Showing posts with label Reventon Ransomware. Show all posts
Showing posts with label Reventon Ransomware. Show all posts

Saturday, 26 September 2015

Porn XHamster Spread Malware Weather


For the third time in a year there are again infected ads on the most popular porn xHamster published that attempted to infect visitors with malware. XHamster receives nearly half a billion monthly visitors and is on the 71st place of most visited websites on the internet.

The infected ads first carried out various checks. Thus, it ensures that the visitor Internet Explorer and certain security tools such as Wireshark and Fiddler active, said anti-malware company Malwarebytes. In case it IE users without said security tools went unnoticed was a page loaded with the Nuclear-exploitkit. This exploitkit uses known vulnerabilities include Adobe Flash Player and Internet Explorer users have not patched.

In the case the attack was successful was ransomware and other malware installed. After being informed removed the ad network TrafficHaus infected ads. A few days later appeared again malicious ads on xHamster. This time the browser was based Brow lock ransomware spread. This ransomware is not on the computer, but locks the browser via a special JavaScript and states that the user must pay to get access again.

Again TrafficHaus was informed. Malwarebytes but does not know if the second round with malicious ads has been removed. In January and April also appeared already contaminated ads on xHamster.

Friday, 8 May 2015

Infected Ads On Dozens Of Porn Sites Discovered


The past week has been on dozens of porn sites infectious ad appeared that visitors via a known vulnerability in Adobe Flash Player tries to infect with malware. Among the stricken porn sites, which together have 250 million visitors are drtuber and nuvid the largest.

Unlike many infectious ads that visitors unnoticed forward to another site, the ad used to contain pornography directly exploitable, which makes abuse of the vulnerability in Adobe Flash Player, as reported anti-virus company Malwarebytes.The ad would be distributed through an advertiser on the AdXpansion ad network. In case the attack success are different infected files placed on your computer. Visitors to porn sites whose Adobe Flash Player up-to-date are not at risk.

Wednesday, 29 April 2015

Weather Infected Ads On Porn xHamster


On the popular porn xHamster again infected ads have appeared that attempt to infect visitors with malware. In late January it was even hit on the porn site, which according to Alexa is on the 68th place of most visited sites on the Internet and gets 514 million visitors monthly.

The ads direct visitors unnoticed to another page where the Angler Exploitkit runs. This page checks to see if the visitor uses the virus from Kaspersky Lab or Norton. If this is not the case, then it is decided to attack the user further. The Angler Exploitkit makes abuse of vulnerabilities in Internet Explorer, Java, Silverlight and Adobe Flash Player. Anti-virus firm Malwarebytes suggests that only an old vulnerability in Internet Explorer is used in the attack.

Is the attack successful, is the Bedep malware installed. The same malware that also the end of January on the website was spread via infected ads. Bedep making computers part of a botnet and can then install additional malware. Once active Bedep used infected computers to commit fraud advertisement. Additionally silently loads the Magnitude Exploitkit, which also makes abuse of vulnerabilities, provide users with additional malware can become infected.

Sunday, 8 February 2015

Renewed Ransomware Shows KLPD Warning


The makers of the Reveton ransomware-have after two years provide their creation of a new design, but at the latest "make over" Dutch users still get a warning that supposedly of the National Police Agency (KLPD) is derived. The KLPD However since January 1, 2013 passed in the National Police. According to the warning, the user has been guilty of storing and distributing child pornography.

Because of this crime is the computer locked and requires an amount of 100 euros paid to regain access, the report said.These so-called fine can be paid via Ukash and PaySafeCard. The ransomware also gives instructions where these vouchers to purchase. The police started in 2013 a campaign to warn shopkeepers as people came to buy this kind of vouchers.

According to researcher JuK of the blog Malware Do not Need Coffee spreads the ransomware via ads on porn sites that use a recent vulnerability in Adobe Flash Player. This vulnerability was on January 24 via an emergency patch Adobe poem. Due to the use of police logos and names Reveton is also called the "police virus."

Unlike crypto ransomware as CryptoWall and Crypto Locker users files are not encrypted by Reveton. The impact is therefore smaller for victims, partly because there are all kinds of tools and manuals are available online to remove Reveton similar ransomware. The past year also saw a particular rise in ransomware crypto while Reveton just came less in the news.

Thursday, 29 January 2015

Infected Ads on xHamster Spread Malware


Researchers have discovered the popular porn site xHamster infected ads that try to infect visitors through a recently patched flaw in Flash Player. According to anti-virus company Malwarebytes is the number of infections from xHamster recent days has increased by 1500%.

The porn is according to measurement agency Alexa on the 64th spot of most visited websites on the internet. In case the attack is successful the Bedep malware is installed. Bedep making computers part of a botnet and can then install additional malware. Meanwhile, there is an update to the attacked Flash Player leak released, but may still not be installed anywhere.

"Although malvertising on xHamster is nothing new, this particular campaign is very active. Given that this porn site generates a lot of traffic, the number of infections are gigantic," says Malwarebytes. Previously had security FireEye already know that had infected ads on porn sites found , including a porn site in the Alexa Top 1000. However, it seems to go a different attack. As was pointed infected computers installed Reveton-ransomware.

Wednesday, 28 January 2015

Visitors Porn Sites Attacked By Flash Player Leak


Visitors from different porn sites, including one that is on the Internet in the Top 1000 most visited sites are attacked by a leak in Adobe Flash Player which published an update until recent days. The attack took place through ads displayed on porn sites.

That says security firm FireEye. Once the ads were shown malware could be installed on the system in a vulnerable browser.To which websites are just the IT security officer does not know. However, the advertisements used a variant of the attack which was observed in the first instance. That first attack was carried out by the Angler Exploitkit while the new attack does not use this exploitkit.

The original Angler attack used some JavaScript and try to detect the presence of virtual machines and scanners, while the new variant no obfuscation used or analyzes the environment. The exploit for Flash Player in this case is loaded via normal JavaScript. The attack is successful then a variant of the Reveton ransomware-installed. Reveton locks the computer and that the user has committed a crime. In order to prevent criminal prosecution and to regain access to the system must be an amount of money to be paid.

Meanwhile, there is for all users released an update that fixes the leak. Through this page can be checked which version of Flash Player installed on your computer. The Finnish F-Secure let know that the Angler Exploitkit last week was the most popular exploitkit among cybercriminals. The virus fighter advises Internet users in addition to installing the update also to set click-to-play. In this case, the user must first click on a Flash object before it is loaded. In this way it can automatically be prevented infecting the computer via browser plug-ins.