New Police Ransomware Can Even Speak In Your Mother Tongue

Dec 10, 2012 | comments

These days, this new breed of ransomware notifies users of the fee (or ransom) under the guise of the victim’s local law enforcement agencies. Thus, a user with a ransomware-infected system from France will get a notification from the Gendarmerie Nationale, while a US-based one will likely receive a message from the FBI.

New Police Ransomware
 People behind police Trojan/Ransomware have implemented improvements to make this threat more effective. Gone are the days when ransomware simply showed a message that users’ systems are “captured” and that they have to pay for a fee to have them back.

As always, users are advised to avoid downloading software from unknown websites and following links embedded in unsolicited emails.
 

Bitcoin Miner Malware Posing as Trend Micro AV

| comments (1)

Beware of Trojan Disguised as Trend Micro Component Drops Bitcoin-Mining Malware,almost always comes in disguise, but some malware peddlers try to do a better job than others.

Malware Posing as Trend Micro AV
Malware writers have devised lots of social engineering tactics to lure users into their scheme. This time around, we saw a Trojan passing itself off as a Trend Micro component as a way to trick users into downloading and executing it.

Trend Micro researchers have recently uncovered a piece of malware that tried to pass itself off as "Trend Micro Anti Virus Plus Anti Spyware.

Unfortunately for whose who get fooled, the software in question is a Trojan that creates the process svchost.exe and downloads additional malicious components such as a Bitcoin miner application created by Ufasoft. This particular application will, unbeknownst to the victim, use the infected system's resources to create Bitcoins for the people behind this scheme.

As always, users are advised to avoid downloading software from unknown websites and following links embedded in unsolicited emails.

Necurs : A Multipurpose Trojan

| comments

Necurs a multipurpose trojan is a prevalent threat in the wild at the moment - variants of Necurs were reported on 83,427 unique machines during the month of November 2012.





Necurs is mostly distributed by drive-by download. This means that you might be silently infected by Necurs when you visit websites that have been compromised by exploit kits such as Blackhole.

Necurs Trojan is capable of:

  • Modifying the computer's registry in order to make itself start after every reboot.
  • Dropping additional components that prevents a large number of security applications from functioning correctly, including the ones manufactured by Avira, Kaspersky Lab, Symantec and Microsoft. According to Microsoft's researchers, Microsoft Security Essentials' real time protection option is often turned off after an infected computer has been rebooted.
  • Disabling the running firewall
  • Contacting a remote host for command and control instructions via HTTP port 80, and sometimes downloading and installing additional malware (mostly rogue AVs) and loading a malicious DLL component that allows attackers to send out spam via Gmail.
  • Creating a permanent backdoor into the system, which allows attackers to gain complete control of the affected computer.
In addition Necurs contains backdoor functionality, allowing remote access and control of the infected computer. Necurs also monitors and filters network activity and has been observed to send spam and install rogue security software. Nefariousness aplenty.Necurs uses MD5 and SHA1 to encrypt its network traffic data when sending or receiving, and contains a regularly updated driver that protects every Necurs component from being removed .


Swiss Bank Returned $700M To Maryam Abacha Nigeria : 419 Scam Alert

| comments

Scammers are once again leveraging a legitimate news article in order to make their stories more convincing. In the latest scam, they’re relying on the fact that Switzerland will return $700 million (546 million EUR) representing part of the money stashed in the country’s banks by Nigeria’s former president.

419 Scam,Maryam Abacha

 The scam email, which comes with a couple of newspaper clippings and a link to an article from Nigeria’s The Sun, reads something like this:

“Dear Sir/Ma,
Greetings to you from Mrs Maryam Abacha, wife of the de facto head of state of Nigeria, 1993 to 1998. My letter may come to you as a surprise but please take a Little time to hear my cry for help.
My late husband left some money for me ,my son Abba and Mohammed at a Swiss bank before his death. The Swiss bank just refunded $700Million of my sons money to the Nigeria Government this week dated the 5th of December 2012. Please check On this site for details or you can just goggle the information for your comfort.
My own share of the funds is now available for disbursement. I need a trustable
partner who can claim these funds and invest judiciously for me and my two children
and also make provisions for us to live Nigeria before we are completely ruined. Please
give me your terms and conditions for helping me. How much you will take as your
fee provided you will work with us as partners in progress. I have so many other
transactions to take care but no freedom to do so. Please be straight with me.
I remain,
Yours Faithfully,
Maryam Abacha


The bottom line is that no matter how convincing they sound and no matter how much proof you’re provided with, such emails should be ignored. Otherwise, you can easily get tangled in the web of lies and you could lose some serious amounts of money.

ProjectWhiteFox : Over 30 High Profile Sites Record Leaked By GhostShell Hackers

| comments

GhostShell Hackers returns with another massive data leak. On this occasion – which represents their last project for this year they’ve leaked around 1.6 million account details from fields such as banking, law, education, military, government and aerospace, as part of a new project called ProjectWhiteFox.



The data dump originates from over 30 websites. The large quantity of information appears to come from the systems of organizations such as NASA, the European Space Agency, Crestwood Technology Group, Bigelow Aerospace, the California Manufacturers & Technology Association and Aerospace Suppliers.


Apple Maps Incorrect Data Puts Travelers In Danger

| comments

Police in the Australia state of Victoria have contacted Apple after incorrect information within its mobile mapping system put drivers heading to the small town of Mildura in “potentially life threatening” situations, as they were led to a national park some 70 kilometers off target.

Apple Maps Incorrect Data Puts Travelers In Danger
Apple replaced Google Maps with its own maps app in the iPhone's latest software upgrade.

The app has been widely panned around the world for its poor map data, which shows numerous mistakes.

Victoria Police say that in the past two months they have rescued six people who were lost in the Murray Sunset National Park while trying to get to Mildura - more than 70 kilometres away.

Russian Hackers Break Into Australian Medical Center Data, Demand $4,000 Ransom

| comments

Australia medical practice has been held to ransom by a group of Russian hackers. The hackers encrypted the practice’s patient database, rendering it unusable until decrypted.

Russian Hackers Break Into Australian Medical Center Data, Demand $4,000 Ransom





Hackers are demanding a ransom of $4,000 to decrypt the sensitive information held on a server at the Miami Family Medical Centre,noting that scammers tend to go for a low-yield, high-volume approach to increase their chances of a payout.


The practice in question is Miami Family Medical Centre, whose co-owner David Wood believed that anti-virus software was enough of a protection against intrusion and other security threats.
Cases like this should serve as a wake-up call for businesses to get proper security advice from professionals — particularly those responsible for sensitive medical information. When you deal with information like this, ignorance is not an excuse.

An IT firm has been called in to try to recover the information from backups. After analyzing the encryption system, experts have concluded that – although it’s not recommended – the only solution to recover the encrypted data might be to pay the ransom.
In the meantime, the Miami Family Medical Centre continues to operate, but the task is not easy without patient records.




GPU Cluster Can Crack Any NTLM 8 Char. Hash In Just 5.5 hours

Dec 9, 2012 | comments

crack password hash with GPU Cluster

Such systems can only operate against off-line password lists, but given the number of system breaches leading to massive password leaks throughout 2012, it should be enough to make websites reconsider how they store user passwords, and how users choose and use their passwords.

There are two primary methods used by attackers to recover the plaintext password from a hash: brute force and dictionary attacks. Brute force involves re-hashing every possible combination of characters and comparing the result to the stored hash until a match is found and the plaintext password discovered. 

Dictionary attacks involve pre-computed tables of the more likely passwords: names, places, words etcetera. The target hash is checked against the dictionary to find the password. Dictionary attacks have proven very successful because users tend to use obvious passwords that they can easily remember.

Salting is used to defeat dictionary attacks. A random value is added to each plaintext password before it is hashed, making it almost impossible to include the result in a dictionary. As a result, passwords stored as salted hashes can effectively only be recovered by brute force. But what Jeremi Gosney, founder and CEO of Stricture Consulting Group, demonstrated last week is that improved software and more powerful hardware is making brute force increasingly feasible. While he used a cluster of 25 GPUs, it is worth noting that Jens Steube, the author of Hashcat, has added VCL support for up to 128 AMD GPUs in oclHashcat-plus v0.09.

In raw terms Gosney’s system processed 348 billion guesses per second against NTLM hashes, 180 billion g/s against MD5, 63 billion against SHA1, and 20 billion against LM. These are known as ‘fast’ hashes – the computation is done rapidly to benefit the user; but clearly it also benefits a brute force attacker. To make things more difficult for the attacker, cryptographers have developed ‘slow’ hashes. While the extra computing time is hardly noticeable to the user (and could be further disguised by a requirement to complete a CAPTCHA process), Gosney shows that it has a dramatic effect on brute forcing. His system processed 77 million guesses per second against md5crypt, 364,000 guesses against sha512crypt and a relatively tiny 71,000 against bcrypt.

The implication of Gosney’s findings are that websites should consider moving to or using a modern slow hash to defeat brute force attacks, with added salting to beat the dictionary attacks. Users, however, should seriously consider that 8-character passwords are no longer sufficient, and should rather use long passwords to help defeat brute forcing, and complex passwords to help defeat dictionary attacks. Furthermore, of course, users should not use the same password on multiple accounts: if it is recovered from a weakly defended website, there is no need for the attacker to expend the time and effort cracking it in a well-defended website.

Christmas Themed Facebook Scam

Dec 8, 2012 | comments

In the latest Christmas-themed Facebook scams, victims are lured with posts advertising certain videos of attractive young girls. The posts are entitled something like “[OMG] This video was on the NEWS,” “Guess which celebrity this is,” or “Seriously she got attacked.” When victim click on the links, they’re taken to a fake Facebook page that promises a “fail blog daily video.”

On this page, the play button of the video window hides a malicious script which either triggers a “Like” – in order to propagate the scam –, or it further redirects victims to another fake video page that utilizes the Cost Per Action advertising method to unlock an alleged YouTube video.

However, after a certain period, victims who don’t press the play button are automatically presented with a message that reads “Merry Christmas!” after which they’re told that they won a prize from retailers such as ASDA, Best Buy or Walmart.

This is the point where users are directed to sites that support affiliate programs. These services are not illegal, but the crooks are relying on the Facebook posts to draw as many users as possible with their affiliate IDs.

By accessing the site with the cybercriminals’ affiliate ID, victims are actually helping the crooks make money.

One noteworthy aspect of this campaign is the fact that the scammers are relying on compromised freedns.afraid.org accounts to host the scam sites. freedns.afraid.org is a service that allows domain owners to benefit from free DNS services.

Fortunately, experts say that Facebook has this campaign under control and the number of scam posts has decreased. However, users are still advised to avoid such videos and voucher offers since similar operations might be launched at any time.

Skynet Botnet Command and Control Servers Controlled Over Tor

| comments

Tor network used to command Skynet botnet
Security researchers have identified a botnet controlled by its creators over the Tor anonymity network. It's likely that other botnet operators will adopt this approach.

The botnet is called Skynet and can be used to launch DDoS (distributed denial-of-service) attacks, generate Bitcoins -- a type of virtual currency -- using the processing power of graphics cards installed in infected computers, download and execute arbitrary files or steal login credentials for websites, including online banking ones.

However, what really makes this botnet stand out is that its command and control (C&C) servers are only accessible from within the Tor anonymity network using the Tor Hidden Service protocol.
Tor hidden services are most commonly Web servers, but can also be Internet Relay Chat (IRC), Secure Shell (SSH) and other types of servers. These services can only be accessed from inside the Tor network through a random-looking hostname that ends in the .onion pseudo-top-level domain.

The Hidden Service protocol was designed to hide the IP (Internet Protocol) address of the clients from the service and the IP address of the service from the clients, making it almost impossible for the parties involved to determine each other's physical location or real identity. Like all traffic passing through the Tor network, the traffic between a Tor client and a Tor hidden service is encrypted and is randomly routed through a series of other computers acting as Tor relays.

As far as I understand, there is no technical way neither to trace and definitely neither to take down the Hidden Services used for C&C.
 
Support : INDIATRIKS
Copyright © 2011. INDIATRIKS - All Rights Reserved
Template Edited By Indiatriks
Proudly Powered By Blogger