Oct14
by
Christopher Talampas (Fraud Analyst)
Trend Micro threat analysts were recently alerted to a phishing attempt targeting random employees of several companies. The email posed as a notification from the company's “system administrator,” reminding the employee to update his/her system's software due to a recent server software upgrade. The spammed email contained a URL using several subdomains that resolved to the same IP address.
Trend Micro Advanced Threats Researcher Joey Costoya believes the subdomains are tailor-made, depending on the recipent's email address. This makes the email ...
Oct7
by
Ryan Flores (Advanced Threats Researcher)
You’ve probably read or heard about KOOBFACE malware propagating through social networking sites such as Facebook, MySpace, and Twitter. A lot of analysis is available online through blogs or malware descriptions. But I bet most of you probably still do not know some or all of these things about KOOBFACE.
KOOBFACE knows: KOOBFACE has the capability to steal whatever information is available in your Facebook, MySpace, or Twitter profile. Profile pages of these social networking sites may contain information about one’s contact ...
Sep17
by
Jonell Baltazar (Advanced Threats Researcher)
The Koobface botnet is widely known to install FAKEAV or rogue antivirus malware onto a victim's PC. It has a dedicated component which actually installs the FAKEAV onto the user's system. However, the Koobface gang has added a new twist to its fake Facebook page.
When the user closes the window/tab with the fake Facebook page, a popup window appears. Whatever button the user clicks, this new Koobface variant is downloaded onto the affected system. Here's a video that illustrates this ...
Industry experts have previously estimated that, on average, a compromised machine remains infected for 6 weeks. However, our latest research indicates that this estimate is far from accurate. During the analysis of approximately 100 million compromised IP addresses, we identified that half of all IP addresses were infected for at least 300 days. That percentage rises to eighty percent if the minimum time is reduced to a month. This data can be seen graphically below:
Figure 1. Infection data by country
The ...
Aug24
by
Robert McArdle (Senior Malware Researcher)
We at Trend Micro Research recently produced a short blog series on the Pushdo botnet, a botnet which excelled at staying under the radar for a considerable amount of time. Pushdo is not alone in this regard however: enter Ilomo.
Ilomo has also being active for several years now, and like Pushdo has done so without attracting too much unwanted attention from the security industry. Like Pushdo, the Ilomo threat is quite modular in nature which makes it difficult to see ...