Saint_Michael
Feb 26 2008, 04:23 AM
I saw this white paper and I thought I bring down some interesting information that has come from 2007 and leading into 2008. I have to say though that the information on this white paper is pretty darn mind blowing as I bounce some facts to everyone. Of course since I been getting into this since last year it is not all that surprising since I posted many topics about it as well. -Sophos currently sees 6,000 new infected webpages each day -One infected page every 14 seconds -Only about 1 in 5 of these sites is a hacker site -83 percent are hacked sites, or legitimate websites that have been compromised by an unauthorized third party. -Biggest form of Malware is Mal/Iframe --Has hit over 10,000 legitimate websites from Italy alone -Hosting of Malware comes From China (51.4%), USA (23.4%), and Russia (9.6%) -Servers that have been affected the most
--Apache at 48.7% --IIS 6 40.6% --nginx 3.4% --GFE 3.9% --Other 3.4% Of course, not surprising enough most of the malware written has come from China but interestingly enough it would seem Brazil is a big Malware writing country as well. Even though a few articles are saying Russia are the King of Malware producers. EMAIL THREATS -2005 1 in 44 -2006 1 in 337 -2007 1 in 909 As you will notice with that number, you actually see a decline in threats via email in the last 3 years, and yet billions of emails are being sent out daily though, but people are becoming more aware of the threats that come from these unknown emails. Although, the attachments are declining the links to bad websites are on the rise though, and that is where people are becoming victims because they would trust the website, but in fact they are booby traps. Of course their was an article out saying that malware designers have been google bombing last few months trying to spike the rankings to infected website as well when people search on google. Worm of 2007 If some of your remember my topics on the Storm work way, way back it would seem that the Storm Worm has been the most destructive worm of that year. TIME LINE Of the Storm WormQUOTE Early January 2007: Starting as Happy New Year malware5 which spread malicious greetings via email attachments, the hackers changed their tack in January using news-related events to encourage recipients to click on what claimed to be video content. One of these disguises, which had subject lines such as “230 dead as storm batters Europe”6, gave the worm its popular name of Storm.
Late January 2007: The Storm worm turned to love in a major new attack as St Valentine’s Day approached7, and in the run-up to US Independence Day on 4th of July8 the malware gang aggressively took advantage of the celebrations with another malicious ecard campaign. On this occasion, the email contained a web link to compromised zombie computers hosting a Trojan horse. August 2007: Storm used a wave of malicious emails which posed as links to YouTube videos9, and then posed as links to music videos of popstars like Beyoncé, Rihanna and The Eagles. If infected, hackers could use victims’ computers to steal personal information, spam out malware and junk email, or launch distributed denial-of-service attacks against innocent parties.
September 2007: The Storm worm took advantage of the NFL Kickoff weekend10 and spammed out an email campaign with links to a hacked website, which would drop malicious code onto insufficiently protected computers. November 2007: The hackers tried to scare email users into believing their telephone conversations were being recorded11, but the ruse was designed to get people to buy bogus security software. In reality, however, the attached MP3 file was a malicious executable program that installed further malware onto the victim’s computer which it downloaded from a dangerous website. Amongst these was a piece of scareware which displayed a fake Windows Security Center alert and tried to convince the victim to purchase bogus security software.
December 2007: The criminal hackers behind the Storm malware showed no signs of letting up and continued their offensive attacks, sending emails claiming to point to websites offering pictures of a stripping “Mrs Clause”12 and Happy New Year messages13
The main goal of the creators of the storm worm was to use topical news stories, electronic greeting cards, videos and fear tactics so gt people to infect their computers with this worm, and if I remember my numbers correctly it was well over 20,000 computers that got infected with this worm. Sadly though I don't they found a way to break this worm yet and officially defend against since the Storm Worm keeps on changing as the months go by. Root kits have made a big come back as well last year, but of course always the big one is detection evasion in which designers code their stuff to hide their presence from Security suites. However as it comes with producing the stuff finding malware, spyware, viruses have made huge improvements as well; the following list shows the successful rate of detection by security companies: QUOTE Sophos 86% Kaspersky 69% Trend Micro 68% F-Secure 67% Symantec 66% McAfee 55% Microsoft 48% ClamAV 42% So as you can tell the big names able to dectect more as their software has improved over the years. Spam Facts-95% of email is spam - Top 12 producers of spam are: QUOTE United States 22.5% India 2.6% Italy 2.7% Spain 2.7% Turkey 3.1% Germany 3.5% France 3.5% Brazil 3.8% Russia 4.7% Poland 4.9% China (incl HK) 6.0% South Korea 6.5% Other 33.5% -Since 2005 US, South Korea, and China have been the top spam producers in the world, and that has not change statistically either. Of course now articles are coming asking for design who know several languages to help virus and malware writers to design website in specific languages besides English. - Pump-and-dump spam is the biggest type of spam sending, you usually this in when you get stock tip emails or the Viagra emails as well. I thought I end on that note, and attached here is the full report on security stuff that has gone on since 2007 and what is expected in 2008. So check out the document and see what the computer underground has been doing since last year as the report talks about Apple, Mobile phones and Wi-Fi devices, Social networking (ID Theft), Securing the business network, State-sponsored cybercrime, and of course big time arrests of big timer spammers and malware designers. [attachment=1041:sophos_s...eport_08.pdf]
Reply
Similar Topics
Keywords : white, paper, security, threat, report, 2008
- Spam Is 30 Years Old May 3, 2008
Come celebrate the birthday of the very first SPAM email (10)
Server Issues? Web Site Down? Cpanel Access?
Server Migration issues to report. (48) I tried downloading my email from website this morning and Thunderbird said it couldn't access
it the server. Then I tried loading my website - to no avail. Does anyone have any idea what's
going on? Is anyone else experiencing this? Seems like this is the second time this spring this has
happened. Is an upgrade going on, or something? Thanks in advance for your help! ....
Ms Office 2008
(3) Not sure if I should buy this or not =[ Does anyone know it's new features and such? I think
2003 is just fine? Any opinions?....
21 (2008)
Currently in theatres (4) 21 Movie Review IMDB Link: http://imdb.com/title/tt0478087/ Trailer:
http://youtube.com/watch?v=PsK1c9ZBpuw * Warning contains spoilers About the movie 21 is a
movie about six MIT students counting cards in Vegas to make millions. Ben is very good at math and
numbers, he had a 4.0 GPA and was looking to get into Harvard. He was being interviewed by a guy in
Harvard that would give the scholarship and wanted something that would dazzle him, so Ben told him
the story. There was an open spot on the team because one of them left so they wa....
Trap17 2008 Award Winners
(11) Finally after many months of waiting, we have the winners of the trap17 awards, we had 652 votes,
and although some of them were voted multiple times. I did my best to clean those multiple votes
up, even though someone earlier decided to go multi voting. So here are the winners of this years
Trap17 awards Winners QUOTE Trapper of the Year Saint Michael 19 OpaQue
16 jlhaslip 16 Most Valuable Poster Saint Michael 18 jlhaslip 16 OpaQue 4
Moderator of the Year Velma 17 jlhaslip 16 rvalkass 9 Most Helpful Memb....
E-bay Prostore Ver 9 Promotion
Get a Free eBay ProStore till Sept 2008! (0) I just received this news from ebay: QUOTE And - as a special offer to eBay Stores sellers -
I'm pleased to let you know that you can try the new ProStores Starter store and pay no monthly
subscription fee through September 2008. That's up to six months on us. Over the next couple
weeks, watch your email and mail box for information on how to access this special offer. After your
free trial subscription, eBay Stores sellers always enjoy 30% off our low monthly subscription rates
every month. So, if you've considered opening your own Web store, this is a ....
Many 2008 Hoaxes!
(9) I didn't know there were so many hoaxes this year! In case you don't know, see this(from
wikipedia) QUOTE 2008 In Gmail, Google featured information for an update called "Gmail
Custom Time"; a feature that would allow its users to send emails back in time. While composing a
message, a button labeled "Set Custom Time" would allow one to send the message a specific interval
in the past, as well as choose if the message appeared as "read" or "unread". None of the features
appear in the service itself, but rather in a description of the update found here: ....
Trap17 2008 Awards Voting
(21) Well the voting has begin for the 3rd annual Trap17 awards and I like to toss a pre-victory
congratulations for those made it to the finals, and a better luck next year for those who did not
make the cut. Also I ask you all to vote only once, because I should have check this poll script
before setting it up, and it seems you can vote more then once and I have check out other ways to
set this up as well. I have faith that people will be honorable in their selections regardless of
the stupidity I put in for not checking this script earlier. Also some categories had to....
Happy Easter 2008 To Western Christian
Happy Easter (11) To Christians in Wesren Churches Happy Easter
________________________________________________________________________________ Passover Week
in Western Churches ....
2008 Trap17 Awards
(36) Introduction Welcome to the 3rd Annual Trap17/Forum Awards, this year we will be adding in
some new categories to the ever growing forums and with the number of active members the competition
to recieve these awards should be better then ever. As usual we will start with nominations this
will last till the end of the month and that way it will give everyone plenty of time to send in
theri nominations. Also You can nominate your but please be reasonable if you don't actively
post in some forums don't nominate yourself in every. Besides there are catego....
Bomb Threat At My High School!?
(6) Ok, so I'm sitting at my desk *cough* enjoying *cough* my math class..... haha... and suddenly I
hear the voice of my principal through our P.A. system. "May I have your attention, May I have your
attention, May I have your attention. They school is now in lock down mode." (or something like
that) Our math teacher runs to the door locks closes the door, and ensures its locked. He tells
everyone to go to the back and sit against the wall. Everyone does as asked, wondering what the crap
is happening. I would say that the majority of people were not scared, as they tho....
2008 Chicago Cubs Analysis
A complete analysis of the Cubs. (0) Below are my thoughts on the Cubs and the direction the team is taking. Also as reference, here
are some links to the Cubs' stats in 2007: Player Stats Overall Team Hitting Stats
Overall Team Pitching Stats Historical Team Hitting Stats Overall : Despite off-years from
star players Carlos Zambrano , Derrek Lee , Aramis Ramirez , and Alfonso Soriano , the team
reached the playoffs thanks to improved starting pitching and a team that reached base at its best
level since 2001. As it's been said, a team lives and dies by its starting pitching. ....
Gametrailers' Most Anticipated Games Of 2008
Top ten list of must-have games (3) GameTrailers.com posted a video for their most anticipated games for 2008: 10. Super Smash Bros.
Melee – Wii/Nintendo 9. Ninja Gaiden 2 – XBOX 360/Micrsoft 8. Prototype –
Multiplatform/Sierra 7. Grand Theft Auto IV – Multiplatform/Rockstar 6. Little Big Planet –
Playstation 3/SCEA 5. Starcraft 2 – PC/Blizzard 4. Final Fantasy XII – Playstation 3/Square
Enix 3. Fallout 3 – Multiplatform/Bethesda 2. Metal Gear Solid 4: Guns of the Patriots –
Playstation 3/Konami 1. Resident Evil 5 – Multiplatform/Capcom The video comes in Standard and
High De....
2007-2008 World Heritage Wall Map
(0) Become a member of the World Heritage website and receive the 2007-2008 World Heritage Wall Map.
/wink.gif" style="vertical-align:middle" emoid=";)" border="0" alt="wink.gif" /> This large format
full-color map features the World Heritage sites. Dimensions: 78 cm by 50 cm (31 in. by 20 in.)
Be sure to check the box requesting the map by mail to get this freebie.
http://whc.unesco.org/en/register/ (i have just registered myself to see if i will soon receive
this in my mailbox. /tongue.gif" style="vertical-align:middle" emoid=":P" border="0"
alt="tongue.gif" /> ....
Security Warning 2008: Top 11 Malware Threats To Watch Out For
(0) Before I go into this topic I have to say, stop making up these crazy names. I know I just getting
into the security side of things but still as long as there are computer problems and ways to sucker
someone into downloading the stuff, the crazy names will still live on. QUOTE Lieware
ADVERTISEMENT In 2007, there was a lot of "rogue anti-virus software," which is sometimes also
referred to as "fake anti-virus software." But these terms are confusing because there's too
much negation going on. Fake anti-virus software is not anti-virus software at all. So what ....
Marijuana
A paper I wrote for english class (3) I wrote an essay similar to this for my English class, I was wondering what some people thought
about it or maybe some nice people can point out some typos and etc since i have no one to proof
read to me. QUOTE Since the 1930s the DEA has been monitoring and illegalizing the use of
drugs. Out of these “drugs” many of them have beneficial purposes in various medical
fields while others were used for religious purposes as well. The Drug Enforcement Agency of the
United States has been strict and manipulative in order to keep these substances illegal. One o....
Html 5 Draft Report Released
Read the changes from html 4 here (16) Link: http://www.w3.org/TR/2008/WD-html5-diff-20080122/ I have just read it once, so I don't
have an opinion to state, but the W3C has released the Draft Version of the HTML 5 Working Group.
Apparently, it will remain as a Draft version until at least 2 Browsers actually implement the
changes. The Document above lists the Differences between the html 4 specs and the proposed html 5.
Looks like some interesting stuff, with a tag, , etc. Notice that there is a further separation
of Structure and Style as a mess of Table attributes will be no longer supported. ....
Do You Dream In Black & White Or Color?
(16) Hellosies! I 'm one of those people who usually dream in VIVID colors ( more like
technicolor sometimes lol!) and was surprised to find that some people dream only in black and
white. So my question for ya'll is how many of you here dream in color? How many here dream in
black and white? Okay so how many of you are super talented and dream in both versions? ....
Australian Open 2008
Who is going to win? Sharapova or Ivanovic. Fedorer (2) I've only been able to watch the highlights on TV but I think sharapova is going to win, Shes
been playing very strongly from what I've seen shes beaten most of her opponents very easily
including world no 1 henin. I dont think the game will air here sadly. while I'm posting this
Roger Federer (SUI) v. Novak Djokovic (SRB) is in progress I dunno who is leading ; ;. Both
are awsome players and that other guy too who already made it to the finals jo-Wilfried Tsonga. He
looks pretty good too. Well my picks are: Womens - Sharapova Mens - Federer....
Comodo Security Software
I love their Firewall (3) Hey everyone, if you read my blog, you will probably see my post about Comodo software. If not,
I'll talk about it on the forums! You know, spending 50$ for a spyware scanner is
tough, you also need to spend that same money on Antivirus, Firewalls etc. Comodo however, is an
amazing company that offers all these products for free. And no, they aren’t stripped down versions
that are made to promote paid products… because that’s the thing. They don’t have paid products.
They’re just some rich company who sell SSL certificates (which can cost over 1000$ f....
From Paper To Film
Do TV series and movies affect an author's literary works? (1) I've been wondering, for the past month, how much of the Harry Potter series is actually JK
Rowling's idea, that is, pure, unadulterated ideas. Er... lemme elaborate. Before the last
books came out, there already are film adaptations of the first few books. Sometimes, I wonder,
would Rowling have made the story run a different course had someone other than Daniel Radcliffe,
Rupert Grint or Emma Watson been casted? Would her last two books, The Half-Blood Prince and The
Deathly Hallows have been significantly different if the special effects of the first movie we....
Ghostbusters - The Video Game
New movie-based game coming Fall 2008 (5) Next fall, who you gonna call? Ghostbusters – The Video Game, based on the 1984 worldwide
blockbuster hit created by Dan Aykroyd and Harold Ramis which spawned a 1989 sequel, a popular
Saturday Morning animated series and countless spin-offs, will hit stores next fall for the
next-generation gaming consoles. Sierra, the software developer behind the RTS hit World in Conflict
and the SWAT series, will co-produce the games with Sony Pictures Entertainment. GameTrailers.com
has posted a debut trailer available in HD and standard definition formats. It’s a little short wit....
Useful Laptop Tips (traveling & Mobile Security)
(4) Here are some tips on how to pack your laptop safely and not having to worry about it getting damage
while flying in a airplane if you do not have it as a carry-on and don't want it to get crushed
under hundreds of other bags. There is a part 2 to this article I will have to wait till it comes
out to add it to this topic. QUOTE My friend Mary has been known to do some crazy things. Last
summer, she won a hat contest by affixing pieces of fried chicken to a straw bonnet and
accessorizing it with biscuit earrings. But before boarding a recent flight, Mary did s....
Football Manager 2008
(9) Right having played for a bit here's what I'm noticing. I haven't spotted a difference
with scouting. The closing down thing obv. Too many fouls from crosses. Too many penalty claims.
Seems there is plenty controversy in every game. Game seems a smidgen faster to me. Saving
especially. Scout reports that suggest a guys character is "run of the mill" is just silly. I
can't find a button that takes me to my squad page, is there one? I'd rather go to squad
page than tactics for "pick team". As in FM07 we need something between "disappointing"....
Test Your Browser For Security
take the browser security test (9) test your browser for security holes: http://bcheck.scanit.be/bcheck/ This checks for the most
commonly occurring security vulnerabilities in the major browsers.In total there are some 40 tests
and may take a long time to finish. I have run this test on 4 browsers: 1)IE 7 : 0 vulnerabilities
(but the browser goes crazy, opening several windows and applications) 2)IE 6 : 1 medium risk (the
browser goes crazy like IE7) 3)Firefox 2.0.0.3: 1 medium risk (i think some plugin might have caused
this as some others have had different results) 4)Opera 9.2: 0 vulnerabilities ....
Data Can Be Stored On Paper
Store GB's of electronic data on Paper (26) A student has developed a technique to store data on portable paper :-) ....
How To Improve Security Of Your Website?
Tips and tricks, important things... (3) First of all i want to apologize to moderators in case that they need to close this topic because
someone opened it before...I used search and i havent found anything...once again sorry if i missed
some topic... Getting to the point! What do we need to do to make our site secure? Daily
backups, deleting install files or something else? So please tell us more about site security!
I know it`s practically impossible to make site 100% hack free, but at least 80% we can do!
Advanced users share your advices with us-newbies! You ll get post count and we....
Cpanel Exploit
security hole in cPanel to hack the servers of a hosting company (8) A pair days ago I read this new on Slashdot: cPanel Exploit Used to Circulate IE Exploit
QUOTE "In a dangerous combination of unpatched exploits, hackers have used a previously
undiscovered security hole in cPanel to hack the servers of a hosting company and use hundreds of
hijacked sites to infect Internet Explorer users with malware using the unpatched VML exploit.
cPanel, whose hosting automation software is used by many large hosting companies, has issued a fix.
It's a local exploit, meaning the attacker must control a cPanel account on the target hosti....
Windows Security Over Regedit
beginners guide: how to cheat windows (1) how to make windows secure over REGEDIT have you ever questioned yourself, how to hide the
complete desktop of a guestaccount? well, here is the way to get it; ---THE USER NEEDS ADMIN
RIGHTS FOR A SHORT TIME--- logon with the user u wanna manipulate . ---!!!--- click
on start/run and type "regedit". the registryeditor should come up and you should see your
computer registry with the hive-keys classes_root current_user local_machine etc. browse through
"hkey_current_user" and go to "software\microsoft\windows\currentversion\p....
Forgot Password To Trend Micro Internet Security
Is there a way to remove it? (5) One day I was bored so I set a password for our Web security software, Trend Micro Internet
Security. I turned on the URL filter, and now, whenever my friends send me something funny that has
no porn or anything in it, I get the Blocked error. I am really annoyed by this; I can't change
other setting in the software too. Is there any way to either reset the password or remove it,
without uninstalling Trend Micro?....
Looking for white, paper, security, threat, report, 2008
|
|
Searching Video's for white, paper, security, threat, report, 2008
|
advertisement
|
|