SECURITY WARNINGS & Notices - Please post them here

Hi malware fighters,

The 2007 Storm worm has reappeared in various new variants that differ from the original in specific aspects:
https://www.honeynet.org/node/539
http://www.avertlabs.com/research/blog/index.php/2010/04/28/dark-and-stormy-comeback-of-a-botnet/
and easier to defy than the original Storm worm:
http://www.v3.co.uk/v3/news/2262211/storm-botnet-forming

pol

New attack bypasses virtually all AV protection

Researchers say they've devised a way to bypass protections built in to dozens of the most popular desktop anti-virus products, including those offered by McAfee, Trend Micro, AVG, and BitDefender.

The Register

Original research paper.

nmb

Hi malware fighters,

Latest Malware Database alerts: http://malwaredatabase.net/blog/

pol

Hi malware fighters,

Win7 compatibility tool could be a trojan and malicious downloader:
http://www.net-security.org/malware_news.php?id=1335

polonus

U.S. May Face Cyber Attack, Says Richard Clarke
http://topnews.us/content/219583-us-may-face-cyber-attack-says-richard-clarke


Hack done to phpnuke.org site :

http://forum.avast.com/index.php?topic=59535.msg501749#msg501749


looks solved:
http://www.theregister.co.uk/2010/05/11/phpnuke_infection_purged/

Windows 7 ā€˜compatibility Checker’ Is a Trojan

http://www.pcworld.com/businesscenter/article/195991/windows_7_compatibility_checker_is_a_trojan.html

http://news.bitdefender.com/NW1535-en--WindowsĀ®-7-Compatibility-Checker-Turns-Out-To-Be-a-Trojan.html

Ok, since that is not working for them, they are trying another angle…pretending to warn users about erm…themselves…

Once again, these are NOT from HSBC, they are fake. The so called hsbc link actually points to:

hXXp://michael-shelton.com/images/uk-hsbc.co.uk/www/INTEGRATION-HSBC/CAM11;jession=14/

Which is obviously fake. (would be interesting to know whether avast! blocks this…)

Another thing is, that they have ā€˜tagged’ (right word?) it as high priority, as you can see in the image (the red exclaimation mark…)

Careful guys…

-Scott-

they are trying another angle...pretending to warn users about erm...themselves...

;D

Yeah…although, I think that sentence needs rephrasing:

Ok, since that is not working very well for them, they are capitalising on it, and trying another angle…pretending to warn users about erm…themselves…

Twitter-controlled botnets
http://www.theregister.co.uk/2010/05/13/diy_twitter_botnets/
http://sunbeltblog.blogspot.com/2010/05/diy-twitter-botnet-creator.html
http://www.wired.com/threatlevel/2009/08/botnet-tweets/

A security researcher has unearthed a tool that simplifies the process of building bot armies that take their marching orders from specially created Twitter accounts.

TwitterNet Builder offers script kiddies a point-type-and-click interface that forces infected PCs to take commands from a Twitter account under the control of attackers. Bot herders can then force the zombies to carry out denial-of-service attacks or silently download and install software with the ease of their Twitter-connected smartphones.

Warning: http://stopmalvertising.com/malvertisements/alert-twcorpscom-replaces-grepadcom/page-2

pol

Hi malware fighters,

Loads of fake av silent download sites being found, example: http://safeweb.norton.com/report/show?name=syspro.edu.co

Discussion on recent website malware: http://evilcodecave.wordpress.com/
interesting linked, that I bookmarked…

polonus

Sites that are at February 14, 2010 are about as current as an old newspaper.

Top attacks here: http://atlas.arbor.net/

See what is on the malcode radar here: http://www.securitywizardry.com/radar.htm

pol

Goes to prove that Chinese with bogus Windows are the major contributors:
CHINANET-BACKBONE
http://atlas.arbor.net/asn/4134
http://atlas.arbor.net/cc/CN

Hi malware fighters,

For the latest wepawet Flash and JS reports, go here:
http://wepawet.iseclab.org/samples.php

pol

Hi malware fighters,

As you can read via the link given websites outside the normal Latin spelling, according tio the new Domain standards for instance in Cyrillic or Arabic can be easier abused by phishers now:
http://www.securelist.com/en/blog/2156/New_domain_standards_new_challenges_new_potential_problems

polonus

Hi malware fighters,

Biggest threat around USB worm: http://news.techworld.com/security/3223707/mcafee-usb-worm-is-biggest-pc-threat/

pol