Showing posts with label Yonathan Klijnsma. Show all posts
Showing posts with label Yonathan Klijnsma. Show all posts

Wednesday, 9 September 2015

Website Headache Centers New Twitter Malware



At several websites attackers have posted malicious code that attempt to infect visitors with malware. It is the Society's website of Dutch Headache Centers and New Twitter, says security researcher Yonathan Klijnsma via Twitter.

In the case of New Twitter that Twitter has more than 10,000 followers, the added code points to the Angler-exploitkit. This exploitkit uses known vulnerabilities, including Adobe Flash Player. What malware is being spread Klijnsma do not know by exploitkit. Angler among other things used to install the Bedep Trojan on unpatched computers.

This Trojan may download additional malware onto the computer and use the system for various forms of cyber crime, such as click and advertising fraud. Klijnsma, also a researcher at the Delft security firm Fox-IT, warned in recent weeks regularly for hacked websites which malware spread. According to the researcher, there is a campaign in which criminals hack into websites and provide malicious code.

Saturday, 5 September 2015

Security Professionals On LinkedIn Stalked By Fake Recruiters


Several security professionals who are active on LinkedIn, have been the target of fake recruiters who probably tried to map the social circle and connections. The Dutch security researcher Yonathan Klijnsma warned two weeks ago for the 'recruiters'.

Also employees of the Finnish anti-virus firm F-Secure were approached by the fake accounts, which utilized under different from stock photos. The "recruiters" were mainly as employees of Talent Sources and approached security professionals through a standard message from a recruiter. What was the real purpose is unknown. Possibly this was an experiment to test how sensitive security professionals for social engineering. The accounts of the 'recruiters' appeared after some time to disappear. Still, warns Sean Sullivan from the F-Secure it is hoped that no one has given the fake accounts important information.

Tuesday, 18 August 2015

Ransomware-Maker: The Victims Have Paid More Attention


A new ransomware variant that has been in development since early this year has a real roadmap for victims to explain the situation they find themselves in, where users also clear that the infection is their own fault. The ransomware was discovered by the Dutch security researcher Yonathan Klijnsma , who works at the Delft Fox-IT.

CryptoApp, as is called ransomware encrypts files with 162 different file extensions, like .docx, .avi and .xslx. Remarkably, according Klijnsma that files from QuickBooks accounting software is encrypted. Once active on a computer, the ransomware is looking not only at local disks for files to encrypt, but also relied network drives. As with other ransomware variants must then be paid an amount to decrypt the files.


It is in this case to an amount of 1 bitcoin, what with the current exchange rate 231 euros. On the website of the ransomware is user-maker explained their situation. As the author states that victims have been infected because they have not been paying attention. Also, the computer of the user according to the ransomware maker poorly protected and the files can be recovered only by paying. Thereby paying victims are advised to turn off their virus scanner.

The tool for decrypting the files can namely be considered as malware and removed by the virus. In that case, users will lose all their files, according to the warning. According Klijnsma the ransomware is not widespread and probably still in development. The website of the ransomware-maker, which was hosted on the Tor network, early August is gone. It may be that the author, the project has stopped or a new location sought to continue its operation, with the old website was a test setup, the researcher says.

Wednesday, 17 June 2015

Infected Ads On Popular Dutch Websites


Besides the Telegraaf recent days more popular Dutch websites infected with malware ads appeared that visitors were trying to infect. It also involves volkskrant.nl , trouw.nl , parool.nl and dumpert.nl , reports the Dutch security company SurfRight .

Yesterday it was announced that several major websites was an active advertising campaign which focused specifically on the Dutch internet users. The ads would be June 11, the websites have appeared. Besides Dutch websites the ads were also Dutch visitors theguardian.com , huffingtonpost.com , lemonde.fr and elle.com shown. According SurfRight contain ads malicious code that uses known vulnerabilities in Adobe Flash Player.

If users have installed the latest version of Adobe Flash Player they run no risk. The installed version of Flash Player can on this page to be viewed. Is there a vulnerable Flash Player version on the computer and the attack successfully, the Bedep Trojan is installed.

This Trojan for Windows can install additional malware, but what the final load is still unknown. The advertising platform for displaying the ads late charge that the infected ads in question have since been removed, so says security researcher Yonathan Klijnsma Fox-IT.

Friday, 27 March 2015

Thousands Hacked WordPress Sites Spread Malware


In recent weeks, thousands of hacked WordPress sites which are then used to distribute malware. It also involves several Dutch websites including nummeriban.nl , hoofdpijncentra.nl and the website of Dries Roelvink. That leaves the Dutch security researcher Yonathan Klijnsma today know.

Fiesta Exploit Kit Gate
On the hacked WordPress sites is an iframe placed visitors, without this, have, to a exploitkit forward. This exploitkit uses known vulnerabilities in Adobe Flash Player, Adobe Reader and Java to infect users. However, if users use the latest version of these plug-ins they run no risk. "There are thousands of websites that contain this iframe at this time. From the data I have is about 3,000 websites, but this is probably only a fraction" says Klijnsma.

In case the attack, there can be all kinds of malware installed successfully, including ransomware encrypts files that sorts to Trojan specifically designed to steal money from online bank accounts. According Klijnsma the WordPress sites hacked through a leak in the RevSlider plugin. This is a known vulnerability for which an update is available. Webmasters have not rolled out the update. Owners of a WordPress site then also be advised to both the content management system as installed plug-ins to keep up-to-date.

Xtube Porn Spreading Malware Via Flash Attack


Visitors to the porn xtube are now warned cyber criminals have hacked the website and use it for distributing malware. Xtube 780 ranked of most visited websites in the United States and would have to deal with 25 million visitors every month.

Unlike other recent attacks are widely used in the case of infectious xtube no ads, but the attackers have malicious code placed directly on the website itself. Something which is possible only if the attackers have access to the website. The code sends users unnoticed through to another website which then tries to put through a known vulnerability in Adobe Flash Player malware on the computer.

It is a vulnerability that already has a security update has been released. Users who have the latest Flash Player version available are therefore not at risk. In case the attack was successfully placed a Trojan horse on the computer. The malware was detected at the time of the attack by 12 of the 57 scanners on VirusTotal, says anti-virus company Malwarebytes .

It is not just porn sites that are victims of these attacks. This week, the Dutch security researcher warned Yonathan Klijnsma that the website nummeriban.nl where users can convert to an IBAN account number, also malicious code was detected. The malicious code sent by visitors to a website that users via known vulnerabilities in Adobe Flash Player, Java and Adobe Reader tried to attack.

Sunday, 11 January 2015

Steam Will Combat Malware With Captcha


The popular online game distribution platform Steam, with more than 100 million active users, has taken measures against malware that attempts to steal virtual goods. Steam users are regularly targeted by phishing attacks and malware. The Dutch researcher Yonathan Klijnsma He recently made ​​a comprehensive analysis of Steam malware. The malware attempts virtual goods that allow users to move their account to other accounts, where they are eventually sold at physical money.

To thwart this type of malware must now enter a captcha in the trading of virtual goods. "We know this is annoying, and we want to make it act not difficult for our users, but we expect that will help users who are tempted to install malware and so lose their stuff," says John Cook from Valve, the company that Steam developed. Cook asked users what they think of the captcha, which now yielded 700 responses, many of which are negative.


Wednesday, 7 January 2015

Users Report Malicious Ads On Skype


Several users report that Skype they were seeing in the use of the popular VoIP software malicious ads to a fake Adobe website creature that tried to install malware. According to the malicious website, the user must update their Flash Player.






In reality, it was malware. Users wonder how the ads could pass the filters of Microsoft. The software giant has not yet responded to the ads, though a Skype employee on the Skype forum to affected users asking whether they have a " Fiddler trace can make. " This would help to find the malignant advertisement in question.


It would not be the first time that Skype is the target of "malvertisement". Last year, the Dutch security researcher Yonathan Klijnsma did know that he had found on Skype malicious ads. A problem with the ads on Skype is a "AdBlocker" that users use their browsers not working for these ads.