Jan 21, 2009

Cyber criminals use cloud computing

McAfee released yearly threat report recently. There are some interesting facts about new tactics in cyber crimes.

Newest method is so called "cloud computing". That means that services will be delivered over internet and usage of scattered computing. McAfee excepts that this will become more popular this year.

Global financial crisis help to bring also other options to fraud. Fake bills, law services and investments offer tools to cheat money from people.

Labels: ,

Nov 3, 2008

Scareware brings a lot of money

Antivirus XP rogue is one of those scareware software of which I blogged earlier. It claims that computer is infected and that user needs to pay $49.95 program for disinfecting the machine.

New York Times wrote recently that people who spread that program might get even $60,000 to $160,000 per month. Russian hacker NeoN had posted that information to Russian electronic bulletin board.

Problem with scareware/rogue programs is that they are always changing. When people learn learn to avoid certain rogue, a new one is already there.

Labels: , ,

Aug 24, 2008

Interview with Dakeyras

Dakeyras, a future malware fighter from Malware Removal University, asked me for interview regarding malware/security issues for his blog and I was happy to agree.

Read entire interview here

Labels: , ,

Jul 28, 2008

More and more different malware

Mikko Hyppönen from F–secure told that when before bad guys tried to infect million
computers with one virus, now same attempt happens with thousand viruses. That is clear sign from tactic change.

Amount of virus definitions has increased vastly after 2005, says Hyppönen.

At that time there was 145 000 definitions in F-secure database, in 2006 over 209 000 and last year 2007 almost half million.

Nowadays amount is one million which was published last Thursday in F-secure's weblog

Rate of increase is really scary.

Labels: ,

Jun 11, 2008

New Rogue AntiSpyCheck

AntiSpySpider is a rogue anti-spyware program which is been advertised and installed by malware.

BleepingComputer has made a nice self-help guide for removing that rogue.

Labels: ,

May 29, 2008

Messenger virus plagues Finland

There is a messenger virus in the wild now in Finland. It will try to get user to open a picture in strange-looking web site. But that picture is actually malware installer. After installation it will try to make other Messenger users to open pictures by using following sentences (translated from Finnish):
"Hi :) Are u here? :D", "Is this your pic?" ja "U were pretty drunk :D"

File names vary a lot. One of the names is photo95.JPG-www.msnimages.com.
Some of these files are hosted under .fi domains.

This is a newer variant of old Sdbot family, Backdoor.Win32.SdBot.ebp. That will make
computer controllable by attacker.

Mikko Hyppönen from F-secure thinks that trojan might have been made in Finland and that latest F-secure virus database will recognize that threat.

Labels: , ,

May 22, 2008

Microsoft patented Proactive Virus Protection

Microsoft left that patent on year 2004 but it got accepted on Tuesday. Similar technique has been used in virus protection for a long time.

This is based on comparison about similarities between a possible malware and information already in database.

For example McAfee and Norton have used similar technique for years before Microsoft's patent.

We'll see if Microsoft contacts McAfee, Norton, Kaspersky etc. soon for some fees.

Source

Labels: , ,

May 21, 2008

Parody site WhiteHouse.org spreads malware

Trend Micro blogged recently about that issue. Problem is here that not only common visitors will get infected but also those who think that WhiteHouse.org is official website for White House. Real website is www.whitehouse.gov.

Malware there is malicious JavaScript code. It is unclear whether or not site has been yet cleaned.

Labels: , ,

May 14, 2008

New rogue AntiSpySpider in the wild

AntiSpySpider is a rogue anti-spyware program which is been advertised and installed by malware.

This one isn't very easy to remove as it disables both Task Manager and regedit.exe

BleepingComputer has a nice self-help guide for removing that nasty.

Labels: ,

Apr 29, 2008

Websites more and more under attack

Security company Sophos stated in new report that one web site is under attack every five seconds.

It counted that 15 000 web sites got infected daily from January to March. Last year daily average was 6 000 web sites so threats really are in the rise.

79 per cent of web sites infected this year are legal sites. But there is also good news. Amount of malware included in emails has been decreased. Now one email of 2500 contains malware and that is 40 per cent less than last year.

But not everything is so bright. 92 per cent of all emails were spam during Jan-Mar. Greatest spammer was USA and other great spammers were eg. Russia and China.

Source: Sophos

Labels: , , ,

Apr 12, 2008

Number of malware reached one million

Symantec has released it's semi-annual security report. According to that report, number of malware reached one million. Scary thing is that half of that amount has been created during the last year. Total raise was 136 per cent compared to year 2006.

Majority of malware are for Windows and they are just new versions of already existing malware, usually useful for criminals.

Now most popular malware are trojans which open access to computer and download other malware as well as keylogger which activates on certain web sites only (like banker trojans).

The raise of malware is because of criminals who pay for programmers that they will make new malware for them. New versions are needed that they can steal even bigger amount of money from victims.

Source: Symantec

Labels: , ,

Apr 4, 2008

Banker trojan strikes back

I wrote like a month ago about banker
spreading widely in Finland.

Now another hot Russian lady, Tatjana, seeks for love in Finnish-written email but has a dangerous link included.

Domain originates this time to China.

Labels: , ,

Feb 21, 2008

Banker trojan spread widely yesterday in Finland

Yesterday many Finns got a new kind of spam - this time in Finnish.

It warned of a radioactive cloud spreading from a nuclear reactor close to the Finnish city of Mikkeli.

Well, there is no nuclear power plant near Mikkeli so it didn't get much success ;)

Another version claims to be from a woman seeking love.

File needed to view pictures was actually a banker trojan targeted to Finnish online banks.

Read more here

Labels: , ,

Feb 19, 2008

In 1.3 percent of Google searches have malware hits

During one year research Google has found more than 3 million malware installing web sites. Majority of them are porn sites but also other sites are listed. Two thirds of those sites are hosted in China.

Most worrying thing is that more and more malware installing sites are in search results. In about 1.3 percent of Google searches have at least one malware hit and amount has been rising all the time.

Read more here

Labels: ,

Feb 2, 2008

Panda received last year over new 3000 malware files daily

PandaLabs (virus laboratory of Panda Security) has announced that it received 3000 new malware samples daily on average.

That mean there were 800 per cent more samples than in 2006 and around 1400 per cent more than in 2005.
That's why Panda said that current situation can be called as silent malware epidemic (hasn't received publicity in media and no major alarms).

Just virus definition updates don't help anymore to ensure users security. PandaLabs reveals that 23 per cent of home users were infected despite of using security programs.

Source: Panda

Labels: ,

Jan 26, 2008

The growth of malware

Sunbelt reported in its blog scary thing about the growth of malware.

See numbers from below (amount is number unique samples)

1997 137,716
2000 176,329
2006 972,606
2007 5,490,960

So it other words number of malware was 5 times bigger in 2007 than it was in 2006.

Some of that amount is explained by variants; it means new versions of same malware.

Source:Sunbelt

Labels:

Nov 10, 2007

International malware statistics from October

Trojans consisted 26 percent of infections and adware 23 percent of them in October.

PandaLabs leader Luis Corrons says that trojans can be widely used for criminal purposes because they can bring significant amount of money to their creators. This is possible either straight via identity thefts which can be used in net frauds or indirectly by charging advertisers from spams sent via botnets.

After trojans and adware, third most popular group were worms (8,3 %).

This malware type is getting more rare because malware creators are motivated by money. Worms were responsible for some of the worst virus epidemics in the past but they are now seemingly decreasing.

Other malware types were backdoors (4 %), spyware (3 %), dialers (3 %) and bots (2 %).

International malware statistics, October 2007

1. Trojan Downloader.MDW
2. Adware PC-Prot, new
3. Trojan Downloader.OZB
4. Trojan Lineage.BZE, new
5. Worm IRCbot.BEP
6. Worm Brontok.H
7. Worm Puce.E
8. Backdoor Hupigon.AZG, new
9. Trojan Dropper.UN, new
10. Worm Sdbot.ftp, new

Source: Panda

Labels: ,

Oct 17, 2007

Skype Defender steals passwords

There is a new malware spreading which pretends to be Skype login screen and tries to steal sensitive information such as login credentials.

After user has entered username and password, malware displays a message saying that the name and password were unrecognized. Skype Defender collects the entered username and password and also all usernames and passwords which are saved in Internet Explorer, and sends them over to a website for collection.

Skype Defender can be removed by manually deleting 65404-SkypeDefenderSetup.exe. Eg. F-secure, Trend Micro and Symantec products should be already able to recognize and delete Skype Defender.

Source

Labels: ,