Archive for November, 2008

This BofA Demo Thing Got Big Fast

November 27, 2008 by Jose Nazario

The Obama spam and malcode gang is back at it with a new fast flux phishing and malcode ruse. This time it’s a demo from the Bank of America that requires the classic “Flash Upgrade”. At the peak I was seeing 400 unique URLs for this run an hour. The URLs were unique strings, possibly [...]

Read More

New OS X Malcode: Not Just a DNSChanger

November 24, 2008 by Jose Nazario

Seems that Apple’s OS X has been taking a minor beating in the malcode front lately, as noted in the blog post New Trojans Strike OS X from CA. I got a copy of it last night and had a look, I wanted to see what the OS X malcode community was up to. The [...]

Read More

TheatIndex Unchanged at 1: MS08-067

November 21, 2008 by Jose Nazario

Symantec has rained their TheatCon to 2, citing: The ThreatCon is at level 2. Symantec Threat Management System sensors are observing a dramatic rise in IPs attacking TCP port 445. This activity is corroborated by activity on our honeypot systems. Currently this activity appears to be related to the exploitation of the vulnerability addressed by [...]

Read More