Showing posts with label Malware Do Not Need Coffee. Show all posts
Showing posts with label Malware Do Not Need Coffee. Show all posts

Wednesday, 8 July 2015

Zero-Day Vulnerability In Flash Player Active Attacked - Update


The vulnerability in Adobe Flash Player which the Italian developer of government spyware Hacking Team disposal is now actively used to infect internet users with malware. Recently, an attacker managed to break in Hacking Team in there and made some 400GB of data booty.

Among the files an exploit was discovered a vulnerability in Flash Player for which no security exists a so-called 'zero-day'.Anti-virus firm Malwarebytes and researcher JuK of the blog Malware Do not Need Coffee now now report that several exploit kits about the exploit to have discovered by Hacking Team Flash Player flaw.

Exploit kits are programs that cyber criminals can infect Internet users through unpatched vulnerabilities in popular software.Thereby running Internet using Adobe Flash Player now a high risk of becoming infected with malware. Visiting a hacked or malicious Web site or see getting an infected ad is sufficient to run an infection.

Emergency Patch

Adobe yesterday evening let know that there are expected today to emergency patch will appear. The notice is still no reports that the vulnerability is also actively attacked. Google Chrome users seem to be already protected against the vulnerability. Yesterday, Google published because a new version of Google Chrome. Details on changes Google is not announced, but discovered that the embedded Flash Player in the browser but was upgraded to a version that is not vulnerable according to Adobe.

Update 12:38

Adobe has released the emergency patch already released . This is version 18.0.0.203 for Windows and Mac users, while version 18.0.0.204 for the Linux version of Chrome is available. For the Linux version of Firefox, version 11.2.202.481 appeared. The update will be rolled out in most cases via the automatic update function, but can also be downloaded manually from Adobe.com .

Sunday, 8 February 2015

Renewed Ransomware Shows KLPD Warning


The makers of the Reveton ransomware-have after two years provide their creation of a new design, but at the latest "make over" Dutch users still get a warning that supposedly of the National Police Agency (KLPD) is derived. The KLPD However since January 1, 2013 passed in the National Police. According to the warning, the user has been guilty of storing and distributing child pornography.

Because of this crime is the computer locked and requires an amount of 100 euros paid to regain access, the report said.These so-called fine can be paid via Ukash and PaySafeCard. The ransomware also gives instructions where these vouchers to purchase. The police started in 2013 a campaign to warn shopkeepers as people came to buy this kind of vouchers.

According to researcher JuK of the blog Malware Do not Need Coffee spreads the ransomware via ads on porn sites that use a recent vulnerability in Adobe Flash Player. This vulnerability was on January 24 via an emergency patch Adobe poem. Due to the use of police logos and names Reveton is also called the "police virus."

Unlike crypto ransomware as CryptoWall and Crypto Locker users files are not encrypted by Reveton. The impact is therefore smaller for victims, partly because there are all kinds of tools and manuals are available online to remove Reveton similar ransomware. The past year also saw a particular rise in ransomware crypto while Reveton just came less in the news.

Friday, 16 January 2015

Cryptowall 3.0 - "Microsoft Sees Hundreds Of New Infections By CryptoWall"


After two months of silence, there is a new version of the CryptoWall-ransomware appeared that managed to infect one day 288 Windows computers, says Microsoft. CryptoWall 3.0 spreads the same way as previous versions, namely via drive-by downloads and installation by malware already present on computers. Once active encrypts CryptoWall kinds of files and then asks for an amount of 500 euros in bitcoin. Victims receive 167 hours to pay, and the price is increased. In previous versions it was then a sum of 1,000 euros.

Cryptowall Decrypt Service.

Communicated the older versions of CryptoWall still using the Tor network, CryptoWall 3.0 uses I2P, which stands for Invisible Internet Project (I2P), says researcher JuK of the blog Malware Do not Need Coffee . I2P is a network layer allowing application messages safely and pseudo-anonymous can exchange. 

Cryptowall 3.0 communications with C&C

The earlier versions of CryptoWall would be more than 830,000 computers have been infected, making it the most "successful" ransomware until now.

VirusTotal Report Zip File: c77a463c5f6481efee38bba2bc8bf085

VirusTotal Report: 6c3e6143ab699d6b78551d417c0a1a45

VirusTotal Report: 47363b94cee907e2b8926c1be61150c7