Showing posts with label Signatures. Show all posts
Showing posts with label Signatures. Show all posts

Monday, 16 November 2015

Microsoft Removes Ransomware 24,000 Computers


Microsoft via the integrated removal tool in Windows this year of about 24 000 computers deleted ransomware. It is spread four ransomware families that spread via email attachments and drive-by downloads. To protect Windows users there is the MSRT.


This stands for Malicious Software Removal Tool. A built-in program that is updated every month with new signatures, mainly to detect active malware and remove. The MSRT is then carried out automatically on the system. This year there are already 29 new malware families added to the program, which in recent months was mainly focus on ransomware. This is because of the impact on victims and the number of infections. Since the removal tool is static and increasing numbers of new variants, Microsoft has this month decided to update the detection of different malware families.

Saturday, 15 August 2015

Researchers Develop Scanner For Cloud Services



Researchers at two British universities have developed a scanner to prevent criminals steal confidential files in the cloud and upload illegal files to cloud services. The system is called Xdet , which stands for Extrusion detection.

Xdet makes a signature of private files and store them. The signature is then compared with the signatures of files exchanged with the cloud service. "This way, unauthorized uploads or downloads of potentially confidential data can be detected and prevented," the researchers compared ScienceDaily . Who argue that even upload illegal files to the cloud in this way can be noticed.

The Xdet software is placed between the cloud server and distributed file storage, instead of the perimeter of the cloud network. This has several advantages. So Xdet itself is protected by perimeter security solutions such as firewalls and IDS.In addition, it is scalable, and better in this way can the cloud provider to use network-based encryption to protect data during transport.

Wednesday, 17 June 2015

Visitors Uber-Petition Sent Via Leakage To Competitor


Vulnerability in a petition page of taxi app Uber made it possible for the researcher who discovered the problem visitors could forward it to competitor Lyft. Uber was on its website a petition initiated by users of the app were called to signs.

Researcher Austin Epperson also received the request and immediately discovered that there were all sorts of characters could be completed in the petition form. The problem was compounded by the petition page the last five signed petitions were presented. Epperson He further discovered that could add an iframe to be completed petition, which he visits automatically competitor Lyft.com sent it. Visiting the petition in this case was sufficient to be forwarded. According to the researcher, however, had the leak can be used for far more dangerous things, such as spreading malware or defrauding visitors through a scam page.

To ensure that his petition with code still on the page appeared Epperson discovered another problem, which he eventually using a program 1,000 petitions able to fill every minute. "I stopped when the count had reached 106,000 signatures," so let him into an explanation of the problems found knowledge. After being informed by the investigator Uber took the site from the air, which at the time of writing is still not online. Epperson further states that the developer of the petition page script one-to-one copied from an online manual, which is precisely that it is a simple contact form.

Sunday, 11 January 2015

Factories Target Online Banking Malware


Trojans designed to steal money from online bank accounts are also used at industrial plants and factories, so has had a security researcher know. Kyle Wilhoit anti-virus firm Trend Micro discovered thirteen different types of malware that occurred as software in SCADA (supervisory control and data acquisition) environments used. It involves, for example, Siemens WinCC, GE Cimplicity, Advantech and other human machine interface (HMI) products.

Although attacks on industrial environments often with attacks by countries are linked, it would be here involve ordinary cybercriminals. "It's an interesting trend, traditional banking Trojans and no targeted attacks," Wilhoit as late versus Dark Reading know. According to the researcher criminals focus their sights on SCADA / ICS systems because they are unsafe.

Many HMI machines run on Windows and would not use a virus scanner or are not equipped with the latest signatures. Most malware Wilhoit encountered no problems would be detected by an up-to-date virus scanner. While targeted attacks are still at risk managers should also take into account normal "crimeware", as the consequences can be just as bad. HMI systems are very susceptible to interference. Infection by a banking Trojan can also just as easily get the system down.

Wilhoit saw in October for the first peak in the attacks, but does not know what the occasion is. The criminals behind the malware use spear phishing mails and drive-by downloads to infect computers. Fake websites are used on that instance, resemble those of Siemens and supposedly download a WinCC update, while it is actually malware. Wilhoit 32 recently discovered malware instances that occurred as WinCC software. Next week, the researcher during a conference SCADA give more details about his research.

Thursday, 11 December 2014

Destover malware signed with Sony certificate


It has been discovered a new variant of the dangerous malware attackers against Sony Pictures Entertainment have deployed and those with a digital certificate of the company is signed, so let researchers know. It is the "Destover" malware, which also last year against South Korean banks and television companies was used. On infected computers malware steals data and then removes all files, making the machines currently unusable.





During the attack on Sony, the attackers have the private keys captured and published that the company used to provide files of a digital certificate. However, they can also be used to sign malware, and then be used in further attacks, let anti-virus firm Kaspersky Lab know. They discovered Destover variant was signed on 5 December. Because Sony certificates are trusted by security makes this attack effectively. The digital certificate has been revoked, let certificate authority DigiCert via Twitter know.

Security Researcher Colin Keigher leave via Twitter that this is a "joke" among security researchers. A researcher who requested anonymity had found the certificate and discovered that it was the password file. Then this investigator signed the Destover malware with the Sony certificate and uploaded it to VirusTotal, which eventually landed at Kaspersky Lab.