Hundreds of infected machines per hour

November 24th, 2007 No Comments »

A new MSN Messenger botnet is growing by hundreds of computers per hour.   This Trojan is another IRC bot variant that is spreading through MSN Messenger by sending itself in a zip file under two file names, both masquerading as digital camera images, one ending with .exe and the other with .pif.  These attachments may come through messages from a known contact on your “buddy list”.   This is the first Trojan found to date that scans for VNC connections (remote access) likely looking to increase the botnet’s number of connections.

Tags: , ,

Author: Christopher

(No Ratings Yet)
Loading ... Loading ...

Virus Top 20 for October 2007

November 2nd, 2007 No Comments »
  • Email-Worm.Win32.NetSky.q
  • Trojan-Spy.HTML.Fraud.ay
  • Email-Worm.Win32.NetSky.aa
  • Worm.Win32.Feebs.gen
  • Email-Worm.Win32.Mydoom.l
  • Exploit.Win32.PDF-URI.k
  • Email-Worm.Win32.NetSky.t
  • Email-Worm.Win32.Bagle.gt
  • Email-Worm.Win32.Nyxem.e
  • Net-Worm.Win32.Mytob.c
  • Email-Worm.Win32.NetSky.x
  • Email-Worm.Win32.Scano.gen
  • Net-Worm.Win32.Mytob.t
  • Virus.Win32.Virut.a
  • Net-Worm.Win32.Mytob.u
  • Email-Worm.Win32.LovGate.w
  • Net-Worm.Win32.Mytob.dam
  • Exploit.Win32.IMG-WMF.y
  • Trojan-Spy.HTML.Paylap.bg

Data from Kaspersky Lab

Tags: ,

Author: Christopher

(No Ratings Yet)
Loading ... Loading ...

A Computer Virus that infects humans!

October 13th, 2007 No Comments »

“Dave gets into work after a good night’s sleep. A few hellos later, he is at his workstation. He is the top finance guy and recently got a high speed computer that he uses to conduct various high value financial transactions every day. He also holds critical and confidential information about company’s financial position on his computer. He is generally quite energetic and is known to be very efficient. But today, he seems dull and has missed his status report deadline, which is very unlike him. Missing a deadline annoys him and he appears unusually temperamental and over-stressed today. He screams at his computer. As the day progresses, similar behavior is observed across the office. Some people are even popping pills to beat their headaches.”

This is a typical scenario at an office that is hit by a computer virus which has not been detected yet. And that shows that computer viruses infect humans too (in a way)….Just check what happens next…

“Dave tries to open a couple of files on his computer. But he cannot access them. His computer is too slow. It’s been 7 hours since he got into office and no work has been done yet. IT department has been informed but nothing has been found wrong. There are no back-ups for his file either”

No backups, low detection rate and slow response to virus outbreak. This is a complete lapse of information security and protection.

“The losses are mounting by the minute and it sends a shiver down your spine. You regret the compromise you made in selecting a proper information security solution “

Lesson Learned: ‘Treating Information security as a secondary thing can cost you your business’

Tags: , , ,

Author: Christopher

(No Ratings Yet)
Loading ... Loading ...

75% of enterprises will be infected

September 29th, 2007 No Comments »

It is estimated that 75% of enterprises will be infected this year with malware targeted to invade traditional defenses according to Gartner Group. 80% of enterprises have deployed some form of URL filtering, less than 15% have deployed some form of deep packet inspection. Tailor-made Trojans are being developed to penetrate YOUR organization; how are you protected against these threats?

Tags: , , ,

Author: Christopher

(No Ratings Yet)
Loading ... Loading ...

Major websites hosting malicious ads

September 26th, 2007 No Comments »

Sites like MySpace and Photobucket are seeing a significant amount of malicious banner ads planted on their pages. Other heavily volume sites are noticing similar occurrences of difficult to detect javascript based trojan downloaders.

These types of threats are very dangerous as you do not have to click on the ad to be infected. These types of ads are not automatically filtered by Right Media’s ad servers as the trojan writer add in code to not display infect the ad if coming from a Right Media IPs. These ‘Agent’ trojans are becoming popular vehicles to deliver more dangerous malware.

Tags: , , ,

Author: Christopher

(No Ratings Yet)
Loading ... Loading ...

No PDF is safe

September 21st, 2007 No Comments »

More flaws have been found in how Adobe Acrobat handles PDF files that allows them to be transports for malware installation. These flaws can be used to exploit PDF to install gain complete control of a remote machine and completely silently.

PDF files are commonly transfered by email in the business environment and embedded into websites. Because PDF files are common trusted to be a safe medium and have wide spread usage these flaws are a huge attack vector.

This exploit appears to be limited to Adobe Acrobat versions 7.0, 8.0, and 8.1.

Tags: ,

Author: Christopher

(No Ratings Yet)
Loading ... Loading ...