<br />
<b>Deprecated</b>:  Function create_function() is deprecated in <b>/home/hidefide/public_html/blog/wp-content/plugins/wr-pagebuilder/core/core.php</b> on line <b>127</b><br />
{"id":537,"date":"2016-03-17T16:00:40","date_gmt":"2016-03-17T16:00:40","guid":{"rendered":"https:\/\/icaruspressblog.wordpress.com\/?p=537"},"modified":"2019-04-17T11:34:32","modified_gmt":"2019-04-17T11:34:32","slug":"massive-spam-attack-slips-past-spam-filters-on-its-way-to-australia","status":"publish","type":"post","link":"https:\/\/hidefideas.com\/blog\/2016\/03\/17\/massive-spam-attack-slips-past-spam-filters-on-its-way-to-australia\/","title":{"rendered":"Massive Spam Attack Slips Past Spam Filters on its way to Australia"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\" size-full wp-image-538 alignleft\" src=\"http:\/\/hidefideas.com\/blog\/wp-content\/uploads\/2016\/03\/aust2.gif\" alt=\"aust2\" width=\"255\" height=\"192\">What is it about Australia these days? Whether it\u2019s their <a href=\"http:\/\/www.theaustralian.com.au\/australian-it\/government\/acma-cracks-anti-spam-whip\/story-fn4htb9o-1226149157054\">tough stance<\/a> on spammers (<a href=\"http:\/\/www.allspammedup.com\/2013\/01\/canadian-government-works-hard-to-be-more-frustrating-than-spam\/\">Canada: take note<\/a>), <a href=\"http:\/\/www.allspammedup.com\/2012\/09\/aussies-among-worlds-top-spammers-gullible-maybe\/\">surprising reports<\/a> about where the spam is coming from, or Aussies saying <a href=\"http:\/\/www.allspammedup.com\/2012\/10\/australian-spam-complaints-rise-over-600\/\">enough is enough<\/a>, the country that\u2019s so cool they called it a continent has been making all sorts of spam news recently, and this week, the country made the news again when a massive spam attack slipped past anti-spam filters and landed squarely in users\u2019 inboxes.<!--more--><\/p>\n<p>Westpac, one of Australia\u2019s big four banks, is the latest target as Trojan laden spam hit more than 125,000 users in a focused attack on Thursday morning, and <a href=\"http:\/\/www.scmagazine.com.au\/News\/336507,westpac-spam-serves-trojan-to-hundreds-of-thousands-of-aussies.aspx\">SC Magazine<\/a> reports that the amount of nasty emails has \u201cspiked into many hundreds of thousands of emails\u201d on Thursday, and that the number appears to be on the rise. Reports are a little fuzzy so far, but the spam messages appear to be packing W32\/Kryptik.KZ!tr and BackDoor.Slym.1498, two known Trojans. Apparently phishing emails, users were instructed to launch the attachment (presumably, some sort of banking notification) using Internet Explorer. The malware has been reported as some sort of remote backdoor Trojan, in other words, nasty stuff with which to become infected, and especially dangerous considering the scope of the attack and the pace at which it\u2019s propagating.<\/p>\n<p>\u201cAt least some of the phishing emails bear the attachment SecureMessage.zip and the sender address secure.mail@westpac.com.au,\u201d SC Magazine is reporting, and <a href=\"http:\/\/www.bit.com.au\/News\/336536,warning-westpac-scam-alert.aspx\">Bit.com<\/a> has reported that the message is being sent with the subject &#8220;WestPac Secure Email Notification.&#8221; Security professionals are reporting that the exact nature of the payload, while still being identified, is being delivered in variants. According to one spokesman, the spam has circumvented 42 out of 44 email antivirus software applications, not a great track record if you\u2019re a fan of\u2026uhm, I don\u2019t know, things actually working the way they\u2019re supposed to. &#8220;This is the biggest fast breaking email the tech guys can remember,&#8221;&nbsp;Anwar Ibrahim, a service delivery director stated. SC Magazine points out that \u201cAlmost 2000 unique IP addresses were logged sending the spam using a single filter, pointing to the United States, Peru and Australia in descending order.\u201d<\/p>\n<p>The attack also appears to be a scorched earth campaign, dispensing with targeted attacks in favor of indiscriminately blasting out as many emails as possible. Bit.com points out that institutions like banks are popular targets. \u201cFraudsters often use the names of trusted organisations such as banks, courier companies and government departments to encourage recipients to open emails containing malware. The&nbsp;Australian Taxation Office (ATO) [is] another name that&#8217;s popular with spammers, for example.\u201d The malware&#8217;s SHA256 hash is 5450eea52c6e04bcae760c6181c6c79198daa6e969fca406e0f9dd3b49212d48.<\/p>\n<p>This incident is just another day in the life of the war with spam. No offense to those affected, but we\u2019ve heard it so many times that it lacks the shock value that we might have felt ten years ago. It is a good \u2013 and timely \u2013 reminder that these things hit without warning, and that spammers will stop at nothing to line their pockets. That it hit so suddenly is not surprising. That it was so effective in slipping past detection software is. We seem to be seeing more and more attacks, which by design have managed not only to fool the anti-spam filters, they in fact are good enough to fool most users. And that\u2019s something we need to discuss.<\/p>\n<p>Spring is almost here. It\u2019s time to do a little spring cleaning. Check your filter settings and spam folders. How effective is it? Maybe a little tweaking is required. Use this opportunity to get your users together and share information. Use some of the more effective spam campaigns \u2013 like the one reported in this article \u2013 as real-world examples of what to look for. Scare your users if you have to. Remember, they don\u2019t know what you know. They\u2019re also very busy making sure their pay checks keep coming, so, unlike you, looking out for malware attacks is not in the forefront of their minds. Take the time to refresh on best practices, phishing methods, link spoofing, the dangers of clicking links and opening attachments, and email preview panes \u2013 all those things that put users at risk. Anti-spam filters are invaluable tools, but like any other tool, they\u2019re only as good as the person wielding it Awareness and vigilance are of utmost importance, because they\u2019re out there. The spammers won\u2019t stop until they\u2019ve got you.<\/p>\n<p>Stay safe.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What is it about Australia these days? Whether it\u2019s their tough stance on spammers (Canada: take note), surprising reports about where the spam is coming&hellip; <\/p>\n","protected":false},"author":3,"featured_media":538,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,14],"tags":[11,9,10,8,7],"class_list":["post-537","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","category-spam","tag-allspammedup","tag-bot","tag-botnet","tag-malware","tag-spam","jsn-master"],"_links":{"self":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/537","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/comments?post=537"}],"version-history":[{"count":2,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/537\/revisions"}],"predecessor-version":[{"id":1763,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/posts\/537\/revisions\/1763"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/media\/538"}],"wp:attachment":[{"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/media?parent=537"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/categories?post=537"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hidefideas.com\/blog\/wp-json\/wp\/v2\/tags?post=537"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}