admin's blog

CelloCloud™ protect you from H1N1 Spam

Hackers usually use the most popular things that people are talking about to send the spam mail. By the spare of the H1N1 globally, the relative topic of H1N1 spam mail are all over the place. CelloCloud™ Threat Sensor System already found out many cases of spam mail which are using the H1N1 as the topic to attack personal computer. They are using a very attractive topic such as ”Madonna caught swine flu!” or ”Swine flu in USA”“ to let the receiver to click the website or download the Trojan to personal computer to steal the personal information or combine with Flash to attack the unguarded computers.

Cellopoint wants to remind everyone 1. Be aware of the suspicious email. Do not open or click the links inside an email. Do not give away any personal information such as bank account number, password…ect in the email. None of the companies would request this kind of information from their user. 2. Do not reply to spam, as it will let Spammer know your email address is valid. Then they will send more spam. In addition, a number of spam contains unsubscribe links will create the same result. The best way to deal with spam is to delete without reading it. 3. Watch out for social-engineering trap. Hackers become more sophisticated and often trick individuals to enable malicious code attacks (Spear Phishing). 4. Do not forward chain letters. This special kind of email may be created by hackers to collect email accounts for the production of spam.

CelloCloud™ Threat Sensor System relase the anti-spam database update when the system discovered the threat of the Swine spam to protect their global clients. CelloCloudTM provides “Global threat protection” and “ Online update protection” functions. It can help for anti-spam, virus, anti-spy, phishing, anti-reply, DoS attack, hackers threat …ect. CelloCloudTM Threat Sensor System just like a safety cloud to prevent our customers from the threat and reach our goal of “Cloud Security for Email”

Free Email is an accessory for hacker to attack job hunters

Due to the economic resection ,there are more and more unemployed people looking for jobs on line and it gives the hackers a perfect chance to defraud those job hunters. Cellopoint Global Anti-spam Center (CGAC) has found and intercepted a huge amount of spear phishing messages which contain messages like “Thank you for applying xx position. After reviewing your resume, you are not qualified for this position. We decide to send your resume back to you…”This email seems normal with the link of the company website. If you open the attached file, it would not be your resume that you are looking for. It would be Trojan Horse. It is impossible for the job hunters to memorize all the companies' names and jobs that they applied for. This is the reason that job hunters are the victims of these false emails.

Cellopoint Global Anti-spam Center (CGAC) thought that these spear phishing attacks are showing the new change of the social behaviors. Besides those Botnet computers which have been attacked by Trojan, hackers also use those free web mail servers as the step stone to attack regular user. For the service provider, this not only slows down the efficiency of the mail server but also becomes the black list which would effect the basic function of sending or receiving mails. If the service provider wants to promote a better email service by charging their customers, the black list would be the biggest problem for their future business plan. The Executive Yuan of the Republic of China has already passed the new law of “the management of sending business email” which says that the email service provider must prevent the spam of business email. If the email service provider can not forbid the spam, they will receive the find until they do something to stop it.

Cellpoint email security and management solution also called Email UTM. It got the first place of the Ites Best Choice of “Anti-spam” in 2008 by Institute for Information Industry. From Email UTM, it included CGAC online guarding service about anti-spam, virus email, anti-spy, phising, anti-Relay, anti-Dos, anti-Hacking to secure the safety of email transferring, Digital Signature to solve the problem of counterfeit email. Cellopoint Policy Center can classify the email into different categories between business email and regular email. It provides IP Pool management. This can avoid the regular email IP to be listed in the spam blacklist. It can forward, delete, quarantine, notice the inspect or secure copy…ect. This can increase the efficiency of the system dramatically for all the clients include the service providers, businesses and organizations.

Cellopoint warns of Valentine’s Threat

With Valentine's Day just around the corner, email threats hided in Valentine’s Card are also awakening. Cellopoint Global Anti-spam Center, CGAC has a warning for internet users: The surge of Valentine Day attacks come from notorious Waledac botnet and disguise as E-card format. This kind of spam carries links to get users to visit malicious sites. Instead of real greeting cards, malware will be downloaded and compromised their computers. The infected computers will become part of botnet and send out spam and virus without awareness as well.
This kind of spam is short and sweet one liner with content like: “Me and You”, “In Your Arms”, “With all my love” and “I give my heart to you” followed by an URL. If you receive an email above and similar to the title, you should be careful. Do not open it without double confirm. Besides, tax refund and online booking confirmation also increases in amount.

Cellopoint provides a few tips to stay away from spam:

  1. Use an email security solution. This solution should protect against inbound email threats and viruses while ensuring transmission of legitimate email messages without delay. It should maintain a very low false-positive rate.
  2. Educate users on secure email practices. Be careful with suspicious email. Never fill out forms in email messages that ask for personal or financial information or passwords. Remember that legitimate companies will never ask for this type of information via email. Avoid opening suspicious emails and clicking on suspicious links.
  3. Do not reply to spam, as it will let Spammer know your email address is valid. Then they will send more spam. In addition, a number of spam contains unsubscribe links will create the same result. The best way to deal with spam is to delete without reading it.
  4. Watch out for social-engineering trap. Hackers become more sophisticated and often trick individuals to enable malicious code attacks (Spear Phishing).
  5. Do not forward chain letters. This special kind of email may be created by hackers to collect email accounts for the production of spam.

About Cellopoint
Cellopoint is a leading provider of email UTM (Unified Threat Management) solutions for organizations ranging from small businesses to large enterprise and ISPs. We defend against email threats such as spam and viruses, prevent leaks of confidential data by content filtering and secure mail delivery, archive email to protect your digital assets, comply with regulatory inquiries and corporate investigations in a single, web-based platform. We provide the maximum reliable, scalable and flexible solutions to help you deploy and manage easily. For more information, please visit: www.cellopoint.com

Botnet goes back after McColo shutdown

The notorious botnet hosting, McColo has been taken down by a group of Internet Providers on Nov 10 and total spam production dropped as much as 50 percent. The action followed investigations by security researchers that found that McColo was found to become the preferred home of for many botnets' command and control servers, including Rustock and Asprox. Now that Cellopoint Lab has found that spam volumes are rising up again after decreasing four weeks ago when a rogue hosting company was shutdown. The volumes dropped for 9 days and are on the rise. The reason that may account for could be some botnets are awakened or regenerated. Spammers seem to try many ways to send out spam. The Mega-D botnet, well-known for producing "billions" of spam, most of which promote sexual performance drugs such as Viagra has worked effectively over the last three weeks to set up new command and control servers and re-establishes connections with its networks of compromised bots. And other famous botnet, Srizbi and Rsutock have also come back. The botnets' return comes as no surprise to the information security industry. The spam should be monitored, despite its dropped volume. Organizations still need to remain the same level of security as usual. To help protect against many email and internet threats, Cellopoint recommends the following: spam filtering and email anti-virus. Rather than rely on any single piece of anti-spam and anti-virus product or technology, deploy multiple layers of security throughout the organization by Email UTM.

About Cellopoint
Cellopoint is a leading provider of email UTM (Unified Threat Management) solutions for organizations ranging from small businesses to large enterprise and ISPs. We defend against email threats such as spam and viruses, prevent leaks of confidential data by content filtering and secure mail delivery, archive email to protect your digital assets, comply with regulatory inquiries and corporate investigations in a single, web-based platform. We provide the maximum reliable, scalable and flexible solutions to help you deploy and manage easily. For more information, please visit : www.cellopoint.com

Personal email accounts and data loss prevention

A few days ago, American Republican vice presidential candidate Sarah Palin's yahoo e-mail account had been compromised by hackers. Parts of the contents of the message were available to download. In addition to a number of personal photos, nothing makes Palin embarrassed. But news pointed out that Palin had consulted with public affairs via this personal email account, it may try to avoid the law. At present, a 20-year-old Democratic Tennessee state representative’s son is suspected and had relations with this. FBI may investigate with him soon.

Not only political figures, the executives of companies have also suffered from target attacks. For corporate governance, it is necessary to prioritize the policy for the usage of personal email accounts. If unable to control it, it had better to limit it to prevent employees from inadvertent forwarding of email containing product development or business plans to other personal email recipients intentionally or not. Cellopoint proposed that businesses or organizations can implement policies and control e-mail messages with auditing tools. Scan the contents and detect improper behaviors of incoming and outgoing messages. If employees may leak sensitive information to external email addresses, the auditing tool should instantly quarantine the email and notify the auditors or the manager. It results in good email leakage prevention.

A New Twist on Phishing: Fraudulent FedEx Email Attacks

In the wake of a flood of phishing email attacks masquerading as news bulletins, hackers have recently launched attacks disguised as FedEx express delivery tracking emails. These hackers use botnet computers to send emails with FedEx package tracking numbers telling recipients that the delivery of their parcel has run into some problem: the address contains an error, the recipient's name does not exist, customer reconfirmation is required, or pick-up is required. A compressed zip file is attached to the email, and the customer is asked to decompress the file, print it out, and send it back. The zip file is actually a malicious program, however, and if opened by an unsuspecting recipient, will automatically install a backdoor program that can steal sensitive data on the computer. This type of email attack relies on social engineering. For instance, a package tracking number may be used to obtain the recipient's trust, or the email may provide notification of a package ready for pick-up. And since there is a compressed zip file, a backdoor program can be installed on the user's computer without the user visiting a malicious web site. CGAC immediately issued an anti-spam database update after detecting this type of email attack on the 22nd; the update will protect users by effectively controlling the spread of the attack and fraudulent email volume.

A Cellopoint Reminder: No Let-up in CNN Phishing Attacks

A flood of phony CNN phishing email has been causing chaos around the world. Thanks to monitoring by the Cellopoint Global Anti-spam Center (CGAC), it has been known that hackers have been sending out vast quantities of phony CNN phishing emails since August 5, and the volume of these malicious emails has not slackened significantly up to this weekend. It is estimated that 7-8 million of these emails are bombarding users' computers worldwide every hour. The subject line of the emails has changed from "CNN.com Daily Top 10" to "CNN Alerts: My Custom Alert," but the body of the email still replaces the normal web site URL with a link to a malicious fraudulent CNN web site. The email attempts to lead the recipient to the phony web site and induce him or her to download a malicious program.

Because CNN originally sent emails with a similar subject line message, recipients may not suspect that clicking on this email will take them to a malicious web site. When the user reaches the phony CNN web site, they will see a message saying that they need to update their browser's Flash player. It's quite likely that many ordinary users will naturally press "Confirm update" at this time. If they do, a malicious sham Flash player program will be downloaded and installed on their computer.

Cellopoint has developed an URL reputation defense mechanism to combat this kind of attack, and all of our customers are protected. CGAC monitors spam and phishing email worldwide on a daily basis, and includes any suspicious web sites in an URL reputation database. Our email security gateway checks passing emails against the list of suspected phishing web sites, and blocks threats at the gateway end. This method provides ironclad protection against phishing email attacks.

Take Charge of Your Email Backup Security

Recently some people have used a Gmail backup software known as G-Archiver to backup their email and save to a portable disk. But in fact it has turned out that G-Archiver is malicious ruse set by hackers. After it is installed, G-Archiver hides a backdoor program that will automatically transmit the user's Gmail account number and password to the hackers, allowing them to enter the user's Gmail. And because of Google Apps services, a hacker possessing a stolen account number and password can access a wide range of services and documents, exposed users in danger. When this type of malicious software steals the e-mail account information of an inattentive employee of a company using Google Apps, all of the company's data and secrets will be vulnerable to the hackers.

According to Cellopoint's technical consultants, that more and more companies are considering adopting outsourced service models in keeping with the growing popularity of software as a service (SaaS). But these companies should make sure to take information security into consideration: Many well-known SaaS providers have had data leaks. For instance, employees at SalesForce have opened e-mail containing trojan horse viruses, leading to the theft of customer data. Everyone should be careful to prevent this kind of incident.

Cellopoint's Email Security Appliance can take care of e-mail security, e-mail audit, and e-mail backup management within your organization. It is less costly than outsourcing, simplifies management tasks, and improves policy implementation efficiency.

Spear Phishing

Spear phishing is an e-mail spoofing fraud attempt that targets a specific organization, seeking unauthorized access to confidential data. As with the e-mail messages used in regular phishing expeditions, spear phishing messages appear to come from a trusted source. Using social networking it gains the trust of receivers to open e-mail, and implants Trojan to the victim computers, theft of personal bank accounts. The truth is that the e-mail sender information has been faked or "spoofed." Whereas traditional phishing scams are designed to steal information from individuals, spear phishing scams work to gain access to a company's entire computer system. The original spear fishing limited to the financial sector for a number of listed companies or the behavior of amateur hackers, but recently the United States Association for Network Security System (SANS Institute) warning, a spear phishing may become international espionage and intelligence activities in a way. They discovered many phishing e-mail attacks of professional models that do not look like amateur hackers, and this is very organized. The suspected motive is not pure; there may be mastermind behind the scheme. Whatever behinds the scene, commercial secrets and national defense secrets are the most serious things we should protect. It will cause irreparable harm to companies or the public. Because hackers are hiding in a dark place, passive prevention is just basic, the auditing is more important to the private companies or public organizations of information access control. In addition to entities outside the control of information, the e-mail content filtering is most important and popular one. Whether outbound or inbound e-mails have to go through the e-mail firewall scanning and confirm no confidential contents before they are allowed to pass through. Even a personal computer inadvertently has been inserted Trojans, data will not be compromised.

Encountering these internet threats, Cellopoint lab suggests that the first thing to do certainly is to develop a complete set of security-control policies and patches enforcement to staff computers. Not only prevention, making timely response measures to prepare for data leakage from inadvertently infected computer. Such as adding an e-mail security auditing and monitoring mechanisms in the last hurdle. Even if employees' computers were compromised and embedded with the Trojan, we could first stop leakage of confidential information at gateway level before computers were inserted Trojan, as an extra key or another layer of protection to avoid regrettable occurrence.

Can-Spam fine – is it working?

National Communications Commission (NCC) of Taiwan reached an agreement last week's meeting that they will amend "Regulation of can spam management" in next year and propose to the Legislative Yuan. If the regulation passed, victims of spam will be able to claim compensation from spammers at maximum 2,000 NTD each. The total amount will be up to 20 million NTD per unique subject email. This is to improve the current situation of the spam proliferation. Looking at the trend, many countries are using legislative ways to punish and deter such acts, but it is very difficult to collect evidence while enforcing. Hackers were mostly utilizing foreign network location as a springboard. Law enforcement would need more international collaboration to solve the problem.

To the United States, the FBI announced last month that it has taken actions against botnet-runners (use of zombie computers to send spam hackers) by collecting evidence and arresting. It has charged eight American botnet - runners and one of them needs to be face a maximum 60 years in prison. The above-mentioned are aimed at hackers within U.S., but actually there are thousands of hackers and illegal companies actually in Russia, China and other places. Without true transnational cooperation, authorities are barely making a dent in the influx of spam, which are most pervasive in countries with lax laws. From the points of enterprises, even with the law is valid, it may too late to patch computers after they were attacked. The most important is earlier detection and prevention, not only to prevent external spam, but the prevention of in-house computers which compromised by hackers as the springboard. For internal monitoring, Cellopoint Email Firewall (CEF) supports outbound email scan. If an email does not behave normal, it will be isolated by CEF. The people in charge will be informed to confirm the delivery. After eliminating the possible of compromised computer, they can safeguard their reputation and remain a good corporate image.