Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Monday, September 10, 2012

Emma Watson Named Web's Most Dangerous Celebrity in 2012


Emma Watson lands atop McAfee's annual list of Most Dangerous Celebrity in Cyberspace. The "The Perks of Being a Wallflower" actress replaces last year's No. 1 champ Heidi Klum on the yearly list released by the Internet security firm.

According to McAfee, "searching for the latest Emma Watson pictures and downloads yields more than a 12.6% chance of landing on a website that has tested positive for online threats, such as spyware, adware, spam, phishing, viruses and other malware."




Sitting behind the "Harry Potter" star on the second place is Jessica Biel. The fiancee of Justin Timberlake occupied the first place in 2009 and sat at the fourth spot last year. Rounding up the top 3 is a new addition to the list, actress Eva Mendes.



Klum is out of the top-10 list, while 2010's most dangerous celebrity Cameron Diaz claims the eighth place, six spots lower than last year's position. Others are Selena Gomez, Halle Berry, Megan Fox, Shakira, Salma Hayek and Sofia Vergara.


  1. Emma Watson
  2. Jessica Biel
  3. Eva Mendes
  4. Selena Gomez
  5. Halle Berry
  6. Megan Fox
  7. Shakira
  8. Cameron Diaz
  9. Salma Hayek
  10. Sofia Vergara
source: aceshowbiz.com


Thursday, April 5, 2012

Sophos: New wave of scareware attacks target Easter-related searches

People searching for Easter-related items such as "eggs," "chocolate" and "bunnies" may have to think twice before clicking on the sites that come out on top of the search results.

Computer security firm Sophos warned Friday (Manila time) a new wave of scareware attacks is targeting computer users searching for the term "Easter."

Sophos said it noted an increase in the volume of search engine optimization (SEO) attacks that put malware-hosting sites on top of the search results.

"(W)ith Easter imminent, it is not surprising that SEO attacks we have seen this week have used topics such as 'eggs,' 'chocolate' and 'bunnies,'" Sophos said in a blog post.

"This is a good time to remind people about the dangers of blindly trusting search engine results," it added.

It noted the first search result may lead to a site with fake anti-virus (scareware), one of which called itself "Windows Care Taker."

Sophos said a variety of rogue info sites are used in the scareware installation, with fresh ones being registered and used all the time.

"The reason why SEO attacks are successful is that all of us tend to trust search engine results. After searching for something we happily click any of the links high up in the first page of results," it noted.

Sophos said its products can identify the components involved in the attack as Mal/SEORed-A, Mal/FakeAvJs-A, Mal/FakeAV-PY.

"Before you click on search engine results, cast a quick glance at the site in question. This may not always help, but if the domain looks completely unrelated to the topic you are interested in, think carefully before clicking," it advised.

As for those using browsers that support plug-ins, it advised them to consider hiding or modifying their referrer.

"(T)he SEO attacks rely on knowing you came via a search engine when you click through to the SEO page," it said. — LBG, GMA News

source: gmanetwork.com

Tuesday, March 27, 2012

Microsoft Employees and U.S. Marshals Raid Offices, Seize Zeus Botnet Servers

Last Friday, Microsoft employees, along with some U.S. Marshals, raided office buildings in Scranton, Pennsylvania and Lombard, Illinois and seized servers thought to be used by botnets for identity theft. The botnet in question is related to Zeus malware, which utilizes keyloggers to snag users’ financial information and is thought to be responsible for around 13 million infections across the globe. That’s part of the reason Microsoft took the initiative to handle things personally; the other part was trademark infringement.

Seizing botnet servers seems like the sort of thing that should be law enforcement territory, but Microsoft’s own Digital Crimes Unit (DCU) got clearance to get their hands dirty after filing a civil suit regarding trademark violations, at which point they were given permission to take a stab at the botnet’s command and control structures with the help of some Marshals. Microsoft claims that Zeus software, which allows its user to wield the botnet, is sold for anywhere between $700 and $15,000 and utilizes many of the seized servers to carry out its dirty work.

Considering the Zeus botnet is comprised of many, many computers, the server seizure isn’t going to take down the whole network. In fact, given the way the botnet is structured, a complete takedown may be practically impossible. Even so, Microsoft maintains that the seizure of these servers should make botnet operation at least a little bit harder and should help stem the tide of Zeus infections for the time being. In the meantime, Microsoft is taking the opportunity to take a very hands-on approach to dealing with botnet identity theft and cyber-crime on the whole. Despair ye, Internet criminals; Microsoft-man is gunning for you.

source: http://www.geekosystem.com/microsoft-dcu-botnet-seizure/

Saturday, March 10, 2012

Bigger bank-hitting Trojan malware seen

A Trojan malware targeting banks now poses an even bigger threat by using compromised websites that infect visitors’ computer systems.

Computer security firm BitDefender said the sites open a seemingly innocent HTML page detected as Trojan.JS.QOS, which asks visitors to “Please wait while page is loading.”

BitDefender said the page actually contains a tricky JavaScript that redirects users to another malicious JavaScript file detected as Trojan.JS.Redirector.YF.

Zbot a.k.a Zeus, ZeusBot or WSNPoem, is a banker Trojan with backdoor and server capabilities. It collects bank-related information, login data, history of the visited Web sites and other sensitive details. Some versions may even snatch screenshots of the compromised machine’s desktop.

“It appears this malicious JS file has been planted on a multitude of servers that host otherwise clean websites, probably as a result of FTP credentials theft. This script has the sole purpose of redirecting the user to the exploit page, the final stop in this redirection trip,” it said in a blog post.

The second HTML page, detected as Trojan.HTML.Downloader.Agent.NBF, embeds a Java applet (Exploit.Java.CVE-2010-0840.P) to download and install a Zbot variant (Trojan.Zbot.HTQ) on the compromised systems.

BitDefender has made available a removal tool for free download and use. It can be downloaded from the Removal Tools section of its Malwarecity.com website.

In the meantime, it advised computer users not to click on just any old site.

“Most importantly, if a website redirects you towards another web location, close it at once. Last but not least, keep your Java Runtime updated at all times,” it said. — TJD, GMA News

source: gmanetwork.com