Showing posts with label Trojan Horse. Show all posts
Showing posts with label Trojan Horse. Show all posts

Wednesday, 2 September 2015

Trojan Blocks Malware On Infected Computers


A Trojan horse is designed to steal money from online bank accounts show the spoils do not want to share with other cyber criminals. Once active blocking Trojan namely other malware on the infected computer. Let researchers at IBM know.

The Shifu Trojan, as malware is called, focuses on Japanese and European banks and for several months running. The malware steals all kinds of data required for online banking, such as passwords, personal certificates and tokens, as well as data from smart cards. Via VNC or Remote Desktop Protocol cyber criminals can directly from the infected computer to commit bank fraud. What stands out to Shifu, the steps taken to block other malware. The Trojan uses a type of virus-like feature, allowing files to be downloaded from the internet and malware are blocked.

It is in this case for executable files that are not signed and are downloaded via HTTP. These files will block the Trojan and sends it to its creators, presumably in order to keep the competition in mind. To let the user suspects nothing to see a message that the system has enough memory for the downloaded file. According to the researchers, it is the first time that malware draw up special rules for stopping suspicious files.

Thursday, 6 August 2015

Fraudulent Invitation Includes Windows 10 Trojan


Cyber ​​criminals from all over the world seem to grasp the launch of Windows 10 to infect internet users with malware. Earlier this month, already widely English e-mails supposedly sent an installer for Windows 10 offered.

In reality, however, it was ransomware. Now, similar reports have surfaced in Brazil, whereby criminals in their email copied from the Microsoft website. The only addition is a link to a so-called "Windows 10 Installer" allows users to download the new OS. However, it is a VBE script hosted on Google Docs. After having opened the script installs a Trojan horse on the computer to copy keystrokes and opens a backdoor, reports anti-virus firm Kaspersky Lab .

Wednesday, 5 August 2015

Trojan Horse Hijacks Linux Routers Via Shellshock Leak



Worldwide, nearly 1500 Linux routers hijacked by a Trojan, that the devices then switch to attack other systems and servers. The PNScan Trojan, as malware by the Russian Doctor Web is called, uses the Shellshock leak last September before taking on Linux routers with ARM, MIPS- or PowerPC architecture.

In addition, the Trojan also installs other malware on hacked routers already present. Shell Shock is the name for a vulnerability in Bash. This is a Unix shell commands with which it can be given to the system. It is used for many applications and many programs running in the background. Last September, the vulnerability was found and patched, but still there are vulnerable systems on the Internet.

If PNScan the router is installed on the Shellshock leak, there is other malware installed on the device. The malware then perform a scan on a range of IP addresses. After this, the malware can perform different attacks. Also, the malware that is installed in addition to the router is able to carry out attacks. It is in this case to DDoS attacks and attempts to take over phpMyAdmin installations.

Besides PNScan there has also been discovered a variant of the Trojan horse. This version does not use the Shellshock leak, but uses weak passwords to gain access via SSH. Worldwide in 1439 were found infected with PNScan routers.

Wednesday, 24 June 2015

G Data: Windows User Must Install Optional UAC Patch


Windows users would be wise to install an optional update for Windows, other malware can use a trick to get unnoticed administrator rights on the computer, so advises the German anti-virus company G Data.Following the spread of the Dridex malware.

This is a Trojan horse that recently in Belgium for major damage caused by the banking system to attack the Belgian companies use. The malware spreads via e-mail and MHTML document. This document contains a macro that attempts to download a "downloader". The downloader will place the final malware on the system. If the user macros enable the downloader is downloaded in Microsoft Office. To get administrative rights on the computer downloader tries to bypass the UAC window.


Windows User Account Control (UAC) is a security measure designed to protect computers from Microsoft as "hackers and malicious software." As software or a user wants to change some Windows settings or try to perform actions that require administrative privileges displays a UAC warning. The downloader adjusts according to G Data to a popular trick to hide the UAC warning. It uses a customized file SDB . In this case, Windows will not show because UAC window.

Microsoft has released a patch developed that allows the UAC warning is also shown in this case, but this is an optional update. "The malware creators abuse a weakness in Microsoft's operating system to be without displaying the UAC notification system. Therefore, we strongly recommend to install the Microsoft patch, Microsoft even designates it as a required patch," the German anti-virus company. In addition, users advised to not open email attachments from unknown senders and no macros enable foreign documents.

Wednesday, 17 June 2015

G Data: Attack Bundestag With Financial Malware



During the attack on the network of the German Bundestag last week, performed financial malware is used. This was reported by the German anti-virus company G Data that has studied the attack. At present it is not clear whether it is a new attack, or a continuation of the attacks in late May 2015 came to light.

According to the researchers there discovered the last attack of the Swatbanker banking Trojan used. This is a Trojan horse that is specifically designed to steal money from online bank accounts, although it can get other information. Research into the configuration files in the malware has made it clear that the administrators of the botnet Swatbanker between 8 and 10 June new filter functions have applied for the domain "bundestag.btg". This is the URL of the intranet of the Bundestag.

Once active malware can all data entered into forms, such as user names and passwords, as well as data from the browser to send the attackers. Swatbanker spreads through e-mails that appear to come from German banks and telecom providers."Looking at the first analyzes, it seems to be an attack with criminal intent. But we can not exclude other motives and the attackers have copied the behavior of criminals to disguise their true intentions," says Ralf Benzmüller , head of G Data Security Labs.

Friday, 29 May 2015

Malignant Macro Virus Bypasses Via MHTML Format



Cyber criminals have used a remarkable file to malicious macros invisible for virus scanners, as several researchers have discovered. The use of macros in Office documents has become a popular tactic to spread malware.

Macros are disabled by default in Office, but when users enable the macro can download and install malware. Recently discovered researcher Bart Blaze a spam campaign where there is a doc file with malicious macros added. In reality it turned out to be a Word MHTML file. According to researchers at security firm Trustwave beat the criminals after making the malicious macro as an MHTML file, to which then rename it to .doc or .xls. As a result the file will be opened by Microsoft Office.

When the spam campaign was detected showed that most virus scanners that are not detected. According to investigators, the criminals have malicious macros intentionally saved as MHTML file, to circumvent virus. An analysis of the MHTML file shows that the part of the evil macro via base64 encoded. In case users open the attachment and run the macro is a Trojan horse installed that is specifically designed to steal money from online bank accounts. Users also are advised to Microsoft Office can be configured to all macros are blocked.

Wednesday, 13 May 2015

Website Chef Jamie Oliver Hacked For Third Time


Attackers are there for the third time succeeded in hacking the website of the British chef Jamie Oliver and use for distributing malware. Previously it had been hit in February and March . As with these incidents the attackers malicious code added to jamieoliver.com.

This code sends visitors unnoticed to another website through which uses known vulnerabilities in Adobe Flash Player and Java to infect visitors with malware. It is malware that attempts to steal passwords. In case the software of visitors up-to-date, they are not at risk. The team that know the website of Oliver would be responsible of the incident and take measures to solve the "once and for all", says anti-virus company Malwarebytes . How the attackers were able to gain access to site is unknown.

Sunday, 15 March 2015

Website Chef Jamie Oliver Spreading Malware Again


The website of the British chef Jamie Oliver has been hacked again and again spreading malware. The site places attackers malicious code that visitors unnoticed forward to another site. This site contains the Fiesta exploitkit which makes abuse of vulnerabilities in Flash Player, Silverlight and Java.

These are vulnerabilities where all updates to be available. Users who are up-to-date are therefore not at risk. In case users are not up-to-date, it will install a Trojan horse, which is recognized by few virus scanners on VirusTotal. In addition, the malware is signed, even though the certificate used now no longer valid, as reported anti-virus company Malwarebytes. The virus fighter discovered the first hack the website and then warned webmasters that it fixed the problem. Or so it seemed.

The structure used by the attackers to now placed malicious code is very similar to that of the first attack. "That's why we think this is the same infection that was not completely removed or perhaps that a vulnerability in the server or content management system (CMS) is still present," said the researchers. Oliver's website is on the 536ste place of most visited websites in Britain and would attract 10 million visitors each month.

Trojan Discovered In Free Mac Software


A Trojan horse spies on the surfing behavior of Mac users is found in free software, warns the Russian anti-virus company Doctor Web. It would, among other things, the program "Install Free Video Cutter Joiner" go, in which a new variant of the OpinionSpy was found.

This malware can gather information about open sites, analyze network traffic intercepted traffic of chat programs, send files on the system to the malware creator and install extensions in Google Chrome and Mozilla Firefox. The Trojan would be found on various websites that offer free software. During the installation, the malware admin rights.

How many Macs do not know by the Trojan tainted late Doctor Web. Nevertheless labeled the anti-virus company OpinionSpy as " threat of the month . " When it comes to infected Macs took the virus fighter in February still about 20,000 Macs infected with the Flashback Trojan from 2012.

Sunday, 22 February 2015

Virus Scanners Microsoft Remove Superfish-Adware


Microsoft released an update for the virus Security Essentials and Windows Defender that addresses the Super Fish-adware on Lenovo laptops as well as the self-signed certificate that the adware used will be deleted. Also the free Microsoft Safety Scanner is able to detect and remove Superfish.This was discovered by Filippo Valsorda of the CloudFlare Security Team.

Meanwhile, Microsoft has also the definition put the Super Fish-adware line, where the threat as a Trojan horse is described.In addition to Microsoft also have several other providers of anti-virus solutions now released an update to detect and remove Superfish. A survey on VirusTotal shows that Superfish yesterday by 17 of the 55 virus was detected. Earlier in the day there were still six .

Besides the anti-virus companies warn the American and Dutch government for Superfish. The Computer Emergency Readiness Team (US-CERT) that part of the US Department of Homeland Security has issued this warning off. Consumers get it advised to remove the adware and the certificate installed. The Dutch government through veiliginternetten.nl published, an initiative of Economic Affairs, the National Cyber ​​Security Center and the ECP, a short article about Superfish.

Expert Wants End to Pre-Installed 'Crapware'


Computer manufacturers must stop before installing all kinds of software on new PCs, also known as 'crapware'. "Companies like Apple, who sell their products on their own merits, saddling their customers with this adware mess," said security analyst Ken Westin at Computerworld . Following the Super Fish-scandal in the Chinese computer manufacturer Lenovo.

Practice to install software in advance, as tryouts, and other programs for which the manufacturers get paid by the software developer, will place many years. In 2011, Microsoft even came with an initiative to rid computers of crapware. Computers with no trialware (tryouts) was present and there were no programs were loaded during startup called "Signature PCs". It was also for these PCs required to provide a clean desktop without gadgets, icons and unnecessary taskbar icons.

According Westin is important that consumers, manufacturers can trust. The analyst makes the blog know his employer Tripwire that mobile phone manufacturers and laptops itself a disservice by using this kind of dated ad strategies. Meanwhile, consider multiple virus Superfish as a Trojan horse. Six of the 57 scanners on VirusTotal store in detecting adware alarm.

Thursday, 19 February 2015

Espionage Firmware In Hard Disks To Detect Barely


The malicious firmware that a group of cyber spies computers permanent commitment to continue spying is hard to detect and extremely difficult to remove. "It is extremely difficult to detect. From the software level, it is impossible," said Vitaly Kamluk, researcher at Kaspersky Lab.

The Russian anti-virus company revealed this week the existence of the spy group who developed all kinds of highly advanced malware. One subset fell on, namely, the ability to infect the firmware of the various popular brands hard disks.Therefore, the malware remains hidden and active, even though the hard disk is formatted or reinstall the operating system.The code ensures that the attackers can create an invisible storage on the hard disk.

"This is unique and the first time we have seen this level of complexity of a sophisticated attacker," said security researcher.However, the module could have been used rarely. "Only a very select list of victims have received this. This is one of the most special modules that I've seen because it is so valuable. They do not want that to be known," Kamluk let know this week during a conference, so reports Threat Mail .

"It is a valuable plug-in that is used only in specific cases for very important people." To detect the malicious firmware should the PC be disassembled and made a dump of the firmware. "And we think that only a few people in the world are able to analyze the malicious code within the firmware, compare and discover," says Kamluk.

According to the researcher takes years to write firmware. But the espionage group would not use vulnerability, but only ride on the way manufacturers roll out firmware updates. "They left the door open and stood possible longtime open. The trick is that you have the full description, the full reference of the current firmware should have and how it works."

Kamluk speculates that the attackers may have access to internal manuals and documentation of the respective suppliers.Manuals that may be stolen by an insider or through another malware attack. "They do not abuse a leak in the code. It is a design flaw." Because of the proprietary communication protocols and algorithms took investigators months before they learned how the malware exactly worked. A truly infected firmware researchers have not been able to find.

Monday, 16 February 2015

Espionage Group Reprograms Firmware Drives


Researchers have identified a group of highly sophisticated cyber spies discovered active as possible for 20 years and the same zero-day vulnerabilities used that eventually were used by the creators of the Stuxnetworm. Also developed this super spies malware to reprogram the firmware from popular brands hard drives, which the researchers have never seen before.

The spies by the Russian anti-virus firm Kaspersky Lab called the "Equation Group". The first domains which date the group used to control infected computers in 2001, while the first malware copies were made ​​in 2002. Other areas that the group used to control the infected computers were already registered in 1996. This could possibly mean that the spies are active for almost two decades.

Equation Group developed several malware platforms that are more advanced than the last year revealed Regin malware.Thus, among other things, developed a computer worm that gathered all kinds of information about targets in Asia and the Middle East in 2008. This worm, named "Fanny", used two zero-day vulnerabilities. Vulnerabilities that were eventually used for Stuxnet. According to Kaspersky, this means that the Equation Group also developed Stuxnet or worked with the developers of the worm.

The Fanny worm probably had as goal to bring networks card that were not connected to the Internet. The malware was distributed through USB sticks. On infected USB sticks Fanny made a hidden storage area to which the information about infected systems preserved. Also intercepted the group of physical goods and replaced by versions with Trojans.

One example involved the participants in a scientific conference in Houston to return some of the participants had received a copy of the conference proceedings on CD-ROM, which was then used to install the Double Fantasy implant of the group on the machine the target. The exact manner in which these CDs were intercepted is unknown.


In addition to USB sticks and CDs espionage group also used a web-based exploits. Thus, among other leaks in Java and Internet Explorer to infect victims. There were also unknown exploits, possibly zero days, against the Firefox 17 version of Tor Browser deployed. Tor Browser uses a custom Firefox version that was attacked by the Equation Group.

Since 2001, the cyber spies would have infected thousands of computers in a variety of sectors including government, telecommunications, energy, nanotechnology, financial institutions, oil and gas and aviation. Most victims are in Iran and Russia. In total, Kaspersky Lab counted 500 victims, but the real number is probably much higher, because the malware has a self-destruct mechanism. It is therefore possible that there may be tens of thousands of computers were infected.

What really makes the group stand out is the ability to reprogram the firmware of all branded hard drives. The researchers were able to secure two modules that were used to reprogram the firmware. Through this method, the attackers could install it again and survive reformatting of the hard drive. In addition, could be created an invisible storage on the hard disk. However, the module would be used on a very limited scale, probably at the most valuable targets.

"Another dangerous consequence is that it is impossible to scan the firmware when the hard disk is once infected with this malicious payload simply:. For most hard disks, there are functions to write the firmware portion of the hardware, but there No functions to read it back. This means that we are virtually blind and can not detect hard drives that have been infected with this malware, "warns Costin Raiu, research director at Kaspersky Lab.

The ability to create an invisible and persistent area in the hard disk is used to store collected information that can be later retrieved by the attackers. In some cases it may also help to crack the encryption of the group: "Given the fact that their Gray Fish implant is activated immediately from the startup of the system, they have the ability to intercept the encryption password and store it in secret area, "explains Raiu.


Although all detected malware worked for Windows, there are also found traces indicating Mac OS X malware. One of the domains, which was used for the control of the infected computers received a variety of compounds of Chinese Mac OS X computers. Therefore, it is assumed that there is at least one of the platforms is also a malware-Mac version. It would also have the group the ability to infect iPhones.

Despite the level of the malware writers have they still left their mark. So were encountered several keywords in the studied modules, such DESERT WINTER, STRAIT SHOOTER and GROK. This last term appeared in NSA documents published by Der Spiegel. Kaspersky Lab discovered the Equation Group during the investigation into the Regin malware. This malware was the NSA by the virus fighter attributed . Additionally, labels the group malware as "implants", a term earlier in the NSA documents appeared Snowden. In addition, the development of Stuxnet is attributed to the NSA.

The next few days will be the Russian anti-virus company publish more details about the group and applied method.Meanwhile, there is already a document published online ( pdf ) with directions and details so that researchers and administrators can check machinery in place within their organization or environment. "The more we investigate this kind of cyber-espionage operations, the more we realize how little we know about it. Together we can uncover these practices and safer (cyber) world works," said the researchers.

Below are the MD5 with Sample Names & VT Checked:

_SD_IP_CF_dll\866f94f30d9865995494a0f7228329c26149eef2960500b2177c736c5c846035

Disk from Houston\868eb363f32beacd8bcdc7a114e020d4cfe67913a15275f4e7493d87db643ff2 

DoubleFantasy\1e55abb94951cedc548fd8d67bd1b50476808f1d0ae72f9842181761ff92f83f 

EquationDrug\1b0eb1a1591140175d1ac111a98c89472b196599baf13ef67ee7f63d0052b00e 

EquationLaser\9412a66bc81f51a1fa916ac47c77e02ac1a7c9dff543233e
d70aa265ef6a1e76 

Fanny\003315b0aea2fcb9f77d29223dd8947d0e6792b3a0227e054be8eb2a11f443d9 

GrayFish\df4bbd02dcd8b8b9e1374c6f71f2e2da8518d39337b35983874266e8fff055e1 
9B1CA66AAB784DC5F1DFE635D8F8A904
GROK\441f2a6775621af8c5d1ead7082e9573ad878bc90675ed55f86abfc8a9e8cc6f 

nls_933w_dll\83d14ce2dcfc852791d20cd78066ba5a2b39eb503e12e33f2ef0b1a46c68de73

TripleFantasy\112d70111fef5e5e072b17e0d5d9312a0826cb85304a17bb51330d9800936c4a 

TripleFantasy\24b7e7553b1aa241997e28775d3952c4cb885056c4606cbed9b450320b601255 

Wednesday, 11 February 2015

Chanitor Trojan: "Maleficent Microsoft Volume Licensing Spreading Malware"


Several companies have recently received an email from the Microsoft Volume Licensing Service Center (VLSC) comes appeared and attempts to spread via a clever trick JavaScript malware. Through the VLSC companies to manage their Microsoft licenses. The message that goes around is very similar to the emails that sends Microsoft normally on the VLSC and a personalized salutation. According to the e-mail recipients may register via the attached link for the VLSC.

The link actually points to a hacked WordPress server. Using JavaScript, however, the real-VLSC Microsoft Web site shown where users can log in. However, there is simultaneously a zip file provided that the hacked WordPress server originates.This seems like the file from the Microsoft Web sites originates, although the hacked WordPress server is listed at the download location.

Offered zip file contains another .scr file is a Trojan horse. This "Chanitor Trojan" then connects to the Tor network. According to Cisco, the malware at the time was that the e-mails were detected around 9 out of 57 virus scanners on VirusTotal.

Hashesh:

1b147fc9d5342ca0fa59207d366ec4fb  (VLSC Microsoft.zip)

6266dc7f68e98b3a52908a7e2b5fe4eb (Volume_Licensing_Service_Center_details_7834892334.scr)

Tuesday, 3 February 2015

260,000 Facebook Users Infected By Trojan


A Trojan horse that Facebook used to spread now has some 260,000 users of the social networking infected. That leaves the researcher know who first all 110,000 infections counted. The malware lures users with messages that point to a page with a porn video.

Once users click on the video appears a message that they need to download the offered "Flash Player" to watch the movie.However, the download is the Trojan horse. Once the malware is active, the browsers on your computer adapted and equipped with an extension. This extension is intended to keep the malware up-to-date and to block websites with virus removal tools or scanners, says researcher Mohammad Reza Faghani.

Meanwhile, the creators behind the malware would have released a new variant that victims, if they are active on Twitter, a specific Twitter account to follow. Like the first version, the malware also infects Facebook profiles and use the hijacked profiles to spread linkjes to the so-called porn video. In addition, infected Facebook users are forced to follow a specific profile. This profile should now have some 260,000 followers. The Trojan mainly in India, North Africa and South America made ​​victims, said in a Faghani update the malware.

Malware Hijacks Microsoft Outlook To Send Email


Researchers have discovered that a Trojan on infected computers used Microsoft Outlook to send infected emails. It is a variant of the Dyre banking Trojan , also known as Dyreza . The malware is specifically designed to steal money from online bank accounts.

The now discovered variant spreads via email attachments posing as faxes or contain a message from an undelivered package and Upatre downloader. This downloader downloads the weather Dyre Trojan on the system, which installs a worm on the computer. The worm uses Microsoft Outlook on the computer to send infected e-mails with Upatre downloader. In addition, the malware does not use the address book of the victim, as it was done by many worms in the past. After the messages are sent, the worm deletes itself again, as reports of anti-virus company Trend Micro.

Sunday, 1 February 2015

Trojan Horse Infected 110,000 Facebook Users


A Trojan horse that has spread through Facebook in two days, more than 110,000 users of the social networking infected, says researcher Mohammad Reza Faghani. The malware lures users with exciting messages that point to a page with a porn video.

Once users click on the video appears a message that they need to download the offered "Flash Player" to watch the movie. However, the download is the Trojan horse. According to the researcher this Trojan horse differs from other Trojans who used Facebook to spread. If sent other Trojans messages on behalf of the victim to some of his friends. Once these friends became infected, the Trojan sent back messages to their friends.

The now discovered Trojan "tagging" the friends of the infected user in the message. This allows not only the friends of the first victim the message, but also their friends again, so the malware can spread quickly. In order not to fall too much on the Trojan would not be more than 20 users tag a message. Once active on a system, the malware can take over the keyboard and mouse.

Sunday, 11 January 2015

Factories Target Online Banking Malware


Trojans designed to steal money from online bank accounts are also used at industrial plants and factories, so has had a security researcher know. Kyle Wilhoit anti-virus firm Trend Micro discovered thirteen different types of malware that occurred as software in SCADA (supervisory control and data acquisition) environments used. It involves, for example, Siemens WinCC, GE Cimplicity, Advantech and other human machine interface (HMI) products.

Although attacks on industrial environments often with attacks by countries are linked, it would be here involve ordinary cybercriminals. "It's an interesting trend, traditional banking Trojans and no targeted attacks," Wilhoit as late versus Dark Reading know. According to the researcher criminals focus their sights on SCADA / ICS systems because they are unsafe.

Many HMI machines run on Windows and would not use a virus scanner or are not equipped with the latest signatures. Most malware Wilhoit encountered no problems would be detected by an up-to-date virus scanner. While targeted attacks are still at risk managers should also take into account normal "crimeware", as the consequences can be just as bad. HMI systems are very susceptible to interference. Infection by a banking Trojan can also just as easily get the system down.

Wilhoit saw in October for the first peak in the attacks, but does not know what the occasion is. The criminals behind the malware use spear phishing mails and drive-by downloads to infect computers. Fake websites are used on that instance, resemble those of Siemens and supposedly download a WinCC update, while it is actually malware. Wilhoit 32 recently discovered malware instances that occurred as WinCC software. Next week, the researcher during a conference SCADA give more details about his research.

Sunday, 14 December 2014

Trojan Horse Hidden Communication Via Invisible Internet Project (I2P)



The makers of a Trojan horse that is specifically designed to steal money from bank accounts have released a new variant that uses I2P to communicate with infected computers. I2P stands for Invisible Internet Project (I2P) and is a network layer allowing application messages safely and pseudo -Anonymous can exchange.



According PhishMe security company that the new variant discovered I2P can be seen as a "secure version of Tor". Thus true DNS destination is standard shielded and it features peer-to-peer features, IP2 each node can act as an exit node. At the Tor network servers must be specifically set as an exit node.

In the case of the Dyre banking Trojan , also known as Dyreza, I2P provides the attackers a separate communication channel which is difficult to analyze and detect. Yet managers are not powerless says analyst Ronnie Tokazowski. Indeed, it is possible to capture I2P on the top-level domain (.i2p) off and thus stop the spread and possibly make IP2 traffic network harmless.