ASE Labs
Welcome Guest. Please register or log in now. There are 45 people online (0 Friends).
  • Home
  • Articles
  • News
  • Forum
  • Register/Login
You are at ASE Labs » News » Cybercriminals Continue to Spam Victims While Posing as Popular Companies According To GFI Software

Cybercriminals Continue to Spam Victims While Posing as Popular Companies According To GFI Software

Poster: SySAdmin
Posted on July 6, 2012 at 8:49:01 AM
Cybercriminals Continue to Spam Victims While Posing as Popular Companies According To GFI Software

Internet users are urged to monitor for red flags in any unsolicited email messages and to exercise caution when clicking on unknown links

CLEARWATER, Fla., July 6, 2012 /PRNewswire/ -- GFI Software today released its VIPRE® Report for June 2012, a collection of the 10 most prevalent threat detections encountered last month. In June, GFI threat researchers observed two fresh spam campaigns linking to Blackhole exploits which posed as confirmation emails from Twitter® and Amazon.com®. Delta Airlines® similarly had their brand misappropriated in a spam campaign meant to infect users with Sirefef and rogue antivirus software. GFI also hosted a free webinar which provided a detailed look at the Flame virus using data gathered from GFI's own GFI Sandbox(TM) technology.

(Logo: http://photos.prnewswire.com/prnh/20120330/NE79547LOGO )

"Cybercriminals are ever focused on infecting as many victims' machines or stealing as much personal information with as little effort as possible. By disguising the source of their spam as messages from companies or organizations with widespread appeal, they can increase the number of potential victims likely to fall for their scams," said Christopher Boyd, senior threat researcher at GFI Software.  "Any notices or 'confirmation emails' that arrive unexpectedly, no matter how legitimate it may appear, should be thoroughly inspected before the user takes any other action. If something seems out of place, users should trust their instincts and use common sense before clicking anything that could make the situation worse."

Throughout the month of June, phony emails claiming to be Amazon.com order confirmations were sent to unsuspecting victims in the hopes of infecting them with malware. Users who clicked any of the links contained in the email were directed to a web page that contained Blackhole exploit code. The exploit scanned the user's system for Adobe® Reader® and Adobe Flash® before loading a Java applet that redirected the victim to web pages that hosted specially-crafted PDF exploit files depending on the version of Adobe Reader found on the system.

Another fake email posing as a Twitter account confirmation linked victims to a Russian website which housed a Blackhole exploit kit. The site deployed exploits that targeted Adobe Reader and Adobe Flash vulnerabilities which were as old as six years. It's important to note that both of these attack campaigns could have been avoided had victims kept their software fully patched and up to date.

A bogus spam email was also discovered disguising itself as a Delta Airlines e-ticket. Users who downloaded the attachment were met with an executable file that infected their system with Sirefef and Live Security Platinum, a rogue antivirus program. This fake AV program blocked the running of all other applications and deployed constant pop-ups and browser redirects to messages alerting the user of an infection and requesting payment to clean up the system.

Analyzing Flame
In June, The GFI Software Flame Task Force identified malware behavior exhibited by Flame not yet reported by other security vendors or malware researchers. To learn how GFI threat researchers were able to generate 100MB of detailed malware behavioral data on Flame in less than 5 minutes using GFI SandBox, please visit http://vimeo.com/44382073.

Top 10 Threat Detections for June
GFI's top 10 threat detection list is compiled from collected scan data of tens of thousands of GFI VIPRE Antivirus customers who are part of GFI's ThreatNet(TM) automated threat tracking system. ThreatNet statistics revealed that Trojans continued to dominate the month, taking six of the top 10 spots.

    Detection                     Type             Percent
    Trojan.Win32.Generic          Trojan                   31.51
    GamePlayLabs                  Browser Plug-in           5.79
    Trojan.Win32.Small            Trojan                    2.97
    Trojan.Win32.Sirefef.pq (v)   Trojan                    2.48
    Yontoo (v)                    Adware                    2.45
    Trojan.Win32.Fakealert.cn (v) Trojan                    1.24
    INF.Autorun (v)               Trojan                    1.06
    GameVance                     Adware (General)          0.96
    Trojan.Win32.Ramnit.c (v)     Trojan                    0.84
    iBryte                        Adware (General)          0.83
About GFI Labs
GFI Labs specializes in the discovery and analysis of dangerous vulnerabilities and malware. The team of dedicated security specialists actively researches new malware outbreaks, creating new threat definitions on a constant basis for the VIPRE home and business antivirus products.

About GFI
GFI Software provides web and mail security, archiving and fax, networking and security software and hosted IT solutions for small to medium-sized businesses (SMB) via an extensive global partner community. GFI products are available either as on-premise solutions, in the cloud or as a hybrid of both delivery models. With award-winning technology, a competitive pricing strategy, and a strong focus on the unique requirements of SMBs, GFI satisfies the IT needs of organizations on a global scale. The company has offices in the United States, UK, Austria, Australia, Malta, Hong Kong, Philippines and Romania, which together support hundreds of thousands of installations worldwide. GFI is a channel-focused company with thousands of partners throughout the world and is also a Microsoft Gold ISV Partner.

For more information
GFI Software
Please email David Kelleher at dkelleher@gfi.com
GFI - Malta: Tel: +356 2205 2000; Fax: +356 21382419.
URL: http://www.gfi.com.

Davies Murphy Group
Please email Jason Gass at gfi@daviesmurphy.com
GFI - US: Tel: +1-781-418-2439

Disclaimer
Copyright © 2012 GFI Software. All rights reserved. All other trademarks are the property of their respective owners. To the best of our knowledge, all details were correct at the time of publishing; this information is subject to change without notice

SOURCE  GFI Software

Photo:http://photos.prnewswire.com/prnh/20120330/NE79547LOGO
http://photoarchive.ap.org/
GFI Software

Web Site: http://www.gfi.com/
 
Print This Entry
Tags PR Press Release
Related Articles
  • KingsIsle Expands Pirate101 With Two New Worlds
  • Hamilton Watches to Close the Cannes Film Festival with Zulu by Jerome Salle
  • =?ISO-8859-1?Q?Supermicro=AE_Announces_the_Highest_Density_Server?= =?ISO-8859-1?Q?_Solutions_with_Coming_Intel=AE_Haswell_Processors?=
  • Game-Changer Beamforming Microphone Array Takes Another Leap Ahead and Now Features Tabletop and Wall Mode Capabilities
  • IGXE Successfully Launches Shopping Mall Mode: A New Era Is Coming
Login
Welcome Guest. Please register or log in now.
Forgot your password?
Navigation
  • Home
  • Articles
  • News
  • Register/Login
  • Shopping
  • ASE Forums
  • Anime Threads
  • HardwareLogic
  • ASE Adnet
Latest News
  • Welcome to the new server
  • Gmail Gets Optional Preview Pane
  • HBO Go on Consoles
  • HP Touchpad Update
  • Happy System Administrator Day!
  • Apple Releases OS X 10.7 Lion
  • More Android Apps Found to be Malware
  • This Weeks News
  • Happy Birthday USA!
  • Windows Phone Gets Angry Birds, Custom Rings Coming To Mango
Latest Articles
  • Sapphire Edge HD4 Mini PC
  • Logitech G710+ Mechanical Gaming Keyboard
  • EnerPlex Kickr IV And Jumpr Solar Power Pack
  • Kingston Wi-Drive
  • Kingston SDX10V/128GB SDXC Memory
  • In-Win K1 All In One Convertible Case
  • Kingston MobileLite G3 USB3 SDXC Card Reader
  • Synology DS712+ Network Application Server
  • Rapoo Wireless Touchpad Keyboard E9080
  • Netgear NeoTV NTV200 Streaming Player
Latest Topics
  • Pokemon: The Ongaku Region
  • Random Fact of the Day
  • What are you listening to now?
  • ufc 160
  • watch iron man 3 online free
  • watch scary movie 5 online free
  • watch tyler perry's temptatinon online free hd 2013
  • watch movies online free without downloading
  • watch star trek into darkness online free
  • watch fast and furious 6 online free
  • Recharge your cellphone in 20 seconds
  • Qu'est-ce charme si fascinant
  • Some Legacy of Music From Standard Pandora Beads
  • track down those behind the brutal
  • Minister David Cameron said Britain
  • Britain would be "absolutely resolute"
Advertisement
Advertisement
Affiliate Reviews
  • A New X.Org-Free Wayland LiveCD Released at Phoronix
  • GCC 4.8.0 vs. LLVM Clang 3.3 Compiler Performance at Phoronix
  • Unity 8, Mir Made Progress This Week On Features at Phoronix
  • LLVM Clang 3.3 RC2 Is Ready For Testing at Phoronix
  • AMD RadeonSI Gallium3D Begins Simple CL Demos at Phoronix
  • Intel Shows Off GNOME3-Based Tizen Shell at Phoronix
  • Wine 1.5.31 Pulls In New Gecko Release at Phoronix
  • NVIDIA GeForce Chips Comparison Table at Hardware Secrets
  • Deep Cool M6 2.1 Speaker System ad Laptop Cool Review at Pro-Clockers
  • Microsoft Announces Mice with Windows 8 Start Button Built-in at Hardware Secrets
  • EVGA GTX 780 Superclocked w/ ACX Cooler 3 GB Review at techPowerUp!
  • Linux Desktop Security Could Be A Whole Lot Better at Phoronix
  • KDE 4.11 Will Be The Last Major KDE4 Workspaces Feature Release at Phoronix
  • New NVIDIA Linux Driver Supports The GeForce GTX 780 at Phoronix
Press Release
  • KingsIsle Expands Pirate101 With Two New Worlds
  • Hamilton Watches to Close the Cannes Film Festival with Zulu by Jerome Salle
  • =?ISO-8859-1?Q?Supermicro=AE_Announces_the_Highest_Density_Server?= =?ISO-8859-1?Q?_Solutions_with_Coming_Intel=AE_Haswell_Processors?=
  • Game-Changer Beamforming Microphone Array Takes Another Leap Ahead and Now Features Tabletop and Wall Mode Capabilities
  • IGXE Successfully Launches Shopping Mall Mode: A New Era Is Coming
  • Got Words? New Word Game "Words in a Pic" Tops Global Mobile Charts
  • Infor Announces Cloud Initiative Using Amazon Web Services to Tackle Big Data With Amazon Redshift
  • HP's New MFPs Deliver Increased Productivity With Reduced Costs
  • CompanionLink Injects Business Companion for Verizon's Galaxy S4
  • Walmart Statement on Hisense Sero 7 Tablet Launch
Home - ASE Publishing - About Us
© 2010 Aron Schatz (ASE Publishing) [Queries: 16 (8 Cached)] [Rows: 292 Fetched: 35] [Page Generation time: 0.038824081420898]