Sophos

6 October 2007 16:52 GMT

Quiet on the malware front

It has been a quiet Saturday here in the UK, at least on the malware front. This means that either virus writing activity is on the decrease or that our proactive protection is catching new variants. I hope both theories are true.

Nevertheless, spammers are active as always on weekends, catching some users unaware. There were several phishing campaigns today with the most interesting one targeting the PayPal service.

Apart from the usual copying of PayPal’s website and the redirection to the real site after collecting the credit card details, the attackers went one step further in trying to convince the user in the legitimate nature of the site. As an additional ’security measure’ they included a CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) to ‘ensure’ that no automated tools would fill-in the form.

PayPal Phish

The CAPTCHA is as fake as the page and the content of the image does not change with the subsequent page reloads.

Vanja Svajcer, SophosLabs, UK