Sign in
Microsoft Malware Protection Center
Threat Research & Response Blog
Tags
Adobe
API
autorun
backdoor
botnets
conference
conficker
CVE-2008-5353
CVE-2009-3867
CVE-2010-0094
CVE-2010-0840
CVE-2010-2568
CVE-2010-3654
CVE-2011-3544
CVE-2012-0507
DEP
ecard
EIP
Eleonore
exploits
EyeStye
Facebook
fake auctions
fake meds
FakePAV
FakeRean
FakeSysdef
FBI
Fedripto
Firefox
Folstart
FOPE
Forefront Endpoing Protection
Forefront Threat Management Gateway
form grabbing
Fort of Agra
Frank Simorjay
fraud
FTC
Fynloski
guidance
hacking
hex
Holly Stewart
identity theft
IE9
Internet Explorer
Java
JavaScript
kernel32
Malicious Software Removal Tool
malware
malware research
MBR
Microsoft Safety Scanner
Microsoft Security Essentials
MMPC
MSRT
packers
Pages
passwords
PDF exploit
phishing
piracy
privacy
research
rogue
scam
Security Intelligence Report
Shockwave Flash
SIR
SIR v10
SIR v11
SIR v9
SMS
social engineering
spam
telemetry
trojan
TwC
Vinny Gullotto
vulnerability
Vundo
Waledac
Win32/Cridex
Win32/Cycbot
Win32/Dofoil
Win32/Dursg
Win32/FakeRean
Win32/Hioles
Win32/Qakbot
Win32/Ramnit
Win32/Rimecud
Win32/Rustock
Win32/Sality
Win32/Taterf
Win32/Tracur
Win32/Winwebsec
Win32/Zbot
worm
Browse by Tags
TechNet Blogs
>
Microsoft Malware Protection Center
>
All Tags
>
spam
Tagged Content List
Blog Post:
Insights into Win32/Bradop
msft-mmpc
Have you heard of Win32/Bradop? We recently investigated this interesting data theft family in more detail and exposed some of its inner secrets. The following is a description of what we found out. Spoiler alert: spam emails, protectors, the download mechanism, database credentials, stolen data, and...
on
15 Jun 2012
Blog Post:
There's a cream for that
msft-mmpc
The other day, while previewing messages in my inbox, I saw a conspicuous message with the following parameters, typos included: To: (email address) CC: (email address),... Subject: Your ex sent me this pciture of you. Body: Hey (email address), Your ex sent me this picture claiming it's you. Is it...
on
12 Mar 2012
Blog Post:
Stratfor customers targeted by cybercriminals
msft-mmpc
Cybercriminals are continuing to use a social engineering trick to lure users for their malware campaigns. This time, they targeted customers of Stratfor - a subscription-based provider of geopolitical analysis. Attacks against Stratfor clients began after a reported breach of their customer database...
on
13 Feb 2012
Blog Post:
Friendly spam carries Zbot
msft-mmpc
This morning I spotted a few messages from my mobile carrier in my email inbox. This was not surprising as, only a few hours prior, I had logged into the carrier's website to pay the monthly bill. The standard mode of operation for my provider is to receive a bill via email, and a confirmation message...
on
6 Dec 2011
Blog Post:
MSRT November: Dofoil
msft-mmpc
As previously noted , one of the three families added to the November release of the Microsoft Malicious Software Removal Tool is Win32/Dofoil . TrojanDownloader:Win32/Dofoil is a configurable downloader. Dofoil will attempt to receive control instructions from a remote server. The response contains...
on
22 Nov 2011
Blog Post:
Getting tagged and your privacy
mmpc2
This morning my Facebook email address was invaded with spam ( scam-spam as I call it) from people in my friends list with subject titles similar to the following: “ <Some Friend1> invited you to the event You Gotta See This Exciting Feature!!<random number>" “ <Some Friend 2>...
on
21 Jun 2011
Blog Post:
Fake Canadian pharma site causing headaches
mmpc2
I awoke the other day to a friend calling me and exclaiming into the phone: “My Yahoo email account was hacked !!!” He had been angrily accused by others in his contact list of sending spam messages and sharing inappropriate website links. Most of the questions he fielded had the same query: " Why...
on
1 Jun 2011
Blog Post:
Slick links linked to slinky Winwebsec
mmpc2
I received a spam email from a friend lately after which I immediately notified him of a potential malware infection. He insisted his technician had taken care of the infection once and for all. After I returned from my vacation I received another three spam mails from him. This time...
on
3 May 2011
Blog Post:
Scam emails - the cost of response
mmpc2
Recently, I received an email in my personal inbox with a subject line “MYSTERY SHOPPER ASSISTANT“ (the message did not filter to my junk folder and was not marked as spam). Image 1 – “Mystery shopper assistant” spam I’m familiar with the hobby of mystery shopping – a service provided under contract...
on
20 Apr 2011
Blog Post:
Doctor Who calling–on Skype, with malware
mmpc2
Earlier this week, I received a phone call via Skype on my laptop, the caller’s ID was “ dralerthelpzc8 ” as in Dr Alert Help ZC8 . The voice on the other end was automated, computerized and otherwise non-human, and alerted me that I had a virus that affects Windows Vista, Windows XP and Windows 7 and...
on
15 Apr 2011
Blog Post:
Analysis of the CVE-2011-0611 Adobe Flash Player vulnerability exploitation
mmpc2
About a month ago, we blogged about an Adobe Flash Player vulnerability ( CVE-2011-0609 ) that was actively exploited in the wild. That exploit was hidden inside a Microsoft Excel document. Over the weekend, a new Adobe Flash Player 0-day ( CVE-2011-0611 ) was reported by Adobe in a recent advisory ...
on
12 Apr 2011
Blog Post:
Trojan downloader Chepvil on the UPSwing
mmpc2
A new spam campaign using UPS (United Parcel Service) as a social-engineering draw was initiated this week. The spammed message contains an attachment, detected as TrojanDownloader:Win32/Chepvil.I . The spam campaign actually started around March 16th 2011. The threat was originally detected as Backdoor...
on
25 Mar 2011
Blog Post:
Operation b107 - Rustock Botnet Takedown
msft-mmpc
Just over one year ago, Microsoft- with industry and academic partners- utilized a novel combination of legal and technical actions to take control of the Win32/Waledac botnet as the first action in Project MARS (Microsoft Active Response for Security). Today, a similar action has had its legal...
on
17 Mar 2011
Blog Post:
MSRT January ‘11: Win32/Lethic
mmpc2
Win32/Lethic is a trojan that communicates with a remote server to distribute spam. Variants of Lethic install executable files with varied file names such as “ shelldm.exe ” or “ xcllsx.exe ”. The malware loads as a process when Windows starts. The trojan establishes a connection to remote servers using...
on
11 Jan 2011
Blog Post:
Phishing encounter while on vacation
mmpc2
It was my first night in Beijing for a long-overdue vacation. I purchased a SIM card from the airport and sent SMS greetings to friends and family and other families in town. SMS is hugely popular and a main communication channel in China. Guess what? The first SMS I received was from a strange number...
on
23 Dec 2010
Blog Post:
Where is Waledac - Episode II
mmpc2
The Spambot Whilst Win32/Waledac is probably best known for the ability to send spam, it can also download and execute arbitrary files. In addition to using this downloading mechanism to update itself, Waledac can also download other malware. The MMPC has observed the download of Trojan:Win32/FakeSpypro...
on
7 May 2009
Blog Post:
Closing In on Open Relay Mail Servers
mmpc2
About four months ago some new colleagues in the security business arrived in our Dublin office. They are part of Microsoft Anti-spam team and it is our pleasure to have them here :) The Dublin Spam team recently told us that almost every week, Microsoft Forefront Online Security for Exchange is filtering...
on
5 May 2009
Blog Post:
Where's Waledac?
mmpc2
The family added to the April MSRT release is Win32/Waledac . If you haven't heard of the family before, there is a chance you may have seen some of the spam generated by Win32/Waledac in your inbox. We've blogged about some of the spam campaigns in the past, such as Fake Obama or the Valentine Devkit...
on
14 Apr 2009
Blog Post:
Cashing in on Conficker's Bad Name
mmpc2
Over the last couple of days we've seen some spam claiming to be from Microsoft, providing a free scan to remove Conficker . Here's an example: The link actually takes you to a typical fake online scanner page used to serve up a rogue security scanner: In this case the page tries to get you...
on
9 Apr 2009
Blog Post:
Spam - What the Doctor Ordered?
mmpc2
Periodically I'll glance into my spam folder within Outlook and see if the messages there deserve this somewhat final resting place. I spotted a number of messages that have a very similar pattern in the message body when viewed in plain-text mode - see if you can spot the pattern too... c'mon, it'll...
on
9 Mar 2009
Blog Post:
Little Red Riding Hood or Big Bad Wolf? Your Sweetheart or Waledac?
mmpc2
Valentine's Day is almost here. While your friends and loved ones are crafting their e-cards, malware authors are also releasing their annual love letters into the mix. Win32/Waledac started a bit early, we noticed it’s Valentine theme spam mails as early as January 26th. However, as Valentine's Day...
on
13 Feb 2009
Blog Post:
MSRT February 2009 - Win32/Srizbi
mmpc2
This month's MSRT takes on one of the largest botnets currently active worldwide – Win32/Srizbi . The Srizbi family of malware consists of trojan droppers and rootkits that often spread through spam e-mails containing download links to the malware. Much like its alleged close cousin Win32/Rustock...
on
10 Feb 2009
Blog Post:
Waledac Trojan Hosted by Fake Obama Website
mmpc2
“Now that Inauguration Day is upon the US, malware authors have a new spate of social engineering tricks up their sleeve.” We've seen Barack Obama's name used by malware authors for malevolent purposes before, during the campaign and leading up to the US Presidential Elections. Now that Inauguration...
on
19 Jan 2009
Blog Post:
O Come All Ye Malware
mmpc2
Well, after our last post, it certainly didn't take long to see some examples of festive malware from the wild. (You'd almost think that we've seen this kind of behavior before - again and again and again...) In the last couple of days, we (and other AV vendors) have observed the arrival of several new...
on
4 Dec 2008
Blog Post:
Merry Malware - You’d better watch out, you’d better think twice…
mmpc2
With visions of sugarplums dancing through my head constantly from around September onwards, I eagerly (and somewhat obsessively) await the festive season every year. As heralded by my son opening the first box on his advent calendar this morning to liberate the toy hidden within, as far as I am concerned...
on
2 Dec 2008
Page 1 of 2 (28 items)
1
2