Blog

Rogueware

A new fake email which pretends to be from Adobe is in the wild and spreading on the Internet. The email has an attachment which contains an executable file having PDF icon. If the user gets convinced by this email and executes the file the computer gets infected. The sample...
Another Facebook spam pretending that the viewers account has been blocked is currently circulating on the Internet. The subject is: “Facebook Service# Your account has been blocked! Order/8236”. The email comes with an attachment called ‘New_Password_FB_1148.zip’. The zip file contains an executable file ‘New_Password.exe’, which tries to fool the victim...
Today we received a mail which pretends to have come from FedEx and it looks as shown below. As seen from the image, the attachment is actually a UPX packed executable file which looks like an invoice document. After execution of the binary, it dropped a copy of itself and...
News about the death of Steve Jobs is being exploited by cyber-criminals who are sending spam emails associated with this incident. The spam email may carry one of the following subjects: – Steve Jobs: Not Dead Yet. – Is Steve Jobs Really Dead? – Steve Jobs Alive! – Steve Jobs...
We all know if you want your ordered goods to be at your doorstep then you opt for DHL. But cyber-criminals are now taking advantage of DHL emails and they are now sending fake emails with the same format to random users. The email shows up the following screenshot: This...
The growing popularity of Android and the tendency of users to store important data on their mobile phones are attracting many hackers. They are targeting users of Google Android mobile operating system with a malicious application that harvests personal information, controls the system and sends it to a remote server....
If you get an email message telling you a hotel has erroneously charged your credit card account, be careful. The odds are that it’s part of a new spam campaign that could infect your computer. The messages started popping up in recent days and there are already many variants of...
We’re seeing a significant “spam attached malware” campaign in the past 48 hours with different attachment MD5s. 3305f83abf31fc66fa8f588b35be8eb2 8e3331b64a5884e1ef4f4c8a3d09bc7a The username portion of the email sender is random, using a classic misspelling that has been consistent. Usernames are a single word, followed by a “.”, “_” or “-“, followed by...
The Chepvil malware which comes via email as an attachment is using another trick to spread itself. You may receive an email stating to be from IRS.gov and with the subject line – “IRS Notification Letter”. The email is as shown below: The attachment comes with the name ‘IRS document.rar’....