Sign in
Microsoft Malware Protection Center
Threat Research & Response Blog
Home
About
View More Blogs
Ecosystem Strategy Blog
Microsoft Accessibility Blog
Microsoft BlueHat Blog
Microsoft Malware Protection Center Blog
Microsoft Security Blog
Microsoft Security Response Center Blog
Security Development Lifecycle Blog
Security Research & Defense Blog
Security Tips & Talk Blog
Trustworthy Computing Blog
Resources
Partner
Microsoft Safety Scanner
Microsoft Security Response Center
Microsoft Security Essentials
Microsoft Forefront
Windows Defender
Microsoft AntiSpam
MMPC
Microsoft Malware Protection Center
Microsoft Security Intelligence Report
TechNet Blogs
>
Microsoft Malware Protection Center
>
June, 2011
June, 2011
Follow Us
RSS for Posts
@msftmmpc
facebook
Security@Microsoft
Security Newsletter
TwC Blogs Windows Phone Application
Get on-the-go access to the latest insights featured on our Trustworthy Computing blogs.
Twitter @msftmmpc
Monthly Archives
Archives
June 2013
(1)
May 2013
(11)
April 2013
(9)
March 2013
(4)
February 2013
(4)
January 2013
(6)
December 2012
(7)
November 2012
(6)
October 2012
(10)
September 2012
(4)
August 2012
(7)
July 2012
(9)
June 2012
(4)
May 2012
(4)
April 2012
(6)
March 2012
(9)
February 2012
(5)
January 2012
(8)
December 2011
(5)
November 2011
(8)
October 2011
(8)
September 2011
(7)
August 2011
(8)
July 2011
(9)
June 2011
(10)
May 2011
(13)
April 2011
(6)
March 2011
(11)
February 2011
(9)
January 2011
(4)
December 2010
(7)
November 2010
(5)
October 2010
(12)
September 2010
(10)
August 2010
(8)
July 2010
(7)
June 2010
(6)
May 2010
(5)
April 2010
(5)
March 2010
(9)
February 2010
(7)
January 2010
(3)
December 2009
(4)
November 2009
(9)
October 2009
(6)
September 2009
(8)
August 2009
(4)
July 2009
(5)
June 2009
(7)
May 2009
(8)
April 2009
(18)
March 2009
(10)
February 2009
(8)
January 2009
(5)
December 2008
(11)
November 2008
(7)
October 2008
(12)
September 2008
(8)
August 2008
(11)
July 2008
(4)
June 2008
(3)
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Microsoft Malware Protection Center
Malware packer integrates with UPX
Posted
over 2 years ago
by
mmpc2
Recently while I was analyzing a bunch of samples packed by custom packers, one of them struck me as a bit different than any others I saw before. At first glance, the outer layer of packing is a UPX stub, which is commonly used in malware. Especially when combined with a custom packer, UPX can provide an excellent compression ratio. Since it's packed by UPX, I first unpacked it with a static unpacker and examined the dump. The heavily obfuscated code at the entry point easily leads me to think there...
Microsoft Malware Protection Center
MSRT June 2011: Targeting Yimfoca
Posted
over 2 years ago
by
msft-mmpc
This month's MSRT families included Win32/Rorpian (an autorun worm that exploits a vulnerability in shortcut files), Win32/Nuqel (another autorun worm that spreads via network drives, removable drives, and instant messaging programs) and Win32/Yimfoca . The last, Yimfoca, is a prevalent IM worm that uses common instant messaging applications and social networking websites to spread. It also affects security settings on the infected computer. Aside from stopping the Windows Update service and thus...
Microsoft Malware Protection Center
Don’t write it, read it instead!
Posted
over 2 years ago
by
mmpc2
The bootkit malware Trojan:Win32/Popureb.E has made some changes in its code compared to previous samples (specifically, Trojan:Win32/Popureb.B), and now it introduces a driver component to prevent the malicious MBR and other malicious data stored as disk sectors from being changed. The driver component protects the data in an unusual way – by hooking the DriverStartIo routine in a hard disk port driver (for example, atapi.sys). The following steps describe the trick: It calls IoGetDeviceAttachmentBaseRef...
Microsoft Malware Protection Center
Getting tagged and your privacy
Posted
over 2 years ago
by
mmpc2
This morning my Facebook email address was invaded with spam ( scam-spam as I call it) from people in my friends list with subject titles similar to the following: “ <Some Friend1> invited you to the event You Gotta See This Exciting Feature!!<random number>" “ <Some Friend 2> tagged you on Facebook ” The messages appeared suspicious to me, enough to trigger my “internal alert system”, and it made me wonder why so many of my friends fell for these silly antics? The scam is...
Microsoft Malware Protection Center
Exploits for CVE-2011-2110 focus on Korea
Posted
over 2 years ago
by
msft-mmpc
Last week, Adobe released an update ( APSB11-18 ) for Adobe Flash Player, fixing a memory corruption vulnerability (CVE-2011-2110) that would allow attackers to take control of the targeted system. In the Advisory, Adobe mentioned reports of active exploitation. We have been tracking the use of this exploit through our signatures (originally as Exploit:SWF/ShellCode.A, and then later as Exploit:SWF/CVE-2011-2110.A ) released to Microsoft Security Essentials and Forefront customers for a number of...
Microsoft Malware Protection Center
Interesting Snowflake
Posted
over 2 years ago
by
msft-mmpc
There's a WinRAR file floating around in the Internet named "2012桌面雪花.rar" * (SHA1: 889cf7076d4c08637e8aeedf7a90dc4a3808f991), which can be downloaded or may be sent out as an attachment in an email message, that contains a program that claims to display beautiful snowflakes on your desktop. If you run the executable contained in the archive (file name "桌面雪花.exe" - SHA1: 7255f61cada0815bc0fa2fb12f5b3c89db7e786d), it does what it claims: It is beautiful, right? But wait, non-beautiful things...
Microsoft Malware Protection Center
MSRT June Release, taking care of a few worm families
Posted
over 2 years ago
by
mmpc2
In this month's MSRT release, we added three new threat families to the detection capability. One of these three is Win32/Nuqel , which has been around for four years since its first variant was found. More than 60 variants of Win32/Nuqel have been identified in the wild. This worm spreads itself via network shares, removable drives and instant messenger programs. These combined spreading methods make it very efficient in propagating, and it has gained prevalence lately. Aside of the typical Autorun...
Microsoft Malware Protection Center
Autorun-abusing malware (Where are they now?)
Posted
over 2 years ago
by
msft-mmpc
On Feb. 8, Microsoft started releasing updates for the Windows XP and Vista platforms to make the Autorun feature more locked-down on those older platforms by preventing AutoPlay from being enabled automatically (except when it comes to "shiny media" such as CDs and DVDs). We knew we would want to come back sometime later to measure how the update changed the rate of infection for these families. That time is now. Let's have a look. As reported in volume 10 of the Microsoft Security Intelligence...
Microsoft Malware Protection Center
May MSRT by the numbers
Posted
over 2 years ago
by
mmpc2
In May, we added Win32/Ramnit to the Microsoft Removal Tool (MSRT) detection capability, as my colleague Scott Molenkamp blogged . As of May 20th, MSRT disinfected 52,549 computers from the Win32/Ramnit infection. Ramnit is one of the four parasitic viruses out of the top 10 detected threat families. Top 25 detections by MSRT, May 10 – May 20 Family Machine Count Note Sality 202,351 Classic parasitic virus Taterf 77,236 Worm Rimecud 65,149 Worm Vobfus 59,918 Worm Alureon 58,884 Evolved parasitic...
Microsoft Malware Protection Center
Fake Canadian pharma site causing headaches
Posted
over 2 years ago
by
mmpc2
I awoke the other day to a friend calling me and exclaiming into the phone: “My Yahoo email account was hacked !!!” He had been angrily accused by others in his contact list of sending spam messages and sharing inappropriate website links. Most of the questions he fielded had the same query: " Why did you send me to this site!? " He was pretty shocked about the ordeal and called me for help. After checking my inbox, I too had received a message from my friend. We did a quick check...
Page 1 of 1 (10 items)