Email Malware comes a Knocking
Comments OffI was checking my email and I got a email. I thought we would talk about it some:
Subject Line: Collection on setebembro months
Anexo (fatura_setebembro.doc)179,kb
__________________________________________
Hircon Assessoria Consultoria e Cobrança LTDA
Prezado cliente,
Consta em nosso sistema uma fatura vencida referente ao mes Setembro (09/2009),
caso nao tenha efetuado o pagamento segue o extrato em anexo.
Agradece a Gêrencia.
This is what it is when you translate it:
Subject Line: Collection on setebembro months
Annex (fatura_setebembro.doc) 179 kb
__________________________________________Hircon Advice and Collection Consulting LTDA
Dear customer
It is recorded in our system won an invoice for the month September (09/2009)
If you have not made the payment following the statement attached.
Thanks management.
| File faturasetembro.exe received on 2009.10.24 09:11:49 (UTC) | |||
| Antivirus | Version | Last Update | Result |
| a-squared | 4.5.0.41 | 2009.10.24 | Trojan-Downloader.Win32.Banload!IK |
| AhnLab-V3 | 5.0.0.2 | 2009.10.23 | - |
| AntiVir | 7.9.1.44 | 2009.10.23 | - |
| Antiy-AVL | 2.0.3.7 | 2009.10.23 | - |
| Authentium | 5.1.2.4 | 2009.10.24 | W32/Trojan-juke-based!Maximus |
| Avast | 4.8.1351.0 | 2009.10.24 | - |
| AVG | 8.5.0.423 | 2009.10.24 | - |
| BitDefender | 7.2 | 2009.10.24 | Gen:Trojan.Heur.je3@rPiM!8aif |
| CAT-QuickHeal | 10.00 | 2009.10.24 | (Suspicious) – DNAScan |
| ClamAV | 0.94.1 | 2009.10.24 | - |
Computer Security : important caveat not all websites are safe
Comments OffEveryday we’ve seen people get infections on there systems and most don’t understand that they’ve been duped and have installed the software themselves.
In this article we will talk about how most people will willingly install these Trojans and virus themselves for several different reasons.
ineluctable truth about Human Nature
These malware authors know all about how people think. It usually happens when people think they are seeing something provocative and something you can watch in your private homes. There are several different ways to do this:
- News stories – Alas this is always being used to spread malware. For example Erin Andrews Peephole malware.
- Fake photos files — This is also a very common ploy, to make people think it is a Photo but in reality it is an Executable. Example : MichealJackson.JPG.EXE
- Fake Codecs — You visit what you think is a popular movie and it says you need to install a codec. This is another way for people to get infected with a Trojan, or a Virus. For example : Harry Potter and the Half Blood Prince malware.
How to Send Files Securely — Securezip
I’ve been testing out Securezip the last few days and I am convinced this is the best option people can use to send files through email.
How does Email work?
So Let’s get down to the basics of Email. Email uses DNS just like the web pages it also can be Sniffed if you are using a public hotspot or other unecrypted networks. We’ve seen people talk about Email Privacy and documents alone can be the most private thing we have.
Email has to be sent through several different servers that you have no control to get to its final destination. So if your really paranoid you know that a server could be used for the man in the middle scenario. In which some server claims to be the final destination and here it is copied and sent on to the true person.
Securing your Email
As you can see email privacy is as easy as telling people everything they want to know about you. Email Security is always going to be an ever evolving technology, because those who want to listen will tend to find ways to listen. You could use PGP Email Encryption to prevent people from reading your emails but what about the files?
Spoof Spam from Skype users
Comments OffI got a strange email from Skype:
As you can tell this is spam but it got through my spam filters because the spammers are actually spoofing the email address. Upon further inspection of the headers of the message I have found this came from a Black Hole IANA.org name server. Then when I did some even more investigation on this, I found that they are seeing more and more of Email Spoofing for Skype. Which if you went to that URL (Websweetness.com) you will not like what you see. IT is an Adult site but that is besides the point. I am betting the spammers are trying to fool the spam filters to make sure this get through. I talked about the Skype Bots before and this seems to be another way they are using Skype for there spam campaigns.
Skype is getting to be used by almost everyone who has internet so this is a good bet that people will get even more spam from spammers who are trying to get around the spam filters. Until Skype fixes this problem, you can go into Email settings and uncheck “Skype can contact me when someone adds me as a contact”. Although I would like to prevent this totally until they add a way for me to only receive messages from people on my contacts through email this will always be problem until they do that.
Canadian Pharamacies not from Canada!!
Comments OffI got an Email that happen to get past the spam filters and wanted to talk about it. The Email goes like this:
Hi there
Hey where have you been recently ? I could not get any news from you for a long time. Anyway, I found a decent pharmacy store from google last week. I decided to give a shot because it was Canada Licensed Drugstore. Well the prices were % 65 cheaper than the local pharmacies in my region. So I took a chance. I took my medicines in my hand 3 days after i ordered and they were packed very well as they claimed that they provide full anonymity. Needless to say medicines are legit and they give me what i wantIf you need any medicine without any prescription, give it a try until the discount ends.
Take care of yourself. I included the url below. See you later.http://www.guidefabledme.com
Several things makes me wonder where it stands out that this is just spam. Here are some examples:
- the word Google — It isn’t capitalised and that should be capilitized.
- Bad Grammar — This shows me this isn’t even close to Canada, I’ll explain later in this article.
You’ve got hacked thanks to Twitter : Don’t “email me at”
Comments OffI was reading a blog post about Spammers Harvesting Sorrow From Twitter.
Something came to my mind, so I did a little research and a lot of thinking and it finally came to me. It is easy for someone to find your email and use it for there own means. There are several different scenarios I can come up with:
- Impersonating someone you know – It is quite simple to find out who we know and who we follow. You can always find someone who you don’t know the email address of and make it seem like your them to get even more information from the person.
- Receiving Viruses, Trojans, or worms – Although if you have a good Anti-virus this one won’t be getting to you but according to ESET : 10 percent of computer users didn’t know if they had anti-virusware installed. This means that there are going to be some success for malware authors to send out a virus to every who twitters there email address and still have success.
Miketechshow Listener Roundtable : #242 Backups
Comments OffWe had a great time talking about backing up our system. On a side note, I’d like to tell people that During the Round table, I was restoring my system due to a major network issue. The system wouldn’t stay connected at all to my network or my USB A600 Cricket Modem. I used the A600 Modem during the podcast with Skype, so the quality isn’t as good as it should but that is due to two different factors. One I had a cheap headset and two the bandwidth limitations. This however shows that this is possible and works really well. I also used the Antenna for the Skype meeting. It actually seems like a stable connection. Although Mike has told us in his email this might be the last Round Table, so if you want this to continue you can either email him or twitter him telling him you want to keep seeing these podcasts. I also talk about Roboform and how I make sure the passwords are backed up. We did talk about making sure to test our backups, so we know if the backup process works. I have to say my backup procedure was without doubt working for me. Even though I had some issues with Vista security updates after the restore, my restore to laptop didn’t take more than an hour to get the programs that I wanted back on the system.
Mike Tech Show Listener Roundtable #242 Backups
Hijacked Accounts being used to spam
Comments OffI just read this from Security Fix and Thought I should talk about it some to better help people fix this:
Dear Friend,
New shopping new life!
How are u doing these days?Yesterday I found a web of a large trading company from china,which is an agent of all the well-known digital product factories,and facing to both wholesalers,retailsalers,and personal customer all over the world. They export all kinds of digital products and offer most competitive and reasonable price and high quality goods for our clients,so i think we you make a big profit if we do business with them.And they promise they will provide the best after-sales-service.In my opinion we can make a trial order to test that.
Look forward to your early reply!
According to Security, they are advertising the Easylifeing.com domain and have compromised GMAIL and Yahoo Mail. This resembles the ones that happen to some other Accounts. Check Yahoo article and the Hotmail Article for other example of compromised accounts.
Dear Friend Spam Emails from Yahoo
The email from our old friend has come back into now compromising Yahoo accounts by sending out this email:
Dear friend:
What are u doing these days?I am going to recommend a Eshop to you.Yesterday I found a web of a large trading company from China,which is an agent of all the well-known digital product factories,and facing to both wholesalers, retailsalers,and personal customer all over the world. They export all kinds of digital products and offer really competitive and reasonable price and high quality goods for their clients,so i think you will make a big profit if you did business with them.And they promise they will provide the best after-sales-service.If you are interested to do business with them,in my opinion, you can make a trial order to test that.
Their Web address: www.nekcn.com
In what seems to be the way of this advertisment company, it seems they have been doing what they did with Hotmail. Deleting your contact list and emailing your friends with this message. Now I am thinking it is being done by them Phishing for the password and Account name, they probably set up an web page to look like Hotmail or Yahoo. One thing to remember to do is check to see that you address bar looks like this:
Are You and Your Friends Fine — Virus Spam
Comments OffLogged into my Google Email and was checking my spam to see what I see and this one draws my attention:
I think I know where this is leading me but I click the link and this website with the Reuters logo pops up:
Now as you can tell this looks authentic but when I did go to this site, AVG detected some trojan. It blocked it, but the file that it is downloaded called “save.exe” and I have talked about flash player fake updates. I have seen other blogs talking about dirty bomb news report leads to malware. I don’t know about you but if I wanted to update my flash player, I go to the source and not use any links. It is wise not to download any programs or files and run them without properly checking them out for viruses and Trojans. You should have a firewall and anti-virus running at all times and that will help but it is your actions that help your prevent from getting viruses or Trojans.
Malicious Spammers target Bank of America
Comments OffI’ve saw two different security firms talking about Bank of America and I wanted to share with you:
Picture from F-secure
It is also been known to be floating around in Facebook this spam. So if you get a link going to a site you don’t know about to see a video and it says you need a codec or the Adobe update you should turn right around and leave site. You should always type in the url of Your Bank and not go there through links.
From what they are saying it monitors Network traffic and Steals ICQ, POP3, and IMAP passwords. If you find network traffic going to Hong Kong IP, then it is time to check to make sure all your Virus definitions are up to date and you’ve installed an Anti-virus and Firewall. I would encourage users to report it to Phishtank so that any other unsuspecting user or person going to that site will be warned.
Are you Email domains being blocked by Cricket?
Comments OffSo I got this Tweet from Mai_ling on twitter and she said:
So I did some digging around the net and found it is something that is a common practice for ISP’s to block PORT 25. If you want to find out if Cricket is blocking your mail service you can easily follow these instructions to see if port 25 is actively being blocked. So what are some options in fixing this little problem.
You could set up your email client to receive on port 25 but send out on the SMTP server of Gmail. This would be useful for people who want to send mail out but not have to change there email address. People will still see it coming from whatevername@whatever.com. You can tell Thunderbird to send out on the port and yet use your domain as your email address.
Another possible solution that may work for some is to sign up for Google Apps. The downside of this is It cost 50$ a year but that is 4.20$ a month to be added on to your Cricket Modem charge. This looks promising and has a 30 day trial so, if it works then you will know before you have to pay for anything. This should be dealt with by Cricket, they should have a way for there customers to send and receive email without having to jump through hoops to send email and receive email.
Fake Emails about Windows Support spam!
Comments OffAccording to Trend Micro, Some malicious software is being sent to unsuspecting users about Windows SP1 andSP2 having a error that could damage software or even hardware. See Trends blog with the photos of the fake spam.
Microsoft sends e-mail messages to subscribers of our security communications when we release information about a security software update or security incident. Unfortunately, malicious individuals can and have sent fake security communications that appear to be from Microsoft.
[Via Microsoft]
So if you get an email from Microsoft you’ll probably want to delete it. Any Microsoft communications will be sent from the Update center. You should never install software that is from an untrusted website. If you are concerned you should check the web and find out what people are saying about the situation and see if it is a scam or true!! Remember only you can prevent a virus or Malware!
I hate Snopes Spam
Comments OffAs you know Snopes is used to find out about urban Legend and Rumors:
I received a Virus alert from my RSS feed about Email virus warning. It even adds a Snope URL. The Author just copies and pasted the virus warning into the blog without even going to Snopes.
According to Snopes and I’ll quote:
Although the Postcard virus is real, it isn’t a “BIG VIRUS COMING” (it’s already been around in multiple forms for a long time now), it will not “burn the whole hard disc” of your computer, CNN didn’t classify it as the “worst virus” ever, and it doesn’t arrive in messages bearing a subject line of ‘Invitation.’[Via Snopes]
Now as you can tell the link described in the blog post was “http://www.snopes.com/computer/virus/postcard.asp”. If you went there, you’d have seen this as a not really true and some parts of this might be but that part about burning your Hard drive or even consider the Worst virus isn’t true.
Some things you need to consider before forwarding anything is:
- Is it completely True?
- Is it Legitimate? (True blown warning about something like a product recall or something important like that)
Microsoft Releases the Patch Information for March
Comments OffMicrosoft Has Released the Patch information For march and This is what is expected to be patch on March 11, 2009:
- Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (Kb949029) — This security update resolves several privately reported and publicly reported vulnerabilities in Microsoft Office Excel that could allow remote code execution if a user opens a specially crafted Excel file. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. (affected System : Microsoft Office)
Gmail Vulnerable to a Change PW Attack!
Comments OffSecuriteam has made an announcement that Gmail has an issue. I will quote:
GMail is vulnerable to CSRF attacks in the “Change Password” functionality. The only token for authenticate the user is a session cookie, and this cookie is sent automatically by the browser in every request.
An attacker can create a page that includes requests to the “Change password” functionality of GMail and modify the passwords of the users who, being authenticated, visit the page of the attacker.The attack is facilitated since the “Change Password” request can be realized across the HTTP GET method instead of the POST method that is realized habitually across the “Change Password” form.
[Via Securiteam]
One way to prevent this to a point is right now having GMAIL automatically connect securely. You would go into your settings in gmail and make sure it uses https connection:
This is one way to prevent the cookie attack but is still needing to be fixed. Since it is using the HTTP GET method it should use the HTTPS method as soon as you try accessing the site. Google needs to change to the HTTPS Get method instead to prevent this type of attack. If you have any other ideas for Google just leave a comment.
Facebook Goes Phishing again
Comments OffIn one of my Previous articles about the Koobface Worm, I talked about the way they were infecting the systems and what you need not do.
It seems that Trend Micro has seen an even more rise in people downloading the WORM_KOOBFACE.AZ and Seems to be on the RISE. This is all done with a Social engineering and Has had some attempts before with this little worm on Facebook.
* facebook.com
* hi5.com
* friendster.com
* myyearbook.com
* myspace.com
* bebo.com
* tagged.com
* netlog.com
* fubar.com
* livejournal.com
This seems to be a social engineering Nightmare for these websites and as yet are unsure what else it does but it says the same thing it did before by saying “This is a Video of You on the Street.” Which is bogus but none the less people click and think they have to download a codec or update their Flash. Social Engineering is on the rise and will be taken seriously. You should read the full report from Trend on what it does but you also should have an anti-virus and Firewall installed to prevent this from happening in the first place. The only true way of preventing this is not to be fooled, you should NEVER Download from a site you don’t know or trust. See all the Facebook articles for more information.
Oh My I got the Presidents Attention!!
Comments OffI just got an email telling me:
Barack H Obama (PresidentBarak) is now following your updates on Twitter.
So I go to the click the link and I see this:

Wow, I didn’t know I was this influental to get the Presidents attention(NOT).
http://www.economygrantprogram.com/
After checking out the profile I see that it has a link to a site that basically asking for your personal address and your email account. After I go check the site I see in really small catch you have to pay 3.95 for Shipping and Handling. Well You know what they say, nothing ever is Free. This looks to be a way to get email addresses to spam in the long run. I wouldn’t give them any information because this is looking to be a scam and I hate scams. You best bet is to go on with your life and report this spam to twitter. This however got my attention because of the who it was, and that is probably why they chose the name. It is however quite funny.
Days like today, I want to take off : GMAIL Down!!
Comments Off
It looks like they are having some troubles with Google MAIL today. This is one of those days I would love to actually go into work to day. If you want to check the status of Gmail You should visit there support page. I have checked it out and it does appear to have a problem with HTML and JAVASCRIPT, but the IMAP functionality seems to work just fine. I have been able to to receive email through IMAP although being kind of slower then normal but It is at least working. SO “DON”T PANIC”, the service will be up and running sometime today!!
*Update*
As Of 7:30am EST the service is back up on my network. So like I said no worries. Good Job Google!!
Careless Facebook profiling can lead to Identity Theft!
Comments OffI just got in contact with a old friend from High school and another friend of mine suggest the new friend. I was looking at her profile and couldn’t believe what I saw:
As you can see this is not good I was amazed at how many people are giving out there birthdays and who they are married to to friends and family. So we heard about how people are claiming they need help or are in need of desperate money. This is nothing new, as you know people are having hard economy times and people are using the social engineering to scam people out of money.
I feel that I should warn people the important necessity. You shouldn’t be broadcasting your DOB and who your married to to your friends, just in case they get hacked.
Recent activity indicates that identity thieves are hacking into trustworthy profiles before selling on the login details to interested parties. This information is used by spammers to target legitimate users, posting misleading links on their “walls” – personalized message boards.
[Via Computing.Co.UK]
Tech Journalist breaks the silence — Journalist got Pwned!!
Comments OffIt was another ordinary day for this tech journalist. He had just waken up from his lovely dreams and hadn’t realized that he was being baited with Phish. Yes that is correct he actually gave out his password to an Phish site and didn’t know it.
I have to admit that he didn’t hide it, in fact he decided to post about how he got Pwned and what happened.
[Click Picture to see the full story]
Internet Security Companies Warn about Patch Tuesday and Valentines Day.
Comments OffWith Tomorrow being released some very highly rated Remote Code Execution to become Zero day in very short time. Some researchers are speculating about more viruses will be released in conjunction to Valentines day. According to this one post it will be likely to be E-cards being sent to try to lure you into downloading Malware.
Various security vendors, including CA Inc, MX Logic Inc., Trend Micro Inc., and Panda Security, have issued alerts about new Valentine’s Day-themed spam campaigns that try to dupe users into installing the Waledec bot.Researchers note that many websites which are affiliated to Waledac e-card scam have been recently updated with content based on the Valentine’s Day theme.
Web sites distribute Trojan files which are commonly named love.exe; onlyyou.exe; you.exe; youandme.exe; and meandyou.exe and the list is not exhaustive.
[Via Express Buzz]
Twitter Spammers are getting more smarter
Comments OffI got an interesting email about someone following me. I went to go check out there profile and Guess what I see:

As you cann se this account only had one post but people seem to be following back due to the picture and the bio. I checked the account about 30 mins later and here I will show you:

A fan wants to Release Windows 7 Now : My Security Concerns
Comments OffAfter reading about this from Kelly Poe) to find out the site he put up and I am quite impressed. Here are few things that I am concerned about starting with the website.
Now that being said that’s the only thing I can think of when it comes to security for your email address, you don’t want to someone to give out your email address to spammers. That would just make it even worse for your email account. You could however use a 10 min Email account to use but that might make it harder for Microsoft to contact you if they want to verify these accounts!!
Now my main concern is Windows 7 right now and Security. You know the Conflicker/Conflickr/Downadup Worm is currently loose on the internet. It uses the the Ms 08-067 Exploit and currently Windows 7 does not protect against this Worm in fact Microsoft has released information that you would need to install the updates manually to fix this problem.
Phishing sites pop up for IRS!
Comments OffWell, this just came to light with The Spywareguide blog. I’ve seen some activity about Where’s my refund lately and I thought I tell you how to make sure you’re on the right site. If you’re expecting a refund check the OFFICIAL SITE. The Official Site is http://www.irs.gov and nothing else. If you want to find out about some of the most common Phishing attempts check out the Phishing advice from the IRS.
gicrisis.org/data/refundtax/SearchTAXERR.php
irs-2009.com/refund/refunds.html
collectrefund-irs.com/refund/refunds.html
cimaonline.ca/application/Internal/Revenue/Service/pas.php?certegy_vm=trueportlet_change_1_actionOverrideFchaseonlineFchangeFprocessDetails_windowLabel_portlet_process_pageLabel_page_process
jklabs.cz/phpayv2/admin/import/.secure/www.irs.gov/get-refund/refunds.php?Where_is_my_refund&Get_Refund
Although this list will most likely change this is just starting for people who filed there income tax. Some things to Remember are:
You can generally access information about your refund 72 hours after IRS acknowledges receipt of your e-filed return, or three to four weeks after mailing a paper return
‘Life Owner’ won’t delete your data!
I received this email from a friend and wanted to talk about this:
VERY IMPORTANT , PLEASE READ THIS
Anyone-using Internet mail such as Yahoo, Hotmail,
AOL and so on.This information arrived this morning,
Direct from both Microsoft and NortonPlease send it to everybody you know who has
access to the Internet.You may receive an apparently harmless e-mail titled ‘Mail Server Report’
If you open either file, a message will appear on your screen saying:
‘It is too late now, your life is no longer beautiful.’Subsequently you will LOSE EVERYTHING IN YOUR PC,
And the person who sent it to you will gain access to your
name, e-mail and password.This is a new virus which started to circulate on Saturday afternoon.
AOLhas already confirmed the severity, and the anti virus software’s are not capable of destroying it.The virus has been created by a hacker who calls himself
‘life owner’.PLEASE SEND A COPY OF THIS E-MAIL
TO ALL YOUR FRIENDS, And ask them to
PASS IT ON IMMEDIATELY!THIS HAS BEEN CONFIRMED BY SNOPES.
http://www.snopes.com/computer/virus/mailserver.asp
Old phish becomes new again
Comments OffAccording to some reports, this phishing has started up again and is now changed a little web address and when you go to the site it looks like:

I’d also suggest getting a password manager so if you use just one password for all accounts you will easily be able to change them and make the passwords much harder to hack. You do not want your passwords stolen do yo? I suggest Roboform it works really well with password management.
Are you worried about your identity?
Comments OffSo after the fiasco of the other day, I decided I will talk about security and why you should worry about new websites that you have never heard of. People are not worrying about there identity and keeping there identity safe. You see whenever someone signs up to a service without thinking about their password being stored or even used maliciously. You see when most people don’t use more than one or two passwords for all there accounts and then you use the same password with a new website. Are you asking for your identity to be stolen? In one of my previous blog posts I talked about not having any privacy on the internet.
So How can you protect your privacy?
When ever I come across a site that I don’t know about and I want to protect my account from being compromised I find out what I can from several places:
- Google — Yes this is quite common to use to find out about what people are saying asking the keywords like is it a scam or what people are saying about the site? This can be very useful to make sure I don’t get scammed by a company for instants the Nationwide marketing scam. Although this is really important when you get things that sound questionable. This can be very useful with regards to keep your wallet safe.
Viacom might be going to HULU
Comments OffAccording to some of the news post people are worried about Viacom leaving Time Warner. Now Here’s where Viacom might be going digital. What do I mean Digital, I am talking about going to HULU. If Viacom doesn’t sign a deal with Time Warner, that would leave a space ope for someone else like Hulu.
So Viacom isn’t happy with Time Warner, or They want to go IPTV. Some of the Headlines I’m seeing are:
- Time Warner Cable Loses Viacom: MTV, Nickelodeon, Comedy Central To Go Dark
- Dispute Between Time Warner and Viacom May Affect Cable Shows
- Viacom could pull MTV off Time Warner Cable
- Viacom And Time Warner Cable Play Chicken; Programmer To Pull Networks Over Fee Dispute
These are just a few that I am seeing pop up around the internet. So what does that mean to the internet user? Well On one of there show’s like Dora the Explorer on Nickelodeon will begin to stream some of the shows previews on Dec 29, 2009 for it’s next show. When you go to Nickelodeon Site you get this:

Twitter Spam bots are hot to trot: http://gentai.com/revenge1
Comments OffOk so I was curious why I all of the sudden got people joining my list. each one I look at just to see who these people are have only one twitter message saying this from two different accounts:
and this one also
and once you click that link it takes you to this website and see what they want you to do:
















