Web Users in Malware Crosshairs

Wednesday, April 9th, 2008

Online malware attacks are becoming more pervasive, targeted, and refined as the underground threat economy continues to evolve and take on the characteristics of an organized industry.The latest iteration of Symantec's Internet Security Threat Report -- covering its research over the final six months of calendar 2007 and released on ...

New Massive Botnet Twice the Size of Storm

Monday, April 7th, 2008

A new botnet twice the size of Storm has ballooned to an army of over 400,000 bots, including machines in the Fortune 500, according to botnet researchers at Damballa.The so-called Kraken botnet has been spotted in at least 50 Fortune 500 companies and is undetectable in over 80 percent of ...

Storm Blogs

Monday, April 7th, 2008

Storm has once again turned its eye to the blogging community, specifically the Blogspot.com community.Several blogger sites with random or very quirky names have been sporting a love theme, Storm style. These sites appear to have been created solely for Storm's purposes and no legitimate blogger site has of yet ...

Analysis of a Win32.Delf Variant

Friday, April 4th, 2008

We have been noticing quite a few malware samples having references to or communicating with Google's SMTP servers. This post dissects one of these samples and in the process attempts to illustrate to the reader some reversing techniques and information gathering techniques, while explaining the behavior and impact of this ...

You’ve been iframed

Wednesday, April 2nd, 2008

Injected iframes into legitimate sites are becoming more and more common these days.  One of the latest targets is a Chinese government site at www.zhangzhu.gov.cn:Please note that while the site adminstrators have been notified, the injected iframe is still present in the site at the time of this posting.The iframe ...