
  • Thinkpad
  • Thurrott
  • tinyurl
  • Tips
  • TiVo
  • TLD
  • Today Show
  • Toolbar
  • toolbars
  • top ten
  • topten
  • toys
  • Translator
  • transunion
  • Tree
  • Trend Micro
  • tricks
  • trillian
  • Trojan
  • tweaks
  • twitter
  • UAC
  • UI
  • Ultimate
  • Unbox
  • Unboxed
  • update
  • Updates
  • upgrade
  • url
  • USB
  • Utility
  • Valentine
  • Verizon
  • versions
  • Veteran
  • Video Games
  • Vista
  • Vulnerability
  • wall-e
  • war
  • Washington
  • web2.0
  • Webslice
  • WGA
  • Widget
  • WiFi
  • Wii
  • WiiItis
  • wiimote
  • Win7
  • Windows 7
  • Windows Secrets
  • Windows Update
  • Windows7
  • WinPartrol
  • WinPatrol
  • winpatrolflash
  • WinPatrolToGo
  • Winter
  • Wireless
  • Wristband
  • WSJ
  • WWII
  • x64
  • Xbox
  • XO
  • XO Laptop
  • XOActivity
  • Xobni
  • xolaptop
  • XP
  • XP SP3
  • xp3
  • Yahoo
  • Zero Day
  • Zone Alarm
  • Zwinky

Blog Archive

  • ▼  2013 (31)
    • ▼  November (2)
      • Employee Manual to Prevent Cryptolocker and More
      • My First State-Sponsored Attack
    • ►  October (1)
    • ►  September (1)
    • ►  August (2)
    • ►  July (3)
    • ►  June (5)
    • ►  May (2)
    • ►  April (3)
    • ►  March (2)
    • ►  February (5)
    • ►  January (5)
  • ►  2012 (30)
    • ►  December (3)
    • ►  November (3)
    • ►  October (2)
    • ►  September (2)
    • ►  August (2)
    • ►  July (3)
    • ►  June (2)
    • ►  May (1)
    • ►  April (4)
    • ►  March (4)
    • ►  February (2)
    • ►  January (2)
  • ►  2011 (28)
    • ►  December (4)
    • ►  November (2)
    • ►  October (4)
    • ►  September (2)
    • ►  August (2)
    • ►  July (2)
    • ►  June (2)
    • ►  May (2)
    • ►  April (2)
    • ►  March (2)
    • ►  February (3)
    • ►  January (1)
  • ►  2010 (44)
    • ►  December (2)
    • ►  November (3)
    • ►  October (3)
    • ►  September (4)
    • ►  August (3)
    • ►  July (3)
    • ►  June (3)
    • ►  May (4)
    • ►  April (4)
    • ►  March (3)
    • ►  February (3)
    • ►  January (9)
  • ►  2009 (90)
    • ►  December (6)
    • ►  November (8)
    • ►  October (6)
    • ►  September (4)
    • ►  August (4)
    • ►  July (12)
    • ►  June (6)
    • ►  May (11)
    • ►  April (7)
    • ►  March (9)
    • ►  February (9)
    • ►  January (8)
  • ►  2008 (122)
    • ►  December (9)
    • ►  November (11)
    • ►  October (14)
    • ►  September (6)
    • ►  August (9)
    • ►  July (9)
    • ►  June (10)
    • ►  May (13)
    • ►  April (8)
    • ►  March (10)
    • ►  February (10)
    • ►  January (13)
  • ►  2007 (155)
    • ►  December (15)
    • ►  November (14)
    • ►  October (12)
    • ►  September (14)
    • ►  August (12)
    • ►  July (13)
    • ►  June (11)
    • ►  May (19)
    • ►  April (17)
    • ►  March (21)
    • ►  February (7)
Powered by Blogger.

About Me

Unknown
View my complete profile