Facebook Spam Now Plays Your Favorite Music

Wouldn’t it be cool if you had immediate access to your favorite music and bands? What if these are readily available on your favorite social networking site? Unfortunately, spammers also find this cool. We recently noted messages and wall posts circulating on Facebook that promote a supposed new music player feature. Below is a [...]

Trend Micro Researchers Identify Vulnerability in Hotmail

A couple of days ago, my colleagues reported an attack which appears to be targeted, and involves emails sent through a webmail service. Upon further investigation, we were able to confirm that this attack involves a previously unpatched vulnerability in Hotmail. Trend Micro detects the malicious email messages as HTML_AGENT.SMJ. The said attack requires [...]

CARBERP Sinkholing Speculations

This report is related to the results of the sinkholing activity we conducted on a CARBERP communication-and-control (C&C) server. Our findings were initially published in this blog post. We contacted identifiable hosts that may have been affected by the CARBERP infections monitored by a particular C&C server. Beyond typical name/account information and perhaps information related with [...]

CARBERP Sinkhole Findings

We were recently able to sinkhole a CARBERP command and control (C&C) server, similar to the way in which we sinkholed a ZeuS C&C in March of this year. This post will explain our findings during the said activity. The results have basically led us to conclude that CARBERP has proven once more that malware creators [...]

From the Love Bug to Scary Predators

(Or, How Money Makes the Web Go ‘Round) May is an important month in the IT security industry because it’s the anniversary of one of the most fearsome viruses ever: the ILOVEYOU virus, also known as the Lovebug. Back in 2000, it was a very big deal because it created a new way of infecting [...]