DLL-Based FAKEAV Returns, in the Wild Again

In our previous FAKEAV white paper, we presented how Trend Micro researchers tracked down the evolution of FAKEAV and followed its development behaviorwise from one generation to the next. One of the earlier generations (fourth, to be exact) in the paper comprises DLL-based FAKEAV—fake antivirus that use a .DLL file to perform all of their malicious routines to primarily [...]

DLL-Based FAKEAV Returns In The Wild

In our previous FAKEAV whitepaper, we presented how Trend Micro researchers tracked down the evolution of FAKEAV and classified its development, behavior-wise, according to generations. One of the early generations listed in the paper can be recalled as the DLL-based FAKEAV (4th Generation) — a FAKEAV group that uses a DLL file to perform [...]

Yahoo! PH Purple Hunt 2.0 Ad Compromised

Earlier the other day, I was browsing through the Yahoo! PH site and the Yahoo! Purple Hunt 2.0 ad caught my attention. Curious, I clicked the ad and found my browser downloading a suspicious file named com.com. Apparently, this ad redirected me to a randomly generated URL similar to the following, which unfortunately led to [...]

Epsilon Security Connect Tool Steals More Information From Users

We were recently made aware of attacks leveraging the recent data breach that involved Epsilon. According to reports, the attack involves a web page that looks very similar to the press release issued by Epsilon concerning the breach incident. The page also instructs the recipient to click a link at the bottom of the post, [...]

Despite the Headlines, SLAAC Does Not Represent a Zero-Day Attack Vector

SLAAC is a mnemonic for IPv6 StateLess Address AutoConfiguration, which follows attempts at obtaining router information that happens only after the interface has established an IPv6 address for the local link. IPv6 does not use Ethernet broadcasting, which imposes scaling limitations on the devices supported on a local link. Instead, IPv6 multicasting divides devices into 16.7 [...]