Showing posts with label Malicious Traffic. Show all posts
Showing posts with label Malicious Traffic. Show all posts

Wednesday, 28 February 2018

Decrease Of Malicious Advertisements In The Second Half Of 2017



The number of malicious advertisements that Internet users tried to infect with malware, tried to deprive data or attempted to defame it in another way, was reduced in the second half of 2017, security company RiskIQ claims. In the third quarter, the security company detected 53 percent less malvertising than in the second quarter of 2017. In the fourth quarter, this decline continued and 10 percent fewer malicious ads were detected.


The use of advertisements to attack unpatched internet users, for example through vulnerabilities in Adobe Reader or Internet Explorer, decreased by 36 percent in the third quarter and 20 percent in the fourth quarter. Other malware in ads decreased by as much as 67 percent in the fourth quarter. The fourth quarter, however, saw an increase of 16 percent in the number of ads pointing to a scam, but overall there were fewer rogue ads in both the third and fourth quarters.

Saturday, 15 August 2015

Infected Ads Hide Behind SSL



The criminals who first infected ads on the websites of Yahoo demonstrated have now found a new ad network and use SSL to complicate the detection of malicious traffic. That leaves anti-virus company Malwarebytes know. The ad network in question is AdSpirit.de whose ads drudgereport.com and wunderground.com shown.

These websites get together more than 110 million visitors per month. The infected ads contain a redirect via SSL to an Azure-site, making it difficult to detect the malicious traffic at the network layer, reports analyst Jerome Segura. The ads users a website with the Angler-exploitkit charge. This exploitkit uses known vulnerabilities include Adobe Flash Player that users are not patched. What malware is installed on a successful attack Segura do not know.

Sunday, 19 July 2015

Voicemail Leads To Malware Attack Via OneDrive


A group of attackers used voicemail messages in combination with malware hosted at onedrive to attack organizations, as several security companies warn. The attack on the organizations begins with targeted phishing mails which contain a self-extracting archive file as an attachment. The attachment occurs when voice mail.

If a user opens the attachment is there as a distraction play a .wav file that looks like a real voice. In the background, however connection with OneDrive made the cloud service from Microsoft. The ultimate malware is then downloaded. Sergey Lozhkin of the Russian anti-virus firm Kaspersky Lab wonders whether this method will be applied by more cyber criminals.

"It is possible because it provides an easy way for attackers to hide malicious behavior. Detecting malicious traffic in legitimate cloud services is much more complex because it involves legitimate services to be blocked," said Lozhkin.Security company Palo Alto Networks has more details about the malware used, which was detected at the time of discovery by 3 of the 54 scanners on VirusTotal.

Friday, 22 May 2015

Dozens Minecraft Apps On Google Play Prove Scareware


On Google Play, researchers from the Slovak anti-virus company ESET found dozens of apps that occur as cheats for the popular computer game Minecraft, but in reality scareware. It involves a total of 33 applications that were placed on Google Play over a period of nine months and have been downloaded between 660,000 and 2,800,000 times.

The apps do not do what they promise and show after starting only banners claiming that the Android device with a "dangerous virus" infected. Then offered to remove the virus, for which there should be a "virus" via SMS enabled. However, it is an SMS user subscription costs 4.80 euro per week. ESET recommends that Android users to still only download apps from official app stores, to check what permissions the app asks and be read reviews from users.

Thursday, 16 April 2015

Police Infected Computers Ransomware


A police chief has admitted in the American Houlton that he was the cause that various police computers ransomware became infected and the police eventually had to pay the ransom of $ 588. Police Chief Joe McKenna leaves opposite Bangor Daily News that the infection was his fault because he opened an infected email attachment.

"The last time I get quotes for different kinds of stuff we will replace," said McKenna. "Between all those emails was an email from a woman that says that the offer had been added. I did not think about it and opened it." The appendix was found to be a blank document, which the police thought that the sender had made a mistake and put his computer.

The appendix was found to be ransomware. When McKenna his computer turned on the ransomware hit, and all kinds of encrypted files on multiple computers. "It locked all computers. All emails to photos, documents and reports," said the police chief. Eventually, the police decided to pay the ransom of $ 588, although the total damage inflicted the ransomware is estimated at $ 1,400.