Showing posts with label Exploitkit. Show all posts
Showing posts with label Exploitkit. Show all posts

Friday, 12 February 2016

Ads On Skype Spreading Ransomware



Cyber Criminals have managed to show ads to Skype users who were trying to infect computers with ransomware, says anti-virus firm F-Secure. Although the ads appeared within Skype, does not mean that the browser is not open to advertising.


In the case of observed infected ads which showed the browser unnoticed load a page with the Angler-exploitkit. This exploitkit uses known vulnerabilities in Adobe Flash Player to infect computers with malware. Users who had not patched their Flash Player could become so infected with the Tesla Crypt-ransomware. Like other ransomware encrypts Tesla Crypt sorts files for ransom. The ads on Skype came from the AppNexus-advertising platform, which in the past often for the spread of infectious advertisements used. Meanwhile, the offending ads are no longer displayed.

Tuesday, 29 September 2015

Infected Ads On YouPorn And Pornhub


After xHamster are also on the popular porn site Pornhub and YouPorn contaminated ads have appeared that tried to infect visitors with malware, says anti-malware company Malwarebytes. The websites get together 800 million visitors per month.

Pornhub is according to Alexa on the 64th spot of most visited websites on the internet. YouPorn is at the 161st place back. The ads came from the ExoClick ad network. The ads sent visitors without being noticed this through to a website with the Angler-exploitkit. This exploitkit uses known vulnerabilities include Adobe Flash Player and Internet Explorer to install malware. For whatever it's malware was not disclosed.

After Geek Mind, publisher Pornhub and YouPorn, discovered the ad network ads were off the infected ads. The company also states that all third-party advertising on "continuous basis" audit to malvertising, as mentioned infected ads preventable. Recently, it was also for the third time in a year hit by xHamster. This website receives nearly half a billion visitors monthly.

Tuesday, 15 September 2015

Infected Advertisements On EBay Weeks Remain Unnoticed


Cyber criminals are recent weeks managed to commonly-used ad networks like DoubleClick and AppNexus a large number of infected ads on popular websites such as eBay, Drudge Report and Answers.com get without that were noticed initially.

Which claims anti-malware company Malwarebytes. The attackers pretended to be legitimate advertisers and offered their ads through various real-time auctions to. Several ad networks allow advertisers bidding through auctions on the available ad space. To convincingly come across criminals used the companies that were registered with the US Chamber of Commerce, whose websites were sometimes recorded years ago.

According to analyst Jerome Segura was enough to fool most ad networks. The ads themselves were not provided with malware, but visitors were redirected to a page via an abbreviated URL that contained the Angler-exploitkit. This exploitkit uses vulnerabilities in Flash Player, among others. In the case the attack was successful Bedep the Trojan was installed on computers.

This Trojan can install additional malware on the computers, as malware, ad fraud and ransomware. The ads appeared on the UK eBay site, which receives 139 million monthly visitors and Drudgereport.com, which receives 61 million monthly visitors. All affected websites monthly gain of about 500 million. In total, the infected ads would have turned nearly three weeks undisturbed. Internet users whose software is up to date ran no risk in this attack.

Wednesday, 9 September 2015

Website Headache Centers New Twitter Malware



At several websites attackers have posted malicious code that attempt to infect visitors with malware. It is the Society's website of Dutch Headache Centers and New Twitter, says security researcher Yonathan Klijnsma via Twitter.

In the case of New Twitter that Twitter has more than 10,000 followers, the added code points to the Angler-exploitkit. This exploitkit uses known vulnerabilities, including Adobe Flash Player. What malware is being spread Klijnsma do not know by exploitkit. Angler among other things used to install the Bedep Trojan on unpatched computers.

This Trojan may download additional malware onto the computer and use the system for various forms of cyber crime, such as click and advertising fraud. Klijnsma, also a researcher at the Delft security firm Fox-IT, warned in recent weeks regularly for hacked websites which malware spread. According to the researcher, there is a campaign in which criminals hack into websites and provide malicious code.

Monday, 13 July 2015

Ads Malware Via Flash Player Flaw


Vulnerability in Adobe Flash Player last Wednesday by Adobe was patched is now attacked by infected ads. It is the first flaw in Flash Player that were found in the stolen data of the Italian Hacking Team.

According to anti-virus firm Malwarebytes there since the discovery of this vulnerability an increase in attacks on Internet users through so-called drive-by downloads. In this case, Internet users become infected through unpatched software, which only visiting a malicious or hacked website or see getting an infected ad is sufficient. One reason for the increase in the number of attacks is that many users their Flash Player version have not yet patched, said analyst Jerome Segura.

Ads

Meanwhile, the leak will also be attacked by infected ads. The way this is done is remarkable, says Segura. This primarily concerns a Flash ad that loads another Flash file containing the exploit for the Flash Player leak. The use of contaminated advertentes is much more common, but in most cases advertisements pointing to another website that the user attempts to attack.

The infected ad came from the DirectRev ad network and offered directly from the ad network server. In case the attack is successful, the Kovter malware is installed. Kovter can use computers to commit fraud ad (click fraud) or install ransomware.The malware was recently still in the news because the vulnerable versions of Flash Player on infected computers patches, to keep other malware on the computer outdoors.

Thursday, 18 June 2015

Adobe Flash Player Popular With Cyber Criminals


Despite an automatic update function Adobe Flash Player continues to be very popular with cyber criminals, who last week patched vulnerability now use the browser plug-in for the spread of ransomware. Reported that the Japanese anti-virus company Trend Micro .

Although the patch is available and can be installed automatically by Flash Player, shows that particularly American, British and Canadian users who did not. In Belgium and Germany are perceived attacks via the vulnerability. It has become a trend in which after the appearance of a Flash Player update cyber criminals develop an exploit to attack users who have not installed the update.

"Many people are still running the previous version, meaning that a large number of users at risk," said analyst Peter Pi. The exploit that uses the vulnerability in Flash Player has been added to the Magnitude Exploitkit. Once unpatched users land on a malicious or hacked page or see an ad that points to this exploitkit, they may become infected with undetected malware.

In this case CryptoWall 3.0-ransomware is installed. These kinds of ransomware encrypts files on the computer and then asks for a certain amount to decrypt the files. Recently warned ( pdf ) also anti-virus company McAfee mean it had observed a sharp increase in the number of attacks in the first quarter of this year via Flash Player vulnerabilities. Adobe Flash Player users would now be using version 18.0.0.160, which through this page can be checked.

Friday, 8 May 2015

Infected Ads On Dozens Of Porn Sites Discovered


The past week has been on dozens of porn sites infectious ad appeared that visitors via a known vulnerability in Adobe Flash Player tries to infect with malware. Among the stricken porn sites, which together have 250 million visitors are drtuber and nuvid the largest.

Unlike many infectious ads that visitors unnoticed forward to another site, the ad used to contain pornography directly exploitable, which makes abuse of the vulnerability in Adobe Flash Player, as reported anti-virus company Malwarebytes.The ad would be distributed through an advertiser on the AdXpansion ad network. In case the attack success are different infected files placed on your computer. Visitors to porn sites whose Adobe Flash Player up-to-date are not at risk.

Wednesday, 29 April 2015

Weather Infected Ads On Porn xHamster


On the popular porn xHamster again infected ads have appeared that attempt to infect visitors with malware. In late January it was even hit on the porn site, which according to Alexa is on the 68th place of most visited sites on the Internet and gets 514 million visitors monthly.

The ads direct visitors unnoticed to another page where the Angler Exploitkit runs. This page checks to see if the visitor uses the virus from Kaspersky Lab or Norton. If this is not the case, then it is decided to attack the user further. The Angler Exploitkit makes abuse of vulnerabilities in Internet Explorer, Java, Silverlight and Adobe Flash Player. Anti-virus firm Malwarebytes suggests that only an old vulnerability in Internet Explorer is used in the attack.

Is the attack successful, is the Bedep malware installed. The same malware that also the end of January on the website was spread via infected ads. Bedep making computers part of a botnet and can then install additional malware. Once active Bedep used infected computers to commit fraud advertisement. Additionally silently loads the Magnitude Exploitkit, which also makes abuse of vulnerabilities, provide users with additional malware can become infected.

Saturday, 18 April 2015

Weather Infected Ads Distributed By Google DoubleClick


Attackers twice in a short time managed to spread infectious ads through Google's DoubleClick. The attack, which has now become known was conducted through a company called Merchenta, which offers an advertising platform and direct ties with Google DoubleClick. Through this platform, the company would be US only deliver 28 billion monthly ad impressions.

The attackers did in this case as an advertiser and infiltrated the platform through a third party, says anti-virus company Malwarebytes. In addition, they managed to get the infected ad on the advertising platform Merchenta, after which it was transferred to the channels of DoubleClick. Contaminated ad within minutes would have had a 95% coverage in the US, Europe and Britain, which ran a large number of people risk, says Malwarebytes.

The virus fighter notes that DoubleClick is not directly responsible for loading the infected ad, but it starts with the chain of trust with the publisher, which has little control over the transactions that take place. The ad in question was using a well-known and already patched vulnerability in Adobe Flash Player to infect computers with malware. At the time of the attack, the exploit that abuse of the leak was detected by any of the virus scanner.

It was the same exploit that was recently used in another attack campaign, which contaminated ads include on the website of the Huffington Post published. The account of the attackers was lifted according Merchenta on 10 April. Two days earlier warned the Delft security firm Fox-IT for another attack that took place around the same time via DoubleClick. However, it has been used a different exploitkit for infecting unpatched Internet users.

Friday, 3 April 2015

WordPress Sites Lead To Infectious Pirate Bay Clone


Researchers at Malwarebytes have different hacked WordPress sites discovered that send visitors unnoticed into a clone of the popular torrent site The Pirate Bay. Since then attempts to spread malware in Adobe Flash Player through a recently patched leak.

The website has been set up through "The Open Bay Project", an initiative that allows anyone with minimal technical knowledge can make a "copy" of the Pirate Bay online. The website features the Nuclear-exploitkit. This exploitkit abuse of a vulnerability in Flash Player that Adobe was patched by the end of January. In the case of visitors to the WordPress sites miss this update, they can become infected by a banking Trojan.

This is a Trojan horse that attempts to steal money from online bank accounts. WordPress sites are also not up-to-date and prove an outdated version of the rotating RevSlider plugin. Recently it was announced that there are thousands of WordPress sites using a vulnerable version of this plug-in have been hacked.

Friday, 27 March 2015

Thousands Hacked WordPress Sites Spread Malware


In recent weeks, thousands of hacked WordPress sites which are then used to distribute malware. It also involves several Dutch websites including nummeriban.nl , hoofdpijncentra.nl and the website of Dries Roelvink. That leaves the Dutch security researcher Yonathan Klijnsma today know.

Fiesta Exploit Kit Gate
On the hacked WordPress sites is an iframe placed visitors, without this, have, to a exploitkit forward. This exploitkit uses known vulnerabilities in Adobe Flash Player, Adobe Reader and Java to infect users. However, if users use the latest version of these plug-ins they run no risk. "There are thousands of websites that contain this iframe at this time. From the data I have is about 3,000 websites, but this is probably only a fraction" says Klijnsma.

In case the attack, there can be all kinds of malware installed successfully, including ransomware encrypts files that sorts to Trojan specifically designed to steal money from online bank accounts. According Klijnsma the WordPress sites hacked through a leak in the RevSlider plugin. This is a known vulnerability for which an update is available. Webmasters have not rolled out the update. Owners of a WordPress site then also be advised to both the content management system as installed plug-ins to keep up-to-date.

Thursday, 19 February 2015

Popular Porn RedTube Spread Malware


On the popular porn RedTube researchers have found malicious code that tried to infect visitors with malware. That leaves anti-virus company Malwarebytes know today. Unlike several other porn sites that for "drive-by downloads" were used, there were no infectious ads used in this case. The attackers had direct access to the code of the website.

The malicious code was executed inside an iframe and pointed to the Angler Exploitkit on another page. This exploitkit uses a recently patched vulnerability in Adobe Flash Player. In case users do not use the latest version of Flash Player, they can become infected with a Trojan horse. This malware steals personal information and installs browser helper objects showing ads. Some of these ads pointing again to other operating pages can infect your computer with malware so on.

RedTube leaves in front Malwarebytes know that last Sunday was attacked and the problem was resolved within a few hours.Meanwhile RedTube the malicious code would be removed . The porn is according to measurement agency Alexa on the 128th place of most visited websites on the internet. Earlier today, the anti-virus company warned that the website of chef Jamie Oliver malware spread . Also, this problem has now been resolved.

Hash:
1e0134d9b5b51d9ad233b0a2ecb7cf83

Wednesday, 18 February 2015

Vulnerability: "Website Chef Jamie Oliver Spreading Malware"


Attackers have managed to hack the website of the British chef Jamie Oliver and provide malicious code that attempts to infect visitors with malware. Researchers at anti-virus company Malwarebytes found on the website that visitors JavaScript invisible sends to a exploitkit on another hacked website. This makes exploitkit abuse leaks in Flash Player, Silverlight and Java.

These are vulnerabilities where all updates to be available. Users who are up-to-date are therefore not at risk. In case users are not up-to-date, it will install a Trojan horse, which is recognized by few virus scanners on VirusTotal. "Unlike most web exploits that we have seen recently, this is not the result of contaminated ads, but a well-hidden injection at the site itself,"says analyst Jerome Segura. He notes that the problem lies in the compromised JavaScript on the website.

It may be possible to go a legitimate script adapted or an entirely malicious script. The webmaster will also receive the advice to look for other signs of infection, then just remove the script in question or modify. "Usually the stolen credentials or a vulnerable plug-in allowing an attacker gets access to a server," said Segura. Oliver's website is on the 536ste place of most visited websites in Britain and would attract 10 million visitors each month.

Hash:
f93f39f39dc5162f9e310648022d6f40