Archive for 2008

Another Holiday, Another E-Card Run – Waledec

December 21, 2008 by Jose Nazario

But this time it’s not Storm, nor does it even seem at all like Storm. This one is dubbed Waldec. Infection strategy: entice email users to come to the website and get a greeting card. No graphics, but it will entice you anyhow. “Daniel just mailed to you an Online greeting card.” Thanks, Daniel! Subject [...]

Read More

Busy Little Phishing Botnet

December 14, 2008 by Jose Nazario

Today it’s an American Express phish. In the past few weeks it’s been JPMorgan Chase, Bank of America, CitiGroup, Colonial Bank, and many others. All of them are using fast flux hosting techniques on the same hosts. I don’t know the name of this botnet (either the malcode or the coloquial name) but it sure [...]

Read More

Distributed SSH Brute Force Attacks

December 5, 2008 by Jose Nazario

Recently a couple of news reports have come in that suggest that someone has changed how they do SSH brute force attacks: Spike in failed SSH logins could be beginnings of a coordinated attack, ISC says from the TechTarget blogs on October 22. Distributed SSH attacks bypass blacklists posted on Heise Security today A low [...]

Read More