Showing posts with label E-Mail Attachments. Show all posts
Showing posts with label E-Mail Attachments. Show all posts

Tuesday, 19 April 2016

Microsoft Warns Of E-mails With Attachments JavaScript


Microsoft has issued a warning to spam messages that contain a JavaScript file attached and try to infect your computer with malware, including Locky-ransomware. The JavaScript attachments are back wrapped in a rar or zip file, says Alden Pornasdoro Microsoft.

In addition to use JavaScript files cyber criminals also Office documents with malicious macros to spread ransomware. According to Microsoft can be rapidly infected a computer via a JavaScript file. "It is interesting to note that an Office attachment with malicious macros usually two or more clicks required to open the document. One click for the document, and another click to activate the macro. On the other hand, the JavaScript annex just one or two clicks to run, "Pornasdoro notes.

He adds that it is very unusual for people to send JavaScript files attached. Who receives such a file must therefore not open. Pornasdoro also advises organizations to enable AppLocker so dubious software can not be performed. In addition, administrators are advised to disable macros in Office programs.

Finland's F-Secure has advice given how the Windows Script Host can be disabled so that JavaScript files are no longer open.

Monday, 16 November 2015

Microsoft Removes Ransomware 24,000 Computers


Microsoft via the integrated removal tool in Windows this year of about 24 000 computers deleted ransomware. It is spread four ransomware families that spread via email attachments and drive-by downloads. To protect Windows users there is the MSRT.


This stands for Malicious Software Removal Tool. A built-in program that is updated every month with new signatures, mainly to detect active malware and remove. The MSRT is then carried out automatically on the system. This year there are already 29 new malware families added to the program, which in recent months was mainly focus on ransomware. This is because of the impact on victims and the number of infections. Since the removal tool is static and increasing numbers of new variants, Microsoft has this month decided to update the detection of different malware families.

Saturday, 7 November 2015

CryptoWall-Ransomware Ransom Increases To 700 Euro


There is a new version of CryptoWall-surfaced ransomware that encrypts file names, victims speaks in a derogatory way and the ransom amount has increased to 700 euro, so researchers at the forum Bleeping Computer discovered.

CryptoWall is a form of ransomware which kinds of files on the computer encrypts. For decrypting victims must then pay. The first variant was last May discovered. This release early victims still 500 for decryption. If victims do not paid this amount was increased to 1,000 euros a time. With CryptoWall 4.0 that figure has now 1400 euros.

The new version also stands out because not only the contents of files are encrypted, but the file names. This is probably done to frustrate victims and make it difficult to determine which files need to be restored, says Lawrence Abrams Bleeping Computer. Like previous versions, removes all CryptoWall 4.0 Volume Shadow copies, turn off System Restore and Windows Startup Repair. Also makes use of the computer, on the basis of operating system and processor, a unique identification number.

Another change in Crypto 4.0 is the text to see victims of an encrypted computer get. Namely, that it has acquired a derogatory tone. So victims are addressed as "Congratulations !!! You have become part of the great CryptoWall community."It is also assumed that victims do not understand the explanations about encryption. Next, the creators which CryptoWall is not malicious and that together with the victims make the Internet safe. How the new version spreads exactly is unknown, but previous versions used mainly e-mail attachments and unpatched software.

Wednesday, 30 September 2015

Developer Citadel Malware Sentenced To 4.5 Years In Prison


A developer of the Citadel malware, making more than 11 million computers were infected, was convicted in the United States to a term of 4.5 years. Citadel was specifically designed to steal money from bank accounts, but was also used to make other data booty.

That lets you know the US Department of Justice. However, it does not seem to be the developer who developed the first version of Citadel. In the statement of the Ministry is mainly spoken that now condemned man Citadel distributed and installed on computers. Citadel was a popular tool among cyber criminals to infect with internet users and steal all kinds of data. Worldwide, hundreds of botnets were active from which existed by Citadel-infected computers.

The computers became infected e-mail attachments and drive-by downloads. Besides using Citadel and managing a Citadel botnet was now the condemned man, a 22-year-old Russian, also accused of providing online help to improve Citadel. The Russian man worked from Russia, but could be when he was arrested in Spain. Citadel would have caused, according to the US Department of Justice more than $ 500 million in damages. In addition to his prison sentence, the man must also pay compensation of $ 322,000.

Wednesday, 12 August 2015

Great Spam Botnet Suddenly Disappeared From Radar



A spam botnet that was last year for a large portion of all spam messages containing malware responsible suddenly disappeared and never returned. It involves ASPROX botnet since 2008 became operational. Over the years there appeared many variations of the malware, which spread mainly through infected e-mail attachments. 80% of all e-mail malware was sent via the botnet.

For example, last year emails with voicemails, send confirmations of courier companies, airline tickets and coupons used to allow users to open the attachment piggybacked. Once the attachment is opened the computer is part of the botnet. At peak times knew the botnet 2 million sessions per week. The end of 2014 the botnet suddenly disappeared from the radar.However, a clear reason missing.

For example, there are no operations of investigative services took place and there are no indications that the botnet operators were arrested. Earlier this year discovered the Internet Storm Center all that the botnet was gone. Security company Palo Alto Networks confirms that the botnet was shut down in January. One possible reason is that the trustees have decided to regroup the botnet and re-deploy. Although the botnet is gone, there are still ASPROX infected "computers" that continue to send e-mails with malware.

Thursday, 6 August 2015

Fraudulent Invitation Includes Windows 10 Trojan


Cyber ​​criminals from all over the world seem to grasp the launch of Windows 10 to infect internet users with malware. Earlier this month, already widely English e-mails supposedly sent an installer for Windows 10 offered.

In reality, however, it was ransomware. Now, similar reports have surfaced in Brazil, whereby criminals in their email copied from the Microsoft website. The only addition is a link to a so-called "Windows 10 Installer" allows users to download the new OS. However, it is a VBE script hosted on Google Docs. After having opened the script installs a Trojan horse on the computer to copy keystrokes and opens a backdoor, reports anti-virus firm Kaspersky Lab .

Tuesday, 4 August 2015

American Town Pays Twice Ransom To Ransomware



A town in the US state of New York last year twice in a short time become a victim of ransomware. And twice it was decided to pay the ransom. It went together to the tune of $ 800. The infections were carried out in Ilion, which consists of 8,000 inhabitants.

The malware was spreading in both cases via e-mail attachments and encrypted both payroll and accounting systems, as the mayor opposite let NBC know. The infections, which occurred in January and May, were reported ( pdf ) by the Office of the State Comptroller. "These incidents are a wake-up call for local governments in the state," as late Comptroller Thomas DiNapoli know. "Although the amount of money was low and no vital information was leaked, this attack does show that lack of standard IT security taxpayers expense can hunt and functioning of cities and school districts can disrupt."

Canada

The problem of ransomware plays not only in the United States. Recently, also various systems of two Canadian towns hit by ransomware. When the infection in Mahone Bay were encrypted files back to 2007. An officer received an email supposedly a resume. The enclosed zip file appeared to be the CryptoWall-ransomware. Since the malware no important data encrypted was not proceeded to pay.

In the case of the infection in the Canadian Bridgewater would even talk of two ransomware specimens have been, namely CryptoWall and Crypto Locker, let the Chief Administrative Officer of the city across from CBC News to know. Also in this case would no important files are encrypted there and the ransom was not paid. To prevent a new infection is now controlled security against ransomware and henceforth be made ​​offline backups.

Sunday, 2 August 2015

Cisco Warns Of Emails With "Windows 10 Upgrade"


Cyber criminals have seized the launch of Windows 10 to distribute emails that attempt to infect surfers with ransomware. Before warns network giant Cisco . Windows 7 and Windows 8.1 users can upgrade to the new Windows version.

And cyber criminals now play in. The emails have the subject line "10 Free Windows Update" and seem to come from update@microsoft.com. The message that the recipient can upgrade to Windows 10. For this, the attached "installer" should be opened. In reality, the e-mail attachment "Win10installer.zip" a variant of the CTB Locker, a known form of ransomware that encrypts files on the computer for ransom.

Then users get 96 hours to pay the ransom in bitcoin, otherwise they lose their files. According to Cisco, the ransomware is now widely distributed. The networking giant also advises users to backup their files and keep these offline, so they can not be attacked by cyber criminals.

Hashes:

SHA256: ec33460954b211f3e65e0d8439b0401c33e104b44f09cae8d7127a2586e33df4 (zip)
aa763c87773c51b75a1e31b16b81dd0de4ff3b742cec79e63e924541ce6327dd (executable)

Friday, 31 July 2015

Infected Version TrueCrypt Used For Cyber Spying


A Russian website has years of an infected version of the popular encryption program TrueCrypt offered, which in reality turned out to be a Trojan horse that has been used for cyber-espionage. That leaves the Slovak anti-virus company ESET in a report published today ( pdf ) know.

The website was a truecryptrussia.ru offered in Russian translated version of TrueCrypt. Visitors who met but were offered an infected version specific criteria. What criteria were precisely known. Once installed on the system was also installed a backdoor that allows the attackers had full control over the computer. At least since June 2012 was offered via truecryptrussia.ru malware.

As a select number of victims were attacked in this way, could also backed by long time undetected, according to ESET. The TrueCrypt website also served as Command & Control domain. Communication between the attackers and infected computers ran through the website. Researchers also think the site was managed by the attackers and that it is not a hacked website.

Apart from the TrueCrypt website spread the malware, called Potao, also via e-mail attachments and USB sticks. This was done on a simple but effective way. The malware placed himself on the USB stick and made all other files invisible. In addition, the malware got the name of the USB stick and a disk icon. Users would have thought that it was a disk or shortcut while they opened the malware in reality.

Most targets of the malware were located in the Ukraine. It was among other things the Ukrainian government, the Ukrainian army and a major Ukrainian news agency. Members of the Russian and Ukrainian popular pyramid games were spied by the malware. So were victims of infectious TrueCrypt version mainly in Russia.

SHA1 hashes: Early Potao versions: 

8839D3E213717B88A06FFC48827929891A10059E
5C52996D9F68BA6FD0DA4982F238EC1D279A7F9D 
CE7F96B400ED51F7FAB465DEA26147984F2627BD 
D88C7C1E465BEA7BF7377C08FBA3AAF77CBF485F 
81EFB422ED2631C739CC690D0A9A5EAA07897531 
18DDCD41DCCFBBD904347EA75BC9413FF6DC8786 
E400E1DD983FD94E29345AABC77FADEB3F43C219 
EB86615F539E35A8D3E4838949382D09743502BF 
52E59CD4C864FBFC9902A144ED5E68C9DED45DEB 
642BE4B2A87B47E77814744D154094392E413AB1 

Debug versions: 

BA35EDC3143AD021BB2490A3EB7B50C06F2EA40B 
9D584DE2CCE6B654E62573938C2C824D7CC7D0EB 
73A4A6864EF68C810C7C699ED51B759CF1C4ADFB 
1B3437C06CF917920688B25DA0345749AA1A4A46 

Droppers with decoy documents: 

FBB399568E0A3B2E461A4EB3268ABDF07F3D5764 
4D5E0808A03A75BFE8202E3A6D2920EDDBFC7774 
BCC5A0CE0BCDFEA2FD1D64B5529EAC7309488273 
F8BCDAD02DA2E0223F45F15DA4FBAB053E73CF6E 
2CDD6AABB71FDB244BAA313EBBA13F06BCAD2612 
9BE3800B49E84E0C014852977557F21BCDE2A775 
4AC999A1C54AE6F54803023DC0FCF126CB77C854 
59C07E5D69181E6C3AFA7593E26D33383722D6C5 
E15834263F2A6CCAE07D106A71B99FE80A5F744B 
A62E69EF1E4F4D48E2920572B9176AEDB0EEB1C6 
900AD432B4CB2F2790FFEB0590B0A8348D9E60EB 
856802E0BD4A774CFFFE5134D249508D89DCDA58 
A655020D606CA180E056A5B2C2F72F94E985E9DB 
04DE076ACF5394375B8886868448F63F7E1B4DB9 31 

Droppers from postal websites:

94BBF39FFF09B3A62A583C7D45A00B2492102DD7 
F347DA9AAD52B717641AD3DD96925AB634CEB572 
A4D685FCA8AFE9885DB75282516006F5BC56C098 
CC9BDBE37CBAF0CC634076950FD32D9A377DE650 
B0413EA5C5951C57EA7201DB8BB1D8C5EF42AA1E 
0AE4E6E6FA1B1F8161A74525D4CB5A1808ABFAF4 
EC0563CDE3FFAFF424B97D7EB692847132344127 
639560488A75A9E3D35E4C0D9C4934295072DD89 

USB-spreaders:

850C9F3B14F895AAA97A85AE147F07C9770FB4C7 
BB0500A24853E404AD6CA708813F926B90B38468 
71A5DA3CCB4347FE785C6BFFF7B741AF80B76091 
7664C490160858EC8CFC8203F88D354AEA1CFE43 
92A459E759320447E1FA7B0E48328AB2C20B2C64 
BB7A089BAE3A4AF44FB9B053BB703239E03C036E 
DB966220463DB87C2C51C19303B3A20F4577D632 
37A3E77BFA6CA1AFBD0AF7661655815FB1D3DA83 
181E9BCA23484156CAE005F421629DA56B5CC6B5 
A96B3D31888D267D7488417AFE68671EB4F568BD 
224A07F002E8DFB3F2B615B3FA71166CF1A61B6D 
5D4724FBA02965916A15A50A6937CDB6AB609FDD 
8BE74605D90ED762310241828340900D4B502358 
5BE1AC1515DA2397A7C52A8B1DF384DD938FA714 
56F6AC6197CE9CC774F72DF948B414EED576B6C3 
F6F290A95D68373DA813782EF4723E39524D048B 
48904399F7726B9ADF7F28C07B0599717F741B8B 
791ECF11C04470E9EA881549AEBD1DDED3E4A5CA 
E2B2B2C8FB1996F3A4A4E3CEE09028437A5284AE 
5B30ECFD47988A77556FE6C0C0B950510052C91E 
4EE82934F24E348696F1C813C24797618286A70C 
B80A90B39FBA705F86676C5CC3E0DECA225D57FF 
971A69547C5BC9B711A3BB6F6F2C5E3A46BF7B29 
C1D8BE765ADCF76E5CCB2CF094191C0FEC4BF085 
2531F40A1D9E50793D04D245FD6185AAEBCC54F4

32 Other droppers:

D8837002A04F4C93CC3B857F6A42CED6C9F3B882 
BA5AD566A28D7712E0A64899D4675C06139F3FF0 
FF6F6DCBEDC24D22541013D2273C63B5F0F19FE9 
76DA7B4ABC9B711AB1EF87B97C61DD895E508232 
855CA024AFBA0DC09D336A0896318D5CC47F03A6 
12240271E928979AB2347C29B5599D6AC7CD6B8E 
A9CB079EF49CEE35BF68AC80534CBFB5FA443780 
1B278A1A5E109F32B526660087AEA99FB8D89403 
4332A5AD314616D9319C248D41C7D1A709124DB2 
5BEA9423DB6D0500920578C12CB127CBAFDD125E 

Plugins: 

2341139A0BC4BB80F5EFCE63A97AA9B5E818E79D 
8BD2C45DE1BA7A7FD27E43ABD35AE30E0D5E03BC 
54FEDCDB0D0F47453DD65373378D037844E813D0 
CC3ECFB822D09CBB37916D7087EB032C1EE81AEE 
F1C9BC7B1D3FD3D9D96ECDE3A46DFC3C33BBCD2B 
9654B6EA49B7FEC4F92683863D10C045764CCA86 
526C3263F63F9470D08C6BA23E68F030E76CAAF3 
E6D2EF05CEDCD4ABF1D8E3BCAF48B768EAC598D7 
CEBAB498E6FB1A324C84BA267A7BF5D9DF1CF264 
324B65C4291696D5C6C29B299C2849261F816A08 
C96C29252E24B3EEC5A21C29F7D9D30198F89232 
CDDDE7D44EFE12B7252EA300362CF5898BDC5013 
84A70CDC24B68207F015D6308FE5AD13DDABB771 

Fake TrueCrypt setup: 

82F48D7787BDE5B7DEC046CBEF99963EEEB821A7 
9666AF44FAFC37E074B79455D347C2801218D9EA 
C02878A69EFDE20F049BC380DAE10133C32E9CC9 
7FBABEA446206991945FB4586AEE93B61AF1B341 

Fake TrueCrypt extracted exe: 

DCBD43CFE2F490A569E1C3DD6BCA6546074FD2A1 
422B350371B3666A0BD0D56AEAAD5DEC6BD7C0D0 
88D703ADDB26ACB7FBE35EC04D7B1AA6DE982241 
86E3276B03F9B92B47D441BCFBB913C6C4263BFE

Thursday, 16 July 2015

Microsoft Windows Computers Check On Ransomware



Microsoft this month controlled hundreds of millions of Windows computers on the presence of ransomware. The audit took place over the Malicious Software Removal Tool (MSRT), the standard Windows virus removal tool which can detect the most prevalent families of malware and remove it.

The tool will be updated every month, so a number of new active malware families can be recognized. Simultaneously, the MSRT scans the computer also in these families. This month Microsoft released an update released so CryptoWall- and-Reveton ransomware on computers can be recognized. CryptoWall spread via email attachments, can be bundled with other malware, or downloaded by exploit kits. In May and June, Microsoft saw 300,000 computers that were infected with Crypto Wall. Once active, the ransomware encrypts all kinds of files and then demands amount to decrypt them. The infections were mainly in the United States and Brazil have been observed.

Microsoft warns users therefore not to open suspicious e-mail attachments. Also, according to the software giant does not guarantee that users after paying the ransom regain access to their files, or that the PC is again restored to its original state.Microsoft recommends paying the ransom than not also. In addition, users of an infected computer via File History recover their files.

The second ransomware family where Microsoft is focused on using the MSRT is Reveton. This family has often been the target of the virus removal tool. The ransomware locks computers and then shows a message that appears to come from the FBI or local police. According to the report, the user has committed a crime and should be a penalty to be paid. In this case, it only involves a warning. Users' files are not encrypted by Reveton.

Friday, 3 July 2015

Ransomware Distributed Through Google And Yandex Disk Drive



Cyber criminals have started a new campaign in which she websites of ministries and energy companies to recreate and then spread through Google Drive and Yandex Disk ransomware. It is a campaign of the Torrent Locker ransomware, which according to the Japanese anti-virus company Trend Micro focuses primarily on UK Internet users.

The attack begins with an email from British Gas, the Ministry of Interior or the Ministry of Justice seems to come. Unlike many other ransomware attacks the e-mail contains no attachment but a link that points to a convincing website. This site seems to be a copy of the original site of the power or ministry, stating that the user must enter a captcha, for example, to see his energy bill.

The captcha is probably the researchers used automated analysis to avoid anti-virus companies and researchers. Once the captcha is completed there will be downloaded a zip file. Were these zip files before storage services SendSpace, MediaFire and Copy.com stored now use the cyber criminals Disk Yandex and Google Drive.

For hosting the images used in the emails make criminals using hacked websites. Trend Micro discovered a total of 800 hacked domains where the images were stored or used as redirect the link in the e-mails functioned. 

Wednesday, 24 June 2015

FBI Warns CryptoWall-Ransomware



Both consumers and businesses in the last year lost millions because they were victims of CryptoWall-ransomware, reason for the FBI to issue a warning. CryptoWall a ransomware variant that encrypts files for ransom.

According to the US, it is the most active investigation service ransomware threat in the United States. In addition, the damage is often greater than the demanded ransom, which is between $ 200 and $ 10,000. Many victims would be faced with additional costs due to network security, taking countermeasures, productivity loss, legal fees, IT assistance and arranging credit monitoring for employees and customers.

Between April 2014 and June 2015, the FBI received 992 complaints about CryptoWall, in which victims indicated that they had lost more than $ 18 million. To avoid infection by ransomware advises the FBI to use a virus scanner and firewall, install pop-up blockers, making backups and to be skeptical. "Do not click on e-mails or attachments you do not recognize and avoid suspicious websites." The latter recommendation, however, does not account for the large number of hacked websites and infected ads on legitimate websites that cyber criminals use ransomware to spread.

Friday, 19 June 2015

PowerPoint Leak Used To Spread Malware


Vulnerability in PowerPoint, which was patched by Microsoft last year is now being actively used to infect activists in Tibet and Hong Kong with malware. The attacks are part of a larger campaign that is taking place for years. Remarkably, however, the use of PowerPoint leak.

Previously used the attackers vulnerabilities in Microsoft Office respectively in 2010 and 2012. The use of the PowerPoint leak would for the first time in two years the trend. For the dissemination of the PowerPoint files as well as e-mail attachments using links to Google Drive. To warn activists against the risk of email attachments campaign "was Detach from Attachments "starts. It is just recommended to use cloud storage for sharing files, such as Google Drive.


The fact that the attackers now use Google Drive, according to the investigators as possibly an indication that the attackers adapt accordingly. When users open the PowerPoint updates from Microsoft are not installed and the presentation they can with a remote access Trojan (RAT) become infected. The malware would be recognized by a few virus scanners.

In total, the researchers saw the Canadian CitizenLab five campaigns where the PowerPoint leak was deployed. To let users do not suspect they get to see a real presentation, while the malware is installed in the background. "The recycled content, low detection scanners and that users do not know that these files are malicious, ensure that these attacks are worrying," the researchers said.

Saturday, 13 June 2015

FBI: Be Alert For Fraud With Gift Cards


The FBI Internet users warned to auction sites where vouchers are offered. In recent years, the market for used "gift cards" has grown. However, this has also attracted criminals, warns the intelligence. So users of these sites may be affected by various types of scams involving gift cards are bought or sold.

Also, consumers are advised to be alert for messages on social media that offer vouchers or gift certificates that are too good to be true. The warning gives the FBI several tips that consumers can avoid becoming victims of fraud, such as only buying and selling parties with a good reputation and not providing the PIN until the transaction is completed.

Tuesday, 2 June 2015

1.25 Million Japanese Pension Data Stolen Via Virus


Japan Pension Service has warned today that data from 1.25 million Japanese are stolen after employees had open infected e-mail attachments. The attachments were found to contain a virus that names, addresses, birth dates and retirement numbers booty made.

The president of the Japan Pension Service made ​​during a conference apologized and said that all affected persons receive a new pension number. The organization has also removed all infected computers from the local network and employees from their work computers can no longer access the internet. What type of malware responsible for the attack, the president did not tell because of the ongoing investigation, reports the Japan Times .

Saturday, 30 May 2015

Macro-Malware Steals Thousands Of Documents From Companies


From late February to mid-March, assailants carried out a campaign macro malware was used to steal passwords and documents thousands of businesses. The attack began with an e-mail contained a Word document. In the document were hidden macros that, when activated by the receiver, malware installed.

Via this malware were then the credentials of workers and business documents stolen. According to anti-virus firm Kaspersky Lab , the attackers managed to steal a total of 10,000 documents of companies, mainly from Thailand and India, although Belgian companies were targeted. In addition, also found thousands of stolen credentials, coming from hundreds of infected computers. By looking at the stolen credentials, according to the virus fighter very clear that workers malware statements sent to each other, since the host names and internal applications were the same.

Friday, 29 May 2015

Malignant Macro Virus Bypasses Via MHTML Format



Cyber criminals have used a remarkable file to malicious macros invisible for virus scanners, as several researchers have discovered. The use of macros in Office documents has become a popular tactic to spread malware.

Macros are disabled by default in Office, but when users enable the macro can download and install malware. Recently discovered researcher Bart Blaze a spam campaign where there is a doc file with malicious macros added. In reality it turned out to be a Word MHTML file. According to researchers at security firm Trustwave beat the criminals after making the malicious macro as an MHTML file, to which then rename it to .doc or .xls. As a result the file will be opened by Microsoft Office.

When the spam campaign was detected showed that most virus scanners that are not detected. According to investigators, the criminals have malicious macros intentionally saved as MHTML file, to circumvent virus. An analysis of the MHTML file shows that the part of the evil macro via base64 encoded. In case users open the attachment and run the macro is a Trojan horse installed that is specifically designed to steal money from online bank accounts. Users also are advised to Microsoft Office can be configured to all macros are blocked.

Wednesday, 27 May 2015

E-mail Resumes And Internship Requests Infects Tills


Researchers have discovered a new variant of checkout malware that spreads via e-mail. The emails focus on companies and have different topics ranging from training requests and resumes, to ask if there are job vacancies. Attached is added to the e-mail a Word document. This document states that it is a secure document and the user macros must turn to see the content.

Once macros are enabled, the document will download the malware. This malware additional malware can be downloaded and installed. Through the malware that is first the attackers can determine what malware is then to be actively installed. It is then possible to install malware that targets POS systems that run on Windows. Several retail chains, especially in the US, using payment terminals that are connected to a Windows computer.

Once the computer is infected, the malware can intercept the data of credit cards and collect processed through the POS system. With the stolen payment card data can then be fraudulent. According to security firm FireEye shows that even attack cyber criminals engaged in random spam operations include cash and malware that can be used to infect some of their victims.

Sunday, 24 May 2015

Malware Steals 80,000 Euros Of Belgian Company


Cyber criminals are using malware 80,000 last month from a Belgian company managed to steal. The malware is aimed at companies that use the Isabel system for Internet banking. This week it was announced that several Belgian companies by the malware were affected.

One of these companies is metal processor Breetec. "My sister Sandra was paid to perform via Isabel," says director Koen Beckers opposite Het Belang van Limburg . "A few days later I saw on the account statement that was paid just over 80,000 at one time to a recipient in Dubai. It was remarkable, because that's a serious amount of money for our business, not ordinary. My sister showed that payment could not to have done. "

The malware where the Belgian companies by affected spreads via e-mail. Once running on the computer the malware puts a fraudulent transaction done. Isabel works with a card reader and PIN required to approve the transaction. The malware transaction can not perform themselves. After getting all of the transaction from the user's card reader, however, will squeak.The risk is that the user now enters his PIN as an automatism and so approves the transaction itself.

Meanwhile, the company that Isabel develops a warning posted on its website. It states that companies recognize an infection if they need to enter the PIN Isabel repeatedly while it is not expected, users are regularly logged and Isabel 6 should reboot and the computer becomes slow. To protect themselves against malware is recommended to disable macros in Microsoft Office, any unknown links or opening attachments, two that multiple persons transactions drafting and drawing and limiting the authority of users to a maximum amount which is sufficient for small daily payments.

Dell: Companies Should Block .Zip And .Exe Files


Companies that want to guard against ransomware would be wise to block .zip and .exe files so they can not get into e-mail to employees. Advising Dell SecureWorks . The advice stated in a comprehensive analysis of the Tesla Crypt-ransomware.

Like other ransomware is spreading Tesla Crypt via email and encrypts all kinds of files on the computer. It thereby ignores music formats like MP3 and video files like MP4. The ransom, which runs into the hundreds of dollars, via bitcoin, PaySafeCard and uKash be paid. In the case of Tesla Crypt Cisco recently unveiled a decryption utility that allows files to be decrypted without charge. Companies and organizations can, however, take several steps to protect themselves against possible infections.

Besides blocking executable files and zip archives is recommended operating system and browser plug-ins to keep up-to-date. Furthermore must permissions on shared network drives are controlled so that users with insufficient privileges Files can adapt. Finally, proposed a "software restriction policy", so as ransomware Tesla Crypt no changes in commonly used directories as "AppData" can make.