::Trend Micro Threat Resource Center::

13 August 2009

52 percent of new viruses only last 24 hours

Every day, PandaLabs receives nearly 37,000 samples of new viruses, worms, Trojans and other types of Internet threats, 52 percent of which (that is 19,240 on average) spread and try to infect users for just 24 hours. After this, they become inactive and harmless as they are replaced by other, new variants that join the list of new specimens in circulation.

The reason for this lies in hackers’ motivation to profit financially from malware. To do this, they try to ensure their creations go unnoticed by users and security solution vendors.

Just 24 hours after they put any strain of malware into circulation, they will modify its code so that it can continue to spread without being detected by security companies.

According to Luis Corrons, Technical Director of PandaLabs, “This is a never-ending race which, unfortunately, the hackers are still winning. We have to wait until we get hold of the malware they have created to be able to analyze, classify and combat it. In this race, vendors that work with traditional, manual analysis techniques are too slow to vaccinate clients, as the distribution and infection span is very short.”

12 August 2009

How Do They Know My Email Address?

Have you received email messages in the last several weeks with several random words in the subject line, and a random sentence in the message body? If your answer is yes, then you are one of the victims of the ongoing directory harvesting attack (DHA) by spammers.

The purpose of a DHA is to find valid email addresses on a domain for future spam attacks. During a DHA attack, any addresses for which the recipient’s email server accepts email are considered valid and will be added to the spammer’s address database to include in future spam attacks.

For example:

Sample #1:

From: joannjasmin8xs@xxxxxx.com
Subject: land

Those journalists showed them a photograph.

Sample #2:

From: clariceboldin9cg@xxxxxx.com
Subject: okay then

They told her the shortest way.

DHA is more than just an annoyance for email recipients. Every successful DHA attack equals one or more email address being subjected to future spam/malware attacks. Furthermore, these attacks also generate a large volume of unnecessary workload and consume significant amounts of system resources on the recipient’s email server. Symantec is closely monitoring these attacks and will inform readers of any further developments.

Credits

09 August 2009

DDoS Attackers Continue Hitting Twitter, Facebook, Google

While it was reported earlier that Twitter is still struggling to recover form the DDOS attacks, the latest update seems to prove otherwise.

And to add on to the action, Google's Blogger blog publishing services were not spared as well. According to a Google spokeman, a small percentage of Blogger users have experienced error messages as the result of what appears to be an ongoing distributed denial of service attack aimed at multiple services across the web.

It is predicted that this DDOS may persist throughout the weekend.

07 August 2009

Twitter & Facebook taken down by denial-of-service attack

Twitter spent the later part of the week fighting off a DOS (denial of service) attack, that also targeted fellow social-media site Facebook.

Social media sites Facebook and Twitter took a beating over the weekend after both were subjected to a DOS attack. Twitter was down for two hours on Thursday and still suffered from the attacks on Friday.

Facebook reported that people had trouble accessing the site on Thursday, but resolved the situation late that morning Pacific Time. A blogger from Georgia claimed that the Russian government sponsored the attacks in an effort to silence him for speaking out against the country's handling of Georgia.

While Twitter was mum on the attacks' motivation, a Facebook spokeswoman said they were directed at an "activist blogger" -- possibly the Georgia advocate -- rather than the sites themselves.

Email Scams Targeting Job Seekers

Email security firm Red Condor has issued a warning to email users about the latest email scams that are targeting people looking for employment.

Among the scams are emails that claim to be offering employment from legitimate companies such as Pepsi and Starbucks or that appear as messages from real job sites like CareerBuilder or Monster.com.

The fake employment offers frequently involve "payment processing" requests which give scammers an excuse to ask for a respondent's bank account information.

In addition to email spam, other scammers are using Craigslist to post fake job ads. When people respond to the ads, they receive an email reply that requires them to go to a "credit check" website to get their credit scores. The credit check link contains the scammer's affiliate, so when the victims pay for the credit check, the scammer gets a commission.

An email response to "Legal Secretary job posting" on craigslist email said, "Do not send me your info or report, I just want to make sure your score is above the 400 mark so check it and give me your exact score when you e-mail me your resume and references."

"Unfortunately, as with all phishing attacks, there is no legitimate employment offer coming, and victims have either given their personal information or money to unknown, deceitful sources," said Dr. Tom Steding, chief executive officer of Red Condor.

"Spammers are once again demonstrating that nothing is off limits as they focus their efforts on the millions of people that are unemployed and looking for work.

06 August 2009

Mobile Malware Targeting Smartphones

Nearly one out of every 63 smartphones powered by the Symbian operating system is infected with some form of malware, according to a new study by mobile security firm SMobile Systems.

A comparison of these statistics to the worldwide smartphone population places the number of infected devices globally in the millions. Because the vast majority of these infections are designed to be stealthy and the fact few smartphones have Anti-Malware applications, most infected users are unaware their devices have been compromised.

Throughout 2009 SMobile's Global Threat Center has seen an increase in the capabilities of new malware infecting mobile devices, as well as frequency of attacks. The attacks have taken the form of worms and Trojans that are transmitted via Bluetooth, SMS, MMS, or emails, as well as Spyware that is downloaded from various online application and shareware websites.

Detailed report here.