What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
Reply to this topicStart new topic
> SPAM frauds, fakes, and other MALWARE deliveries...
AplusWebMaster
post Jul 31 2008, 04:55 AM
Post #91


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,577
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Airlines - infected ticket invoices...
Attachment contains same Trojan horse that stole 1.6M records from Monster.com last year
- http://preview.tinyurl.com/66ayhz
July 28, 2008 (Computerworld) - "Several airlines, including Delta Air Lines Inc. and Northwest Airlines Corp., have warned customers that bogus e-mails posing as ticket invoices contain malware and urged them to immediately delete the messages. A researcher at McAfee Inc. confirmed the campaign in a post to the company's blog*. The e-mails, which purport to be from an airline, thank the recipient for using a new "Buy flight ticket Online" service on the airline's site, provide a log-in username and password, and say the person's credit card has been charged an amount usually in the $400 range. An attachment claims to be the invoice for the ticket and credit card charge..."
* http://www.avertlabs.com/research/blog/ind...m-takes-flight/

More...
- http://www.f-secure.com/weblog/archives/00001477.html
July 30, 2008 - "... Today when we saw a large spam run sending out fake JetBlue etickets... The mail contains a ZIP file that contains the file eTicket#1721.exe which we detect as Trojan-Spy:W32/Zbot.QO. The malware itself tries to steal usernames and passwords to online banks..."
(Screenshot available at the F-secure URL above.)

- http://www.us-cert.gov/current/#airline_e_...et_email_attack
July 31, 2008

ph34r.gif dry.gif

This post has been edited by AplusWebMaster: Aug 5 2008, 04:29 AM
Go to the top of the page
 
+Quote Post
 
Start new topic
Replies
AplusWebMaster
post May 22 2009, 08:27 AM
Post #92


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,577
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

Malicious iFrame on Gadgetadvisor.com
- http://www.f-secure.com/weblog/archives/00001687.html
May 22, 2009 - "Are you a gadget geek? Do you often seek advice from Gadget Advisor before making a purchase? Our Web Security Analyst discovered a malicious IFrame on the popular tech website that redirects visitors to a malicious website... If the site detects a PDF browser plugin for Adobe Acrobat and Reader, it loads a specially-crafted malicious PDF file that exploits a stack-based buffer overflow vulnerability ( http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-2992 ). The net effect of the attack is to plant a trojan, detected as Trojan-Downloader.Win32.Agent.brxr, on vulnerable systems by calling the util.printf JavaScript function, which connects back to the malicious website in order to download the trojan to the machine. A remote attacker can access the user's machine once it has been infected with the trojan... This attacks is targeted against older, unpatched version of Adobe programs, as the latest Adobe updates have already fixed this problem. More information and the updates can be found at Abobe at:
http://www.adobe.com/support/security/bull.../apsb08-19.html. Disabling the JavaScript function in Acrobat and Reader will also prevent the threat from proceeding."

(Screenshot available at the F-secure URL above.)

ph34r.gif dry.gif
Go to the top of the page
 
+Quote Post

Posts in this topic
- AplusWebMaster   SPAM frauds, fakes, and other MALWARE deliveries...   Jul 31 2008, 04:55 AM
- - AplusWebMaster   FYI... ID theft malware rates... - http://preview...   Mar 10 2009, 08:09 AM
- - AplusWebMaster   FYI... TinyURL phishing... - http://blog.trendmic...   Mar 13 2009, 08:09 AM
- - AplusWebMaster   FYI... Malicious SPAM run(s), again... - http://w...   Mar 13 2009, 02:53 PM
- - AplusWebMaster   FYI... More rogues... - http://sunbeltblog.blogsp...   Mar 14 2009, 01:18 PM
- - AplusWebMaster   FYI... Waledac - SPAM new variant theme in the wi...   Mar 16 2009, 08:17 AM
- - AplusWebMaster   FYI... 2000 percent increase in web threats - 200...   Mar 18 2009, 02:24 PM
- - AplusWebMaster   FYI... SPAM - fake Comcast, Facebook e-mails - ht...   Mar 20 2009, 04:27 AM
- - AplusWebMaster   FYI... Antivirus2009 ransomware... - http://previ...   Mar 20 2009, 09:34 AM
- - LDTate   Self Help Guide also found here. http://forums.wha...   Mar 20 2009, 06:35 PM
- - AplusWebMaster   FYI... Trafficconverter takedown... - http://www....   Mar 23 2009, 07:52 AM
- - AplusWebMaster   FYI... Trafficconverter takedown - Downadup motiv...   Mar 24 2009, 04:35 AM
- - AplusWebMaster   FYI... More Malicious SPAM from Pushdo... - http:...   Mar 25 2009, 07:26 AM
- - AplusWebMaster   Some references previous post in this thread: - ht...   Mar 25 2009, 11:40 AM
- - AplusWebMaster   FYI... Ghostnet - targeted attacks - http://www.f...   Mar 29 2009, 06:33 PM
- - AplusWebMaster   FYI... Conficker hype used by rogue gangs - http:...   Mar 30 2009, 04:21 PM
- - AplusWebMaster   FYI... Trace Q1-2009 report - http://www.marshal....   Apr 2 2009, 01:39 PM
- - AplusWebMaster   FYI... More Conficker rogue AV... - https://forum...   Apr 3 2009, 10:07 AM
- - AplusWebMaster   FYI... Malicious Excel XLS file - http://www.f-se...   Apr 7 2009, 08:13 PM
- - AplusWebMaster   FYI... Match.com malware SPAM - http://securityla...   Apr 8 2009, 05:19 AM
- - AplusWebMaster   FYI... IRS SPAM fakes and phish... - http://blog....   Apr 8 2009, 06:26 AM
- - AplusWebMaster   FYI... Rogue AV on 10M machines - http://www.dark...   Apr 9 2009, 09:44 AM
- - AplusWebMaster   FYI... NOT the easter egg you were expecting - ht...   Apr 10 2009, 01:54 PM
- - AplusWebMaster   FYI... Easter worm in Twitter... - http://www.f-s...   Apr 12 2009, 11:18 AM
- - AplusWebMaster   FYI... Copycat Twitter XSS worms... - http://isc....   Apr 13 2009, 01:34 PM
- - AplusWebMaster   FYI... Twitter worm Google searches lead to malwa...   Apr 14 2009, 04:55 PM
- - AplusWebMaster   FYI... New rogue: P Antispyware 09 - http://sunbe...   Apr 15 2009, 06:44 AM
- - AplusWebMaster   FYI... Yet another Twitter worm - http://www.f-se...   Apr 17 2009, 06:24 PM
- - AplusWebMaster   FYI... New rogue: AV Antispyware - http://sunbel...   Apr 19 2009, 04:51 AM
- - AplusWebMaster   FYI... Zango: The End - http://www.vitalsecurity....   Apr 21 2009, 05:38 AM
- - AplusWebMaster   FYI... Spam referencing Swine flu outbreak - http...   Apr 27 2009, 01:09 PM
- - AplusWebMaster   FYI... Rogue AV projected growth in 2009 - http:/...   Apr 28 2009, 03:45 PM
- - AplusWebMaster   FYI... Facebook phishing attack - http://preview....   Apr 30 2009, 05:10 AM
- - AplusWebMaster   FYI... - http://sunbeltblog.blogspot.com/2009/04/...   Apr 30 2009, 03:54 PM
- - AplusWebMaster   FYI... More Swine/Mexican/H1N1 related domains - ...   May 2 2009, 02:19 PM
- - AplusWebMaster   FYI... IFrame redirects lead to MBR rootkit - htt...   May 4 2009, 04:41 AM
- - AplusWebMaster   FYI... Facebook phishing malware - http://isc.san...   May 4 2009, 10:20 AM
- - AplusWebMaster   FYI... H1N1 Domains - http://www.f-secure.com/web...   May 4 2009, 07:33 PM
- - AplusWebMaster   FYI... Waledac Turns to Cash and Vaccines w/SPAM ...   May 6 2009, 04:19 AM
- - AplusWebMaster   FYI... Targeted attacks - most common file types ...   May 7 2009, 08:48 AM
- - AplusWebMaster   FYI... Rogue Browser Agents - http://www.f-secure...   May 18 2009, 03:55 PM
- - AplusWebMaster   FYI... eBay phishing Scam... - http://www.sophos....   May 20 2009, 10:13 AM
- - AplusWebMaster   FYI... Malicious iFrame on Gadgetadvisor.com - ht...   May 22 2009, 08:27 AM
- - AplusWebMaster   FYI... Facebook phishing/spam/"worm" .....   May 25 2009, 04:39 AM
- - AplusWebMaster   FYI... Facebook phishing using Belgium (.be) doma...   May 26 2009, 05:45 AM
- - AplusWebMaster   More on same... Koobface... again - http://securi...   May 27 2009, 08:04 AM
- - AplusWebMaster   FYI... Another "Digital Certificate" ma...   Jun 1 2009, 03:19 PM
- - AplusWebMaster   FYI... Twitter hit with rogue anti-virus scam - h...   Jun 1 2009, 11:28 PM
- - AplusWebMaster   FYI... More Blackhat SEO "scareware" ca...   Jun 9 2009, 06:48 AM
- - AplusWebMaster   FYI... Malicious SPAM - Air France plane crash - ...   Jun 11 2009, 11:05 AM
- - AplusWebMaster   FYI... Fake MSRT... - http://preview.tinyurl.com/...   Jun 12 2009, 01:07 PM
- - AplusWebMaster   FYI... SPAM - Fake EULAs, fixtools... - https://f...   Jun 13 2009, 12:13 PM
- - AplusWebMaster   FYI... Rogue AV hosted in USA... - http://sunbelt...   Jun 15 2009, 10:09 AM
- - AplusWebMaster   FYI... - https://forums2.symantec.com/t5/blogs/bl...   Jun 15 2009, 02:17 PM
- - AplusWebMaster   FYI... Fake MS Update SPAM... - http://blog.trend...   Jun 22 2009, 08:20 PM
- - AplusWebMaster   FYI... Nonstop site re-infections - http://securi...   Jun 24 2009, 05:12 PM
- - AplusWebMaster   FYI... Zbot In Your Inbox - http://www.marshal8e6...   Jun 25 2009, 05:36 AM
- - AplusWebMaster   FYI... SPAM runs exploit celebrity deaths - http:...   Jun 26 2009, 06:01 AM
- - AplusWebMaster   FYI... MSN IM - Pushdo variant... - http://blog.t...   Jun 28 2009, 03:15 PM
- - AplusWebMaster   FYI... More celebrity malware... - http://www.f-s...   Jun 29 2009, 02:01 PM
- - AplusWebMaster   FYI... Torrentreactor site compromised - http://s...   Jul 1 2009, 04:56 PM
- - AplusWebMaster   FYI... Click fraud trojan... - http://secureworks...   Jul 2 2009, 01:37 PM
- - AplusWebMaster   FYI... Happy 4th from Waledac... - http://securit...   Jul 3 2009, 04:01 PM
- - AplusWebMaster   FYI... More on Waledac for the 4th... - http://bl...   Jul 4 2009, 10:49 AM
- - AplusWebMaster   FYI... Waledac July 4th update - New domains adde...   Jul 5 2009, 07:26 PM
- - AplusWebMaster   FYI... Koobface worm infections exploding - http:...   Jul 6 2009, 11:11 AM
- - AplusWebMaster   FYI... Twitter suspends Koobface infected compute...   Jul 10 2009, 07:10 AM
- - AplusWebMaster   FYI... H1N1 SPAM w/virus... - http://www.f-secure...   Jul 21 2009, 06:02 AM
- - AplusWebMaster   FYI... Targeted malware calling home... - http://...   Jul 23 2009, 05:17 PM
- - AplusWebMaster   FYI... Rogue AV terminates EXE files - http://blo...   Jul 27 2009, 06:39 AM
- - AplusWebMaster   FYI... Malicious Twitter Posts Get More Personal ...   Jul 27 2009, 03:01 PM
- - AplusWebMaster   FYI... Dilbert sends out 419 scams... - http://ww...   Jul 31 2009, 05:27 AM
- - AplusWebMaster   FYI... Rogueware growth - 2009 ... - http://www.d...   Jul 31 2009, 05:44 AM
- - AplusWebMaster   FYI... Q2-2009 - $34m in Rogueware per month...   Aug 10 2009, 06:52 AM
- - AplusWebMaster   FYI... PayPal fraud with CAPTCHA - http://blog.tr...   Aug 11 2009, 07:38 PM
- - AplusWebMaster   FYI... Spam changes HOSTS file... - http://blog.t...   Aug 14 2009, 05:35 AM
- - AplusWebMaster   FYI... Facebook apps used for phishing - http://b...   Aug 20 2009, 09:29 AM
- - AplusWebMaster   FYI... Employers block social networking, web sur...   Aug 24 2009, 04:19 AM
- - AplusWebMaster   FYI... Cybercrime Hub in Estonia - http://blog.tr...   Aug 26 2009, 05:22 AM
- - AplusWebMaster   FYI... Malware in the mail... - http://www.thereg...   Aug 27 2009, 06:31 PM
- - AplusWebMaster   FYI... Rogue AV goes Green - http://securitylabs....   Sep 2 2009, 04:06 PM
- - AplusWebMaster   FYI... Malicious blogs on Blogspot... - http://ww...   Sep 4 2009, 10:40 AM
- - AplusWebMaster   FYI... Swine flu SPAM leads to malware - http://b...   Sep 6 2009, 05:04 AM
- - AplusWebMaster   FYI... WordPress worm circulating... > http://...   Sep 7 2009, 07:22 AM
- - AplusWebMaster   FYI... Koobface attacks on Facebook and MySpace.....   Sep 8 2009, 06:34 AM
- - AplusWebMaster   FYI... Bogus work-at-home schemes... - http://voi...   Sep 10 2009, 06:12 AM
- - AplusWebMaster   FYI... FakeAV for 9/11 - http://blog.trendmicro.c...   Sep 11 2009, 06:02 AM
- - AplusWebMaster   FYI... Google Groups trojan - http://www.symantec...   Sep 11 2009, 08:20 PM
- - AplusWebMaster   FYI... NY Times pushes Fake AV malvertisement - h...   Sep 14 2009, 05:57 AM
- - AplusWebMaster   FYI... Fake A/V hacks for another celebrity death...   Sep 15 2009, 06:22 AM
- - AplusWebMaster   FYI... Rogue Anti-Virus SEO Poisoning... - http:/...   Sep 17 2009, 03:29 AM
- - AplusWebMaster   FYI... PBS site hacked - used to serve exploits -...   Sep 19 2009, 08:33 AM
- - AplusWebMaster   FYI... Fake Twitter accounts for Fake AV - http:/...   Sep 21 2009, 04:20 AM
- - AplusWebMaster   FYI... Monopoly Game malware... - http://security...   Sep 21 2009, 04:46 PM
- - AplusWebMaster   FYI... Fake Malwarebytes - Bogus Sponsored Link L...   Sep 24 2009, 08:07 AM
- - AplusWebMaster   FYI... Malvertisements - weekend run... - http://...   Sep 25 2009, 08:19 AM
- - AplusWebMaster   FYI... Fake IRS email SPAM - w/Zeus Trojan... - h...   Sep 28 2009, 05:42 AM
- - AplusWebMaster   FYI... Phishing attacks reach record levels in Q2...   Sep 28 2009, 07:23 AM
- - AplusWebMaster   FYI... Tropical Storm leads to FAKEAV - http://bl...   Sep 29 2009, 01:49 PM
- - AplusWebMaster   FYI... Rogue downloader uses Firefox warning scre...   Sep 30 2009, 05:20 AM
- - AplusWebMaster   FYI... Fraudsters on social networking sites - ht...   Oct 1 2009, 10:34 PM
3 Pages V  < 1 2 3 >


Reply to this topicStart new topic

 


RSS Time is now: 22nd March 2010 - 04:20 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy