Showing posts with label Anti-Virus Company. Show all posts
Showing posts with label Anti-Virus Company. Show all posts

Saturday, 14 November 2015

2000 Sites Affected By Linux Ransomware



The ransomware that encrypts Linux web servers has already affected some 2,000 Web sites, but it is still unknown how systems get infected in the first place. Last week, reported the Russian anti-virus company Doctor Web that Linux ransomware had discovered.

The malware encrypted files and demanded one bitcoin, equivalent to 300 euros. The text file with instructions proved to be indexed by Google, so the number of affected sites could be mapped. Initially it went to a hundred websites, as shown by the Google search results. The Finnish anti-virus company F-Secure estimated, used on the basis of the bitcoin wallet that the ransomware that approximately 36 people of the requested ransom also had paid.

Now reports Doctor Web which now has around 2000 sites affected by the ransomware. This relates to WordPress websites and web shops running on Magento. The attackers know exactly how to enter, according to the virus fighter is not yet known.What is known is that it is still all about the first version of the Linux ransomware, which contains an error. This allows victims to free decrypt their data via a Bitdefender tool. Doctor Web warns that the chances are that the creators of the ransomware end up with a new version including all the problems are solved.

Saturday, 18 July 2015

Google Removes Backdoor App From Play Store


Google has removed a rogue app from Google Play posing as a news app, but in reality it was a backdoor. The app used the name 'BeNews "of the now vanished news site with the same name, to look legitimate, say researchers at the Japanese anti-virus company Trend Micro . The researchers discovered the app in the data that was stolen by the Italian Hacking Team.

The app seems to have been developed in order to circumvent the monitoring of the Play Store. To protect Android users Google checks the content of applications for malicious code. Initially, the app asks for three permissions. Via dynamic loading technology, the app can also download and execute code from the Internet. The downloaded code will not be loaded when Google carries out the checks, but only when the app is used by a victim. The app can then use an exploit to increase its rights on the device. The exploit works on Android version 2.2 to 4.4.

In the stolen data, the researchers found also the source code of the backdoor and the server that can be used to communicate with contaminated devices. Trend Micro believes Hacking Team offered the app to customers, but there is no evidence. The app on Google Play downloaded between 10 and 50 times before it was removed by Google. The developer of the app on the Play Store has placed no other apps in the App Store Google. Google Plus account by this developer also contains no further information except a link to a "testing" area of ​​the app on Google Play.

Wednesday, 27 May 2015

Avast: Virus Scanner To Scan HTTPS Traffic



As more Internet traffic over SSL is encrypted, it is important that virus scanners can inspect HTTPS traffic, even though they have here a "man-in-the-Middle" with self-signed certificates to perform. That leaves anti-virus company Avast know, the free virus scanner is one of the most widely used anti-virus programs in the world.

An SSL certificate is used to encrypt traffic between websites and visitors. Traffic is theoretically no longer available by third parties. To still analyze whether the traffic is free of malware or other malicious code, Avast installs on computers a self signed certificate that is accepted by the browser. Normally give self-signed certificates in the browser a warning, because the publisher is not trusted. To solve this Avast adds itself as a certificate authority to the browser so that certificate or trust.

Once the browser a SSL connection setup the virus will own this certificate to use that now causes no warning. This way you will find there is actually a man-in-the-Middle (MITM) attack place. According to Avast this is necessary to scan the traffic.There is also a difference with traditional MITM attacks, said the virus fighter. "The" man in the middle "that we use is on the same computer as the browser and uses the same Internet connection."

Avast also announced that it generates a different private key for each certificate. A user would with its own installation therefore can not intercept traffic from other Avast users. Yet recently proposed a security researcher that the process of virus scanners, including those from Avast, safety HTTPS undermine.

Adware Disguises Himself As AdBlocker Plus Browser


Adblock Plus is a popular browser extension that must stop ads, but now researchers have discovered a form of adware that is just as Adblock Plus disguises in the browser. The adware refers to himself in the browser "AdBlocker" with the publisher AdBlocker and AdBlocker Plus logo.


Furthermore, it is also adapted to the installation date, so users do not immediately see the installed extension when sorting by date. Once the active adware makes all kinds of ads to view websites. In order to prevent the adware is easily noticed and removed which also makes use of single-rootkit elements, as discovered anti-virus company Malware Bytes .

For the installation, the use of a adware "LSP hijacker". LSP stands for Layered Service Provider and is a DLL that the Winsock API (Application Programming Interface) used to inject itself into the TCP / IP stack. Since it can intercept all traffic between the Internet and applications, filter and customize. According to analyst Pieter Arntz allows use of the rootkit components and LSP hijacker see that "potentially unwanted software" more and more like real malware starts to behave.

Wednesday, 20 May 2015

Digital Attacks On Oil Traders Without Malware


Researchers from the Spanish anti-virus company Panda Security discovered a digital attack on oil traders with no malware was used and the traders also were not the ultimate target. The attack starts with an executable file that looks like a PDF document.

In reality, it is a self-extracting archive file with several files, including various scripts, batch files and .exe files. Yet these files themselves are not malicious. "These are all legitimate applications that anyone can use," the researchers said that the threat of "The Phantom Menace" ( pdf call). The applications are created to store user names and passwords in the e-mailcient and browser in a text file and send it via FTP.

On the FTP server of the attackers, the researchers discovered more than 80,000 text files. It turned out to be files from ten companies in the oil sector. However, these companies were not the ultimate target. These are namely oil buyers. And especially oil buyers seeking special oil from the Nigerian city of Bonny. This oil is very popular because of its composition.In Nigeria holds the Nigerian National Petroleum Corporation (NNPC) on each transaction oil supervision.

Anyone who wants to sell in Nigeria oil must also be registered with the NNPC. Fraudsters operating in this market approaching traders and brokers and, for example offer a large amount of oil from Bonny at a very attractive rate. The potential buyer requests for documents that the product also exists. For this, several documents can be issued by the NNPC.

To use to inform the buyers on the scammers legitimate documents they captured at the previously attacked oil traders. Then the buyer will see this document and pay a deposit, for example, 50,000 to 100,000 dollars, but gets its oil never see.Eventually Panda Security was able to trace the possible culprit behind the attacks. The problem is that none of the attacked oil traders will report it, for fear of damage to reputation and the fact that they themselves have become a victim. This allows the police can not start investigation and the alleged perpetrator is still at large.

Infected Version Of PuTTY Steals Passwords


Cyber criminals are spreading on the Internet an infectious variant of the popular SSH client PuTTY, which is designed to steal passwords. PuTTY is a free open source terminal emulator application as a client for SSH, Telnet, rlogin, and raw TCP protocols can serve.

The now discovered version is not on the official PuTTY download site spreads, but via a hacked another page. The infected version would have been the end of 2013 and then already been distributed over the Internet. Recently, anti-virus company Symantec observed more infections. The infection starts with a user searching through a search engine to PuTTY.

Instead of choosing the official website, the user selects a hacked website. The hacked website sends the user several times and let him finally downloading an infected version. When the user logs in via the infected version on a system, the login information can be sent to the attacker. Users also are advised to check that they only download software from the official website of the supplier or developer.

Tuesday, 19 May 2015

Owner Hide My Ass Multimillionaire By Selling VPN Service


The Czech anti-virus company AVG has the VPN service Hide My Ass adopted , allowing the 26-year-old developer and owner multimillionaire has become. The sale has Jack Cator, the Briton who the VPN service a decade ago in one afternoon put together, earned 35 million euros.

In addition, AVG will pay another 17.5 million if the VPN service over the next year is able to achieve certain goals. Cator decided to develop the VPN service because he was at school some music and games sites could not visit. Through a VPN enabled him to reach those websites because first connection was made with another machine, where websites could then be visited.

The then 16-year-old Cator thought to be desired quality of existing VPN services and decided to build his own VPN solution, so let him across the BBC know. In just one afternoon he set Hide My Ass in each other, which was in ten years one of the leading VPN providers in the world, with 250,000 paying users. Despite the acquisition Cator will remain as director of Hide My Ass.