Archive | Malware


27 October 2010 | 12,596 views

Hackers Exploit Unpatched Firefox 0day Using Nobel Peace Prize Website

It’s been a while since Firefox has been in the news, but this is a fairly high profile case involving the Nobel Peace Prize website. It seems there is a race condition vulnerability in the latest versions of Firefox (including 3.6.11) that allows remote exploitation. In this case it was used via an iFrame on [...]

Continue Reading


21 October 2010 | 7,324 views

Malware Pushers Abuse Firefox Warning Page

This is a pretty neat attack from the malware pushes leveraging on the ignorance of the average user – which in all honestly is a safe bet most of the time! You could consider it a Social Engineering attack as it’s taking something that’s familiar and changing it to deliver malware. I’m sure all the [...]

Continue Reading


20 October 2010 | 8,671 views

NSDECODER – Automated Website Malware Detection Tool

NSDECODER is a automated website malware detection tool. It can be used to decode and analyze an URL to see if it host to malware. Also, NSDECODER will analyze which vulnerability has been exploited and the original source address of malware. Functions Automated analysis and detection of website malware. Detection for plenty of vulnerabilities. Log [...]

Continue Reading


01 October 2010 | 6,465 views

Police In UK & US Charge & Arrest Multiple People Over Zeus Trojan E-banking Fraud

Zeus has been around for quite some time, we reported it about it initially back in 2009 when it was noted Zeus could evade anti-virus software. In more recent months it was noted that Zeus has become more focused and variations of Zeus were found to be targeting banks and financial organisations in specific geographic [...]

Continue Reading


22 September 2010 | 8,662 views

Twitter onMouseOver XSS Exploit Causes Chaos

The big news yesterday was an epic XSS flaw on Twitter that sent the micro-blogging service into chaos. They actually made an announcement during the hack that users should stay off the web-site and use 3rd party services through the API (Software such as Tweetdeck, Seesmic, Gravity etc). They posted an update on the status [...]

Continue Reading


10 September 2010 | 10,540 views

Email Worm Spreading Like Wildfire – W32.Imsolk/VBMania Variant

Oh this is a throw back to the 90s, a self-replicating e-mail worm based around a malicious screensaver (.scr) that sends itself to everyone in your address book. It seems this one is spreading fast though with hundreds of thousands of infections. Reminds of the heydays of ILOVEYOU and Anna Kournikova. A fast-moving email worm [...]

Continue Reading


03 September 2010 | 7,984 views

Malware Hash Checking Tool – Online & Offline Support

This program intends to detect a malicious file in two ways; online and offline. It calculates the md5 hash of a specified file and searches it in its current hash set (offline) or on VirusTotal site (online) and shows the result. It has http proxy support and update (for hash set) feature. It’s a simple [...]

Continue Reading


15 July 2010 | 6,116 views

Sunbelt Software Bought By GFI For An Undisclosed Sum

Looks like this is the way business is heading, especially in the software sector. As led by the giants Microsoft, acquisition is the way to get new and innovative software without having to produce it yourself! Sunbelt Blog is one of the few we actually link to in the sidebar and also read regularly. They [...]

Continue Reading


09 July 2010 | 10,502 views

REMnux: A Linux Distribution For Reverse-Engineering Malware

REMnux is a lightweight Linux distribution for assisting malware analysts in reverse-engineering malicious software. The distribution is based on Ubuntu and is maintained by Lenny Zeltser. REMnux is designed for running services that are useful to emulate within an isolated laboratory environment when performing behavioral malware analysis. As part of this process, the analyst typically [...]

Continue Reading


08 July 2010 | 9,730 views

Regional Trojan Threat Targeting Online Banks

Well it was inevitable really, I’ve noticed in the last couple of years Phishing e-mails have started to use targeted lists especially for banking sites and the next up of course is trojans developed for specific regions. A security company Trusteer (who makes Rapport) has done some research on this matter which has pin-pointed certain [...]

Continue Reading