Showing posts with label malicious. Show all posts
Showing posts with label malicious. Show all posts

Tuesday, July 7, 2009

Internet Users Warned of Serious Computer Security Hole

Microsoft Corp. has taken the rare step of warning about a serious computer security vulnerability it hasn't fixed yet.

The vulnerability disclosed Monday affects Internet Explorer users whose computers run the Windows XP or Windows Server 2003 operating software.

It can allow hackers to remotely take control of victims' machines. The victims don't need to do anything to get infected except visit a Web site that's been hacked.

Security experts say criminals have been attacking the vulnerability for nearly a week. Thousands of sites have been hacked to serve up malicious software that exploits the vulnerability. People are drawn to these sites by clicking a link in spam e-mail.

The so-called ``zero day'' vulnerability disclosed by Microsoft affects a part of its software used to play video. The problem arises from the way the software interacts with Internet Explorer, which opens a hole for hackers to tunnel into.

Microsoft urged vulnerable users to disable the problematic part of its software, which can be done from Microsoft's Web site, while the company works on a ``patch'' _ or software fix _ for the problem.

Microsoft rarely departs from its practice of issuing security updates the second Tuesday of each month. When the Redmond, Washington-based company does issue security reminders at other times, it's because the vulnerabilities are very serious.

A recent example was the emergency patch Microsoft issued in October for a vulnerability that criminals exploited to infect millions of PCs with the Conficker worm. While initially feared as an all-powerful doomsday device, that network of infected machines was eventually used for mundane moneymaking schemes like sending spam and pushing fake antivirus software.

Agencies

Saturday, April 25, 2009

Has Conficker attacked thousands of PCs globally?

A malicious software programme known as Conficker that many feared would wreak havoc on April 1 is slowly being activated, weeks after being dismissed as a false alarm, security experts said.

Conficker, also known as Downadup or Kido, is quietly turning thousands of personal computers into servers of e-mail spam and installing spyware, they said.

The worm started spreading late last year, infecting millions of computers and turning them into "slaves" that respond to commands sent from a remote server that effectively controls an army of computers known as a botnet.

Its unidentified creators started using those machines for criminal purposes in recent weeks by loading more malicious software onto a small percentage of computers under their control, said Vincent Weafer, a vice president with Symantec Security Response, the research arm of the world's largest security software maker, Symantec Corp.

"Expect this to be long-term, slowly changing," he said of the worm. "It's not going to be fast, aggressive."

Conficker installs a second virus, known as Waledac, that sends out e-mail spam without knowledge of the PC's owner, along with a fake anti-spyware program, Weafer said. The Waledac virus recruits the PCs into a second botnet that has existed for several years and specializes in distributing e-mail spam.

"This is probably one of the most sophisticated botnets on the planet. The guys behind this are very professional. They absolutely know what they are doing," said Paul Ferguson, a senior researcher with Trend Micro Inc, the world's third-largest security software maker.

He said Conficker's authors likely installed a spam engine and another malicious software program on tens of thousands of computers since April 7.

He said the worm will stop distributing the software on infected PCs on May 3 but more attacks will likely follow. "We expect to see a differen
t component or a whole new twist to the way this botnet does business," said Ferguson, a member of The Conficker Working Group, an international alliance of companies fighting the worm.

Researchers had feared the network controlled by the Conficker worm might be deployed on April 1 since the worm surfaced last year because it was programmed to increase communication attempts from that date. The security industry formed the task force to fight the worm, bringing widespread attention that experts said robably scared off the criminals who command the slave computers.

The task force initially thwarted the worm using the Internet's traffic control system to block access to servers that control the slave computers. Viruses that turn PCs into slaves exploit weaknesses in Microsoft's Windows operating system. The Conficker worm is especially tricky because it can evade corporate firewalls by passing from an infected machine onto a USB memory stick, then onto another PC.

The Conficker botnet is one of many such networks controlled by syndicates that authorities believe are based in eastern Europe, Southeast Asia, China and Latin America.

Agencies

Monday, November 10, 2008

Obama talk steals the show

While the race to the US presidency has ended with Barack Obama winning by a landslide, the race for new Web threats related to his victory has now begun. Trend Micro Research Manager Ivan Macalintal reported of spam messages that started circulating to spread malware, within hours after Obama delivered his acceptance speech.

Says Amit Nath, Country Manager, India & SAARC, Trend Micro: "The spam which has so far affected computers in China, US and Japan, may come with a subject line like, 'Election Night Results' or 'Priorities for the New President' or 'Fear of a Black President'. The modus operandi of infecting is quite stealthy, which may lead several gullible users infected, the email invites readers to click on a link to watch Obama's speech, this link leads them to a make-believe website, 'America.gov'.

The video pane reads, 'Loading Player', and prompts to download Adobe Flash Player. To further make it look genuine, the site also provides the estimated time for downloading as 4-6 seconds! This tricks users into clicking the link that serves the malicious file adobe_flash9.exe."

Trend Micro detects the downloaded Trojan file as TROJ_DLOADER.ISZ of 3,261 bytes size. Trend Micro researcher Macalintal further points out that this spam run is from the same group that sends fake bank certificate spam (targeting Wachovia, Bank of America, Merrill Lynch, and a German bank's account holders). The properties of this attack still suggest cybercriminals using a fast-flux network of compromised computers. This spam run is currently still underway as of this writing, using different subjects and fast-changing domains.

Warns Nath: "Trend Micro analysis reveals that TROJ_DLOADER.ISZ downloads an infostealer, TSPY_PAPRAS.AM, which in turn drops a rootkit component which hides its routines. This infostealer dives into network packets to scour for passwords using Carnivore by searching strings like ftp, icq, imap, and pop3. It sends stolen information to a server in Ukraine. The Trojan is known to infect Windows 98, ME, NT, 2000, XP and Server 2003."

The malicious URL where this Trojan is downloaded is already blocked by the Trend Micro Smart Protection Network.

Total Pageviews