Showing posts with label Bitdefender. Show all posts
Showing posts with label Bitdefender. Show all posts

Wednesday, 5 July 2017

Test: Ten Tested Virus Scanners For MacOS



German test lab AV-Test has a new test virus put online, this time for anti-virus software for MacOS looked. The amount of new malware for MacOS is not commensurate with those for Windows. However, last year there was an increase in visible , of 819 new units in 2015 to 3033 in 2016.

Most infections MacOS is still doing for social engineering, in which users are tricked into installing malware, although some cases are known where attackers managed to add malware to legitimate programs. That there is little malware for MacOS in circulation is evident from the number of copies that malware-AV-Test used for the test. The lab works on Windows with tens of thousands of malware specimens. 184 specimens were used for the test with Mac malware.

Four products (Bitdefender, Intego, Symantec and Kaspersky Lab) were able to detect all malware instances. MacKeeper ends with a score of 85.9 percent down. Besides the detection was also the tax system looked when copying files. Then put Canimaan Software and MacKeeper down the best performance, followed by Kaspersky Lab and Symantec with one second difference. Intego slows the most systems. Finally, we looked at the false positives. In this case considers a virus if infected legitimate, clean files. During this test item was no virus in error.

Tuesday, 1 December 2015

Linux Ransomware Encrypts 3000 Websites



In recent weeks there have been the ransomware which it has provided encrypted hit 3,000 websites on Linux web servers. This places the Russian anti-virus company Doctor Web, which relies on weather data from Google. It is called ransomware Linux.encoder.

Attackers behind ransomware deliberately set WordPress websites and online stores using Magento. Through a still unknown vulnerability know the attackers to gain access to the Web server that hosts the website and then perform Linux.encoder.This ransomware, which additional duties require encrypts all kinds of files, and then asks one bitcoin, what with the current exchange rate is 349 euros. It is unknown how many webmasters have finally paid the ransom.

F-Secure reported in early November, about 36 people had paid, which at that time corresponded to an amount of 12,000 euros. Due to an error encrypted files can be decrypted without paying. The Romanian anti-virus company BitDefender has developed a free decryption tool for victims. From examination of the virus fighter shows that an early version of ransomware already was distributed on August 25 of this year and then seven people paid the ransom.

Wednesday, 11 November 2015

Servers Dozens Of Sites Encrypted By Ransomware Linux



The Linux ransomware which since last week to be warned is to encrypt the web servers of dozens of websites know. This is evident from the Google search results. The search engine indexes namely encrypted web servers, so says Mikko Hypponen at anti-virus firm F-Secure.

This involves both unpatched WordPress and Magento websites, including websites that are ready or put ever tested and forget. Through the vulnerabilities attackers can execute the ransomware on the Web server, which then encrypts files and leaves a text file with instructions. This text file is indexed by Google. To decrypt prompted an amount of 1 bitcoin files, which with the current exchange rate corresponds to 333 euros.

Victims, however, do not have to pay, because the Romanian antivirus company BitDefender discovered a flaw in the way the ransomware encrypts files, making it possible to free decrypt the files. A researcher at F-Secure estimates the criminals in one month have earned almost 12,000 euros. That would mean that 36 people have paid.

Tuesday, 10 November 2015

Researchers Crack Linux Ransomware By Design Flaw


Researcher managed to crack the Linux.Encoder-ransomware for Linux so that victims without paying their files to recover. The ransomware was last week announced by the anti-virus company Doctor Web. At the time, it was unknown how the ransomware spreading.

It was known that it was mostly web servers that were infected. Now the Romanian anti-virus company said Bitdefender attackers use a vulnerability in the popular content management system magento to access servers. Then they install the ransomware, which looks a lot like Windows ransomware. Like Windows-based ransomware encrypts Linux.Encoder files with AES. The symmetric key is then encrypted with an asymmetric encryption algorithm (RSA).

When designing the ransomare the creators have made ​​a big mistake, allowing researchers Bitdefender can identify the AES key without that first with the RSA private key must be decrypted. The ransomware does not use any keys and initialisation vectors for encryption, but leads these two pieces of information on a specific feature in combination with the time of the encryption. This information is easily retrieved and, according to the researchers, a major design flaw. They now have a tool(zip) has been developed which automatically encrypted files can decrypt.

Friday, 16 October 2015

Company Claims Nearly 1,000 New Mac Malware In 2015


An American security company claims it has this year found nearly 1,000 instances of malware for Mac OS X, five times as many as in 2010, 2011, 2012, 2013 and 2014 combined. However, the report from Bit9 and Carbon Black does not know what malware is involved.

Also not reported how it is contracted, how widespread the malware found and whether for instance, there are trails. As a result, it is unclear how large the actual threat is now. The study (pdf) researchers from Bit9 and Carbon Black gathered for a period of 10 weeks in all sorts of places malware specimens, such as blacklists, Cont Agio malware dump, open source and security incidents. In total more than 1400 unique OS X malware specimens were found. 180 examples date from 2010 to 2014. 948 copies were for the first time this year have appeared.

"The number of copies in this analysis is large enough that even the most optimistic Mac OS X user realizes that security is now of paramount importance," said the researchers. They expect the number of Mac malware attacks will increase in the coming months. How that will take place just is not reported. Recently, anti-virus firm BitDefender said that nearly half of all Mac malware is actually adware.

Mac users run mainly via adware bundled software, for example through pop-ups and ads on websites that say that something is wrong may be using the computer or the performance improved. Bitdefender recommends Mac users also to be selective about which programs they download and install. It is also advised to only download apps from the official Mac App Store. Researchers at Carbon Black advised Mac users to install a virus scanner, with free alternatives to Avast, Malwarebytes, and Sophos highlights. Users who wonder if they are infected may be advised the Dynamic Hijack Scanner or Knock Knock use.

Tuesday, 13 October 2015

Anti-Virus Company: Nearly Half Of Mac Threats Consist Of Adware


Almost half of the threats for Mac OS X falls into the category of adware, says the Romanian antivirus company BitDefender on the basis of its own research. The virus fighter analyzed the Mac malware that appeared in the first six months of this year.

Of all Mac malware found in the United States showed 46% can be classified as adware. In Germany, Denmark and Romania was about 45%, 61% and 58% respectively. However, no absolute numbers, so it is unclear how many copies are involved. Once active adware can display unwanted pop-ups and ads and adjust search results.

Mac users run mainly via adware bundled software, for example through pop-ups and ads on websites that say that something is wrong may be using the computer or the performance improved. Bitdefender recommends Mac users also to be selective about which programs they download and install. It is also advised to read the terms and conditions of the software, install a AdBlocker and Mac OS X to keep up-to-date. Earlier it was even called that adware is the main threat for Mac users.

Thursday, 10 September 2015

Malware On Google Play Subscribe Victims On SMS Service



Google Play researchers have discovered Android malware that tries to subscribe victims of costly SMS services. The malware was late last year noted for the first time, but was then distributed only through unofficial marketplace. Now the malware surfaced in Google Play.

Once the malware is actively attempting to subscribe users to costly SMS services. These services require that a CAPTCHA code solved. To this end the malware using Antigate.com, an online service where people CAPTCHA codes solve fee.The code is then dissolved the victim subscribed to the SMS service.

The malware was found to be hiding in different apps. Two of these apps were downloaded between 100,000 and 500,000 times, reports the Romanian antivirus company BitDefender. In total there are seven apps, of which several versions are always placed in Google Play. Google would now be informed of the malicious apps.

Sunday, 2 August 2015

Hackers Put Credentials BitDefender Clients Online



Hackers have penetrated systems of the antivirus company BitDefender and there have been captured under other login details of customers. According to the burglars appeared usernames and passwords are stored in simple text.

He calls himself DetoxRansome and had managed to seize confidential identification data of users present on the firm's server. It is unfortunate that hackers can touch a security company but that's not all ... expect the best!

The stolen data is put online by hackers. Across Forbes confirmed BitDefender to a number of client user names and passwords were stolen. The Romanian antivirus company said that the servers are not cracked, but the hackers used a vulnerability in an application within its cloud service, which data could be intercepted. Ultimately, less than one percent of customers are exposed to hackers, says BitDefender. The problem should now be resolved and affected customers received the message with the request to change their password.

On the underground Web, DetoxRansome hacker is selling data for Bitcoins 8 and clarifies that the vulnerability stems Amazon Elastic Web service that often has problems with SSL. To err is human, and it is via a sniffing technique that he could compromise private data, as explained Hack Film . In short, no zero day vulnerability is involved.


Contrary to what the BitDefender notify the hackers that they are in control of two servers that the company uses to provide its cloud services. They used to intercept logins, so they told Forbes. On his BitDefender servers would use Amazon Elastic Web. Users of this service are responsible for implementing security on communications between server and client.


Approximately 250 customers data is put online. The hackers decided to proceed to publication as BitDefender's ransom did not pay for the information. The company was then embarrassments since the conscious data stored in simple text, and so were not encrypted. Therefore could potentially be easily abuse of the stolen data. Whether that actually happened is not known. BitDefender also did not let go or it's going to work with encryption in the future.

Wednesday, 24 June 2015

Kodi Media Center (XBMC) Vulnerable To MITM Attacks



The popular media center Kodi, formerly known as XBMC, contains a vulnerability which attackers between a user and the Internet are able to attack the system. Through Kodi allows users movies, music and other media, for example playback on their TV or sound system.

The software contains a collection of add-ons that allow users popular services like YouTube, Grooveshark and Dropbox can access. Each time Kodi is started watching the software or pre-installed add-ons updates. In the case of a new version is automatically downloaded and installed. The update check takes place entirely over HTTP without encryption, as discovered the Romanian antivirus company BitDefender .

The software asks during the update check to a MD5 hash for the last addons.xml file, which contains information about add-ons. An attacker can send back, in this case a random MD5 hash, which does not have to correspond to the file that is then presented. The attacker could send a specially prepared following addons.xml file indicating that a new version for a particular add-on is available. Then, the attacker must send the correct MD5 hash for his malicious add-on. Once Kodi this add-on installs the malicious Python code running in the add-on to the system.

For their demonstration, the researchers succeeded to download an executable file and place it in the startup directory of the system. It should be noted that an attacker the same privileges as the user running Kodi. Eventually they managed also to steal login details for YouTube and could Dropbox add-on change, so when starting or synchronizing files all content from the local Dropbox directory to a specified FTP server was sent. The Kodi developers are informed by Bitdefender and working on an update. When that appears is unknown.

Thursday, 28 May 2015

Android Ransomware Not Give Paying User Penalty


Last week, more than 15,000 e-mails are sent with Android ransomware that occurs when a security update for Adobe Flash Player. The messages contain little text, except that the enclosed APK file, "Check Updates.apk" is an update to Flash Player.

In reality, it is ransomware that locks the device and a warning from the FBI shows. According to the warning, the user would have viewed pornographic websites. To unlock the device must be an amount of $ 500 to be paid. If the user attempts to unlock the device, the amount is increased to $ 1,500, reports the Romanian antivirus company BitDefender .

According to the Spanish security company S21sec ransomware makers find new ways to spread their creations. Currently used mainly social engineering, but new capabilities are added continuously, according to the IT security officer. Users also are advised to install APK files from untrusted sources and email filtering with MOT attachments.

Wednesday, 6 May 2015

Expert: Mac Malware Invisible By Lack Of Anti-Virus


Because Mac users install anti-virus software is difficult for anti-virus companies to estimate how big the problem of Mac malware is actually. That says Bogdan Botezatu, an analyst of the Romanian antivirus company BitDefender. Previously, Apple had yet know that users could install a virus, but now it no longer does so.

"Apple is promoting these products as virus-free. They say you do not need a virus scanner, because they know that people hate anti-virus software. The tools often slow down your computer, so they themselves will not promote," Botezatu said front Digital Trends . Mac OS X, according to the analyst to deal with more serious vulnerabilities than all the different Windows versions added. Because Microsoft has always been attacked over the years would have learned to respond quickly to security threats.

Having vulnerabilities still says nothing about attacks on the platform. However, when it comes to Mac computers is missing important information to say something about this, the analyst noted. "The absence of virus scanners on Mac OS X hides the reality, because the malware is not reported. We know it happens on Windows because it is visible to us here, but with Mac OS X, there is often no anti-virus to give something back report. "

In addition, Mac users would not know that their computer is infected, because most malware these days is hardly noticeable."It's the same as with the PC. Hackers realized how silent they are, the longer they go unnoticed. Modern Mac and Windows malware slows down your computer, unless the bitcoin-miners are," said Botezatu. The large market share of Windows would, according to the analyst still ensure that cyber criminals are targeting this platform.

Saturday, 7 March 2015

Ransomware Spreads Via Malicious Help Files


Cyber ​​criminals have been distributed in the Netherlands emails containing malicious help files that contain the CryptoWall-ransomware. Before that warns the Romanian antivirus company BitDefender. The e-mails contain a .chm file as an attachment. This stands for Microsoft Compressed HTML Help, and is the successor to the help files in Windows.

Chm files are highly interactive and can contain various technologies, such as JavaScript. This makes it possible to automatically download a file when the .chm file is opened. According to analyst Catalin Cosoi is a logical choice for cybercriminals to use chm files. "The less user interactions, the greater the risk of infection." In addition, users will these files may not be regarded as suspect.

The e-mails in question occur among others as e-mail messages from a fax machine. Once opened the ransomware can encrypt files on the computer and then asks for a certain amount of users to decrypt them. According Bitdefender however the attackers with this spam run would have to provide companies and attempting to infiltrate corporate networks. Over the past several months, let companies know that they are the victim of ransomware became.

Saturday, 28 February 2015

Aggressive Android Adware discovered on Google Play


Researchers from the Romanian antivirus company Bitdefender have on Google Play different Android apps discovered containing aggressive adware. Using apps after installation on the device a different name, which may make it more difficult for users to find and remove them.

Once active show the apps, such as "What is my IP?", All kinds of so-called warnings to install subscribing users on expensive telephone or make additional apps that contain more ads. One possible reason that the apps Google checkout managed to avoid is that the URL that sends users does not point to malicious APK files. The URL allows browsers to open a website that users from one ad to another forward.


For example, users in each search, clicked URL or open Facebook link to a special page redirected showing various location-specific ads. "Aggressive adware has in recent years developed further in-app ads and adware software development kits, to browser redirects and turning legitimate apps under similar names," said analyst Liviu Arsene. Some of the apps are as Bitdefender still be found on Google Play.

Hashes:

f2d57300d5f991dbc965ac092d5f4301 – com.alm.alm
c1d7afa5c4eb0b8e3c0292eadf98771e – com.tr.dum.dum
16967bea7d3dcb08c12220925ef6f030 – com.est.hk
cb9d3ff0eea162dd602eefe7b08ded49 – com.est.esteban
dbc99ba3241f943cc9e58870f0e40b34 – com.brer.brer
51bc232de9af3f34a58d824da86a70bc – com.tr.ipp
996c4a1525729466d87edf85cbbdf5de – com.who.myip.detect
6f37bd3c286440e37103ee8b67aca7d6 – com.tf.fed
47b863625a8022399247fc92c4d5d178 – com.esc.escd
e1ccb51569635415e66af16cbdd94ddc – com.esc.escde