Showing posts with label trojans. Show all posts
Showing posts with label trojans. Show all posts

Tuesday, 12 April 2011

Ransom Trojan locks Windows

Ransomware is slowly becoming quite a problem, and the latest one spotted by F-Secure tries a rather innovative approach: it locks the victims out of Windows and doesn't allow them boot Windows in either normal or Safe mode until they have entered a code to "complete activation":



Posing as a legitimate Microsoft action, the scammers claim that the activation is "absolutely free and is simply a formality." The victims are offered six phone numbers to which they can place a call, enter a given code and once they receive an activation key, enter it and gain access to their computer again.

The note says that the call from the victim's county is free of charge, but that's a complete lie. The calls purportedly go to Microsoft call centers, but these numbers belong to rogue call centers seemingly located in countries such as the Dominican Republic or Somalia - i.e. countries with expensive phone rate.

But, these rogue call centers are actually located in countries the calls to which are much cheaper than to the previously mentioned ones, so the scammers and the owners of these call centers split the difference in the fee.

F-Secure's Mikko Hypponen demonstrated how the scam works, and says that no matter how many times and to which of the offered numbers one makes the call, one is forced to listen to a four minutes long prerecorded message that reveals at the end always the same activation code: 1351236.

You Windows can be unblocked only by entering the code or formatting your hard drive and restoring its contents from your backup - there is no other way.

[net-security]

“Facebook Support. Your password has been changed!” contains trojan

MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subject “Facebook Support. Your password has been changed! ID09687″. Note that the number may change with each email.

The email is send from the spoofed addresses:

account@facebook.com
manager@facebook.com

The message has the following body:
Dear user of FaceBook.
Your password is not safe!
To secure your account the password has been changed automatically.
Attached document contains a new password to your account and detailed information about new security measures.
Thank you for your attention,
Your Facebook
The attached ZIP file has the name New_Password_IN04393.zip, note that the number at the end will change, and contains the 33 kB large file New_Password.exe.

The trojan is known as Gen:Heur.VIZ.2 (BitDefender), Mal/FakeAV-JX (Sophos), Trojan.Generic.Bredolab-2 (ClamAV).

The following files will be created:

%System%\document.doc

Several Windows registry changes will be exectued and the trojan can establish connection with the IP 193.106.34.20 on port 80.

Data can be obtained from following URLs:
  • hxxp://profmiale.ru/TGQW4nHJOS/document.doc
  • hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=8
  • hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=9
  • hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=uploader
  • hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=grabbers
  • hxxp://profmiale.ru/TGQW4nHJOS/grabbers.php
  • hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=0
  • hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=1
  • hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=2
  • hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=3
  • hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=4
  • hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=5
  • hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=6
  • hxxp://profmiale.ru/TGQW4nHJOS/load.php?file=7
At the time of writing, only 6 of the 42 AV engines did detect the trojan at Virus Total.

Virus Total permalink and MD5: ecc2d442886b7296b5bd7eaeaae0bcea.

[ComputerSecurityArticles]

Sunday, 20 March 2011

A Good Decade for Cyber Crime

Cybercrime is one of the most successful and lucrative industries of our time, growing by double digits year after year.

Over the last decade, cyber crooks have developed new and sophisticated ways to prey on an explosion of Internet users, with little danger of being caught.

Meanwhile, consumers face greater risks to their money and information each year.

A few famous exploits illustrate different eras of cybercrime:


“I Love You” worm’s false affection: $15 billion estimated damage
Emails with the subject line “I love you” proved irresistible in 2000. Millions of users downloaded the attached file, which was supposedly a love letter but was actually a virus. This infamous worm cost companies and government agencies $15 billion.


MyDoom’s mass infection: $38 billion estimated damage

This fast-moving worm, which first struck in 2004, tops McAfee’s list in terms of monetary damage. It delivered enough spam to slow global Internet access by 10% and reduce access to some websites by 50%, costing billions of dollars in lost productivity and online sales.


Conficker’s stealthy destruction: $9.1 billion estimated damage

This 2008 worm infected millions of computers. It went a step further than the other two worms on our list, downloading and installing a variety of malware that gave hackers remote control over victims’ PCs.
Some of the most common and nefarious scams include:


Fake antivirus software

Selling fake antivirus software is one of the most insidious and successful scams in recent years.
Cyber criminals play on users’ fears that their computers and information are at risk, displaying misleading pop-ups that prompt the victim to purchase antivirus software to fix the problem.
When victims enter their credit card information, it is stolen and, instead of security software, they wind up downloading malware.


Phishing scams

Phishing, or trying to trick users into giving up personal information, is one of the most common and persistent online threats. Phishing messages can come in the form of spam emails, spam instant messages, fake friend requests, or social networking posts.


Phony websites

In recent years, cyber crooks have become adept at creating fake websites that look like the real deal.
From phony online banking to auction sites and e-commerce pages, hackers lay traps in the hopes that you will be fooled into entering your credit card number or personal information.

For your own peace of mind, consider subscribing to an identity theft protection service such as McAfee Identity Protection, which offers proactive identity surveillance, lost wallet protection, alerts when suspicious activity is detected on your accounts, and access to fraud resolution agents. For additional tips, visit CounterIdentityTheft.com.


Robert Siciliano is a McAfee consultant and identity theft expert. See him explain how to protect yourself from identity theft on CounterIdentityTheft.com. (Disclosures)

[InfoSecIsland]

Inside the Cybercrime Underworld: 100 Billion Spam E-Mails a Month

American and German researchers who infiltrated and crippled one of the world’s biggest spam-producing networks last summer have released a formal paper on the experience, and the numbers are staggering.

The Pushdo/Cutwail “botnet” sent out 1.7 trillion e-mails over 15 months (about 113 billion per month), had 100,000 enslaved “bots” around the world and had about 30 command-and-control servers in

Europe, North America and Russia.

Its Russian cybercriminal operators bought and sold e-mail addresses by the million and compromised PCs by the thousand, with lower prices for less-desirable countries and volume purchases.

[Read the original research paper here (PDF).]

"The interesting things were just the amount of spam that they were sending and how they operate like a professional business, with detailed statistics and error reporting,” Brett Stone-Gross, one of the researchers and a doctoral candidate at the University of California, Santa Barbara, told Kaspersky Lab’s ThreatPost blog. “This is a real business."

The 16 Pushdo/Cutwail servers that the researchers were able to access contained 2.35 terabytes of data, 24 databases full of details about operations and billions of target e-mail addresses.

The researchers estimate that the botnet’s operators have earned between $1.7 million and $4.2 million since June 2009.

Even one sub-botnet — Pushdo/Cutwail was divided into several domains, each under the control of one gang member — was able to pump out 87.7 billion e-mails in the four weeks between July 30 and August 25, 2010.

"I was most surprised by the sheer number of e-mails sent by this one botnet," another researcher, Thorsten Holz of Ruhr-University Bochum in Germany and Lastline, Inc., in Santa Barbara, told UBM TechWeb’s Dark Reading blog. "It turns out this one botnet sent out billions of spam messages."

Symantec Labs estimated last year that 89 percent of all e-mails are spam.


Takedown

The research team got service providers to pull the plug last summer on about 20 of Pushdo/Cutwail’s 30 command-and-control servers. (The other service providers refused.) The botnet was crippled for several months.

Botnets are illicit networks of computers that have been enslaved by malware, which burrows deep into their operating systems and opens “backdoors” that allow control by remote operators, or “bot herders.”
Malware infection usually happens when a user opens a compromised e-mail attachment (a Trojan) or visits a compromised website (a drive-by download).

The bots, ordinary machines scattered across the globe whose users have no idea they are infected, are used to send out spam touting Viagra and pornography, phishing e-mails and Trojans to harvest more bots.

Almost 40 percent of Pushto/Cutwail’s bots were in India, Holz and his colleagues found. Other countries’ shares were far lower; Australia came in second, comprising 9 percent of the compromised PCs.

Holz and his colleagues also got an archived copy of Spamdot.biz, an online forum used by botnet operators for communication and trade, which provided a fascinating look into the world of mid-level cybercriminals.

More than 90 percent of the posts on Spamdot.biz were in Russian, and less than 9 percent in English. It had nearly 2,000 registered members, who had to be recommended by at least two other existing members to be accepted.

E-mail addresses were bought and sold in blocks of a million, with prices ranging from $25 to $50 per block depending on geographical location, status (free Web-based e-mail services such as Gmail or Hotmail were cheaper) and volume.

Specialized groups sold services, such as infecting new batches of computers with the client’s malware. These sold in blocks of 1,000, with prices ranging from $13 for Asian computers to $125 for PCs based in the United States.


Top-notch software

The software used by the Pushdo/Cutwail botnet was remarkably sophisticated. Each server running Cutwail, the spam engine, constantly tested its messages against a built-in copy of the SpamAssassin e-mail filter.

Pushdo, the Trojan used for command and control, used a proprietary, and often encrypted, communications protocol to direct its bots.

Despite the technological efforts and the sheer volume of spam sent out, only 30 percent of Pushdo/Cutwail’s e-mails ever reached their target servers, the researchers estimate. Half went to invalid addresses, and nearly 17 percent were blacklisted.

"That's quite a big loss," Holz told DarkReading. "And even if the mail is received by the targeted mail server, with filtering and SpamAssassin a large chunk of that 30 percent gets filtered and doesn't necessarily reach the inbox of the user."

Still, having all this information isn’t much of a victory in the fight against spammers.

Pushdo/Cutwail has been rebuilt since last summer and is now back up to its pre-takedown size of about 100,000 bots. It’s the second-largest botnet in the world; the Rustock botnet has an estimated 250,000 enslaved PCs.

How can you prevent your computer from being enslaved by a botnet? No method is foolproof, but your odds of infection drop dramatically if you do two things: Don’t open any unrequested e-mail attachments, even those from friends; and install and constantly update and run anti-virus software, even if you’re using a Mac.

Using a Mac instead of a Windows PC also does help, at least for now. Macs are not immune from infection and a few Mac Trojans have been found in the wild, but Apple’s PC market share is still so small that most cybercriminals don’t bother writing malware for it.

[SecurityNewsDaily]

73,000 malware strains created daily in 2011

The number of threats in circulation has risen in comparison to last year. In the first three months of 2011, PandaLabs identified an average of 73,000 new malware strains, most of which were Trojans. Moreover, there was a 26 percent increase of new threats compared to the same period last year.



While PandaLabs observed a quarter-over-quarter increase of new malware in 2010, the rise was not nearly as notable as the one experienced over the last several quarters.

Trojans remain the most popular type of threat to computer systems, and now account for 70 percent of all new malware. This is unsurprising considering it can be incredibly lucrative for cybercriminals to commit fraud or steal money from Internet users through the online banking channel.


“The proliferation of online tools that enable non-technical people to create Trojans in minutes and quickly set up illegal business – especially when it can provide access to banking details - is responsible for Trojans’ impressive growth”, said Luis Corrons, technical director of PandaLabs.

Not all kind of Trojans grow at the same pace. Taking a look further at the subtypes of malware, PandaLabs found that Banker Trojans have decreased, bots have remained steady, and fake anti-virus or rogueware has descreased in popularity. However, the number of “downloaders” has increased significantly.

Downloaders are a subtype of Trojan that, once it has infected a user's computer, connect through the Internet to download additional malware. Hackers often use this method because the downloader is lightweight – only containing a few lines of code - and can go completely unnoticed unlike other Trojans.

[Net-Security]

Sunday, 6 March 2011

‘United Parcel Service notification’ email contains trojan

MX Lab, http://www.mxlab.eu, started to intercept a new trojan distribution campaign by email with the subject “United Parcel Service notification” send from the spoofed address “United Parcel Service <support2pyq@ups.com>”.

The body of the email is made from an image but on our computer the image is broken. The included image UR points to http://1stchoiceindustrial.com/bd32t.jpg but no file is found on this server. I’m sure that we can guess what they are willing to share with us.

The attached ZIP file has the name document.zip and contains the 37 kB large file document.exe.

The trojan is known as TROJ_SPYEYE.SMEP (Trend Micro), Trojan.Agent/Gen-FakeAlert[RnGlobal] (SuperAntiSpyware), W32/Bamital.FA!tr (Fortinet).

At the time of writing, only 5 of the 43 AV engines did detect the trojan at Virus Total.

[Virus Total] via [ComputerSecurityArticles]

Friday, 4 March 2011

Simple protection steps from credit card fraud

Every year, cybercriminals steal billions of dollars from unsuspecting computer users and companies by committing credit card fraud.



Although this activity was once relegated to pick-pocketers and mailbox thieves, today roughly half of all credit card fraud starts with online attacks ranging from phishing and email scams to spyware programs such as adware, keyloggers, Trojans, system monitors, browser hijackers, and dialers.

Fortunately, if you know what to watch for – and have good online protection – you can avoid becoming a victim of these fraudsters and keep your personal information safe.

The first step to ensuring that you're able to catch any form of credit card fraud (online or otherwise) early is to closely monitor your credit card activity. You can do this the old-fashioned way via your credit card company's official website, or you can find a security program that monitors your credit cards for you and alerts you to suspicious activity.

Here are a few additional tips from Webroot to help you safeguard your personal information online:
  • Use varied and complex passwords for all your accounts, including online shopping accounts, bank accounts, social networking sites, etc. (You may want to try using a security software program with a password manager to help you keep them straight.)
  • Only provide personal information on secure sites. (Look for "https" in the web address or the lock icon at the bottom of the browser.)
  • Do not respond to unsolicited requests for personal information – they are often a sign of phishing.
  • Avoid questionable Web sites, such as adult sites and file sharing sites.
  • Only download software from sites you trust.
  • Practice safe email protocol by not opening messages from unknown senders. Immediately delete messages you suspect to be spam.
Some signs and symptoms that your PC may be infected and require cleanup (as well as updated spyware and virus protection) include:
  • Sluggish performance
  • Increased number of pop-ups
  • New toolbars you can't delete
  • Unexplained changes to homepage settings
  • Puzzling search results
  • Frequent computer crashes.

Trojans still top malware threat


Continuing a trend observed since last summer, the same types of Trojan horse programs have persistently dominated the threat landscape through February, according to GFI Software.

Statistics show that Trojans made up six of the top 10 malware threats of the month. Trojans detected as Trojan.Win32.Generic!BT continue to be the number one threat, accounting for 22.97 percent of total detections. This is an increase from the 21.38 percent in January and 21.93 percent in December of total threats detected.

These Trojans are downloaders associated with rogue security programs known as “scareware”. Once they are on a user’s system, these programs perform a fake scan of a victim’s computer for malware then display false warnings that the machine is infected in an attempt to convince victims to purchase fake security software.

"The Security Shield rogue has become very noticeable. These types of attacks notoriously cause a great deal of stress for the victim in addition to simply infecting their computer," said Chris Boyd, senior threat researcher, GFI Labs.

While Trojans continue to be the most common threat detected, GFI Labs researchers are also seeing a rise in lesser-known attack vectors. Although they are not as common, these forms of attack are especially dangerous because most users may not know how to spot them.

"PDF exploits continue to be problematic, showing a small increase since January. February has also seen continued use of fake Java applet installs to infect PCs with malware, Alureon infected videogame patches distributed on P2P networks and phishing attempts targeting customers of the popular online retailer Play.com,” said Boyd. “With new attacks popping up every day, users need to always stay cautious and research programs they plan to download when there is any doubt.”


[Net-Security]

Thursday, 3 March 2011

Potentially deadly Trojan is a modified security solution


An interesting tactic for hiding a Trojan has recently been spotted by Symantec researchers.

Instead of using entirely their own malicious code, the malware authors have decided to take advantage of the code belonging to the KingSoft WebShield browser protection software (part of the KingSoft Internet Security solution).

"The interesting part of this package is in its configuration, which allows an opportunity for malicious intent," explains researcher Éamonn Young. "Kingsoft WebShield has the ability to lock the home page to a specific domain as well as to redirect URLs based entirely on plain text configuration files. This means that a person with malicious intent can repackage it using malicious configuration files and use this as a home-made Trojan package."

And so they did. The new package contains the legitimate software and its support components, but also two configuration files that practically modify it into the Trojan.

Once the apparently legitimate software is installed and running, one of these files makes it so that the home page is changed to one of the designated URLs - which house advertisement link farms - and locked so that the user can't change it.

The other one makes sure that if a user wants to visit one a number of popular domains listed in it, he is also redirected to one of the aforementioned designated URLs.

The authors of the malware are likely to be Chinese, and so are the targeted users. The misused legitimate software is manufactured by Chinese software developer Kingsoft, and all the websites - the advertisement link farms and the domains from which the user is redirected - cater to Chinese users.

Another interesting thing about this Trojan is that deletes all Quick Launch icons except for the Internet Explorer one. And if there isn't one, it creates it. Since the whole package works as they want to only in Internet Explorer, this is a rather (too) obvious way to make sure the user uses only that browser.

Since Kingsoft WebShield works as it usually does, the user might not spot that there's something wrong with his computer right away upon installation of the tainted package. And even when he finally gets suspicious about the constant redirection, it will take a while before he learns how to deinstall it since the uninstaller has been omitted.

All in all, the authors of this improvised Trojan have manufactured an annoying but not very dangerous piece of malware. Unfortunately, it seems to me that it is only a matter of time until someone changes the configuration files again and the users are redirected to more malicious sites.

Malware decreases, Trojans still dominate

 According to data gathered by Panda Security, only 39 percent of computers scanned in February were infected with malware, compared to 50 percent last month.

Trojans were found to be the most prolific malware threat, responsible for 61 percent of all cases, followed by traditional viruses and worms which caused 11.59 percent and 9 percent of cases worldwide, respectively. These figures have hardly changed with respect to the January data.


There have hardly been any changes either in the most prevalent malware specimens detected this February.

The CI.A, Downloader.MDW or Lineage.KDB Trojans continued to spread and infect systems in approximately the same numbers as last month.


China, Ukraine, Thailand or Taiwan held the top four highest rates of infection (over 50 percent of cases). Other countries such as Italy, the U.S. or France recorded rates below 40 percent, but ranked higher than last month.


[net-security]

Wednesday, 2 March 2011

Rootcager Trojan found on the official Android market


Free Android applications bundled up with malware have spilled over into the official Android marketplace.

According to Symantec, the malware in question can root the phone, harvest data and open backdoors - similar to the recent Geimini Trojan spotted lurking on third-party Chinese Android app markets.

"The applications in question are popular free apps, bundled with malware, that have then been republished in the official marketplace under different application and publisher names," says researcher Joji Hamada.

Google has jumped into the fray and removed the applications from the market, but according to Symantec's sources somewhere between 50,000 and 200,000 downloads took place during the four days that the apps were available for download.

This new Trojan has been dubbed Rootcager because of the rageagainstthecage file included in the Android Package containing the affected apps.

Rageagainstthecage is a file that can also be used to legitimately root a phone in order for the users to gain administrative rights, but in this case it's used to allow the Trojan to do things like taking screenshots, harvesting IMEI and IMSI numbers and send them to remote sites, and drop a DownloadProvidersManager Android Package that will further execute downloads in the background.

For the full list of the potentially affected apps, go here. In you think you may have installed one of them on your device, check the installed apps against it or check the “running services“ settings on your phone for the DownloadManageService started by an application.

Monday, 28 February 2011

Researchers spot new Mac OS X malware


Security researchers from Sophos have spotted a new piece of malware targeting Mac OS X users.
According to the company, the BlackHole RAT release is still under development, and appears to be using the source code of a popular Windows trojan horse known as darkComet.
The screen lock feature reads:

Hello I’m the BlackHole Remote Administration Tool. I’m a trojan horse, so I have infected your Mac Computer. I know, most people think that Macs can’t be infected, but look, you ARE infected! I have full controll over your Computer and I can do everything I want, and you can do nothing to prevent it. So, Im a very new virus, under Development, so there will be much more functions when I’m finished. But for now, it’s okay what I can do. To show you what I can do, I will reboot your Computer after you have clicked the Button right down.

Open source malware is an inseparable part of the cybercrime ecosystem, allowing novice cybercriminals to quickly catch up with that used to be sophisticated propagation tactics, a few years ago.
With open source malware now every day’s reality, it shouldn’t be surprising the the growth of malware is reaching such epic proportions of the overall picture. Although rate, malware releases for Mac OS X are only going to get more popular with the time, given the under served market segment, combined with the countless number of malware coders.

The company emphasizes the fact the BlackHole RAT isn’t spreading in the wild, and urges users to exercise extra caution when downloading freeware applications, or even worse, pirated releases. A short clip showing the trojan horse in action can be seen here.

New type of financial malware hijacks online banking sessions

A new type of financial malware has the ability to hijack customers’ online banking sessions in real time using their session ID tokens.

OddJob, which is the name Trusteer gave to this Trojan, keeps sessions open after customers think they have "logged off", enabling criminals to extract money and commit fraud unnoticed.





This is a completely new piece of malware that pushes the hacking envelope through the evolution of existing attack methodologies. It shows how hacker ingenuity can side-step many commercial IT security applications traditionally used to defend users' digital - and online monetary - assets.

Trusteer have been monitoring OddJob for a few months, but have not been able to report on its activities until now due to ongoing investigations by law enforcement agencies. These have just been completed.

Trusteer's research team has reverse engineered and dissected OddJob's code methodology, right down to the banks it targets and its attack methods. Financial institutions have been warned that OddJob is being used by criminals based in Eastern Europe to attack their customers in several countries including the USA, Poland and Denmark.

The most interesting aspect of this malware is that it appears to be a work in progress, as we have seen differences in hooked functions in recent days and weeks, as well as the way the Command & Control (C&C) protocols operate.

These functions and protocols will continue to evolve in the near future, and that our analysis of the malware's functionality may not be 100 per cent complete as the code writers continue to refine it.

OddJob's most obvious characteristic is that it is designed to intercept user communications through the browser. It uses this ability to steal/inject information and terminate user sessions inside Internet Explorer and Firefox.

OddJob’s configuration data shows that it is capable of performing different actions on targeted Web sites, depending on its configuration. The code is capable of logging GET and POST requests, grabbing full pages, terminating connections and injecting data into Web pages.

All logged requests/grabbed pages are sent to the C&C server in real time, allowing fraudsters to perform session hijacks, also in real time, but hidden from the legitimate user of the online bank account.

By tapping the session ID token - which banks use to identify a user's online banking session - the fraudsters can electronically impersonate the legitimate user and complete a range of banking operations.

The most important difference from conventional hacking is that the fraudsters do not need to log into the online banking computers - they simply ride on the existing and authenticated session, much as a child might slip in unnoticed through a turnstile at a sports event, train station, etc.

Another interesting feature of OddJob, which makes it stand out from the malware crowd, is its ability to bypass the logout request of a user to terminate their online session.

Because the interception and termination is carried out in the background, the legitimate user thinks they have logged out, when in fact the fraudsters remain connected, allowing them to maximise the profit potential of their fraudulent activities.

All matching is case-insensitive, and, using this process of pattern matching, fraudsters using OddJob are able to cherry pick the sessions and targets they swindle to their best advantage.

The final noteworthy aspect of OddJob is that the malware's configuration is not saved to disk - a process that could trigger a security analysis application – instead; a fresh copy of the configuration is fetched from the C&C server each time a new browser session is opened.

[net-security]

Thursday, 24 February 2011

Fake YouTube pushes out Trojan disguised as plugin

It could happen to anyone. A click on a link posted by a compromised Facebook account or in an e-mail sent from an e-mail account of a friend who got phished, and you're on a spoofed page imitating a video sharing site.

Once on it, a Java applet keeps popping up and asking you to run it so that you can view the video you followed the link to see.

And if you aren't aware that most video sharing sites use Adobe Flash to play them, you will likely fall for the request of installing an unsigned application or codec.

BitDefender researchers have recently discovered such a page:



In this particular instance, the application the site asks the user to run is a generic downloader Trojan that, once installed, will get in touch with its C&C center and download more malicious files that can make it spy on your chat conversations, make your computer part of a DDoS botnet and redirect your search queries to further malicious sites.

[net-security.org]