Feedback Form
Friday 3rd September 2010

Posts Tagged ‘spam’

Beware of Shortened Hyperlinks Says Antivirus Review

Friday, July 30th, 2010

The latest anti virus review from the Symantec MessageLabs Intelligence unit, produced by the company which develops the Norton Antivirus software, warns that spammers are making greater use of shortened hyperlinks.

The anti virus review shows that over the last 12 months, the percentage of spam which contains shortened hyperlinks has dramatically increased from a one-day peak of 18% on 30 April, 2010, compared to just short of 10% in 2009.

And 18% equates to just over 23 billion emails. Another way to see it is that for some days in 2010, around 5% of all spam messages contained shortened hyperlinks.

Paul Wood, MessageLabs Intelligence Senior Analyst, at Symantec Hosted Services, the team behind Norton Antivirus, said:
“As far as spammers are concerned, any tactics that make it harder to block their spam emails are going to be exploited. When spammers include a shortened URL in spam messages, these shortened hyperlinks contain reputable and legitimate domains, making it harder for traditional anti-spam filters to identify the messages as spam based on the reputation of the domains found in the spam emails.
“While botnets are often the source of short URL spam, 28% of this type of spam originated from sources not linked to a known botnet such as unidentified spam-sending botnets or non-botnet sources such as webmail accounts created using CAPTCHA-breaking tools.”

The anti virus review also stated that spammers shortened hyperlink strategy is working. For every 74,000 spam emails which contained a shortened url link, one website visit was generated. Furthermore, the most often used shortened hyperlink contained within spam got more than 63,000 website visits.

The various Norton Antivirus Software packages are continually updated from information supplied by the Symantec MessageLabs Intelligence unit.

Guest Article by Neil Camp

Share/Save/Bookmark

Microsoft Accused of Stealth Download

Tuesday, June 22nd, 2010

Software giant Microsoft has been accused of making a stealth download via one of its recent security patches.

Stealth downloads involve an unwitting computer user downloading code onto their machine without knowing of its transmission. It is sensitive subject in the computer security industry, as this is one of the main ways that malware is delivered onto people’s computers. It is a practice abhorrent in the industry and so for a leading company like Microsoft to be accused of such actions, has caused some embarrassment.

Allegedly, along with its regular Patch Tuesday security update, Microsoft bundled a Bing toolbar add-on. The stealth download adds the Bing toolbar to both the Mozilla Firefox and Internet Explorer browsers. And it does so without the users permission.

News of the stealth download was reported by technology blog Ars Technica. It stated that the Search Enhancement Pack update actually loaded the Bing toolbar onto those users who had installed the Windows Live Toolbar, or MSN bar, onto their Firefox and Internet Explorer browsers.

An apparently unabashed Microsoft told another tech news site, The Register, when questioned about the stealth download, that the problem arose because of a bug in the update file. It has, said Microsoft, now been fixed. They went on to explain the update, via the Search Enhancement Pack, was only supposed to work on those users with a Windows Live toolbar, MSN toolbar and a Bing Bar.

A spokesman said:
“We fixed the update so that going forward folks who still have only the older Windows Live Toolbar or MSN Toolbar will not see this behaviour anymore.”

So that’s alright then! Industry experts are a little less understanding and some have questioned Microsoft’s real intentions behind their stealth download tactics.

Microsoft was also in the news for suing an alledged spammer. Target of the lawsuit is Connecticut spammer Boris Mizhen. He is alledged to have sent unwanted emails to Microsoft customers and for gaming Hotmail’s spam filter. Mizhen is named in the legal action, as are several of his companies.

This is not the first time that Mizhen and Microsoft have locked horns. He was sued by the Seattle software giant in 2003 for sending spam to the web-based Hotmail service. The case then ended in a settlement with Mizhen paying out a reported $2 million and an agreement not to send anymore spam to Hotmail customers.

As regards the new, alledged campaign, Mizhen’s associates are keen to point out that these new messages were not spam and that many Hotmail users had moved them from their junk folders to their inboxes. Fair enough, although it’s thought by some that Mizhen and his companies alledgedly created the accounts which did this.

This has opened up the whole debate as to how successful spam filters are, especially those that rely on user feedback to judge the criteria of spam. Such techniques as whitelisting, blacklisting and Bayesian filtering are some of the ones used to recognize and filter out spam. Because these techniques are well known, they can be abused by spammers intent on ‘fixing’ the system and allowing their spam to get through.

Guest Article by Neil Camp

Share/Save/Bookmark

Top Malware and Spam Trends

Friday, May 28th, 2010

When it comes to finding out about the top malware and spam trends, then the latest report from computer security giants McAfee, covering the first quarter of 2010, is a great place to start.

It discovered that top of the list for top malware and spam trends is a USB worm that has grabbed number one position for top malware worldwide. Furthermore, it concluded that spam trends differ considerably from country to country. What’s more, spam originating out of China and other Asian countries is on the increase. And, early 2010 has been marked by major events, such as earthquake news, which has led to many web searches being poisoned.

The top malware and spam trends report also concluded that most malicious URLs are hosted by US based servers.

High up in the top malware and spam trends report is the fact that the increasing use of removable devices, the majority being USB drives, is acting as a beacon for the most popular malware. Infections that are related to AutoRun held the top and third places. In fifth place are password stealing Trojans which include generic downloaders, gaming software and unwanted programmes, all designed to collect statistics anonymously.

Looking at spam, the report concluded that whilst rates are steady, the subjects differ from country to country. The report shows that the most significant amounts of diploma spam come out of China, South Korea and Vietnam. Diploma spam is all about buying bogus job qualifications in order to get jobs.

Whereas countries such as Singapore, Hong Kong and Japan – says the report – are known for high rates of Delivery Status Notification spam.

Mike Gallagher, senior vice president and chief technology officer of Global Threat Intelligence for McAfee, said:
“Our latest threat report verifies that trends in malware and spam continue to grow at our predicted rates. Previously emerging trends, such as AutoRun malware, are now at the forefront. We were also surprised to find some of geographic difference in spam related topics, such as the volume of diploma spam coming out of China.”

The top malware and spam trends report also discovered that Brazil, China, Chile, Colombia, India, Indonesia, Philippines, Romania and Thailand, do have a higher proportion of malware infections and spam. McAfee says this may be down to the rapid increase in computer and internet use that these countries have experienced in the last few years, and that as a result, they lack a proper appreciation of security awareness.

The top malware and spam trends report that hackers continue to make use of bad news events, such as the earthquakes in Haiti and Chile, in order to bump their malicious sites up the site engine rankings.

As to where most of the new malicious URLs are hosted, the top malware and spam trends report concludes that 98% are hosted in the US, mainly because this is where most of the Web 2.0 services are provided.

So, when it comes to the top malware and spam trends report, use it to help keep yourself from the hackers out there.

Guest Article by Neil Camp

Share/Save/Bookmark

Bot Herders Apply for Panda Labs Job

Tuesday, May 25th, 2010

Two bot herders who were part of the team behind the Mariposa botnet thought that their CVs would stand them in good shape when they applied for jobs at Panda Labs.

Bot herders are hackers who establish what’s known in the industry as botnets; computers that have been taken over by the hackers – without the knowledge of their owners – and networked to combine powerful tools for nefarious activities, such as spam mailing.

It’s long been a tactic of hackers, such as bot herders, to commit an attack on a company’s software, or network, and then use that as a kind of ‘real-life’ CV to get job. But in an industry which is becoming far more professional every day, it’s unlikely that this type of job canvassing is going to win many friends in the future.

So when the two herders who helped run the Mariposa botnet turned up at Panda’s offices, there was some amusement and not a little incredulity.

The two bot herders in question were both Spanish and hid behind their online nicknames of ‘Ostiator’ and ‘Netkaira’ when running the Mariposa botnet. But according to Panda, the job hunt was not down to any feelings of remorse, or repentance, but to the fact that the Mariposa botnet had been closed down and the two bot herders had literally run out of money. They hoped that they could come to an ‘understanding’ with Panda, who they believed would welcome their knowledge.

According to Panda, the fact that the two bot herders had been so closely involved in Mariposa, meant that they could not be employed and went on to say that their somewhat dubious technical skills, meant they were unsuitable anyway.

Undeterred, the two bot herders tried again to secure jobs as Panda some months later, but were again turned down.

Panda pointed out that the openness of the two bot herders approach might be explained by the fact that in Spain, running a botnet is not illegal. Although the company went on to say the Spanish national police force, the Guardia Civil, were looking at ways in which the two bot herders could be prosecuted for stealing identities through the Mariposa botnet.

Guest Article by Neil Camp

Share/Save/Bookmark

BitDefender Picks Up Sixth Consecutive VBSpam Award

Tuesday, March 30th, 2010

BitDefender, which provides anti-malware security solutions, has won its sixth consecutive VBSpam Award for it’s BitDefender Security for Mail Servers 3.0.2.

This leading application, designed for Linux servers, came out with a Gold following the latest Virus Bulletin Anti-Spam Comparative Review. The review revealed there was only one false positive out of 2,400 legitimate emails.

The test involved using a SuSE Linux Enterprise Server 11 for a 11-day period. Emails were sent to a number of Virus Bulletin email addresses and were mixed with spam emails provided by Project Honey Pot. And the emails were also sent in multiple language and character sets, including English, French, Russian, Dutch, Norwegian and Asian languages.

The result was an impressive 97.84% of spam messages were caught during the test, giving a false positive rate of only 0.04%.

Catalin Cosoi, Senior Researcher at BitDefender, said:
“We are thrilled to receive another VBSpam Award for BitDefender Security for Mail Servers 3.0.2. This award represents our sixth consecutive honour from Virus Bulletin, and we are particularly happy with test results showing only a single false positive out of 2400 genuine emails.”

The company say the success of the BitDefender is based on a new technology based on live query. This originates from the cloud-computing paradigm, providing an immediate response time and protection to users all over the world, regardless of language or what type of spam they receive.

How Does BitDefender Antivirus Software work?

In practice, it works by first scanning an incoming email locally with proprietary, proactive antispam solutions. If the email passes the initial filtering sequence, but still cannot be categorised as spam, or a legitimate message, then a proprietary algorithm extracts key elements from the analysed mail. This then creates something similar to a unique encrypted fingerprint of that message. Finally, if the BitDefender network of servers finds a match in its databases of known spam fingerprints, it issues a block command to the client application.

This provides a very thorough technique of catching spam emails.

Guest Article by Neil Camp

Share/Save/Bookmark

Things worse say McAfee

Monday, November 30th, 2009

Computer security giant McAfee says that things have got worse in the last quarter with spam, malware and web-based threat creation reaching record levels.

McAfee’s latest Third Quarter Threats Report, which covers July to September 2009, also revealed that the number of new file-sharing sites which host unauthorised, copyrighted content increased dramatically. What’s more, another trend on the increase is the number of cybercriminals who are extorting website owners with threats of denial-of-service attacks.

There was a 300% rise in the creation of file-sharing sites following the brief shutdown of the Swedish based Pirate Bay operation. Pirate Bay was a torrent site, one that can host links to copyrighted material and very controversial in the authorised spread of content. And with this huge rise in the number of similar sites, cybercriminals are presented with the ideal opportunity to exploit the way certain sites share content. Malware writers are skilled at creating sites to trick users looking to download copyrighted material into downloading malicious programs.

And McAfee warns that the number of these malicious sites could dramatically increase during the fall and holiday blockbuster film seasons.

File-sharing site problems to one side, McAfee reported that spam and malware levels have reached a record high, with threats surpassing previous levels in the last quarter. And rather gruesomely, web-based attacks have also increased as cybercriminals take advantage of celebrity deaths and natural disasters. At such times, website activity and email traffic dramatically increases, and malware authors quick to take advantage of such news stories and chat to hide their malicious intentions.

McAfee now reckon that of all email traffic, some 92% is spam. In other words, a tiny 8% is legimate email traffic.

The increase in web-based attacks – which target people who visit a malicious Web page, and are delivered to users through spam, phishing, social networks and even through redirects from hijacked legitimate websites – are fast becoming the most dangerous weapon wielded by a cybercriminal.

And McAfee estimates that 55% of all malicious URLs are hosted in the US. What’s more, cybercriminals are getting increasingly effective at utilising SEO techniques to drive traffic to the bad sites.

Denial of Service attacks are a particularly odious tactic employed by cybercriminals and McAfee has seen many more attacks in the latest quarter, and with some involving significant ransom demands.

Cybercriminals are offering for sale, to the highest bidder, botnets which are made up of thousands of zombie computers to attack sites. The botnets are used to knock out even some of the most-protected sites. And when offering such sophisticated botnets, the cybercriminals will often demonstrate their capability to prospective buyers with ‘live’ demonstrations, bringing down targeted websites for a few minutes.

Just recently, four Australian sports betting companies were targetted by cybercriminals and their sites taken down during key sports events, which resulted in the loss of millions of dollars of revenue.

Guest Article by Neil Camp

Share/Save/Bookmark

Cybercriminals Go Phishing with Sony Ericsson Name

Thursday, September 10th, 2009

Mobile phone giant Sony Ericsson have been forced to issue a press release after their name has been illegally used in a number of spam and phishing attacks.

The terse announcement states that the Company is aware that: “…a series of unsolicited emails have been sent to members of the general public from an email address that appears to bear the name ‘Sony Ericsson’ and which tells that the recipient has won a sum of money in a competition and requests that certain personal data be confirmed.”

Another version of the hoax is an email which says that Sony Ericsson will give away a free laptop to users who forward promotional information. It includes not only a photograph of the Sony Ericsson logo, but also a ‘company’ contact name and number (both bogus). The Company points out that all its competitions and promotions are organised through official channels, including their own and partner websites.

A Sony Ericsson spokesperson warned:

“Please be wary of any competition or promotion that appears to come from outside of Sony Ericsson or Sony Ericsson’s partners official channels. Examples of these include via spam emails or SMS. Please do not reply to or forward the email if you receive it.”

Sony Ericsson go on to apologise for these emails, which they believe are solely for the fraudulent gathering of personal information, and hope that too much inconvenience has not been caused.

The Company ask that anyone effected by such attacks should contact them via an email: questions.gb@support.sonyericsson.com

This is just one of millions of such attacks which are known as phishing and the simple idea behind them is that cybercriminals will send out millions of hoax emails (many sent unknowingly via ‘zombie’ computers) which use company logos, addresses and phone numbers to lend them some degree of authenticity. To the practiced, or indeed jaded eye, then they are quite easy to spot. Poor quality reproduction of the logo and layout of the company identity; incorrect English with spelling and grammatical mistakes; and, a bullying message (‘…send back personal information or we cut your service…’), are all dead give-aways that the email is a hoax. In short, if the respondent has any doubts advise computer security experts, then never reply.

Guest Article by Neil Camp

Share/Save/Bookmark

McAfee Says Spam, Botnets at an All Time High

Tuesday, August 18th, 2009

The second quarter threat report from McAfee has some bad news for all computer users out there. The main finding is that Spam volumes have increased by 141% since March, 2009, continuing the longest streak of increasing spam volumes ever. But that’s not all, as there has been a dramatic expansion of botnets and auto-run malware.

The report highlighted the fact that 14 million computers have been enslaved by cybercriminal botnets, a 16% increase over last quarter.

Auto-run is becoming an increasing problem and over a test period of 30 days, it was discovered to have infected over 27 million files. Auto-Run malware, which exploits Windows Auto-Run capabilities, does not require any user clicks to activate. It is most often spread through portable USB and storage devices. Depressingly, the rate of detection surpasses the infamous Conficker worm by 400%, making it the number one piece of malware detected around the world.

Mike Gallagher, Senior Vice President and Chief Technology Officer of McAfee Avert Labs, said:
“The jump in bot and spam activity we saw in the last three months is alarming, and the threat from Auto-Run malware continues to grow. The expansion of these infections is a grave reminder of the potential harm that can be caused by unprotected computers in homes and businesses.”

McAfee also provides some background showing the a generally worsening computer security situation.

It is noted that fourteen million additional computers have been turned into botnets this quarter. This equates to more than 150,000 computers infected every day, or 20% of the personal computers bought daily.

It also said that South Korea accounted for the largest boost in bot activity. The country saw a 45% increase in new infected computers over the last quarter. And such botnets were used to execute the recent DDoS cyber attacks against the White House, the New York Stock Exchange and South Korean government Web sites.

But although South Korea has its problems, it only accounts for less than four percent of the world’s new bots. And its the U.S. which tops the list with 15% of the new zombie computers.

And its this bot expansion that is behind the increasing volume of spam, which is now 92% of all email. Spam volumes have now exceeded the highest volume on record by 20%, increasing at a steady rate of roughly 33% each month. This equates to spam volumes growing by over 117 billion emails every day.

What’s most disturbing, is that as the number of bots continues to grow, malware writers have begun to offer malicious software as a service to those who control botnets. By exchanging, or selling resources, cybercriminals distribute new malware to wider audiences instantaneously. And the creation of and management of malware is becoming even easier, thanks to programmes like Zeus.

Programs like Zeus – an easy-to-use Trojan creation tool – continue to make the creation and management of malware even easier.

And cyber criminals are increasingly turning their attention to the popular social networking sites, including Twitter, Facebook and MySpace.

Guest Article by Neil Camp

Share/Save/Bookmark

McAfee Identifies Most Dangerous and Safest Web searches

Monday, August 17th, 2009

The computer security giant McAfee has identified which Internet searches are most dangerous to computer safety and which are the safest.

McAfee’s report, entitled ‘The Web’s Most Dangerous Search Terms’ claimed that dangerous Internet searches include searching for things such as free music or screensavers. These search terms are used by cybercriminals to ensnare web users and lead them to their own websites.

Once a web surfer has visited this website, they are vulnerable to downloads that infect your computer, such as spyware which can help reveal private bank details to hackers and other cybercriminals.

McAfee’s report also identifies that these dangerous search terms are changing with regard to the new global economic environment. With higher numbers of people being made redundant due to the economic slump affecting so many, cybercriminals are now using search results to target people looking to save money or find a job working at home.

Jeff Green, senior vice president of McAfee Product Development & Avert Labs said: “Cybercriminals are smart. Like sharks smelling blood in the water, hackers will create related Web sites laden with adware and malware whenever a particular topic increases in popularity. Unsuspecting consumers are then tricked into downloading malicious software that leads them to blindly hand over their personal assets to cybercriminals.”

The riskiest set of search words, according to McAfee’s report, include keywords to the variation of ‘screensavers’. The research concluded that nearly six out of the top 10 search results for the keyword ‘screensavers’ contained some form of malware.

The riskiest search of the 2,600 most popular keywords that McAfee researched was ‘lyrics’, with the risk factor rising to one in two.

The research concluded, however, that the word Viagra was one of the least risky of keywords. The keywords with the safest risk profile included search words related to health and the current economic climate.

McAfee’s report also indicated global variations on these risks. Many of these countries had keyword categories that ended up exposing web surfers to the higher risk sites. 12 countries were exposed to an overall higher risk than McAfee’s average, including Mexico and India. McAfee’s report therefore pointed to cybercriminals targeting those outside of the U.S.

McAfee gave caution to home workers and to those looking to save money: if a result contains the word ‘free’ it has a 21.3% chance of infecting a computer with spyware, spam, adware and other malicious cyber threats. The search ‘work from home’ is four times riskier than the average risk given for all popular terms.

To protect against these vulnerabilities, McAfee SiteAdvisor Technology has been designed. This rates every trafficked site on the Internet to conduct automated tests. Web sites are ranked using coloured ratings, so that users are knowledgeable as to what they are clicking on. McAfee have also recently announced the Cybercrime Response Unit to help arm users against the threat.

Guest Article by Neil Camp

Share/Save/Bookmark

Michael Jackson Death Increases Spam

Saturday, July 18th, 2009

Cyber criminals are exploiting Michael Jacksons death by spreading spam and viruses via bogus sympathy emails.

And grieving fans are amongst the worst victims. Computer security experts are warning everyone to be on their guard against such cynical attacks.

It took some hackers and spammers just hours to start launching cruel emails into the system. One example claimed to have up-to-date news of the 50-year-old mega-star’s progress in hospital, while others stated they had secret pictures and songs.

There were a number of subject lines in use, including ‘Remembering Michael Jackson’. Attachments included a ZIP file with the title ‘Michael songs and pictures.’

But once opened, many of these cynical emails deposited viruses and captured thousands of email addresses for further distribution of spams.

Computer security firms reported a massive rise in the spam right after news of Michael Jackson’s demise. They point out that the perpetrators have no respect for anyone and are just interested in making money and spreading trouble around the globe. They recommend zapping such emails immediately and never opening any accompanying attachments.

Another spam started the rounds later on, this time supposedly from Tamla Motown’s founder Berry Gordon. It promised a chance to win free copies of Michael Jackson CDs, but again proved to be bogus and dangerous.

Guest Article by Neil Camp

Share/Save/Bookmark

RSS

Want the latest antivirus reviews and news? Subscribe to our RSS feed

Blog Categories

The Editor

Alan PottsMy name is Alan Potts and I'm the Editor of the Antivirus-BUYability web site and Managing Director of BUYability Limited. You can connect with me or keep up to date with new posts on this blog via the following social media sites:

Facebook LinkedIn Plaxo Twitter StumbleUpon Plurk FriendFeed Digg Technorati Delicious

Recent Readers

© BUYability