Sign in
Microsoft Malware Protection Center
Threat Research & Response Blog
Home
About
View More Blogs
Ecosystem Strategy Blog
Microsoft Accessibility Blog
Microsoft BlueHat Blog
Microsoft Malware Protection Center Blog
Microsoft Security Blog
Microsoft Security Response Center Blog
Security Development Lifecycle Blog
Security Research & Defense Blog
Security Tips & Talk Blog
Trustworthy Computing Blog
Resources
Partner
Microsoft Safety Scanner
Microsoft Security Response Center
Microsoft Security Essentials
Microsoft Forefront
Windows Defender
Microsoft AntiSpam
MMPC
Microsoft Malware Protection Center
Microsoft Security Intelligence Report
TechNet Blogs
>
Microsoft Malware Protection Center
Follow Us
RSS for Posts
@msftmmpc
facebook
Security@Microsoft
Security Newsletter
TwC Blogs Windows Phone Application
Get on-the-go access to the latest insights featured on our Trustworthy Computing blogs.
Twitter @msftmmpc
Monthly Archives
Archives
May 2013
(10)
April 2013
(9)
March 2013
(4)
February 2013
(4)
January 2013
(6)
December 2012
(7)
November 2012
(6)
October 2012
(10)
September 2012
(4)
August 2012
(7)
July 2012
(9)
June 2012
(4)
May 2012
(4)
April 2012
(6)
March 2012
(9)
February 2012
(5)
January 2012
(8)
December 2011
(5)
November 2011
(8)
October 2011
(8)
September 2011
(7)
August 2011
(8)
July 2011
(9)
June 2011
(10)
May 2011
(13)
April 2011
(6)
March 2011
(11)
February 2011
(9)
January 2011
(4)
December 2010
(7)
November 2010
(5)
October 2010
(12)
September 2010
(10)
August 2010
(8)
July 2010
(7)
June 2010
(6)
May 2010
(5)
April 2010
(5)
March 2010
(9)
February 2010
(7)
January 2010
(3)
December 2009
(4)
November 2009
(9)
October 2009
(6)
September 2009
(8)
August 2009
(4)
July 2009
(5)
June 2009
(7)
May 2009
(8)
April 2009
(18)
March 2009
(10)
February 2009
(8)
January 2009
(5)
December 2008
(11)
November 2008
(7)
October 2008
(12)
September 2008
(8)
August 2008
(11)
July 2008
(4)
June 2008
(3)
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Microsoft Malware Protection Center
Another way Microsoft is disrupting the malware ecosystem
Posted
5 months ago
by
msft-mmpc
Like it or not, in today’s world, online advertising plays a large and important role in supporting the web. Pay-per-click (PPC) advertising, born in 1998, created a system whereby advertisers only pay when potential customers click on an advertisement's link. This system allowed companies to target very specific market segments, better gauge sales campaign performance and to only pay for what was clicked. This helped drive demand for publishers. Publishers are those people with websites or...
Microsoft Malware Protection Center
An analysis of Dorkbot’s infection vectors (part 2)
Posted
6 months ago
by
msft-mmpc
In part 1 of this series , we talked about Dorkbot and its spreading mechanisms that required user interaction. In this post, we'll talk about how Dorkbot spreads automatically, via drive-by downloads and Autorun files. Spreading vectors not requiring user interaction: Drive-by downloads and Autorun files Dorkbot can also spread automatically, without user interaction. We recently encountered a malicious Java applet that exploits the vulnerability described in CVE-2012-4681 to distribute the...
Microsoft Malware Protection Center
Smoke and mirrors and Win32/Phorpiex
Posted
6 months ago
by
msft-mmpc
This month one of the families introduced to MSRT is Win32/Phorpiex , a worm that spreads via removable drives and has IRC controlled backdoor functionality. In most respects Phorpiex is another worm, with typical command and control via IRC as well as spreading via removable drives. Like many other malware it usually does this by using Autorun, copying itself to the removable drive and writing an "autorun.inf" file to ensure execution on access, assuming the system is configured to allow autorun...
Microsoft Malware Protection Center
A technical analysis on new Java vulnerability (CVE-2012-5076)
Posted
6 months ago
by
msft-mmpc
There is a new Java vulnerability now publicly disclosed, CVE-2012-5076 . Recently, we have seen more and more Java malware and malware distributors using new vulnerabilities quicker than ever before. Here’s a brief analysis of this newly disclosed Java vulnerability and related malware. Just like the recent CVE-2012-4681 , this vulnerability is about a package access issue. But this time, it’s not caused by vulnerable code that exposes restricted packages. The malware we’ve...
Microsoft Malware Protection Center
An analysis of Dorkbot's infection vectors (part 1)
Posted
6 months ago
by
msft-mmpc
Malware nowadays benefits from the complexity of the Internet ecosystem to infect new computers through vectors such as browser plugins, social networks, and instant messaging programs. In this two-parter series, we'll look at Worm:Win32/Dorkbot, a prevalent worm with the capabilities of an IRC backdoor and a password stealer. Dorkbot relies both on social engineering attacks and on methods that don't require human intervention, such as infected removable drives and drive-by downloads. This versatility...
Microsoft Malware Protection Center
Don't fall for Folstart
Posted
6 months ago
by
msft-mmpc
We use thumb drives in different ways – usually to transfer files from one computer to another. When we create folders in thumb drives, we have a certain level of confidence that the folder isn't malicious or doesn't contain malware. Unfortunately, this assumption is not always true. For the month of November, we added the Folstart family to the Microsoft Malicious Software Removal Tool (MSRT) . Folstart is a family of worms that copies itself using the same names as folders in your USB...
Microsoft Malware Protection Center
All copy and paste makes Jack a bored boy
Posted
6 months ago
by
msft-mmpc
We recently came across what appeared to be a new sample, but was actually part of malware discovered in 2010. This new-old sample is built from publicly available source code and, like many of its kind, is frequently rebranded. Because of all the changes that malware authors have made, we have detection for each customized iteration. One such iteration (SHA1 8d81462089f9d1b4ec4c7423710cf545be2708e7) is commonly deployed under private obfuscators (such as H1N1 or Umbra). We detect this threat as...
Microsoft Malware Protection Center
Happy Halloween from the MMPC
Posted
6 months ago
by
msft-mmpc
One of my pet peeves working in computer security has always been the use of emotive language. I have always felt that using highly emotive terms to discuss malware greatly adds to the already-considerable FUD (fear, uncertainty and doubt) that surrounds a lot of malware information. The FUD, in turn, leads users to think that this is a problem that is too big for them – too daunting, too scary – when that simply isn’t true. Malware are computer programs just like other computer...
Microsoft Malware Protection Center
MSRT October '12 - Nitol by the numbers
Posted
6 months ago
by
msft-mmpc
As mentioned in our previous post , Microsoft's study [ PDF ] behind Operation b70 found that PC consumers might be at risk of malware infection even with brand new computers, if the computers come pre-installed with counterfeit versions of Windows software. This is what happened to some consumers in China who purchased their computers from an untrusted supply chain. A staggering 4 out of 20 machines were found to be infected with malware, and one of those infectors was Nitol. MMPC's infection...
Microsoft Malware Protection Center
Know your enemy - protect yourself
Posted
7 months ago
by
msft-mmpc
Of the many weapons and tricks in an attacker’s arsenal, none is more dangerous or insidious than the ability to hide and continuously compromise a system from within. This is the role of a rootkit. Malware uses rootkits, or rootkit functionality, in order to hide their presence on an affected computer and thus impede their removal. Once compromised by a rootkit, any information returned by an affected system can no longer be trusted and must be regarded as suspect (which is exactly how they...
Page 5 of 44 (440 items)
«
3
4
5
6
7
»