Showing posts with label trojan. Show all posts
Showing posts with label trojan. Show all posts

Tuesday, April 13, 2010

New Ransomware Targets Copyright Law, Threatens Legal Action

A new piece of "ransomware", a piece of malware that is actually acting like a legitimate program, has cropped up and is now demanding $400 from users that is says are violating copyright laws.

The "ransomeware" informs victims that an "Antipiracy foundation scanner" has found illegal torrents on the users system. If he/she won't pay $400 (via a credit card transaction), they might face jail time and huge fines. Victims are instructed to pay the very FAKE ICPP Copyright Foundation. This company purports to be associated with the RIAA and MPAA, and that a copyright violation has been logged.

Beware all of this is completely fake. There is no "ICPP Foundation", and the messages will appear even if the system contains no illegal material whatsoever.

If you are hit by this trojan, DO NOT PAY. Instead, use an antivirus program that is capable of detecting it to remove the trojan. F-Secure Antivirus detects it as Rogue:W32/DotTorrent.A. You can use F-Secure's free online scanner at ols.f-secure.com to check your system.

More details can be found Via F-Secure's blog post:
ICPP Copyright Foundation is Fake - F-Secure Weblog : News from the Lab

Tuesday, December 01, 2009

New Ransomware Blocks Internet Access, Demands Money

Ransomware is nothing new, we've all seen Windows trojans resorting to a little blackmail, and locking up a users PC waiting for them to spend money on fake anti-virus that turns out to be more malicious than the original infect. Today however has to be the first I've ever heard of a piece of Ransomware that blocks a users internet access flat out demanding a ransom before it will return control.

Computer Associates' Internet Security Business Unit, first discovered the new trojan bundled with software named uFast Download Manager. Once downloaded the software was installed along side the uFast download manager without informing the user. The trojan then goes to work blocking internet access until the user enters an activation code. This activation code is obtained by sending an SMS containing a particular number to an expensive premium rate phone number – CA does not mention the sum involved.

The malware, dubbed 'Win32/RansomSMS.AH', appears to be Russian in nature, as it uses a Russian language GUI. The ransom page translates to state:

Internet access is blocked due to violation of the
license agreement schedules of uFast Download Manager
You must activate your copy

Get a registration code by sending an SMS with the following
code fw0004199 to number ****

In response you will receive an activation message.

Enter the activation message received from the SMS response ________

CA withheld the details of the amount involved in sending the SMS to the premium rate phone service however past ransomware programs demanded upwards of $50-60 for removal. This time around CA ISBU found a way to circumvent the activation scheme and created an activation code generator for this particular ransomware. As of yet there has been no word on actual removal tools. It is suggested that you keep your AV, anti-malware and anti-spyware update to possibly stave off infection.

Source: CA Security Advisor Research Blog

Thursday, March 26, 2009

New Ransomware "FileFix Pro 2009" Holds PCs Hostage

A nasty new piece of "ransomware" has been circulating the web taking PCs hostage with demands of a $50 payment for the restoration of corrupted files.

AVG Internet SecurityRansomeware (aka "scareware") is nothing new, in fact variants have been cruising the web in the form of fake antivirus programs for years. The phony AV programs which include several variants of "AntiVirus 2009" aka know as AV 2009 (the name changes yearly) have been very lucrative for hackers with some hackers reportedly making as much as $5 million a year.

With the old scams gaining attention and many sites trying to get the word out that these fake programs are actually the real culprit. The scammers had to upgrade their tactics. And it now looks like they've done just that. The newest version of "ransomware" are now posing as a "file repair application".

It all begins when a user is dupped into installing a malicous piece of software, typically from a fake active X script, a fake software update or a pop-up box. The file contains a Trojan which can then download and install other pieces of software, or carry out some malicious tasks on its own. The malicious software starts by encrypting several different document types on the infected PC. These files range from Microsoft Word .doc files to Adobe Reader .pdf documents. It also scrambles all the files in Windows' "My Documents" folder.

When an unsuspecting user tries to open one of the encrypted files the virus comes to life and an alert pops up saying that a utility called FileFix Pro 2009 will unscramble the data. The message appears to be a legitimate "semi-official" looking notice from the operating system: "Windows detected that some of your MS Office and media files are corrupted. Click here to download and install recommended file repair application," the message reads.

Clicking on the alert downloads and installs FileFix Pro, but the utility is anything but legit. It will decrypt only one of the corrupted files for free, then demands the user purchase the software at a price of $50.

Users who have fallen for the FileFix Pro 2009 con do not have to fork over cash to restore their files, according to other researchers, who have figured out how to decrypt the data. The Bleeping Computer site, for instance, has a free program called "Anti FileFix" available for download that unscrambles files corrupted by the Trojan. And security company FireEye Inc. has created a free online decrypter that also returns files to their original condition.

Thursday, March 13, 2008

Trend Micro Site Hacked, Possibly Infected Users With Trojan

From ComputerWorld.com "Trend Micro site infected users with Trojan"

Antivirus vendor Trend Micro Inc. confirmed Thursday that "some portions" of its site had been hacked earlier this week, but hedged when asked if those pages had been serving up attack code to unsuspecting visitors.


"'When users viewed any of the modified pages, they were reconnected to other sites without realizing it, and a type of virus was installed on their computer that causes them to download other viruses in a series,'" Yomiuri Shimbun, one of Japan's largest newspapers.

Sophos, a Trend Micro rival, claimed that the hack had been an SQL injection attack and included a link to an alert Trend placed on its Japanese-language site that identified the malware as JS_DLOADER.TZE. The alert also said that users could have been infected by accessing one of 11 infected pages on the Japanese site or 20 pages on the English site, or by clicking a link embedded in the malware's name

Tuesday, March 04, 2008

Mebroot Rootkit Virus

Mebroot rootkit infects a PC's master boot record (MBR), making it nearly invisible to security software.

F-Secure, a Finish anti-virus and computer security software company, originally discovered Mebroot back in December.

Trojan.Mebroot takes control of the system by overwriting the MBR with its own code. This allows the trojan to start before any other programs including the operating system. Which makes it nearly impossible for anti-virus programs to detect.

Analysis of Trojan.Mebroot shows that its current code is at least partially copied from the original eEye BootRoot code. The kernel loader section, however, has been modified to load a custom designed stealth back door Trojan 467 KB in size, stored in the last sectors of the disk.

For now, Trojan.Mebroot seems to run successfully only on Windows XP (all Service Packs) however Symantec Security reports there may be variants that will affect Windows Vista, Windows Server 2003 and Windows 2000.

Once a machine is infected, the hacker controlling the rootkit has complete control over the victim's machine, opening up the potential for a variety of other attacks. For example, the hacker could try and download other malicious software to the machine to log a person's keystrokes and collect financial or personal data.

F-Secure, which specializes in finding rootkits, says its technology is only able to "suspect" if Mebroot is on a PC. F-Secure has said it is possible to detect the trojan using their security software CD to boot up the PC.

Thursday, June 21, 2007

Beware Harry Potter Spoilers a Phishing Scam

An attacker named "Gabriel" claims to have stolen the text of the upcoming "Harry Potter and the Deathly Hallows" from Bloomsbury Publishing by use of a phishing scam.

He has published what he claims are all of the plot points—including main characters who get killed and the final outcome of the seven-book series.

Gabriel says he used "the usual milw0rm downloaded exploit." The exploit entailed delivering to a Bloomsbury employee an e-mail with an invitation to click on a link, open a browser and click on a maliciously crafted animated icon that allowed the attacker access to the victim's system.

"It's amazing to see how much [sic] people inside the company have copies and drafts of this book," Gabriel wrote in a posting on Insecure.org. "Curiosity killed the cat." (Ed. note: Spoiler alert: Do not click on the link to read Gabriel's posting if you don't want to have the plot spoiled.)

milw0rm is a group of politically motivated "hacktivists" whose most famous exploit was penetrating the computers of the Bhabha Atomic Research Centre (BARC) in Bombay, the primary nuclear research facility of India, on June 3, 1998. They have anti-nuclear and pro-peace agendas and, in this case, anti-Harry Potter and pro-Pope Benedict XVI.

"We did it by following the precious words of the great Pope Benedict XVI when he still was Cardinal Joseph Ratzinger," Gabriel said. "He explained why Harry Potter bring the youngs [sic] of our earth to Neo Paganism faith. So we make this spoiler to make reading of the upcoming book useless and boring."

Gabriel said he did it "to protect you and your families."

Monday, May 14, 2007

Top Threat: Windows Hacktivation

Symantec is reporting on a Trojan horse that mimics the Windows activation interface.

What they are calling Trojan.Kardphisher doesn't do most of the technical things that Trojan horses usually do; it's a pure social engineering attack, aimed at stealing credit card information. In a sense, it's a standalone phishing program.

Once you reboot your PC after running the program, the program asks you to activate your copy of Windows and, while it assures you that you will not be charged, it asks for credit card information. If you don't enter the credit card information it shuts down the PC. The Trojan also disables Task Manager, making it more difficult to shut down..

Running on the first reboot is clever. It inherently makes the process look more like it's coming from Windows itself, and it removes the temporal connection to running the Trojan horse. The program even runs on versions of Windows prior to XP, which did not require activation.

This is not an attack that will sneak by you. The executable is nearly 1MB large. But if you find yourself in this situation you should be able to disable it in Windows Safe mode by removing the registry keys described in the Symantec writeup and deleting the program it points to. Updated antivirus software should also be able to remove it.