Who Fell for the Facebook Password Reset Scam Yesterday?
blog.threatfire.com
Who Fell for the Facebook Password Reset Scam Yesterday?

ThreatFire Blogger

Wed, 28 Oct 2009 19:41:17 GM

Unfortunately, a lot of people didn't realize that the email and attachment we posted yesterday was not really from The Facebook Team . . ThreatFire. users were protected from the Bredolab downloader and its Zbot payload, and it's a good ...

waledac birdie_a.exe, birdie_b.exe, corvus_b.exe, william_a.exe ...
blog.threatfire.com
waledac birdie_a.exe, birdie_b.exe, corvus_b.exe, william_a.exe ...

ThreatFire Blogger

Mon, 24 Aug 2009 21:09:00 GM

communications retrieved from com/up21.php (there are others), as evidenced here: av detection is surprisingly low for these executables, be sure to add a layer of behavioral protection to your system with . threatfire. .

intellectual virus scan?
blog.threatfire.com
intellectual virus scan?

ThreatFire Blogger

ue, 08 Sep 2009 23:24:00 GM

as dancho danchev chronicles the blackhat seo work of his biggest ukrainian fan club (that is sarcasm, folks) leading to delivery of a particular fakeav, the . threatfire. community is protected from fakeav polymorphic downloaders from ...

reported ppstream 0day? exploitable or just a crash?
blog.threatfire.com
reported ppstream 0day? exploitable or just a crash?

ThreatFire Blogger

Fri, 04 Sep 2009 16:40:00 GM

the author had not released a workable exploit, and there appears to be no . threatfire. community reports for the component. its exploitability is being discussed on full disclosure lists and various other forums: ...

 ThreatFire AntiVirus Free Edition 4.6
free-ultimate-downloadz.blogspot.com
ThreatFire AntiVirus Free Edition 4.6

(Abhishek Dutta)

Fri, 16 Oct 2009 08:51:10 GM

ThreatFire. does not rely on signatures, but instead provides behavior-based protection. It is designed to be used alongside your existing antivirus software and it fills the gap in protection between your antivirus signature updates. ...

no microsoft ftp module 0day, but spybot/kolab exploits
blog.threatfire.com
no microsoft ftp module 0day, but spybot/kolab exploits

ThreatFire Blogger

ue, 01 Sep 2009 20:38:00 GM

we've been waiting for some stats to come rolling in, but we haven't seen a hint of an 0day worm or any attacks for that matter on the current microsoft ftp module 0day. instead of the ftp 0day showing global activity, spybot/kolab is ...

pc tools at virus bulletin 2009
blog.threatfire.com
pc tools at virus bulletin 2009

ThreatFire Blogger

Mon, 31 Aug 2009 17:39:00 GM

on the technical track, kurt baumgartner from our pc tools . threatfire. research team will be presenting for a third year. "antire en masse" will be a discussion of anti reversing techniques documented in peter ferrie's recent set of ...

headline malware downloaders
blog.threatfire.com
headline malware downloaders

ThreatFire Blogger

Wed, 02 Sep 2009 16:48:00 GM

threatfire. is preventing the malicious downloaders in high volumes and currently is the most reliable solution for detecting this family. scanning the files as they are downloaded and run by users shows dismal detection rates, ...

total security and pav.exe
blog.threatfire.com
total security and pav.exe

ThreatFire Blogger

Mon, 31 Aug 2009 19:33:00 GM

threatfire. preventions for this scareware/rogue​ware payload continue to be on the rise. before installing any software, be sure to inform yourself by looking into opinions and reviews of legitimate products.

bredolab armored attachments
blog.threatfire.com
bredolab armored attachments

ThreatFire Blogger

Fri, 21 Aug 2009 16:04:00 GM

over the past three days, . threatfire. users were being targeted by a higher number of bredolab downloaders. bredolab is a nasty, morphing little downloader being spammed out in droves mostly to users in the us and europe. ...

koobface 0x3e8 folders and setup.exe links
blog.threatfire.com
koobface 0x3e8 folders and setup.exe links

ThreatFire Blogger

hu, 13 Aug 2009 17:08:00 GM

here is an abbreviated list of the more high volume koobface urls that the . threatfire. community has been protected from over the past 48 hours. see a pattern here (do not visit any of these links and download the malware served there)? ...

when is flash-plugin not a flash plugin?
blog.threatfire.com
when is flash-plugin not a flash plugin?

ThreatFire Blogger

Wed, 05 Aug 2009 17:37:00 GM

myart-gallery .com robert-art .com superarthome .com threatexpert report here. add a behavioral based security layer to your system like . threatfire. and be wary of sites trying to force a codec install or upgrade.

foto049.com and banking password stealers
blog.threatfire.com
foto049.com and banking password stealers

ThreatFire Blogger

Mon, 03 Aug 2009 16:59:00 GM

our . threatfire. community in brazil and other parts of the world has been protected from the threat since this variant first appeared on friday, and users must be wary of running unsigned (or any) executables from links that are spread ...

Whitelists Killed AV? ThreatFire Research Blog
blog.threatfire.com
Whitelists Killed AV? ThreatFire Research Blog

(ThreatFire Blogger)

Mon, 21 Jul 2008 23:05:01 GM

Does . ThreatFire. use White listing at all? . ThreatFire Blogger. says: July 23, 2008 at 10:10 am. spywarebox-. Thanks for the post. To answer your question, yes. Where necessary, to reduce the chances of false positives for our users, ...

give your antivirus a boost with threatfire
mywumingzhan.blogspot.com
give your antivirus a boost with threatfire

(Admin)

ue, 04 Aug 2009 01:05:00 GM

threatfire. will complements your anti-virus tool to identify malware earlier. unlike other program, it won't interfere with your anti-virus package because it's designed to run along with it. ...

waledac fourth of july run
blog.threatfire.com
waledac fourth of july run

ThreatFire Blogger

Sat, 04 Jul 2009 23:35:00 GM

the . threatfire. community saw waledac code injected into svchost processes and prevented by . threatfire. in low volumes, bundled with other attacks. so, it is somewhat surprising that the botnet group just cannot pass up another holiday, ...

streamviewer.exe, tubeviewer.exe, tubeplayer.exe, now onlinemovies ...
blog.threatfire.com
streamviewer.exe, tubeviewer.exe, tubeplayer.exe, now onlinemovies ...

ThreatFire Blogger

hu, 09 Jul 2009 18:55:00 GM

it seems that the isp's may be acting on public information -- the sites were up for only a short time today, but . threatfire. protected the community from this prevalent malware all morning. related names currently resolving to that ...

itsecure.microsoft.com?
blog.threatfire.com
itsecure.microsoft.com?

ThreatFire Blogger

hu, 09 Jul 2009 21:15:00 GM

your browser could be redirected to antivir-systemp​ro.com, and you could be fooled into buying something from a spoofed website, following a driveby attack on your system. or, a piece of malware could edit your hosts file and open a ...

New (delf?)lob or (z?)lob variant ThreatFire Research Blog
blog.threatfire.com
New (delf?)lob or (z?)lob variant ThreatFire Research Blog

ThreatFire Blogger

Fri, 04 Jan 2008 04:27:01 GM

This site could have been a part of the fake codecs on . blogger. effort, but because detection is so low, it is most likely a new effort or will be a part of a new effort. Notice the play video title bar and the instruction You must ...

koobface on the loose as "flash_update.exe"
blog.threatfire.com
koobface on the loose as "flash_update.exe"

ThreatFire Blogger

Wed, 03 Dec 2008 17:31:00 GM

social networking worms like the koobface family are a reality, and their prevalence shows on our . threatfire. community. users of facebook need to be aware that links appearing on friends' facebook pages may be links to malware downloads ...

From Google Blog Search: 'threatfire blogger'
Sun Nov 22 03:25:15 2009 [ refresh local cache ]