Zscaler Australia & New Zealand http://blog.zdemo.net Most recent posts at Zscaler Australia & New Zealand posterous.com Wed, 23 Mar 2011 21:09:00 -0700 Zscaler Research: Randomization of code and binaries used by a fake antivirus website http://blog.zdemo.net/zscaler-research-randomization-of-code-and-bi http://blog.zdemo.net/zscaler-research-randomization-of-code-and-bi
Last week, I talked about heavy obfuscation being used by attackers to hide their HTML source code from detection. This time we came across an interesting fake antivirus website, which not only continually changes the source of the webpage but also the malicious binaries being used in the attack. This occurs when you revisit that same malicious site. The malicious site also changes certain strings used inside the animation sequences. For this blog, I have visited that site a few times in span of a minute and collected the various source files and malicious binaries.

Umesh continues his discussion of fake AV sites, showing how the attackers are getting more sophisticated and introducing random changes to the attacks.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks
Wed, 23 Mar 2011 03:56:00 -0700 Zscaler Research: Many university websites used for spam http://blog.zdemo.net/zscaler-research-many-university-websites-use http://blog.zdemo.net/zscaler-research-many-university-websites-use
University websites are becoming a preferred vector for different types of spam. The vast number of sub-domains, each of them likely managed by a different group which may not have professional IT/Security skills, make them an easy target.

Permalink | Leave a comment  »

]]>
http://files.posterous.com/user_profile_pics/1818888/about_dot_me_slash_richii_20122821519.png http://posterous.com/users/3sISSbA3DvH3 Richard Stocks richii Richard Stocks