Posted Tuesday, October 20, 2009 3:10 PM by mmpc
As we’ve mentioned before, your average user is the most at risk of getting infected these days. So, with the release of Microsoft Security Essentials recently en masse, we’re really able to see some of the fruits of our labour over the last few years. We’re very pleased to see such a positive response to MSE, with many new home users giving it a try, which as you can imagine, makes us all happy little Vegemites*.
As you might expect, we see pretty different infection types from home-users versus the enterprise. Generally, infection vectors for the home user are web-based; either via malicious websites or by being enticed to download something that is, how you say ‘not so much with the good’. The term ‘home user’ generalises – computer-based experience of these users covers a broad spectrum. The savvier of these computer users, one would expect, would have a better chance of avoiding infection. However this is not entirely true; as we’ve mentioned in previous posts, savvy computer users actually open themselves up to more risks while they’re exploring the deeper darker depths of what the Internet has to offer.
To wit, after MSE’s release, we’ve seen a spike in a particular variant of Win32/Bifrose – Backdoor:Win32/Bifrose.EO. Why, you ask? Well, it seems that the malware authors (or perhaps an unsuspecting pirate) are distributing a ‘cracked’ version of Windows that comes pre-infected for your convenience – labelled, fittingly, “Vista Black Edition”. Just to clarify, this means computer users are downloading an ISO of pirated Microsoft software (and saving to disk on a Genuine Windows system) and a free Microsoft anti-virus product is alerting them to a potential infection in their freshly stolen software. I’m not really sure if ‘irony’ really emphasises the situation enough. But hey, at least the Windows is free**, right?
What’s even more interesting (read: funny) is that despite this, it seems this isn’t enough to stop people from trying to utilize their ill-gotten gains. Underground forums are teeming with helpful hints on how to disinfect your newly acquired (though somewhat ‘not as advertised’) software. No doubt some of the instructions include using other pirated software products.
So you see kids, illegal software is seldom free of all cost. Chances are you’re paying for it in ways you didn’t consider.
Matt McCormack
MMPC Melbourne
*The team down in Australia at least
** Disclaimer: “Free” may be changed at any time to actually mean “cost you”, with one or more of the following words appended to the end: passwords, bandwidth, login information, bank account details, email accounts, credit rating, dignity, ...
Wednesday, 21 October 2009
Scareware Serving Conficker.B Infection Alerts Spam Campaign
A fake "conficker.b infection alert" spam campaign first observed in April, 2009 (using the following scareware domains antivirus-av-ms-check .com; antivirus-av-ms-checker .com; ms-anti-vir-scan .com; mega-antiviral-ms .com back then) is once again circulating in an attempt to trick users into installing "antispyware application", in this case the Antivirus Pro 2010 scareware.
This campaign is directly related to last week's Microsoft Outlook update campaign, with both of these using identical download locations for the scareware.
The following is an extensive list of the domains involved in the campaigns:
abumaso3tkamid .com - Email: drawn@ml3.ru
afedodevascevo .com - Email: sixty@8081.ru
alertonabert .com - Email: flop@infotorrent.ru
alertonbgabert .com - Email: vale@e2mail.ru
alioneferkilo .com - Email: va@blogbuddy.ru
anobalukager .com - Email: chalkov@co5.ru
anobhalukager .com - Email: humps@infotorrent.ru
bufertongamoda .com - Email: kurt@8081.ru
buhafertadosag .com - Email: bias@co5.ru
buhervadonuska .com - Email: vale@e2mail.ru
bulakeskatorad .com - Email: bias@co5.ru
bulerkoseddasko .com - Email: bias@co5.ru
buleropihertan .com - Email: def@co5.ru
celiminerkariota .com - Email: morse@corporatemail.ru
certovalionas .com - Email: kurt@8081.ru
dabertugaburav .com - Email: def@co5.ru
elxolisdonave .com - Email: curb@cheapmail.ru
enkafuleskohuj .com - Email: kerry@freemailbox.ru
ertanueskayert .com - Email: xmas@co5.ru
ertonaferdogalo .com - Email: kerry@freemailbox.ru
ertu6nagertos .com - Email: recipe@isprovider.ru
ertubedewse .com - Email: weak@infotorrent.ru
ertugasedumil .com - Email: chalkov@co5.ru
ertugaskedumil .com - Email: humps@infotorrent.ru
ertunagertos .com - Email: def@co5.ru
erubamerkadolo .com - Email: kerry@freemailbox.ru
fedostalonkah .com - Email: bias@co5.ru
ftahulabedaso .com - Email: raced@corporatemail.ru
gumertagionader .com - Email: seize@e2mail.ru
huladopkaert .com - Email: chute@infotorrent.ru
iobacebauiler .com - Email: roy@corporatemail.ru
itorkalione .com - Email: pygmy@8081.ru
julionejurmon .com - Email: jacob@freemailbox.ru
julionermon .com - Email: pygmy@8081.ru
konitorsabure .com - Email: chalkov@co5.ru
konitorswabure .com - Email: humps@infotorrent.ru
lersolamaderg .com - Email: chalkov@co5.ru
lersolamgaderg .com - Email: humps@infotorrent.ru
linkertagubert .com - Email: kerry@freemailbox.ru
lionglenhrvoa .com - Email: sixty@8081.ru
liposdakoferda .com - Email: leaf@corporatemail.ru
lopastionertu .com - Email: cues@e2mail.ru
nebrafsofertu .com - Email: humps@infotorrent.ru
nuherfodaverta .com - Email: morse@corporatemail.ru
nulerotkabelast .com - Email: dealt@8081.ru
nulkersonatior .com - Email: dealt@8081.ru
obuleskinrodab .com - Email: xmas@co5.ru
ofaderhabewuit .com - Email: kerry@freemailbox.ru
okavanubares .com - Email: chalkov@co5.ru
okaveanubares .com - Email: humps@infotorrent.ru
onagerfadusak .com - Email: cues@e2mail.ru
orav4abustorabe .com - Email: drawn@ml3.ru
oscaviolaner .com - Email: larks@freemailbox.ru
ovuiobvipolak .com - Email: sixty@8081.ru
ovuioipolak .com - Email: bias@co5.ru
paferbasedos .com - Email: chalkov@co5.ru
pafersbasedos .com - Email: humps@infotorrent.ru
polanermogalios .com - Email: dealt@8081.ru
rdafergfvacex .com - Email: jacob@freemailbox.ru
rtugamer5tobes .com - Email: drawn@ml3.ru
rtugamertobes .com - Email: kw@co5.ru
scukonherproger .com - Email: kazoo@isprovider.ru
shuretrobaniso .com - Email: frail@infotorrent.ru
tarhujelafert .com - Email: raced@corporatemail.ru
tavakulio5nkab .com - Email: recipe@isprovider.ru
tavakulionkab .com - Email: def@co5.ru
tertunavogav .com - Email: la@freemailbox.ru
tertunwavogav .com - Email: drawn@ml3.ru
tsabunerkadosa .com - Email: humps@infotorrent.ru
tsarbunerkadosa .com - Email: humps@infotorrent.ru
tubanerdavaf .com - Email: chalkov@co5.ru
tubanerdavjaf .com - Email: halkov@co5.ru
uhajokalesko .com - Email: flop@infotorrent.ru
uhajokvfalesko .com - Email: flop@infotorrent.ru
ulioperdanogad .com - Email: vale@e2mail.ru
uliopewrdanogad .com - Email: kerry@freemailbox.ru
uplaserdunavats .com - Email: dealt@8081.ru
utka3merdosubor .com - Email: drawn@ml3.ru
utkamerdosubor .com - Email: kw@co5.ru
utorganedoskaw .com - Email: kerry@freemailbox.ru
utorgtanedoskaw .com - Email: xmas@co5.ru
uvgaderbotario .com - Email: def@co5.ru
vudermaguliermot .com - Email: leaf@corporatemail.ru
vuilerdomegase .com - Email: leaf@corporatemail.ru
vuilleskomandar .com - Email: seize@e2mail.ru
vulertagulermos .com - Email: dealt@8081.ru
vuretronulevka .com - Email: dealt@8081.ru
weragumasekasuke .com - Email: kazoo@isprovider.ru
werynaherdobas .com - Email: dealt@8081.ru
Despite the comprehensive portfolio of domains used, relying on spam to increase revenue from scareware sales is prone to fail, in this specific case due to the lack of event-based social engineering theme, something that was present in the first campaign.
This campaign is directly related to last week's Microsoft Outlook update campaign, with both of these using identical download locations for the scareware.
The following is an extensive list of the domains involved in the campaigns:
abumaso3tkamid .com - Email: drawn@ml3.ru
afedodevascevo .com - Email: sixty@8081.ru
alertonabert .com - Email: flop@infotorrent.ru
alertonbgabert .com - Email: vale@e2mail.ru
alioneferkilo .com - Email: va@blogbuddy.ru
anobalukager .com - Email: chalkov@co5.ru
anobhalukager .com - Email: humps@infotorrent.ru
bufertongamoda .com - Email: kurt@8081.ru
buhafertadosag .com - Email: bias@co5.ru
buhervadonuska .com - Email: vale@e2mail.ru
bulakeskatorad .com - Email: bias@co5.ru
bulerkoseddasko .com - Email: bias@co5.ru
buleropihertan .com - Email: def@co5.ru
celiminerkariota .com - Email: morse@corporatemail.ru
certovalionas .com - Email: kurt@8081.ru
dabertugaburav .com - Email: def@co5.ru
elxolisdonave .com - Email: curb@cheapmail.ru
enkafuleskohuj .com - Email: kerry@freemailbox.ru
ertanueskayert .com - Email: xmas@co5.ru
ertonaferdogalo .com - Email: kerry@freemailbox.ru
ertu6nagertos .com - Email: recipe@isprovider.ru
ertubedewse .com - Email: weak@infotorrent.ru
ertugasedumil .com - Email: chalkov@co5.ru
ertugaskedumil .com - Email: humps@infotorrent.ru
ertunagertos .com - Email: def@co5.ru
erubamerkadolo .com - Email: kerry@freemailbox.ru
fedostalonkah .com - Email: bias@co5.ru
ftahulabedaso .com - Email: raced@corporatemail.ru
gumertagionader .com - Email: seize@e2mail.ru
huladopkaert .com - Email: chute@infotorrent.ru
iobacebauiler .com - Email: roy@corporatemail.ru
itorkalione .com - Email: pygmy@8081.ru
julionejurmon .com - Email: jacob@freemailbox.ru
julionermon .com - Email: pygmy@8081.ru
konitorsabure .com - Email: chalkov@co5.ru
konitorswabure .com - Email: humps@infotorrent.ru
lersolamaderg .com - Email: chalkov@co5.ru
lersolamgaderg .com - Email: humps@infotorrent.ru
linkertagubert .com - Email: kerry@freemailbox.ru
lionglenhrvoa .com - Email: sixty@8081.ru
liposdakoferda .com - Email: leaf@corporatemail.ru
lopastionertu .com - Email: cues@e2mail.ru
nebrafsofertu .com - Email: humps@infotorrent.ru
nuherfodaverta .com - Email: morse@corporatemail.ru
nulerotkabelast .com - Email: dealt@8081.ru
nulkersonatior .com - Email: dealt@8081.ru
obuleskinrodab .com - Email: xmas@co5.ru
ofaderhabewuit .com - Email: kerry@freemailbox.ru
okavanubares .com - Email: chalkov@co5.ru
okaveanubares .com - Email: humps@infotorrent.ru
onagerfadusak .com - Email: cues@e2mail.ru
orav4abustorabe .com - Email: drawn@ml3.ru
oscaviolaner .com - Email: larks@freemailbox.ru
ovuiobvipolak .com - Email: sixty@8081.ru
ovuioipolak .com - Email: bias@co5.ru
paferbasedos .com - Email: chalkov@co5.ru
pafersbasedos .com - Email: humps@infotorrent.ru
polanermogalios .com - Email: dealt@8081.ru
rdafergfvacex .com - Email: jacob@freemailbox.ru
rtugamer5tobes .com - Email: drawn@ml3.ru
rtugamertobes .com - Email: kw@co5.ru
scukonherproger .com - Email: kazoo@isprovider.ru
shuretrobaniso .com - Email: frail@infotorrent.ru
tarhujelafert .com - Email: raced@corporatemail.ru
tavakulio5nkab .com - Email: recipe@isprovider.ru
tavakulionkab .com - Email: def@co5.ru
tertunavogav .com - Email: la@freemailbox.ru
tertunwavogav .com - Email: drawn@ml3.ru
tsabunerkadosa .com - Email: humps@infotorrent.ru
tsarbunerkadosa .com - Email: humps@infotorrent.rutubanerdavaf .com - Email: chalkov@co5.ru
tubanerdavjaf .com - Email: halkov@co5.ru
uhajokalesko .com - Email: flop@infotorrent.ru
uhajokvfalesko .com - Email: flop@infotorrent.ru
ulioperdanogad .com - Email: vale@e2mail.ru
uliopewrdanogad .com - Email: kerry@freemailbox.ru
uplaserdunavats .com - Email: dealt@8081.ru
utka3merdosubor .com - Email: drawn@ml3.ru
utkamerdosubor .com - Email: kw@co5.ru
utorganedoskaw .com - Email: kerry@freemailbox.ru
utorgtanedoskaw .com - Email: xmas@co5.ru
uvgaderbotario .com - Email: def@co5.ru
vudermaguliermot .com - Email: leaf@corporatemail.ru
vuilerdomegase .com - Email: leaf@corporatemail.ru
vuilleskomandar .com - Email: seize@e2mail.ru
vulertagulermos .com - Email: dealt@8081.ru
vuretronulevka .com - Email: dealt@8081.ru
weragumasekasuke .com - Email: kazoo@isprovider.ru
werynaherdobas .com - Email: dealt@8081.ru
Despite the comprehensive portfolio of domains used, relying on spam to increase revenue from scareware sales is prone to fail, in this specific case due to the lack of event-based social engineering theme, something that was present in the first campaign.
ChoicePoint to pay $275,000 in latest data breach
By Elinor Mills
InSecurity Complex
CNet News
October 20, 2009
ChoicePoint, one of the nation's largest data brokers, has been fined $275,000 by the U.S. Federal Trade Commission for a data breach that exposed personal information of 13,750 people last year.
In April 2008, ChoicePoint turned off a key electronic security tool that it used to monitor access to one of its databases and failed to notice the problem for four months, according to an FTC statement.
During that period, unauthorized searches were conducted for 30 days on a ChoicePoint database that contained Social Security numbers and other sensitive information, the FTC said.
The FTC alleged that ChoicePoint's conduct violated a 2006 court order requiring the company to institute a comprehensive information security program following a 2005 breach that compromised the personal information of more than 163,000 people and resulted in at least 800 cases of identity fraud. The company was ordered to pay $10 million in civil penalties and $5 million to consumers in that case.
InSecurity Complex
CNet News
October 20, 2009
ChoicePoint, one of the nation's largest data brokers, has been fined $275,000 by the U.S. Federal Trade Commission for a data breach that exposed personal information of 13,750 people last year.
In April 2008, ChoicePoint turned off a key electronic security tool that it used to monitor access to one of its databases and failed to notice the problem for four months, according to an FTC statement.
During that period, unauthorized searches were conducted for 30 days on a ChoicePoint database that contained Social Security numbers and other sensitive information, the FTC said.
The FTC alleged that ChoicePoint's conduct violated a 2006 court order requiring the company to institute a comprehensive information security program following a 2005 breach that compromised the personal information of more than 163,000 people and resulted in at least 800 cases of identity fraud. The company was ordered to pay $10 million in civil penalties and $5 million to consumers in that case.
Tuesday, 20 October 2009
Classified Info on Dangerous Chemicals Hacked
The Korea Times
10-17-2009
Hackers stole classified information on dangerous chemicals in their raid on the South Korean army computer network in what was believed to be an attack by North Korea, Yonhap News Agency reported Saturday, quoting government officials.
The Chemicals Accident Response Information System, used by 589 South Korean government agencies including fire and police stations, was accessed by hackers on March 5. Hackers appear to have broken into the system using the ID of a South Korean army officer whose personal computer was infected by a virus, according to officials.
"We believe the hacker tapped into the system using the ID, withdrawing classified information of 1,350 dangerous chemicals," an army official was quoted as saying by Yonhap. "The government believes North Korea could be behind the hacking. We are continuing our investigation."
The revelation comes less than three months after cyber attacks severely slowed or disrupted dozens of South Korean government and business Web sites, including those of the presidential office and ministries of defense and foreign affairs. Rumors were rampant then that North Korean hackers orchestrated the attacks, although they have yet to be substantiated.
"We are trying to find out exactly how much information has been withdrawn," another unnamed official at Seoul's Environment Ministry was quoted as saying, adding the government has asked organizations dealing with the chemicals to tighten security.
Unnamed intelligence sources in Seoul said in May that North Korea operates a cyber warfare unit that seeks to disrupt South Korean and U.S. military networks and visits U.S. military sites more frequently than any other country.
South Korea and the U.S. signed a memorandum of understanding on April 30 to bolster cooperation in fighting cyber terrorism against their defense networks.
10-17-2009
Hackers stole classified information on dangerous chemicals in their raid on the South Korean army computer network in what was believed to be an attack by North Korea, Yonhap News Agency reported Saturday, quoting government officials.
The Chemicals Accident Response Information System, used by 589 South Korean government agencies including fire and police stations, was accessed by hackers on March 5. Hackers appear to have broken into the system using the ID of a South Korean army officer whose personal computer was infected by a virus, according to officials.
"We believe the hacker tapped into the system using the ID, withdrawing classified information of 1,350 dangerous chemicals," an army official was quoted as saying by Yonhap. "The government believes North Korea could be behind the hacking. We are continuing our investigation."
The revelation comes less than three months after cyber attacks severely slowed or disrupted dozens of South Korean government and business Web sites, including those of the presidential office and ministries of defense and foreign affairs. Rumors were rampant then that North Korean hackers orchestrated the attacks, although they have yet to be substantiated.
"We are trying to find out exactly how much information has been withdrawn," another unnamed official at Seoul's Environment Ministry was quoted as saying, adding the government has asked organizations dealing with the chemicals to tighten security.
Unnamed intelligence sources in Seoul said in May that North Korea operates a cyber warfare unit that seeks to disrupt South Korean and U.S. military networks and visits U.S. military sites more frequently than any other country.
South Korea and the U.S. signed a memorandum of understanding on April 30 to bolster cooperation in fighting cyber terrorism against their defense networks.
VoIP hack suspect fugitive extradited back to US
By John Leyden
The Register
19th October 2009
A Venezuelan hacking suspect arrested in Mexico last February on computer hacking and fraud charges faces a court appearance in New Jersey on Tuesday, following his extradition to the US last week.
Edwin Pena, 26, a former Miami resident, fled from US justice in August
2006 two months after he was bailed on charges of hacking into phone systems and stealing VoIP call credits. Pena allegedly resold these services in collusion with an accomplice, Robert Moore of Washington.
Pena and Moore raked in an estimated $1.4m through the alleged sale of 10 million voice call minutes stolen from telecoms suppliers.
Moore pleaded guilty multiple computer hacking and fraud offences in late 2007, resulting in a two year jail sentence. His admitted involvement in the scam involved scanning telecom supplier networks for vulnerabilities between June 2005 and October 2005. Pena, the alleged brains of the operation and major beneficiary, use Moore's reconnaissance to draw up a list of targets for attack.
The Venezuelan used brute force techniques to extract activation codes from vulnerable telecom supplier systems. Among those victimised was a Newark, New Jersey supplier of telecoms services.
The Register
19th October 2009
A Venezuelan hacking suspect arrested in Mexico last February on computer hacking and fraud charges faces a court appearance in New Jersey on Tuesday, following his extradition to the US last week.
Edwin Pena, 26, a former Miami resident, fled from US justice in August
2006 two months after he was bailed on charges of hacking into phone systems and stealing VoIP call credits. Pena allegedly resold these services in collusion with an accomplice, Robert Moore of Washington.
Pena and Moore raked in an estimated $1.4m through the alleged sale of 10 million voice call minutes stolen from telecoms suppliers.
Moore pleaded guilty multiple computer hacking and fraud offences in late 2007, resulting in a two year jail sentence. His admitted involvement in the scam involved scanning telecom supplier networks for vulnerabilities between June 2005 and October 2005. Pena, the alleged brains of the operation and major beneficiary, use Moore's reconnaissance to draw up a list of targets for attack.
The Venezuelan used brute force techniques to extract activation codes from vulnerable telecom supplier systems. Among those victimised was a Newark, New Jersey supplier of telecoms services.
Medical Records: Stored in the Cloud, Sold on the Open Market
By Kim Zetter
Threat Level
Wired.com
October 19, 2009
When patients visit a physician or hospital, they know that anyone involved in providing their health care can lawfully see their medical records.
But unknown to patients, an increasing number of outside vendors that manage electronic health records also have access to that data, and are reselling the information as a commodity.
The revelation comes in a recent New York Times article about how so-called "scrubbed" patient data isn't as anonymous as people think.
The piece focuses primarily on how anonymized data can be cross-bred with other publicly available databases, such as voting records, which subverts the anonymity. Buried near the end of the article is the news that medical data is collected, anonymized and sold, not by insurance agencies and health care providers, but by third-party vendors who provide medical-record storage in the cloud.
Electronic health record (EHR) services have been a growing industry in the last few years, according to Sue Reber, marketing director of the Certification Commission for Health Information Technology. Reber says most vendors used to simply sell software packages; once the product was sold, the vendor had no connection to the data stored in it. But an increasing number of companies have begun to offer web-based software-management applications that include database storage controlled and managed by the vendor.
Botnet Unleashes Variety Of New Phishing Attacks
By Kelly Jackson Higgins
DarkReading
Oct 19, 2009
The massive Zbot botnet that spreads the treacherous Zeus banking Trojan has been launching a wave of relatively convincing phishing attacks during the past few days -- the most recent of which is a phony warning of a mass Conficker infection from Microsoft that comes with a free "cleanup tool."
The wave of attacks began early last week targeting corporations in the form of email messages that alerted victims of a "system upgrade." Email is accompanied by poisoned attachments and links; in some cases it poses as a message from victims' IT departments, including their actual email domains, and alerts them about a "security upgrade" to their email accounts. The message then refers victims to a link to reset their mailbox accounts, and the link takes them to a site that looks a lot like an Outlook Web Access (OWA) page (PDF), but instead infects them with the Zeus Trojan.
Today, researchers at F-Secure spotted the botnet spamming out malware-laden email that tries to trick recipients with a convincing lure messages that says, "On October 22, 2009 server upgrade will take place."
"What we're seeing is an evolving campaign of different lures to see which one works," says Richard Wang, manager of Sophos Labs in the U.S.
The Zbot botnet, which is made up of 3.6 million PCs in the U.S., or 1 percent of all PCs in the country, according to data from Damballa, spreads the deadly Zeus Trojan. Zeus, which steals users' online financial credentials, represents 44 percent of all financial malware infections today, according to Trusteer.
Subscribe to:
Posts (Atom)