Custom Search

Spammers disguise malware as Vodafone MMS email

The email includes original links to Vodafone websites, which makes it a lot less suspicious for spam filters and explains why so many users have initially received the email.

The given telephone numbers in those mails vary, but the gist always remains the same: The recipient is asked to open …

Of Elections and Shenanigans

Today is that fateful day: Election Day. And we’re not short of seeing shenanigans related to this big event that online criminals and scammers have been taking advantage of for months.

What we have below are just some of what we found surrounding the elections.

First off is a file that goes by …

Malware Uses Google Go Language

Designed in 2007 and introduced in late 2009, the Go programming language developed by Google has been gaining momentum the past three years. It is now being used to develop malware. Recently seen in the wild, Trojan.Encriyoko is a new threat associated with components which are written in Go. The Trojan attempts to encrypt various …

Caring About QUERVAR

We have received several reports and inquiries about file infectors PE_QUERVAR.B-O (mother file infector) and PE_QUERVAR.B (infected file). Both are getting some media attention, specifically in Europe. Reports identify infections registering mostly in Netherlands. Its massive spreading maybe explained by a couple of things:

It infects file that are most commonly found and shared in …

Have you seen this picture of yours in attachment?? Three Facebook friends sent it to me today!

A series of emails with malware attachments have been widely distributed in the last few days. The emails alert the recipient about a picture of themselves (or an ex-girlfriend) that has been circulated online. The text from three of the messages is shown below:

Sorry to disturb you , – I have a …

Mac OS X Threat Masquerading as Image Files

Last year, a variant of OSX/Imuler has been discovered and masquerades as an innocent PDF Document.

Recently, a new variant of OSX/Imuler has been discovered and masquerading as image files of the popular Russian model Irina Shayk. The malicious application is placed inside a ZIP archive together with other various image files taken from the …

New Version of Imuler Trojan Horse Masquerades as Image Files

Intego has discovered a new version of the Imuler Trojan horse, which the company first discovered in September, 2011. At the time, the sample discovered masqueraded as a PDF file containing Chinese text. This was not found in the wild, and the risk was considered to be low.

The latest version, Imuler.C, has been found to …

Bot shopping with my wife

When my wife told me she had received an email with a purchase confirmation she hadn’t done, my first thought was:

How can she even remember what she bought? She buys thousands of clothes online, probably she doesn’t remember it, this wouldn’t be the first time

After she told me 1,000 times she had …

Zbot Trojan spreads through fake ConEdison billing notification email

Today we came across a new malicious spam campaign that is actively sent out by the Cutwail spam botnet. The suspicious email claims to be a bill summary from the New York-based energy company Con Edison, Inc. It may use the subject line “ConEdison Billing Summary as of <DATE>” and the attachment uses …

New Facebook “Your account has been blocked!” scam

Another Facebook spam pretending that Your account has been blocked is currently circulating on Internet. The subject is: Facebook Service# Your account has been blocked! Order/8236.

The email comes with an attachment called New_Password_FB_1148.zip.

The zip file contains the New_Password.exe , which tries to fool the victim by posing as a Microsoft Word …

MSRT June Release, taking care of a few worm families

In this month’s MSRT release, we added three new threat families to the detection capability. One of these three is Win32/Nuqel, which has been around for four years since its first variant was found. More than 60 variants of Win32/Nuqel have been identified in the wild. This worm spreads itself via network shares, removable drives …