Tampilkan postingan dengan label Malware Spam n Trojan - English. Tampilkan semua postingan
Tampilkan postingan dengan label Malware Spam n Trojan - English. Tampilkan semua postingan

Minggu, 06 Juli 2008

The Great S.P.A.M. Experiment

Malware is known to piggyback on spam, finding entry to millions of computers at home and in the workplace. Spam is not just a nuisance, it can be dangerous without the proper software protection.
A few months ago, McAfee (News - Alert), Inc., the anti-virus and anti-malware folks, launched its global S.P.A.M. (Spammed Persistently All Month) Experiment. For 30 days a cross section of the world’s population (a group of 50 consisting of housewives, students, retirees, government officials, etc.) were given spanking clean laptops, an email address absolutely no anti-spam software, and then asked to surf the web unprotected, buy things online and register for promotional items. Then McAfee set up blogs for the participants at www.mcafeespamexperiment.com so they could describe their experiences, as McAfee tallied how much spam was arriving in each respective email mailbox.

McAfee discovered that the average web user will collect 70 spam messages each day.
The U.S. participants topped the list, with 23,233 spam emails received. In second place was Brazil with 15,856. Italy was next with 15,610, then Mexico with 12,229. The U.K. came in fifth with 11,965. Australia had 9,214, The Netherlands 6,378, Spain 5,419, France 2,597, and Germany 2,331.
Many of the bloggers noted how their systems were slowing down over time, which suggests that malware arriving in spam or websites they visited was installing itself and usingCPU power to conduct some nefarious activities – such as use the host PC to send out more spam. About 8 percent of the spam consisted of so-called ‘phishing’ emails that attempt to blatantly trick or otherwise cajole users into divulging their various usernames, passwords and account numbers.
Spam recently celebrated its 30th “anniversary”, so to speak. 30 years ago (May 3rd, 1978) to be exact, there was a great minicomputer company, now part of Hewlett Packard, called DEC (Digital Equipment Corporation). Gary Thuerk, a marketer at DEC, decided to send an email to 393 users of the ARPANET, the predecessor of the Internet. That fateful email — now considered to be the first example of spam, started off as follows: “DIGITAL WILL BE GIVING A PRODUCT PRESENTATION OF THE NEWEST MEMBERS OF THE DECSYSTEM-20 FAMILY; THE DECSYSTEM-2020, 2020T, 2060, AND 2060T.”
Thuerk apparently wasn’t familiar with the ‘Sndmsg’ email program. The email addresses inadvertently overflowed into the body of the text, resulting in not all the intended 393 recipients receiving the spammed message. That didn’t stop the one who did receive it from being incredibly angry. They claimed it was an illegal use of the ARPANET.
Recently, Adaptive Mobile (www.adaptivemobile.com), a mobile security company, marked the 30th anniversary of spam by pointing out how spammers are moving their efforts to mobile phones. A YouGov report estimates that two thirds of mobile users in the U.K. have received mobile spam or phishing attacks. In China, mobile users receive six to ten spam message a day.
It appears that spam evolves along with the technology it leverages.

unique spam

Why content filtering doesn't work

Other systems rely on looking for things that are bad.

Filtering on content is a losing proposition. While it seems like a logical way to eliminate spam, it's not effective because spammers are using these filters to get around them. Content filters are constantly being improved.

How we solve the problem

The fact is, compared to the total number of email addresses, your business only communicates with a small fraction of them. There are only a small number of people that your business communicates with.

Content filtering doesn't work. Behaviorial filtering does.

If you wanted to discuss Viagra with someone by email, chances are you couldn't, because a content filter would block your message. Our system knows the difference between the people you want to talk to, and strangers, and applies different rules.

Our system revolves around a database of relationships between senders and recipients. When you send a message to someone, they are automatically whitelisted.

Configurable from domain down to address level.

There is no one way to filter mail that works for everyone.

The result

  • Drastic reduction in spam. Most spam comes from personal computers that have been hijacked by spammers. EMFilter virtually eliminates spam from these sources.
  • Drastic reduction in bandwidth usage. If you run your own filtering system, spammers are using your bandwidth. EMFilter only passes good messages to your server, eliminating wasted bandwidth.

EMFilter's servers are constantly being updated and improved.

Save your organization time and money.

14 years experience developing and operating large-scale mail services.

We also offer IMAP and QMTP services.

Your mail is backed up.

Redundant.

emvault.com

expert assistance

Spam (electronic)

From Wikipedia, the free encyclopedia

Jump to: navigation, search
An email box folder of spam messages.
An email box folder of spam messages.

Spamming is the abuse of electronic messaging systems to indiscriminately send unsolicited bulk messages. While the most widely recognized form of spam is e-mail spam, the term is applied to similar abuses in other media: instant messaging spam, Usenet newsgroup spam, Web search engine spam, spam in blogs, wiki spam, mobile phone messaging spam, Internet forum spam and junk fax transmissions.

Spamming remains economically viable because advertisers have no operating costs beyond the management of their mailing lists, and it is difficult to hold senders accountable for their mass mailings. Because the barrier to entry is so low, spammers are numerous, and the volume of unsolicited mail has become very high. The costs, such as lost productivity and fraud, are borne by the public and by Internet service providers, which have been forced to add extra capacity to cope with the deluge. Spamming is widely reviled, and has been the subject of legislation in many jurisdictions.[citation needed]

Persons who create electronic spam are called spammers.[1]

E-mail spam

From Wikipedia, the free encyclopedia

Jump to: navigation, search
An e-mail program detecting spam messages. Spammers frequently disguise their messages with obfuscated text.
An e-mail program detecting spam messages. Spammers frequently disguise their messages with obfuscated text.

E-mail spam, also known as "bulk e-mail" or "junk e-mail," is a subset of spam that involves nearly identical messages sent to numerous recipients by e-mail. A common synonym for spam is unsolicited bulk e-mail (UBE). Definitions of spam usually include the aspects that email is unsolicited and sent in bulk.[1][2][3][4][5] "UCE" refers specifically to "unsolicited commercial e-mail."

E-mail spam slowly but exponentially grew for several decades to several billion messages a day. Spam has frustrated, confused, and annoyed e-mail users. Laws against spam have been sporadically implemented, with some being opt-out and others requiring opt in e-mail. The total volume of spam (over 100 billion emails per day as of April 2008) has leveled off slightly in recent years, and is no longer growing exponentially. The amount received by most e-mail users has decreased, mostly because of better filtering. About 80% of all spam is sent by fewer than 200 spammers.[citation needed] Botnets, networks of virus-infected computers, are used to send about 80% of spam.[citation needed] The cost of spam is borne mostly by the recipient, so it is a form of postage due advertising.

E-mail addresses are collected from chatrooms, websites, newsgroups, and viruses which harvest users' address books, and are sold to other spammers. Much of spam is sent to invalid e-mail addresses. ISPs have attempted to recover the cost of spam through lawsuits against spammers, although they have been mostly unsuccessful in collecting damages despite winning in court.[6][7]

The word “spam”, in relation to unwanted e-mail, should not be spelled with all capitals as such spelling used in this sense might infringe on the rights of the legal copyright owner of the SPAM® brand

Diary of a Deliberately Spammed Housewife

For Tracy Mooney, a married mother of three in Naperville, Ill., the decision to abandon cyber-sense and invite e-mail spam into her life for a month by participating in a McAfee experiment was a bit of a lark.

The idea of the Spammed Persistently All Month (S.P.A.M.) experiment -- which fittingly started on April Fool's Day -- was to have 50 volunteers from around the world answer every spam message and pop-up ad on their PC.

What would be the experience in 10 countries when everyday people, armed with a PC and e-mail account McAfee provided for the Global S.P.A.M. Diaries project, clicked through the spam and chronicled the results?

Mooney -- who had observed the family's PC crippled just before Christmas by a virus -- was game, especially because McAfee was giving a free PC to all participants. She was selected to be among the 50 volunteers picked by McAfee out of 2,000 people who applied to be part of the adventure.

By the time it was all over, after every bank-account phishing scam, Nigerian bank scheme, and offer for medication, adult content and just plain free stuff had been pursued. "I was horrified," says Mooney, a realtor by profession. "It's all snake oil. I'm amazed at what true junk is out there when you're clicking through on e-mail."

McAfee is releasing the results Tuesday of its free-wheeling month-long S.P.A.M. experiment, done largely to illustrate -- if you didn't know already -- how spam is connected to malware and criminal activity, not to mention some of the slimiest marketing ever devised. (Compare antispam products.)

Each S.P.A.M. volunteer saw an average of 70 spam messages arrive in their in-box each day, with men receiving about 15 more per day than women. That was a lot to answer, but "Penelope Retch" -- the alias that Mooney chose for her S.P.A.M. adventure -- answered every single message.

In her guise as Penelope Retch, Mooney answered the e-mail that came into her account. "I'd see an interactive spam, open it, click on it and asked to be removed. That would only make it worse," she says. "They'd say 'no.'"

Whether trying to win an iPod online, get free travel brochures, weight-loss tea or Maybelline eyeliner, the effect of entering a home address was extreme. Immediately, a deluge of mail landed at her doorstep, directed to the attention of Penelope Retch.

"One of the mail offers I got was a $7,500 credit card for Penelope Retch," Mooney says, noting that the sudden upsurge in junk mail left the neighborhood postman somewhat aghast. "It grew exponentially, so I stopped giving out my home address," she says, adding, "I am concerned about the environment."

Mooney clicked through on the phishing e-mails for fake Wells Fargo and other bank sites, sat back as the supposed government of Nigeria sought to give her an inheritance, and watched a foreign IP address go after a dummy PayPal account that had been set up as part of the S.P.A.M. experiment.

Overall, the most obvious result of the S.P.A.M. experiment was that the PC that McAfee had provided for the project noticeably slowed down, clogged up with spyware, Mooney says.

According to McAfee, which selected five participants from each of 10 countries for the S.P.A.M. experiment, the five U.S. participants received the most spam: 23,233 messages over the course of the month.

Brazil and Italy were in the 15,000-plus category, and Mexico and United Kingdom above 10,000. Australia, The Netherlands and Spain were in the 5,000 to 9,000-plus spam range. The S.P.A.M. volunteers in France and Germany got the least, less than 3,000 for the month. McAfee didn't even include what it calls "grey mail" (e-mail that arrived after participants signed up for a newsletter, for example) in this count.

Phishing e-mail accounted for 22% of the spam received by the Italian volunteers and 18% of the U.S. ones. In general, spam appears to still largely be delivered in English; French- and German-language spam were the only non-English spam to amount to more than 10% of spam received by the participants in France and Germany respectively.

Some oddball facts that emerged from the experiment are that fake Chase.com was the most common phishing e-mail spotted during the project, and that the British volunteers received the most Nigerian scam e-mail.

In addition to Mooney, the other S.P.A.M. participants also kept a blog about the experience, which some found amusing and others disturbing. One participant in Australia named Marika wrote, "I don't know whether I would feel safe to surf to that extent again. I tried to sign up for jobs that would generate an at-home income with what seemed like respectable sites, however these sites led to massive amounts of spam."

For more information about enterprise networking, go to NetworkWorld. Story copyright 2008 Network World Inc. All rights reserved.

Trojan Poses as July 4th Video

As predicted, hackers tried to trick users into downloading the Storm bot Trojan Friday by unleashing a flood of Fourth of July spam bearing links to malicious sites, several security companies reported.

The spam campaign, anticipated earlier in the week by MX Logic Inc. , used messages with subject headings ranging from "Amazing firework 2008" and "Celebrating Fourth of July" to "Light up the sky" and "Spectacular fireworks show," said U.K.-based Sophos Plc. in an alert posted to the Web Friday.

Links in the spam led to hacker-controlled sites that trumpeted a video clip worth downloading. "Colorful Independence Day events have already started throughout the country," the malicious sites claimed. "The largest firework happens on the last weekday before the Fourth of July. Unprecedented sum of money was spent on this fabulous show. If you want to see the best Independence Day firework just click on the video and run it."

The file pitched to users was an executable: "fireworks.exe."

Users who agreed to the download didn't receive a video, but instead infected their Windows-running PCs with the Storm Trojan horse, which hijacked the system and added it to the existing collection of compromised computers making up the Storm botnet.

"You're not going to be feeling in the mood for celebrations if this malware infects your PC," said Graham Cluley , a Sophos senior technology consultant, in a statement.

Security researchers at F-Secure Corp. , the SANS Institute's Internet Storm Center (ISC) and Trend Micro Inc. also reported the Storm spam and infection attempts.

Storm's backers have regularly used holiday-themed spam to dupe users into downloading the Trojan and self-infecting their PCs. Last year , the bot was behind a massive surge in spam during July, and it has been linked to campaigns around Christmas and New Year's .

Earlier this year, Microsoft Corp. researchers said that their company's Malicious Software Removal Tool (MSRT) had beaten Storm into submission, a claim contested by third-party security experts.

Security Firm Reports Trojan Targets Macs

Security researchers reported recently that they have spotted a Mac Trojan horse in the wild that could compromise machines running Apple Inc.'s Mac OS X 10.4 or 10.5.

Last week, SecureMac, a Mac-specific vendor of antivirus tools, posted an alert saying that its researchers had found a Trojan horse, dubbed "AppleScript.THT," being distributed from a hacker-operated site where discussions of spreading the malware via iChat, Apple's instant messaging and video chat software, were also taking place.

The company classified the threat posed by the Trojan as "critical."

The malware exploits a recently publicized vulnerability in the Apple Remote Desktop Agent (ARDAgent), part of Tiger's and Leopard's Remote Management component. Composed as a compiled AppleScript, or in another variant, script bundled into an application, the Trojan leverages the ARDAgent bug to gain full control of the victimized Mac.

"[It] allows a malicious user complete remote access to the system, can transmit system and user passwords, and can avoid detection by opening ports in the firewall and turning off system logging," claimed SecureMac. "Additionally, the Trojan can log keystrokes, take pictures with the built-in Apple iSight camera, take screenshots, and turn on file sharing."

SecureMac's warning came one day after an anonymous reader disclosed a few details of the ARDAgent vulnerability on Slashdot, and on the same day that rival security vendor Intego provided more information about the bug.

Malicious AppleScript, said Intego, can call ARDAgent, which then gives that script full "root" access to the system. "When an application enables a root privilege escalation of this type, any malicious code that is run may have devastating effects. These may range from deleting all the files on the Mac to more pernicious attacks such as changing system settings and even setting up periodic tasks to perform them repeatedly," Intego's warning read.

Like any Trojan horse, AppleScript.THT does not spread on its own but relies on user actions, such as downloading and launching, to infect a machine. Trojans can also be silently introduced on a computer if it's injected after a successful attack using another vulnerability, such as a browser bug.

Some researchers downplayed the threat. Thomas Ptacek of Matasano Security LLC, a New York-based security consultancy, said the ARDAgent vulnerability wasn't much of a concern.

"Who cares if someone busts root on your Mac?" Ptacek said in a Thursday entry on the Matasano blog. "It's a single-user system. I'll let you in on a Matasano state secret: if you break [my user] account, I'm in trouble. If you're malware and just trying to spread, or redirect my browser to phishing pages, you're wasting your time with this 'root' silliness."

Ptacek and others have noted that users can protect themselves by removing ARDAgent from its normal location, which is System/Library/CoreServices/RemoteManagement, and archiving the application.

Malware is Getting Smarter, F-Secure Warns

Watch out for the newest generation of malware that is difficult to crack and efficient, warns antivirus firm F-Secure.

The Finnish firm has warned that today's malware is characterized by the packing, encryption, and obfuscation of existing families of Trojans, backdoors, exploits, and other threats, which is now done with industrial efficiency.

What the increasing use of self-defense technologies in malware represents is the ever growing professionalism within the crime-ware community, according to F-Secure.

In its data security summary on the first half of the year, the firm noted that there have been a growing number of targeted malware attacks on individuals, companies, and organizations.

Targeted Attacks

In a targeted malware attack, the attacker profiles his victim and sends an e-mail using the recipient's name, title, and perhaps references to his job function. The message's content is typically something that the recipient would expect to receive via e-mail.

"I have a nasty feeling that the situation is getting worse, not better", said Mikko

Hyppönen, Chief Research Officer at F-Secure Corporation. "However, we're not giving up either."

Targeted malware attacks are also being used for political and military motives, pointed out F-Secure. During the recent clashes between Tibetans and the Chinese military, the battles on the streets were accompanied by political espionage on the Internet. Human rights groups, pro-Tibet organizations and individuals supporting the freedom of Tibet were attacked with a carefully targeted and technically advanced e-mail campaign that attempted to infect their computers in order to spy on their actions.

Malware, Spam, and other Net Pests Rev Up

The spam and malware tsunami continues to cast a mounting shadow over the Internet.

An announcement from F-Secure warned that malware is growing faster than ever before, while Marshal's TRACE team claims that the volume of malicious spam in circulation has more than tripled in one week.

Marshal fingered the Srizbi botnet as the chief culprit, currently responsible for 46 percent of all spam sent, helping malicious spam figures jump from 3 to almost 10 percent of all spam traffic so far in June.

The TRACE team lead threat analyst, Phil Hay, said that Srizbi's criminal controllers are currently on a major expansion drive.

Srizbi is duping recipients by including the first part of their e-mail address in the subject line with the suggestion that they look "stupid" in a video, luring them to a Web site to view the video where they are exposed to malware.

Marshal said Srizbi is also targeting social networking sites like Classmate.com, luring victims to dodgy sites with the promise of messages from long lost school friends. A Flash video player link is presented to the victim, which downloads an executable file that infects their computer.

"This kind of social engineering tactic is nothing new," said Hay.

"What is significant is the rapid increase in the volume. It once again demonstrates the incredible power and dominance that the major spamming botnets have over email traffic. Very few legitimate businesses could triple their e-mail capacity at the push of a button. But this is the advantage that the illegal control of thousands of computers gives the spammers. "We see Srizbi as one of the biggest threats to Internet users today. Users should be wary of emails that make personal offers such as online friend connections or include inflammatory personalized subjects such as 'you look stupid in this video', particularly if they don't recognize the sender," he said.

According to F-Secure's security summary for the first half of 2008, the unprecedented growth in malware is due to the packing, encryption, and obfuscation of existing families of trojans, backdoors, exploits and other threats now being done with "industrial efficiency".

The number of malware detections has grown by almost half a million since the end of the year, jumping from 500,000 total detections to 900,000.

"I have a nasty feeling that the situation is getting worse, not better", says Mikko Hypponen, chief research officer for the security vendor.

F-Secure cited targeted malware attacks such as the classmates.com con that Marshal reported as key growth areas for dodgy software peddlers over the past six months.

Targeted malware attacks typically involve the attacker profiling their victim and sending an e-mail using the recipients name, title, job function and a subject field related to the victim's position in order to trick them into opening something they would normally expect to receive via e-mail.

Targeted malware attacks against political or military organizations also increased, such as an e-mail attack against human rights and pro freedom of Tibet groups that aimed to install malware on their PCs that would allow their political opposition to spy on their actions.

F-Secure's half-yearly security summary also looked at emerging mobile phone threats such as Jailbreaking, growth in SQL injection attacks, and the risks emerging around third party applications like Adobe Flash.