<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' version='2.0'><channel><atom:id>tag:blogger.com,1999:blog-817304909931888080</atom:id><lastBuildDate>Fri, 25 Jul 2008 14:06:27 +0000</lastBuildDate><title>MoMusings</title><description/><link>http://momusings.com/momusings/index.htm</link><managingEditor>noreply@blogger.com (Martin)</managingEditor><generator>Blogger</generator><openSearch:totalResults>119</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-6949508185928917729</guid><pubDate>Fri, 25 Jul 2008 13:46:00 +0000</pubDate><atom:updated>2008-07-25T14:06:27.483Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>tools</category><category domain='http://www.blogger.com/atom/ns#'>malware</category><category domain='http://www.blogger.com/atom/ns#'>scams</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>FREE Anti-Virus Software...</title><description>I thought it is about time for me to cover this again due to the current world-wide credit crunch and fuel, power and food costs soaring. This means many people are looking for ways to cut costs; including costs for protecting their computers. FREE isn't a bad word, but the bad guys and girls have started to make it feel like it ought to be. The phrase Caveat Emptor [&lt;em&gt;Let The Buyer Beware&lt;/em&gt;] seems to be more pertinent than ever.&lt;br /&gt;&lt;br /&gt;What do I mean by "&lt;em&gt;the bad guys and girls have started to make it feel that it ought to be&lt;/em&gt;"? Let me explain:&lt;br /&gt;&lt;br /&gt;Look at these for examples of the rather naughty ways that the bad guys and girls are trying to get you to download and use their anti-virus:&lt;br /&gt;&lt;br /&gt;First they try scare tactics:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/xpantivirus-email2.gif"&gt; &lt;br /&gt;&lt;br /&gt;Then they try a little more direct approach:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/xpantivirus-email1.gif"&gt; &lt;br /&gt;&lt;br /&gt;If you are foolish enough to go to the sites, then this is what you'd currently see:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/xpantivirus-website.gif"&gt; &lt;br /&gt;&lt;br /&gt;Looks very professional, doesn't it? Hard to believe that this is a bad site! Want proof? OK, here it is:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/xpantivirus-website2.gif"&gt; &lt;br /&gt;&lt;br /&gt;That is the very same site [URL] but visited using Firefox 3.x instead.&lt;br /&gt;&lt;br /&gt;But that isn't all, this site is also being promoted by a botnet called Asprox. This botnet searches for sites using SQL, and it then tries to run exploit code, which if successful, overwrites all URLs in the database with a single link. If this now 'bogus' link is clicked on a website using the SQL injected database for content, it starts a chain reaction, which often ultimately ends up either on the site shown above, or it may infect vulnerable systems using exploit code that was run as part of the chain reaction. This may include infecting your system and making it part of the Asprox botnet.&lt;br /&gt;&lt;br /&gt;But there's more.....&lt;br /&gt;&lt;br /&gt;Here's a screenshot of another e-mail I received recently:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Free-Anti-Virus-Email.gif"&gt; &lt;br /&gt;&lt;br /&gt;The link, if foolishly clicked on, takes you here:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Free-Anti-Virus-Website.gif"&gt; &lt;br /&gt;&lt;br /&gt;Does it look familiar?&lt;br /&gt;&lt;br /&gt;Here's a screenshot of the source of the above page:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Free-Anti-Virus-Website-Source.gif"&gt; &lt;br /&gt;&lt;br /&gt;Notice how it uses the REFRESH function to popup a download of the executable they offer; no it isn't anti-virus software, it is actually malware!&lt;br /&gt;&lt;br /&gt;So, who can you trust if you want FREE anti-virus software?&lt;br /&gt;&lt;br /&gt;These are the FREE ones I'd personally recommend include:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://free.avg.com/"&gt;AVG&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://www.avast.com/i_idt_153.html"&gt;Avast&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://www.free-av.com/"&gt;AntiVir&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Please be aware that there are a number of '&lt;em&gt;bogus&lt;/em&gt;' anti-spyware tools out there too and probably even '&lt;em&gt;bogus&lt;/em&gt;' personal firewalls. &lt;br /&gt;&lt;br /&gt;You can find all the links mentioned above, and other useful tools, etc. &lt;a href="http://momusings.co.uk/software.aspx"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;At the end of the day to help keep you system free of net nasties and their kin, you need to ensure that you have a personal firewall, up to date anti-virus installed, anti-spyware tool(s) installed, and last but not least practice '&lt;em&gt;Safe-Hex&lt;/em&gt;'.&lt;br /&gt;&lt;br /&gt;Computer problems are bad enough most of the time which means the following anti-stress kit might be useful? However once you add malware to the more usual computer problems it becomes a must have piece of kit, well it stops the common hair-loss normally associated with stress! ;-)&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/anti-stress-kit.gif"&gt; &lt;br /&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;Hopefully, this posting will help you retain your sanity, or at least reduce the cranial damage you may do to yourself using the above anti-stress kit.&lt;br /&gt;&lt;br /&gt;Be careful out there, the web is a dangerous place without suitable protection...&lt;br /&gt;&lt;br /&gt;If any of you out there in blog land have other security software that you recommend then please feel free to drop me a line or leave the details in a comment.Thanks!</description><link>http://momusings.com/momusings/2008/07/free-anti-virus-software.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-3355109135421919704</guid><pubDate>Thu, 24 Jul 2008 10:25:00 +0000</pubDate><atom:updated>2008-07-24T10:26:34.842Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>tools</category><category domain='http://www.blogger.com/atom/ns#'>scams</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>Phishing for Feedback?</title><description>According to the e-mail I received this morning HSBC have a customer survey they would like me to take. &lt;br /&gt;&lt;br /&gt;For starters here's a screenshot of the e-mail I received:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Phish-Survey-HSBC-Email.gif"/&gt;&lt;br /&gt;&lt;br /&gt;I'm always willing to give feedback to companies I use, but I am not an HSBC customer, so let us see where we go when the link is clicked?&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Phish-Survey-HSBC-Website1.gif"/&gt;&lt;br /&gt;&lt;br /&gt;Looks like a normal survey so far, apart from the dodgy website address [&lt;em&gt;IP dotted&lt;/em&gt;]. So let me fake some data and click on the submit button, here goes:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Phish-Survey-HSBC-Website2.gif"/&gt;&lt;br /&gt;&lt;br /&gt;Ah, now I smell something very &lt;em&gt;phishy&lt;/em&gt; indeed [&lt;em&gt;even if I didn't before&lt;/em&gt; ;-)]. They want some account details; &lt;em&gt;Ker-ching&lt;/em&gt;!&lt;br /&gt;&lt;br /&gt;Oh, yes and there is no prize money, so don't expect to win, just like the fake lottery notifications that you get, it is just a scam.&lt;br /&gt;&lt;br /&gt;Each phishing e-mail I receive is checked; all links are tested against the &lt;a href="http://toolbar.netcraft.com/"&gt;Netcraft toolbar&lt;/a&gt;, and any new ones, that the Netcraft toolbar doesn't yet know about are submitted for inclusion in their database. Nothing too unusual there. However, once in a while I spot something that makes a new phish stand out from the crowd, such as this one. &lt;br /&gt;&lt;br /&gt;At the time I tested these links to the bogus [&lt;em&gt;phishy&lt;/em&gt;] HSBC survey site it was not detected by the Netcraft toolbar, or even the Firefox anti-phishing functions which are now built into the browser. As I finish up writing this post Netcraft should now have it in their database as I sent them the details.&lt;br /&gt;&lt;br /&gt;Just be careful when acting on requests for participating in surveys for companies you use, as they may be &lt;em&gt;phishy&lt;/em&gt; and you may get more than you bargained for. In those &lt;em&gt;phishy&lt;/em&gt; cases it is likely that your personal data will be stolen and used to make fraudulent transactions on your account.</description><link>http://momusings.com/momusings/2008/07/phishing-for-feedback.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-7961773459277312323</guid><pubDate>Fri, 04 Jul 2008 10:04:00 +0000</pubDate><atom:updated>2008-07-04T10:07:08.480Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>malware</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>A Stormy Independence Day...</title><description>It seems that the so-called &lt;em&gt;'Storm Worm Gang&lt;/em&gt;' are back and couldn't resist the opportunity to try and get you to infect your computer again using the guise of a 4th of July [American Independence Day] firework show. This latest wave started early this morning:&lt;br /&gt;&lt;br /&gt;The subjects of the e-mails I've seen so far include:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;em&gt;America the Beautiful&lt;br /&gt;Celebrating the spirit of our Country&lt;br /&gt;Time for Fireworks&lt;br /&gt;Well done 4th!&lt;br /&gt;Light up the sky&lt;br /&gt;The best firework you've ever seen&lt;br /&gt;Long Live America&lt;br /&gt;Celebrating the Glory of our Nation&lt;br /&gt;American Independence Day&lt;/em&gt;&lt;/blockquote&gt;&lt;br /&gt;The body of all the e-mails seen so far contain a single line of text and a URL [the usual dotted IP sort, e.g. http://100.123.12.1], here are just a small selection of the text I've seen used so far:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;em&gt;A Hearty Wish&lt;br /&gt;Amazing Independence Day show&lt;br /&gt;Stars and Strips forever&lt;br /&gt;Well done 4th!&lt;br /&gt;Celebrate the spirit of America&lt;br /&gt;Happy Independence Day&lt;br /&gt;Home of the Brave&lt;br /&gt;Spectacular fireworks show&lt;br /&gt;Long Live America&lt;br /&gt;Amazing Independence Day salute&lt;/em&gt;&lt;/blockquote&gt;&lt;br /&gt;Here's a screenshot of one of the emails that I've received this morning:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Storm-4thJuly-Email.gif"&gt;&lt;br /&gt;&lt;br /&gt;Here's a screenshot of another one of the emails that I've received this morning [Can you spot the difference ;-)]:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Storm-4thJuly-Email2.gif"&gt;&lt;br /&gt;&lt;br /&gt;If you are foolish enough to click on the link in the email, you'll end up on a page that looks like this:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Storm-4thJuly-Website.gif"&gt;&lt;br /&gt;&lt;br /&gt;And here is the source of the web page currently in use:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Storm-4thJuly-Website-Source.gif"&gt;&lt;br /&gt;&lt;br /&gt;The more eagle-eyed of you may have noticed that the code includes an IFRAME which loads a PHP file called '&lt;em&gt;ind.php&lt;/em&gt;; this is what part of the page source code looks like for that file:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Storm-4thJuly-Website-Source2.gif"&gt;&lt;br /&gt;&lt;br /&gt;You may notice that this uses an obfuscated JavaScript routine, the end result, if you have JavaScript enabled in your web browser and your anti-malware doesn't detect this malcode, is that a dropper will be written to your hard disk. This is effectively a '&lt;em&gt;drive-by-download&lt;/em&gt;' as you don't have to click on anything on the webpage to download the file hidden in the JavaScript in '&lt;em&gt;ind.php&lt;/em&gt;'. The lower part of the code has been digitally munged by myself, as you don't need to see all of it.&lt;br /&gt;&lt;br /&gt;At the time of posting this blog entry the detection of the offered '&lt;em&gt;fireworks.exe&lt;/em&gt;' file was still not complete, with only &lt;em&gt;20 out of 32&lt;/em&gt; tested scanners identifying that this is a malicious file. &lt;br /&gt;&lt;br /&gt;Furthermore the file being offered is not a static binary, as in my testing so far each request ends up serving a file which appears to be different, not in size but the MD5 hash is not the same. I'm not sure whether this is a case of server-side polymorphism or just a pool of pre-compiled executables from which one is chosen at random.&lt;br /&gt; &lt;br /&gt;If I get any further useful data or news then I'll try and update this entry later today.&lt;br /&gt;&lt;br /&gt;For those of you celebrating this particular holiday, I would like to wish you a very happy day and enjoy the real fireworks rather than the fake ones being offered in the latest Storm Worm run.&lt;br /&gt;&lt;br /&gt;Oh by the way, I forgot to mention that this isn't the first time that fireworks have been used to get people to infect their own computers, anyone remember '&lt;em&gt;&lt;a href="http://www.f-secure.com/v-descs/ska.shtml"&gt;Happy99.exe&lt;/a&gt;'&lt;/em&gt; (also-known-as '&lt;em&gt;Ska&lt;/em&gt;')?</description><link>http://momusings.com/momusings/2008/07/stormy-independence-day.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-4441949613033122814</guid><pubDate>Thu, 03 Jul 2008 10:23:00 +0000</pubDate><atom:updated>2008-07-03T10:25:20.146Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>scams</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>The Tax Man Giveth....</title><description>If you are anything like me you probably can't remember the last time the 'Tax Man'  [those from HM Revenue and Customs] told you that you had paid too much tax and that he [or she] would like to return some money to you....Yeah right, like that is going to happen! I think I can honestly say that I have NEVER had any form of refund from them, ever, and I've been working for almost 30 years.&lt;br /&gt;&lt;br /&gt;So, when I received the following e-mail [screenshot below] I was already rather sceptical:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Phishy-HMRC-Email.gif"&gt;&lt;br /&gt;&lt;br /&gt;The email looks quite believable, doesn't it? Even the link looks real.&lt;br /&gt;&lt;br /&gt;If you are foolish/brave enough to click on the link, this is what you will see in your web browser:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Phishy-HMRC-Website.gif"&gt;&lt;br /&gt;&lt;br /&gt;Again, very believable, especially if you have no anti-phishing solutions in place.&lt;br /&gt;&lt;br /&gt;If you are foolish/brave enough to fill in the requested data and then click on the link, this is what you will see in your web browser next:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Phishy-HMRC-Website2.gif"&gt;&lt;br /&gt;&lt;br /&gt;Finally, if you are foolish/brave enough to fill in the requested financial data and then click on the link, this is what you will see in your web browser:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Phishy-HMRC-Website3-NOT.gif"&gt;&lt;br /&gt;&lt;br /&gt;Yes, if you clicked on the final page you will be taken from the '&lt;em&gt;phishy&lt;/em&gt;' HMR&amp;C site to the '&lt;strong&gt;real&lt;/strong&gt;' HMR&amp;C site, none the wiser that you have been '&lt;em&gt;phished&lt;/em&gt;'. The final image [above] is the real HMR&amp;C site.&lt;br /&gt;&lt;br /&gt;Usual fare for the Phishers, they want your personal details so that they can steal money from your account or use the details to open new accounts or credit arrangements in your name, so when they default on the loan, you'll be the one being hassled or taken to court for non-payment. &lt;br /&gt;&lt;br /&gt;Meanwhile your credit rating will nose-dive, and it will take you weeks, months or even years to recover from the effects. All because you were '&lt;em&gt;phooled by a phish&lt;/em&gt;'.&lt;br /&gt;&lt;br /&gt;So, if you get an e-mail stating that you have a tax refund.....be warned as you may end up even more out of pocket than you would if you were dealing with the real HMR&amp;C, at least they are up-front about it! So, to finish the second half of the line used for the title of this posting "&lt;em&gt;The Tax Man Giveth [NOT] and the Phishers Fake it to Take it all!&lt;/em&gt;"</description><link>http://momusings.com/momusings/2008/07/tax-man-giveth.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-6415655557607273640</guid><pubDate>Fri, 27 Jun 2008 15:36:00 +0000</pubDate><atom:updated>2008-06-27T15:50:29.255Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>malware</category><category domain='http://www.blogger.com/atom/ns#'>scams</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>I'll Have a 419 With a Side Order of Malware, Please....</title><description>No this isn't about an order being placed at my local Chinese restaurant or takeaway; their menu item number don't go up that far, believe me I have checked ;-).&lt;br /&gt;&lt;br /&gt;So for starters, let me show you a screenshot of an e-mail I received this morning:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/419-Perfect-Email.gif"&gt; &lt;br /&gt;&lt;br /&gt;Looks like a pretty typical 419 scam e-mail doesn't it? A little more terse than usual, I'll grant you, but still a 419 scam, hang on it has an attachment, most unusual! Here's a screenshot showing the attached file:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/419-Perfect-Email-Attachment.gif"&gt; &lt;br /&gt;&lt;br /&gt;An executable file, very suspicious and most unusual for it to be attached to a 419 scam. I wonder what the Bad Guys and Girls from Lagos are up to now? I think a bit of testing and investigation is in order, don't you?&lt;br /&gt;&lt;br /&gt;Some details on the executable file first:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;em&gt;FileName: 108 3386 8257.exe&lt;br /&gt;FileDateTime: 26/06/2008 11:38:39&lt;br /&gt;Filesize: 303842&lt;br /&gt;MD5: 3e5480b34a38d2dc5e1f45f561c7d5f2&lt;br /&gt;CRC32: F7A3CF76&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;/em&gt;&lt;/blockquote&gt;&lt;br /&gt;Which is a WinRAR SFX [executable archive] and this contains the following files:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;em&gt;108 3386 8257.txt&lt;br /&gt;gbt.exe&lt;br /&gt;gbthk.dll&lt;br /&gt;inst.dat&lt;br /&gt;kw.dat&lt;br /&gt;pk.bin&lt;br /&gt;rinst.exe&lt;/em&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;So, let me extract the files, no not by running the RAR SFX file, as that would infect my system with the malware contained inside it.&lt;br /&gt;&lt;br /&gt;Of these only one is a true executable file, this is:&lt;br /&gt;&lt;blockquote&gt;&lt;em&gt;FileName: rinst.exe&lt;br /&gt;FileDateTime: 24/06/2007 21:08:18&lt;br /&gt;Filesize: 19456&lt;br /&gt;MD5: f3d0beef15eb987dbcec8e803bf6c89d&lt;br /&gt;CRC32: 94F8865E&lt;br /&gt;File Type: PE Executable&lt;br /&gt;&lt;br /&gt;This file "&lt;em&gt;rinst.exe&lt;/em&gt;" is packed using Armadillo and the executable itself appears to be written using Microsoft Visual C++.&lt;/em&gt;&lt;/blockquote&gt;&lt;br /&gt;This is the main installation file, and if you are foolish enough to run the attachment, all the enclosed files are dropped to "&lt;em&gt;C:\WINDOWS\TEMP\RarSFX0&lt;/em&gt;" and then it proceeds to run "&lt;em&gt;rinst.exe&lt;/em&gt;" to perform the install of the malcode; in this case it also tries to identify and kill any recognised anti-malware tools. Once installed it attempts to load the  "&lt;em&gt;108 3386 8257.txt&lt;/em&gt;" file which contains the following text:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;em&gt;MTCN CONTROL NUMBER  108 3386 8257&lt;br /&gt;AMOUNT : $3,450USD&lt;br /&gt;RECIEVER : JONATHAN NWEKE,LAGOS NIGERIA&lt;br /&gt;&lt;/em&gt;&lt;/blockquote&gt;&lt;br /&gt;The rest of the files appear to be obfuscated files that are part of the installation of a keylogger, so not only is this malware attempting to kill any security defences you have in place, it is also trying to record what you type, etc. Nasty!&lt;br /&gt;&lt;br /&gt;So next time you receive a 419, have a closer look and see if the Bad Guys and Girls from Lagos have included an attachment to get you to infect your computer and steal your personal data. It seems that they have finally learned that this is now a multi-billion dollar business, and if they fail to adapt then they will either get left behind or other professional cyber-criminals will take their traditional business away from them.&lt;br /&gt;&lt;br /&gt;If you want to know more about 419 scams and their genesis, then you can find more &lt;a href="http://momusings.com/papers/VBApr07.pdf"&gt;here&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;Right, back to my analysis of this to find out what else it does...</description><link>http://momusings.com/momusings/2008/06/ill-have-419-with-side-order-of-malware.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-5808485090565076137</guid><pubDate>Mon, 23 Jun 2008 15:38:00 +0000</pubDate><atom:updated>2008-06-23T15:39:07.517Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>scams</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>Would You Rather Be A Mule [REDUX]?</title><description>How many of you out there have seen job offers [both part-time and full-time positions] that look like the following screenshots:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Mule-Vacancies-Email-Part1.gif"&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Mule-Vacancies-Email-Part2.gif"&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Mule-Vacancies-Email-2.gif"&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Mule-Vacancies-Email-3.gif"&gt;&lt;br /&gt;&lt;br /&gt;Tempted to apply, or do they seem too-good-to-be-true?&lt;br /&gt;&lt;br /&gt;Well, they are too-good-to-be -true, all the screenshots of the e-mails are nothing more than an attempt to recruit staff to act as money launderers, also known as mules.&lt;br /&gt;&lt;br /&gt;I've written about &lt;a href="http://momusings.blogsome.com/2005/01/10/are-you-or-your-loved-ones-a-mule/"&gt;mules before&lt;/a&gt; on this blog, but I though it was time to revisit the area as the bad guys and girls have been very active in trying to recruit new mules just recently.&lt;br /&gt;&lt;br /&gt;So, a quick recap&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;"&lt;em&gt;We are not talking about four legged creatures that are half horse and half donkey….think more of drug couriers who are more usually referred to as Mules!&lt;br /&gt;&lt;br /&gt;Now, in most cases Mules are those that either carry things for others [hence the use of the term] or act as laundering points, such as in organized crime syndicates, they do the dirty work of moving material from A to B and usually have little or no idea hat what they are doing is illegal. They may even be acting as a Mule under duress, such as blackmail, etc.&lt;/em&gt;"&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Next time you see a job advert on the web, in the local paper or receive a job offer via e-mail, stop and think is this really legit, or am I about to be turned into a mule, or as the song goes:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;"&lt;em&gt;Would you like to swing on a star&lt;br /&gt;carry moonbeams home in a jar&lt;br /&gt;and be better off than you are&lt;br /&gt;or would you rather be a mule&lt;br /&gt;&lt;br /&gt;A mule is an animal with long funny ears&lt;br /&gt;he kicks up at anything he hears&lt;br /&gt;His back is brawny but his brain is weak&lt;br /&gt;he's just plain stupid with a stubborn streak&lt;br /&gt;and by the way if you hate to go to school&lt;br /&gt;You may grow up to be a mule...&lt;/em&gt;"&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;The full lyrics can be found &lt;a href="http://www.lyrics007.com/print.php?id=TmpFME1EVT0"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;By all means swing on a star, but not if it means you grow up to be a mule...to fund the lifestyle, and end up broken, saddled with a criminal record, and end up corralled in jail with numerous other mules, while those that run the scams get away with turning the endless train of desperate people [including students] into yet more mules.</description><link>http://momusings.com/momusings/2008/06/would-you-rather-be-mule-redux.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-1272204153394176309</guid><pubDate>Thu, 19 Jun 2008 13:26:00 +0000</pubDate><atom:updated>2008-06-19T14:18:31.500Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>malware</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>They're Back!!! Beijing Earthquake</title><description>Early this morning we started to see emails pushing a new variant of the so-called '&lt;em&gt;Storm Worm&lt;/em&gt;'. These are using a similar tactic to those that gave the malware authors their name, in this case it isn't real storms it is a fictional new earthquake in Beijing, China.&lt;br /&gt;&lt;br /&gt;Here is a screenshot showing many of the subject lines seen so far for this new Storm Worm run:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Storm-worm-beijing-email-list.gif"&gt;&lt;br /&gt;&lt;br /&gt;Here is a screenshot of one of the e-mails I have received:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Storm-worm-beijing-email.gif"&gt;&lt;br /&gt;&lt;br /&gt;Most of them do not have the anti-virus scanning message at the bottom, I picked this one as I'm not sure whether this was added by one of the infected clients, or as part of the next wave, as some form of extra social-engineering ploy. It should also be noted that they have gone back to using real domain names for this run, instead of their more usual dotted IP addresses. According to F-Secure, these are all flast-fluxed.&lt;br /&gt;&lt;br /&gt;Here's a screenshot of the website you would end up on if you clicked on the link:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Storm-worm-beijing-website.gif"&gt;&lt;br /&gt;&lt;br /&gt;The file offered is not a video, it is, not surprisingly an executable file, here are the details of a sample I downloaded earlier today.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;em&gt;FileName: beijing.exe&lt;br /&gt;FileDateTime: 19/06/2008 12:56:05&lt;br /&gt;Filesize: 83608&lt;br /&gt;MD5: 3752f1a45c897471369f5f17dc42c8ee&lt;br /&gt;CRC32: DA97A2FB&lt;br /&gt;File Type: PE Executable&lt;/em&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Here are the scan results of the currently offered file '&lt;em&gt;beijing.exe&lt;/em&gt;' as scanned by over 30 up-to-date malware scanners:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;em&gt;@Proventia-VPS NOT DETECTED&lt;br /&gt;AntiVir Worm/Zhelatin.zc&lt;br /&gt;Avast! Win32:TDrop [Drp]&lt;br /&gt;AVG NOT DETECTED&lt;br /&gt;BitDefender Trojan.Peed.JLV&lt;br /&gt;CA-AV NOT DETECTED&lt;br /&gt;CA-AV (BETA) NOT DETECTED&lt;br /&gt;ClamAV NOT DETECTED&lt;br /&gt;Command NOT DETECTED&lt;br /&gt;Dr Web NOT DETECTED&lt;br /&gt;eSafe File [100] (suspicious)&lt;br /&gt;Ewido NOT DETECTED&lt;br /&gt;F-Prot NOT DETECTED&lt;br /&gt;F-Secure NOT DETECTED&lt;br /&gt;F-Secure (BETA) NOT DETECTED&lt;br /&gt;Fortinet NOT DETECTED&lt;br /&gt;Fortinet (BETA) NOT DETECTED&lt;br /&gt;Ikarus Email-Worm.Win32.Zhelatin.zy&lt;br /&gt;Kaspersky NOT DETECTED&lt;br /&gt;McAfee NOT DETECTED&lt;br /&gt;McAfee (BETA) NOT DETECTED&lt;br /&gt;Microsoft NOT DETECTED&lt;br /&gt;Nod32 Win32/Nuwar worm&lt;br /&gt;Norman NOT DETECTED&lt;br /&gt;Panda NOT DETECTED&lt;br /&gt;Panda (BETA) NOT DETECTED&lt;br /&gt;QuickHeal NOT DETECTED&lt;br /&gt;Rising NOT DETECTED&lt;br /&gt;Sophos W32/Nuwar-E&lt;br /&gt;Sunbelt NOT DETECTED&lt;br /&gt;Symantec NOT DETECTED&lt;br /&gt;Symantec (BETA) NOT DETECTED&lt;br /&gt;Trend Micro NOT DETECTED&lt;br /&gt;Trend Micro (BETA) NOT DETECTED&lt;br /&gt;VBA32 NOT DETECTED&lt;br /&gt;VirusBuster NOT DETECTED&lt;br /&gt;WebWasher Worm.Zhelatin.zc&lt;br /&gt;YY_A-Squared NOT DETECTED&lt;br /&gt;YY_Spybot Worldsecurityonline.FakeAlert,,Executable&lt;/em&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;It should also be noted that the &lt;em&gt;Storm-Worm&lt;/em&gt; gang are trying something new with this new variant, they are using &lt;em&gt;Alternate Data Streams&lt;/em&gt; [ADS] , in this case there is an ADS called &lt;em&gt;Zone.Identifier&lt;/em&gt;, which is a text file that contains:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;em&gt;[ZoneTransfer]&lt;br /&gt;ZoneId=3&lt;/em&gt;&lt;/blockquote&gt;&lt;br /&gt;I'm not quite sure what they are using this for at the moment, maybe some form of tracking data?&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;UPDATE:&lt;/span&gt; This may actually be nothing to do with the Storm Worm gang after all [the ADS part, that is], as it seems that this may be a new 'feature' of Firefox 3.x instead, sneaky!&lt;br /&gt;&lt;br /&gt;So  what do you do if you receive such an e-mail? Simply delete it, do not click on the link and definitely do not download and launch the file that is offered, and finally update your anti-virus at least once a day, as otherwise you will become a victim. Hopefully most anti-virus products will be able to detect this within the next 24 hours.</description><link>http://momusings.com/momusings/2008/06/theyre-back-beijing-earthquake.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-8267378864533286772</guid><pubDate>Mon, 16 Jun 2008 14:48:00 +0000</pubDate><atom:updated>2008-06-16T14:51:14.716Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>scams</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>Every Little Helps...</title><description>Is the catchphrase for &lt;em&gt;Tesco&lt;/em&gt; [a very well known UK supermarket] who sent me an e-mail today informing me that I "&lt;em&gt;have added an additional email address to my account&lt;/em&gt;", see below for the full e-mail:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Tesco-Phish-Email.gif"&gt;&lt;br /&gt;&lt;br /&gt;The email address it was sent by was "&lt;em&gt;customer@tesco.com&lt;/em&gt;" which is also the return address in the raw e-mail headers too. So, let's see where we end up when we click on one of the four links in the e-mail itself, shall we?&lt;br /&gt;&lt;br /&gt;Here's a screenshot of the website that we end up on [using Opera 9.50].....Hmmmm...&lt;em&gt;Tesco.com&lt;/em&gt; [according to the tab text]. Looks like the real thing, but is it?&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Tesco-Phish-Website.gif"&gt;&lt;br /&gt;&lt;br /&gt;How many of you spotted the red warning in the browsers address bar? It reads [&lt;strong&gt;!Fraud site&lt;/strong&gt;]*. Bit of a giveaway, and also when I clicked on the link in the e-mail it actually goes to a dotted IP address, before being redirected [probably some form of click fraud] to the bogus &lt;em&gt;Tesco.com&lt;/em&gt; site shown in the screenshot above. Yes, it is a Phishing site, not the real &lt;em&gt;Tesco.com&lt;/em&gt; at all!&lt;br /&gt;&lt;br /&gt;So, what is the site and what is it trying to achieve?&lt;br /&gt;&lt;br /&gt;Well, this appears to be a Phishing scam, but instead of being targeted at a bank or other financial organisation, or &lt;em&gt;Paypal, eBay, eGold, &lt;/em&gt;etc. it is targeting customers of a supermarket instead. This is the first time I've seen a supermarket being the target of a Phishing scam run, most unusual!&lt;br /&gt;&lt;br /&gt;Not sure why the bad guys and girls are targeting &lt;em&gt;Tesco &lt;/em&gt;customers, unless the stolen customer login details are just a way for them to gain access to any stored credit/debit card details on the &lt;em&gt;Tesco.com&lt;/em&gt; account? Maybe they are just hungry ;-)&lt;br /&gt;&lt;br /&gt;So, is this a new trend, can we expect similar Phishing scams for &lt;em&gt;Sainsbury's, Waiterose, Marks and Spencer's and Morrisons&lt;/em&gt;? Unfortunately, I expect so, so please be very careful and if you have the option on any such service do &lt;strong&gt;NOT&lt;/strong&gt; store your credit/debit card details, it may make shopping faster, but it also makes identity theft easier too.....as &lt;em&gt;Tesco&lt;/em&gt; states "&lt;em&gt;Every Little Helps&lt;/em&gt;", just don't let it be true for the bad guys and girls allowing them to gain access to your personal information and credit/debit card details. &lt;br /&gt;&lt;br /&gt;* This is a new feature in the latest version of Opera.</description><link>http://momusings.com/momusings/2008/06/every-little-helps.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-2980178236554583136</guid><pubDate>Tue, 27 May 2008 17:14:00 +0000</pubDate><atom:updated>2008-05-27T17:18:08.958Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>scams</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>The FBI Have Contacted Me!</title><description>I received the following e-mail [screenshot below] this morning which says it has come from the&lt;em&gt; FBI&lt;/em&gt;, not only that, it states that it was sent by &lt;em&gt; FBI Director Robert S.Mueller the Third&lt;/em&gt; of the &lt;em&gt;Anti-terrorist and Monetary Crimes Division&lt;/em&gt; and if I don't respond and/or supply the requested information that I'll be charged!&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/FBI-419-1.gif"&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/FBI-419-2.gif"&gt;&lt;br /&gt;&lt;/center&gt;&lt;br /&gt;It goes on to say that I have &lt;em&gt;$10,500,000.00&lt;/em&gt; being wired to me via a&lt;em&gt; Secured Diplomatic Transit Account&lt;/em&gt; [S.D.T.A] and I need to prove that I have the required paperwork, including a &lt;em&gt;Diplomatic Immunity Seal of Transfer&lt;/em&gt; [DIST] and an &lt;em&gt;FBI Identification Record &lt;/em&gt;(aka a &lt;em&gt;Rap Sheet&lt;/em&gt; or &lt;em&gt;Criminal History Record&lt;/em&gt;) to prove I am who I claim to be and that I'm not a terrorist or drugs dealer. If I can supply these proofs, then the money is all mine!&lt;br /&gt;&lt;br /&gt;OK, how many of you out there reading this would go along with this? Hands up, so I can count ;-)&lt;br /&gt;&lt;br /&gt;Now, how many of the rest of you smell something fishy? Well, it isn't a Phish at all, it is just another new version of the so-called 419 scam.&lt;br /&gt;&lt;br /&gt;The twist here, is that the Boys and Girls from Lagos [or almost anywhere else in the World now] are using fear as a new social engineering tactic to get you to part with personal data which they will then either mis-use or sell to others.&lt;br /&gt;&lt;br /&gt;If you somehow, miraculously come up with the requested proofs, then guess what, you won't get any money at all, because there is no money in the first place, and the e-mail isn't from the FBI [or anyone in law-enforcement], surprise! ;-)&lt;br /&gt;&lt;br /&gt;Whatever you do don't fall for this scam [or any of it's relations], it relies on what the Lagos boys call Wad [rich, greedy people]. They also use a less polite name for the people they dupe; Mgbada*. &lt;br /&gt;&lt;br /&gt;To the Boys and Girls from Lagos [the 419ers that run these scams], it is a business, some say it should be considered an African cottage industry, however they want to try and justify it, it is still a crime, no more, no less.&lt;br /&gt;&lt;br /&gt;Other unusual examples of 419s I've covered include&lt;br /&gt;&lt;em&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://momusings.com/momusings/2007/07/scam-victims-compensation-payments.html"&gt;Scam Victims Compensation Payments&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://momusings.com/momusings/2007/12/barclays-five-million-us-dollar.html"&gt; Barclays FIVE MILLION US Dollar Transfer&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://momusings.com/momusings/2007/04/google-product-too-far.html"&gt; A Google Product Too Far?&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://momusings.com/momusings/2007/04/secret-intelligence-service-scam-alert.html"&gt; Secret Intelligence Service SCAM ALERT!! E-mail&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/em&gt;&lt;br /&gt;Lots of other examples have also been covered oer the years on this blog, and I have written several articles for Virus Bulletin on 419s, which can be found&lt;a href="http://momusings.com/papers/"&gt; here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;* If anyone can tell me what this means in English, then please e-mail me, thanks.&lt;/em&gt;</description><link>http://momusings.com/momusings/2008/05/fbi-have-contacted-me.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-6534789722021754660</guid><pubDate>Wed, 07 May 2008 13:46:00 +0000</pubDate><atom:updated>2008-05-07T13:49:33.010Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>tools</category><category domain='http://www.blogger.com/atom/ns#'>malware</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>papers</category><title>EICAR 2008 Conference Paper Now Available</title><description>This is a quick update on my posting from yesterday, and to announce that the full paper for the EICAR 2008 conference which was held earlier this week is now available for download as a PDF [Adobe Acrobat] file.&lt;br /&gt;&lt;br /&gt;To refresh you memories,here is the abstract from the paper, entitled "&lt;em&gt;Where To Now: Detecting The Unknown&lt;/em&gt;":&lt;br /&gt;&lt;blockquote&gt;&lt;em&gt;The increasing speed of new malware strains being written and released means that security professionals are more likely than ever before to see new malware.&lt;br /&gt;&lt;img src="http://www.eicar.org/image/conference/2008/laval_kl.jpg" align="right"&gt;&lt;br /&gt;This means new malware which is not detected by the anti-malware solutions they have deployed in their infrastructure, be it workstation, server, PDA or at the gateway.&lt;br /&gt;&lt;br /&gt;Imagine this scenario: An end-user calls the helpdesk and reports that their system is running very sluggishly when it wasn't a week ago and that they can't access the Windows 'Task Manager' or open a command prompt any more.&lt;br /&gt;&lt;br /&gt;Is this caused by malware or is it a 'user' problem? The virus scanner is right up to date and active, and it says the system is clean, the personal firewall is active too. Where do you go from here? Investigate or rebuild the box?&lt;br /&gt;&lt;br /&gt;How can you tell if the machine is clean or infected by a new malware, with a reasonable level of confidence for your conclusion?&lt;br /&gt;&lt;br /&gt;This paper will look at what tricks, tools and techniques you can use to help establish the true state of the 'suspect' system. It will focus on a step by step approach of what tools to use, what to look for and what to do with any suspicious files. It will also discuss the use of forensic tools in such a scenario, as a last port of call.&lt;br /&gt;&lt;br /&gt;The paper will draw on real scenarios where new [undetected] malware has been responsible for 'odd' system or network behaviour.&lt;br /&gt;&lt;/em&gt;&lt;/blockquote&gt;&lt;br /&gt;The paper can be downloaded via the following links:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://momusings.com/papers/EICAR2008-Where-To-Now-1.01.pdf"&gt;http://momusings.com/papers/EICAR2008-Where-To-Now-1.01.pdf&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://momusings.co.uk/Documents/EICAR2008-Where-To-Now-1.01.pdf"&gt;http://momusings.co.uk/Documents/EICAR2008-Where-To-Now-1.01.pdf&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;As usual all feedback is most welcome.</description><link>http://momusings.com/momusings/2008/05/eicar-2008-conference-paper-now.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-7802860392315445011</guid><pubDate>Tue, 06 May 2008 11:46:00 +0000</pubDate><atom:updated>2008-05-06T11:54:50.254Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>tools</category><category domain='http://www.blogger.com/atom/ns#'>malware</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>papers</category><title>No, I [Still] Haven't Fallen Off The Edge Of The World....</title><description>Or been kidnapped by aliens,  gone over to the dark side or gone down with a virus [or should that now be malcode?].&lt;br /&gt;&lt;br /&gt;It seems that about this time, every year, I end up writing a post like this, so here is this years version. ;-)&lt;br /&gt;&lt;br /&gt;Sorry for the lack of blog entries over the last month or so, but I've been writing a conference paper for the &lt;a href="http://www.eicar.org/conference/"&gt;EICAR&lt;/a&gt; international conference which is, as I write this, being held in Laval, France. &lt;br /&gt;&lt;br /&gt;So, am I writing this blog entry from there? No, unfortunately not, let me explain...&lt;br /&gt;&lt;br /&gt;Why am I not presenting my paper at &lt;a href="http://www.eicar.org/conference/index.htm"&gt;EICAR 2008&lt;/a&gt; in Laval, France? Why am I not there today?&lt;br /&gt;&lt;br /&gt;Well, the decision was made that because we [the new team/service I'm part of] was in the middle of a major analysis of new malcode, and this was a very high priority. It was decided at a commercial level that it would be better if I were available at a moments notice if new samples were found that required immediate analysis. If I were in Laval, France I would be unable to work on live malcode and keep in contact.&lt;br /&gt;&lt;img src="http://momusings.com/images/sorry.gif" align="right"&gt;&lt;br /&gt;So, I'd like to apologise once more to EICAR that I was unable to attend and present my paper at the conference. Hopefully, if the team I'm now part of is expanded this won't have to happen again. Anyone that attended EICAR will have still seen my paper presented, but by Eric Filiol [who does not work for IBM or ISS] instead. This was the best solution we could come up with at the last moment. &lt;br /&gt;&lt;br /&gt;The paper will be made available later this week at the following locations*:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;&lt;a href="http://momusings.com/papers"&gt;http://momusings.com/papers&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://momusings.co.uk/publications.aspx"&gt;http://momusings.co.uk/publications.aspx&lt;/a&gt;&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Writing the paper for EICAR is only one of the reasons for my lack of posting, other changes have been afoot!&lt;br /&gt;&lt;br /&gt;Firstly, I have moved to a new company, well sort of, I now work for Internet Security Systems, who as some of you may know were acquired by IBM a while ago. So, I now work for ISS, which is owned by IBM. However, my role has changed as I now work in the X-Force Professional Security Services section as a Malware Analyst and Consultant.&lt;br /&gt;&lt;br /&gt;So, what does this new role involve?&lt;br /&gt;&lt;br /&gt;The main part of it is malware analysis and reverse-engineering. So, in some ways I have stepped back in time to the sort of work I used to do when I wrote my own anti-virus detection and remediation tools [whilst I was working for another company]. However, the game has changed quite a bit since then; luckily my skills are not that rusty, so I have managed to get back up to speed very quickly.  Other skills I have picked up and honed over the years will probably also be required for other parts of my new role; more on that another time.&lt;br /&gt;&lt;br /&gt;However, that is not all that has kept me from posting recently, other things include:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Lecturing at the University of Warwick on malware and internet security later this month, so my slides need to be updated and tweaked before then.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Writing and submitting abstracts for this years &lt;a href="http://www.virusbtn.com/conference/index"&gt;Virus Bulletin conference&lt;/a&gt; to be held in Ottawa, Canada this year.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Building systems and finding/creating  tools to help in the analysis of new samples, they just keep coming!&lt;/em&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Working very long hours on malcode analysis.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Normal, [once or twice a week postings] service will be resumed as soon as I can find that elusive 25th hour in the day, or I decide to give up trying to get any sleep at all!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;* All my published papers and articles can be found at those web addresses.&lt;/em&gt;</description><link>http://momusings.com/momusings/2008/05/no-i-still-havent-fallen-off-edge-of.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-4157997453575322729</guid><pubDate>Tue, 01 Apr 2008 09:12:00 +0000</pubDate><atom:updated>2008-04-01T09:16:24.452Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>malware</category><category domain='http://www.blogger.com/atom/ns#'>hoax</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>Don't 'Fool' For It...</title><description>Normally I do my own April Fools blog posting, using some bogus malware, anti-malware or other computer related bit of nonsense for a bit of fun, and hopefully you find them funny, or at least interesting?&lt;br /&gt;&lt;br /&gt;However, this year I didn't need to bother, as the Bad Guys and Girls have their own; trouble is, it isn't a joke, and it certainly isn't funny!&lt;br /&gt;&lt;br /&gt;It seems that the so-called &lt;em&gt;'Storm Worm Gang&lt;/em&gt;' are back playing the fool again and couldn't resist the opportunity to try and get you to infect your computer using the guise of a April Fools e-card. This new wave started late last night/early this morning [depending where you are in the world]:&lt;br /&gt;&lt;br /&gt;The subjects of the e-mails I've seen so far include:&lt;br /&gt;&lt;blockquote&gt;&lt;em&gt;Surprise!&lt;br /&gt;Happy April Fools!&lt;br /&gt;Happy All Fool's Day&lt;br /&gt;Gotcha! April Fool!&lt;br /&gt;Gotcha! All Fool!&lt;br /&gt;I am a Fool for your Love&lt;br /&gt;Today You Can Officially Act Foolish&lt;br /&gt;Join the Laugh-A-Lot&lt;br /&gt;Surprise! The joke's on you&lt;br /&gt;&lt;/em&gt;&lt;/blockquote&gt;&lt;br /&gt;The body of all the e-mails seen so far contain a single line of text and a URL [the usual dotted IP sort, e.g. http://100.123.12.1]&lt;br /&gt;&lt;br /&gt;Here's a screenshot of one of the emails that I've received this morning:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/April-Fool-Storm-Email1.gif" /&gt;&lt;br /&gt;&lt;br /&gt;If you are foolish enough to click on the link in the email, you'll end up on a page that looks like this:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/April-Fool-Storm-Website1.gif" /&gt;&lt;br /&gt;&lt;br /&gt;After 5 seconds you'll see a download dialogue box, like this:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/April-Fool-Storm-Download1.gif" /&gt;&lt;br /&gt;&lt;br /&gt;And here is the source of the web page currently in use:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/April-Fool-Storm-Website-Source1.gif" /&gt;&lt;br /&gt;&lt;br /&gt;However you spend the day, whatever jokes you play, or end up the victim of, don't 'Fool' for this one, as otherwise you computer will get infected and the Bad Guys and Girls will have the last laugh again, at you expense!.&lt;br /&gt;&lt;br /&gt;At the time of posting this blog entry the detection of the offered '&lt;em&gt;funny.exe&lt;/em&gt;' file was rather poor, with less than half of 32 tested scanners identifying that this is a malicious file.  This is the default file and is automatically offered for download [within 5 seconds of the page rendering].&lt;br /&gt;&lt;br /&gt;You may have noticed that two other filenames appear in the HTML source; these are:&lt;blockquote&gt;&lt;em&gt;kickme.exe&lt;br /&gt;foolsday.exe&lt;/em&gt;&lt;/blockquote&gt;&lt;br /&gt;If you click on the image, you get &lt;em&gt;kickme.exe,&lt;/em&gt; and if you click on "click here" you get &lt;em&gt;foolsday.exe.&lt;/em&gt; instead.&lt;br /&gt;&lt;br /&gt;If I get any further useful data or news then I'll try and update this entry later today or tomorrow.&lt;br /&gt;&lt;br /&gt;Whilst I was browsing the web looking for a good basis for an April Fools blog posting, I found these:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.f-secure.com/weblog/archives/00001411.html"&gt;Unusual banking trojan found today&lt;/a&gt; &lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://www.sophos.com/security/blog/2008/04/1246.html?_log_from=atom"&gt;RAPIL - a slap in the face for hackers and virus writers&lt;/a&gt; &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Please let me know if you spot any more, thanks!</description><link>http://momusings.com/momusings/2008/04/dont-fool-for-it.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-657410987004621245</guid><pubDate>Mon, 10 Mar 2008 17:45:00 +0000</pubDate><atom:updated>2008-03-10T17:46:15.647Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>malware</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>3D Screensaver E-mails?</title><description>This morning I started to receive e-mails offering me screensavers.  I immediately smelt a rat, well at least a malware author, anyway! ;-)&lt;br /&gt;&lt;br /&gt;So, I took a look  at it in more details, here's a screenshot of one of the e-mails:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/3D-Screensavers-Email1.gif" /&gt;&lt;br /&gt;&lt;br /&gt;I clicked on the link to see where I'd end up, and you can see what I found, below:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/3D-Screensavers-Website1.gif" /&gt;&lt;br /&gt;&lt;br /&gt;Looks like a very professional and polished website offering 3D Screensavers; very believable, isn't it?&lt;br /&gt;&lt;br /&gt;So, I clicked on one of the links offered and I ended up here:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/3D-Screensavers-Website2.gif" /&gt;&lt;br /&gt;&lt;br /&gt;Still very believable, so I proceeded to download a copy of the screensaver offered, so that I could analyse it [you didn't think I was actually going to install it, did you? ;-)].&lt;br /&gt;&lt;br /&gt;Will you be surprised to learn that the results of my analysis showed that this wasn't a screensaver at all, it was a piece of malware. I then proceeded to download several other samples, from the other selections offered, and the resulting files, although having different names, were all the same size [18,944 bytes], had the same MD5 hash value [which means they are all effectively identical internally], and were not being detected by a number of anti-malware tools.&lt;br /&gt;&lt;br /&gt;At the time of posting this the files I downloaded from the site were named "&lt;em&gt;Screensaver-66713.scr&lt;/em&gt;", "&lt;em&gt;Screensaver-8719.scr&lt;/em&gt;" and "&lt;em&gt;Screensaver-83580.scr&lt;/em&gt;", this of course may change, and there are certainly others with different filenames being offered.&lt;br /&gt;&lt;br /&gt;If you see an e-mail like the one shown above, then simply delete it, as otherwise you will infect your computer, rather than save it's screen.&lt;br /&gt;&lt;br /&gt;Hopefully by the end of today most anti-malware vendors should have updated their products to detect it.&lt;br /&gt;&lt;br /&gt;So, in those immortal words, "&lt;em&gt;Be careful out there....&lt;/em&gt;"</description><link>http://momusings.com/momusings/2008/03/3d-screensaver-e-mails.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-1318402961565019529</guid><pubDate>Wed, 05 Mar 2008 15:19:00 +0000</pubDate><atom:updated>2008-03-05T15:20:33.403Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>Stealthed Spam, Redux II!</title><description>The spammers are upping the stakes in the stealthed spam arena again. This entry will cover a stealthed spam I received this morning, but before that let me suggest that if you don't know what I am talking about, then you should take a look at my previous blog entries covering this area. These are [&lt;a href="http://momusings.com/momusings/2008/01/stealthed-spam-redux.html"&gt;30th January 2008&lt;/a&gt;] and [&lt;a href="http://momusings.com/momusings/2007/10/stealthed-spam.html"&gt;17th October 2007&lt;/a&gt;]. This will also allow you to follow the development of this as a spamming technique.&lt;br /&gt;&lt;br /&gt;So, now if you know what I mean by stealth and stealth spam, let me show you the latest example I have seen, just today, in fact:&lt;br /&gt;&lt;br /&gt;The body of the e-mail would have you believe that it is from '&lt;em&gt;Irwin Bank and Trust&lt;/em&gt;':&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Stealth-spam4.gif" /&gt;&lt;br /&gt;&lt;br /&gt;With the above example, all the URLS [web-links] except one, used in the e-mail point to the real Banks site! All the text is probably taken from the real Banks website. This e-mail passes the tests that most of us use to decide if something is spam or not, in other words it pretty easily passes the '&lt;em&gt;Eyeball&lt;/em&gt;' test fairly easily as it  looks pretty genuine. The only missing pieces are any remote graphics, which most e-mail programs will not show, at least not by default.&lt;br /&gt;&lt;br /&gt;So, what does it look like when I enable '&lt;em&gt;allow remote images&lt;/em&gt;' in the e-mail program?&lt;br /&gt;&lt;br /&gt;It looks like this [&lt;em&gt;yes, it is the same e-mail&lt;/em&gt;]:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Stealth-spam-revealed4.gif" /&gt;&lt;br /&gt;&lt;br /&gt;Now it fails the '&lt;em&gt;Eyeball&lt;/em&gt;' test with ease.&lt;br /&gt;&lt;br /&gt;Although, the stealthed e-mail shown above is pretty convincing, it isn't perfect as the e-mail address it shows as the from address [&lt;em&gt;admin@viagra.com&lt;/em&gt;] and the subject used [&lt;em&gt;RE:February 83% OFF&lt;/em&gt;] are not consistent with the rest of the e-mail, and are obviously spammy. So, the spammers need to sort these problems out to create the perfect stealthed spam.&lt;br /&gt;&lt;br /&gt;Why do I call this '&lt;em&gt;Stealthed Spam&lt;/em&gt;'? Well, simply because the spam component is hidden and not in plain view, at first.&lt;br /&gt;&lt;br /&gt;As they say "&lt;em&gt;&lt;a href="http://en.wikipedia.org/wiki/Shaw_Taylor"&gt;Keep 'em peeled!&lt;/a&gt;&lt;/em&gt;", which means keep your eyes open and stay alert. Or, as other might say, "&lt;em&gt;don't believe everything you see or read&lt;/em&gt;", it may be a clever fake.&lt;br /&gt;&lt;br /&gt;If you see any other interesting new tricks/techniques or file formats being used by spammers then please feel free to send me the details or post the information as a comment. Thanks!</description><link>http://momusings.com/momusings/2008/03/stealthed-spam-redux-ii.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-2821694597995004838</guid><pubDate>Thu, 28 Feb 2008 16:40:00 +0000</pubDate><atom:updated>2008-02-28T16:46:11.795Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>malware</category><category domain='http://www.blogger.com/atom/ns#'>scams</category><category domain='http://www.blogger.com/atom/ns#'>social-networks</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>Out of Office Notifications Are...</title><description>An accident waiting to happen!&lt;br /&gt;&lt;br /&gt;In fact a number of these accidents have already happened. But I'm getting ahead of myself. So, why do I think that they are inherently bad?&lt;br /&gt;&lt;br /&gt;Personally, I hate out of office notifications, not because it means that I can't get a reply from the person I sent an e-mail too in the first place, but because they can be misused by not just the person who is '&lt;em&gt;Out of the Office&lt;/em&gt;' but also by the '&lt;em&gt;Bad Guys and Girls&lt;/em&gt;'. Let me explain in more detail, what I mean...&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;1. Too Much Information&lt;/strong&gt;&lt;br /&gt;Often when people enable '&lt;em&gt;Out of Office&lt;/em&gt;' they offer too much information; such as when they are going and coming back, and where they are going to. They also often include a second person's details to contact in their absence; including their full e-mail address. This is then often enabled for all incoming e-mail to their e-mail address, which means that not only internal [company/organisation] colleagues are informed, but also, in many cases anyone on the internet that sends them e-mail. The next two points explain in more details why this is a '&lt;em&gt;bad&lt;/em&gt;' thing.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;2. Confirmation that your e-mail address exists&lt;/strong&gt;&lt;br /&gt;As mentioned above, if you enable your '&lt;em&gt;Out of Office&lt;/em&gt;' notification to send an automatic response to all e-mail that is received, you are assisting spammers, scammers and malware authors by confirming that the e-mail address is in use [that makes it worth more]. If you also include another persons details to contact while you are away, then the '&lt;em&gt;Bad Guys and Girls&lt;/em&gt;' can also harvest that to either sell on for profit to others, misuse it themselves, or often both. The end result is more spam, scams and malware arriving in yours and anyone else's inbox that you kindly supplied in your '&lt;em&gt;Out of Office&lt;/em&gt;' notification, I'm sure that they will be quick to thank you for all the extra '&lt;em&gt;crud&lt;/em&gt;' they are now receiving ;-)&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;3. Physical and Cyber attacks while you are '&lt;em&gt;away&lt;/em&gt;'.&lt;/strong&gt;&lt;br /&gt;If you are unwise enough to indicate you are on holiday or just out of the country where you normally reside, then the '&lt;em&gt;Bad Guys and Girls&lt;/em&gt;' can do a number of things whilst you are not at home. If they have enough data on you, then you could come back to find your house burgled, full of squatters, vandalised or even worse.&lt;br /&gt;&lt;br /&gt;If they don't have access to that level of information then can hack into your personal webspace, social networking and other web sites you may use. They could also perform a '&lt;em&gt;Joe Job&lt;/em&gt;' or a '&lt;em&gt;DDoS&lt;/em&gt;' to discredit you or damage your business or reputation. While you are away they may use your stolen identity to take out loans, credit cards and even mortgages in your name. If they already have some of your financial data, such as bank account or credit card data, you could suddenly find your bank account empty or unathorised charges [and ATM withdrawals] on your debit or credit cards.&lt;br /&gt;&lt;br /&gt;In all these cases listed above, this is only likely to happen if you have come to their attention; such as being a thorn in their side, or making life difficult for them, or someone else is willing to pay for the information and/or attacks to take place.&lt;br /&gt;&lt;br /&gt;If you don't believe that these things happen, then I can assure you that many of the cyber attacks happen to many of us who work in computer security, especially those that are widely published or who work for anti-malware companies or in law-enforcement.&lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;img src="http://momusings.com/images/OOF-Example1.gif" /&gt;&lt;br /&gt;&lt;em&gt;Figure 1: Too Much Information is an Invitation for Trouble!&lt;/em&gt;&lt;/div&gt;&lt;br /&gt;&lt;strong&gt;4. Bounced Spam&lt;/strong&gt;&lt;br /&gt;This is the latest way that '&lt;em&gt;Out of Office&lt;/em&gt;' notifications can be mis-used and it affects all of us who are already on spammers/scammers and malware authors lists (or soon will be).&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Here is the scenario:&lt;/em&gt;&lt;br /&gt;The Bad Guys or Girls sign up for a free webmail account, at say, Google, Yahoo, Live, etc. and then enable the '&lt;em&gt;Out of Office&lt;/em&gt;' feature. They then place the spam message they want to distribute in the '&lt;em&gt;Out of Office&lt;/em&gt;' e-mail body.&lt;br /&gt;&lt;br /&gt;Next, the spammer sends this new webmail account with the enabled '&lt;em&gt;Out of Office&lt;/em&gt;' feature, lots of e-mails using spoofed '&lt;em&gt;From:&lt;/em&gt;' addresses so that the '&lt;em&gt;Out of Office&lt;/em&gt;' reply will be sent to the intended victim [&lt;em&gt;the spoofed From: address&lt;/em&gt;].&lt;br /&gt;&lt;br /&gt;Why do this? Well, e-mail sent from this booby-trapped spamming webmail account will contain anti-spam header information, such as &lt;em&gt;DKIM, DomainKey, Sender ID&lt;/em&gt; or any of the other similar systems, which means that the mail server that deals with the intended victims email will be more likely to let the spam through as it has come from a&lt;em&gt; trusted source&lt;/em&gt;.&lt;br /&gt;&lt;br /&gt;This is now easier for the spammers to do, as the &lt;em&gt;CAPTCHA&lt;/em&gt; systems used by Yahoo and Googlemail have been cracked; so that they can now automate the creation of these '&lt;em&gt;trusted&lt;/em&gt;' '&lt;em&gt;Out of Office&lt;/em&gt;' spam relays.&lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;img src="http://momusings.com/images/OOF-Example2.gif" /&gt;&lt;br /&gt;&lt;em&gt;Figure 2: Out of Office Spam Setup&lt;/em&gt;&lt;/div&gt;&lt;br /&gt;So, next time you go to enable your '&lt;em&gt;Out of Office&lt;/em&gt;' feature, think carefully about what information you provide, and if you can do not enable the respond to internet address option, as you may live to regret it!</description><link>http://momusings.com/momusings/2008/02/out-of-office-notifications-are.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-1489044261126879438</guid><pubDate>Thu, 21 Feb 2008 16:01:00 +0000</pubDate><atom:updated>2008-02-21T16:06:59.043Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>scams</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>A Right Royal Grant?</title><description>Wow, according to the e-mail I received today I have been awarded a grant of &lt;em&gt;half-a-million&lt;/em&gt; pounds [&lt;em&gt;£500,000.00&lt;/em&gt;], not just from any old society or company, but from one calling itself '&lt;em&gt;Queen Elizabeth's Foundation&lt;/em&gt;'!&lt;br /&gt;&lt;br /&gt;I'm honoured, that I have personally come to the attention of our countries ruling monarch, and what's more she feels that I deserve &lt;em&gt;half-a-million&lt;/em&gt; in cash with her head on it all...&lt;br /&gt;&lt;br /&gt;Here's a screenshot of the e-mail, so that you can see it for yourself, and bask in my glory:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/QE-Grant-419-Email.gif" /&gt;&lt;br /&gt;&lt;br /&gt;OK, yes I'm not really being serious, or getting too big for my boots, or thinking that I'm now above you all ;-) I know it is a scam and I'm just playing along.&lt;br /&gt;&lt;br /&gt;So, let me start by checking out if the domain that the email claims to be sent from actually has a website:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/QE-Grant-419-Website.gif" /&gt;&lt;br /&gt;&lt;br /&gt;Nope, no website, most odd! OK, so let me know check to see who the domain is registered with and to whom:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/QE-Grant-419-Domain.gif" /&gt;&lt;br /&gt;&lt;br /&gt;If I didn't already know that this was a 419 scam, then I would by now, so let me dig deeper. Next, let me check out the phone numbers, they look real and they are, but they are not registered to any charity or person, they are so-called 'personal' numbers being offered for FREE by the following company:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/QE-Grant-419-Phone.gif" /&gt;&lt;br /&gt;&lt;br /&gt;So, what do we know so far? There is no such society or organisation, the telephone numbers given are real but suspect, they have no website and the domain isn't even registered [so how could they send e-mail from it?], and finally they want me to reply to a different e-mail address, and they can't make their mind up as to who I should be replying to, is it:&lt;br /&gt;&lt;blockquote&gt;&lt;em&gt;&lt;strong&gt;Rooney James&lt;/strong&gt; or &lt;strong&gt;Williams Anderson&lt;/strong&gt;?&lt;/em&gt;&lt;/blockquote&gt;&lt;br /&gt;To get to the bottom of the mystery of where the e-mail was sent from, I took a quick peek at the raw headers, and what did I find? I found that the e-mail was actually sent via the webmail service of the company shown in the final screenshot, below:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/QE-Grant-419-Webmail.gif" /&gt;&lt;br /&gt;&lt;br /&gt;Yes, they sent the e-mail using a webmail service based in &lt;em&gt;Hawaii&lt;/em&gt;, for the &lt;em&gt;United Kingdom&lt;/em&gt; monarch who's name is used for an organisation that doesn't exist, doesn't have a website or own a domain at all, and they want me to reply to an email account hosted on &lt;em&gt;Microsoft Live&lt;/em&gt;, just so that they can send me &lt;em&gt;half-a-million&lt;/em&gt; quid!&lt;br /&gt;&lt;br /&gt;So, do you smell a rat now, or would you send them the data they ask for?&lt;br /&gt;&lt;br /&gt;Just to be crystal clear about this: There is no money, as usual, this is a scam which has been around in one format or another for many years, all that happens if you get caught up with these scammers is that you will lose money, not gain any.&lt;br /&gt;&lt;br /&gt;Just because they use the name of the &lt;em&gt;Queen of the United Kingdom&lt;/em&gt;, and names of well known real organisations such as &lt;em&gt;UNICEF&lt;/em&gt;,  doesn't mean that this is real [&lt;em&gt;even if the money actually existed, which it doesn't&lt;/em&gt;]. This is just another twist in '&lt;em&gt;The Game&lt;/em&gt;' that is collectively known as &lt;em&gt;419 or Advance-Fee-Fraud&lt;/em&gt;.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;Sorry, Your Majesty, but I'm going to have to turn down your kind offer...&lt;/em&gt;</description><link>http://momusings.com/momusings/2008/02/right-royal-grant.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-7683918700833327728</guid><pubDate>Tue, 12 Feb 2008 16:03:00 +0000</pubDate><atom:updated>2008-02-12T16:04:26.204Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>malware</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>FREE Greetings FOR YOU !!!</title><description>Looks like a busy day for me today, just what I need, not!&lt;br /&gt;&lt;br /&gt;Here's a screenshot of another tempting* email that I've received this afternoon:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Yahoo-Greeting-Software-Email.gif"&gt;&lt;br /&gt;&lt;br /&gt;If you are foolish enough to click on the link in the email, you'll end up being offered a file called '&lt;em&gt;greeting.exe&lt;/em&gt;', this file appears to be hosted on the free web-hosting service called &lt;em&gt;ZeroCatch&lt;/em&gt;. Here's a screenshot of the default page for the sub-domain hosting the file. As you can see the malware author couldn't even be bothered to put a basic page together:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Yahoo-Greeting-Software-Web.gif"&gt;&lt;br /&gt;&lt;br /&gt;So, I hear you all ask, do you get FREE Greetings, as promised? Nope, all you'll get is an infected PC for your trouble, although it will be FREE! ;-)&lt;br /&gt;&lt;br /&gt;At the time of posting this blog entry the detection of the offered '&lt;em&gt;greeting.exe&lt;/em&gt;' file was very poor, with only &lt;em&gt;6 out of 32&lt;/em&gt; tested scanners identifying that this is a malicious file. &lt;br /&gt;&lt;br /&gt;Furthermore the file being offered appears to be a static binary, as in my testing so far all samples downloaded are the same size and produce the same MD5.&lt;br /&gt; &lt;br /&gt;&lt;em&gt;[*] Only really tempting if I had a lobotomy or suffered other severe head or brain trauma which seriously affected my common-sense.&lt;br /&gt;&lt;/em&gt;</description><link>http://momusings.com/momusings/2008/02/free-greetings-for-you.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-6695793105706066646</guid><pubDate>Tue, 12 Feb 2008 10:56:00 +0000</pubDate><atom:updated>2008-02-12T21:07:21.749Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>malware</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>Another Stormy Valentine's Day...</title><description>...Coming To A PC Near You, Soon!&lt;br /&gt;&lt;br /&gt;I hope that you are all ready for a safe and pleasant, if not wonderful, Valentines Day on Thursday?&lt;br /&gt;&lt;br /&gt;It seems that the so-called &lt;em&gt;'Storm Worm Gang&lt;/em&gt;' are back playing cupid again and couldn't resist the opportunity to try and get you to infect your computer again using the guise of a valentine e-card, again. The latest wave of these started early this morning:&lt;br /&gt;&lt;br /&gt;The subjects of the e-mails I've seen so far include:&lt;br /&gt;&lt;blockquote&gt;&lt;em&gt;&lt;br /&gt;Blind Love&lt;br /&gt;Heart pump&lt;br /&gt;Love Rose&lt;br /&gt;Phone Love&lt;br /&gt;With All My Love&lt;br /&gt;Valentine Friends&lt;br /&gt;Happy Valentine's day!&lt;br /&gt;The love Train&lt;br /&gt;You're Super Sweet&lt;br /&gt;Me &amp;amp; You&lt;/em&gt;&lt;/blockquote&gt;&lt;br /&gt;The body of all the e-mails seen so far contain a single line of text and a URL [the usual dotted IP sort, e.g. http://100.123.12.1], here are just a small selection of the text I've seen used so far:&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;A Hearty Wish&lt;br /&gt;Love You&lt;br /&gt;My Heart&lt;br /&gt;Rockin' Valentine&lt;br /&gt;Smiley Kiss&lt;br /&gt;You Stay In My Heart&lt;br /&gt;Valentine Friends&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;Here's a screenshot of one of the email that I've received this morning:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Valentine-Storm-Email-Wave2-1.gif" /&gt;&lt;br /&gt;&lt;br /&gt;If you are foolish enough to click on the link in the email, you'll end up on a page that looks like one of these [these are not all the known permutations], the graphic shown on the website is randomly chosen from a pool of at least 6:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Valentine-Storm-Web-Wave2-1.gif" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Valentine-Storm-Web-Wave2-2.gif" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Valentine-Storm-Web-Wave2-3.gif" /&gt;&lt;br /&gt;&lt;br /&gt;And here is the source of the web page currently in use:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Valentine-Storm-Source-Wave2.gif" /&gt;&lt;br /&gt;&lt;br /&gt;However you spend the day, whatever you do for the '&lt;em&gt;love-of-your-life&lt;/em&gt;', don't become part of the collateral damage of the annual '&lt;em&gt;Valentine's Day [Malware] Massacre&lt;/em&gt;'.&lt;br /&gt;&lt;br /&gt;If I see anymore 'bogus' Valentine's Day e-mails, I'll try and post details here when I can. Also, if&lt;em&gt; you&lt;/em&gt; see any that I haven't yet posted about, then please let me know.&lt;br /&gt;&lt;br /&gt;Hopefully, between us we can try and keep the annual massacre down to a mere scuffle! ;-)&lt;br /&gt;&lt;br /&gt;At the time of posting this blog entry the detection of the offered '&lt;em&gt;valentine.exe&lt;/em&gt;' file was very poor, with only &lt;em&gt;4 out of 32&lt;/em&gt; tested scanners identifying that this is a malicious file.&lt;br /&gt;&lt;br /&gt;Furthermore the file being offered is not a static binary, as in my testing so far each request ends up serving a file which appears to be different in size, I'm not sure whether this is a case of server-side polymorphism or just a pool of pre-compiled executables from which one is chosen at random.&lt;br /&gt;&lt;br /&gt;If I get any further useful data or news then I'll try and update this entry later today or tomorrow.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;UPDATE:&lt;/b&gt; The URLs [Web links] included in the e-mail may also now be domain names containing the word 'moon' which I will omit from the web links I have seen so far, see below:&lt;br /&gt;&lt;br /&gt;&lt;ul style="font-style: italic;"&gt;&lt;li&gt;[the-m-word]starfood.com&lt;/li&gt;&lt;li&gt;destroythe[the-m-word].com&lt;/li&gt;&lt;/ul&gt; I suspect that others will appear shortly, please do not go to those domains as they contain live malware, you have been warned!</description><link>http://momusings.com/momusings/2008/02/another-stormy-valentines-day.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-7181915729559729011</guid><pubDate>Fri, 01 Feb 2008 19:47:00 +0000</pubDate><atom:updated>2008-02-01T19:49:09.198Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>malware</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>papers</category><title>Presenting at The University of Loughborough...</title><description>Once more I have been asked to present at a conference, this time it is one being held at the University of Loughborough in Leicestershire.&lt;br /&gt;&lt;img src="http://www.ucisa.ac.uk/groups/ig/events/AntiVirus/SirDenisRookBuilding.jpg" align="right"&gt;&lt;br /&gt;So, this is another one for me to add to my collection of Universities I've presented/lectured at. These include: The Open University and Warwick University.&lt;br /&gt;&lt;br /&gt;This presentation is on Rootkits, and is an updated version of the one I gave at the Virus Bulletin 2006 conference in Montreal, Canada. If you are interested in finding out more about rootkits, then the paper can be found here: &lt;a href="http://momusings.com/papers"&gt;http://momusings.com/papers&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As usual you will not only find the Rootkit paper there, but also all my published papers and magazine articles too.&lt;br /&gt;&lt;br /&gt;I'm hoping that the weather doesn't cause any issues with the trains, and that the rails have been repaired after &lt;a href="http://news.bbc.co.uk/go/rss/-/1/hi/england/leicestershire/7221590.stm"&gt;this mornings crash&lt;/a&gt; on the same line!&lt;br /&gt;&lt;br /&gt;For those of you that are interested, here is a link to the UCISA website covering the &lt;a href="http://www.ucisa.ac.uk/groups/ig/events/AntiVirus/"&gt;details and agenda&lt;/a&gt; for the event.&lt;br /&gt;&lt;br /&gt;The travel time from where I live is about 3.5 hours each way, so I will probably leave home about 6AM and won't get back until around 9PM, still I might get a chance to write some of my EICAR 2008 paper, or at least some abstracts for the Virus Bulletin 2008 conference.</description><link>http://momusings.com/momusings/2008/02/presenting-at-university-of.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-5315080714015565845</guid><pubDate>Thu, 31 Jan 2008 09:20:00 +0000</pubDate><atom:updated>2008-01-31T14:37:39.782Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>Stealthed Spam, Redux!</title><description>I originally covered this back in &lt;a href="http://momusings.com/momusings/2007/10/stealthed-spam.html"&gt;October of 2007&lt;/a&gt;, but things have, as usual, recently repeated themselves, the spammers that is. This time the stealthed spam is different as new approaches and techniques have been used. However, a quick recap of what I mean by stealth.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;"&lt;em&gt;Here's an interesting trick that the spammers are increasingly using to defeat not only software and hardware anti-spam defences but also "&lt;em&gt;wetware&lt;/em&gt;" anti-spam defences; wetware is the geek/nerd term for you, dear reader, the interface between the chair and the keyboard. ;-)&lt;br /&gt;&lt;br /&gt;Stealth is not a new idea, computer viruses and other malware have been using technique to hide since the very beginning of the problem on IBM  and compatible PCs. In fact the very first virus on this platform '&lt;em&gt;&lt;a href="http://www.f-secure.com/v-descs/brain.shtml"&gt;Brain&lt;/a&gt;&lt;/em&gt;' used stealth. Also, most of you are aware that stealth is widely used by the military, not only to make &lt;a href="http://en.wikipedia.org/wiki/Stealth_technology"&gt;warplanes invisible&lt;/a&gt; [or almost] to radar and other tracking technologies, but also warships.&lt;/em&gt;"&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;So, now you know what I mean by stealth, so what does stealth spam look like, well guess what, you can't see it at first as it is stealthed [hidden], here's some recent examples so you can see what I mean:&lt;br /&gt;&lt;br /&gt;The first one claims to be from '&lt;em&gt;Media Inc.&lt;/em&gt;':&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Stealth-spam1.gif"&gt;&lt;br /&gt;&lt;br /&gt;The second one claims to be from '&lt;em&gt;Windows Live Hotmail&lt;/em&gt;':&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Stealth-spam2.gif"&gt;&lt;br /&gt;&lt;br /&gt;The third and final one claims to be from '&lt;em&gt;A Credit-Card Company&lt;/em&gt;':&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Stealth-spam3.gif"&gt;&lt;br /&gt;&lt;br /&gt;With all of the above examples, all the URLS [web-links] used in the e-mail point to the spammy site and the &lt;em&gt;To&lt;/em&gt; and &lt;em&gt;From&lt;/em&gt; e-mail address used tends to be the same, that being &lt;em&gt;yours&lt;/em&gt;! All the text is probably taken from real newletters/e-mails/websites. These e-mails pass the tests that most of us use to decide if something is spam or not, in other words they pass the '&lt;em&gt;Eyeball&lt;/em&gt;' test fairly easily as they look like genuine e-mails from real companies. The only missing pieces are any remote graphics, which most e-mail programs will not show, at least not by default.&lt;br /&gt;&lt;br /&gt;So, what do they look like when I enable '&lt;em&gt;allow remote images&lt;/em&gt;' in the e-mail program?&lt;br /&gt;&lt;br /&gt;They look like this:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Stealth-spam-revealed1.gif"&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Stealth-spam-revealed2.gif"&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Stealth-spam-revealed3.gif"&gt;&lt;br /&gt;&lt;br /&gt;Yes, you aren't seeing double, the second and third example produce the same result when viewed in an HTML capable e-mail reader or web browser.&lt;br /&gt;&lt;br /&gt;Now they all fail the '&lt;em&gt;Eyeball&lt;/em&gt;' test with ease.&lt;br /&gt;&lt;br /&gt;Why do I call these '&lt;em&gt;Stealthed Spam&lt;/em&gt;'? Well, simply because the spam component is hidden and not in plain view.&lt;br /&gt;&lt;br /&gt;The final screenshot shows part of the HTML source of the final example shown above when it is only showing the image:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Stealth-spam-source3.gif"&gt;&lt;br /&gt;&lt;br /&gt;You can clearly see the other HTML, which doesn't get shown when rendered in a browser or a HTML e-mail reader.&lt;br /&gt;&lt;br /&gt;As they say "&lt;em&gt;&lt;a href="http://en.wikipedia.org/wiki/Shaw_Taylor"&gt;Keep 'em peeled!&lt;/a&gt;&lt;/em&gt;", which means keep your eyes open and stay alert. Or, as other might say, "&lt;em&gt;don't believe everything you see or read&lt;/em&gt;", it may be a clever fake.&lt;br /&gt;&lt;br /&gt;If you see any other interesting new tricks/techniques or file formats being used by spammers then please feel free to send me the details or post the information as a comment. Thanks!</description><link>http://momusings.com/momusings/2008/01/stealthed-spam-redux.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-1148127452781602685</guid><pubDate>Mon, 28 Jan 2008 18:13:00 +0000</pubDate><atom:updated>2008-01-28T18:15:15.659Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>tools</category><category domain='http://www.blogger.com/atom/ns#'>malware</category><category domain='http://www.blogger.com/atom/ns#'>stats</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>papers</category><title>Paper Selected For The EICAR 2008 Conference</title><description>&lt;a href="http://www.eicar.org"&gt;EICAR&lt;/a&gt; have informed me that my abstract has been selected for the EICAR 2008 conference to be held in Laval, France between the 3rd and the 6th of May. &lt;br /&gt;&lt;br /&gt;The abstract for the paper appears below:&lt;br /&gt;&lt;blockquote&gt;&lt;em&gt;The increasing speed of new malware strains being written and released means that security professionals are more likely than ever before to see new malware.&lt;br /&gt;&lt;img src="http://momusings.co.uk/images/sasser2.gif" align="right"&gt;&lt;br /&gt;This means new malware which is not detected by the anti-malware solutions they have deployed in their infrastructure, be it workstation, server, PDA or at the gateway.&lt;br /&gt;&lt;br /&gt;Imagine this scenario: An end-user calls the helpdesk and reports that their system is running very sluggishly when it wasn't a week ago and that they can't access the Windows 'Task Manager' or open a command prompt any more.&lt;br /&gt;&lt;br /&gt;Is this caused by malware or is it a 'user' problem? The virus scanner is right up to date and active, and it says the system is clean, the personal firewall is active too. Where do you go from here? Investigate or rebuild the box?&lt;br /&gt;&lt;br /&gt;How can you tell if the machine is clean or infected by a new malware, with a reasonable level of confidence for your conclusion?&lt;br /&gt;&lt;br /&gt;This paper will look at what tricks, tools and techniques you can use to help establish the true state of the 'suspect' system. It will focus on a step by step approach of what tools to use, what to look for and what to do with any suspicious files. It will also discuss the use of forensic tools in such a scenario, as a last port of call.&lt;br /&gt;&lt;br /&gt;The paper will draw on real scenarios where new [undetected] malware has been responsible for 'odd' system or network behaviour.&lt;br /&gt;&lt;/em&gt;&lt;/blockquote&gt;&lt;br /&gt;All I have to do now, is carry out all the required research and write the paper; should only take me about 3 months. However, as usual they need the completed paper by the &lt;em&gt;17th of March&lt;/em&gt;!&lt;br /&gt;&lt;br /&gt;I've several other ideas for abstracts already sketched out ready for to submit for this years Virus Bulletin conference. Any topics that you think should be covered are most welcome, just drop me a note or leave a comment.</description><link>http://momusings.com/momusings/2008/01/paper-selected-for-eicar-2008.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-678896184006327621</guid><pubDate>Sat, 26 Jan 2008 09:50:00 +0000</pubDate><atom:updated>2008-01-26T09:52:41.375Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>hoax</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>A Shocking Mobile Call...</title><description>I often receive e-mails from people who are either, just forwarding the latest chain mail, urban legend, hoax or scam e-mail, or they send them to me to ask my opinion as I have seen many of these types of e-mails over the last 15 years and can usually spot the real ones from the fake ones very quickly.&lt;br /&gt;&lt;br /&gt;So, yesterday I was sent the following in an e-mail by someone asking me if it was a hoax or not?:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Shocking-Mobile-Call.gif"&gt;&lt;br /&gt;&lt;br /&gt;What do you think, real or hoax?&lt;br /&gt;&lt;br /&gt;Before I give you my answer, I would like to bring to your attention the following data:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;em&gt;Most phones use power adapters that step down the voltage from standard mains [usually in the range of 110-240 Volts] to significantly lower [usually in the range of 3-12 Volts], not only that these power adapters usually have very low ampage [a quick look at several of the ones I have on hand shows that 200ma is fairly typical]. &lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;There have been a number of reports of exploding mobile phones [well actually batteries] over the last few years.&lt;/li&gt;&lt;br /&gt;&lt;br /&gt;&lt;li&gt;Most phone manufacturer instruction manuals contain information which state that it is perfectly safe to use a mobile phone while it is being recharged.&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;My conclusion is that &lt;em&gt;if&lt;/em&gt; this did happen then the phone and/or the power adapter were faulty or damaged and that this caused the effect allegedly witnessed, either that of the building that the person was in at the time suffered from a lightning strike which fed into the mains circuit. However, no such data is supplied and therefore it is almost impossible to corroborate or give any credence to this report. I therefore conclude that it is a hoax.&lt;br /&gt;&lt;br /&gt;If you still think it is real and not a hoax, then I'd suggest you read the full debunk which can be found here:&lt;br&gt;&lt;a href="http://www.snopes.com/horrors/techno/cellcharge.asp"&gt;http://www.snopes.com/horrors/techno/cellcharge.asp&lt;/a&gt;</description><link>http://momusings.com/momusings/2008/01/shocking-mobile-call.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-5007015944803929386</guid><pubDate>Mon, 21 Jan 2008 13:17:00 +0000</pubDate><atom:updated>2008-01-21T13:25:32.088Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>malware</category><category domain='http://www.blogger.com/atom/ns#'>stats</category><category domain='http://www.blogger.com/atom/ns#'>scams</category><category domain='http://www.blogger.com/atom/ns#'>hoax</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>December 2007 Malware Review</title><description>December was another busy month for me as I was writing abstracts for conferences, doing presentations and trying to take some of my holiday entitlement as well as dealing with my usual workload. This meant that I didn't have quite as much time to blog and do trend and sample analysis as I usually do.&lt;br /&gt;&lt;br /&gt;As usual on the malware related security threats front it has been an interesting month with yet more malware using social-engineering to get the victim to infect their computer without the need for the malware author to have to code routines to automate infection. We've also seen lots of activity from scammers and cyber-criminals once more during the month.&lt;br /&gt;&lt;br /&gt;Like previous months, I will cover some statistics from my own sensors and compare those against those from a couple of major anti-virus companies, and finally I will cover new and interesting things that occurred during the month. &lt;br /&gt;&lt;br /&gt;I have created some graphs and performed some trend analysis from the raw data from my WormCharmer and Bayesian filter. I have included four sources of information for the graphs and pie-charts, these are:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.kaspersky.com/"&gt;Kaspersky&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://www.sophos.com/"&gt;SOPHOS&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;WormCharmer&lt;/li&gt;&lt;li&gt;Malware Bayesian Filter&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;The last two are my own projects and all data is from the Internet, these systems are running on an aDSL link and are personal research projects that have been running for some time; WormCharmer 5 years, Malware Bayesian Filter 4 years. &lt;br /&gt;&lt;br /&gt;In total I captured 573 samples during December, which have been catalogued as just 27 distinct families and variants. In comparison during November I captured 476 samples which were also catalogued as 27 distinct families/variants. As you can see the captures in December are up once more, but this time of year is usually quite busy.&lt;br /&gt;&lt;br /&gt;As shown, once more, by December's statistics the general trend is still downwards. It still appears that social-engineering has been the technique of choice and that 2007 should be now known as the year of the social engineer.&lt;br /&gt;&lt;br /&gt;The first pie chart below shows the Top 10 distinct malware by percentage. Let The first pie chart below shows the Top 10 distinct malware by percentage. Let us look at this in more detail: &lt;br /&gt;&lt;br /&gt;During December I reported 65 new Phishing sites which are now included in the Netcraft phishing site database used by the &lt;a href="http://toolbar.netcraft.com/"&gt;Netcraft anti-phishing toolbar&lt;/a&gt; which I blogged about some time ago.&lt;br /&gt;&lt;br /&gt;The first pie chart below shows the Top 10 distinct malware by percentage. Let us look at this in more detail:&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;img alt="" src="http://momusings.com/images/Dec07Top10.gif"&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;W32/Tenga.3666 [Frisk] has continued to hold on to the pole position it took back in April. It now accounts for over 80 percent of the samples captured in December, just short of the high points of 82 percent it had in August.&lt;br /&gt;&lt;br /&gt;As in the top tens for September, October, and November there are still eight members of the Opaserv.worm family in December's chart. These are variants: AE, D, AJ, K, AC, AD, AI and I in second, third, fourth, fifth, sixth, seventh, eighth and tenth places respectively. &lt;br /&gt;&lt;br /&gt;The final slot left is occupied by a re-entry, this being our old friend Dupator who returns to the top ten in ninth place.&lt;br /&gt;&lt;br /&gt;If you compare the above to the data from Kaspersky and also the data from SOPHOS you may see some marked differences. Why? Well, simply my sample capture systems collect data from multiple 'vectors' and combine the data, so I tend to get a more rounded picture of what is really running round the Internet in the way of net nasties. &lt;br /&gt;&lt;br /&gt;Netsky.q [aka P] is back into the top 10, straight back in at pole position, what a comeback! It is joined by another member of the family, AA which is also a re-entry back in at eighth place.&lt;br /&gt;&lt;br /&gt;November's pole sitter, Scano.gen has had to settle for fifth place in December's chart after falling down the chart.&lt;br /&gt;&lt;br /&gt;In the runner-up spot, we have a new entry, this being Diehard.dc, which is not the only member of this new family, as it is joined by Diehard.db and Diehard.dd which are also new entries, straight in to the chart in fourth and seventh place respectively. &lt;br /&gt;&lt;br /&gt;Trojan-Spy.HTML.Fraud.ay has slipped further down the chart from fourth to ninth. &lt;br /&gt;&lt;br /&gt;This month's chart is packed with new entries, the next one is Warezov.xd, straight in to the chart and stealing the final podium place; third.&lt;br /&gt;&lt;br /&gt;And to complete the top ten, we have two more re-entries, these being, Bagle.gt and Nyxem.e [aka MyWife.D] in to the top ten in sixth and tenth places respectively.&lt;br /&gt;Kaspersky had this to say about December's chart:&lt;br /&gt;&lt;blockquote&gt;&lt;em&gt;"At the end of the year, the mail traffic situation suddenly changed. In place of the traditional and somewhat dull domination of the rankings by old email worms, in December we encountered the explosive propagation of a new generation of programs. A new generation which are not worms.&lt;br /&gt;&lt;br /&gt;It's true that first place this month is taken by the veteran NetSky.q worm. It returned with a leap and a bound from beyond the bottom of the rankings, having not figured in our November Top Twenty at all. It made up 20% of mail traffic - that's almost an epidemic, and it's unclear how a worm which has been in existence for almost 4 years, and which is known to all antivirus companies, has continued to survive and spread to the present day."&lt;br /&gt;&lt;/em&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;center&gt;&lt;img alt="" src="http://momusings.com/images/kav-dec-2007.gif"&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Please note:&lt;/strong&gt; SOPHOS are now effectively only using family names for their top ten malware and because of this I will now use the same method for analysing their data.&lt;br /&gt;&lt;br /&gt;IIn the SOPHOS chart we see a different pattern; Netksy has once more regained the runner-up position it last held in October's chart. Last months pole-sitter Troj/Pushdo has further managed to consolidate its hold on pole position.&lt;br /&gt;&lt;br /&gt;Mytob has reversed its slide down the chart, once more climbing back up from sixth to third place. W32/Zafi has continued it progress sliding further down the chart from fifth to sixth place.&lt;br /&gt;&lt;br /&gt;Mydoom which was a re-entry in October's chart has climbed up one place from eighth to seventh place.&lt;br /&gt;&lt;br /&gt;There are two re-entries in December's chart, these are, Troj/Dloadr, back in to the chart in eighth place, and W32/Sality back in to the chart in tenth place. &lt;br /&gt;&lt;br /&gt;W32/Bagle is up one place from tenth to ninth and to complete the chart we have W32/Strati up from ninth to the fourth and finally Mal/Dropper is down one place from fourth to fifth place.&lt;br /&gt;&lt;br /&gt;Here is some commentary on December from Sophos:&lt;br /&gt;&lt;blockquote&gt;&lt;em&gt;"Overall, 0.09 percent of emails, or one in 1111, had malicious attachments in December 2007, with Pushdo retaining its position as the most prevalent email-based malware detected in December."&lt;br /&gt;&lt;/em&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;center&gt;&lt;img alt="" src="http://momusings.com/images/sophos-dec-2007.gif"&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;The final pie chart below shows the Top 10 malware families trapped by percentage. As you can see this includes not only mass-mailers but also share-crawling worms and bots. &lt;br /&gt;&lt;br /&gt;This month the table is still headed up by the September 2005 leader, Tenga. Operserv has had to once more settle for the runner-up spot; second. The final step of the podium, third place, is once more occupied by our old friend Dupator.&lt;br /&gt;&lt;br /&gt;Win32.Zhelatin has managed to consolidate its hold on the final place in the chart; tenth, Win32.Agent falls a single place down from eighth to ninth, and IRC.Zapchast has bucked the trend and climbs up from ninth to fourth place.&lt;br /&gt;&lt;br /&gt;We have three re-entries in December's chart, these are: mIRC-Based back in to the chart in fifth, Hidrag grabs sixth place and W32.Tibs takes seventh place.&lt;br /&gt;&lt;br /&gt;The final place in December's chart is occupied by our old friend Netsky, which has fallen from grace; down from third to eighth place.&lt;br /&gt; &lt;br /&gt;&lt;center&gt;&lt;img alt="" src="http://momusings.com/images/Dec07Top10Fam.gif"&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;If you wish to see the current top 10, then see my external website at &lt;a href="http:/momusings.com"&gt;http://momusings.com&lt;/a&gt;. The data which feeds the WormCharmer stats is updated every 3 minutes 24 hours a day.&lt;br /&gt;&lt;br /&gt;Please feel free to ask questions if you need any clarification on the data, the setup or whatever.&lt;br /&gt;&lt;br /&gt;Now, let's switch to a different method: The following graph shows the percentage of malware that I received and my Bayesian Filtering tool classified correctly. You can see the data for the whole of the period of 2005 - 2007 [up to the end of December] here. This clearly shows that December was busier than both October and November. As shown in the figures for December, the overall trend is still downwards [as far as e-mails with malware attachments are concerned] and we will continue to see less malware being seeded via e-mail. Instead we will continue to see more malware being seeded via links in e-mails, rather than as attachments, such as fake e-cards or targeting particular events, such as Christmas; which can be seen in the What's New section of this blog postine. &lt;br /&gt;&lt;br /&gt;The reason for the jumps during July-September is that I adjusted my filters to classify the e-card notifications used by the 'Storm Worm' gang as malware, even though there are no attachments. This is due to the fact that these e-mails contain links to malware files being hosted on web servers, also the web pages they link to contain a number of exploits to try and automatically infect visitors that are not patched or otherwise protected.&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;img src="http://momusings.com/images/bayes-malware-dec2007.gif"&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;The raw statistics (both CSV and Graphed) can be found in the usual place on my site. If you feel you need access then please contact me to discuss.&lt;br /&gt;&lt;br /&gt;If we look at the overall growth of malware in 2007, it grew from 222,473 [as at the end of 2006] to 358,873 at the end of December. That's a growth of 136,400 new malware strains and/or variants for the whole of 2007. Just in December, the number of new malware found was 9,022.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;What's New?&lt;/strong&gt;&lt;br /&gt;Instead of including commentary here about things I have already written about, I will offer links to other blog entries that may be of interest, topical, or cover some of the interesting occurrences during December 2007.&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://momusings.com/momusings/2007/12/rent-spammer.html"&gt;Rent-a-Spammer [Wednesday, 5 December 2007]&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://momusings.com/momusings/2007/12/six-million-dollar-relative.html"&gt;The Six Million Dollar Relative [Thursday, 6 December 2007]&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://momusings.com/momusings/2007/12/ups-delivery-of-over-one-million-us.html"&gt;UPS Delivery of Over ONE MILLION US Dollars! [Wednesday, 12 December 2007]&lt;/a&gt;&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://momusings.com/momusings/2007/12/dont-let-mrs-santa-get-her-claus.html"&gt;Don't Let Mrs. Santa Get Her Claus... [Monday, 24 December 2007]&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;strong&gt;Conclusions: &lt;/strong&gt;&lt;br /&gt;The current trend of using social-engineering which has been widespread in January - November has continued during December, if anything it has accelerated as can be seen by the examples covered above of the Storm Worm spam runs. In fact I think it would be fair to say that 2007 has been the year of the Social Engineer. In fact after Christmas the Storm Worm gang were working flat out producing new malware, web-sites and spam runs, but more on that, another time.&lt;br /&gt;&lt;br /&gt;Levels of spam are back to around their usual levels after the slight drop in the level of spam during September. The spammers haven't been idle during December as they are still trying out other file formats which they hope will bypass anti-spam defences.&lt;br /&gt;&lt;br /&gt;The phishers have been busy both with new versions of their scams, as shown by the mass of attacks aimed at many of the UK banks during December, especially Natwest, Nationwide and Barclays, again. &lt;br /&gt;&lt;br /&gt;Malware being seeded via e-mail is back, however as we have seen it is different than the malware that used to arrive via e-mail as an attachment. Now they just get you to download the malware and infect your own computer, works just as well and without the need for extra coding as they aim for the weakest link in the security chain; the person using the computer. It seems that the malware authors are taking lessons from the phishers as we have seen several phishing quality 'fake' websites used to get people to infect their own computers. I have shown two examples of this new method being used, in this blog entry.&lt;br /&gt;&lt;br /&gt;As expected December and the run up to Christmas and the New Year was a very busy time of the year for all the bad guys and girls as they took advantage of the season of goodwill to claim even more victims. &lt;br /&gt;&lt;br /&gt;I would like to wish you all a very happy new year, stay safe!&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Links:&lt;/strong&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.viruslist.com/en/analysis?pubid=204791979"&gt;Virus Top Twenty for December 2007&lt;/a&gt; [Kaspersky]&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;a href="http://www.sophos.com/pressoffice/news/articles/2008/01/toptendec07.html"&gt;Top ten viruses and hoaxes for December 2007&lt;/a&gt; [Sophos]&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;strong&gt;Please note:&lt;/strong&gt; &lt;em&gt;December's report may well be the last one I do for the forseable future due to changes in my role.&lt;br /&gt;&lt;/em&gt;</description><link>http://momusings.com/momusings/2008/01/december-2007-malware-review.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-7019549876509169662</guid><pubDate>Tue, 15 Jan 2008 19:36:00 +0000</pubDate><atom:updated>2008-01-15T19:46:26.060Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>malware</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>From Storm With Love...</title><description>It seems that the &lt;em&gt;Storm Worm Gang&lt;/em&gt; have decided that you all need some loving, so they are now sending out fake e-card e-mail notifications informing you how much they love you, because you make their job of building botnets so easy ;-)&lt;br /&gt;&lt;br /&gt;Either that or their calendar is screwed up again; they almost missed Christmas and were then very early for New Year!&lt;br /&gt;&lt;br /&gt;Here's a screenshot of what just one of these new &lt;em&gt;With Love&lt;/em&gt; based emails look like:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Valentine-Storm-Email1.gif"&gt;&lt;br /&gt;&lt;br /&gt;The body text can be one of a number of text strings. The rest of the e-mail is usually a  link, this time they have gone back to using IP addresses rather than actual domain names, not sure why? The IP addresses used are varied, so don't just think that they use just the one shown in the example here.&lt;br /&gt;&lt;br /&gt;Of course, when you click on the link you go to a very nice, but fake &lt;em&gt;e-card&lt;/em&gt; site. &lt;br /&gt;&lt;br /&gt;Here is a screenshot of the web page you could end up on if you click on the link in one of these fake &lt;em&gt;With Love&lt;/em&gt; themed e-mails.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Valentine-Storm-Web1.gif"&gt;&lt;br /&gt;&lt;br /&gt;Here's a screenshot showing the HTML source for the page, does it look familiar? It should as this is almost exactly the same code used during the New Year campaign.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/Valentine-Storm-Source1.gif"&gt;&lt;br /&gt;&lt;br /&gt;The message shown is fake, the  &lt;em&gt;'withlove.exe&lt;/em&gt;' file offered isn't an ecard offering words of love from an admirer, partner or colleague, in other words, if you are unwise enough to download the file and run it you won't get to see an &lt;em&gt;ecard&lt;/em&gt;, in fact you will get a &lt;em&gt;bot&lt;/em&gt; installed instead and your computer will join one of the many &lt;em&gt;Storm Worm&lt;/em&gt; botnets.&lt;br /&gt;&lt;br /&gt;At the time of publishing this entry detection was almost non-existent, with most of the top anti-virus products not detecting the malware laden file as infected, you have been warned.&lt;br /&gt;&lt;br /&gt;As mentioned before, please &lt;strong&gt;do not&lt;/strong&gt; go to these sites and download the files offered, as they are real, live, malware.&lt;br /&gt;&lt;br /&gt;More details on the file currently being offered can be found &lt;a href="http://momusings.com/vsub/2008/01/vs0801002-possible-new-malware-nuwar.html"&gt;here&lt;/a&gt; on my VSUB blog, complete with detection results at the time of publishing.</description><link>http://momusings.com/momusings/2008/01/from-storm-with-love.html</link><author>noreply@blogger.com (Martin)</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-817304909931888080.post-1120611593877943308</guid><pubDate>Tue, 15 Jan 2008 13:11:00 +0000</pubDate><atom:updated>2008-01-15T13:12:54.429Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>all</category><category domain='http://www.blogger.com/atom/ns#'>social-engineering</category><category domain='http://www.blogger.com/atom/ns#'>malware</category><category domain='http://www.blogger.com/atom/ns#'>social-networks</category><category domain='http://www.blogger.com/atom/ns#'>life</category><category domain='http://www.blogger.com/atom/ns#'>spam</category><title>MySpace Storm...</title><description>It seems that the &lt;em&gt;Storm Worm Gang&lt;/em&gt; have finally changed their social engineering tactic from the New Year e-cards that we have been seeing since the &lt;a href="http://momusings.com/momusings/2007/12/late-for-christmas-early-for-new-year.html"&gt;26th of December&lt;/a&gt; until the &lt;a href="http://momusings.com/momusings/2008/01/watch-out-watch-out.html"&gt;2nd of January&lt;/a&gt; when they sent out their last new version of that particular tactic!&lt;br /&gt;&lt;br /&gt;So, what are they now using to get you to infect your computer? They are using fake &lt;em&gt;MySpace&lt;/em&gt; invite e-mails which contain links to phishing quality fake &lt;em&gt;MySpace&lt;/em&gt; websites.&lt;br /&gt;&lt;br /&gt;This seems rather spooky as I was blogging about &lt;a href="http://momusings.com/momusings/2008/01/social-network-engineering.html"&gt;social network engineering&lt;/a&gt; on the 4th of January!&lt;br /&gt;&lt;br /&gt;Here's a screenshot of what just one of these new &lt;em&gt;MySpace&lt;/em&gt;  based emails look like:&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/MySpace-Mal-Email1.gif"&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/MySpace-Mal-Email2.gif"&gt;&lt;br /&gt;&lt;br /&gt;The body text can be one of a number of fake names and text strings. The rest of the e-mail including the links appear to be fairly static, at the moment, anyway. Once more the link is an actual domain name, rather than the more usual IP address based links that the &lt;em&gt;Storm Worm&lt;/em&gt; gang used to use.&lt;br /&gt;&lt;br /&gt;Of course, when you click on the link you go to a very professional, but fake &lt;em&gt;MySpace&lt;/em&gt; site. &lt;br /&gt;&lt;br /&gt;Here is a screenshot of the web page you could end up on if you click on the link in one of these fake &lt;em&gt;MySpace&lt;/em&gt; themed e-mails.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/MySpace-Mal-Website1.gif"&gt;&lt;br /&gt;&lt;br /&gt;In fact there are several links in the e-mail which take you to different domain names, all under the control of the &lt;em&gt;Storm Worm&lt;/em&gt; gang. &lt;br /&gt;&lt;br /&gt;Here's another example showing another domain name in use.&lt;br /&gt;&lt;br /&gt;&lt;img src="http://momusings.com/images/MySpace-Mal-Website2.gif"&gt;&lt;br /&gt;&lt;br /&gt;The message shown is fake, the  &lt;em&gt;'install_flash_player.exe&lt;/em&gt;' file offered isn't genuine, in other words, if you are unwise enough to download the file and run it you won't get a copy of &lt;em&gt;Flash Player&lt;/em&gt; installed, in fact you will get a &lt;em&gt;bot&lt;/em&gt; installed instead and your computer will join one of the many &lt;em&gt;Storm Worm&lt;/em&gt; botnets.&lt;br /&gt;&lt;br /&gt;Just to make it crystal clear, the file offered on this site will &lt;strong&gt;NOT&lt;/strong&gt; install or update &lt;em&gt;Flash Player&lt;/em&gt;; All that will happen is that your computer will be infected and turned in to a &lt;em&gt;zombie&lt;/em&gt; [bot infected computer that is part of a botnet], if it is not protected by any mitigating technologies, such as up-to-date anti-virus, and so on.&lt;br /&gt;&lt;br /&gt;At the time of publishing this entry detection was still very patchy, with a number of the top anti-virus products not detecting the malware laden file as infected, you have been warned.&lt;br /&gt;&lt;br /&gt;As mentioned before, please&lt;strong&gt; do not &lt;/strong&gt;go to these sites and download the files offered, as they are real, live, malware.&lt;br /&gt;&lt;br /&gt;More details on the file currently being offered can be found &lt;a href="http://momusings.com/vsub/2008/01/vs0801001-possible-new-malware-agent.html"&gt;here&lt;/a&gt; on my VSUB blog, complete with detection results at the time of publishing.&lt;br /&gt;&lt;br /&gt;No doubt I'll be updating this post in the next day or so, as the &lt;em&gt;Bad Guys and Girls&lt;/em&gt; tinker with their latest social engineering technique, or they change it to a new one...&lt;br /&gt;&lt;br /&gt;&lt;em&gt;As I post this I have now received over &lt;strong&gt;FIFTY&lt;/strong&gt; of the fake MySpace invite e-mails!&lt;/em&gt;</description><link>http://momusings.com/momusings/2008/01/myspace-storm.html</link><author>noreply@blogger.com (Martin)</author></item></channel></rss>