Dec 21 2008

Hallmark, Coke, and McDonalds: VIRUS Alert

Category: Nerdologyzerolove @ 11:20 pm

I recently posted about sending e-cards, and then I go to work and there is an outbreak. Wouldn’t you know it was started via E-Cards. As of now some virus scanners are picking it up, most are still not. It bothers me when the scanners I would normally trust are not detecting it yet.  Being I use open source scanner I just made my own signature to catch it.

Continue reading “Hallmark, Coke, and McDonalds: VIRUS Alert”

Tags: , , ,


Aug 18 2008

msnbc.com – BREAKING NEWS: VIRUS Alert

Category: Nerdologyzerolove @ 11:56 pm

Well we have another one following on the heals of the CNN Alert and CNN.com Daily Top 10. These are the same and have links to download an updated flash player. The flash player is NOT flash player at all but a trojan.

Some examples of the Subject:

msnbc.com - BREAKING NEWS: All Baseball Players May Be Indicted For Steroid Abuse

msnbc.com - BREAKING NEWS: SJC Loosens Handgun Control To Stimulate Economy

msnbc.com - BREAKING NEWS: Elizabeth Taylor found murdered at home

msnbc.com - BREAKING NEWS: Nature Did Not Connect the Funny Bone to the Satire Bone

They are also starting a BBC NEWS and just a breaking news. None of the From: fields are msnbc, cnn, or BBC. So lets just start calling this the news alert virus. These viruses are based on the assumption that someone they are sending to is signed up to receive the alert. Without looking just clicking links, I know for one I am signed up to receive some of these type of alerts. I guess one of the things that have saved me is I only receive email in plain text and I do not click on the links if they are not from the sending domain. For instance in one of the breaking news from msnbc.com the link goes to www.4×4.co.rs and well this is NOT msnbc.com. So some tips:

If you receive breaking news alerts instead of clicking the link move your mouse over the link and copy the shortcut. Open your web browser and paste it into the web browsers URL field. If the URL is NOT to the site the email came from DO NOT GO TO IT. Delete it from the URL and delete the email.

Remember folks this is a simple one. If you are NOT expecting the email do not open it, especially if it has an attachment. If it is from someone you know and it has an attachment call them and ask “Hey what is this your sending me” if they do not know then do NOT open it. It is just common sense.

If you go to a web site and it wants you to update any software go to the original site to update it. For instance all these trojans want you to update FLASH Player. Go to the Adobe download site at http://www.adobe.com/products/flashplayer/ and update your flash player. Do NOT update it from a web site you do not know. You should never install and or update software from a web site that you do not know.

Others:
http://www.securitywatch.co.uk/2008/08/13/msnbccom-breaking-news-spam/
http://blog.mxlab.be/2008/08/13/msnbccom-breaking-news/
http://www.securitywatch.co.uk/2008/08/13/msnbccom-breaking-news-spam/
http://www.securitymanagement.com/news/beware-msnbc-com-breaking-news-spam-e-mails-004502
http://securitylabs.websense.com/content/Alerts/3159.aspx

Tags: , , , , , , , , ,


Aug 08 2008

CNN Alerts: My Custom Alert - Virus Alert!

Category: Nerdologyzerolove @ 10:32 am

Follow up to yesterdays post about CNN.Com Daily Top 10, today we have a new one. This one has the subject of CNN Alerts: My Custom Alert. The email “From” address is random, and the content looks legit except for the Full Story link. This is the one that takes you to the site that immediately ask for you to install an updated version of flash. This is the virus, the payload…. This virus is part of the Rustock Rootkit and Spam Bot.

Tags: , , , ,


Aug 07 2008

CNN.com Daily Top 10 - Virus Alert!

Category: Nerdologyzerolove @ 1:18 pm

Recently I wrote about the “UPS, FedEx, and US Customs Email Virus” today I want to tell you about the CNN.Com Daily Top 10 email going out. I’m seeing this from allot of different sources and it is pretty heavy out in the wild. I’m sure you have probably already seen it somewhere. The interesting points of this one, the virus payload is not in the email but from the links in the email. This allows it to by pass most virus scanners. It is NOT From: user@cnn.com but from a randomly generated or infected users email address. The links in the email take you to sites, not cnn.com, that want to show you a video but says you have the wrong flash player installed. Other points:

  • The URL’s are not cnn.com
  • The writing is poor (even worst then mine)
  • It ask you to install Flash Player 0
  • The ActiveX installer does not seem like a standard ActiveX installer
  • It is not digitally signed.
CNN Daily Top 10

CNN Daily Top 10

Tags: , , , ,