Showing posts with label Sandbox. Show all posts
Showing posts with label Sandbox. Show all posts

Tuesday, 27 October 2015

Ads On Porn Sites Spread Browser Ransomware


Visitors to porn sites have been warned of rogue ads that users of Internet Explorer forwarded to a page with browser ransomware. This ransomware encrypts files but locks the browser and that the user has committed a crime.

Also, the claims that the page of the user's files are encrypted, while this is not the case. Then there must be an amount of between 100 and 500 euros paid to regain access to the system. The criminals behind this ransomware use a vulnerability in Internet Explorer to determine whether it is a genuine user and not a sandbox or honeypot researchers.

The page locks the browser uses JavaScript to prevent the closing of the page. Even if users pay will not close the page.Using Task Manager browser lock can however be undone. The ads that direct visitors since August this year already active on porn sites and have the features, reports anti-virus company BitDefender.

Thursday, 16 July 2015

Manufacturer Stops Installing Flash Player On Computers



The American computer manufacturer System76 has stopped the default install Adobe Flash Player on new computers. It includes both desktops and laptops now come without the video plug-in. System76 delivers desktops, laptops and servers, which all run on Ubuntu.

In 2007, the manufacturer of a license to install Adobe Flash Player advance new systems. Something the company did until now standard. Starting today, there came a change in systems and be delivered without Flash Player. According to the manufacturer's decision is based on two reasons. First, Flash Player no longer required to have a "full web experience", whereas previously it was often the case. In addition, the safety of users of the other reason.

In recent weeks, several zero-day vulnerabilities discovered in the video plug-in, which were then used by cyber criminals to infect computers silently by malware. Besides the decision to henceforth avoid Flash Player System76 also advises to remove the browser plug-in already purchased systems. "Even if you think you need Flash, you might have to experiment further by not using a time. You will be surprised how little your Internet experience is changing," the company said.

In case customers but not without Flash Player is advised to Google Chrome, which uses a proprietary Flash Player located in a sandbox. Still, this offers no guarantee, as one of the Flash Player vulnerabilities that an attacker had discovered had to break out here the Italian Hacking Team, and then take on the underlying system. Therefore, it is according to the manufacturer still more sensible to avoid flash at all.

Tuesday, 24 March 2015

Macro Malware Infected Computer By Closing Document


Researchers have discovered a new macro malware that infects your computer only if the document is closed, to circumvent detection. The malware looks to the presence of certain sandboxes like Sandboxie sandbox and Anubis. Macros allow users to automate various tasks and were used years back on a large scale by malware. Because of the security risks, Microsoft decided therefore to block macros by default in Office.

A year ago, appeared more and more .doc and .xls documents containing macros were hidden. The documents users were summoned to enable macros. Once the user enables the macro is the background example, it downloaded and installed malware. At least, that is the expected behavior.

A new variant of the Dridex malware downloads the malware until the user closes the document. According to security firm Proofpoint hope to bypass the malware creators this virus scanners and intrusion detection systems that monitor when opening documents loading malware. For this type of behavior to prevent their detection systems have security sandboxes and adapted to "wait" longer any malicious activity.

"The possibility of malicious macros to perform as the document is closed increases the infection window and forces a detection sandbox to monitor longer and possibly miss the infection. How long sandbox also wait, the infection will not occur, and if the sandbox closes or stops without closing the document, the infection is missed as a whole, " said the researchers from Proofpoint.

Sandbox

Also security PhishMe warns of a variant of Dridex that spreads via macros. This variant looks specifically at the presence of certain sandboxes like Sandboxie sandbox and Anubis. In case these sandboxes are detected, the computer will not be infected. Is the attack or successful, then download the macro Dridex banking Trojan on the computer. This malware is specially designed to steal money from online bank accounts.