Showing posts with label Sophos. Show all posts
Showing posts with label Sophos. Show all posts

Thursday, 19 November 2015

Botnet Tool Uses Twitter Direct Messages



Cyber criminals can control their botnet recently via Direct Messages on Twitter. The Python program Twittor called, was designed by the idea of GCAT, a similar program cyber criminals command & control servers to be managed via Gmail. Twittor made ​​by self-appointed security researcher Paul Amar and available from September, but is now observed by Sophos.

The tool uses direct messages on Twitter. The "advantage" of them, as compared to the conventional way of managing command & control servers, which the Direct Messages on Twitter are private. And the traffic is not stopped with IP filtering because Twittor use the Twitter API.

In addition, Twitter announced earlier this year that the limit of 140 characters is widened in private messages. This will therefore also more malicious traffic. The limitation is that there is a maximum of 1 000 direct messages per day can be sent.A botmaster can therefore no more than approximately 100 bots manage per account.

Many security tools such as Nmap and Metasploit, are not only useful for cyber criminals also useful for security researchers. Publishing a free tool that makes it possible to create a botnet via Twitter Direct Message operate seems an odd way of security research, says John Zorabedian Sophos.

Wednesday, 28 October 2015

FBI Denies Payment Advice To Ransomware Victims


The FBI provides victims of ransomware no advice to pay the demanded ransom, as has informed the American investigative know. Last week, an FBI agent in the news which said that paying the FBI ransomware victims regularly advises.

"Ransomware is so good," said FBI agent Joseph Bonavolonta. "To be honest, we often advise people to pay the ransom."A spokesman for the FBI late to anti-virus firm Sophos know that the investigative makes no recommendations to companies. However, the FBI puts the opportunities to affected companies. "It is up to the companies to decide what is the best solution for them. That is whether to restore backups, access a security professional or pay."

It also asked whether victims have to pay or not. In this case pointed to a website that recommends not to pay. According to Paul Ducklin of Sophos, people and enforcement agencies simply talk if it is not about their data. He also states that pay quite okay, but that appearance is preferred.

Saturday, 24 October 2015

FBI Recommends Ransomware Victims To Pay


The FBI regularly advises victims of ransomware to pay the ransom so that they recover their files. Ransomware is still a major problem in the United States. In June, let the FBI know that between April 2014 and June this year had received 992 complaints about the CryptoWall-ransomware. Victims should by the malware 18 million dollars have been lost.

Victims of ransomware are advised to contact the FBI, but the US detection can often advise his little else to pay if companies want their data. "Ransomware is so good," said FBI agent Joseph Bonavolonta. "To be honest, we often advise people to pay the ransom." That left Bonavolonta during Cyber ​​Security Summit 2015 in Boston know, reports The Security Ledger.

"The easiest way is to pay the ransom," as the FBI agent added. According Bonavolonta are attempts by the FBI and others to crack the encryption of the ransomware not been successful. "The amount of money that these criminals get inside is huge and that's because the vast majority of institutions pay the ransom." Earlier this year, also left the British anti-virus firm Sophos know that paying ransomware in some cases the only solution is.

A recommendation which earlier also by the Computer Emergency Readiness Team of the US Government (US-CERT) was given.

Saturday, 17 October 2015

Test: Virus Still Gives Many False Alarms


It is still common for virus scanners and security software wrongly clean consider software as malware, sometimes causing millions of users can get duped and even important files can lose. According to a test of the Austrian test lab AV-Comparatives.


According to the test lab, it is important to not only to measure the detection of malware in the testing of anti-virus software, but also the reliability. A part of the trustworthiness is dealing with clean files, and it does not give false alarms, the so-called 'false positives'. "False positives are an important yardstick for the quality of anti-virus software. A false positive notification from a customer can provide a lot of work and support to remedy the problem. Sometimes it can even lead to data loss and system inaccessible," said the test lab.

During the test from AV-Comparatives gave ESET, Microsoft Security Essentials and Panda Security no false alarms.Kaspersky Lab, Lavasoft, Tencent, Bitdefender, Emsisoft, Trend Micro, BullGuard, eScan, Avira, AVG, McAfee and Sophos was fewer than nine times the error. Fortinet, Quick Heal, F-Secure and Threat Track saw 12 to 18 clean files for malware. Avast and Baidu exciting with respectively 35 and 139 false alarms crown.

The impact varies by product. Fortinet regarded as Adobe Acrobat as malware, and Threat Track this occurs when the Symantec software. Avast see the Trend Micro software again for malware and multiple virus scanners to choke on a game.

Thursday, 17 September 2015

Writer Loses Part Of His Life's Work By Ransomware


A New Zealand writer who for 50 years on a book about cars works is a part of his life's work lost by ransomware and the man did not have backups. The 73-year-old Bruce Utting in his life had some 200 cars owned and operated since 1965 trying to write about a book.

Recently touched his computer infected with ransomware which encrypted files. To regain access to the files he had to pay $ 500. If it was not paid on time would amount to $ 1000 are doubled. Utting knocked on NetSafe, an organization sponsored by the government that gives online security advisory. "It was suggested that I should throw this computer and a new one had to buy, as there was no safe way to format or to avoid the risk of reinfection," said the writer.

Utting then decided to go to the police, but they sent him back to NetSafe. The organization advised not to pay the ransom, even letting victims of ransomware regularly know that after paying their files to recover. The British anti-virus firm Sophos understands else that pay victims, especially if they have no backups. Despite all warnings the writer did not have backups, so the encrypted files can not be retrieved in a different way.

Utting was lucky however, as ransomware but four or five chapters encrypted. He uses a very old version of Microsoft Works for writing his book and the earlier chapters were not recognized by the ransomware and encrypted, reports the New Zealand news site Stuff. The writer is now planning to buy a new computer.

Wednesday, 9 September 2015

Microsoft Office: Documents Install Backdoor Through Recent Office Leak



A recent vulnerability in Microsoft Office that in April was patched is already several weeks actively attacked and used to install a backdoor on Windows computers. A problem because many organizations install security updates for Microsoft Office or wait very long time here.

By opening a malicious document, an attacker could then install malware on the computer. A tactic that has been successfully applied. Last year made ​​the British anti-virus firm Sophos study (pdf) to the vulnerabilities that attackers use to this kind of attack. Two leaks, one from 2010 and one from 2012, was attacked by most of the malicious documents. Also from other surveys show that the vulnerability in 2012 the favorite target of attackers.

Although there is an update to the now attacked Office leak for about five months is available, the question is how many organizations have installed. Even before the patch Microsoft released the vulnerability was attacked. Early August saw Sophos, however, pass by a series of papers that try to take advantage of the leak. The documents have subjects like "WUPOS_update.doc", "ammendment.doc", "Information 2.doc" and "Anti-Money Laude Ring & Suspicious cases.doc".

In case the files are opened on an unpatched machine, the code in the document called Uwarrior install a backdoor on the computer. This allows the attackers full control over the machine. To prevent infection, managers and users are advised to patch Office and not to open unexpected or unsolicited documents. Last week warned IBM all e-mail attachments to make a comeback as an attack vector.

Tuesday, 8 September 2015

Kaspersky Close Critical Vulnerability In Anti-virus Software


The Russian anti-virus firm Kaspersky Lab last week released a critical security vulnerability in the anti-virus software patched. Through the vulnerability an attacker could completely take over the system without users here had to do something. The leak was discovered by Tavis Ormandy.

Ormandy works for Google, but also carries out research in its own right. According to the researcher, who also critical vulnerabilities in anti-virus software from ESET and Sophos discovered, the problem arose in the default configuration. Ormandy called the leak as bad as it can be. Through the vulnerability an attacker could execute code with system privileges ie, without user interaction.

Where exactly the problem was and how an attacker can use them was not disclosed. At first it was difficult, according to the researcher to a security contact at Kaspersky found. After being informed was the Russian virus fighter within 24 hours with an update that was rolled out to users, so let Ormandy on Twitter know.

Thursday, 25 June 2015

Google Finds Critical Vulnerability In Virus ESET


A researcher from Google alone in a few days a critical vulnerability in the virus scanners and security of the Slovak anti-virus company ESET discovered which allows remote attackers computers and systems can completely take over, without any user interaction is required. The vulnerability would therefore be ideal for a worm which business networks that use ESET software can be completely infected.

ESET software uses a mini-filter to intercept all input and output (I / O) to the hard disk, analyze and then emulate in case it comes to executable code. Through emulation, a file can be carried out partially before the virus signatures are used to determine whether the file is malicious or not.

Through the browser, email client, instant messaging, file sharing, network, USB and many other ways an attacker disk I / O and so cause execute the attack. The problem is in fact caused by the emulation performing ESET. The emulator does not appear to be robust and easy to compromise, says researcher Tavis Ormandy of Google. They may run malicious code with root privileges.

The problem is at all ESET products, including virus scanners for Linux, Mac OS X and Windows. As proof Ormandy developed a working exploit which systems to attack from a distance. Last Friday warned Google ESET, where the results were discussed in person with the company. Three days later, on Monday, the Slovak virus fighter came with an update to resolve the issue.

Risk

According to Ormandy, however whether users are the risks and benefits of security weigh. In the past, even though Ormandy revealed major problems in the anti-virus software from Sophos , and this week it was announced that the NSA and GCHQ to vulnerabilities have sought in anti-virus programs. Attacking users through their virus is therefore not a theoretical risk, according to Ormandy.

Saturday, 25 April 2015

ESET: Ransomware Victims Should Not Pay



Computer users who are victims of ransomware and therefore no longer have access to their data should the ransom demand the criminals do not pay. This enables Raphael Labaca Castro of Slovak anti-virus company ESET. In recent months, several experts spoke out about paying ransomware and it was revealed that dozens of Dutch companies had the ransom paid after they were infected.

British anti-virus firm Sophos found that prevention is better than cure, but in the case of an infection the best " okay "is to pay the ransom. Labaca Castro has a different opinion. "If you pay your support cyber criminals by providing them with more money." In addition, according to the security expert would be no guarantee that the encrypted files are decrypted.Nevertheless, recent incidents where the ransom be paid to victims recovering their files.

Yet calls Labaca Castro paid a dangerous option. "Remember, this is not a service. The cyber criminals. Even if you pay, they do not on a" whitelist "position, so you can be infected again. So it is not a real solution for the future." Prevention according to the expert is the main weapon against ransomware. He also advises to make regular backups.

Saturday, 21 March 2015

Anti-virus Company Will Pay Ransomware Okay


British anti-virus firm Sophos finds it okay if victims of ransomware pay to pay their encrypted data, although it is better not to do this. Thus the virus fighter is partially against the advice of police and some experts in that just advise to never pay .

By paying criminals would continue with their practices. In addition, there is no guarantee that victims receive a decryption key or to decrypt the work files. Recently 25 Dutch companies had paid the creators of ransomware and recovering their files. There are also cases of American police agencies known to have been infected and eventually paid .

Sophos also states that it is easy to say that victims should not pay, but it's a different story if it were your own data. The anti-virus company says that it's okay to pay, but if it can be avoided. In addition, Internet users would be wise to take precautions, such as making backups. In the case of an infection can therefore be reduced and ultimately the damage is unavoidable that there is to be paid.

Friday, 6 February 2015

Research: Cyber Spies Sloppy Programmers


Groups that advanced persistent threats (APTS) for cyber espionage prove to be sloppy programmers use, says a researcher ( pdf ) of the British anti-virus firm Sophos . The virus fighter compared the malware cybercriminals applied by cyber spies.

Apts are often considered sophisticated attacks, in which attackers long time to access the network from a target managed to obtain. However, the quality of the malware used appears to be disappointing, says researcher Gabor Szappanos. For example, there appeared to be no quality control in the APT-groups. "A big part of their creations is not well tested, and they do not see why some functionality is not working," he tells.

It also appears that ordinary malware writers have more knowledge than the known exploits APT groups. Something which is bad news, because APT groups focusing on specific targets, while the malware from the malware writers has a much greater range. The APT groups do not have extensive skills when it comes to exploits. New exploits are quickly utilized, but it comes to units which have been developed by others or come from Metasploit.

Usually they develop exploits yourself and in the case of other people's exploits are barely changed. Metasploit is a framework that is offered by security firm Rapid7 and allows security professionals to test the security of systems. According Szappanos let his research shows that when security researchers and administrators respond rapidly to undetected leaks, they probably handle this type of APT groups.

"Despite this, the malware writers mentioned in the report should not be underestimated. They develop sophisticated Trojans and know that spread to major organizations. The fact that they are not good with exploits does not mean that they are less dangerous," concludes the researcher.