Showing posts with label Javascript Malware. Show all posts
Showing posts with label Javascript Malware. Show all posts

Tuesday, 16 June 2015

Chinese Tor - And VPN Users Exposed Via JavaScript


A select group of Chinese users of VPN services and the Tor network has become the target of a JavaScript attack that attempted to discover their true identities. Reported security Alien Vault Labs .The company took a "watering hole" attack where, with several Chinese-language websites of NGOs, Uighur and Muslim organizations were hacked.

Watering holes are so called because potential victims to visit the websites of itself. In most of these attacks, the attackers put malicious code on the hacked website that visitors often try to infect via an exploit with malware. Researchers at the Chinese-language websites hacked observed a new technique not previously been applied to watering holes.

The websites had placed a malicious JavaScript file which users through " JSONP hijacking "vulnerabilities in more than 15 major Chinese-language websites are attacking. Through JSONP requests the attackers could steal private data from users if they were logged on a vulnerable websites. It involves major Chinese portals like Baidu, Sina and QQ. Then, the JavaScript code sends the information to a server of the attackers.

It may then go to the real user's name and his email address. According Alien Vault Labs was a small group of people the campaign of the target, which aims to unmask users who visit these sites, even if they come through Tor or a VPN. Researchers call the Chinese websites in question to remedy the JSONP vulnerabilities. In addition, users advised to avoid visiting sensitive sites after they have logged on to another website.

Wednesday, 11 February 2015

Chanitor Trojan: "Maleficent Microsoft Volume Licensing Spreading Malware"


Several companies have recently received an email from the Microsoft Volume Licensing Service Center (VLSC) comes appeared and attempts to spread via a clever trick JavaScript malware. Through the VLSC companies to manage their Microsoft licenses. The message that goes around is very similar to the emails that sends Microsoft normally on the VLSC and a personalized salutation. According to the e-mail recipients may register via the attached link for the VLSC.

The link actually points to a hacked WordPress server. Using JavaScript, however, the real-VLSC Microsoft Web site shown where users can log in. However, there is simultaneously a zip file provided that the hacked WordPress server originates.This seems like the file from the Microsoft Web sites originates, although the hacked WordPress server is listed at the download location.

Offered zip file contains another .scr file is a Trojan horse. This "Chanitor Trojan" then connects to the Tor network. According to Cisco, the malware at the time was that the e-mails were detected around 9 out of 57 virus scanners on VirusTotal.

Hashesh:

1b147fc9d5342ca0fa59207d366ec4fb  (VLSC Microsoft.zip)

6266dc7f68e98b3a52908a7e2b5fe4eb (Volume_Licensing_Service_Center_details_7834892334.scr)