Recently we have seen a spike in a Visual Basic 6-compiled AutoRun worm family. The family is both client- and server-side polymorphic. (For more on this family, refer to our VIL and Advisory entries.) The W32/Autorun.worm.aaeh family usually gets on a victim’s machine through email spam, Blacole drive-by downloads, or downloads by BackDoor-FJW. From a behavioral Read more…
Tags: Autorun, RAR, RC4 encryption, thumb drive, VB6, Visual Basic 6, worm, ZIP
Microsoft has issued Security Advisory 2718704, in which the company disclosed that it recently became aware of the Flamer/Skywiper threat, which uses certificates derived from the Microsoft Certificate Authority. The actual certificate in question was used to sign at least one of the attack components associated with the module in the Skywiper framework. This is Read more…
Tags: CA, certificate authority, Flame, Flamer, SkyWiper, worm
Malware is on the rise. At the beginning of 2008, our malware collection had 10 million samples. Today we have already surpassed 70 million. Most of the malicious samples are Trojans (backdoors, downloaders, fake alerts), but there are also a lot of viruses, worms, and bots that in a short time can infect many computers Read more…
Posts tagged under worm