Showing posts with label email. Show all posts
Showing posts with label email. Show all posts

Thursday, May 23, 2013

Microsoft Issues Worldwide Virus Alert

The talk and the footprint of computer viruses in the online world had reduced significantly in the last year. Hackers and online miscreants had moved on to other methods of attacking computers as viruses were considered to be too weak. But Microsoft recently announced that the trend is all set to change in the coming days. A security expert from the IT giant said that hackers were reverting back to the usage of viruses and coming up with innovative attack vectors. He said that this year, the world will witness a significant increase in the usage of viruses for attacking computers (both personal and corporate).

Low Broadband Penetration Rate


computervirus

Tim Rains, the security expert who announced the news, said that Microsoft was monitoring the virus trends on the World Wide Web and noticed a spike in the volume of viruses for the first time. He said that low broadband penetration rate has increased the chances of a computer getting infected with any of the malicious software, including Trojans and worms. He said that this trend is being exploited by hackers and they are using viruses more actively to infect broadband connected computers (which is almost every internet enabled computer today). Microsoft also added that they had traced the infections to as far as Egypt, Pakistan, and Bangladesh.

Viruses Are Easy to Eliminate


Rains said that even today, viruses are very easy to be removed as their signatures can be easily detected and tracked. He said that users are expected to keep their anti-virus systems updated which will significantly reduce the chances of being attacked by a virus.

[via NBC News ]

Thursday, April 18, 2013

Texas Plant Explosion Spam Leads to Malware Attack

Spam emailConsidering cybercriminals jumped on the opportunity to spread malware by sending spam related to Monday’s Boston marathon bombing, it’s not all that surprising that they’re now doing the same with yesterday’s fertilizer plant explosion in West, Texas.

Here are some of the subject lines to watch out for:

  • West TX Explosion

  • Waco Explosion HD

  • Texas Plant Explosion

  • Texas Explosion Injures Dozens

  • CAUGHT ON CAMERA: Fertilizer Plant Explosion Near Waco, Texas

  • Raw: Texas Explosion Injures Dozens


Like the marathon-themed emails, the spam messages tied to the new fertilizer plant explosion trick users into following malicious links by promising video footage of the devastating event.

Texas Explosion Email



Image Credit: Sophos


While it’s true that the victim is presented with a series of embedded videos related to the incident, they are also being exposed to the misdeeds of the Redkit exploit kit, which will use Adobe PDF or Java vulnerabilities to silently install malware on the victim’s computer.

Avoiding these attacks should be relatively easy – don’t follow links in unsolicited emails. Aside from that, keeping your operating system (& installed software) up-to-date and running antivirus software should help your PC remain malware-free.

Have you received any suspicious emails related to the plant explosion or marathon bombing? Share your experiences below and get the word out to help protect others!

[via Sophos][via AppRiver]

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

Wednesday, April 17, 2013

Spammers Exploit Boston Marathon Bombing to Spread Malware

Warning!Click with caution if you receive unsolicited emails or find yourself wanting to click a website link related to the deadly bombing attack at the Boston Marathon on Monday.

Antivirus firms Avira and Sophos, along with email security provider AppRiver have already intercepted emails from spammers aspiring to dupe users into following malicious links by offering links to video footage of the attacks.

There are a variety of domain names and subject lines associated with this spam campaign; some of the subject lines in use are:

  • Explosion[s] at Boston Marathon

  • Boston Explosion Caught on Video

  • Aftermath to explosion at Boston Marathon

  • Video of Explosion at the Boston Marathon 2013

  • Runner captures. Marathon Explosions

  • 2 Explosions at the Boston Marathon


The body of the email appears to contain nothing more than a link pointing to a website that has legitimate videos from the attack. However, that same site is rigged with malicious code that will attempt to exploit Java plugin vulnerabilities in order to drop a backdoor Trojan on your machine.

Avira identifies the threat as TR/Crypt.ZPACK.Gen, while Sophos identifies it as Troj/Tepfer-Q.

Upon a successful infection, TR/Crypt.ZPACk.Gen (or Troj/Tepfer-Q) will modify the system registry and connect to a remote server, granting an attacker remote access to the affected PC.

Tips to Keep Your PC Safe


Avira warns that malicious links may also be posted on Facebook, so users should also exercise caution when following links shared on social networks. Here are a few other bits of advice to help keep your computer malware-free:

  • Do not click links or download files attached to unsolicited emails.

  • Stick to the official websites of your favorite news channel to get the latest updates.

  • Keep your operating system and installed third-party software fully patched and up-to-date.

  • Always run antivirus software and keep the virus definitions current.


Did You Already Fall for It?


Both Avira and Sophos offer security products capable of detecting and removing the malware being spread by these online attacks. So if you have the sinking feeling that you may have followed a bad link, you may want to try performing a full system scan using one of their products.

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

Friday, April 12, 2013

American Airlines Spam Spreads Backdoor Trojan

American AirlinesWebroot is cautioning users not to fall for spam emails posing as a notification from American Airlines stating that their ticket is all set and ready for download.

This spam campaign isn’t exactly new, although previous versions may have had malicious files attached directly to the email itself.

Here’s what the current variant looks like:

 American Airlines Phishing Email



American Airlines

Customer Notification

Your bought ticket is attached to the letter as a scan document.

To use your ticket you should Download It.

The embedded link will prompt users to download an executable, “Electronic Ticket.exe” that only 10/46 antivirus will identify as malware.

Dr. Web antivirus detects the threat as BackDoor.Kuluoz.4. Once it has infected your system, BackDoor.Kuluoz.4 will modify system files, inject itself into system processes and connect to a list of command & control servers.

Did You Get this Spam Email?


If you received a copy of this spam email, it is advised that you:

  • Do not click on any links within the email.

  • Do not download any files that may be attached or linked from this email.

  • Forward a copy of the email, including the header to webmaster@aa.com.

  • Delete the email immediately.


If You Downloaded Any Files...


If you made the mistake of clicking the link or opening any files attached to spam emails resembling the one above, you are advised to perform a full system scan using an antivirus solution offered by one of the following vendors:

Their products are capable of detecting and removing the threat associated with this attack. Be sure to be more careful in the future!

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

Thursday, April 4, 2013

Watch Out for Fake HP Printer Scan Emails

Email Security WarningKeep an eye out for fraudulent emails claiming that a document was scanned and sent to you from your office Hewletter-Packard ScanJet printer.

Sophos warns that spammers are once again sending out bogus scan-to-email notices in an attempt to dupe users into clicking malicious links that lead to websites serving malware.
Subject: Fwd: Re: Scan from a Hewlett-Packard ScanJet #1788378

A document was scanned and sent to you using a Hewlett-Packard HP9289197

Sent to you by: PEARLIE
Pages: 3
Filetype(s): Images (.jpeg) View

This isn’t the first time that spammers mimicked document-to-file scan notifications, but previous attempts involved malicious file attachments vs. links in the email itself.

The malware served in the attack was not disclosed; however, the websites associated with this attack are rigged with the BlackHole exploit kit, which typically leverages PDF, Flash & Java vulnerabilities in order to plant malware on the visiting machine.

So, keep your computer safe by:

  • Not following links embedded in unsolicited emails – at least not without investigating them first.

  • Running antivirus software that offers real-time scanning & keep the virus definitions current. (Btw, Sophos blocks the page as Mal/ExpJS-N.).

  • Keeping your operating system and third-party software fully patched & up-to-date.


If you’ve already clicked the link, run a full system scan to detect & remove any potential malware that may have been installed on your computer.

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

Monday, March 18, 2013

Experian Spam Used to Spread Data-Stealing Trojan

Computer Trojan HorseDon’t open any files attached to emails purporting to be from Experian, claiming that a “key change” has been posted to “one of your three national credit reports.”

Spammers are pumping out Experian phishing emails in an attempt to infect as many computers as possible with malware.

Below is a copy of the email to watch out for:
From: Experian
Subject: IMPORTANT – A Key Change Has Been Posted

Experian

Membership ID #932823422

A Key Change Has Been Posted to One of Your Credit Reports

A key change has been posted to one of your three national Credit Reports. Each day we monitor your Experian, Equifax, and TransUnion Credit Reports for key changes that may help you detect potential credit fraud or identity theft. Even if you know what caused your Report to change, you don’t know how it will affect your credit, so we urge you to do the following:

  • View detailed report by opening the attachment.

  • You will be prompted to open (view) the file or save (download) it to your computer.

  • For best results, save the file first, then open it in a Web browser.

  • Contact our Customer Care Center with any additional questions.


Note: The attached file contains personal data.

Your Experian.com membership gives you the confidence you need to look after your credit. We encourage you to log-in regularly to take full advantage of the benefits your membership has to offer, such as unlimited access to your Credit Report and Score Tracker. Notifications like this are an important part of your membership, and in helping you stay on top of your credit.

*If it has been less than thirty days since you joined Experian.com, your monthly credit statement includes your information for the period of time you have been enrolled.

© 2013 Consumerinfo.com, Inc.

The danger of this email lies within the attached file, Credit_Report_XXXXXXXXX.zip which contains an .exe file with the same name and a misleading PDF icon. A virus total scan of the exe reveals that it is actually PWS:Win32/Fareit, and not a credit report as the email suggests (big surprise there).

Did You Receive This Email?


If this email lands in your inbox, be sure that you:

  • Do not download or open any attached files.

  • Report the email to SpamCop.

  • Delete the email immediately.


Did You Already Open the Attached File?


According to Virus Total, 29/46 antivirus programs are capable of detecting the threat associated with this spam campaign, so double-check the VT results and make sure your antivirus can catch it.  Then, do a full system scan and remove any detected threats.

[via DataProtectionCenter.com]

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.

Thursday, March 14, 2013

Spam: Surprise! That 40% Apple Discount Coupon is Actually ZeuS Banking Malware

AppleIf you get an email offering a coupon to get 40% off Apple products – don’t open the file attached!

Spammers have been sending out emails with bogus coupons that can allegedly be used to shave 40% off the cost of a shiny new iMac, Macbook, or whatever other Apple product the recipient chooses to use it on.

Unfortunately, the only thing enclosed in the file attached to the email, Apple coupon.zip is a copy of the ZeuS Trojan, which will cost the victim money - not help save it - since it steals banking information.

Here's the email to watch out for:

Apple Discount Coupon Spam



From: Apple Inc.
Subject: You are the one!

One out of thousand!

Only 1000 people have been chosenas winners and you turned out to be one of them!

We?d like to offer you a 40% discount coupon for any Apple production (it?s attached to this email). You can buy a MacBook, iPod, iPhone or anything else Apple products you want! All you need to do is print it out and present at the checkout.
So, next time you go to BestBuy, Circuit City or Apple Store you are able to save up to 40% of any purchase of Apple production.

The discount coupon is accepted in Circuit City, Apple Store ot BestBuy

All the rules and detailed information about the lottery are also can be found in the attachments to this email.

Congratulations!

Did You Get This Email?


If you get an email like the one above, it is recommended that you:

  • Do not download or open any files attached to it.

  • Report the email to SpamCop.

  • Delete the email immediately.


[via Barracuda]

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.

BBB “Your Accreditation Terminated” Spam Spreads Cridex Worm

BBB - Better Business BureauSpammers are extorting the Better Business Bureau brand in a new spam campaign focused on infecting computers with the Cridex worm.

The spam messages do their best to entice users to click the embedded hyperlinks by claiming that their BBB accreditation has been terminated due to consumer complaints. However, recipients should be able to tell that the email is a fake since it is riddled with mindless grammar & spelling mistakes. ("Beaureau"? Really?)

Below are two variants that are currently circulating:
Your Accreditation Terminated

The Better Business Bureau has been temporary Terminated Your Accreditation
A number of latest complaints on you / your company motivated us to transitory Abort your accreditation with Better Business Beaureau. The information about the our decision are available for review at a link below. Please pay attention to this question and let us know about your mind as soon as possible.

We kindly ask you to visit the SUSPENSION REPORT to respond on this claim

We are looking forward to your prompt response.

If you think you got this email by mistake – please forward this message to your principal or accountant

Faithfully yours

Dispute Consultant
Better Business Bureau

 
Dear Owner:

Your accreditation with [COMPANY] was Terminated

A number of latest complaints on you/ your company motivated us to transient Abort your accreditation with Better Business Beaureau. The details of the our decision are available at the link below. Please give attention to this problem and notify us about your mind as soon as possible.

We pleasantly ask you to overview the ABORT REPORT to reply on this situation.

If you think you received this email by mistake – please forward this message to your principal or accountant

We are looking forward to your prompt reaction.

Looking for info on additional ways your BBB Accreditation can boost your business? Visit the BBB SmartGuide.

Sincerely,
– Online Communication Specialist
bbb.org – Start With Trust

Users that make the mistake of following one of the links in the emails shown above will be directed to a third-party website hosting the infamous BlackHole exploit kit, which will attempt to take advantage of system vulnerabilities in order to drop Worm: Win32/Cridex.E on the visiting machine.

Upon infection, Cridex will modify the system registry to ensure it executes whenever Windows starts, inject itself into a variety of running processes, connect to a remote server to provide an attacker remote control, and copy itself to any removable drives attached to the affected system.

Keep Your PC Safe!


Given that this threat requires user-interaction, avoiding it should be relatively simple.

  • Manually type in the URL of the website you wish to visit instead of clicking links in emails, especially if they are unsolicited.

  • Do not download or open any files attached to unsolicited emails (or at least be sure to scan them first).

  • Always keep your operating system and installed third-party software patched and up-to-date.

  • Always run antivirus software that offers real-time scanning and keep the virus definitions current.


Too Late?


Did you already click the link in an email similar to the ones above?

Hopefully you’re running one of the 19 antivirus programs capable of detecting the Cridex worm, because you’re going to need to perform a system scan to detect and remove the infection. Hop to it!

[via Webroot]

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.

Friday, March 8, 2013

"CIA 'Deleted' Hugo Chavez" Spam Leads to Malware Attacks

Email Security WarningDo not let curiosity get the best of you (and your PC) if an email drops in your inbox suggesting that the CIA and FBI played a role in the death of Venezuelan President, Hugo Chavez.

Researchers at Kaspersky Lab intercepted a spam email using said theory to pique the interest of recipients, hoping that they will follow one of the embedded links to a malicious website hosting the BlackHole 2.0 exploit pack.

Below is an example email that Kaspersky researchers warn users not to fall for:
Subject: CIA “DELETED” Venezuela’s Hugo Chavez?

Chavez was a leader who tried to free his people from the grip of people who will do anything to keep the consumer hostage. In the fall of 1988 oil was $15 a barrel and gasoline was 89 cents a gallon. I was called a dupe of Saddam by western media. We posted a video called A War On Children.

Our latest video is What Can You Buy With 5 Trillion Dollars Anything You Want April 2012. The key information in the new video is that $500 billion per year is paid by the United States to oil producing nations. In ten years, five trillion dollars will be paid to oil producing countries for foreign oil. The movement of trillions of American dollars to other countries is a great concern for the security of the United States.

Even in November I said: CIA and FBI Had Planned to Assassinate Hugo Chavez

To no surprise, the exploit code on the malicious sites attempt to leverage a [patched] vulnerability within the Java browser plugin, CVE-2012-0507. If that vulnerability seems familiar to you, it may be because it was the same one used to infect thousands of Macs with Flashback malware in 2012. (See why it’s so important to keep your computer up-to-date?)

The payload dropped was not disclosed; however, 8/46 antivirus programs were able to detect the exploit code, including Kaspersky products.

Tips to Stay Safe


Given that this is an email based attack, this threat shouldn’t be too difficult to avoid. However, we offer the following bits of advice to keep your PC safe:

  • Always keep your operating system and installed third-party software fully patched and up-to-date.

  • Always run antivirus software that offers real-time scanning and keep the virus definitions current.

  • Do not click hyperlinks embedded in unsolicited emails.

  • Do not download or open files attached to unsolicited emails.

  • Remove Java from your system if it is not needed, or if it is necessary, dedicate a single browser to browsing Java-based websites and disable the Java plugin in all other browsers.

  • Remain vigilant when surfing the web – dangers lurk everywhere!


Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.

Tuesday, March 5, 2013

Phishers Impersonate Mark “Zurckerberg” to Hijack Facebook Accounts

Facebook EmailFacebook users should be wary of phishing emails signed by a “Mark Zurckerberg” stating that their Facebook account may be permanently suspended due to TOS violations unless they verify their account.

The email is a sham, and recipients that click the embedded verification link will be taken to a spoofed Facebook login page designed to steal their login information.

Users may not suspect that something is amiss until they’re redirected to the ‘Help’ section of the real Facebook site after supplying their login credentials, but the damage will already have been done at that point.

The miscreants behind this scam will already have the victim’s login information, which can be used to take over the victim’s Facebook account and pose as the victim and/or launch additional scam/spam campaigns.

Here’s an example of an email associated with this scam:
Mark Zurckerberg

Dear Facebook user, After reviewing your page activity, it was determined that you were in violation of our Terms of service.Your account might be permanently suspended.

If you think this is a mistake,please verify your account on the link below.This would indicate that your Page does not have a violation on our Terms of Service.

We will immediately review your account activity,and we will notify you again via email.
Verify your account at the link below:

=========================================
Link Removed
=========================================

Protect Your Facebook Account


Users can minimize their chances of falling for this Facebook phishing scam – or any others by following these few bits of advice:

  • Access your account safely by manually typing in the URL in your address bar or using your bookmarks instead of following hyperlinks.

  • Always double-check the URL in your address bar before entering any confidential information, including login credentials.

  • Beef up your Facebook account security by enabling login notifications and login approvals.


Did You Fall for This Scam?


If you have already fallen for this scam:

[via Hoax-Slayer]

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+.

Thursday, February 14, 2013

Adobe Confirms 0-Days in PDF Reader & Acrobat, Says Patch in the Works

Adobe AcrobatAdobe has confirmed the existence of two critical vulnerabilities (CVE-2013-0640, CVE-2013-0641) in Adobe Reader and Acrobat that are actively being exploited in targeted attacks.

FireEye researchers first spotted the exploit earlier this week, and revealed attacks involved a malicious PDF disguised as an international travel visa application that would drop 2 DLLs onto the target system upon successful execution.

Although these attacks appear to target Windows users, Adobe’s security advisory notes that the vulnerabilities affect Adobe Reader & Acrobat for other operating systems:

  • Adobe Reader XI (11.0.01 and earlier) for Windows and Macintosh

  • Adobe Reader X (10.1.5 and earlier) for Windows and Macintosh

  • Adobe Reader 9.5.3 and earlier 9.x versions for Windows, Macintosh and Linux

  • Adobe Acrobat XI (11.0.01 and earlier) for Windows and Macintosh

  • Adobe Acrobat X (10.1.5 and earlier) for Windows and Macintosh

  • Adobe Acrobat 9.5.3 and earlier 9.x versions for Windows and Macintosh


Protect Yourself


Adobe is currently working on a patch to fix the security holes, and advises users to enable Protected View in the meantime:

  • Menu -> Edit

  • Selecting Preferences

  • Clicking Security (Enhanced)

  • Pick “Files from potentially unsafe locations”


Adobe also advised enterprise administrators that they can protect Windows users across their organization by enabling Protected View in the registry and propagating that setting via GPO or any other method. (More information on that here.)

Aside from that, try not to open any suspicious PDF files sent from untrusted sources (for instance, an unsolicited email).

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

Wednesday, February 13, 2013

New Adobe PDF Reader & Acrobat 0-Day Exploit Spotted

Adobe Acrobat PDFFireEye is warning users not to open PDF files sent from unknown/untrusted sources following the discovery of a a new zero-day vulnerability that’s actively being exploited in-the-wild.

The attack begins with a booby-trapped PDF - which may be masquerading as an application for an international travel visa -that drops 2 DLL files on the target machine should the exploit code be executed successfully.

“The first DLL shows a fake error message and opens a decoy PDF document, which is usually common in targeted attacks “ FireEye researchers explain in a Tuesday blog post, "The second DLL in turn drops the callback component, which talks to a remote domain. "

Zheng Bu, Senior Director of Security Research at FireEye told Threatpost that this exploit is the first to bypass the sandbox in Adobe Reader X and higher.

FireEye notified Adobe of the bug, and has agreed to avoid posting technical details of the zero-day until further notice. FireEye was able to successfully execute this attack in Adobe Reader 9.5.3, 10.1.5 and 11.0.1.

Adobe is currently investigating the bug and will release an update once they have more information.

Until then, be sure that you do not open PDF files from unknown or untrusted sources.

Update: Adobe has confirmed the vulnerabilities discovered by FireEye & promises to release a patch soon.

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

Friday, February 8, 2013

Adobe Updates Flash Player to Fix Vulnerabilities Used in Ongoing Attacks

Adobe Flash PlayerIt’s time to update Adobe Flash Player!

Adobe released an emergency patch for Adobe Flash Player to address two vulnerabilities (CVE-2013-0633 & CVE-2013-0634) that are actively being exploited by cybercriminals to spread malware.

Attacks using the CVE-2013-0633 vulnerability involve tricking Windows users into opening a booby-trapped Word document (.doc) containing malicious Flash (SWF) content. The malicious Word documents arrive as an email attachment.

The second vulnerability, CVE-2013-0634 is being exploited in drive-by-download attacks using malicious Flash content and pose a threat to both Windows & Mac OS X users.

Adobe recommends that Linux and Android users update their software even though Windows & OS X are the only ones that appear to be targeted in the ongoing attacks.

Affected Flash Player versions, according to Adobe’s security advisory:

  • Adobe Flash Player 11.5.502.146 and earlier versions for Windows and Macintosh

  • Adobe Flash Player 11.2.202.261 and earlier versions for Linux

  • Adobe Flash Player 11.1.115.36 and earlier versions for Android 4.x

  • Adobe Flash Player 11.1.111.31 and earlier versions for Android 3.x and 2.x


Not Sure What Version of Flash Player You Have?


Users that are unsure of what version they’re running can find out by:

  • Visiting the About Flash Player page on Adobe’s website.

  • Right-clicking on content running in Flash Player & select “About Adobe (or Macromedia) Flash Player” from the menu.


Be sure to check the version in each web browser installed on your system; just remember that Google Chrome & IE10 will be updated automatically!

How to Update Adobe Flash Player


To update their installation of Adobe Flash Player, users can:

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

Tuesday, February 5, 2013

Tax Spam Aims to Trick Users Into Downloading Backdoor Trojan

ITax Day Aheadt’s tax season again and that means spammers will be pumping out malicious phishing emails in hopes of catching recipients off-guard.

Sophos has already intercepted one of the tax-related spam emails going around, and is warning users not to open the files attached to it:
Subject: FW: 2010 and 2011 Tax Documents; Accountant's Letter

I forward this file to you for review. Please open and view it.
Attached are Individual Income Tax Returns and W-2s for 2010 and 2011, plus an accountant's letter.

This email message may include single or multiple file attachments of varying types.
It has been MIME encoded for Internet e-mail transmission.

The name of the zip archive attached to the email will vary from email-to-email as it is named after the recipient (i.e. the file will be named “sally.zip” if your email is sally@email.com). However, each archive contains the a dangerous executable, "Individual Income Tax Returns.exe" that Sophos identifies as Troj/Agent-ZWM, a backdoor Trojan that will grant an attacker remote control of your system.

What to Do If You Receive This Spam Email


If this email happens to drop in your inbox, it is recommended that you:

  • Avoid downloading or opening the attached file.

  • Report the email to SpamCop.

  • Delete the email immediately.


[via Sophos]

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

Friday, January 25, 2013

DocuSign Phishing Emails Loaded with Data Stealing Trojan

DocuSign Professionals that use DocuSign should beware of an active phishing campaign looking to infect their computer with a data-stealing Trojan, warns antivirus firm Bitdefender.

The phishing email has been carefully crafted to appear as if it were a legitimate notice sent by DocuSign Electronic Signature Service on behalf of the administration department of the recipient’s company.

DocuSign Phishing Email
Screenshot Credit: Bitdefender



From: DocuSign Service (dse@docusign.net)
Subject: To all Employees – Confidential Message

DocuSign
Your document has been completed

Sent on behalf of administrator@bitdefender.com.

All parties have completed the envelope ‘Please DocuSign this document: To All Employees 2013.pdf’.

To view or print the document download the attachment .

(self-extracting archive, Adobe PDF)

This document contains information confidential and proprietary to bitdefender.com

LEARN MORE: New Features | Tips & Tricks | View Tutorials

DocuSign. The fastest way to get a signature.

If you have questions regarding this notification or any enclosed documents requiring your signature, please contact the sender directly. For technical assistance with the signing process, you can email support.

Attached to the email is a zip file named “To ALL Employees.zip,” and it shouldn't be a surprise to anyone that inside the archive is a payload identified as Trojan.Generic.KD.834485.

Once it has infected a machine, Trojan.Generic.KD.834485 will get to work by stealing login credentials stored in email clients & web browsers, attempt to log into other network machines by guessing weak passwords using remote desktop protocol (RDP), possibly download and install additional malware (such as the infamous ZeuS/Zbot), and collect account information related to server names, port numbers, login IDs, FTP clients, and cloud storage programs.

DocuSign is aware of this email threat and has taken the courtesy of posting a warning on their website advising users that legitimate emails do not contain zip or executable files as attachments and to mouseover links to check for the docusign.com or docusign.net domains before following them.

Think You Received a DocuSign Phishing Email?



  • Do not download or open any attached files.

  • Hover your mouse over links to check for the legitimate docusign.com or docusign.net domains. (Note: This may not matter if a file is attached since real emails from DocuSign do not contain attachments.)

  • Report the email by forwarding it to spam@docusign.com.

  • Delete the email immediately.


Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

Tuesday, January 8, 2013

Spam Alert: More FedEx Phishing Emails Hitting Inboxes

FedExBrace yourselves, folks - more FedEx spam is coming your way!

Our last copy of FedEx spam arrived back in early December, and it doesn’t look like much has changed since. The sender’s address is still some random email (not a fake fedex.com address), the subject line is still a random tracking number, and the goal is still to infect your computer with Win32/TrojanDownloader.Zortob.B.

Here’s the email (the previous version can be seen here):

FedEx Spam (1/7/12)
From: Shipping Service (clients-262@corpuschristi.com)
Subject: Tracking ID (387)91-387-387-9611-9611

FedEx

Order: JN-1454-28625287
Order Date: Thursday, 3 January 2013, 11:23 AM

Dear Customer,

Your parcel has arrived at the post office at January 6.Our courier was unable to deliver the parcel to you.
To receive your parcel, please, go to the nearest office and show this receipt.

GET & PRINT RECEIPT

Best Regards, The FedEx Team.

For those of you who are curious (or possibly new to this FedEx spam thing), when you click the ‘Get & Print Receipt’ link, you will be taken to a third-party site that will download the file Postal-Receipt.zip onto your PC. Hopefully you will not make the mistake of opening this file as it contains the aforementioned Zortob.B Trojan.

What to Do With FedEx Spam


If you receive an email like the one above, it is strongly recommended that you:

  • Do not click on any links or open any attached files.

  • Report the email to FedEx by forwarding it to abuse@fedex.com.

  • Delete the email immediately.


Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

Yahoo! Fixes XSS Exploit Used to Hijack Yahoo! Mail Accounts

Yahoo! MailAn unknown number of Yahoo Mail users found their accounts compromised yesterday, thanks to a document object model-based cross-site scripting vulnerability that was discovered by a security researcher by the name of Shahin Ramezany.

Ramezany posted a video on YouTube demonstrating the XSS vulnerability, which only takes minutes to execute and affects all current browsers, on January 6th. According to the video, a Yahoo! Mail user can fall victim to the exploit by simply clicking on a malicious link sent to them via email, putting an estimated 400 million accounts at risk of being taken over.

Users that were affected by the exploit took to Twitter to complain and warn anyone that received an email from them not to click any embedded links.

Thankfully Yahoo! stepped in to close the security hole yesterday evening, issuing the following statement to The Next Web in the process:
“At Yahoo! we take security very seriously and invest heavily in measures to protect our users and their data. We were recently informed of an online video that demonstrated a vulnerability. We confirm that the vulnerability has been fixed. In addition, we are investigating recent reports of increased abusive traffic and will work diligently to fix any vulnerabilities that are found. Concerned users are encouraged to change their passwords to a safe password that combines letters, numbers, and symbols.”

Lesson to be learned here? Exercise caution when following links, even when they are sent by a friend - you never know what hides behind it!

Update: Researchers say Yahoo! Mail exploit still active, despite claim of being fixed

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

Friday, January 4, 2013

Don't Accept Bikini Screensavers Offered via Spam

Bikini Photo

Sophos is warning users not to fall for the latest trap spammers are planting inside email inboxes: unsolicited messages claiming to have bikini photos inside an attached zip file.

Here’s one of the emails picked up by SophosLabs:
Subject: Merry Christmas
Hello my dear!!!

How are you? As I promised, here’s my bikini photos. I hope you will be love it!
This is my humble gift for Christmas! See you later :)
Your love Ciara
28.12.2012

If the poor grammar wasn't an indicator of a potential scam, then the attached file, Bikini.zip should raise some red flags as it contains a Windows screensaver file named “Bikini.scr” instead of a bunch of regular image files.

That's likely because .SCR files are executable (capable of installing code) and can unleash mayhem on your poor machine. So don't open them unless they're coming from a trusted source.

Sophos detects this threat as Troj/Agent-ZMO, but you should be able to avoid it as long as you don't open files attached to spam.

Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+

Friday, December 28, 2012

What to Look for to Protect Yourself from Phishing Emails

phishingAt any point in your Internet usage life-time, you can be bombarded by emails that are either "phishing" for personal information or trying to get you to install something you don't want or need.

Although a large portion of these emails can seem legitimate, there are a few things you can look at in order to tell if they are fake or not.

  1. Sender - If an email looks legitimate with logos, branding, and business-type language take a look at where the email came from. Companies such as Facebook, PayPal, and others do not use Yahoo, Gmail, or Hotmail in order to send important account information. Make sure that the company name is spelled correctly in the email address as well. Some scams using PayPal have had the email extension "@payspal.com" - notice the 's'.

  2. Undisclosed Recipients - If you are getting an email that speaks to you as an individual but says it was sent to "undisclosed recipients" in the "To:" heading, this means that someone or a bot sent that email to many people using blind-carbon-copy. This means that emails stating that you won $1.5 million in a UK lottery that was sent to "undisclosed recipients" was probably sent to 1.5 million email addresses.

  3. Addressed by Name - Professional emails coming from Facebook, PayPal, UPS, and a slew of others willalways address you by the name on the account. It will never say Dear User, Friend, Customer, or the like. If the company's system was hacked and personal names to the accounts were released, it could still be fake. However, this instance is extremely rare.

  4. Locality - Beware of emails that were sent from email addresses based in other countries. Extensions such as .hk, .uk, .pi, and vast amounts of others are favored by scam artists and hackers. If you live in Florida and receive an email from UPS, it will not be from Hong Kong.

  5. Personal Info - A favored tactic of scam artists is the use of PayPal and Facebook professional looking emails that request your account information, login, and passwords so they can "verify" or "activate" your account. A legitimate business will never request your account or personal information through an email. First of all, they already have your personal info if it is legitimate. Secondly, email can be intercepted and your account info can be stolen.

  6. Unsolicited - If you didn't enter a lottery or contest, you didn't win the prizes spoken of in that email from the UK. If you're not expecting an ATM card worth $1 million, than it's not really there. If an email comes to you stating how the sender was able to find you to give you something but they need your information, question it. If they found your correct email address, they should have your name in the first place.


Never give your personal information, usernames, or passwords to anyone in an email. This could give the criminal element access to your personal accounts and information in order to steal your identity. If an email looks too good to be true, then it usually is 99.9% of the time. That poor Nigerian prince will have to find someone else to move that multimillion dollar account of his.

This guest post is compliments of Ken Myers, the founder of Longhorn Leads. Over the years, Ken has learned the importance of focusing on what the customer is looking for and literally serving it to them. He doesn't try to create a need, instead he tries to satisfy the existing demand for information on products and services.

Thursday, December 27, 2012

'UPS Delivery Confirmation Failed' Spam Leads to Drive-by-Download Attacks

UPS LogoBe careful not to click on any links within emails purporting to be from UPS claiming that a delivery confirmation failed.

Webroot researchers warn that spammers are up to their old tricks and are widely-spamming out fraudulent UPS notices to drive users to malicious websites serving malware.

Here’s a copy of the email currently being sent out:

UPS Delivery Confirmation Failed
Screenshot Credit: Webroot



UPS – Your UPS Team

Good Morning,

Dear Client, DELIVERY CONFIRMATION: FAILED

Track your Shipment now!

Pack it. Ship ip. No calculating , Your UPS Team.

According to Webroot, recipients that click on a link within the email will be taken to a third-party website hosting the infamous BlackHole exploit kit, which will attempt to exploit system vulnerabilities in order to plant malware on the visiting machine.

What to Do with UPS Spam


If you receive an email similar to the one below, it is strongly recommended that you:

  • Do NOT click on any hyperlinks within the email.

  • Report the email to UPS by forwarding it to fraud@ups.com (be sure to include the full headers).

  • Delete the email immediately.


Don’t miss out on the latest tech news and computer security alerts! Follow us on Twitter at @hyphenet,  “Like” us on Facebook or add us to your circle on Google+