Subscribe to RSS feeds

Archive for the ‘Security’ Category

Jul15
by Joey Costoya (Advanced Threats Researcher)

Below is a screenshot of the spammed email message in the spam run we've been monitoring since last week (still pointing to the bogus PornTube page). Only this time, the landing page of the email link is not R.HTML, but rather MAIN.HTML. Figure 1. Sample spam with the main.html link. The following are some of the subject lines used: • US government war brothels • Barack Obama graft trial begins • Obama outrageous lies exposed • Iran announces completion of nuclear weapon On the other hand, the ...

Posted in Security | 1 TrackBack »

Jul11
by Jasper Pimentel (Advanced Threats Researcher)

May's series of Web site compromises were replaced with spam and spoofed sites last June. Users were also served with a bigger serving of spam with a malware aftertaste, as many of the malware that emerged this month used were distributed through spam links. Notable Malware TROJ_PIDIEF.AC This malware, which could be downloaded from a malicious URL, was revealed to have the capability to exploit an unknown vulnerability in Adobe Acrobat. When exploited successfully, Acrobat would download another malware from the same malicious ...

Posted in Security |

Jul9
by JM Hipolito (Technical Communications)

The increase in attacks targeting job hunters calls for more security measures for both of job recruitment sites owners and job seekers alike, especially on the disclosure and access of information being posted by job seekers. A service involving a tool that scours through popular US job recruitment sites to harvest jobseekers’ information right from their curriculum vitas (CV) is currently being offered by the Russian gang, Phreak, TheRegister reports. The tool uses a predefined recruiter ID which it uses to ...

Posted in Security |

Jul4
by Fatima Bancod (Fraud Analyst)

Trend Micro Content Security engineers just received a timely Apple Store phishing email. This attack comes well after Apple introduced the 3G iPhone to the consumer market early last month—and conveniently nestled the week before it actually becomes available in stores (in most countries) next week. Figure 1. Hovering your mouse above the link shows its real destination. The URL loads the following phishing page that asks the user for personal information, such as the user’s credit card type, credit card number, ...


Jun25
by Jovi Umawing (Technical Communications)

Photobucket, one of cyberspace's more popular image-sharing Web sites, was attacked by the Turkish hacker group NetDevilz, as reported in forums, discussion boards, and security blog posts. The Register also reported of the attack. Hackers were said to have used a Domain Name Server (DNS) hack that leads anyone who accesses photobucket.com to be redirected not to the legitimate page, but to a greeting page from the hackers who performed the attack. A screenshot of the said page can ...



© Copyright 2008 Trend Micro IncAll rights reserved. Legal Notice