Wednesday, 2 April 2014

Ransomware Crypto Defense allows decryption key behind computer victim

Ransomware Crypto Defense contains a crucial mistake: it allows the decryption key back to the computer of the victim.


Symantec analyzed Crypto Defense. The ransomware is part of the extended family of malware programs that encrypt files of victims until a ransom is paid. Crypto Defense uses Microsoft and Windows API to generate Encryption and decryption keys.

Key
Defense Crypto encrypts files using a 2048-bit RSA key. The secret key needed to de-crypt the files will be sent back to the server, the attacker until the ransom is paid again. Apparently the developers did not know that the secret key on the computer of the victim is in a directory containing application data. This key can decrypt the victim his data without the intervention of the cyber criminals. Itself, Unfortunately, the average user will not have enough knowledge to make this actually perform.

Success
Symantec estimates that have received, which shows the effectiveness of the scam. Cyber criminals within one month, more than $ 34,000 in bitcoins.
Symantec has blocked 11,000 Defense Crypto infection attempts in more than 100 countries. The majority of infection attempts were in the U.S., followed by Britain, Canada, Australia, Japan, India, Italy and the Netherlands.

MD5: f57d188c4667fab46208396af20badd2 (Virus Total Permalink)
         60f302b88160c27263c61c7e91dcb94e (Virus Total Permalink)

Tinder plagued by spam bots


A number of users of dating app Tinder reports that they are matched a fake profile of an attractive woman.In reality the automated bots that users want to download. Mobile game "Castle Clash"
The bots display a link to the game via the URL "Tinderverified.com", making it seem like Tinder is the owner of the URL, or is involved in any case in one way or another to the action. This is not the case.
A Reddit user realized what was happening and posted a screenshot. This post now has a handful of responses from others who say they have experienced the same. Also on Twitter More and more reports from people who claim they are matched with a fake profile.
The bot first sends innocent messages like "hey" and "how are you?" then they tell the unsuspecting user that they have such a fun game on their phone, "Castle Clash, have you heard of?" The bot then informs the URL, no matter what was the response of the user.
It is still unclear who exactly is behind the fake accounts, even though the app developer IGG.com course obvious. The company offers dozens of games on the App Store and Google Play. However, it is also possible that the developer himself the victim of an aggressive promotional network as previously happened with the on-demand ride service Uber .
Tinder shows himself to be aware of the problem and said the necessary steps to remove the spam.

Symantec Detailed Report

Tuesday, 1 April 2014

Access and location Tesla only protected by password of 6 characters

The only thing standing between a hacker and a $ 100,000 Tesla is a password of 6 characters, says Nitesh Dhanjani , author of several books on hacking and own a Tesla, at the Black Hat security conference in Singapore Asia. Dhanjani found several design flaws in the security system of the Tesla Model S sedan.
He found no vulnerabilities in the main system and its findings forwarded to Tesla.


Dhanjani states that if your password is stolen or hacked be. Thus easily traced the location of the car.
The car can be opened and belongings in the car to be stolen. To actually start the car does need a key.
When the car is ordered, the user creates an account which is only protected by a password of 6 characters. This password is used for the mobile app and the Tesla online account. The freely available app can determine the location of the car but also certain features of the car monitor and manage. The password is vulnerable to attack the usual methods that are used to gain access. To a computer or online account Thus, it is possible to guess the password, for example, via the website Tesla, as it permits an unlimited number of log-in attempts. "It is quite something when a car of $ 100,000 is only protected by a password of 6 characters" says Dhanjani.


Tesla would not comment on the findings of Dhanjani but spokesman Patrick Jones gave an e-mail to the findings of security researchers to observe and investigate further. Extremely seriously "Together with our team of top-notch security professionals protect our products and systems against vulnerabilities. We also work together with the community of security researchers and encourage them to communicate with us."

Monday, 31 March 2014

Barracuda launches Threat Glass

Barracuda Networks, the provider associated with the cloud storage solutions and ICT security, introduces Threat Glass, an online tool for searching, analysis and exchange of information on websites with malware. With Threat Glass users can see reviews of the infected websites with screenshots of the stages of infection and analyze network issues.

Daily popular websites cyber criminals exploited to. Malware to visitors loose Threat Glass of Barracuda Networks offers both casual users and the research community the opportunity to bring this persistent problem, identify and understand better. Threat Glass was developed as a front-end to a large-scale automated system that uses lightweight visualization for the independent detection of vulnerabilities and abuse thereof (exploits). The platform analyzes millions of websites every week. The websites that are submitted for inspection from various data feeds, including the top 25,000 websites by Alexa, social feeds and suspicious sites that are detected by the worldwide network of customers Barracuda, which spans more than one hundred fifty thousand organizations. Besides screenshots of the infection Threat Glass offers different views of network traffic, including DNS, HTTP and Net flow, in both graphic and text format. The system has about ten thousand live web-based malware attacks mapped to date and adds daily information on new events added.Detection engines from Barracuda Labs have numerous malware infections found in reputable websites. In recent months Barracuda Labs has published analyzes of popular websites like Cracked.com, Php.net and Hasbro.com.Information on this and thousands of other infected websites is now available through Threat Glass

Tuesday, 25 March 2014

XP malware allows criminals ATM emptying via SMS

ATM malware infects a Windows XP installation makes it possible for criminals by sending a single SMS message to retrieve the dispenser. Empty It involves the Ploutus malware last October for the first time in Mexico was discovered, but is now active in more countries.

Two weeks after the discovery of a new variant Ploutus was found . This version was translated not only in English but also had a modular architecture. Anti-virus company Symantec has this version further analyzed and discovered that criminals now the ATM to clean out. via sending text messages.

Attack
To attack the ATM criminals first need to have physical access to it. Then the ATM machine booted from a boot CD. This boot CD contains the Ploutus malware that infects the operating system of the ATM during startup. In addition, the virus may be present, the malware also switches off.

After installation, it is possible to activate Ploutus via a special key combination can be spent on command. Money Criminals straw men gave the command to retrieve the money had to share this key. If the straw men knew what could be done with the key they can light up their client, says Symantec.
Ploutus ATM attack overview


Smartphone
To solve this problem, the criminals can also link a smartphone to the ATM. The already installed malware ensures that the criminal can communicate. Using the smartphone with the ATM This avoids key shared. Lake with the straw man The criminal can now send an SMS to the ATM which then spends the money that is being recorded. Straw man by himself The attacks would have been observed. Different places in the world.

Symantec notes that as encrypted hard drives, which installed the malware may occur. Modern ATMs have better security, Older ATMs, however, would run on XP and are therefore more vulnerable. Ploutus example works only on Windows XP. Banks also get the advice to Windows 7 or 8 upgrade. In addition, the BIOS must be locked so that it can not be booted. From other media.

MD5:
488acf3e6ba215edef77fd900e6eb33b
b9f5bd514485fb06da39beff051b9fdc

Virus Total Link:
https://www.virustotal.com/en/file/0106757fac9d10a8e2a22dce5337f404bfa1c44d3cc0c53af3c7539888bc4025/analysis/

https://www.virustotal.com/en/file/34acc4c0b61b5ce0b37c3589f97d1f23e6d84011a241e6f85683ee517ce786f1/analysis/

Monday, 24 March 2014

White Hat Security company launches "secure browser" on Internet


An American security company claims to have the "most secure browser" launched on the Internet that users must protect. Against both malware and parties who want to violate the privacy Aviator, such as the browser is called, was published last year, the Mac version and now there is also a Windows version.

Aviator has been developed by white hat security and based on Chromium, the open-source browser that is used. Google Chrome The reason it was chosen Chromium is that it has several unique security features, such as a sandbox. White Hat found that Chromium is not safe enough and made ​​an adapted version with more security and privacy settings.

"Google and Microsoft make a lot of money on online ads. Unfortunately, very intrusive online advertising, because you basically follow anywhere on the Internet. Even Mozilla receives most of the revenue through advertisements. Implementing truly effective security and privacy could adversely for their business operations, " said the security company

For example, the default search engine DuckDuckGo instead of Google and integrates the browser Disconnect. An extension that ads and tracking on the Internet blocking. In addition, the browsing history, cache, cookies, auto-complete, and local storage after restarting the browser removed. Standard third party cookies are blocked, plug-ins require an additional mouse to work state Do-Not-Track is enabled by default and minimum data is sent to Google.

Earnings
Although there is little advertising for the Mac version was made, was downloaded thousands of times in recent months. The browser is free to download, but still is underway on a revenue model, allows product management director Robert Hansen know . He gives the guarantee that no money will be earned on the information provided by users, as do many other browsers.
Current users of the browser, however, would be no need to worry, because the browser can always use for free. "Once we have determined how we can make money on new users will only have to pay for a license." In the future, other operating systems are supported. Alongside Mac and Windows

Sunday, 23 March 2014

India is fighting botnets computers with cleaning center


The Indian government is planning to establish that engages in the fight against botnets. A special "cleaning center" In recent years, the number of Indian computers part of a botnet has exploded. In 2007 it went to some 26,000 systems.
In the first half of 2013 the number of bots, however, rose to 4.2 million systems . The increase is explained by the growing Internet usage in India. In addition, it is not just computers that become infected, more and more smart phones would become part of a botnet. Therefore, the government now wants to start a center to end the infection must, along with internet providers said the Deccan Herald.

NSA spying on Chinese networking giant Huawei


The NSA has a widespread espionage attack against China conducted in which both the Chinese government and Chinese companies were targeted. Reports that the German newspaper Der Spiegel on the basis of documents received from the whistleblower Edward Snowden.
Among the attacked companies are banks and telecommunication companies. However, the NSA focused in particular on the Chinese networking giant Huawei, the second largest network provider in the world and a competitor of the U.S. Cisco. In 2009, the U.S. Secret Service began an operation that internal "Shot Giant" was mentioned. A special NSA unit managed to break into the corporate network from Huawei and copied a list of 1,400 customers, as well as internal documents on training were engineers on the use of Huawei products.

Source

From a secret NSA presentation shows that the NSA also managed to gain access to the internal e-mail archive and the secret source of Huawei products. The network where the U.S. Secret Service had broken up generated as many e-mail and data that the NSA did not know what to do with it. The reason for the break-in at the company let the NSA in the documents know that many of the targets via Huawei products communicate. "We want to make sure that we can attack these products," said an official in one of the secret documents.
In a statement, says a spokesperson from the network giant that if the reports are correct it is very ironic, since the United States Huawei always have accused the Chinese government would help in espionage. More details about the espionage attack by the NSA will Der Spiegel published tomorrow.

Wednesday, 19 March 2014

Windows Spyware WinSpy and GimmeRAT monitors Android devices

If you are using Android Phone and syncing with the Windows Operating System for backup and transferring files, Then Be Careful.
Mechanism of attack on financial institution employing WinSpy

Researchers have found by analysis of an attack on a U.S. financial institution Windows spyware that is also able to monitor. Android devices The institution was attacked by a spear phishing email, which had a large NSIS file as an attachment.
Once the file was opened, the recipient was a picture of a payslip to see while installed in the background. WinSpy This is commercially available Windows-spyware which makes it possible to monitor, according to the authors. Computers but also Android devices In a second attack on the institution was again used WinSpy, only the malware was now hiding in an Excel document with a macro.
Once the malware on your computer is active, the attacker can control the webcam, capture screenshots, saving keystrokes, disable security software, downloading and surfing habits chat conversations via the microphone shoot, upload and download files and send messages to the computer.

Android



During the analysis of the malware security company FireEye also discovered various Android components that can be used to monitor the victim. It involves three different applications, one of which only works when the device is connected to the Windows computer while the other two make it possible to control. Android device via SMS
Deployment Scenarios for Android Components

To install the Android spyware must be connected, then the installation takes place. On the infected computer Windows phone Through the Android spyware screenshots can be stolen and it is possible to find out. The location of the target
"These attacks and tools to confirm that we live in an age of digital surveillance and theft of intellectual property. Commercial Remote Administration Tools (RATs) continue to proliferate and are increasingly being used by attackers," said analyst Thoufique HaqHe notes that the rise of mobile platforms like Android, a new market has emerged which also asked about RATs that support these platforms.



Operation Windigo: 25,000 Linux servers infected by malware


In cooperation with the CERT-Bund, the Swedish National Infrastructure for Computing and other institutes, ESET's malware researchers have uncovered an attack by cyber-criminals, currently more than 25,000 Unix monitored worldwide server.
High level perspective of Windigo’s components and their relationship

Due to the attack, the security experts "Operation Windigo" call servers are infected, which then send out millions of spam e-mails. But the criminals have developed a complex system of sophisticated malware components. This pirate servers, infect visiting computers and steal information. Among the victims of "Operation Windigo" include cPanel and kernel.org.
ESET released today under welivesecurity.com / windigo a detailed document that represents the results of the studies and an analysis of malware. A guide provides information about how users can check their own system for infection. In addition, ESET shows how the malicious code can be removed.
Operation Windigo: Over three years have gone unnoticed
While experts have encountered early on parts of Windigo, the full extent and complexity of these cyber criminal organization in the professional sector has remained undetected.


Flowchart of Windigo’s credential stealing scenario
"Windigo has largely won unnoticed by the security community in more than two and a half years in strength and taken control of over 10,000 servers," says ESET security researcher Marc-Etienne Leveille. "More than 35 million spam messages sent every day to the e-mail accounts of innocent users. These clog inboxes and compromise computer systems.'s Worse is that every day half a million computers are running the risk of becoming newly infected. Visiting a web page whose server has been infected by the 'Operation Windigo', ends on dangerous exploit kits or with unwanted advertising. "
Although sites were infected by Windigo Windows computers only contaminate an exploit kit with malware, even Mac users get advertisements for dating sites. iPhone owners will be redirected to pages with pornographic content.
Sysadmins are encouraged to take action against Windigo
About 60 percent of the world's websites run on a Linux server. ESET researchers ask webmasters and system administrators to review their systems to infection.
"Webmasters and IT professionals generally have much going on why we're sorry that we can make them even more work -.. However it is important it is to protect their opportunity and perhaps even duty, other Internet users," says Leveille. "Everyone should strive to prevent the spread of malware and spam. A few minutes can make a big difference and contribute to the solution."
Timeline of Events

Quick-Check for Server
The ESET experts advise Unix server administrators and webmasters, perform the following command. He is quick indication of whether the own server is compromised:
$ ssh-G 2> & 1 | grep-e-e illegally unknown> / dev / null && echo "System clean" | | echo "system infected"
In the case of an established infection ESET recommends to clean the affected computer completely and reinstall the operating system and the software. It is imperative to use new passwords and private keys. The existing credentials might be compromised.
Bitter medicine for Windigo victims
"The Ebury backdoor that was used by 'Operation Windigo', does not use the weaknesses of Linux or OpenSSH from" Leveille continues. "Instead, they will be installed manually by the attacker. It's scary that the cyber criminal group has done this successfully on thousands of different servers. During antivirus programs and two-factor authentication on clients are common, they are rarely on the protection of servers employed. This makes in relation to the theft of access and malware rankings quite vulnerable. "
Should therefore be message in the future about it for a greater degree of protection, also use technologies, such as two-factor authentication.
"We know that cleaning the server and the rebuilding of the systems is a very bitter pill. If attackers have but stolen or cracked administrators access data and were able to establish a remote access to the server, which is the only safe way," said Leveille. "Unfortunately, some of the victims, to whom we have contact, so far done nothing to clean up their systems - and thus bringing other Internet users at risk." All computer users should always remember never to use passwords that are easy to crack or have been used.
More information
A Detailed report on "Operation Windigo" is located here: Eset

Tuesday, 18 March 2014

Intruders attacked Google public DNS server


Traffic to the free DNS service provided by Google last Saturday was hijacked 22 minutes so that the commands and traffic to Google's servers temporarily came out at a Venezuelan network, as claimed BGPmon, a company that monitors network and internet traffic.
Internet, the DNS servers of their own provider replaced by that of Google. The Domain Name System (DNS) is similar to the directory and translates among other domain names into IP addresses. By setting up Google's the DNS servers (8.8.4.4 and 8.8.8.8) Internet users do not ask their provider where the IP address of a given domain name is found, but at Google.

Last Saturday was the traffic to the DNS servers of Google redirected to a network in Venezuela 22 minutes. According BGPmon there was a BGP (Border Gateway Protocol) hijacking. Had implications for both the transmission networks in Venezuela and Brazil. How the hijacking could occur late BGPmon not know, but the possibility of abuse was enormous, the company said on Twitter .

Monday, 17 March 2014

Spyware provider sells smartphones with spyware


A provider of a spyware program for smartphones nowadays also offers aircraft where the spyware already installed in advance. mSpy, the company name, defines its own software as a "powerful monitoring solution" that all activities of the user to follow.
Thus, it is possible to listen in on phone calls to block calls them to read, chat conversations view, browsing history to lock the device, calendar, and view, store, read emails and photos and videos to view keystrokes address book . Spyware which '100% undetectable "would be had to still first be installed. Device
For the cases where this is not possible or too much work, in the shop of mSpy now advance infected devices available.It is a 5 Nexus, Apple iPhone 5S, HTC One and Galaxy S4, including annual subscription to the spyware. According mSpy is to use the spyware is legal, as long as the target in advance is informed and gives consent.

In a Forbes Article highlighting the software, the company founder Andrei Shimanovich, addressing that issue, is quoted as saying:
It is the same question with the gun producer. If you go out and buy a gun and go shoot someone, no one will go after the gun producer. People who shoot someone will be responsible for this. Same thing for mSpy. We just provide the services which can solve certain tasks regarding parents and teenagers.