Showing posts with label botnet. Show all posts
Showing posts with label botnet. Show all posts

Thursday, 19 November 2015

Botnet Tool Uses Twitter Direct Messages



Cyber criminals can control their botnet recently via Direct Messages on Twitter. The Python program Twittor called, was designed by the idea of GCAT, a similar program cyber criminals command & control servers to be managed via Gmail. Twittor made ​​by self-appointed security researcher Paul Amar and available from September, but is now observed by Sophos.

The tool uses direct messages on Twitter. The "advantage" of them, as compared to the conventional way of managing command & control servers, which the Direct Messages on Twitter are private. And the traffic is not stopped with IP filtering because Twittor use the Twitter API.

In addition, Twitter announced earlier this year that the limit of 140 characters is widened in private messages. This will therefore also more malicious traffic. The limitation is that there is a maximum of 1 000 direct messages per day can be sent.A botmaster can therefore no more than approximately 100 bots manage per account.

Many security tools such as Nmap and Metasploit, are not only useful for cyber criminals also useful for security researchers. Publishing a free tool that makes it possible to create a botnet via Twitter Direct Message operate seems an odd way of security research, says John Zorabedian Sophos.

Monday, 5 October 2015

AV-Test Lab: Linux User Without Virus


The amount of malware for Linux is still very limited, especially compared to Windows. Nevertheless, even Linux systems with malware become infected. In addition, Linux systems are often used in Windows environments and thus come into contact with Windows Malware. Astute Linux users, however, need to install a virus scanner, according to the German test lab AV-Test.

AV-Test decided 16 different security packages for Linux with both Linux and Windows Malware to test an Ubuntu system.The results are disconcerting for some products, because they are by letting 85% of the Windows Malware and up to 75% of the Malware Linux. Eight of the sixteen security suites able to detect between 99.7% and 99.9% of the 12,000 common Windows Malware. Only Symantec scores 100%. McAfee and Comodo scoring with 85.1% and 83% respectively lower.Much worse are the results from Dr. Web (67.8%), F-Prot (22.1%) and ClamAV (15.3%).

Tested for the second part of the test was 900 malware instances for Linux. Kaspersky'm here solely to detect all malware, followed by ESET with 99.7%. AVG scores 99%, followed by the server versions of Kaspersky and Avast that detect more than 98% of malware. Symantec, which identified all Windows Malware recognizes 97.2% of Linux Malware. The other products scored less well, with ClamAV, McAfee, F-Prot Comodo and finish at the bottom. The detection rates lie between 66.1% and 23%.

Linux And Malware


The question remains to what extent it is necessary for Linux users to install a virus. According to AV-Test, the number of Trojans for Linux has increased recently, but they are of poor quality. This is according to the test lab because attackers are aware of good security practices that Linux offers. There is then also especially the ignorance of users use, for example, which become infected by operational errors.

The most common way to become infected by Malware Linux is by installing software updates or via third parties, according to AV-Test. The software will ask during the installation to temporary root privileges. If the user allows this software to the system will be manipulated and attackers can install a backdoor on the system and is it part of a botnet.

According to AV-Test, most Linux users believe that they are one of the safest systems available use. "This statement is true if you only look at the system and leave the rest aside." Insecure third-party software and user errors can ultimately ensure that a Linux system, like Windows and Mac with malware gets infected.

Research by anti-virus companies shows that many infected Linux servers that are part of a botnet. Linux-based botnets often remain even longer operational because the servers do not use security software, unlike Windows Servers where this is the case. And if there is already software installed are often the wrong products. "In many Linux Forums free Comodo products, ClamAV and F-Prot be recommended to home users. This is not good advice", says AV-Test.

The test shows that home better for the free versions of Sophos or Bitdefender can choose. For server systems, there is the free scanner from AVG. ESET is as a whole out on top, followed by Symantec and Kaspersky. For servers are Kaspersky, AVG and Avast recommended.

Virus Scanner Necessary?

Or Linux Users must install a virus is ultimately to their own behavior. AV-Test says that security suites are only a second line of defense. The main security is in fact the user. Anyone who loves his system up-to-date, no unnecessary ports opens, only install software from trusted sources, prevents the browser to run active content and not open just e-mail attachments will do when it comes to Linux Malware no worries make, according to the testing lab.

Saturday, 26 September 2015

Porn XHamster Spread Malware Weather


For the third time in a year there are again infected ads on the most popular porn xHamster published that attempted to infect visitors with malware. XHamster receives nearly half a billion monthly visitors and is on the 71st place of most visited websites on the internet.

The infected ads first carried out various checks. Thus, it ensures that the visitor Internet Explorer and certain security tools such as Wireshark and Fiddler active, said anti-malware company Malwarebytes. In case it IE users without said security tools went unnoticed was a page loaded with the Nuclear-exploitkit. This exploitkit uses known vulnerabilities include Adobe Flash Player and Internet Explorer users have not patched.

In the case the attack was successful was ransomware and other malware installed. After being informed removed the ad network TrafficHaus infected ads. A few days later appeared again malicious ads on xHamster. This time the browser was based Brow lock ransomware spread. This ransomware is not on the computer, but locks the browser via a special JavaScript and states that the user must pay to get access again.

Again TrafficHaus was informed. Malwarebytes but does not know if the second round with malicious ads has been removed. In January and April also appeared already contaminated ads on xHamster.

Wednesday, 23 September 2015

Swiss Government Warns Of Contaminated Ads


The Computer Emergency Response Team (CERT) of the Swiss government has warned Internet users to infected ads that tried to install a Trojan horse. The ads were distributed through a popular Swiss ad network was hacked.

The ads were equipped with malicious code that abuse of known vulnerabilities in Internet Explorer, Firefox, made Java or Adobe Flash Player. In case users this software were not up to date and had a German or French institution, the Gozi Trojan was installed. This is a Trojan specifically designed to steal money from online bank accounts. The version that was spreading through the ads focused on five Swiss and two Thai sofas.

According to the Swiss CERT are potentially hundreds of thousands of Internet users become infected through contaminated ads. Last Friday, the owner of the botnet suddenly decided to remove the malware. All the infected computers were instructed to uninstall the Trojan horse. The reason is unclear, according to the CERT. The government organization thinks the botnet administrator may have earned enough money or that he saw the CERT operation had been discovered and therefore decided to disable the botnet.

Thursday, 6 August 2015

Gang Stealing An Estimated $ 100 Million Of Accounts


A large group of more than 50 cyber criminals stole recent years to an estimated $ 100 million of bank accounts and between 20 and 30 terabytes of data captured. The FBI and security Crowd Strike and Fox-IT today announced at the Black Hat conference in Las Vegas announced.

The gang used the Game Over Zeus malware, a Trojan horse that was on the infamous Zeus Trojan based and was mainly used to steal data from online banking and other services. Game Over Zeus botnet was last June by the FBI, Europol, several companies and police forces from the extracted air . Early this year, the FBI put $ 3 million on the head of a Russian man suspected of developing Game Over Zeus.

Today published data show that the botnet from an average of about 200,000 systems existed. Besides also steal money from bank accounts, the gang held behind Game Over Zeus engaged in espionage in Eastern European countries. In total, there would be via the malware 20 to 30 terabytes of data have been stolen. It also appears from the investigation of the criminals that they are well organized. The gang calls itself the "business club" and consists of more than 50 people. The Russian man who is wanted by the FBI was always seen as a mastermind Game Over Zeus, but he would not be the sole leader of the group of criminals. According to the researchers, there is someone else with whom he leads the gang together.

Wednesday, 29 July 2015

Internet Again Exposed To Contaminated Ads


In recent weeks several popular websites appeared infected ads, making the potential for at least 10 million Internet users have run risk of infection. The actual number of people that the received ads to see infected and as a consequence thereof became infected is not known. The ads pointed to a copy of the Angler Exploitkit.

This exploitkit tries users silently through vulnerabilities in popular software such as Adobe Flash Player to infect with malware. It regularly happens that the ads or exploits are displayed only to visitors from certain countries. In case the infected advert appears the attack can only succeed if the visitor uses the attacked software or browser plug-in instance is not up to date.

The sites where the ads would appear according to statistics from security Cyphort SimilarWeb and get at least 10 million visitors per month. The most popular websites showing the infected ads were found in Vietnam, Greece, Indonesia and Thailand. Earlier this month, the ads were also found on the Japanese edition of the Huffington Post. Earlier this year warned Cyphort even for infected ads on popular websites. Even when it came to the Huffington Post.

Saturday, 11 July 2015

Botnet Firefighter Destroys Petabytes Of Hard Disk Drives With Drill


For permanently erasing hard drives is often the free open source program DBAN recommended, but for organizations with large amounts of hard disks can be very laborious. It is also possible that the hard drive has failed and is no longer so clear.

The Netherlands-based Shadow Server Foundation, an organization dedicated to the fight against botnets, recently had to destroy a petabyte of failed hard drives. Since the organization mainly depends on sponsors and donations, enabling a company was to let the hard disks fee not destroy seen as a good expense.

The solution was for less than 360 euros a drill, a holder, drills, bought a broom and dustbin. Subsequently drill holes in all hard drives. "Maybe it was not the best method to spend our time and holes, it solved our problem to clean up a petabyte hard disks," the organization a number of photos put online by the operation.

Saturday, 20 June 2015

Research: Botnets Consist Of Average 1700 Computers



In the first quarter of this year were from botnets average 1700 computers, claims ISP Level 3 on the basis of own research ( pdf ). For the study 600 to 1000 Command & Control servers were monitored allow cyber criminals to control infected computers.

The number of computers part of a botnet accounted fluctuated considerably in the first months of this year. So it went in January to an average of 3,763 computers, but this was dropped in March to 338 computers. According to Level 3 is due to the decline in the "vigilance" by the security community. Computers that are part of a botnet are found mainly in China and the United States, each with more than half a million infected machines, followed by Norway with 213,000 "zombies."

Norway was in the first quarter, also the target of the most botnet traffic, followed by the US and Spain. The presence of Norway is explained by a single incident where a botnet server was hosted within a specific hosting environment.

Netherlands

The report also mentioned several times Netherlands. For example, the Netherlands is in fourth place worldwide in countries that generate botnet traffic and in third place in Europe. "From a global perspective, the Netherlands is higher in relation to other European countries. The top 10 listing is primarily due to a large and heavy port scanner which made a number of victims in the Nordic region," says the report. It is further stated that the Netherlands provides a "robust infrastructure," making it "ideal" is to centralize botnets in the region.

Saturday, 13 June 2015

IBM Sees Weather DDoS Attacks From Bill Gates Linux Botnet


A botnet that infects Linux computers and used to carry out DDoS attacks is active again, says IBM. It's the "Bill Gates botnet" which last year was first detected, reports IBM . The bot-amplification uses DNS to carry out the DDoS attacks.

With DNS amplification open DNS servers are used to enhance the traffic to the attacked websites or services. An interesting feature of this malware, according to the Russian anti-virus company Dr. Web together with the Finnish F-Secure paid attention to the last year malware. According to the Russian virus fighter is the Gates-malware also allegedly found because of a sophisticated modular structure that never experienced Linux malware.

At the time, it was unknown how the malware was spreading. Something where IBM still has no answer. It is not known who is behind the botnet. However, the company argues that there has been observed a significant increase in traffic, which are used forged packets and the destination IP address in China.

Saturday, 6 June 2015

Skype Botnet Spread Adware Disabled


Researchers in collaboration with Amazon and Microsoft disabled a botnet that focused on Skype users and adware spread. The botnet's popular VoIP software used to infect users. The criminals behind the botnet used all kinds of usernames called Skype users and immediately hanged. The username pointed to an area where there is a video message would wait.

On the website in question, however, was offered a file called VideoPlayer.exe adware which turned out to be. According to the website users had to install the file if they did not see the video message. To disrupt the botnet, researchers from PhishMe first look at the IP addresses used. It appeared that the cyber criminals used Amazon for their hosting. The researchers then warned that Amazon could take the Internet giant steps.


Furthermore, Microsoft was informed so that it could tackle the usernames that were used for the distribution of adware. "If users are trained to recognize suspicious cases, the amount of information you get back a hundred-fold increase," says Ronnie Tokazowski of PhishMe. In this case you could use the information of a user who PhishMe eventually be warned disordered many adware campaign.

Tuesday, 12 May 2015

Large DDoS Botnet Of Tens Of Thousands Of Routers Discovered


Researchers have discovered a worldwide botnet consisting of tens of thousands of hijacked routers and is used to carry out DDoS attacks on websites. Reported security Incapsula in a new report . Although the hijacked routers were found in 109 different countries, found that a majority (85%) is located in Brazil and Thailand.

The routers are in turn controlled via servers which are in China and the United States. The researchers thought initially that the routers were acquired via a vulnerability in the firmware. Further investigation showed, however, that all devices were accessible through the standard ports HTTP and SSH. Was not changed in almost all cases the default password.

Thus, the attackers were able to install the "MrBlack" malware on the routers. In addition, a script on the hijacked routers installed it looked for other vulnerable routers. To avoid getting users advised to change the default password such attacks, install the latest firmware and ensure that the operator interface is not accessible via HTTP or SSH. Something that through this tool can be controlled.

Friday, 8 May 2015

Infected Ads On Dozens Of Porn Sites Discovered


The past week has been on dozens of porn sites infectious ad appeared that visitors via a known vulnerability in Adobe Flash Player tries to infect with malware. Among the stricken porn sites, which together have 250 million visitors are drtuber and nuvid the largest.

Unlike many infectious ads that visitors unnoticed forward to another site, the ad used to contain pornography directly exploitable, which makes abuse of the vulnerability in Adobe Flash Player, as reported anti-virus company Malwarebytes.The ad would be distributed through an advertiser on the AdXpansion ad network. In case the attack success are different infected files placed on your computer. Visitors to porn sites whose Adobe Flash Player up-to-date are not at risk.

Wednesday, 29 April 2015

Weather Infected Ads On Porn xHamster


On the popular porn xHamster again infected ads have appeared that attempt to infect visitors with malware. In late January it was even hit on the porn site, which according to Alexa is on the 68th place of most visited sites on the Internet and gets 514 million visitors monthly.

The ads direct visitors unnoticed to another page where the Angler Exploitkit runs. This page checks to see if the visitor uses the virus from Kaspersky Lab or Norton. If this is not the case, then it is decided to attack the user further. The Angler Exploitkit makes abuse of vulnerabilities in Internet Explorer, Java, Silverlight and Adobe Flash Player. Anti-virus firm Malwarebytes suggests that only an old vulnerability in Internet Explorer is used in the attack.

Is the attack successful, is the Bedep malware installed. The same malware that also the end of January on the website was spread via infected ads. Bedep making computers part of a botnet and can then install additional malware. Once active Bedep used infected computers to commit fraud advertisement. Additionally silently loads the Magnitude Exploitkit, which also makes abuse of vulnerabilities, provide users with additional malware can become infected.

Sunday, 12 April 2015

Beebone Malware: FBI Praises Cooperation With Dutch Cyber Cops


The FBI is proud to work with the High Tech Crime Team (THTC) of the Dutch police that this week along a botnet pulled off the air. It was a joint operation of the THTC, the FBI, Europol and various security companies was against the malware, which in the press releases of the various investigative services Beebone or AAEH was mentioned.

However, the malware also known as Vobfus and Changeup, Symantec, so let know . It is a worm that first appeared in 2009 and spread through the Autorun feature of Windows. A year later, the worm used the LNK vulnerability allowing the Stuxnet worm spread knew. There were also social engineering used by Changeup.

Working of Beebone Malware
On infected USB drives and network folders worm placed a copy of itself with the names Porn.exe, Sexy.exe, Passwords.exe and Secret.exe and created the executable files with the names of all existing files. These files have a folder icon, so it seemed like it was a folder. Since Windows file extensions by default does not show users could thereby unintentionally activate the malware.

Additional malware

Changeup active once installed all sorts of malware, including malware that tried Internet banking data and passwords to steal, as well as fake virus scanners and ransomware, according to the FBI. The US investigation service went to court with a request to take up 100 domain names that use the botnet to communicate with infected computers. Something the judge gave permission. Then the investigative services were these domains to the servers of Internet providers and Computer Emergency Response Teams (CERTs) of views on the world.

"Botnets as Beebone have made ​​all over the world victims, which shows why a joint approach to global investigative services with the private sector is so important. The FBI is proud to cooperate in the fight against botnets with our partners in the European Cybercrime Centre of Europol, the Joint Action Cybercrime Task Force (J-CAT) and the Dutch High Tech Crime Team, " said FBI Assistant Director Joseph Demarest.

Tuesday, 7 April 2015

Linux Server Australia Hacked Through Unknown Leak


The organization of Linux Australia, an Australian organization that organizes various Linux Conferences and commitment to the open source community in the country, has recently been faced with a hacked server, where possible personal data captured.

That the organization this weekend via its mailing list disclosed. On March 22, there was a large number of system messages sent from the conference management server. This server is used to host various conferences. The messages were generated automatically by the system. Further investigation on March 24 showed that the server on March 22, was hacked.

Under Linux Australia managed to cause the attacker to an unknown vulnerability a buffer overflow and then got root privileges on the server. The attacker installed below a remote access tool to control the remote server and installed software to the server part of a botnet. At the time of the attack, the attacker access to personal information including name, address, phone numbers, email addresses and hashed passwords.

However, the organization says it has found no evidence that there are data captured, but assumes the worst scenario.Because of the attack have been taken several measures, including the removal of all malicious software. In addition, the compromised server will be discarded and there is now set up a new server. The security of this server will be strengthened, including through a rigorous update schedule, duplicating logs and running of user accounts three months after the conference.

Saturday, 14 March 2015

Small Percentage Of Botnet Servers Hosted In Netherlands


Two years ago there was still controversy when McAfee reported that the Netherlands in the Top 3 countries stood with most botnet servers, but now the situation has changed, according to anti-virus firm Trend Micro. The virus fighter analyzed more than 3,000 servers for botnets in 2014 infected computers were aiming. It turned out that was hosted 2.6% of botnet servers in the Netherlands.

This puts the Netherlands in ninth place in the list of countries. Leader is the USA (21%), followed by the UK (9.5%) and India (6.1%). If there specifically looked at botnet servers used in targeted attacks coming Netherlands not even appear in the list.Trend Micro noted that the location of a botnet server says nothing about the country or the criminals behind the infection.


"Most botnet servers are not located in countries that are thought to shelters for his cybercrime panels. Instead, it is a reflection of the wider internet landscape where countries with an extensive infrastructure all kinds of servers hosting that are popular with cybercriminals," said the researchers

Tuesday, 3 March 2015

Anti-virus company: Europol Operation Failed Against Botnet


The operation against the Ramnit botnet that Europol several European investigative services and security last week performed partly failed, causing hundreds of thousands of computers controlled by cybercriminals, according to the Russian anti-virus company Doctor Web.

In the operation were seized hundreds of domains that the botnet used to communicate with infected computers, as well as different servers. The Ramnit malware did over a period of almost five years in total to infect 3.2 million computers. The last half year were approximately 500,000 computers have been infected with the malware.

Doctor Web suggests that there are several variations of Ramnit are active, including one which since September 2011 has been announced. This version can steal all kinds of passwords and FTP programs would have on hundreds of thousands of computers are active every day. "Despite the message in the media about a successful operation against the Ramnit botnet, our analysts have no decrease seen botnets that monitors the anti-virus laboratory," the anti-virus company.

According to researchers from the virus fighter would definitely twelve Ramnit botnets operate. Two of these botnets exist together from more than 500,000 infected computers. "The figures show that the parties behind the operation to destroy the botnet Ramnit evidently not been able to turn off all servers of this botnet," as the researchers conclude whatsoever.

Thursday, 26 February 2015

FBI Put $ 3 Million Head Of Cybercriminal


The FBI has offered a reward of $ 3 million put at the head of an unknown Russian cybercriminal who is considered the mastermind behind the Crypto Locker ransomware and the Game Over Zeus botnet. Last year there was a large-scale international operation against the botnet and ransomware place where the Russian was indicted by the US authorities.

Game Over Zeus malware that the man would have developed is a Trojan horse that is based on the infamous Zeus Trojan and was mainly used to steal data for online banking and other services. The malware that infected hundreds of thousands of computers over the years, would have caused more than $ 100 million in damage.

Game Over Zeus botnet was next to steal credentials used for spreading the Crypto Locker ransomware. This ransomware encrypted files on computers and gave users not access it if they ransom paid, which could amount to hundreds of dollars.Estimated Crypto Locker would have until April 2014 hostage together 234,000 computers. The FBI estimates that in the first two months that Crypto Locker active victims were paid a total of $ 24 million.

Nine months later, the Russian cyber criminals still on the run. According to the FBI maintains the man in Russia, but it may be that he travels abroad. To convict him is now $ 3 million awarded for the golden tip that leads to an arrest and / or conviction.

Wednesday, 25 February 2015

Large Botnet Achieved By Europol In The Air


Europol has partnered with European investigation services a large botnet off the air that had infected 3.2 million computers worldwide. It involves Ramnit botnet that for years was active and on infected computers include passwords booty made ​​and other data.

Computers were infected by opening links in spam emails and visiting infected websites. Ramnit is also a so-called "file infector" who .exe, .dll- and .html files on hard drives and connected storage devices infected. Once a computer became infected malware added the infected code in these files, and as soon as they were started spreading the infection further. Also were found public FTP servers that were used for distributing Ramnit.

In addition to investigative agencies from the Netherlands, Italy, Germany and Britain Europol coordinated the operation with Microsoft, Symantec and Anubis Networks . During the operation of the botnet Command & Control servers were turned off, and the 300 domains that were used to control infected computers.

"This successful operation demonstrates the importance of cooperation between international investigative agencies and private industry in combating cybercrime. We will remain committed to disable botnets and disrupting the infrastructure used by criminals for cyber crime," said Wil van Gemert, Deputy Director of Europol. Microsoft and Symantec have now been delivered solutions to remove the malware from infected computers.

Monday, 9 February 2015

DDoS Botnet Is Linux Servers Via SSH


Linux Servers are already several months the target of a DDoS botnet machines via SSH trying to take over in order to use them subsequently for DDoS attacks. The attack consists of three different phases where tens of thousands of passwords are trying to log in via SSH.

The botnet infected machines leaving out a certain number of times to log in before the next IP address is used to carry out the attack. According to security firm FireEye use the assailants include a modified version of the Rock You password list .In case the login attempt is successful is immediately logged out. Within 24 hours is logged in from a different IP address.The attackers do this in a way that they know to bypass the default logging and thus leave no trace.

After being signed is ultimately the "XOR.DDoS" malware installed. On the honeypotservers of FireEye were nearly 1 million logins attackers observed within three months. According to researchers at the company XOR.DDoS one of the more advanced malware families for Linux. It also supports multiple platforms, including x86 and ARM. "Network devices and embedded systems are vulnerable to brute force SSH attacks," said analyst Michael Lin.

He notes that it is not always possible or apparent to end users how these systems can be protected against these attacks.However, users are advised to set as their SSH server that encryption keys are used instead of passwords. Furthermore, it is advised to turn off the remote login to the root account. Also the use of fail2ban is recommended.

"Brute force attacks are one of the oldest attacks. Because it avoids many there are plenty of solutions available to protect against it. Yet many systems vulnerable," Lin says. He warns that the brutal Forcen of credentials in the Top 10 of methods is allowing companies to be hacked.