Showing posts with label Exploit Kits. Show all posts
Showing posts with label Exploit Kits. Show all posts

Monday, 12 March 2018

Recent Adobe Flash Player Vulnerability Leak Attacked Via Exploit Kits



A recently patched vulnerability in Adobe Flash Player is being actively attacked via exploit kits. This means that visiting a hacked website or seeing infected ads with a vulnerable Flash Player version is sufficient to infect with malware.

The vulnerability in question was resolved by Adobe on February 6 through an emergency patch . The vulnerability appeared to have been targeted against South Korean organizations since last November . Here Excel and Word files with embedded Flash objects were used. Now it appears that cyber criminals also have the exploit to use them via the web.

Flash Player was and still is the most popular target for exploit kits. Due to the absence of new exploits, and the fact that more and more browsers are phasing out the support of Flash Player, the effectiveness of exploit kits has declined sharply in the past period . According to researcher Kaffeine of the Malware do not need coffee blog , this is the first new Flash exploit that has been added to an exploit kit since July 2016 for a Flash leak. The new Flash exploit will be deployed via infected ads and will successfully install the Hermes ransomware. Users are therefore advised to upgrade to Flash Player version 28.0.0.161 or later, as the vulnerability has been corrected.

Tuesday, 10 November 2015

Adobe Flash Player Most Attacked Software


Adobe Flash Player is the most attacked software on the Internet, according to the US company Recorded Future, on the basis of its own research. For the study were analyzed for more than one hundred exploit kits. These are programs that use vulnerabilities in software to fully automated and without requiring users to install malware on computers this notice.

Of the 10 most attacked vulnerabilities exploitable by kits are there in Flash Player 8. The other two attacked vulnerabilities present in Internet Explorer and Microsoft Silverlight. Most popular among cybercriminals vulnerability involves a flaw that Adobe Flash Player on February 2 this year patched. The survey also shows that Java, which was a favorite target in the past, from the radar of cyber criminals has disappeared.

Where criminals often in the past for some time using old vulnerabilities made, dating all attacked vulnerabilities in the Top 10 this year. Recorded Future suggests that companies should decide themselves whether to install the continuous flow of Flash Player updates a viable is an option. Otherwise, click-to-play "be used as a solution to prevent attacks.

Monday, 2 November 2015

Flash Player And Internet Explorer Favorite Cyber Criminal



Internet users who do not update their software run mainly risk of becoming infected with malware if they use Adobe Flash Player and Microsoft Internet Explorer, according to figures from the Russian anti-virus firm Kaspersky Lab. This involves infections via so-called "drive-by downloads."

These cyber criminals use of exploit kits, which automatically infect Internet through unpatched vulnerabilities with malware.Most kits include attacks to exploit vulnerabilities in IE, Flash Player and Silverlight. It is in all of these cases vulnerabilities this year by Adobe and Microsoft were patched. We look at the attacked software, it is mainly Flash Player and Internet Explorer. Attacks on Java even took off. In recent exploit kits there are no exploits for Java included.

Kaspersky Lab also looked at attacks from "web resources" and where those resources are located. 

Tuesday, 11 August 2015

Ransomware Focuses On Russia And Ukraine


Makers of ransomware is not only aimed at English speakers, also should beware of Internet users in Russia and the Ukraine. Microsoft saw earlier this year named a ransomware variant appear Troldesh mainly in June was very active. The malware spreads through exploit kits, which infect Internet via, for example vulnerabilities in Adobe Flash Player.

Once active Troldesh encrypts files on the computer and then asks for a fee to decrypt them. Unlike other ransomware which victims must make the payment in bitcoin, the maker of Troldesh communicate via email with his victims. On the infected computer is left a text file with instructions. These instructions enable the victim via e-mail contact with the author should include.

In June, a researcher contacted the maker, then successfully on the ransom amount to barter . Eighty percent of infections Troldesh took place in Russia, followed by Ukraine with 9%. Microsoft advises victims to not pay the requested ransom for decryption, as there is no guarantee that the victims referred to regain access to their files.

Thursday, 16 July 2015

Microsoft Windows Computers Check On Ransomware



Microsoft this month controlled hundreds of millions of Windows computers on the presence of ransomware. The audit took place over the Malicious Software Removal Tool (MSRT), the standard Windows virus removal tool which can detect the most prevalent families of malware and remove it.

The tool will be updated every month, so a number of new active malware families can be recognized. Simultaneously, the MSRT scans the computer also in these families. This month Microsoft released an update released so CryptoWall- and-Reveton ransomware on computers can be recognized. CryptoWall spread via email attachments, can be bundled with other malware, or downloaded by exploit kits. In May and June, Microsoft saw 300,000 computers that were infected with Crypto Wall. Once active, the ransomware encrypts all kinds of files and then demands amount to decrypt them. The infections were mainly in the United States and Brazil have been observed.

Microsoft warns users therefore not to open suspicious e-mail attachments. Also, according to the software giant does not guarantee that users after paying the ransom regain access to their files, or that the PC is again restored to its original state.Microsoft recommends paying the ransom than not also. In addition, users of an infected computer via File History recover their files.

The second ransomware family where Microsoft is focused on using the MSRT is Reveton. This family has often been the target of the virus removal tool. The ransomware locks computers and then shows a message that appears to come from the FBI or local police. According to the report, the user has committed a crime and should be a penalty to be paid. In this case, it only involves a warning. Users' files are not encrypted by Reveton.

Friday, 9 January 2015

VirusTotal - "Online Virus Scanner Google Focuses On Java malware"




VirusTotal, an online virus scanner from Google last month quietly several improvements made ​​so researchers are better able to analyze Java malware. Via VirusTotal users can upload files and then to scan dozens of virus scanners.

In early December an update was rolled out to provide more information about suspicious Mac files and iOS apps. Silently was also improved the analysis of JAR files and Java .class files. The online virus scanner scanned the contents of these files already, but now also provides additional information, such as the used Java packages, the manifesto of the JAR-beam striking strings, file type distribution and timestamp metadata for files in the JAR file.



According to Emiliano Martinez VirusTotal is a lot of malware nowadays spread via exploits kits, of which a large portion of malicious JAR files uses to attack unpatched Java vulnerabilities. By expanding the virus Martinez hopes that researchers better this kind of threats can detect and analyze.