Zhelatin gang has updated its tactic again today. We've received its new spams. In the latest spams, a malicious domain "sup<removed>eas.com" was contained. Besides spams, we also found this malicious domain was posted on lots of blogs.
Two files, "StormCodec.exe" and "StormCodec8.exe", will be downloaded. Kaspersky detects them as Email-Worm.Win32.Zhelatin.wt.
Here is the screenshot of this malicious site:
Two files, "StormCodec.exe" and "StormCodec8.exe", will be downloaded. Kaspersky detects them as Email-Worm.Win32.Zhelatin.wt.
Here is the screenshot of this malicious site:
Adobe released a security bulletin: APSB08-11.
According to Adobe summary:
Affected software versions:
According to Adobe summary:
Critical vulnerabilities have been identified in Adobe Flash Player that could allow an attacker who successfully exploits these potential vulnerabilities to take control of the affected system. A malicious SWF must be loaded in Flash Player by the user for an attacker to exploit these potential vulnerabilities. It is recommended users update to the most current version of Flash Player available for their operating system.
Affected software versions:
Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier
It's April 2008 Microsoft patch day today.
Microsoft released 8 bulleins for this month. Five of them are Critical, three of them are Important. Please update at once.
MS08-018:Vulnerability in Microsoft Project Could Allow Remote Code Execution (950183)
MS08-019:Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (949032)
MS08-020:Vulnerability in DNS Client Could Allow Spoofing (945553)
Microsoft released 8 bulleins for this month. Five of them are Critical, three of them are Important. Please update at once.
MS08-018:Vulnerability in Microsoft Project Could Allow Remote Code Execution (950183)
MS08-019:Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (949032)
MS08-020:Vulnerability in DNS Client Could Allow Spoofing (945553)
Today is the April Fool's Day. More friends like joking on this day. The Storm Worm gang also like this day, and they come back after being inactive for a long time.
The new spams began being spread earlier today. We've received lots of spams in our mailbox. The subject lines are as the following:
The new spams began being spread earlier today. We've received lots of spams in our mailbox. The subject lines are as the following:
April Fools' Day
Happy All Fools!
Doh! April's Fool.
I am a Fool for your Love
Gotcha! All Fool!
Happy April Fool's Day.
Happy All Fools!
Doh! April's Fool.
I am a Fool for your Love
Gotcha! All Fool!
Happy April Fool's Day.
The last time Storm Worm active was Valentine Day.
Today, we monitored the Storm Worm gang began reactive. The file "postcard.exe" or "e-card.exe" will be downloaded automatically in a few seconds after users visit these websites.
The spams are like the following:
Today, we monitored the Storm Worm gang began reactive. The file "postcard.exe" or "e-card.exe" will be downloaded automatically in a few seconds after users visit these websites.
The spams are like the following:
A exploit about Rising Antivirus Online Scanner Insecure Method Flaw was published on milw0rm.com.
Rising company released a bulletin last night to fix the vulnerability in Chinese. The users of Rising Antivirus Online Scanner should visit the Rising Antivirus Online Scanner webpage to install the latest ActiveX control.
- Rising is a popular anti-virus product around China.
- there's an insecure method flaw inside its free online scanner.
- it's quite easy to exploit the bug which leads to a remote execution.
- clsid:E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153
- there's an insecure method flaw inside its free online scanner.
- it's quite easy to exploit the bug which leads to a remote execution.
- clsid:E4E2F180-CB8B-4DE9-ACBB-DA745D3BA153
Rising company released a bulletin last night to fix the vulnerability in Chinese. The users of Rising Antivirus Online Scanner should visit the Rising Antivirus Online Scanner webpage to install the latest ActiveX control.
In recent two days, we found similar spams to the Hillary Clinton video spams. The following malicious URLs are inaccessable now:
We received another spam about Hizer Mills video today. The subject lines are such as "Sensation.Video New - make haste to look!!!".
The screenshot of spams:
http://bibber.bi.funpic.de/test/bild<removed>/images/gallery/susy/rdown.php?ugeih
http://www.neufeld-media.de/Neufeld-Media/Re<removed>/news/rdown.php?lEtEmwn
http://bibo1981.bi.funpic.de/b<removed>/movie/rdown.php?ojfbG
http://www.neufeld-media.de/Neufeld-Media/Re<removed>/news/rdown.php?lEtEmwn
http://bibo1981.bi.funpic.de/b<removed>/movie/rdown.php?ojfbG
We received another spam about Hizer Mills video today. The subject lines are such as "Sensation.Video New - make haste to look!!!".
The screenshot of spams:
The United States 2008 presidential election is underway. Hillary Clinton and Barack Obama already eyeing another Super Tuesday - March 4,2008.
As while, the bad guys also eyeing the United States 2008 presidential election. We received a new trojan spam about it today. The subject lines of these spams are such as "Hillary Clinton Full Video !!!".
The screenshot of spams body:
As while, the bad guys also eyeing the United States 2008 presidential election. We received a new trojan spam about it today. The subject lines of these spams are such as "Hillary Clinton Full Video !!!".
The screenshot of spams body:
Today Microsoft released its biggest batch of monthly patches, releasing 11 security updates to patch 17 vulnerabilities, six of which are Critical, five of which are Important.
The critical bulletins are include the following:
The critical bulletins are include the following:
MS08-007: Vulnerability in WebDAV Mini-Redirector Could Allow Remote Code Execution(946026)
MS08-008: Vulnerability in OLE Automation Could Allow Remote Code Execution(947890)
MS08-009: Vulnerability in Microsoft Word Could Allow Remote Code Execution(947077)
MS08-010: Cumulative Security Update for Internet Explorer(944533)
MS08-012: Vulnerabilities in Microsoft Office Publisher Could Allow Remote Code Execution (947085)
MS08-013: Vulnerability in Microsoft Office Could Allow Remote Code Execution (947108)
MS08-008: Vulnerability in OLE Automation Could Allow Remote Code Execution(947890)
MS08-009: Vulnerability in Microsoft Word Could Allow Remote Code Execution(947077)
MS08-010: Cumulative Security Update for Internet Explorer(944533)
MS08-012: Vulnerabilities in Microsoft Office Publisher Could Allow Remote Code Execution (947085)
MS08-013: Vulnerability in Microsoft Office Could Allow Remote Code Execution (947108)




April 9, 2008 20:13 




