Chinese Internet Security Response Team (GMT +0800)

Baidu.com DNS hijacking Unknown

Category : Others | Post on : January 12, 2010 10:47 by smallmo Reship : Original

We received lots of reports about Baidu.com, the most popular search engine in China, had been unavailable since this moning.

As the time of writing, Baidu.com is also unavailable.

We noticed this case may be caused by DNS hijacking by the “Iranian cyber Army”, the same guys we mentioned several weeks ago.

A related news: Baidu, China’s Largest Search Engine, Hacked by “Iranian Cyber Army”

Tags: , ,

ISC: Twitter outage via DNS hijacking Unknown

Category : Others | Post on : December 18, 2009 16:31 by smallmo Reship : Original

I just saw Sans.org reported that Twitter outage via DNS hijacking.

A reader posted a image in the comments of this report.

http://i.imgur.com/Q1EgM.jpg


Tags: ,

First iPhone Worm Ikee Unknown

Category : Worm | Post on : November 9, 2009 08:43 by smallmo Reship : Original

There are lots of reports about first iPhone worm "Ikee" today.

F-Secure: First iPhone worm found

Sophos: First iPhone worm spreading in the wild

ISC: iPhone worm in the wild




Tags: ,

Spams with "Hello Darling" Unknown

Category : Trojan | Post on : November 3, 2009 19:37 by smallmo Reship : Original

The spams had been sent with the subject "Hello Darling" and attchment "photo.zip".

Subject: Hello Darling
Mail body:
Hi, how are you? My photos Which I promised in attached file

Attchment: photo.zip

Get Back to My Office for More Details Spams Unknown

Category : Trojan | Post on : November 1, 2009 18:55 by smallmo Reship : Original

I saw lots of spams which contained subject "get back to my office for more details" and attchment "info.zip" in recent two days. Be careful of them.

From: boss <"boss">
Subject: get back to my office for more details
Mail body:
Please read the attached letter and get back to my office for more details to proceed further.

Thanks and have a very nice day.

Facebook Password Reset Confirmation Spams Unknown

Category : Trojan | Post on : October 27, 2009 09:10 by smallmo Reship : Original

Be careful of the new round of spams about Facebook Password Reset Confirmation.

From: The Facebook Team <service@facebook.com>
Subject: Facebook Password Reset Confirmation.
Mail body:
Hey gt ,

Because of the measures taken to provide safety to our clients, your password has been changed. You can find your new password in attached document.

Contract of Settlements Spams Unknown

Category : Trojan | Post on : October 24, 2009 18:53 by smallmo Reship : Original

There is a new round of spams, which contained the subject titles as "Contract of Settlements" and the attachments as "contract_1.zip".

Be careful.

Subjects: Contract of Settlements

Mail body:
Greetings,
We have prepared a contract and added the paragraphs that you wanted to see in it. Our lawyers made alterations on the last page. If you agree all the provisions we are ready to make the payment on Friday for the first consignment, We are enclosing the file with prepared contract. Password: 34****

Conflicker.B Infection Alert Spams Unknown

Category : Trojan | Post on : October 20, 2009 10:30 by smallmo Reship : Original

Be careful of spams about Conflicker.B Infection Alert.

They are the same gang as i mentioned before.

Subject:Conflicker.B Infection Alert
Mail body:

More Spams Unknown

Category : Trojan | Post on : October 15, 2009 15:44 by smallmo Reship : Original

Numerous spams had been sent these days. The name of attchments are like "DHL_package_label_1f553.zip" , "DHL_print_label_433a6.zip" , "DHL_Label_a4f79.zip" , "DHL_Package_ac42d.zip" , "install.zip", etc.

Be careful of these spams.

I listed some spams' content:
Quotation
Subject: DHL service. You should get the parcel! Delivery NR.6445
Mail body:
Hello!

The courier company was not able to deliver your parcel by your address. Cause: Error in shipping address.

You may pickup the parcel at our post office personaly!

Please note!
The shipping label is attached to this e-mail. Please print this label to get this package at our post office.

Thank you for attention.
DHL Delivery Services.

Renren.com XSS Worm Unknown

Category : Worm | Post on : August 25, 2009 09:44 by smallmo Reship : Original

I noticed Sophos and ISC reported a Chinese social web site - renren.com(aka xiaonei.com), was attacked by a flash XSS worm.

If you can read Chinese, you may read more details written by KnownSec Team here.


Tags: , ,
Pages: 1/26 First page 1 2 3 4 5 6 7 8 9 10 Next page Final page [ View by Articles | List ]