Tuesday, 9 December 2014

"Turla Linux Malware" - Researchers discover espionage virus for Linux


Researchers from the Russian anti-virus firm Kaspersky Lab have discovered a spy virus for Linux that may go unnoticed for years, although for the latter is no proof yet. It is a variant of the Turla malware, also known as Snake or Urburos which all other known specimens have been developed only for Windows.

The researchers knew that there are Linux versions of Turla existed but had never yet found in the "wild" so far. Turla according to Kaspersky Lab is one of the most sophisticated espionage campaigns ever discovered . Among others, the Belgian Ministry of Foreign Affairs would have become the victim of the campaign. The now discovered Turla variant supports Linux so that there can be infected with more systems attacked organizations.

"We suspect that this part years was active in an organization attacked, but have no concrete evidence to prove it," said Costin Raiu of Kaspersky Lab. Through the malware an attacker can communicate with infected systems and execute arbitrary code. Thereby Turla do not need elevated privileges. Also, the malware can not be found via netstat, a tool that system administrators use to get an overview of open network connections.

"It uses techniques that do not require root access, so it can move freely on the system of a victim. Even if it's a regular limited user launches can continue to intercept the incoming packets and execute commands on the system," says Raiu . He notes that the Linux malware especially in other public source code is based, in which the attackers a number of things have been added. How the malware spreads exactly is not reported.

Monday, 8 December 2014

"More openness required --> Antivirus companies on government spyware"

Regin Malware

Anti-virus companies have to be more open about the government spyware that they find, says security expert Bruce Schneier . Schneier reigns on the discovery of the highly advanced Regin malware , which would be by the US and British intelligence developed .

Anti-virus companies have known for some time of the malware, but made ​​the existence of Regin until the end of November to the public. It was the first that Symantec came out with a publication because it knew that another party would reveal the malware. This party was news The Intercept. After the report, Symantec also followed F-Secure and Kaspersky Lab with their own findings. All three follow the anti-virus companies said Regin years, where she copies of years ago found.

"Why were all these companies Regin long secret and why they showed us all this time vulnerable?" Schneider asked. Self thinks the expert that the anti-virus companies no incomplete picture wanted to express. Unlike malware cybercriminals is the effect of government spyware much more complex. In addition, Regin was only used against specific targets, which makes it difficult to obtain copies.

"If you're big in the press comes with a newly discovered malware copy you want to have the whole story. Apparently no one thought they had it with Regin," said Schneier. The expert, however, find this no excuse. "Now government malware more often will come we will often not have the whole story." As long as nations will fight each other over the internet, according to the expert, some individuals or organizations are the target and the residual risk to be hit inadvertently by this type of malware.

Even more

Schneier believes that anti-virus companies are at the moment even more incomplete stories on all government malware. "But they should not do. We want and need that our anti-virus companies us all about these threats tell as soon as they can, and not wait for the appearance of a political story so they can no longer remain silent."

Saturday, 6 December 2014

Preinstalled Malware on Cheap Android Devices - Death Ring


Researchers have found in several Android phones malware advance was already installed. It comes to phones that are sold mainly in Africa and Asia, such as Vietnam, Indonesia, India, Nigeria, Taiwan and China. The phones are standard Trojan horse called "Death Ring" that occurs as a ringtone app.

In reality, the app SMS and wapcontent of the Command & Control server to download to the phone, says security firm Lookout . The malware is activated in two ways, depending on how the user uses his phone. The malware is activated when the phone is restarted five times. In addition, start the malicious service if the victim fifty times are unlocked device.

Lookout has described various scenarios malware can do on a phone, but has no concrete examples. However, the company warns that the malware can not be removed by a virus app, as it is in the system directory. Which is added in the supply chain the malware is unknown. Consumers also are advised to pay attention to where the equipment they buy comes from.

The infections were detected forged Counterfeit Samsung GS4/Note II Various TECNO devices Gionee Gpad G1 Gionee GN708W Gionee GN800 Polytron Rocket S2350 Hi-Tech Amaze Tab Karbonn TA-FONE A34/A37 Jiayu G4S – Galaxy S4 Clone Haier H7 No manufacturer specified i9502+ Samsung Clone

It is not the first time that pre-installed malware on Android devices found .

Friday, 5 December 2014

SONY - Malware Analysis

The malware was used recently against Sony is the same " destructive "malware that the FBI this week warned. Reported that the Japanese anti-virus company Trend Micro that a copy of the malware got hold. The main part of the malware is a collection of user names and passwords to be logged on shared network drives.



Once active users remove the malware files and files connected network drives and stops the Microsoft Exchange Information Store service. Then the malware two hour idle and then restart the system. Another part of the malware puts a .bmp file on the computer that contains the message "Hacked by #GOP". This is the same image that would have appeared on the computers from Sony. Trend Micro therefore proposes that the malware that was used against Sony.

Here is Deep Analysis of Destructive Malware By Some Security Research Companies:

Trend Mirco
Kaspersky
Symantec
BlueCoat

VirusTotal Link:
https://www.virustotal.com/en/file/4d4b17ddbcf4ce397f76cf0a2e230c9d513b23065f746a5ee2de74f447be39b9/analysis/1417763962/


Thursday, 4 December 2014

Kaspersky - Regin Malware Copy 1999

The Russian anti-virus firm Kaspersky Lab has a copy of the advanced Regin-espionage malware found in 1999. This involves the oldest copy that is known up to now. Earlier, a specimen was labeled in 2003 as a senior. The existence of Regin was recently made ​​public by several anti-virus companies.

Regin Platform Diagram

An analyst at Kaspersky Lab named the malware even more sophisticated than Stuxnet . Yet there was also criticism of the anti-virus companies as long as they would have waited to disclose the information. The Russian anti-virus company this refers to a comparison of Sean Sullivan from F-Secure. He likened the search for Regin with the work of paleontologists who found the bones of an unknown dinosaur. Everyone has a bone, but the entire skeleton is missing.


In the case of Regin Kaspersky Lab discovered in 2012 damaged "bone" of a hitherto unknown malware. Figuring out the size of a particular campaign or espionage malware family can sometimes take months or years, the company notes. As it sometimes worked with other parties who may have other parts of the malware possession. "It makes little sense to publish your discovery until you can confirm that the samples really are big and dangerous," said the Russian anti-virus company.

Most Regin copies date from 2007, 43 pieces in total, followed by 35 copies in 2009. Kaspersky also addresses accusations that anti-virus companies, the existence of Regin would have concealed. "We have never been asked by a customer or government agency to whitelist certain malware or to pass through. We would never meet such a request, no matter who it comes from."


Wednesday, 3 December 2014

ESET & Facebook Works Together To Fight Against Malware




To protect users from malware, Facebook has signed a cooperation agreement with ESET's online virus scanner and will of the Slovak anti-virus company now offer to users. The online virus scanner is to start directly from Facebook.

"We have cooperated with ESET to add their security software directly to our detection and prevention systems, just as we did earlier this year with the other providers," says Facebook engineer Chetan Gowda. Facebook previously signed a similar agreement with the Finnish F-Secure and Japanese Trend Micro online virus scanners which were already integrated into Facebook.

If the computer of a Facebook user behaves erratically and shows signs of a malware infection, a message appears that an online virus scan is offered. Then, the user can perform the scan, the results and remove malware without the need to first log out of Facebook.

According Gowda help the three anti-virus companies in this way in blocking malicious links and malicious websites in the news feeds and messages from the 1.35 billion Facebook users. Users often miss the most basic security to prevent infection and remove, observes the engineer on.

Google - Captcha Fighter Against Robots

Google has a new captcha developed to distinguish people on websites of robots, whereby it is no longer necessary to solve a puzzle first. CAPTCHAs are used inter alia for the automatic creation of accounts and post spam on websites counter.

To often distinguishable robots people must puzzles and distorted texts are resolved. Google uses recaptcha example, where there are words from books must be retyped. Our own research shows that the search giant artificial intelligence with an accuracy of 99.8% can solve the puzzles. According to Google would therefore be much easier to apply directly to users whether they are human or robot. This allows users to quickly register or use of a service, which also eliminates the annoyance of solving the captcha.



API

A new API (Application Programming Interface) makes this captcha experience now possible. On websites that use the API receives a large number of users the ability to attach a single click that they are not a robot. Although this sounds simple, the underlying technology is complex, according to the search giant. Last year was a special backend developed that performs a risk if users want to solve a captcha.

On the basis of the way in which the user handles were examined with the captcha or the user was a human. The new API is a development of this, which is looked at many factors which indicate that it is a human being. Where does the risk of insufficient evidence to make this decision will appear captcha again. In addition, the API also makes it possible to test other types of captcha's. The new API would now be used on various websites, including Snapchat, WordPress and Humble Bundle.


Tuesday, 2 December 2014

Sony Pictures Hacked By #GOP (Guardians of Peace)



Previous Sony Pictures (Sony Pictures) computer was hacked US subsidiary, approximately 11TB of important information stolen, GOP (Guardians of Peace) Sony hacker group said the company did not meet their demands, the company did not release more than the movie exposure on the network, speculation Sony Corporation to assassinate Kim Jong-un as the theme of the movie "The Interview" is about to be released, is likely to startle events related to the DPRK.



November 25, 2014, Sony Pictures, the US branch office network is attacked, all office computers are not available, the hacker also left a signature "Hacked By #GOP" and requires the Sony computer and stole Important information about 11TB, mainly some financial documents and password file, the hacker left a message is displayed if Sony Corporation can not meet their demands on the network will be open and stole documents. The incident led to Sony Pictures was hacked office can not work, e-mail and phone systems are all paralyzed.



The Interview - Official Teaser Trailer - In Theaters This Christmas


According to the Re / code website reported, Sony company is investigating whether the incident was related to the DPRK startle. Sony Pictures's latest film The Interview will be December 25, 2014 release, the film tells the story of two American CIA was hiring a reporter to interview, citing the story of trying to assassinate Kim Jong-un, although this is a comedy, North Korea still aroused strong protest, saying it was an unforgivable blasphemy against the Korean people, if the movie release schedule, the DPRK will launch a merciless counterattack, North Korean government has also sent a letter to the Federation Council's Secretary-General Ban Ki-moon, accusing Sony acts of terrorism.

A thread on Reddit provided information on what hackers could have stolen from the Sony pictures system. According to the thread, the data might contain passport and visa information for cast and crew working on Sony movies, Outlook inboxes, documents detailing the company’s IT systems plus accounting and research information- but all this is just a small part of this gigantic breach.

But, this is a surety that most of the data from the breach would be video files and some of them might be pirated movies downloaded by the Sony staff.
  • Adventure Time-2x04a-Power Animal.avi
  • Adventure Time Her Parents.avi
  • Adventure Time The Silent King.avi
  • Adventure Time-2x09b-Susan Strong.avi
  • Adventure Time-2x11a-Belly of the Beast.avi
  • Human.Planet.S01E05.720p.BluRay.x264-SHORTBREHD.mkv
  • Human.Planet.S01E02.720p.BluRay.x264-SHORTBREHD.mkv
  • Human.Planet.S01E06.720p.BluRay.x264-SHORTBREHD.mkv
  • Human.Planet.S01E03.720p.BluRay.x264-SHORTBREHD.mkv
  • Human.Planet.S01E04.720p.BluRay.x264-SHORTBREHD.mkv
  • Human.Planet.S01E01.720p.BluRay.x264-SHORTBREHD.mkv
  • Human.Planet.S01E07.720p.BluRay.x264-SHORTBREHD.mkv
During the week, Sony tried to get its systems up and also analyzed the damage conceded by their systems due to the breaches. But, mid-week four of the Sony movies were uploaded, each within space of few minutes. Only one of these was released in USA, their names are as follows:
  • ‘Still Alice‘ starring Julianne Moore, Alec Baldwin (US date: Jan 16, 2015)
  • ‘Mr Turner‘ starring Timothy Spall. (US date: Dec 19, 2014)
  • ‘Annie‘ starring Jamie Foxx and Cameron Diaz. (US date: Dec 19, 2014)
  • ‘Fury‘ starring Brad Pitt (US date: Oct 17, 2014)
However, there is no official word from Sony but a page from torrent site 1337x says that a user uploaded these video and will reveal another soon that is of an upcoming movie (To Write Love on Her Arms) whose release data is March 2015.


One of the sets from the data involves files that might be of significance to the piracy watchers. List of files below were used by the company Audible Magic and relate to the automatic content recognition systems.


  • audible_magic_sftp_private_key.ppk
  • audible_magic_sftp_private_key.ppk
  • set_ssh-private-key-file.htm
  • audible_magic_sftp_private_key.ppk
  • private_and_private_key.txt
So, it now makes upcoming week lot more fascinating as it remains to be seen how many uploads hackers will do during the week. But, one thing is for sure these hacks will hurt Sony badly not just for months but for many upcoming years.

Monday, 1 December 2014

Virustotal - Added New Tool For iOS & Mac Malware Analysis




VirusTotal.com, the online virus scanner from Google, two weeks ago quietly added a new tool to improve the analysis of suspicious files Mac and iOS apps. Via VirusTotal users can upload files and then to scan dozens of virus scanners.

In addition, the binary contents of each file is scanned, regardless of file type, then to check whether anti-virus companies recognize the scanned code. The new tool launched recently trying executable files Mac OS X and iOS apps to further characterize by finding out interesting features. Thus collected header information of the file, as well as file segments, shared libraries that the file uses, load commands and signature information if the code is digitally signed.

In the case of Mac OS X that contains executable mach-o-files for different systems, each embedded file of the properties will be displayed. When it comes to iOS apps will generate VirusTotal also metadata about the package itself and iTunes detail. Emiliano Martinez VirusTotal hopes that the new tool will help you find and study threats for Mac OS X and iOS.

Recently, Virustotal has expanded the size limit from 64MB to 128MB.

Sunday, 30 November 2014

US Parking Malware



The payment of various car parks in the United States are infected by malware, where possible, data from credit and debit cards from an unknown number of customers have been stolen. Before warns SP Plus an American company that parking services offered to owners of real estate, such as shopping malls and offices.

SP Plus received a message from the provider that manages the payment systems in the parking garages. An attacker could access the remote access tool received from the supplier and so could log on to the payment. There installed the malware attacker could intercept the data of payment cards which was settled in the car parks. It would be the cardholder's details (cardholder's name, card number, expiration date and verification code).

In all, 17 parks have been affected. Whether there actually map data can be stolen SP Plus does not say, but the company decided to issue a warning. Meanwhile, the malware would be disabled on all affected systems. In addition, the company's supplier obliged henceforth to use two-factor authentication when logging on to the payment.

17 SP+ Affected Parking Location's

Wednesday, 26 November 2014

DroidJack RAT Android App Malware



Software developers who first made ​​apps for Android now versatile malware developed for the platform that it include possible to eavesdrop on conversations, intercept WhatsApp messages, looking into the camera or the microphone to listen to the environment. It is a remote administration tool (RAT) called DroidJack.

DroidJack website homepage


In a report issued late last year on Facebook developers claimed that they were novice entrepreneurs. They published at the same time on Google Play app that allows to control a remote computer. Symantec had the legitimate app developers with little success and they then directed their attention to the development of Android malware. DroidJack is now openly available over the internet. The malware will cost $ 210, which buyers also get lifetime support.

In order to carry out the RAT are no root rights are required. Once activated, it is possible to steal files, read WhatsApp messages, calls and eavesdrop on the microphone, see the address book, to operate the camera and the last GPS location to retrieve the device and Google Maps to display. The malware is equipped with a disclaimer, but they come before a judge not get away with, says analyst Peter Coogan.

Some of the Features of DroidJack:
  • No root access required 
  • Bind the DroidJack server APK with any other game or app 
  • Install any APK and update server 
  • Copy files from device to computer 
  • View all messages on the device 
  • Listen to call conversations made on the device 
  • List all the contacts on the device 
  • Listen live or record audio from the device's microphone 
  • Gain control of the camera on the device 
  • Get IMEI number, Wi-Fi MAC address, and cellphone carrier details 
  • Get the device’s last GPS location check in and show it in Google Maps

There are many more features which the App offers.

Disclaimer:

Disclaimer used in DroidJack marketing

Tuesday, 25 November 2014

USB Charger E-Cigarette Spreading Malwares.






Companies must not only pay attention to e-mail attachments and web traffic, even USB chargers can be used for electronic cigarettes to infect computers with malware. That leaves a self-proclaimed IT guy on the popular social news site Reddit know. The IT person tells how a not got closer to said large company with malware. It was the director of the computer where the infection was found.

The system was fully up to date and had up-to-date anti-virus. Seeking a declaration asked the IT department or the director for the past two weeks, maybe something had changed in his life. The man appeared to have switched to e-cigarettes. Further investigation revealed that contained the used USB charger for charging the e-cigarette malware. Once the charger was plugged touched the infected computer malware and made the connection to a remote server.

Boot-Sector Virus


While no further details are shared, let Rik Ferguson of Trend Micro anti-virus company opposite the Guardian know that it is a plausible scenario. "Malware in product lines has existed for years," he notes. There are several examples of MP3 players and digital photo frames that are already in the plant malware infection incur and it then passed on to the consumers who used the equipment. Thus warned consumer electronics giant Samsung still in 2008 that included the installation CD for a digital photo frame malware.

If you want to protect yourself from USB Malware start using USB Condoms by Sync Stop.

More Details by Srlabs : PDF & Video