# Tags

NPAV – Net Protector AntiVirus truth exposed

Since the last 3-4 days we have come across a lot of cases of reported infection of W32.Xpaj virus and surprisingly, found Net Protector Antivrus (NPAV) installed on the computers of all those cases. We were surprised to find the connection and were attempting to find the connection between this malware and the dubious NPAV […]

Beware of Fake FedEx Tracking Report Notification

Last week some of our customers informed us that they are receiving spam emails claiming to be from FedEx carrying the subject line: “FedEx Shipment Notification”. The email looks like this: The spam email contains a Zip file. Upon extraction, it presents an executable file named “FedEx_Tracking_Report_Notification_ID.exe”. This is a malicious file belonging to the […]

Fake emails – American Airlines

I have come across some significant activity related to spam email messages that are pretending to be from American Airlines. This email misguides the user that his purchased ticket scan copy is attached with this email and asks him to print it for use. The email has “Ticket.zip” as an attachment contains a malicious ‘Ticket.exe’ […]

Phishing Campaign Using Spoofed US-CERT Emails

Phishers are using spoofed email addresses from the US Computer Emergency Response Team (US-CERT) to trick recipients into downloading a malicious executable file. The emails are sent from the spoofed email address soc@us-cert.gov with the subject line: “Phishing incident report call number: PH0000003863970”. The fake warning claims US-CERT has opened the incident number PH0000007135030 and […]

Microsoft announces workaround for the Duqu exploit

Microsoft has posted a security advisory 2639658 to address the recently disclosed Windows kernel vulnerability (CVE-2011-3402) exploited by the Duqu malware. Microsoft has determined the flaw is in the processing of embedded True Type Fonts (TTFs). According to Microsoft: “The attacker could then install programs; view, change, or delete data; or create new accounts with […]