Showing posts with label Adobe Flash Player. Show all posts
Showing posts with label Adobe Flash Player. Show all posts

Monday, 12 March 2018

Recent Adobe Flash Player Vulnerability Leak Attacked Via Exploit Kits



A recently patched vulnerability in Adobe Flash Player is being actively attacked via exploit kits. This means that visiting a hacked website or seeing infected ads with a vulnerable Flash Player version is sufficient to infect with malware.

The vulnerability in question was resolved by Adobe on February 6 through an emergency patch . The vulnerability appeared to have been targeted against South Korean organizations since last November . Here Excel and Word files with embedded Flash objects were used. Now it appears that cyber criminals also have the exploit to use them via the web.

Flash Player was and still is the most popular target for exploit kits. Due to the absence of new exploits, and the fact that more and more browsers are phasing out the support of Flash Player, the effectiveness of exploit kits has declined sharply in the past period . According to researcher Kaffeine of the Malware do not need coffee blog , this is the first new Flash exploit that has been added to an exploit kit since July 2016 for a Flash leak. The new Flash exploit will be deployed via infected ads and will successfully install the Hermes ransomware. Users are therefore advised to upgrade to Flash Player version 28.0.0.161 or later, as the vulnerability has been corrected.

Thursday, 26 October 2017

Infrastructure Behind BadRabbit Ransomware Since 2016 Active


The infrastructure used last Tuesday to spread the BadRabbit ransomware has been active since 2016, says Dutch security researcher Yonathan Klijnsma from security company RiskIQ. During the attack the attackers used a large number of hacked websites.

These websites showed a popup to visitors that they needed to install an update for Adobe Flash Player. In fact, it was a Petya ransomware variant that encrypted files on the hard drive and overwritten the Master Boot Record from the hard drive. As a result, the operating system can no longer be started. Furthermore, BadRabbit tries to spread on SMB via a list of commonly used passwords and intercepting login credentials via SMB.

On the hacked websites, code was sent to an injection server that showed the malicious popup on the websites. One of these injection servers was first observed last September. In addition, various hacked websites have been compromised since last year. RiskIQ counted 63 hacked websites where the attackers had access. The security company claims, however, that it can go for more websites.

"The group behind the BadRabbit ransomware has been active for quite some time," said Klijnsma. The researcher speaks of a long-term campaign that could possibly be set up for something other than BadRabbit. "Although the BadRabbit ransomware is brand new, we can track the distribution industry by the beginning of 2016, which shows that victims had been compromised a lot before before the ransomware hit and the news cycle began. The campaign could originally be set up for something other than BadRabbit. " Security company Symantec claims that 86 percent of the infections occurred in Russia and it mainly concerns companies.

Tuesday, 24 October 2017

Ukraine And Russia Hit By Bad Rabbit Ransomware


Organizations in Ukraine and Russia have been hit by a new ransomware copy called Bad Rabbit, which would be a Petya ransomware variant that spread this summer, reports anti-virus company ESET. The malware would have infected hundreds of systems.

Among the victims are the Kiev metro, the Odessa airport and the Ukrainian ministries, according to the virus fighter. Anti-virus company Kaspersky Lab announces that most victims are in Russia. For example, the Russian press agency Interfax has been hit by the ransomware. The press office reports that the news services are not available because of the attack. "Based on our research, it is a targeted attack on corporate networks through methods similar to the ExPetr attack," said Kaspersky researcher Alex Perekalin. ExPetr is one of the names given to the Petya variant of this summer.

According to Kaspersky Lab, Bad Rabbit ransomware is spread through a number of hacked Russian media websites. ESET researcher Lukas Stefanko , Proofpoint researcher Darien Huss and the known anti-virus veteran Vesselin Vladimirov Bontchev warn that ransomware is on websites as an update for Flash Player . As soon as a user downloads and opens this so-called update, the Bad Rabbit ransomware will be activated on the system. Bad Rabbit tries to spread on the network. To do this, a list of common passwords is used, and Bad Rabbit tries to steal login data through the Mimikatz tool.

Bad Rabbit encrypts files and, like Petya, overwrites the Master Boot Record (MBR) of the hard drive. Therefore, the system becomes unusable. The ransomware claims victims 240 euros for decrypting the files. Whether victims pay the ransom to recover their files is still unknown. Organizations are advised to block executing files c: \ windows \ infpub.dat and c: \ windows \ cscc.dat and, if possible, disable Windows WMI service so that ransomware can not spread further .

Initially, ESET researcher Stefanko reported that the EternalBlue operation was also used. This does not appear to be the case at all. The article has been modified.

The attackers knew to hack several media and news sites. Then there was a malicious code that offered the so-called Flash Player update. Most infections have been observed in Russia, followed by Ukraine, Bulgaria and Turkey. According to ESET, all major companies are affected at the same time. "It is possible that the attackers already had access to the network and launched the attack through the websites at the same time as distraction," said Marc-Etienne M.Léveillé of ESET. He notes that there are no indications that employees of affected organizations have been stepped into the so-called Flash Player update. Anti malware company Malwarebytes announces that the attackers behind Bad Rabbit are likely to be responsible for the Petya / NotPetya variant of last June.

In the meantime, several technical analyzes of Bad Rabbit have appeared online. :

- Bitdefender

- Cisco

- ESET

- Kaspersky Lab

- Malwarebytes

- McAfee

- Qualys

According to Costin Raiu of Kaspersky Lab, the attackers behind Bad Rabbit would have been working on setting up the network of hacked websites since July. The attackers had access to, inter alia, Russian, Turkish, German and Bulgarian websites.

Monday, 9 October 2017

Infected Pornhub Ads Spread Kovter Malware



On the popular porn site Pornhub, infected advertisements appeared to infect visitors with malware. According to market researchers, the porn site is ranked in the top 30 of most visited websites in the world. Pornhub claims itself to get 75 million unique visitors a day.

The infected ads were spread through Traffic Junky's ad network. The ads passed users to a website that believed that there was an important update for the browser or Adobe Flash Player. When users clicked on the page, a JavaScript file was downloaded that installed the final malware. It was about malware that caused the computer advertising fraud. After being informed, both Traffic Junky and Pornhub have removed the ads, according to security company Proofpoint.


"The combination of large scale malvertising campaigns on print-enabled websites with sophisticated social engineering that convinces users to infect themselves means that potential exposure to malware is quite high and millions of Internet users are reached," says the Proofpoint researcher with the alias Caffeine. "Once again, we see that attackers exploit the human factor as they adapt their tools and approaches to a landscape where traditional exploits are less effective." The investigator thus targets the fact that attacking vulnerabilities in browsers and Adobe Flash Player causes ever fewer infections to cyber criminals.


Indicators of Compromise (IOCs):


IOC
IOC Type
Description
www.advertizingms[.com|204.155.152.173
domain|IP
Suspicious Epom server 2017-10-01
*-6949.kxcdn.com
domains
Subdomain from a rogue KeyCDN customer 2017-10-01
phohww11888[.org|192.129.215.155
domain|IP
KovCoreG soceng host  2017-10-01
cipaewallsandfloors[.net|192.129.162.107
domain|IP
KovCoreG soceng host  2017-10-01
b8ad6ce352f502e6c9d2b47db7d2e72eb3c04747cef552b17bb2e5056d6778b9
sha256
            T016d6n7t96x2hc43r5f3u6gs61d.zip (zipped runme.js)  2017-10-01

4ebc6eb334656403853b51ac42fb932a8ee14c96d3db72bca3ab92fe39657db3
sha256
FlashPlayer.hta
 2017-10-01
a9efd709d60e5c3f0b2d51202d7621e35ba983e24aedc9fba54fb7b9aae14f35
sha256
Firefox-patch.js
 2017-10-01

0e4763d4f9687cb88f198af8cfce4bfb7148b5b7ca6dc02061b0baff253eea12
sha256
 Kovter 2017-10-01

f449dbfba228ad4b70c636b8c46e0bff1db9139d0ec92337883f89fbdaff225e
sha256
 Kovter 2017-10-01

Tuesday, 19 April 2016

Adobe: Flash Player Security Thwart Hackers


Adobe security measures in recent months have added to Flash Player ensures that hackers could not carry out successful attacks on the media player during a recent hacking contest, as the software company announced.

During the annual Pwn2Own contest hackers are rewarded for demonstrating unknown vulnerabilities in different browsers and Adobe Flash Player. During the last edition of March Flash Player was finally twice successfully hacked , but that number could be higher, says Peleus Uhley of Adobe. In preparation for the hack contest Adobe rolled several updates to enhance the security of Flash Player.

These measures paid off as several attempts to hack Flash Player failed thus said Uhley. Still, Flash Player has been successfully hacked twice. "These victories show that there is always more vendors can do to improve security," he continues. Uhley notes that companies such as Adobe, Microsoft and Google are engaged in a race with hackers.

Adobe invests in his own words than a lot of security and regularly adds features to thwart it. hackers as only goal. "Such measures are increasingly being added. The companies themselves will change on the frontline of this battle and to grow the more expensive." According Uhley help hacking contests like Pwn2Own software companies to develop. "While Pwn2Own each year seems to take the same required innovations and challenges to books every year results," said Uhley.

Friday, 12 February 2016

Ads On Skype Spreading Ransomware



Cyber Criminals have managed to show ads to Skype users who were trying to infect computers with ransomware, says anti-virus firm F-Secure. Although the ads appeared within Skype, does not mean that the browser is not open to advertising.


In the case of observed infected ads which showed the browser unnoticed load a page with the Angler-exploitkit. This exploitkit uses known vulnerabilities in Adobe Flash Player to infect computers with malware. Users who had not patched their Flash Player could become so infected with the Tesla Crypt-ransomware. Like other ransomware encrypts Tesla Crypt sorts files for ransom. The ads on Skype came from the AppNexus-advertising platform, which in the past often for the spread of infectious advertisements used. Meanwhile, the offending ads are no longer displayed.

Thursday, 11 February 2016

Google Stops From 2017 With Flash Ads


From January 2017 Google stops displaying Flash ads on their own ad networks, such as the Google Display Network and DoubleClick, as the Internet giant has over Google Plus disclosed. According to Google, it's important for advertisers to switch to HTML5 ads, so many people can be reached.

To accelerate this process will AdWords and DoubleClick Digital Marketing from June 30 to accept new Flash ads this year.From January 2, 2017 Flash ads will no longer be on the Google Display Network are displayed via DoubleClick. Google warns advertisers that they should have converted their ads to HTML5 for these dates. For now, the new measure does not affect video ads created in Flash.

Google has long been working to make Flash unnecessary. As YouTube videos are automatically played through HTML5. In the case of Flash ads that are distributed through AdWords, which are automatically converted to HTML5 since February last year. Since September 1st of last year, most Flash ads automatically in Google Chrome paused .

Last year, also called Alex Stamos, the new Chief Security Officer (CSO) of Facebook, which with Adobe Flash technology to stop , so that it can be switched completely on HTML5. HTML5 is natively supported by modern browsers and allows playback of videos and other "rich content" without installing additional plug-ins possible.

Wednesday, 10 February 2016

Adobe Close Critical Vulnerabilities In Flash Player And Photoshop



Adobe has patched critical vulnerabilities in Flash Player and Photoshop computers could allow an attacker to take complete. In the case of Flash Player is about 22 critical vulnerabilities which allowed an attacker to execute arbitrary code on the computer, such as installing malware by just visiting a hacked website or see it from an infected ad.

There was no further interaction required from users. As far as known vulnerabilities are not attacked on the Internet. Since attackers often develop after the release of Flash Player updates exploits to attack unpatched users, Adobe advises to update to Flash Player version 20.0.0.306 within 72 hours. This can be done via the automatic update function or Adobe.com. In the case of Google Chrome, Internet Explorer 10 and 11 on Windows 8 and 8.1 and Internet Explorer 11 and Microsoft Windows 10 Edge Embedded Flash Player will be updated using the browser. Through this Adobe page can be verified that the system version is installed.

There is also a security update for Adobe Photoshop CC and Adobe Bridge CC appeared. The update fixes three critical vulnerabilities that an attacker could take over your computer if opened a malicious file. Because Photoshop traditionally not been a target for attackers, Adobe advises users and administrators to install the update if it suits them. Updating via the built-in updater of drawing programs. In the case of Photoshop CC 02.04.2014 is the update to download only via Adobe.com.

Saturday, 28 November 2015

Hacked Site Reader's Digest Spread Malware


Attackers have managed to hack the website of Reader's Digest and use this now to spread malware. Before that anti-malware company cautions Malwarebytes. According to the company, there is an increase in the number of hacked WordPress websites and Reader's Digest is one of them.


On the hacked websites is placed code that visitors unnoticed to a page with the Angler-exploitkit forward. This exploitkit is using known vulnerabilities in Adobe Flash Player and Internet Explorer users have not patched. In case the attack is being installed Bedep Trojan on the computer successfully, which can install additional malware again.

Reader's Digest was a few days ago warned by Malwarebytes, but the security company and got no response when a blog posting about the infection appeared online yesterday distributed the website still malware.

Friday, 13 November 2015

Google Closed Leak Of Information In PDF Reader Chrome


There is a new version of Google Chrome appeared where one vulnerability has been eliminated, as well as multiple vulnerabilities in embedded Flash Player. The vulnerability was an information leak in the PDF reader in Chrome. Besides Flash Player browser also has a built-in PDF reader.

Details on the vulnerability Google will not disclose if enough users have installed the new version. However, the leak has been labeled as 'high'. In this case, a malicious website could read confidential data from other websites or modify. The vulnerability was discovered by Rob Wu, who was awarded $ 4,000. It is also added the Flash Player to Chrome this week appeared. Update to Chrome 46.0.2490.86 happens on most systems automatically.

Wednesday, 11 November 2015

Critical Vulnerabilities In Adobe Flash Player Poem



There is a new version of Adobe Flash Player that appeared in a total of 17 vulnerabilities were fixed, allowing an attacker in the worst case, the computer could take over completely. Through 16 of the leak, it was possible for an attacker to execute arbitrary code on the computer.

An example is to install malware. Only was visiting a hacked or malicious website is adequately, or viewing an infected ad.The remaining vulnerability allowed an attacker to bypass the security of Flash Player, which made it possible to attribute any data to the file system with the rights of the logged in user.

A researcher named Bilou discovered 11 of the 17 vulnerabilities and sold to HP's Zero Day Initiative, which then briefed Adobe. Users are advised to update within 72 hours to Flash Player version 19.0.0.245. This can be done via the automatic update feature or Adobe.com. In the case of Google Chrome, Internet Explorer 10 and 11 on Windows 8 and 8.1 and Internet Explorer 11 on Windows 10 and Microsoft Edge Embedded Flash Player will be updated via the browser. Through this page Adobe can check which version is installed on the system.

Tuesday, 10 November 2015

Adobe Flash Player Most Attacked Software


Adobe Flash Player is the most attacked software on the Internet, according to the US company Recorded Future, on the basis of its own research. For the study were analyzed for more than one hundred exploit kits. These are programs that use vulnerabilities in software to fully automated and without requiring users to install malware on computers this notice.

Of the 10 most attacked vulnerabilities exploitable by kits are there in Flash Player 8. The other two attacked vulnerabilities present in Internet Explorer and Microsoft Silverlight. Most popular among cybercriminals vulnerability involves a flaw that Adobe Flash Player on February 2 this year patched. The survey also shows that Java, which was a favorite target in the past, from the radar of cyber criminals has disappeared.

Where criminals often in the past for some time using old vulnerabilities made, dating all attacked vulnerabilities in the Top 10 this year. Recorded Future suggests that companies should decide themselves whether to install the continuous flow of Flash Player updates a viable is an option. Otherwise, click-to-play "be used as a solution to prevent attacks.

Sunday, 1 November 2015

IBM: Businesses Need Flash Apps Replaced By HTML5


Companies that offer Flash applications are wise to that HTML5 to convert, since the call for an internet browser without plug-ins is getting stronger, says David Strom IBM. Strom pointing to newer versions of Chrome and Firefox that no longer support the old NPAPI plug-sustaining nature. The main reasons for this are security and performance issues.

Recently, Mozilla announced that it is supporting the Java browser plug-in will cease altogether. However, there is a plug-in that is still supported, and that's Adobe Flash Player. Increasingly parties, however, are calling for an alternative, so that Internet users do not need more plug-ins to view online content or use. So pleaded Facebook CSO Alex Stamos before the end of the Flash technology.

According to Strom, this is not a new trend, since the appearance of the first Apple iPad without Flash support organizations have attempted to create websites with HTML5, the intended successor of Flash. This year, however, HTML5 can make its breakthrough, according to security evangelist at IBM. He argues that the time has come for organizations and companies for their Flash based apps to HTML5 to convert.

Saturday, 24 October 2015

Google Slow Closing Of Flash Vulnerability In Chrome


A critical vulnerability in Adobe Flash Player which last week an emergency patch released almost a week later poem by Google in Chrome. Notable because Google updates for Flash Player sometimes been rolled out in Chrome than Adobe releases updates to users.

Chrome includes an embedded version of Flash Player must be updated by Google. Last week Friday, October 16th Adobe released an emergency patch for a critical vulnerability in which was actively used to infect computers with malware. Microsoft added this update on October 19 to 10 and Internet Explorer 11 on Windows 8 and 8.1 and Internet Explorer 11 and Microsoft Edge on Windows 10. These browsers also feature an embedded Flash Player.

Yesterday, Thursday, October 22, Google came only with a new version of Chrome, the update was processed. It is in this case Chrome 46.0.2490.80 for Windows, Mac and Linux. This version will be automatically installed on most systems. The latest version of Adobe Flash Player 19.0.0.226. Through this page from Adobe, see what version of the system state.

Friday, 23 October 2015

Magento: Hacked Websites Have Not Installed Update



Monday warned security for thousands of hacked Magento sites used to distribute malware. According Magento websites are not adopted by an unknown vulnerability, but the administrators have not installed an important update.

This update was published in February this year and fixed the so-called "Shop Elevator Bug". Through this vulnerability, attackers execute arbitrary code remotely and gain administrator access. In February Magento warned that webmasters should install the update immediately, but eight months later turn out thousands of merchants to have given no answer to this.

In addition, some merchants have been taken over possible because administrators used a weak password. Owners get a Magento site advised to check their website for the presence of malicious code and malware, rename all administrators in the system and install all available updates immediately.

Monday, 19 October 2015

Thousands Hacked Magento Sites Spread Malware


In recent days, thousands of Magento sites are hacked and include malicious scripts that attempt to infect visitors with malware. How websites are hacked exactly is still unknown, so let security firm Sucuri in an analysis know.

According to the company, Google has been hacked 7000 Magento sites blocked. Magento is a popular open source content management system for web shops. Anti-malware company Malwarebytes reports that the attackers script on the hacked websites sites visitors unnoticed to a page with the Neutrino-exploitkit. This exploitkit uses a known vulnerability in Adobe Flash Player to put the Andromeda malware on the system. This malware can steal login details for internet banking and make your computer part of a large botnet.

Latest Adobe Flash Attack Bypassed Security



In July, added Adobe new security measures to Flash Player, which combines with Google had developed it more difficult for attackers had to make to exploit vulnerabilities, yet his attackers managed to circumvent this obstacle, according to the zero-day attack this week.

Through the new vulnerability in the browser plug-in foreign ministries were attacked in many countries. The vulnerability has been through an emergency patch poem. Reason for anti-virus company Trend Micro, the zero-day attack as first reported, to more details to release about the leak. According to the virus-fighter have to evade the attackers in this attack the security of Adobe and Google know.

"This particular vulnerability is a new kind we Method Confusion can call it. It's the most interesting Flash flaw that I have ever studied," said analyst Peter Pi. In the case the attack was successful Sednit the malware was installed. This malware was previously at various espionage attacks deployed. According to Pi security measures such as those from Adobe and Google reduce the likelihood of a successful attack, but they are not panaceas. "History has shown that good or perfect vulnerabilities always managed to bypass security." Due to the latest Flash Player flaw advised the Internet Storm Center businesses and users to uninstall the browser plug-in permanently systems.

Thursday, 15 October 2015

Adobe Comes Up With New Emergency Patch For Flash Player Flaw


Adobe next week will release an emergency patch for a serious vulnerability in Flash Player that asset is used by attackers to infect computers with malware. The newest vulnerability in the software this week was discovered during attacks in various ministries.

The attacks took place via e-mails containing a link. The link pointed to a website with an exploit that used the vulnerability in Flash Player in order to infect the computer of the target. Adobe has now confirmed that the latest version of Flash Player, version 19.0.0.207, which is indeed a critical vulnerability has been used in a limited number of targeted attacks.

During the week of October 19 will Adobe therefore with an emergency patch to come. The zero-day vulnerability was reported on the very day that Adobe released version 19.0.0.207, where 13 vulnerabilities were fixed. According to anti-malware company Malwarebytes Now is the time to seriously consider switching from Flash Player in the browser or to remove completely from the computer.

Daily Mail Spread Malware Via Infected Adverts


On the website of the popular British newspaper the Daily Mail are infected ads appeared which attempted to infect visitors with malware. The ads were supposedly advertisement for shoes, but let visitors actually load a page with the Angler-exploitkit.


This exploitkit uses vulnerabilities in Internet Explorer and Adobe Flash Player to infect computers with malware. These are known vulnerabilities. Users whose software was up-to-date therefore were not at risk. In the case the attack was successful CryptoWall-ransomware is installed. After being informed by anti-malware company Malwarebytes the advertisements of the site were removed. The Daily Mail gets 156 million visitors monthly and is according to Alexa at the 100th place of most visited websites on the internet.

Wednesday, 14 October 2015

Zero-Day Vulnerability In Latest Flash Player Active Attacked


In the latest version of Adobe Flash Player that came out yesterday is a zero-day vulnerability for which no update is available and actively attacked. Reported that the Japanese anti-virus company Trend Micro. Several foreign ministries would be attacked by the leak.

Victims receive a spear phishing email containing a link to a website. This website loads an exploit of the Flash Player flaw uses to install malware on the computer. The emails have subjects like: "Suicide car bomb targets NATO troop convoy in Kabul," "Syrian troops make gains as Putin defends air strikes", "Israel launches airstrikes on targets in Gaza", "Russia warns of response to Reported US nuke buildup in Turkey, Europe "and" US military reports 75 US-trained rebels return Syria ". Visiting such a malicious page with a vulnerable Flash Player is enough to get infected. There is no further interaction is required.

According to Trend Micro, the group behind the attack is also responsible for an attack in which a zero-day vulnerability was used in Java. Also, the group behind attacks on NATO, the White House, the German parliament and foreign ministries sit. The message of the anti-virus company coincides with the Tuesday patch from Adobe. Yesterday released a new version of Adobe Flash Player that 13 vulnerabilities were patched. Yet even Flash Player 19.0.0.207, the latest version now vulnerable to the observed attacks. Adobe would be informed of the new leak, but he has not yet written warning.