Blog

Insights on Data Security & Threat Intelligence

Increased usage of unregistered spam domains

Consider a spam email that promotes an online casino site. URL check and filtering systems that block access to such sites usually run a few checks before adding the URL to the “spam” category. One of these checks is that the URL is registered. Once this is known the date

Read More >

Updated: Aisha Gaddafi plea for he..

Scammers have been quick to capitalize on the death of Muammar Gaddafi by sending out emails from Ayesha Gaddafi. Ayesha (also spelled Aisha) is the daughter of Muammar Gaddafi who has reportedly fled to Algeria. The creators of the email seem to have made an error by including the message

Read More >

Results of our compromised/hacked/stolen accounts survey

In Late September we posted a survey where we asked you to tell us your stolen account stories. We have summarized the results in a special report “the state of hacked accounts” The data reveals that most users get hacked at high rates even when they do not think they

Read More >

Facebook scam promises free Macbook Air

Compromised Facebook accounts are being used to send out scam posts promising free Apple Macbooks. The scam does not make reference to the death of Steve Jobs as others have. The link leads to marketing affiliate sites that ask for a user’s mobile phone number – users are then signed

Read More >

Malware Uses New DLL Loading Technique – MS11-071

It has been a year since we have witnessed a DLL hijacking technique which loads a malicious DLL that affects hundreds of programs. The method involves dropping a collection of normal files together with the malicious DLL from within a directory. We recently analyzed the following archive sample. Only the

Read More >

Twice as bad: speeding ticket with attached malware

Nobody likes receiving a traffic ticket, but one with attached malware is a lot worse. We could get into a philosophical argument about which is truly more terrible – a traffic ticket that adds points to your license and raises your insurance rates, or malware that infiltrates your PC, insinuating

Read More >

Updated: NACHA Payment cancelled – scam continues

In February 2011, NACHA alerted the public about fraudulent emails being distributed that appeared to be sent from NACHA and signed by a non-existent NACHA employee. We reported this campaign back in June 2011 but it has come back in the past 2 weeks with a new twist to trick

Read More >