Showing posts with label CERT. Show all posts
Showing posts with label CERT. Show all posts

Monday, 5 October 2015

McAfee Receives Award For Research Into Botnet


Anti-virus company McAfee has at the Virus Bulletin conference in Prague received an award for research into a botnet which was in collaboration with the Dutch police shut. The botnet, which Beebone, VObfus or AAEH was called, was a polymorphic botnet.


The malware that caused computers part of the botnet had been active since 2009 and spread via infected USB sticks and social engineering. In early April of this year, the botnet was the High Tech Crime Team (THTC) of the Dutch police, the FBI, Europol and security Intel Security, Kaspersky Lab and Shadow Server taken off the air.

To disable the botnet domains were all registered and seized that used the malware to communicate with infected computers. Then the investigating authorities showed these areas to the servers of Internet providers and computer emergency response teams (CERTs) by pointing all over the world, a process also known as "sink holes" is mentioned.Research showed that the malware had infected 12 000 computers.

According to McAfee cooperation between law enforcement agencies and security companies was essential to make the botnet from the air. The anti-virus company wrote a technical report (pdf) on the malware and operation of the botnet.Previously received McAfee last week at the Virus Bulletin conference Peter Szor Award. An annual prize for the best security research named after the anti-virus pioneer deceased in 2013.

Szor began twenty years ago with the analysis of malware and in 2005 wrote the book "The Art of Computer Virus Research and Defense. He worked for Symantec and F-Secure, before he went to work in 2011 at McAfee. In 2013 died he unexpectedly. "This kind of research makes everyone safer, as did the survey conducted late Peter Szor," said Martijn Grooten of Virus Bulletin.

Wednesday, 23 September 2015

Swiss Government Warns Of Contaminated Ads


The Computer Emergency Response Team (CERT) of the Swiss government has warned Internet users to infected ads that tried to install a Trojan horse. The ads were distributed through a popular Swiss ad network was hacked.

The ads were equipped with malicious code that abuse of known vulnerabilities in Internet Explorer, Firefox, made Java or Adobe Flash Player. In case users this software were not up to date and had a German or French institution, the Gozi Trojan was installed. This is a Trojan specifically designed to steal money from online bank accounts. The version that was spreading through the ads focused on five Swiss and two Thai sofas.

According to the Swiss CERT are potentially hundreds of thousands of Internet users become infected through contaminated ads. Last Friday, the owner of the botnet suddenly decided to remove the malware. All the infected computers were instructed to uninstall the Trojan horse. The reason is unclear, according to the CERT. The government organization thinks the botnet administrator may have earned enough money or that he saw the CERT operation had been discovered and therefore decided to disable the botnet.

Sunday, 12 April 2015

Beebone Malware: FBI Praises Cooperation With Dutch Cyber Cops


The FBI is proud to work with the High Tech Crime Team (THTC) of the Dutch police that this week along a botnet pulled off the air. It was a joint operation of the THTC, the FBI, Europol and various security companies was against the malware, which in the press releases of the various investigative services Beebone or AAEH was mentioned.

However, the malware also known as Vobfus and Changeup, Symantec, so let know . It is a worm that first appeared in 2009 and spread through the Autorun feature of Windows. A year later, the worm used the LNK vulnerability allowing the Stuxnet worm spread knew. There were also social engineering used by Changeup.

Working of Beebone Malware
On infected USB drives and network folders worm placed a copy of itself with the names Porn.exe, Sexy.exe, Passwords.exe and Secret.exe and created the executable files with the names of all existing files. These files have a folder icon, so it seemed like it was a folder. Since Windows file extensions by default does not show users could thereby unintentionally activate the malware.

Additional malware

Changeup active once installed all sorts of malware, including malware that tried Internet banking data and passwords to steal, as well as fake virus scanners and ransomware, according to the FBI. The US investigation service went to court with a request to take up 100 domain names that use the botnet to communicate with infected computers. Something the judge gave permission. Then the investigative services were these domains to the servers of Internet providers and Computer Emergency Response Teams (CERTs) of views on the world.

"Botnets as Beebone have made ​​all over the world victims, which shows why a joint approach to global investigative services with the private sector is so important. The FBI is proud to cooperate in the fight against botnets with our partners in the European Cybercrime Centre of Europol, the Joint Action Cybercrime Task Force (J-CAT) and the Dutch High Tech Crime Team, " said FBI Assistant Director Joseph Demarest.