Showing posts with label Proofpoint. Show all posts
Showing posts with label Proofpoint. Show all posts

Sunday, 3 May 2015

Companies Attacked Through CVs On Job Sites


Several companies who were looking for staff on the job site CareerBuilder became the target of a sophisticated attack. Through CareerBuilder job seekers can respond to available vacancies by uploading a resume. Companies gain when the resume is uploaded an e-mail that they can download it.


Proofpoint security firm says it has detected an attack where cyber criminals upload malicious CVs. These are files named "RESUME.DOC" and "cv.doc". The documents are abuse of two vulnerabilities in Microsoft Office that were patched by Microsoft in 2012 and 2014. In case the documents are opened malware can be installed on unpatched computers. The malware thereby poses as an image to blend in.

It is a backdoor that contains the TeamViewer application. This, according to Proofpoint legitimate cloud service that allows computers to be controlled remotely. Not only TeamViewer used by some companies and would therefore not stand, also helps the application in circumventing NAT limitations. Both the server and client make beginning with a connection to an endpoint in the cloud before they connect to each other.

While the attack requires more time and effort of the attackers, the chance that the file is opened greater than in any documents sent, according to Proofpoint . The attackers namely make use of the services of an existing website. It is also legitimate emails that remind recipients of the uploaded documents. Documents expect the receivers and just want to open.The observed attacks were directed against energy companies, television companies, credit unions and electricity suppliers.Whether they are successful and who is behind it is unknown.

Tuesday, 24 March 2015

Macro Malware Infected Computer By Closing Document


Researchers have discovered a new macro malware that infects your computer only if the document is closed, to circumvent detection. The malware looks to the presence of certain sandboxes like Sandboxie sandbox and Anubis. Macros allow users to automate various tasks and were used years back on a large scale by malware. Because of the security risks, Microsoft decided therefore to block macros by default in Office.

A year ago, appeared more and more .doc and .xls documents containing macros were hidden. The documents users were summoned to enable macros. Once the user enables the macro is the background example, it downloaded and installed malware. At least, that is the expected behavior.

A new variant of the Dridex malware downloads the malware until the user closes the document. According to security firm Proofpoint hope to bypass the malware creators this virus scanners and intrusion detection systems that monitor when opening documents loading malware. For this type of behavior to prevent their detection systems have security sandboxes and adapted to "wait" longer any malicious activity.

"The possibility of malicious macros to perform as the document is closed increases the infection window and forces a detection sandbox to monitor longer and possibly miss the infection. How long sandbox also wait, the infection will not occur, and if the sandbox closes or stops without closing the document, the infection is missed as a whole, " said the researchers from Proofpoint.

Sandbox

Also security PhishMe warns of a variant of Dridex that spreads via macros. This variant looks specifically at the presence of certain sandboxes like Sandboxie sandbox and Anubis. In case these sandboxes are detected, the computer will not be infected. Is the attack or successful, then download the macro Dridex banking Trojan on the computer. This malware is specially designed to steal money from online bank accounts.

Friday, 27 February 2015

Phishing Mail Hijacks Routers Using Default Password


During the final weeks of last year and the first half of January, cybercriminals conducted a small-scale email attack which tried to hijack different models of routers. The less than 100 emails were sent to Brazilian Internet users.

The email seemed the largest Brazilian telecommunications company coming and contained a link to a website. This website was abuse of cross-site request forgery (CSRF) vulnerabilities in the UTStarcom- and TP-Link routers from the telco. The CRSF attack tried to log into different default passwords and administrator names on the router. In case the attack was successful, the DNS servers from the router were changed.


The Domain Name System (DNS) is similar to the directory and translates among other domain names into IP addresses. The DNS hijacking an attacker can manipulate the movement of users and intercept sensitive data. Example, if users want them to be redirected to another page to their banking site. During the attack on Brazilian users to security firm Proofpoint , the campaign found out, not knowing what was done using the custom DNS servers.

Thursday, 9 October 2014

Botnet of 500,000 computers - Qakbot Malware

The Attack Chain


Researchers have identified a botnet of 500,000 computers discovered that 52% of machinery exists that run on Windows XP. A comparatively very high percentage, since it no longer supported by Microsoft operating system worldwide share of between 14% and 24%.

The computers have been infected with qbot via known vulnerabilities in Adobe Flash Player, Java, Adobe Reader and Internet Explorer, also known as Qakbot. On infected computers qbot steals all kinds of data for Internet banking. Researchers from Proofpoint found that the login data of 800,000 accounts online banking were intercepted. In 59% of these cases involved one of the five largest American banks.

Further figures ( PDF ) show that the malware on the American Internet has provided, since 75% of the infected computers over an American IP address available. especially In addition to steal login details infected machines are also offered for other cybercriminals. Paid as proxy These criminals can the infected computers as a springboard for other attacks use or for storage or transportation of stolen data.

Following are the steps How It works:

1. Infecting Legitimate Websites

Infecting Legitimate Websites

2. Filtering Targets- Traffic Distribution Systems.

Filtering Targets- Traffic Distribution Systems

3. Getting Into The User's Machines -Exploits

Getting Into The User's Machines -Exploits

4. Stealing User Banking Credentials - Malware

Stealing User Banking Credentials - Malware