Tuesday, 2 December 2014

Sony Pictures Hacked By #GOP (Guardians of Peace)



Previous Sony Pictures (Sony Pictures) computer was hacked US subsidiary, approximately 11TB of important information stolen, GOP (Guardians of Peace) Sony hacker group said the company did not meet their demands, the company did not release more than the movie exposure on the network, speculation Sony Corporation to assassinate Kim Jong-un as the theme of the movie "The Interview" is about to be released, is likely to startle events related to the DPRK.



November 25, 2014, Sony Pictures, the US branch office network is attacked, all office computers are not available, the hacker also left a signature "Hacked By #GOP" and requires the Sony computer and stole Important information about 11TB, mainly some financial documents and password file, the hacker left a message is displayed if Sony Corporation can not meet their demands on the network will be open and stole documents. The incident led to Sony Pictures was hacked office can not work, e-mail and phone systems are all paralyzed.



The Interview - Official Teaser Trailer - In Theaters This Christmas


According to the Re / code website reported, Sony company is investigating whether the incident was related to the DPRK startle. Sony Pictures's latest film The Interview will be December 25, 2014 release, the film tells the story of two American CIA was hiring a reporter to interview, citing the story of trying to assassinate Kim Jong-un, although this is a comedy, North Korea still aroused strong protest, saying it was an unforgivable blasphemy against the Korean people, if the movie release schedule, the DPRK will launch a merciless counterattack, North Korean government has also sent a letter to the Federation Council's Secretary-General Ban Ki-moon, accusing Sony acts of terrorism.

A thread on Reddit provided information on what hackers could have stolen from the Sony pictures system. According to the thread, the data might contain passport and visa information for cast and crew working on Sony movies, Outlook inboxes, documents detailing the company’s IT systems plus accounting and research information- but all this is just a small part of this gigantic breach.

But, this is a surety that most of the data from the breach would be video files and some of them might be pirated movies downloaded by the Sony staff.
  • Adventure Time-2x04a-Power Animal.avi
  • Adventure Time Her Parents.avi
  • Adventure Time The Silent King.avi
  • Adventure Time-2x09b-Susan Strong.avi
  • Adventure Time-2x11a-Belly of the Beast.avi
  • Human.Planet.S01E05.720p.BluRay.x264-SHORTBREHD.mkv
  • Human.Planet.S01E02.720p.BluRay.x264-SHORTBREHD.mkv
  • Human.Planet.S01E06.720p.BluRay.x264-SHORTBREHD.mkv
  • Human.Planet.S01E03.720p.BluRay.x264-SHORTBREHD.mkv
  • Human.Planet.S01E04.720p.BluRay.x264-SHORTBREHD.mkv
  • Human.Planet.S01E01.720p.BluRay.x264-SHORTBREHD.mkv
  • Human.Planet.S01E07.720p.BluRay.x264-SHORTBREHD.mkv
During the week, Sony tried to get its systems up and also analyzed the damage conceded by their systems due to the breaches. But, mid-week four of the Sony movies were uploaded, each within space of few minutes. Only one of these was released in USA, their names are as follows:
  • ‘Still Alice‘ starring Julianne Moore, Alec Baldwin (US date: Jan 16, 2015)
  • ‘Mr Turner‘ starring Timothy Spall. (US date: Dec 19, 2014)
  • ‘Annie‘ starring Jamie Foxx and Cameron Diaz. (US date: Dec 19, 2014)
  • ‘Fury‘ starring Brad Pitt (US date: Oct 17, 2014)
However, there is no official word from Sony but a page from torrent site 1337x says that a user uploaded these video and will reveal another soon that is of an upcoming movie (To Write Love on Her Arms) whose release data is March 2015.


One of the sets from the data involves files that might be of significance to the piracy watchers. List of files below were used by the company Audible Magic and relate to the automatic content recognition systems.


  • audible_magic_sftp_private_key.ppk
  • audible_magic_sftp_private_key.ppk
  • set_ssh-private-key-file.htm
  • audible_magic_sftp_private_key.ppk
  • private_and_private_key.txt
So, it now makes upcoming week lot more fascinating as it remains to be seen how many uploads hackers will do during the week. But, one thing is for sure these hacks will hurt Sony badly not just for months but for many upcoming years.

Monday, 1 December 2014

Virustotal - Added New Tool For iOS & Mac Malware Analysis




VirusTotal.com, the online virus scanner from Google, two weeks ago quietly added a new tool to improve the analysis of suspicious files Mac and iOS apps. Via VirusTotal users can upload files and then to scan dozens of virus scanners.

In addition, the binary contents of each file is scanned, regardless of file type, then to check whether anti-virus companies recognize the scanned code. The new tool launched recently trying executable files Mac OS X and iOS apps to further characterize by finding out interesting features. Thus collected header information of the file, as well as file segments, shared libraries that the file uses, load commands and signature information if the code is digitally signed.

In the case of Mac OS X that contains executable mach-o-files for different systems, each embedded file of the properties will be displayed. When it comes to iOS apps will generate VirusTotal also metadata about the package itself and iTunes detail. Emiliano Martinez VirusTotal hopes that the new tool will help you find and study threats for Mac OS X and iOS.

Recently, Virustotal has expanded the size limit from 64MB to 128MB.

Sunday, 30 November 2014

US Parking Malware



The payment of various car parks in the United States are infected by malware, where possible, data from credit and debit cards from an unknown number of customers have been stolen. Before warns SP Plus an American company that parking services offered to owners of real estate, such as shopping malls and offices.

SP Plus received a message from the provider that manages the payment systems in the parking garages. An attacker could access the remote access tool received from the supplier and so could log on to the payment. There installed the malware attacker could intercept the data of payment cards which was settled in the car parks. It would be the cardholder's details (cardholder's name, card number, expiration date and verification code).

In all, 17 parks have been affected. Whether there actually map data can be stolen SP Plus does not say, but the company decided to issue a warning. Meanwhile, the malware would be disabled on all affected systems. In addition, the company's supplier obliged henceforth to use two-factor authentication when logging on to the payment.

17 SP+ Affected Parking Location's

Wednesday, 26 November 2014

DroidJack RAT Android App Malware



Software developers who first made ​​apps for Android now versatile malware developed for the platform that it include possible to eavesdrop on conversations, intercept WhatsApp messages, looking into the camera or the microphone to listen to the environment. It is a remote administration tool (RAT) called DroidJack.

DroidJack website homepage


In a report issued late last year on Facebook developers claimed that they were novice entrepreneurs. They published at the same time on Google Play app that allows to control a remote computer. Symantec had the legitimate app developers with little success and they then directed their attention to the development of Android malware. DroidJack is now openly available over the internet. The malware will cost $ 210, which buyers also get lifetime support.

In order to carry out the RAT are no root rights are required. Once activated, it is possible to steal files, read WhatsApp messages, calls and eavesdrop on the microphone, see the address book, to operate the camera and the last GPS location to retrieve the device and Google Maps to display. The malware is equipped with a disclaimer, but they come before a judge not get away with, says analyst Peter Coogan.

Some of the Features of DroidJack:
  • No root access required 
  • Bind the DroidJack server APK with any other game or app 
  • Install any APK and update server 
  • Copy files from device to computer 
  • View all messages on the device 
  • Listen to call conversations made on the device 
  • List all the contacts on the device 
  • Listen live or record audio from the device's microphone 
  • Gain control of the camera on the device 
  • Get IMEI number, Wi-Fi MAC address, and cellphone carrier details 
  • Get the device’s last GPS location check in and show it in Google Maps

There are many more features which the App offers.

Disclaimer:

Disclaimer used in DroidJack marketing

Tuesday, 25 November 2014

USB Charger E-Cigarette Spreading Malwares.






Companies must not only pay attention to e-mail attachments and web traffic, even USB chargers can be used for electronic cigarettes to infect computers with malware. That leaves a self-proclaimed IT guy on the popular social news site Reddit know. The IT person tells how a not got closer to said large company with malware. It was the director of the computer where the infection was found.

The system was fully up to date and had up-to-date anti-virus. Seeking a declaration asked the IT department or the director for the past two weeks, maybe something had changed in his life. The man appeared to have switched to e-cigarettes. Further investigation revealed that contained the used USB charger for charging the e-cigarette malware. Once the charger was plugged touched the infected computer malware and made the connection to a remote server.

Boot-Sector Virus


While no further details are shared, let Rik Ferguson of Trend Micro anti-virus company opposite the Guardian know that it is a plausible scenario. "Malware in product lines has existed for years," he notes. There are several examples of MP3 players and digital photo frames that are already in the plant malware infection incur and it then passed on to the consumers who used the equipment. Thus warned consumer electronics giant Samsung still in 2008 that included the installation CD for a digital photo frame malware.

If you want to protect yourself from USB Malware start using USB Condoms by Sync Stop.

More Details by Srlabs : PDF & Video 


Monday, 20 October 2014

Virustotal - Upgraded File Size 64MB to 128MB

Virustotal.com

How To Scan A File of More Than 64 MB FileSize With Multiple Scanners?

Here is a Good News, VirusTotal that provides cloud scan services has expanded to 128MB from 64MB the maximum amount of files that can be scanned. VirusTotal By uploading a file that you specify on the browser, is a cloud scan services that can check the safety of the file by the antivirus engine of more than 50 kinds.

Virustotal Scanners

Until now was a 64MB file capacity that can be scanned, but we make sure that you are able to upload until today 128MB. Because there was a limit of 64MB, if you want to scan a file of more than 64MB, you can scan up to 100MB Dr.Web Online Scanners , you can scan up to 80MB Metascan Online had to be used as alternative means. However, only one type of Dr.Web, anti-virus engine can be scanned by anti-virus engine of 40 or more types of Metascan Online is Dr.Web online scanners, but there was that it pales somewhat when compared with VirusTotal. Scan engine corresponding Among these cloud scan services in many cases, the VirusTotal capacity was also as many as 128MB, utility value should go up more and more in the future. Initially up to 20MB, capacity can be scanned in a stepwise fashion 64MB, and 128MB and up to 32MB followed is up to VirusTotal. You may come to support up to large files more than 1GB in the future.

Here is a List of Online Scanners:

1. Virustotal
2. Metascan
3. NoDistribute
4. Jotti's Malware Scan

Soon I Will Update This List.
Happy Hunting & Be Safe From The Malware.

Monday, 13 October 2014

SEANux OS - A Linux Distribution OS Coming Soon By SEA (Syrian Electronic Army)



Hacktivists of the Syrian Electronic Army (SEA) on Twitter own Linux distribution called SEANux announced. One reason for the launch of its own distribution is not given, but the hacktivists announced that the source code will be, so users can check the operating system. Possible backdoors opensource When SEANux exactly will appear is still unknown, but according to the announcement it will "soon" be.

Previously advised the SEA already to use for security reasons. No American or Russian web services The hacktivists came last year in the news regularly because they managed to hijack. Twitter accounts and web services of all major media organizations

Thus, among other Skype , Microsoft , CNN , recommendation service Outbrain , hosting provider Melbourne IT , chat service Viber , the British newspaper The Guardian , media company Thomson Reuters , satirical website The Onion , business magazine Forbes , Wall Street Journal , advertisements on Reuters.com and Israeli army successfully attacked.

Thursday, 9 October 2014

Botnet of 500,000 computers - Qakbot Malware

The Attack Chain


Researchers have identified a botnet of 500,000 computers discovered that 52% of machinery exists that run on Windows XP. A comparatively very high percentage, since it no longer supported by Microsoft operating system worldwide share of between 14% and 24%.

The computers have been infected with qbot via known vulnerabilities in Adobe Flash Player, Java, Adobe Reader and Internet Explorer, also known as Qakbot. On infected computers qbot steals all kinds of data for Internet banking. Researchers from Proofpoint found that the login data of 800,000 accounts online banking were intercepted. In 59% of these cases involved one of the five largest American banks.

Further figures ( PDF ) show that the malware on the American Internet has provided, since 75% of the infected computers over an American IP address available. especially In addition to steal login details infected machines are also offered for other cybercriminals. Paid as proxy These criminals can the infected computers as a springboard for other attacks use or for storage or transportation of stolen data.

Following are the steps How It works:

1. Infecting Legitimate Websites

Infecting Legitimate Websites

2. Filtering Targets- Traffic Distribution Systems.

Filtering Targets- Traffic Distribution Systems

3. Getting Into The User's Machines -Exploits

Getting Into The User's Machines -Exploits

4. Stealing User Banking Credentials - Malware

Stealing User Banking Credentials - Malware






Monday, 21 July 2014

For copyright infringement Mail.ru blocked in Italy



Mail.ru and 23 internet hosting infringe copyright bootlegging film production.

Rome prosecutor's office has closed access to the Russian Internet site Mail.ru throughout Italy.According to the newspaper Corriere della Sera, citing a statement the prosecutor's office, the Russian Internet portal is accused of violating copyright law.

Investigation initiated Film Company Eyemoon Pictures.Her representatives said that Mail.ru and 23 internet hosting infringe copyright bootlegging film production.

According Eyemoon Pictures, on the Russian Internet portal Mail.ru illegally providing links to two cartoon studios Fruivtale Station and The Congress, which came on the screen back in 2013.After receiving complaints from Eyemoon Pictures prosecutors Rome start "Operation Eyemoon».An investigation was confirmed copyright infringement online resource Mail.ru and other portals.

Prosecutor's Office of Rome made ​​the "black" list of 24 Internet resource.Besides the Russian Mail.ru resource sharing in list got Kim Dotcom Mega, as well as popular torrent trackers.

At the moment in time in Mail.ru search engine you can find links to cartoons companies Fruivtale Station and The Congress.However, the site now provides only a textual description of the above video.

Microsoft launched a website statement for Windows Phone users



Microsoft has launched a website for new users of the operating system Windows Phone, who are unfamiliar with this platform or want to discover new useful features. To demonstrate the capabilities of most systems were dropped short and understandable videos. The company also did not forget to tell how you can easily transfer all your data from Android-smartphone or iPhone.


Watch Video Here .

Personally visit the site to get acquainted with the capabilities of the operating system Windows Phone.

PayPal lets bug webshops arbitrary amount Checkout

Paypal Bug

A bug in the online payment service PayPal enables webshops to settle after the customer has been given. Attachment for a different amount any amount Thus, the customer thinks he is buying something for one euro, for example, while the shop settles 200 euros.
However, the customer receives only the confirmation email from PayPal that 200 euros is charged. The problem is when using the PayPal Express Checkout, says the German security researcher Jan Kechel . This confirms the customer in its PayPal payment environment and think you have judged. After the payment through PayPal, the user is sent back to the shop, where another function is called that allows you to transfer, without the customer has given consent another amount will be.
Kechel discovered the problem and reported it to PayPal. The payment service stated that it is not a bug but is "intended behavior", due to small differences in transport costs and the like. The researcher believes that PayPal however all amounts greater than the fixed amount must confirm this. Again by the customer As evidence Kechel made ​​this demonstration .

First version of Open Wireless Router launched



During the X HOPE conference in New York, the first experimental version of the Open Wireless Router has launched a router update that causes the wifi connection is open for other people put. This open access is controlled by a separate guest area.
This should not only make Internet more accessible, but also improve the privacy and anonymity. An IP address is still almost always traceable to a particular Internet user, if there will be anywhere open Wi-Fi networks that link is not so easy to make more.
User
The software should be easy for users to create finally open while they just own WPA2-protected can hold. Partly for their own Wi-Fi network for others In addition, users will also be able to set how much bandwidth guests get assigned, so that the connection of the owner of the Wi-Fi network does not bother the guests are having.
For now operates the Open Wireless Router Netgear WNDR3800 only on the router. It also includes an experimental version. However, the developers hope that more people will get involved, so the software will soon work on more devices and get more features. Themselves with the project
Thus, it is intended to have an automatic update feature to add that some of the information for the updates will be downloaded, which is a targeted attack on the router "very difficult" to make. Using Tor Owners of a Netgear WNDR3800 who want to go to work with the firmware update can be provided through Openwireless.org download.