Java is at the center of yet another security storm after Polish security researchers found not one, but two new separate zero-day flaws in the Web plug-in software.Web users are once again warned to disable Java immediately to prevent any infection on production machines or networks. Read thisAmid a serious security flaw in the latest version of Java 7, where even the U.S. Department of...
Thứ Năm, 28 tháng 2, 2013
Thứ Ba, 26 tháng 2, 2013
Thứ Năm, 21 tháng 2, 2013



How the adventure started..It's mid-February and we find the scientist David Banner searching for information concerning tax mattters involving charitable giving and fundraising when he clicks through a Google search link to h00p://jonesfortenberry.com. Suddenly an Anti-Virus scan begins to run. After a few moments Dr. Banner is informed that his machine has numerous infections."Windows Security...
Thứ Tư, 20 tháng 2, 2013



BackgroundThis is more than just a malware analysis blog post. Morelike a threat report or updates of a cyber crime group activity that continuing their malicious operation and distribution method, that we think people who use internet must aware about. The spam driven credentials/PWS stealer group we track, that is known for infecting trojan to steal credential via Blackhole Exploit Exploit Kit,...
Thứ Tư, 13 tháng 2, 2013


The hpHOSTS Hosts file has been updated. There is now a total of 185,378 listed hostsnames.If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)Latest Updated: 13/02/2013 23:00Last Verified: 13/02/2013 18:00Download hpHosts now!http://hosts-file.net/?s=Downl...
Thứ Bảy, 9 tháng 2, 2013


It was all started from a curiosity, and ending up into a serious analysis, testing and reporting..So we have the SWF exploitation of CVE-2013-0634 and I dare myself to analyze of what we suspect as the sample of it, to try to understand what is really going on there. Warning :-) I am a unix engineer and not a Flash developer, so bear with some missing in here and there. There are still so many unsolved...
Thứ Sáu, 8 tháng 2, 2013


Another day, another phish (as if that'll surprise anyone). This time, it's targeting Steam users.Already working on takedown, but in the meantime, you'll want to block;g1fts4free.free.lcIf you've been to this, or any other Steam related site recently, I strongly recommend you change your password - just in case.Hat tip to horiaonof...
Thứ Năm, 7 tháng 2, 2013


Influx of PayPal phishes this morning, 30 so far, since 09:53.So far, whilst the subjects have been slightly varied, the href have all remained the same, with all leading to;49paypal.com/73ecc8e60844c7b6e67fa3897b6f134d/01.phpThe domain has been registered through Internet.BS, and lives at;IP: 63.90.228.38IP PTR: Resolution failedASN: 701 63.80.0.0/12 UUNET - MCI Communications...
Thứ Tư, 6 tháng 2, 2013


Everyone using Facebook will already be seeing the same thing, so nope, not a warning about Facebook Spam.I actually detest social networking sites, the only reason I've got an account on Facebook, is for finding and investigating scams and malware on it.Since creating the test account, there's been a flurry of spam every single day from Facebook, with the usual "you have more friends than...
Thứ Ba, 5 tháng 2, 2013



[NEW!] New case infection w/same payload type & infection MO in different domain.Landing page: 3thtyjtyjcc.ns02.us/closest/209tuj2dsljdglsgjwrigslgkjskga.phpPayload: ZeroAccessExploit: Java: #CVE-2010-4476 #CVE-2013-0422, PDF: #CVE-2010-0188, CVE-2009-0927Sorry for the report in text--> http://pastebin.com/raw.php?i=HPESHngh I am on a half way on a plane of a long trip, got many spare time...
Đăng ký:
Bài đăng (Atom)