Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Finjan Discovers 1.9 Million Corporate and Government Computers Controlled by Cybercriminals

Finjan Discovers a Network of 1.9 Million Malware-Infected Computers Controlled by Cybercriminals - Corporate and Government Computers Are Included

Findings show that the UK and the US top the list with the highest number of infected computers

Farnborough, United Kingdom, 22nd April 2009Finjan Inc., a leader in secure web gateway products and the provider of unified web security solutions for the enterprise market, announced that Finjan’s Malicious Code Research Center (MCRC) has discovered a network of 1.9 million malware-infected computers. Corporate, government and consumer computers around the world were infected by the malware.

This discovery is part of a research conducted by MCRC when investigating command and control servers operated by cybercriminals. The cybercrime server has been in use since February 2009, is hosted in the Ukraine and is controlled by a cybergang of 6 people. These cybercriminals established a vast affiliation network across the Web to successfully distribute and operate their malware install-base. They compromised computers in 77 government-owned domains (.gov) from the UK, US and various other countries.

The malware is remotely controlled by the cybercriminals, enabling them to instruct the malware to execute almost any command on the end-user computer as they see fit, such as: reading emails, copying files, recording keystrokes, sending spam, making screenshots, etc.

Since the discovery of its findings, Finjan has provided UK and US law enforcement with information about the server. Finjan has also contacted affected corporate and government agencies to let them know that they were part of the infected computer names.

“As predicted by Finjan at the end of last year, cybercriminals keep on looking for improved methods to distribute their malware and Trojans are winning the race. The sophistication of the malware and the staggering amount of infected computers proves that cybergangs are raising the bar,” said Yuval Ben-Itzhak, CTO of Finjan. ”As big money drives today’s cybercrime activities, organizations and corporations need to protect their valuable data to prevent theft by these kind of sophisticated cyberattacks.”

The research also revealed that the malware is installed on computers when visiting compromised websites serving malicious code. Information found by MCRC on the command and control server includes the IP addresses of the infected computers as well as the computers’ name inside corporate and government networks that are running the malware.

The global spread of infected computers in percentages is as follows:

· US: 45%
· UK: 6%
· Canada: 4%
· Germany: 4%
· France: 3%
· Other: 38%

The malware is infecting computers running the Windows XP operating system and using the following Web browsers:

· Internet Explorer - 78%
· Firefox - 15%
· Opera - 3%
· Safari - 1%
· Other - 3%

As recommended by leading analysts, a unified Web security solution is the preferred solution for corporate and government agencies against today’s cyber attacks. Finjan’s Unified Secure Web Gateway product combines multi-layered Web security, utilizing real-time content inspection technologies, with data leakage prevention (DLP) solutions. Finjan’s product also provides Web 2.0, productivity, liability and bandwidth control via URL categorization, content caching and applications control technologies on one dedicated appliance. This enables companies and governmental agencies alike to enjoy optimal multi-layered protection in real-time, with lower Total Cost of Ownership (TCO) and higher Return on Investment (ROI).

Screenshots and examples taken from the command and control server can be found on Finjan’s MCRC blog post at: www.finjan.com/mcrcblog

Finjan’s team will be available for questions regarding the discovery at Infosecurity Europe conference, Earls Court, London, UK on 28-30 April (Booth H20, Hall EC1). Finjan also invites you to come to the Business Strategy Theatre, when Finjan’s UK Regional Director Mr. Tim Warner will hold the seminar “How Organisations can protect themselves against the current Cybergeddon” on Wednesday April 29, starting at 15:20 hrs.

Finjan’s Malicious Code Research Center (MCRC) specializes in the detection, analysis and research of web threats, including Crimeware, Web 2.0 attacks, Trojans and other forms of malware. Its goal is to be ahead of hackers and cybercriminals, who are attempting to exploit flaws in computer platforms and applications for their profit. In order to protect Finjan’s customers from the next Crimeware wave and emerging malware and attack vectors, MCRC is a driving force behind the development of Finjan's next generation of security technologies used in its unified Secure Web Gateway solutions. For more information please also visit MCRC’s info center and blog.

Finjan is a leading provider of secure web gateway solutions for the enterprise market. Finjan Secure Web Gateway provides organizations with a unified web security solution combining productivity, liability and bandwidth control via URL categorization, content caching and applications control technologies. Crimeware, malware and data leakage are proactively prevented via patented active real-time content inspection technologies and optional anti-virus modules. Powerful central management enables intuitive task-based policy management, excellent drill-down reporting capabilities and easy directory integration for all network implementation options. By integrating several security engines in a single dedicated appliance, Finjan’s comprehensive and integrated web security solution enables quick deployment, simplified management and reduction of costs. Business benefits include real-time web security (no patches or updates needed), lower total cost of ownership (TCO), cost savings in administration efforts, lower maintenance costs, and reduction in loss of productivity. Finjan's security solutions have received industry awards and recognition from leading analyst houses and publications, including Gartner, IDC, Butler Group, SC Magazine, eWEEK, CRN, ITPro, PCPro, ITWeek, Network Computing, and Information Security. With Finjan’s award-winning and widely used solutions, businesses can focus on implementing web strategies to realize their full organizational and commercial potential. For more information about Finjan, please visit: www.finjan.com.

Neil Stinchcombe
Eskenzi PR
<>

Microsoft MEA Director's comments on security shows the need for branch office protection says Finjan

Farnborough, United Kingdom, 1st April 2009 - Comments on the need to stay protected by Microsoft's Commercial Market Strategy Director in the Middle East and Africa highlight the need not to overlook the security requirements of branch offices, says Yuval Ben-Itzhak, Finjan's Chief Technology Officer.

"The comments of Microsoft's Mark Chaban, which came after Chinese cyber spies had been found to have infiltrated into the online networks of companies around the world are very relevant to the needs of branch offices," he said.

"When news reports like this there is a tendency to overlook the fact that we live and work in a global village, and that many companies have branch offices in the Middle East or, of course, that Middle Eastern firms have operations elsewhere in the world," he added.
According to Ben-Itzhak, Chaban's revelations that Microsoft's security software detected malware and similarly unwanted applications on 42.6 per cent more PCs in the Gulf States last year than in 2007 makes for very interesting reading.

Whilst many major companies install unified Web security on their head office systems, he says, the security needs of branch offices and operations are often overlooked, with the result that these branch IT systems are usually the weakest link in the IT security defence chain.
Hackers, he explained, are now sufficiently criminally-driven (and minded) to research their victim companies and, as a result, target branch offices, knowing full well that this is their best chance of gaining unauthorised access to the organisation concerned.

Ben-Itzhak went on to say that, in its latest quarterly cybercrime report (http://preview.tinyurl.com/cajblt), Finjan identified that criminal hackers are injecting search engine optimisation targeted pages to include repetitive popular search keywords with minor typos.

By targeting regional pages of major companies, which have lesser page visitors, but whose page accesses are still measured in the tens of thousands, he says, it is far easier to get these injected pages to the top of the search engine lists.

"This means that, when someone searches for XYZ Corporation Middle East, they have a greater chance of ending up on the compromised pages of XYZ Corp's pages than if they searched for the company name alone," he said.

"And this is where weaker defences on branch office IT systems really come into play, as their weaknesses can be exploited by hackers wanting to route innocent Internet users over to their compromised sites," he added.

It's against this backdrop that Ben-Itzhak is urging IT managers to spend just as much time and resources on securing their branch offices as their head office.

"Only by doing this can they hope to equally protect all aspects of their organisation's IT operations against criminals," he said.

Finjan MCRC specializes in the detection, analysis and research of web threats, including Crimeware, Web 2.0 attacks, Trojans and other forms of malware. Our goal is to be steps ahead of hackers and cybercriminals, who are attempting to exploit flaws in computer platforms and applications for their profit. In order to protect our customers from the next Crimeware wave and emerging malware and attack vectors, Finjan MCRC is a driving force behind the development of Finjan's next generation of security technologies used in our unified Secure Web Gateway solutions. For more information please also visit our info center and blog.

Secure Gateway provides organizations with a unified web security solution combining productivity, liability and bandwidth control via URL categorization, content caching and applications control technologies. Crimeware, malware and data leakage are proactively prevented via patented active real-time content inspection technologies and optional anti-virus modules. Powerful central management enables intuitive task-based policy management, excellent drill-down reporting capabilities and easy directory integration for all network implementation options. By integrating several security engines in a single dedicated appliance, Finjan’s comprehensive and integrated web security solution enables quick deployment, simplified management and reduction of costs. Business benefits include real-time web security (no patches or updates needed), lower total cost of ownership (TCO), cost savings in administration efforts, lower maintenance costs, and reduction in loss of productivity. Finjan's security solutions have received industry awards and recognition from leading analyst houses and publications, including Gartner, IDC, Butler Group, SC Magazine, eWEEK, CRN, ITPro, PCPro, ITWeek, Network Computing, and Information Security. With Finjan’s award-winning and widely used solutions, businesses can focus on implementing web strategies to realize their full organizational and commercial potential. For more information about Finjan, please visit: www.finjan.com.

For more on Mark Chaban's comments: http://preview.tinyurl.com/dan3xd

Neil Stinchcombe, Eskenzi PR
<>

Facebook we have a problem

Koobface, and other worms target Facebook Friends

by Michael Smith

London, March 7, 2009: As Facebook works to make itself more relevant and timely for its growing member base with a profile page makeover, attackers seem to be working overtime to steal the identities of the friends, fans and brands that connect though the social-networking site.

Indeed, Facebook has seen five different security threats in the past week alone. According to Trend Micro, four new hoax applications are attempting to trick members into divulging their usernames and passwords. Also, a new variant of the Koobface worm is running wild on the site, installing malware on the computers of victims who click on a link to a fake YouTube video.

The Koobface worm very is dangerous. It can be dropped by other malware and downloaded unknowingly by a user when visiting malicious Web sites, Trend Micro reports. When attackers execute the malware, it searches for cookies created by online social networks. The latest variant is targeting Facebook, but earlier variants have also plagued MySpace.

Once Koobface finds the social-networking cookies, it makes a DNS query to check IP addresses that correspond to remote domains. Trend Micro explains that those servers can send and receive information about the affected machine. Once connected, the malicious user can remotely perform commands on the victim's machine.

According to Trend Micro once cookies related to the monitored social-networking Web sites are located, it connects to these Web sites using the user log-in session stored in the cookies. It then navigates through pages to search for the user's friends. If a friend has been located, it sends an HTTP POST request to the server.

Ultimately, the worm's agenda is to transform the victim's computer into a zombie and form botnets for malicious purposes. Koobface attempts to do this by composing a message and sending it to the user's friends. The message contains a link to a Web site where a copy of the worm can be downloaded by unsuspecting friends. And the cycle repeats itself.

Malware authors are investing more energy in Facebook and other social-networking sites because that effort pays off, according to Michael Argast, a security analyst at Sophos. Facebook alone has more than 175 million users, which makes it an attractive target.

"Many computer users have been conditioned not to open an attachment from an e-mail or click a link found within, but won't think twice about checking out a supposedly hot new video linked to by a trusted friend on Facebook," Argast said.

Argast called the Koobface worm a mix of something old and something new. The new is using social networks as a method to spread malware. The old is using fake codec Trojans linked to a saucy video to induce the user to install the malware.

Argast said people can protect themselves by running up-to-date antivirus software, restricting which Facebook applications they install, thinking twice before clicking on links from friends and never, never installing a codec from some random Web site in the hopes of catching some celebrity in a compromised situation.

"I would expect to see more attacks on Facebook," Argast said. "As long as this is a successful propagation method, the bad guys will double down and invest more. They are entirely motivated by financial gain. If it pays, they'll continue to romp in your social playgrounds."

This advice is the same and the rules should be the same as to the emails that arrive claiming that here or there one can have a look at this or that celebrity or whatever in compromised positions or such.

I personally must say that I never understand why people have this desire to believe that there are such videos about even and that they are worth taking a look at.

However, as we all know, people being people they have this strange drive and they will do just that and that is what the malware writers exploit.

As Michael Argast from Sophos says, have proper up-to-date anti-virus – and remember that you protection is only as good as your latest update, whenever that may have been – and also, and this is my advice, run other good protection software such as PC Tools ThreatFire and such like.

None of such protection has to cost you anything as for the private personal user you can get most of the stuff free. So there is no excuse not to have a fully protected PC or Laptop.

One note, on the side: those worms and Trojans and viruses are dangerous and some more dangerous than others; Koobface worm is very dangerous but not because, as some people might believe, it destroys hard drives or such – those viruses are (mostly) gone nowadays – but because it is a piece of code that ultimately turns the infected PC into a zombie on a botnet.

© M Smith (Veshengro), 2009
<>

Experts warn Cloud Computing may be safe harbour for malware

GSS warns that Cloud Computing may be safe harbour for malware

Global Secure Systems, the value-added IT security consultancy, has warned that Cloud Computing may turn into malware-fest after researchers have found a method of using the Amazon EC2 service as a BitTorrent host/downloading mechanism.

"Using P2P programs like BitTorrent has always been a risky procedure for PC users owing to the issue of infections arriving along with the pirated software and other executables. Reports have just come in, in fact, that BitTorrent is hosting a malware-loaded version of the Apple iWork software," said David Hobson, GSS' managing director.

"What is even more worrying, however, is the fact that researchers have developed a method of using the Amazon EC2 Cloud Computing service as a remote harvester and hosting system for BitTorrent files," he added.

This means, says Hobson, that hackers and other interested parties can simply use a prepaid (and anonymous) debit card to pay the $75 a month fee to Amazon and harvest BitTorrent applications at high speed with little or no chance of detection.

This, he explained, raises P2P filesharing to a whole new level, and is almost certain to dramatically increase the usage of BitTorrent - with all the risk the facility entails - amongst experienced Internet users.

"The danger here is that companies may find their staff FTP-ing files from Amazon EC2 - a completely legitimate domain - to the firm's computers, resulting in an internal computer infection. The consequences of this do not bear thinking about," he said.

According to Hobson, companies thinking of using Cloud Computing services need to think very carefully about extending their IT security envelope to counter this and other issues that arise from the use of the Cloud.

No-one could have envisaged the security risk of using a Cloud Computing resource as a BitTorrent harvester, but it has happened and companies need to be ware of the potential risk the technology now poses, he said.

For more on the use of Amazon EC2 as a BitTorrent harvester: http://tinyurl.com/77rogn

For more on GSS: http://www.gss.co.uk

Yvonne Eskenzi
Eskenzi PR
<>

Virtual Worlds - Real Money. Multiplayer online gamers 'soft target' for cybercriminals - EU Agency report warns.

Serious real-world money locked up in the 1.5 Bn Eur virtual goods market is leading to a wave of malware threatening ca 1 Bn users worldwide. The EU Agency's report includes 12 recommendations for governments, game providers and users.

Online gaming fraud is an increasingly serious threat - according to a new ENISA report. The failure to recognise the importance of protecting real-money value locked up in this grey-zone of the economy has lead to a 'year of online-world fraud'. A survey in the report shows that 30% of users have recently lost some form of virtual property through fraud. In less than a year, more than 30,000 new malicious programs have been detected specifically targeting accounts and property in online games and virtual worlds - "this is a jump of 145%", says Kaspersky labs.

Such malware is invariably aimed at the theft of virtual property accumulated in a user's account and its sale for real money. "While annual real-money sales of virtual goods is estimated at nearly 1.5 Bn Euro worldwide, users can do very little if their virtual property is stolen. They are a very soft target for cybercriminals," says Giles Hogben, editor of the report put together by a group of industry, academic and government experts. "There are 1 Bn registered players of online games worldwide and the malware targeting them affects everyone with a computer connected to the internet."

Privacy and personal data, Another important area is the misuse of personal data. The survey of 1.500 respondents in the UK, Sweden and Germany shows that most people think their avatar cannot reveal anything about their real identity. But an avatar is no different from using any online persona, particularly in so-called "social worlds", i.e. hybrids between online games and social networks. "People should take just as much care of their personal data in these environments as in any other online context," says Mr. Andrea Pirotti, Executive Director of the Agency. Bots can be sprinkled within virtual worlds to spread spam or advertise products, for example, and these sites are vulnerable to novel variants of denial of service attacks. "Multiplayer online games are especially vulnerable to denial of service attacks because of their centralized architecture and poorly authenticated clients," the report says. The report identifies 12 recommendations to tackle these problems, e.g.;

- An industry-wide forum for service providers to share best-practice on security vulnerabilities
- Clarification of virtual property rights for more adequate theft protection
- A checklist of key technical issues for service providers/developers
- Awareness-raising campaigns for users eg., on child-safety and privacy risks.

For full report and survey see: http://www.enisa.europa.eu/doc/pdf/deliverables/enisa_pp_security_privacy_virtualworlds.pdf

Source: ENISA
<>

Eight times more malicious email attachments spammed out in the third quarter of 2008

by Michael Smith

Sophos, the IT security and control firm, reports that eight times more malicious email attachments spammed out in the third quarter of 2008 compared to the previous quarters and has revealed the top twelve spam-relaying countries responsible for this.

Identity thieves and hackers are striking Windows users on all fronts, as Russia rears its head higher in the Dirty Dozen league of spam-relaying nations. Amongst others of this, for instance, also Brazil can be found. China, on the other hand, is busy with hacking into computers in order to gain national and industrial secrets of the western world.

The figures show an alarming rise in the proportion of spam emails sent with malicious attachments between July - September 2008, as well as an increase in spam attacks using social engineering techniques to snare unsuspecting computer users.

We have also seen the fist clickjacking in this third quarter of 2008 and I shall be writing some more about clickjacking as soon as possible.

Sophos’s latest report reveals that one in every 416 email messages between July and September contained a dangerous attachment, designed to infect the recipient’s computer – a staggering eight-fold rise compared to the previous quarter where the figure stood at only one in every 3,333 emails.

This is such an enormous rise that one can but wonder who we can protect ourselves against this, whether large or small business, and especially the home business user.

Sophos has identified that much of this increase can be attributed to several large-scale malware attacks made by spammers during the period. The worst single attack was the Agent-HNY Trojan horse which was spammed out disguised as the Penguin Panic Apple iPhone arcade game.

Other major incidents included the EncPk-CZ Trojan which pretended to be a Microsoft security patch, and the Invo-Zip malware, which masqueraded as a notice of a failed parcel delivery from firms such as Fedex and UPS.

We also must not forget the malware that comes courtesy of visits to website, some even legitimate websites. The so-called “Drive-by Downloads” or as I have termed them “Drive-by Shootings”, often without the user having to do anything at all.

Windows users opening any of these attachments exposed their PCs to the risk of infection and potentially put their identity and finances at risk. The most widespread attacks seen by Sophos are not designed to run on Unix, Linux and Mac OS X.

"For Apple Mac and Linux/Unix lovers, these major spam attacks just mean a clogged-up inbox, not an infected operating system. But organized criminals are causing havoc for Windows users in the hunt for cold hard cash," said Graham Cluley, senior technology consultant at Sophos. "Too many people are clicking without thinking – exposing themselves to hackers who are hell-bent on gaining access to confidential information and raiding bank accounts. The advice is simple: you should never open unsolicited attachments, however tempting they may appear."

The one thing to always consider: if an email looks suspicious do not open the email even, let alone the attachments. While I know that this is not 100% protection as an email may claim to be from a friend or a colleague or such, one way to protect oneself a little bit is to (1) not using the preview pane and (2) to always check any suspect mail via the “properties” box as to contents and originator. The “preview” pane should be deactivated in Outlook, Outlook Express or other email client, as some malware does not require the opening of the payload, that is to say the attachment, but is capable of running just by opening the mail.

Creative social engineering continues to out-fox users

As well as using malicious email attachments, cybercriminals have continued to embed malicious links and spam out creative and timely attacks designed to prey on users’ curiosity.

For example, in August, Sophos warned of a widespread wave of spam messages claiming to be breaking news alerts from MSNBC and CNN. Each email encouraged users to click on a link to read the news story, but instead, took unsuspecting users to a malicious webpage which infected Windows PCs with the Mal/EncPk-DA Trojan horse.

Emails like that are best binned immediately and never, I repeat never, opened. Immediately remove them from the PC by clicking “delete” while holding down the “shift” key. This way they are kept out of the “deleted items” box as well.

"When a spam email appears to come from a trusted source, too many users are fooled and end up clicking through to a malicious webpage," remarked Cluley. "The naivety shown by many internet users is downright dangerous. In the past hackers were more like teenage mischief-makers breaking into sheds to see what they could find. Today they’re hardened criminals wearing hobnail boots with no qualms about breaking into your home and stealing everything they can get their hands on."

New frontiers

Spammers have proven themselves to be unafraid of trying new methods of distributing their marketing messages and spreading their malware to an undefended public during the last three months. Sophos has seen an escalation in the amount of spam being sent via social networking websites such as Facebook and Twitter, and expects to see this continue to rise.

Emerging countries surface as spam-relaying offenders in dirty dozen chart

Sophos made three new entries to the spam hall of shame in the third quarter of 2008 and those are Colombia and Thailand. Those tow nations have assumed eleventh and twelfth place respectively, while India has shot straight into the chart at number seven.

"Insecure computers, wherever they are in the world, are a spammer’s dream – they can be easily hijacked remotely and joined to sprawling networks of botnets designed to create chaos by sending floods of spam and carrying out denial-of-service attacks," explained Cluley. “The message needs to be heard loud and clear: if you don’t properly defend your PC you are not only putting your data, finances, and identity at risk, you are also endangering other members of the internet."

Sophos identified the top twelve countries responsible for relaying spam across the globe between July-September 2008 and whilst the United States retains its position as the top relayer of spam, Russia has increased its contribution to the world spam problem, soaring from 4.4 percent last year, to 8.3 percent during this time period. When it comes to cybercrime of the real high stakes then Russia is one of the top players.

According to Sophos researchers there is no sign that recent legal action by the authorities against major spam gangs have had any perceptible impact on the amount of spam in circulation.

Sophos recommends companies automatically update their corporate virus protection, and run a consolidated solution at their email and web gateways to defend against viruses and spam.

Where does that leave the little guy, however? Well, in a way the same advice applies, that is to say, automatically update anti-virus programs and other protection software, such as firewall, anti-spyware, etc.

Furthermore, the most important thing to do is to use common sense. Yes, that misnomer, because it is not as common as it should be. If someone tells you you have won the lottery despite the fact you never entered into a draw then it is too good to be true and hence it is a fake.

The same it true for Yahoo or MSN lotteries that, supposedly, have drawn your email out of the hat. Those also malware bearing emails or emails which have a “claim” link that will direct him or her who opens such a link to a website with malware.

News items that you have not subscribed to via that feed, for instance, especially if they claim various strange things are certainly not something that you should open and definitely you should not click on the links in any such email.

The best advice must be: if in doubt do not open and check with sender if such an email was sent. That should ensure a certain degree of high level safety.

© M Smith (Veshengro), November 2008
<>

November 24 could be 'Black Monday' for computer viruses

by Michael Smith

The Internet security company PC Tools has warned that next Monday could be the worst day of the year for computer attacks.

The spread of viruses and malicious software is expected to peak on Novem 24, along with attempts by hackers to seize control of computers, according to PC Tools.

PC Tools, by the way, is the “maker” of ThreatFire, amongst other items of software, and ThreatFire, which I have reviewed in the pages of this journal and used for a considerable time by now, I am certain, has done the bulk of work in preventing my system, while other have been infected, from staying free of problems.

The company has analysed information on more than 500,000 computers worldwide, and looked at data from the same period last year, which appears to suggest the Monday before Thanksgiving in the US is a prime time for security attacks.

PC Tools believes that this could probably be because of the increased online activity at this time of the year, as people starting shopping online for Holiday gifts, and for details of bargains they might be able to pick up on Black Friday, the day after Thanksgiving, when many US stores hold huge sales.

Online shoppers are a tempting target for hackers and fraudsters, many of whom will try and trick consumers into clicking links in emails and websites that will download software onto their computers that allows malicious attackers to take remote control of the system and/or to gain control of their passwords and other sensitive information.

With such software on board hackers will then be able to log keystrokes in order to access banking login details and passwords for online shopping sites, and more dangerously even, credit card numbers, PayPal account details and such like.

Web users must be especially vigilant in the run-up to the Holidays and they really must keep their wits about them. While in the real world they would shield their PIN for their Credit or Debit cards they must do similar things as regards to protecting their online identity and credentials.

People who plan to do their gift shopping on the Internet should ensure their anti-virus software and firewall security is up to date, that they don't open emails and files from unfamiliar people, and that they ensure they only enter credit or debit card information on secure web pages.

Secure web pages are denoted by the appearance of a padlock symbol somewhere around the border of the webpage or in the address bar, and the "http://" prefix for the website changing to "https://" to show it is a secure link.

As to opening emails let me add that even emails that are sent from friends may not actually be from them. Their details could have been cloned in the same way as your own details can be cloned – even my own. So let the user beware and if in doubt contact the sender of an email, if he is a known associate, as to whether he or she has, in fact sent you and email with this or that title. If so then it is, more than likely, safe to open.

I have received emails even from my own email addresses – supposedly – that never were from my own addresses. However, the address had been cloned and could have, maybe, confused people.

So, as I always say; let's be careful out there.

© M Smith (Veshengro), November 2008
<>

Fake celebrity websites infect the unwary with malware

by Michael Smith

By all rights and also to all intents and purposes, using fake websites as a malware attack vector should have died out long ago.

Rather than dying, however, those attacks initiated through phony celebrity websites have continued to grow and expand. This is possibly because their intended victims – the celebrity-obsessed among us – either do not have an abundance of brains or a basic knowledge of how computers and the Internet actually work. One could probably assume that in the majority of the cases both would apply.

According to recent data from McAfee, a leading anti-virus program vendor and research company, an Internet user searching for a range of Brad Pitt-themed items, say wallpapers, screensavers, photos, and the like, has, on average, an 18% chance of running into malware in one form or another. Such malware is often served up by a "fake" celebrity website the primary purpose of which it is to push Trojans and worms onto the desktops of the unwary. These websites differ from standard malware landing pads, inasmuch as they try to appear as a legitimate source of news.

In order to create such sites, malware authors rely on an ever-changing list of "hot" celebrities. The turnover rate is fairly high – Paris Hilton was the most dangerous celebrity to search for in 2007, but doesn't even make the top 20 this year, while Britney Spears, which was #4 in 2007, is also missing in action.

This year, 2008, Brad Pitt, Justin Timberlake, and George Clooney are the top three dangerous male searches, and come in first, third, and ninth on McAfee's list and for the women we have Beyonce in first place, followed by Heidi Montag and Mariah Carey. I must say that, personally, I am not even sure who they are; the women, I mean.

McAfee's findings suggest that these sorts of searches are quite common, both at home and in the workplace. Aggressively searching such content while on the job is almost certainly against an employer's rules, even in a company with a fairly lax Internet policy, but that doesn't change the fact that such searches occur, and could expose company systems to any number of attacks. One form of damage control would be to present users with a list of verified "clean" news websites and encourage them to use these for news on any number of topics. Corporate policies that tacitly encourage non-work-related web use aren't going to find a warm reception in the boardroom, but practical advice on where to surf might do more to solve the problem than attempting to beat a basic understanding of the problem into employees' heads.

All of the usual rules about using an up-to-date virus scanner, avoiding suspicious-looking URLs, and not opening an unknown program just because a web browser shoves it in your face still apply, but in this case, the best protection is simply not to look. There are plenty of celebrity websites that make it their mission to stay right on top of the latest rumor, photo, or scandal, and they do so without serving up a healthy portion of Storm Worm on the side. If nothing else, try to remember that you don't actually need Brad Pitt wallpaper or a screensaver featuring outtakes from the Chinese movie My Wife is a Gambling Maestro. When in doubt—heck, even when not in doubt—it's best to stay away entirely.

Searching for desktop items such as Brad Pit screensavers of the like is not a recommended pastime whether or not you have all the relevant anti-virus protection even.

Aside from relying on the unwary to search for celebrity items the distributors of malware also try to trap the news hungry with fake news, such as “Third World War has started”, “USA has attacked Iran”, “Iran has sunk US aircraft carrier”, and similar. I am sure they will not cease to come up with new stuff. Invariably those attempts come via email with links in them which the recipient is meant to click on. He or she will then end up on a website specially created for the sole purpose of distributing this or that Trojan or worm.

News can be had from such a large variety of legitimate main stream and underground news sources – via RSS feed – that no one has to even go as far as opening such emails and clicking on the links therein. If the BBC or the CNN sites are not running it then it has not happened, such as an attack or such, we can rest assured of that. No need to fall prey to the virus distributors.

Whether fake celebrity sites or fake news sites as malware attack vectors, in most cases than not, aside from the above mentioned search for celebrity-themes items, are initiated by a spam email to the recipient. This should already have all possible alarm bells ringing and anyone with an ounce of brain should delete such mails without opening them.

The most dangerous thing on the Internet, and I have written about that before, is the unsecured PC and the user who has no idea what he or she is doing. This is how the spam and the viruses are being circulated.

Have proper anti-virus software (you do not have to pay for it to be secure) that is updates at least once a day. The same for spyware blasting programs – one is in fact called Spyware Blaster – and also have a browser that does not automatically download anything. Internet Explorer's greatest fault is that it just does that; any script and such it encounters and any .exe file it automatically downloads and runs. Use Firefox, for instance. It has a download manager that will ask you what you want to do with the file you have chose to open/download and, obviously, if you have not chosen to open/download anything directly it gives you the choice to cancel it. It is then high time to hightail it out of that site and, for safety, run a full systems check – just in case.

Without the gullibility of so many users and also the fact that so many just do not have the understand of how computers and the Internet work and how, and that despite us all telling them, viruses and such are being spread, such malware sites and spam would have ceases a long time ago.

If everyone would but listen and heed the advise that magazines and websites such as that of the ICT Review here give such malware would by now be either non-existent or very much diminished and would be headed for extinction; all of it.

Alas, as long as there are users out there who do think they know better and such we will continue to be plagued by this.

© M Smith (Veshengro), September 2008
<>

Angelina Jolie Guest Stars in Malware Scheme

Spammers use sensationalized headlines to lure unsuspecting computer users

BitDefender researchers have identified a new wave of spam messages that use fake events related to actor Angelina Jolie in order to trick users into downloading and installing Trojan malware onto their computers.

This new campaign of spreading malware is mostly carried via spam messages based around an alleged adult video footage with the movie star. In order to watch the movie, users have to download binary file, video-nude-anjelina.avi.exe, which is infected with Trojan.Agent.AGGZ.

The spam message is comprised of an explicit image of Angelina Jolie, along with some text claiming that the mail has been sent as part of the MSN Featured Offers program. The text message plays a double role by it trying to trick the user into thinking that this is a legitimate news message and by preventing spam filters from labelling the entire mail as spam message.

“The spam wave is part of a larger category of unsolicited mail messages that rely on social engineering techniques in order to lure unwary users into installing Trojans,” said Vlad Valceanu, Head Of Antispam Research. “This type of attack seems to be extremely successful, as the number of messages has quickly escalated over the last couple months. In order to achieve their goals, spammers usually rely on international celebrities and their pictures, along with catchy, yet fake news leads.”

This is not the only incident involving Angelina Jolie. Recently, the actor has given birth to two children, and spammers took advantage of the event in order to infect more computers. The spam campaign following the event wrongfully announced the fact that Jolie gave birth to no less than five children, and even offered users a link to a website allegedly hosting a small video with the event. The announcement, combined with Angelina Jolie’s fame was meant to take advantage of users’ hunger for sensational events.

Once on the respective page, users were shown an image impersonating a flash video player. When the user landed on the compromised webpage, the download started immediately, without any user intervention (a procedure also refered to as drive-by download). The binary file was infected with Trojan.Downloader.Exchanger.Gen.1, a piece of malware that has been widely used in another spam campaign promoting an alleged antivirus utility, called Antivirus XP 2008.

Although the approach is relatively new, the underlying technique has been widely used in the past. This campaign mostly targets computer users who are not educated in computer security - as they are not aware about free online scanners offered by major security providers.


The spam message directs the user to a legitimate webpage who’s index page has been doubled to facilitate the attack. For instance, while the normal home page is index.php, the compromised URL would always end in index1.php. This secondary index page is neatly crafted using the Windows Vista look-and-feel (the Aero wallpaper and icon buttons). The professional look dramatically contributes to gaining users’ confidence, but there are a few details that should tip off the visitor about the scam.

For instance, the virus top on the upper right side of the screen displays the most aggressive viruses that were active during May - meaning the page has not been updated. Secondly, the other text elements are written in plain English, with ambiguous explanations (such as ”Trojan attacks damage more than $3 million/hour.”) The spam message itself is written using poor grammar, with multiple obfuscations to trick spam filters.

”This spam wave built on an older recipe, making heavy use of text obfuscation in order to prevent spam filters from identifying and marking the message as junk,” said Vlad Valceanu. “The message itself should be enough of a warning for the user that the advertised piece of software is not legitimate and might come from ’unorthodox’ sources. More than that, users should pay extra attention to webpages that automatically try to download a file on the computer.”

Once installed on the computer, the rogue antivirus utility would stealthily start installing other high security risks such as adware, spyware or other malware from multiple servers or sources on the internet. Also, when run, the antivirus would display that it found multiple fake or false security threats on the host computer. This is a common tactic for rogue security applications, as they try to mislead unaware computer users and make them pay for the “full” version of a bogus utility.

Source: BitDefender News Center
<>

P.S. Such headlines are not limited to dealing with Angelina Jolie or other such celebrities and such malware also comes by means of emails with other titles, such as claiming to be news and weather information, news of military operations by US and allied forces in Iraq, Afghanistan, or claims that attack on Iran has started, and many other such headlines.

The advice can only be as always... DO NOT OPEN such emails.

Most web malware found on legitimate websites

by Michael Smith (Veshengro)

More than two thirds of web-based malware is now found on legitimate web sites, according to a report by security supplier Scansafe. This represents an increase of 407% in comparison with May of last year, that is to say May 2007.

According to a senior security researcher at Scansafe hackers have moved away from direct attacks like social engineering to focus on indirect attacks that use trusted brand names.

Just because you are accessing a well-known site you definitely and absolutely cannot and should not assume that that site if safe. At this presently moment thousands of legitimate web sites are being compromised on a daily basis.

According to the report there has also been a 220% increase in the different kinds of web-based malware in the past year.

According to Scansafe authentication-bypass and password stealing malware has grown the fastest with an 855% increase, which puts sensitive corporate data at serious risk.

Since October last year there have been hundreds of thousands of mainly China-based attacks, in which hackers passed malicious code to visitors on completely legitimate websites.

The computers of visitors to those sites are infected when they are redirected to malicious servers using a code injection method based on the database query language SQL.

A number of legitimate websites have thus been attacked in the USA and the United Kingdom, amongst them the Wal-Mart's website in the USA, as well as the websites of the Royal Statistical Society, National Media Museum, Skills for Care, and a number of businesses in the UK.

Unlike in the past, so it would appear, a much larger number malicious networks and servers were used in those recent attacks. Whether this means that the attacker or attackers has or have changed tactics or whether we are seeing a copycat is still not clear at this moment, it would seem.

The one thing this might point to though is a government sponsored attack, maybe. Rumor has it, though that is rumor from serious professionals, that many of the attacks from China are in fact coming from security services and military in that country. Maybe we are seeing an attempt to find out weaknesses in the systems in order to attack much more sensitive places next.

© M Smith (Veshengro), June 2008

Users' Bad Habits Invite Malware

Some estimates suggest spyware problems in the U.S. are decreasing, but writers of all kinds of malware are prevailing – partly because of computer user behavior, antispyware experts have stated.

Computer users far too often run outdated antivirus software, operating systems and browsers that have not been updated or patched since time immemorial because they're scared of change, said Janie "CalamityJane" Whitty, administrator of security software vendor Lavasoft's online support forums.

Whitty sees people running a 2003 version of antivirus software, she said during an Anti-Spyware Coalition conference in Washington, D.C. "The nature of malware has changed since 2003," she added.

In addition to problems caused by users, there's a healthy underground market for the kinds of data compromised by spyware and other malware, said Stefan Savage, director of the Collaborative Center for Internet Epidemiology and Defenses at the University of California in San Diego. The center monitored a popular malware-trading IRC forum for about six months in 2006 and found the advertised value of compromised bank accounts offered there was US$54 million.

While some estimates show the spyware problem shrinking, U.S. companies and consumers are losing the battle against malware in general, Savage said. Antivirus vendors, in unguarded moments, will say they're able to catch less and less malware as criminals become more sophisticated, he said.

The chances of an Internet fraudster getting caught are "virtually zero," he added.

"By any objective measure... this is something we end up losing on," Savage said. "The more money these guys make, the more money they can invest to get better."

The panel on consumer behavior kicked off a day-long session on fighting spyware, during which many experts said they continue to have major concerns about spyware and other malware. Those concerns remain despite Consumer Reports' annual estimate of spyware that suggests the problem is declining. The magazine estimated that 850,000 U.S. households had to replace computers in the first half of 2007, with the cost of fighting spyware at $1.7 billion for the year. In 2006, spyware cost U.S. individuals and businesses an estimated $2.6 billion, the magazine said.

Part of the problem is that people hang on to outdated operating systems and browsers, even though newer ones have better security controls, because they don't want to learn how to operate the new software, Whitty said. "The malware changes," she said. "If we don't change with it, they're going to win."

Computer users seem to be of two minds when it comes to giving up personal information, added Susannah Fox, associate director at the Pew Internet and American Life Project, a research organization. Many young computer users will refuse to disclose personal information to e-commerce sites, she said. "But yet this is the same group that is putting their whole lives" on social-networking sites, she said. One private detective has told Fox that social-networking sites make it significantly easier to track down details about people, Fox said.

No one hast to have outdated antivirus and anti-spyware and anti-malware software. There are great programs out there to be had for FREE that will do the job properly and often better than the paid-for bits of software and on the other hand there are also operating systems out there available for free that are not even susceptible to any such threats. However, for the Windows PC user rather than the Linux PC user antivirus and other protection software, as well as all the patches, is a must and programs like AVG from Grisoft.com will give great anti-virus protection for FREE, and then there is Spyware Search & Distroy, Spyware Blaster, and AdAware. All are free to the home user. All people must do is (1) download and install then, (2) regularly, ideally daily, update them and (3) run regular checks.

A protected Windows PC is a happy PC. Otherwise get a Linux PC; that is an even happier PC.

Michael Smith (Veshengro), February 2008