Wednesday, 3 June 2015

Ransomware Maker Decrypts As Promised Infected PCs


The creator of the Locker-ransomware has promised as encrypted files on all computers he infected without charge and automatically decrypted. The ransomware had for some time on computers running before it on May 25 suddenly proceeded to encrypt files.

At various forums complained large numbers of users that their files were encrypted suddenly. Unlike other ransomware variants, which require hundreds of dollars, Locker asked a sum of 22 euros for decrypting the files. Rich is the author therefore did not become. According to Symantec, he would total 152 euros received 22 victims.


Last week the ransomware maker on Pastebin posted a message in which he regret expressed. It was at its say never been his intention to spread the ransomware. He compiled a file with all the encryption keys available and stated that on June 2, all remaining infected computers would be automatically decrypted. And the author has fulfilled that promise, reports Bleeping Computer . For users that their computer had been disinfected, there is a unlocker tool made ​​available. How to distribute the ransomware is managed is still unknown.

Armed Door Cannot Save Cybercriminal Twins



In Russia, in an operation police arrested two brothers who were members of a gang of cyber criminals and had taken all kinds of measures designed to prevent an arrest properly. That leaves the Russian security company Group-IB , which was involved in the operation, know today.

The brothers, who are twins, were in the past been convicted of cyber crime. They were still in their probationary period when they end of 2011 again took to the wrong path. Only in mid-2012 the Russian police to identify the brothers. It took three years before all the evidence had been collected. The brothers were found to use malware to gain access to bank accounts and intercept SMS codes. On May 20, police found surgical site which was directed against the brothers and other members of the gang.

During the raid showed that the brothers were well prepared for the arrival of the police. Thus, the apartment was equipped with armored door, there was an electromagnetic transducer for destroying computer equipment. Also, the brothers had prepared special SMS alerts to warn other members that they had to destroy material. In the raid, the brothers tried to destroy all the material by the money, USB sticks and mobile phones by flushing the toilet.

Researchers: VPN Service Hola Big Security Risk



The free VPN service Hola appears not to be used for DDoS attacks, malware also communicated over the network. In addition, the software is such a big security risk that users can better remove VPN service, say researchers at security company Vectra.

Last week Hola came into the news because it resold the bandwidth of users to other parties. Someone who knew the company did then the bandwidth to be used for a DDoS attack. Also, researchers discovered several vulnerabilities, making it possible to track users and to execute arbitrary code on computers. The CEO of Hola promised improvement and suggested that the vulnerabilities were corrected, although researchers contradict this.

Malware

The DDoS attack via the VPN service is no exception, because cyber criminals Hola appear to have been longer in sight.During investigation of the Hola protocol Vectra researchers discovered five malware instances that also use the protocol."Not surprisingly, this means that the bad guys already realized the potential of Hola before the power of public reports published by the good guys", so put them in this analysis .

The investigation revealed further problems upwards. In addition to behave like a botnet contains Hola according to researchers various opportunities that seem to have been a targeted by introducing a human-driven cyber attack on the network from which the computers of the Hola-user stand.

It also appears Hola additional software without knowledge or consent of the user to download and install. This is possible because Hola after installation installs its own certificate on the computer. This additional code can be installed and run without the user would not be informed. "These capabilities allow a skilled attacker to execute almost everything," said the researchers. They also advise users to remove the software.

Samples Hashes:

SourceForge Stopped Bundling Adware



The popular site for open source SourceForge has stopped bundling adware with projects that are not managed, so the website will know. Recently, the site "simply refusing offers from third parties" decided in a small number to join unmanaged SourceForge projects.

It would be to pass a test, but after criticism from the media and users decided to turn it back. Website Ars Technica recently reported how the setup of the graphical editing tool GIMP for Windows adware was provided. The creators of GIMP would have the project eighteen months ago abandoned and SourceForge not use more as a download location. SourceForge continued to offer the download, only includes an installer containing advertisements and tried to install any other software.

Several other projects were hosted on SourceForge ever were air adware installer, such as VLC, Firefox, Drupal and many other tools. Although the administrators of the software no longer maintained through SourceForge, the software was still available via the website. Removing an open source project on SourceForge would namely very difficult to be. As for bundling adware will only take place through an "opt-in" of developers that are still active on the website.

Free Sandboxes For Malware Analysis Compared


On the Internet are several free tools available that makes it possible to analyze malware. Tools, for example, can be very useful in security incidents, according to the Belgian security analyst Koen van Impe. Companies can find through the analysis of malware for example, other infections on their network and thus take measures to protect systems.

Van Impe decided to various free solutions to look for analyzing malware, namely VirusTotal , Anubis , VxStream and Malwr , then to compare them. Thus, among other things, examined what file formats the solutions can go, including Office, PDF, Android, Windows and PDF, or hashes are displayed, an API is available and whether there are network activities are displayed.

Users are warned by Van Impe that public sandboxes public. "You have to realize that everything you share or upload these sandboxes is accessible to everyone, including the bad guys." In some cases, according to the analyst wise malware specimens that are used for a specific environment not upload to a public service, because otherwise you can let the attackers know that their operation has been detected.

Tuesday, 2 June 2015

VPN Service Hola Promises Improvement After DDoS Attack


VPN service Hola has promised change after the bandwidth of users were used to carry out a DDoS attack and leaks were discovered in the software, but researchers are not convinced. Hola is an extension for Google Chrome offers users a free VPN connection.

What many people do not know is that the company behind the VPN service sells the users of bandwidth via a service called Luminati. Luminati gives parties that pay access Hola network. Recently knew anyone to use this service for a DDoS attack on the 8Chan website. Hola got them to endure a storm of criticism and the founder of 8Chan advised users to uninstall the software.

In addition, several vulnerabilities were discovered in the software that could allow an attacker to execute arbitrary code in the worst case to the computer. In a statement CEO Ofer Vilenski states that there is "growing pains" and that some allegations in the media are unjustified. However, the company will take various measures.

Bandwidth sharing

The first measure concerns about sharing of bandwidth. Through a P2P network called Hola thought it was clear to users that their bandwidth was used. Something not subsequently turns out to be, according Vilenski. Therefore, it still will be clearer for users to communicate. Furthermore, the CEO that there are not used as much bandwidth users, namely 6MB per day.

This bandwidth should be accessible only to business customers. In the case of DDoS attack that took place last week did a 'spammer' to pretend to be a company and were not noticed by Luminati. To avoid repetition have changed several processes.In addition, a Chief Security Officer will be appointed.

Vulnerabilities

Further Vilenski points to two vulnerabilities that were discovered and now would be patched. Hola also run some code by a third party and there will be a "bug bounty" program to be launched, in which hackers and researchers who report vulnerabilities are rewarded. Despite the words of the CEO are the researchers who discovered the vulnerabilities unconvinced.

According to them, the problems still exist and Hola has only made ​​cosmetic changes so that their demonstration of the leak has stopped working. "Many of the problems are ignored, and some claims are simply not true", so leave them on the website Adios-Hola.org know.

1.25 Million Japanese Pension Data Stolen Via Virus


Japan Pension Service has warned today that data from 1.25 million Japanese are stolen after employees had open infected e-mail attachments. The attachments were found to contain a virus that names, addresses, birth dates and retirement numbers booty made.

The president of the Japan Pension Service made ​​during a conference apologized and said that all affected persons receive a new pension number. The organization has also removed all infected computers from the local network and employees from their work computers can no longer access the internet. What type of malware responsible for the attack, the president did not tell because of the ongoing investigation, reports the Japan Times .

Ransomware-Maker Repents And Gives Decryption Keys Away




Last Monday, numerous computers suddenly by a new ransomware variant called Locker hit a small amount to the victims asked for decryption, but the automaker would now regret his actions and provides all the decryption keys free of charge.

In addition, the ransomware on June 2 will automatically create all encrypted files accessible. Locker really came up out of nowhere. The ransomware had for some time on computers running before it on May 25 suddenly proceeded to encrypt files.At various forums complained large numbers of users that their files were encrypted suddenly. Unlike other ransomware variants, which require hundreds of dollars, Locker asked a sum of 22 euros for decrypting the files.

On Saturday put someone who "Poka Bright Minds" calls a message on Pastebin . In it he claims to be responsible for Locker. According to him it was never intended to spread the ransomware. The online storage Mega he has now a file with bitcoin addresses and keys installed. The forum Bleeping Computer confirms that the file actually contains the keys of victims. In addition, on June 2, the automatic start decryption. How the malware spread exactly is still unknown.

File Information 
Name: database_dump.csv
Size: 127.5 MB
MD5: d4d781412e562b76fe0db0977cf6279b
SHA-1: 6ba671ce2a6c256c74d7db81186b0dbddd5e2185
SHA-256: d7fd791b86615fada64fe0290aecb70e5584b9ac570e7b55534555a3b468b33f

VirusTotal Link

Mega Link

Leak In Older MacBooks Makes Installation Possible Rootkit


A security researcher has discovered a vulnerability in the firmware of several older Apple MacBooks, allowing an attacker could install malware. The latest models do not seem to be vulnerable, but 100% sure researcher Pedro Vilaca not, he tells on his blog.

Vilaca discovered that he is the Unified Extensible Firmware Interface (UEFI) can adjust from "userland". UEFI is the successor to the BIOS and a new model for the interface between the computer's operating system and the platform firmware.The UEFI code should normally be inaccessible to users but the researcher discovered that the code is accessible after a computer is restarted and is in sleep mode.

The problem is in MacBooks for mid-2014 and is mounted on a MacBook Pro Retina MacBook Pro 8.2 and a MacBook Air.Through the vulnerability it is possible to install a rootkit. An attacker does not even have a physical access, since the leak via Safari or attack another attack vector distance is.

The researcher thought that Apple knew of the problem, but that turns out not to be so. So it is a zero-day vulnerability for which no security update Apple has released. Users also are advised to completely turn off their computers and not to put into sleep mode. Vilaca further advises to mail Apple asking for a firmware update.

Monday, 1 June 2015

NSA Should Stop Large-Scale Data Storage Phone



The US National Security Agency, the mass collection of phone records of US citizens now stop the Senate no agreement has been reached on an extension of Section 215 of the Patriot Act. Through this legislation, the NSA was authorized to store massive conversation data and store. In total expired three commissions of the Patriot Act, says civil rights movement EFF .

It is the section that used to store the state of your phone data and business data, the " lone wolf "provision and" roving wiretap "provision. Preliminary section 215 will be reversed to the state of the Patriot Act, which does not allow financial or communication data storage and requires the government consults specific facts to show that works a target for a foreign government.

During a heated debate showed Sen. Rand Paul know that he is afraid that the new legislation would introduce the US government, the Freedom Act, the NSA still gives wide powers. The new standards would require that telecommunications companies to store the data, which can then be retrieved after a court order by the NSA. According to Paul, his general orders the reason that the American Revolution was fought.

Senator Bob Corker said that the government has the effectiveness of a major program to national security limits as well as the ability to fight terrorists. Other senators are calling for swift action to take and implement the Freedom Act. Despite the expiration of Section 215 of the EFF states that the US government had sufficient authority has to store and process data.

French Prime Minister Wants To Use Hackers Jihadists


French Prime Minister Manuel Valls wants Hackers jihadist recruiters and propaganda on the Internet wagers, so he has this week during a speech at the Dauphine University in Paris know. Valls announced several measures to combat online jihadists. Thus there will be "community managers" appointed who will keep an eye on extremists on the web.

Extremists who are under Valls getting smarter on the Web. It is therefore important to have the same tools and people with adequate knowledge, said the premier. In addition to police officers why he wants to use hackers and technicians. The hackers aim to monitor online jihadists and try to identify them, reports The Local according to French media . Since the terrorist attacks in France earlier this year, the French government set aside 60 million euros to combat radicalization, where there are "cyber patrols" social media occur.

Cybercriminals Steal 60 Million Of Russian Banks


Cyber ​​criminals have stolen 60 million last year from Russian banks and their customers, as announced, the Russian Central Bank. This involves both attacks on online banking users as attacks against the banks themselves. So last year was several times for attackers gained access to ATMs and so could control the issuance of banknotes.

An analyst of the Russian anti-virus firm Kaspersky Lab opposes SC Magazine that these attacks are mainly possible because the ATMs are still running on Windows XP. In addition to these direct attacks on banks virus fighter saw the number of Trojan horses that was designed to defraud online banking increase by a factor of nine.

According to a spokesman of the Russian Central Bank passed the number of attacks on bank accounts last year 300,000 operations, allowing the Russian banking system would be the most vulnerable in Europe. Due to the increased activity of cyber criminals looking Russian banks also new guidelines to tighten security.