Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Friday, June 6, 2014

A Big Problem: Cryptolocker the Ransomware


Cryptolocker is back in the headlines, thanks to a coordinated effort to take down the computers and criminals that run the notorious "ransomware". But what is it? And how can you fight it?

Cryptolocker is ransomware: malicious software which holds your files to ransom

The software is typically spread through infected attachments to emails, or as a secondary infection on computers which are already affected by viruses which offer a back door for further attacks.
When a computer is infected, it contacts a central server for the information it needs to activate, and then begins encrypting files on the infected computer with that information. Once all the files are encrypted, it posts a message asking for payment to decrypt the files – and threatens to destroy the information if it doesn't get paid.

The authorities have won users a two-week window of safety
The National Crime Agency (NCA) announced yesterday that the UK public has got a "unique, two-week opportunity to rid and safeguard" themselves from Cryptolocker. The agency didn't go into more detail, but it seems likely that at least one of the central servers which Cryptolocker speaks to before encrypting files has been taken down.
The NCA has also taken down the control system for a related piece of software, known as GameOver Zeus, which provides criminals with a backdoor into users' computers. That back door is one of the ways a computer can be infected with Cryptolocker in the first place.
What that means is, until the window is closed – and the virus cycles to new servers – users who are infected with Cryptolocker won't lose their files to encryption. As a result, these users have the chance to remove the virus before it destroys data, using conventional anti-virus software. In other words, there has never been a better time to update the protection on your computer. 
But watch out – while the servers that control Cryptolocker are out of action, it's possible to be infected with it and not know. If you don't keep your computer clean, then at the end of the two-week period, you could be in for a nasty surprise.

Cryptolocker only infects PCs, but there are other types of ransomware
Cryptolocker is the name of one particular virus, which only infects Windows PCs, running XP, Vista, Windows 7 or Windows 8. So if you use an Apple computer, it can't affect you. Similarly, smartphones are safe from cryptolocker. 
Although it is the most famous example of ransomware, it's not the only one. Even in the two-week window, PC users may be infected with other types of ransomware, and Android and Mac OS users should carry on with their normal security precautions. Being safe from one type of malware doesn't mean you're safe from all of them.

If you've been infected by Cryptolocker, your files really are gone unless you have a backup
 
Some ransomware is little more than a confidence trickster, presenting a message asking for payment without having done anything to the user's files. Cryptolocker isn't like that: the software really does encrypt your files, to a strength which renders it unbreakable even by the fastest computers in the world – even if they had the entire lifetime of the universe to work on it.
 
That means you'll have to rely on any backups of your data to get it back. But it's important that you don't try and restore your data before you clear your computer of the infection, otherwise you could lose your backup, too.

Sometimes paying the ransom will work, sometimes it won't
Except, of course, there is another possibility. Some users hit with Cryptolocker report that they really did get their data back after paying the ransom – which is typically around £300. But there's no guarantee it will work, because cybercriminals aren't exactly the most trustworthy group of people. 
What's more, if the NCA really is bringing down the command and control servers, then the criminals may not be able to return the data, even if the ransom has been paid. There's also a whole load of viruses which go out of their way to look like Cryptolocker, and which won't hand back the data if victims pay. Plus, there's the ethical issue: paying the ransom funds more crime.

This article was originally posted on:

Wednesday, December 26, 2012

Scareware - Yes it is that Scary

Scareware aka smitfraud or rogue security software, is a type of software that is defined as malware. These types of malware not only try to disrupt your computer, but also try to trick you into conducting a transaction with your credit card.

These types of malware appear to users in the form of pop-ups that resemble Windows system messages, usually masquerading as an antivirus or antispyware software, a firewall application or a registry cleaner. 
The message displayed by this malware informs the user that the PC in use is in trouble and contains many security issues and a large number of virus infections.  The Popup claims that the software it is marketing will be able to remove all the infections, speed up your PC and optimize its performance.

Naive enough some people do fall for this lame trick, and they follow the pop-up instructions and submit their personal data along with credit card number to buy this rogue software that pretends to save their PCs.
These scareware are well known for their ability to lock or limit the usage of control panel, disable registry editor, and prevent the user from visiting legitimate valid antivirus websites.

Some of the scareware I have encountered and seen on different systems are: Antivirus 2007, 2008 and 2009, XP Antivirus 2010, WinFixer, DriveCleaner, and Malware Cleaner.

If you face a suspicious pop-up, you should carefully close it by right-clicking on the item in the task bar and select "Close" or by manually exit the browser by using the task manager (Ctrl-Alt-Delete). To protect your system from future attempts, install a good pop-up blocker and configure it to prevent pop-ups from sites that you haven’t allowed.

Don’t automatically click download when prompted, don’t follow suspicious links even if received from your known friends (they might be infected and unknowingly spreading the infection).

Keep all your software applications up to date, that includes: Java, Adobe Reader, Flash Player, Windows and certainly your Antivirus.
Remember: Scammers and Hackers will keep on finding new technical and non technical means to exploit systems and PCs. It is your job to avoid their traps.

Thursday, August 30, 2012

Watch out for the Facebook Scam!


Many Facebook users receive notifications by email when they are tagged in pictures, or if someone had written something on their wall and so on. This is not a really a good idea because of a newly discovered malware by the security firm "Sophos". Why isn't it a good idea? Basically, because this malware sends a fake email notification masquerading "Facebook Notification Emails" informing you that "one of your friends has tagged you in a picture". Once you click on the link provided in the email, a file that is able to infect your Windows-operated computer will be downloaded automatically, allowing hackers to gain control and access to your PC. 

This is how the email looks like:

How identify this Malware?
Usually, when Facebook sends you an email notification, it identifies the user that tagged you in a photo, wrote on your wall or sent you a message by displaying the Name or Alias. Notice that in the above picture, this email does not specify who tagged you, it just states that "one of your friends". So whenever you see "one of your friends" in the email notifications, do not open that email, just delete it and mark it as junk mail.

Another way to protect yourself from this scam is to stop email notifications in general. Who wants a bulk of email notifications in their inbox? It just causes your inbox to be congested and that will discourage you from checking your email more often. I advice you to stop these email notifications. So whenever you receive an email notification from Facebook, it will probably be a scam since you already stopped all email notifications. You can always check your Facebook notifications on the Facebook site itself. It is simple, easy and most importantly safe.

Always remember to keep your antivirus up to date, that will also help in identifying new malware.

Tuesday, June 5, 2012

Avoiding the Flame

After reading many articles and expert reviews about the Flame Virus I came up with the following summary

What is the Flame: Worm or Trojan
Flame is a complex attack toolkit, it is a TROJAN modified to have WORM like features, allowing it to replicate within local networks and removable media.
The initial entry point of Flame is still unknown – but once a system is infected, sKyWIper, another name for Flame virus, begins a sophisticated set of operations, including:
  • Running on Windows XP, Windows Vista and Windows 7 systems;
  • Scanning network resources;
  • Stealing information as specified;
  • Communicating to Control Servers over SSH and HTTPS protocols;
  • Detecting the presence of over 100 security products (AV, Anti-Spyware, FW, etc);
  • loading itself as a part of Winlogon.exe then injects to Explorer and Services;
  • Concealing its presence as ~ named temp files, just like Stuxnet and Duqu;
  • Attacking new systems over USB Flash Memory and local network;
  • Creating screen captures, Recording voice conversations;
  • Using SQLite Database to store collected information;
  • Utilizing PE encrypted resources;

Flame Complexity: Master Piece  
Flame is a huge package of modules accumulating up to 20 MB in size when fully deployed. Because of this, antivirus companies state that it is an extremely difficult piece of malware to analyze.
The reason why Flame is so big is because it includes many different libraries, such as for compression (zlib, libbz2, ppmd) and database manipulation (sqlite3).

Flame creation date: unknown
The developers of Flame were able to change the dates of creation of the files associated with this virus to 1992, 1994, 1995 and so on, but it’s very obvious that these dates are incorrect and they aim only to give false data to investigators.
Analyzers believe that the main Flame project was created in 2010, but is still undergoing active development to date. But there is big possibility that an earlier version of this virus existed before 2010.

Why the Name: Flame
Flame aka Flamer aka SKyWIper all different call signs for the same malware. The Flame virus consists of multiple modules, one main module is called Flame – as the picture indicates – The flame module is responsible for attacking and infecting additional computers, and this is mainly the reason behind this malware naming.
No one to claim the spoils
Although, no party has claimed responsibility for the creation and usage of this malware, but it is so obvious that it was not created by a group of hacktivists to send a certain message or anonymous hackers just for the lulz.
The complex anatomy of this malware along with the geographic spread of the targets leaves no doubt that great deal of resources were invested in the creation of this virus and that it was created by nation state in order to collect info on the operations of certain countries in the Middle East, including Iran, Lebanon, Syria, and so on. 
Here’s a map of the top 7 affected countries:
 
    
Stop the Flame: Update your Antivirus
In general, most of the recent malware are small in size to be easily hidden, usually between 100k and 700K, but in Flame's case things are totally different. The large size of the Flame malware is precisely why it wasn’t discovered two years ago. For who would doubt a nine megabytes ~ named temp file to be a malware database file.
Finally In order to remove this Malware follow one of the following links and install the appropriate removal tool / Antivirus:
  1. Mcafee Stinger
  2. BitDefender Flame Removal Tool
  3. AVG and Keep it updated