Tuesday, April 13, 2010
New Ransomware Targets Copyright Law, Threatens Legal Action
The "ransomeware" informs victims that an "Antipiracy foundation scanner" has found illegal torrents on the users system. If he/she won't pay $400 (via a credit card transaction), they might face jail time and huge fines. Victims are instructed to pay the very FAKE ICPP Copyright Foundation. This company purports to be associated with the RIAA and MPAA, and that a copyright violation has been logged.
Beware all of this is completely fake. There is no "ICPP Foundation", and the messages will appear even if the system contains no illegal material whatsoever.
If you are hit by this trojan, DO NOT PAY. Instead, use an antivirus program that is capable of detecting it to remove the trojan. F-Secure Antivirus detects it as Rogue:W32/DotTorrent.A. You can use F-Secure's free online scanner at ols.f-secure.com to check your system.
More details can be found Via F-Secure's blog post:
ICPP Copyright Foundation is Fake - F-Secure Weblog : News from the Lab
Tuesday, December 01, 2009
New Ransomware Blocks Internet Access, Demands Money
Computer Associates' Internet Security Business Unit, first discovered the new trojan bundled with software named uFast Download Manager. Once downloaded the software was installed along side the uFast download manager without informing the user. The trojan then goes to work blocking internet access until the user enters an activation code. This activation code is obtained by sending an SMS containing a particular number to an expensive premium rate phone number – CA does not mention the sum involved.
The malware, dubbed 'Win32/RansomSMS.AH', appears to be Russian in nature, as it uses a Russian language GUI. The ransom page translates to state:
CA withheld the details of the amount involved in sending the SMS to the premium rate phone service however past ransomware programs demanded upwards of $50-60 for removal. This time around CA ISBU found a way to circumvent the activation scheme and created an activation code generator for this particular ransomware. As of yet there has been no word on actual removal tools. It is suggested that you keep your AV, anti-malware and anti-spyware update to possibly stave off infection.Internet access is blocked due to violation of the
license agreement schedules of uFast Download Manager
You must activate your copyGet a registration code by sending an SMS with the following
code fw0004199 to number ****In response you will receive an activation message.
Enter the activation message received from the SMS response ________
Source: CA Security Advisor Research Blog
Thursday, March 26, 2009
New Ransomware "FileFix Pro 2009" Holds PCs Hostage
With the old scams gaining attention and many sites trying to get the word out that these fake programs are actually the real culprit. The scammers had to upgrade their tactics. And it now looks like they've done just that. The newest version of "ransomware" are now posing as a "file repair application".
It all begins when a user is dupped into installing a malicous piece of software, typically from a fake active X script, a fake software update or a pop-up box. The file contains a Trojan which can then download and install other pieces of software, or carry out some malicious tasks on its own. The malicious software starts by encrypting several different document types on the infected PC. These files range from Microsoft Word .doc files to Adobe Reader .pdf documents. It also scrambles all the files in Windows' "My Documents" folder.
When an unsuspecting user tries to open one of the encrypted files the virus comes to life and an alert pops up saying that a utility called FileFix Pro 2009 will unscramble the data. The message appears to be a legitimate "semi-official" looking notice from the operating system: "Windows detected that some of your MS Office and media files are corrupted. Click here to download and install recommended file repair application," the message reads.
Clicking on the alert downloads and installs FileFix Pro, but the utility is anything but legit. It will decrypt only one of the corrupted files for free, then demands the user purchase the software at a price of $50.
Users who have fallen for the FileFix Pro 2009 con do not have to fork over cash to restore their files, according to other researchers, who have figured out how to decrypt the data. The Bleeping Computer site, for instance, has a free program called "Anti FileFix" available for download that unscrambles files corrupted by the Trojan. And security company FireEye Inc. has created a free online decrypter that also returns files to their original condition.
Thursday, March 13, 2008
Trend Micro Site Hacked, Possibly Infected Users With Trojan
Antivirus vendor Trend Micro Inc. confirmed Thursday that "some portions" of its site had been hacked earlier this week, but hedged when asked if those pages had been serving up attack code to unsuspecting visitors.
"'When users viewed any of the modified pages, they were reconnected to other sites without realizing it, and a type of virus was installed on their computer that causes them to download other viruses in a series,'" Yomiuri Shimbun, one of Japan's largest newspapers.
Sophos, a Trend Micro rival, claimed that the hack had been an SQL injection attack and included a link to an alert Trend placed on its Japanese-language site that identified the malware as JS_DLOADER.TZE. The alert also said that users could have been infected by accessing one of 11 infected pages on the Japanese site or 20 pages on the English site, or by clicking a link embedded in the malware's name
Tuesday, March 04, 2008
Mebroot Rootkit Virus
F-Secure, a Finish anti-virus and computer security software company, originally discovered Mebroot back in December.
Trojan.Mebroot takes control of the system by overwriting the MBR with its own code. This allows the trojan to start before any other programs including the operating system. Which makes it nearly impossible for anti-virus programs to detect.
Analysis of Trojan.Mebroot shows that its current code is at least partially copied from the original eEye BootRoot code. The kernel loader section, however, has been modified to load a custom designed stealth back door Trojan 467 KB in size, stored in the last sectors of the disk.
For now, Trojan.Mebroot seems to run successfully only on Windows XP (all Service Packs) however Symantec Security reports there may be variants that will affect Windows Vista, Windows Server 2003 and Windows 2000.
Once a machine is infected, the hacker controlling the rootkit has complete control over the victim's machine, opening up the potential for a variety of other attacks. For example, the hacker could try and download other malicious software to the machine to log a person's keystrokes and collect financial or personal data.
F-Secure, which specializes in finding rootkits, says its technology is only able to "suspect" if Mebroot is on a PC. F-Secure has said it is possible to detect the trojan using their security software CD to boot up the PC.
Thursday, June 21, 2007
Beware Harry Potter Spoilers a Phishing Scam
He has published what he claims are all of the plot points—including main characters who get killed and the final outcome of the seven-book series.
Gabriel says he used "the usual milw0rm downloaded exploit." The exploit entailed delivering to a Bloomsbury employee an e-mail with an invitation to click on a link, open a browser and click on a maliciously crafted animated icon that allowed the attacker access to the victim's system.
"It's amazing to see how much [sic] people inside the company have copies and drafts of this book," Gabriel wrote in a posting on Insecure.org. "Curiosity killed the cat." (Ed. note: Spoiler alert: Do not click on the link to read Gabriel's posting if you don't want to have the plot spoiled.)
milw0rm is a group of politically motivated "hacktivists" whose most famous exploit was penetrating the computers of the Bhabha Atomic Research Centre (BARC) in Bombay, the primary nuclear research facility of India, on June 3, 1998. They have anti-nuclear and pro-peace agendas and, in this case, anti-Harry Potter and pro-Pope Benedict XVI.
"We did it by following the precious words of the great Pope Benedict XVI when he still was Cardinal Joseph Ratzinger," Gabriel said. "He explained why Harry Potter bring the youngs [sic] of our earth to Neo Paganism faith. So we make this spoiler to make reading of the upcoming book useless and boring."
Gabriel said he did it "to protect you and your families."
Monday, May 14, 2007
Top Threat: Windows Hacktivation
What they are calling Trojan.Kardphisher doesn't do most of the technical things that Trojan horses usually do; it's a pure social engineering attack, aimed at stealing credit card information. In a sense, it's a standalone phishing program.
Once you reboot your PC after running the program, the program asks you to activate your copy of Windows and, while it assures you that you will not be charged, it asks for credit card information. If you don't enter the credit card information it shuts down the PC. The Trojan also disables Task Manager, making it more difficult to shut down..
Running on the first reboot is clever. It inherently makes the process look more like it's coming from Windows itself, and it removes the temporal connection to running the Trojan horse. The program even runs on versions of Windows prior to XP, which did not require activation.
This is not an attack that will sneak by you. The executable is nearly 1MB large. But if you find yourself in this situation you should be able to disable it in Windows Safe mode by removing the registry keys described in the Symantec writeup and deleting the program it points to. Updated antivirus software should also be able to remove it.