Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Tuesday, May 28, 2019

$1.345 Million Malware Laden “The Persistence of Chaos” Laptop!

Product shot 1
A used Samsung NC10 laptop usually costs about $200. But a used Samsung NC10 with six of the most dangerous types of malware;

ILOVEYOU
The ILOVEYOU virus, distributed via email and file sharing, affected 500,000+ systems and caused $15B in damages total, with $5.5B in damages being caused in the first week.
MyDoom
MyDoom, potentially commissioned by Russian e-mail spammers, was one of the fastest spreading worms. It's projected that this virus caused $38B in damages.
SoBig
SoBig was a worm and trojan that circulated through emails as viral spam. This piece of malware could copy files, email itself to others, and could damage computer software/hardware. This piece of malware caused $37B in damages and affected hundreds of thousands of PCs.
WannaCry
WannaCry was an extremely virulent ransomware cryptoworm that also set up backdoors on systems. The attack affected 200,000+ computers across 150 countries, and caused the NHS $100M in damages with further totals accumulating close to $4B.
DarkTequila
A sophisticated and evasive piece of malware that targeted users mainly in Latin America, DarkTequila stole bank credentials and corporate data even while offline. DarkTequila costed millions in damages across many users.
BlackEnergy
BlackEnergy 2 uses sophisticated rootkit/process-injection techniques, robust encryption, and a modular architecture known as a "dropper". BlackEnergy was used in a cyberattack that prompted a large-scale blackout in Ukraine in December 2015.

is apparently worth $1.345 million—so long as it’s art. Yes some one bid 1.345 million dollars for this computer “The Persistence of Chaos” which Internet artist Guo O Dong created.

Wednesday, December 03, 2014

G-Data Reins In Regin: Top-tier Espionage Tool.

Regin is a full cyber espionage platform capable of complete remote control and monitoring on all possible levels. Attribution is difficult in cases like this however considering the complexity of development, G-Data suspects that this operation is supported by a nation-state, but not originating from Russia and not from China.

Kaspersky Lab has done some research on the Regin as well;

Perhaps one of the most publicly known victims of Regin is Jean Jacques Quisquater (https://en.wikipedia.org/wiki/Jean-Jacques_Quisquater), a well-known Belgian cryptographer. In February 2014, Quisquater announced he was the victim of a sophisticated cyber intrusion incident. We were able to obtain samples from the Quisquater case and confirm they belong to the Regin platform.
G-Data has created a tool to detect the trojan;
We identified the use of an encrypted virtual file system. In the version mentioned above, the file system is a fake .evt file in %System%\config. The header of the virtual file system is always the same:
typedef struct _HEADER {
  uint16_t SectorSize;
  uint16_t MaxSectorCount;
  uint16_t MaxFileCount;
  uint8_t FileTagLength;
  uint16_t crc32custom;
}
During our analysis, the checksum was a CRC32. A generic approach to detect the infection could be a detection of the existence of a virtual file system on the infected system by checking the custom CRC32 value at the beginning of the file system.
 Get the tool from G-Data

Tuesday, December 02, 2014

FBI Warns Business Of 'Destructive' Malware Attackes In The Wake Of Sony Hack.

According to Reuters, the FBI has warned businesses in the USA via a confidential report about new malicious software that can be used to launch "destructive" cyber attacks, which explains that U.S. businesses should remain vigilant. Last week Sony Pictures was hacked and and investigators are still at task.
The report does not directly connect the Sony incident but the five page FBI report mentions about the malware used in the attack. It advices business how to react to the Malware and to report any suspected malware to FBI.
The malware overrides all data on hard drives of computers, including the master boot record, which prevents them from booting up.The hard drives will need to be replaced or re imaged after such attacks and is very time consuming.
Reuters

Wednesday, July 20, 2011

Protecting Users From Malware Using Knowledge Gained From Data


You may have seen an unusual sign if you visited Google recently, like in the image above. That is Google and power of data acting together with security engineers to protect you.
If you see the message, your machine is infected with a strange variant on malware.
Google was able to detect that computers infected with this strain of malware is sending traffic to Google via a set of proxy servers.
Google expect to help out users with eradicating these malware by warning users when traffic is coming from these proxies. Users are directed to a special help page to work with antivirus software to remove infections.
So far this is what Google / we know about these infections;
  • The malware appears to have gotten onto users' computers from one of roughly a hundred variants of fake antivirus, or "fake AV" software that has been in circulation for a while. We aren't aware of a common name for the malware.
  • We believe a couple million machines are affected by this malware.
  • We've heard from a number of you that you're thinking about the potential for an attacker to copy our notice and attempt to point users to a dangerous site instead. It's a good security practice to be cautious about the links you click, so the spirit of those comments is spot-on. We thought about this, too, which is why the notice appears only at the top of our search results page. Falsifying the message on this page would require prior compromise of that computer, so the notice is not a risk to additional users.
  • In the meantime, we've been able to successfully warn hundreds of thousands of users that their computer is infected. These are people who otherwise may never have known.

Official Google Blog: Using data to protect people from malware

Saturday, August 25, 2007

Zango does Tango with FTC

The following comes straight from;
Benjamin Edelman - Spyware Research, Legislation, and Suits

Zango Practices Violating Zango's Recent Settlement with the FTC

"In my hands-on testing, Zango continues numerous practices likely to confuse, deceive, or otherwise harm typical users as well as practices specifically contrary to Zango's obligations under its November 2006 settlement with the FTC.

Among these practices are widespread, ongoing Zango-designed installation sequences which install Zango pop-up ad software without any on-screen disclosure of material terms. Instead, these installations mention Zango's effects only in a lengthy EULA – exactly contrary to the FTC settlement's requirements.
Zango's ongoing practices also include widespread in-toolbar ads without the labeling and hyperlinks specifically required under the FTC settlement. Other Zango ads, including desktop icons and even certain pop-ups, also lack these labels and links.

This article summarizes selected incidents I have recently observed. In particular:

  • Widespread Zango “ActiveX” Installations without Unavoidable, Prominent Disclosure of Material Terms (XP SP1 and Earlier). Details.
  • Widespread Zango Banner-Based Installations without Unavoidable, Prominent Disclosure of Material Terms (XP SP2). Details.
  • Ongoing Zango Installations with No Disclosure Whatsoever. Details.
  • Unlabeled Zango Ads - Toolbars, Desktop Icons, and Pop-Ups. Details.
  • Zango Ads for Bogus Sites that Attempt to Defraud Users. Details."