Sign in
Microsoft Malware Protection Center
Threat Research & Response Blog
Home
About
View More Blogs
Ecosystem Strategy Blog
Microsoft Accessibility Blog
Microsoft BlueHat Blog
Microsoft Malware Protection Center Blog
Microsoft Security Blog
Microsoft Security Response Center Blog
Security Development Lifecycle Blog
Security Research & Defense Blog
Security Tips & Talk Blog
Trustworthy Computing Blog
Resources
Partner
Microsoft Safety Scanner
Microsoft Security Response Center
Microsoft Security Essentials
Microsoft Forefront
Windows Defender
Microsoft AntiSpam
MMPC
Microsoft Malware Protection Center
Microsoft Security Intelligence Report
TechNet Blogs
>
Microsoft Malware Protection Center
Follow Us
RSS for Posts
@msftmmpc
facebook
Security@Microsoft
Security Newsletter
TwC Blogs Windows Phone Application
Get on-the-go access to the latest insights featured on our Trustworthy Computing blogs.
Twitter @msftmmpc
Monthly Archives
Archives
June 2013
(1)
May 2013
(11)
April 2013
(9)
March 2013
(4)
February 2013
(4)
January 2013
(6)
December 2012
(7)
November 2012
(6)
October 2012
(10)
September 2012
(4)
August 2012
(7)
July 2012
(9)
June 2012
(4)
May 2012
(4)
April 2012
(6)
March 2012
(9)
February 2012
(5)
January 2012
(8)
December 2011
(5)
November 2011
(8)
October 2011
(8)
September 2011
(7)
August 2011
(8)
July 2011
(9)
June 2011
(10)
May 2011
(13)
April 2011
(6)
March 2011
(11)
February 2011
(9)
January 2011
(4)
December 2010
(7)
November 2010
(5)
October 2010
(12)
September 2010
(10)
August 2010
(8)
July 2010
(7)
June 2010
(6)
May 2010
(5)
April 2010
(5)
March 2010
(9)
February 2010
(7)
January 2010
(3)
December 2009
(4)
November 2009
(9)
October 2009
(6)
September 2009
(8)
August 2009
(4)
July 2009
(5)
June 2009
(7)
May 2009
(8)
April 2009
(18)
March 2009
(10)
February 2009
(8)
January 2009
(5)
December 2008
(11)
November 2008
(7)
October 2008
(12)
September 2008
(8)
August 2008
(11)
July 2008
(4)
June 2008
(3)
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Microsoft Malware Protection Center
Revenge of the Reveton
Posted
over 1 year ago
by
msft-mmpc
Computer users around the world are increasingly accustomed to managing their bank accounts, paying their bills and performing other activities online. The use of technology to manage finances has long been a target of attackers, and malware authors continue to create scams that try to persuade potential victims to provide access to their valuable personal information, including logon credentials for online accounts. Trojan:Win32/Reveton.A is a recent example of malware that attempts to phish these...
Microsoft Malware Protection Center
MSRT April 2012: Win32/Claretore
Posted
over 1 year ago
by
msft-mmpc
We included three threat families in the April edition of the Microsoft Malicious Software Removal Tool - Win32/Claretore , Win32/Bocinex and Win32/Gamarue . In this post, we discuss Win32/Claretore. The earliest reported variant in this family can be traced back to November 2011. Claretore is a trojan that injects itself into running processes to intercept browser traffic and redirect the browser to an attacker-defined URL. It also sends information about the affected computer to a remote server...
Microsoft Malware Protection Center
Microsoft and partners disrupt Zeus botnets
Posted
over 1 year ago
by
msft-mmpc
We have discussed in the past our collaboration with external parties to combat botnet threats to further the betterment of the Internet, such as Operations b49 , b107 and b79 . This week, Microsoft has partnered with security experts and the financial services industry on a new action codenamed Operation b71 to disrupt some of the worst known botnets using variants of the notorious Zeus malware (which we detect as Win32/Zbot ). Due to the complexities of these targets, unlike Microsoft’s...
Microsoft Malware Protection Center
Vulnerability analysis, practical data flow analysis and visualization
Posted
over 1 year ago
by
msft-mmpc
Recently at CanSecWest 2012, we presented on the technology we use for analyzing malicious samples and PoC files. As malware often actively attempts to exploit software vulnerabilities these days, understanding the internals of these vulnerabilities is essential when writing defense logic. Out of the many methods that can be used for vulnerability analysis, we presented a method that uses dynamic binary instrumentation and data flow analysis. Dynamic binary instrumentation and data flow analysis...
Microsoft Malware Protection Center
Piecing the malware puzzle – Exploring a spike in exploit activity
Posted
over 1 year ago
by
msft-mmpc
In this post, we explore a telemetry spike in Java/OpenConnection and CVE-2011-3544 exploit activity. While reviewing user feedback from the Microsoft Malware Protection Center recently, we noticed an unprecedented amount of feedback on one particular Java/OpenConnection variant -- TrojanDownloader:Java/OpenConnection.PK . Such interest in this type of Java applet-based exploit is quite unusual, and prompted us to investigate further. A signature for this threat was introduced on February 22...
Microsoft Malware Protection Center
An interesting case of JRE sandbox breach (CVE-2012-0507)
Posted
over 1 year ago
by
msft-mmpc
Recently we received a few samples that exploit the latest patched JRE (Java Runtime Environment) vulnerability. These samples are kind of unusual to see, but they can be used to develop highly reliable exploits. The malicious Java applet is loaded from an obfuscated HTML file. The Java applet contains two Java class files - one Java class file triggers the vulnerability and the other one is a loader class used for loading. The vulnerability triggering class is actually performing deserialization...
Microsoft Malware Protection Center
Ransomware: Playing on your fears
Posted
over 1 year ago
by
msft-mmpc
The last two years have seen an increase in malware which takes control of, and holds hostage an infected machine, locking the user out until a payment of some form can be extorted. This threat type is also known as 'ransomware'. Various tactics have been used by the malware writers in an attempt to intimidate users into paying a ransom in order to get back control of an infected machine. We wrote a blog post last December that describes malware extortion tactics, here . Scare tactics include...
Microsoft Malware Protection Center
MSRT March: Three Hioles in one
Posted
over 1 year ago
by
msft-mmpc
In a previous post , we discussed Win32/Dorkbot , one of the major threat families included in the March 2012 release of MSRT. In this post, we discuss the other inclusions, Win32/Hioles , Win32/Pluzoks and Win32/Yeltminky . Win32/Hioles Similar to last month's focus on Win32/Pramro , Win32/Hioles is another trojan that resides on the computer and functions as a proxy server. The first variant was identified in mid-2011. One popular infection vector for the malware is via spammed messages containing...
Microsoft Malware Protection Center
MSRT March 2012: Breaking bad
Posted
over 1 year ago
by
msft-mmpc
This month, the MMPC added Win32/Dorkbot to the Microsoft Malicious Software Removal Tool along with detections for the threats Win32/Hioles , Win32/Pluzoks and Win32/Yeltminky . Win32/Dorkbot is described as an IRC-based botnet and a worm, a backdoor with rootkit capability and a password stealer. Despite using a very simple IRC protocol to communicate with the command and control (C&C) server, it was able to build a substantial installation base after a couple of years in operation. Some...
Microsoft Malware Protection Center
There's a cream for that
Posted
over 1 year ago
by
msft-mmpc
The other day, while previewing messages in my inbox, I saw a conspicuous message with the following parameters, typos included: To: (email address) CC: (email address),... Subject: Your ex sent me this pciture of you. Body: Hey (email address), Your ex sent me this picture claiming it's you. Is it really so? You probaly should see a doctor:) They can cure it now:). Attachment: " Photo.zip " The attached file is a ZIP archive that contains an executable file named " IMG04958.exe " ( SHA1...
Page 10 of 45 (442 items)
«
8
9
10
11
12
»