End of the year presents:
These are 4 samples of Skype Dorkbot / W32.Phopifas
Related News and Analysis:
October 2012
Infection Spreads Profile Pic Messages to Skype Users -GFI
W32.Phopifas | Symantec
![]() |
| Img.baronet4tibet. Tibetan furniture featuring a leopard and a lion |
| Hurricane Sandy, Jersey Shore Src. Twitter Oct 28,2012 author unknown |
Here is quick post for a CVE-2012-5076 sample (from Cool pack, as described by Kafeine here Cool EK : "Hello my friend..." CVE-2012-5076 )
Here are two samples of Java CVE-2012-4681 exploit - one from the original targeted attack described in our post on August 30, 2012 and the other from today's spam redirecting to Blackhole 2.0 exploit kit and using CVE-2012-4681 adapted from the Metasploit framework.![]() |
| ladyilonwick.wordpress.com |
![]() |
| img.kids.discovery.com |
In Israel and the Palestinian Territory, 750 incidents have been recorded." (Kaspersky)
Yara Signatures: You can develop your own yara signatures based on these and other indicators you find in the files. I will share signatures on Yara Signature Exchange Google Group. If you are interested in making and sharing, please see DeepEnd Research: Yara Signature Exchange Google Group