Showing posts with label Zip File. Show all posts
Showing posts with label Zip File. Show all posts

Friday, 8 May 2015

Australia Warns Of CVs Ransomware

The Australian government has warned companies to resumes that are currently scattered through e-mail and try to infect computers with ransomware. The e-mail suggests someone and says that he has attached his job. It is a zip file that contains a JavaScript file again. Once this .js file is opened, the computer becomes CryptoWall-ransomware infected.

It is the same attack in the April 21 news came. The Stay Smart Online campaign by the Australian government suggests that the attack focuses on Australian companies and a new campaign is active since last week. CryptoWall encrypts files on the computer and then asks for a ransom here. The Australian government warns that many victims recover their files if they pay the ransom, but there is no guarantee, since users have to deal with criminals. "Prevention is therefore the best medicine for ransomware and other malware attacks," the campaign.

Wednesday, 11 February 2015

Chanitor Trojan: "Maleficent Microsoft Volume Licensing Spreading Malware"


Several companies have recently received an email from the Microsoft Volume Licensing Service Center (VLSC) comes appeared and attempts to spread via a clever trick JavaScript malware. Through the VLSC companies to manage their Microsoft licenses. The message that goes around is very similar to the emails that sends Microsoft normally on the VLSC and a personalized salutation. According to the e-mail recipients may register via the attached link for the VLSC.

The link actually points to a hacked WordPress server. Using JavaScript, however, the real-VLSC Microsoft Web site shown where users can log in. However, there is simultaneously a zip file provided that the hacked WordPress server originates.This seems like the file from the Microsoft Web sites originates, although the hacked WordPress server is listed at the download location.

Offered zip file contains another .scr file is a Trojan horse. This "Chanitor Trojan" then connects to the Tor network. According to Cisco, the malware at the time was that the e-mails were detected around 9 out of 57 virus scanners on VirusTotal.

Hashesh:

1b147fc9d5342ca0fa59207d366ec4fb  (VLSC Microsoft.zip)

6266dc7f68e98b3a52908a7e2b5fe4eb (Volume_Licensing_Service_Center_details_7834892334.scr)