Showing posts with label Malicious Files. Show all posts
Showing posts with label Malicious Files. Show all posts

Sunday, 16 August 2015

Kaspersky: Angry Ex-Employees Behind Bogus


Yesterday Reuters with a story that Russian anti-virus firm Kaspersky Lab competitors like AVG, Avast and Microsoft did years sabotaged, but according to founder Eugene Kaspersky and the anti-virus company is a nonsense story from angry ex-employees.

The story would have provided the anti-virus company legitimate files from malicious code. These files are then uploaded to the VirusTotal website and shared with other anti-virus companies. VirusTotal is a website where Internet files can be scanned dozens of virus scanners. Uploaded files are shared with participating anti-virus companies. By uploading the files sabotaged legitimate files the virus of anti-virus companies would therefore be regarded as malware.

Kaspersky Lab that the statements are unfounded and untrue and made ​​by angry ex-employees. The anti-virus company shares data correctly with other parties. "Although the security market is very competitive, is the exchange of threat data is an important component of the security of the entire IT ecosystem and we work hard to ensure that this exchange does not jeopardize or sabotaged."

Experiment

Well carried out the anti-virus company in 2009 and 2010, two experiments in which clean files to VirusTotal were sent and Kaspersky Lab files considered intentional malware. A few months later found several other scanners on VirusTotal that the files were infected, even though that was not the case. Kaspersky Lab made ​​the investigation public . In their own words to indicate that the problems with the testing of malware.

Ex-employees

On his own blog is Eugene Kaspersky also on the story and denounces in particular the use of anonymous sources. "Angry ex-employees often say nasty things about their former employer, but in this case the lies are simply ridiculous." According to Kaspersky, the resources possible to convince the journalist of Reuters know, but the story is ultimately published without any evidence. "I therefore ask myself what these ex-workers' media tell us about the next time and who believe their bullshit then."

In the blog posting Kaspersky also discusses the problem with false positives. In 2012 and 2013 had anti-virus companies many problems with false positives. An attacker provided legitimate software from malicious code and spread it. Both Kaspersky Lab and other antivirus companies were targeted. There was then a meeting behind closed doors, where there is information about the attacks was exchanged. This also was the suggestion suggested that another anti-virus company possible was behind the attacks. Symantec confirms the story and says that Kaspersky Lab, in any case, none of the suspects.

Sunday, 17 May 2015

Check Point: Microsoft Needs To Create Help Files Harmless


Cyber criminals use Microsoft help files that Windows users just provide information on various subjects, in order to spread malware. The software giant should therefore take measures to defuse this threat, as advocates security company Check Point.

The problem is present with chm files, which stands for Microsoft Compressed HTML Help. This format is the successor of the famous .hlp file in Windows. CHM files are highly interactive and can contain various technologies, such as JavaScript and PowerShell commands. This makes it possible to automatically download a file when the CHM file is opened.

There have been several attacks in which malicious observed chm files are distributed via e-mail. Many users would not know that this is a potentially dangerous file. "The .chm help files are often used as software documentation and help manual. As the use is so common, we find the use of the help files is usually not suspected," says analyst Oded Vanunu Check Point.

He recently discovered a CHM file that the program Putty downloaded and executed on the computer, which then further commands could be executed on the computer. Many virus scanners, however, would not detect the malicious CHM files."Microsoft has not yet developed a patch to prevent this attack method. Therefore, it is still used by attackers as not be noticed by virus," said Vanunu.