Blog

Insights on Data Security & Threat Intelligence

How PDF Files Hide Malware & Malicious Code

Chances are likely that your business uses Adobe Reader on a regular basis in order to read Portable Document Format (PDF) files. Adobe Reader, formerly known as Acrobat Reader, is the number one program that is used to handle and read PDF files. Adobe Reader unfortunately has a history of

Read More >

Analysis of an online phishing attack targeting Bank of America customers

The attack begins with a message that comes from a spoofed “Bank of America” sender (such as: RiskDept@hotmail.com, or RiskDept@msn.com). See sample below (note the very advanced date):  The attached file, BillingVerification.exe, is a self-extracting archive which contains and automatically loads an html page in the recipient’s browser. The file

Read More >

EXCLUSIVE!! The spam to watch for during Super Bowl XLV breaks

Yes! Take a break from the football, half-time show and amazing ads, head on over to you PC, and be on the lookout for these subjects: *hot* turnkey nfl football site for quick superbowl cash!  cash landslide means winning today thru the superbowl happy super bowl cash weekend. sure winner.

Read More >

Mass emailings support change in Egypt, and now Syria

In addition to the much publicized use of Facebook and Twitter to organize protests, supporters of change in Egypt have also been using good old email to spread the word. The emails appear to be spreading using the traditional “forward this to all your contacts”. The subjects include: Stand with

Read More >

Turkey Ministry of Finance vehicle sale – leads to banking Trojan

The attack starts with a spoofed email which claims to be from the Ministry of Finance in Turkey (FROM: “MALIYE BAKANLIGI”<bilgi@maliye.gov.tr>). Below is the translated email (courtesy of Google translate):  The RAR archive attachment which seems to include the list of cars for sale, actually contains a file with a

Read More >

Malware spread via Facebook Chat

Facebook chat messages containing malicious links are being sent from compromised Facebook accounts. The messages are typically sent to all of the compromised user’s friends.  The distribution of the malware includes the following steps Legitimate website is hacked A new folder is created on the hacked site including malware (an

Read More >

419 me once, shame on you; 419 me twice, shame on me

Attention, After proper and several investigations and research at Western Union and MoneyGram Office, we found your name in Western Union database amongst those that have sent money through Western Union to Nigeria and this proves that you have truly been swindled by those unscrupulous persons by sending money to

Read More >

Kama Sutra Virus – a position you don’t want to get into…

Partner Cyberoam* brought this one to our attention. The kamasutra virus is being transferred in the form of a downloadable PPT/PPS file link. When the “presentation” (actually an exe file) is opened, users are treated to “illustrated” Kama Sutra positions. In the background the malicious code installation is started along

Read More >