Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Wednesday, December 2, 2009

Caution - Fake H1N1 Alert leads to Malware Attack

Here’s a look at the fake spoofed CDC Web site being used in this attack:
Malicious hackers are using fake alerts around H1N1 (Swine Flu) vaccines to trick end users into installing malware on Windows computers, according to warnings issued by computer security firms.

The latest malware campaign begins with e-mail messages offering information regarding the H1N1 vaccination. The e-mail messages contain a link to a bogus Centers for Disease Control and Prevention site with prompts to create a user profile. During this process, a malware file gets planted on the user’s machine.

This US-CERT advisory contains some of the e-mail subject lines being used in the spam run. Some examples:
“Governmental registration program on the H1N1 vaccination”
“Your personal vaccination profile.”
According to researchers at AppRiver, the scam tricks computer users into believe they are part of a “State Wide H1N1 Vaccination Program” and are required to create a vaccination profile on the CDC website.

“The link provided in the email takes you to a very convincing looking imitation of a CDC web page where you are given a temporary ID and a link to your ‘vaccination profile’. The link is in fact…an executable file that contains a copy of a Trojan most commonly identified as xpack or Kryptik…once installed on your PC, this Trojan will create a security-free gateway on your system and will proceed to download and install additional malware without your authorization. It also enables a remote hacker to take complete control of your computer.”

AppRiver says the messages are being received at a rate of 18,000 per minute, more than one million per hour.

Friday, October 16, 2009

Malware Loses its Impact Power and Surprise Factor After 24 Hours in the Cloud

Security vendors—particularly those with Web filtering and antivirus products, boast about the exponential growth in malware. Symantec, McAfee and others say the number of malware samples detected over the last two years is approaching 3 million. Strange, that's more than all the samples of unique and variant viruses and worms detected in the last two decades.

Volume doesn't necessarily equal damage. 52% of malware lose it's power within 24 hours of being released into the wild (Cloud).

It's a surprising statistic that reflects the changing nature of malware. Many malware writers are using a malicious cloud computing model to capture valuable data. They're spreading worms and Trojans that either direct users to compromised or bogus Websites, or use a specific domain to send command and control instructions to their compromised clients.

McAfee recently reported, the volume of malware that's designed to monitor specific domains such as banks and gaming sites to stealthily steal access credentials increased more than 400 percent in 2008.

We already know that malware creators will not stick around, waiting to get caught. They're quickly moving or deactivating their controlling domains to avoid detection.

Also, carriers, hosting services and law enforcement are acting quickly to block or take down such malicious domains. The result is that those malware bots, dependent upon those malicious domains, are rendered inert within the first 24 hours. Therefore the impact power and surprise factor of malware, decreases over the next 72hours.

This is good news, right? Not always. It takes time for antivirus vendors and researchers to detect and create conventional signatures for new malware, somewhere in the order of 72 hours. This means most organisations are exposed to high infection rates and compromise, during the most dangerous time of malware infection.

The 24-hour window of vulnerability is an opportunity for solution providers to talk with customers about the benefits of adding synergistic security technologies that augment and complement traditional antivirus packages. Technologies such as data loss prevention, intrusion prevention, and Web and traffic monitoring and filtering can help detect and isolate malicious traffic and stop data loss.

Friday, September 25, 2009

Malware, Worms, Viruses - Clampi Trojan Renews Assault on Bank Accounts

Secure Channel - Malware, Worms, Viruses - Clampi Trojan Renews Assault on Bank Accounts

Sporadic reports are surfacing that the authentication credential stealing Trojan Clampi is regaining momentum and poised to begin a new round of stealthily siphoning cash from the bank accounts belonging to compromised users.

Clampi - also known as Ligats, Ilomo and Rscan - was first discovered in January 2008. The Trojan targets machines running nearly all versions of Windows and spreads as a drive-by download through Websites with compromised vulnerabilities in Flash and ActiveX. It sits in the background monitoring Web browsing activity, specifically log-ins to accounts with financial activity. Without impeding connections or PC performance, Clampi stealthily captures users' account IDs and authentication credentials and passes them to its master.

In recent months, Clampi has started spreading like a worm across networks with infected PCs. In a CNET report, SecureWorks' Joe Stewart explained that Clampi uses capture domain registration credentials to leverage the Windows SysInternals tool "psexec" to copy itself across all connected computers within a domain.

What makes Clampi different, according to published reports, is that it's monitoring a vast number of financially sensitive accounts. Banks and financial institutions are its prime target, but it's also monitoring retail sites, utilities, ad networks, government agencies, online casinos and military portals.

The threat is not contained to individual home users. The Washington Post previously reported Clampi is responsible for several large, unauthorized bank transfers. A Kentucky county lost more than $415,000 to cyber-criminals after a treasurer's PC was compromised. A Pennsylvania school district was hit to the tune of $700,000 and an auto parts store in Georgia lost $75,000, the newspaper reported.

The conventional advice for dealing with Clampi is much the same as with all malware in the wild: Update antivirus signatures, monitor inbound and outbound traffic, block traffic from suspicious or known malicious domains, and patch vulnerability applications and services. In his interview with CNET, Stewart went a step further to say that businesses should isolate PCs used for high-value activities such as managing financial transactions and that those same machines should never be used for browsing the Web or accessing e-mail.


Shared via AddThis

Saturday, August 22, 2009

Symantec and Norton Produce list of 100 Dirtiest Websites

Symantec and Norton have produced a definitive listing of 100 of the dirtiest websites i.e. the websites to avoid.

These websites are most likely to damage your PC or laptop system and /or to install viruses, Malware and Mal-bots, intended to cause major disruptions to all web users.

Click here to see the Report.....