Senior Threat Researcher Ranieri Romera writes in Trend Micro blog about botnet that is targeting Mexican users, particularly PayPal's local site and Bancomer that is the biggest bank in Mexico. Client program of Tequila botnet can arrive to user's computer via different ways.
First, it takes advantage of the news about missing four-year-old girl, Paulette Gebara Farah. Users who are following the said news may fall prey to this attack by visiting the page http://www.knijo.{BLOCKED}0.net/fotografias-al-desnudo-de-la-mama-de-paulette.htm which contains an article about Paulette and claims to show nude photos of her mother. When user arrives at the page one is shown fake dialog trying to make user install "Adobe Flash Player". If user clicks "run" one is led to the download of the file video-de-la-mama-de-paulette.exe that is actually client of a bot detected as TSPY_MEXBANK.A by Trend Micro. Among spreading via malicious webpages the Tequila botnet may spread itself via USB devices and via MSN Messenger as well. It sends messages that either contain the file itself (as an attachment of sorts) or links that go to copies of the malware.
The whole blog post with more detailed description of Tequila botnet can be read here.
Showing posts with label botnets. Show all posts
Showing posts with label botnets. Show all posts
Wednesday, June 2, 2010
Thursday, April 29, 2010
Storm Making A Comeback As A Modified Version
The bot code used in the infamous, massive Storm botnet that was taken down nearly two years ago is being used to build another spamming botnet.
Related links:
https://www.honeynet.org/node/539
http://www.darkreading.com/insiderthreat/security/client/showArticle.jhtml?articleID=224700110
http://krebsonsecurity.com/2010/04/infamous-storm-worm-stages-a-comeback/
Related links:
https://www.honeynet.org/node/539
http://www.darkreading.com/insiderthreat/security/client/showArticle.jhtml?articleID=224700110
http://krebsonsecurity.com/2010/04/infamous-storm-worm-stages-a-comeback/
Sunday, February 28, 2010
Microsoft Aims Its Target At Other Botnets
Sunday, August 16, 2009
Jaiku Used For Sending Botnet Commands
Twitter doesn't seem to be the only social service criminals have used for sending commands to botnet clients. Kaspersky's lab blog tells that similar service, though not as popular as Twitter, Jaiku had also account with name "upd4t3" set up sending similar commands like suspended Twitter account used to send.
Jose Nazario tells in updated post at Arbor Networks blog that he had found also "upd4t3″ profile in Tumblr. However, that profile was abandoned of some reason.
Jose Nazario tells in updated post at Arbor Networks blog that he had found also "upd4t3″ profile in Tumblr. However, that profile was abandoned of some reason.
Friday, August 14, 2009
Twitter Account Used As Botnet Command Channel
Microblogging service Twitter has been one of the hottest topic for the past couple of weeks due to attacks putting more traffic than it could handle towards the service. Jose Nazario, the manager of security research at Arbor Networks made the latest add to Twitter related news by telling in the company's blog how he noticed Twitter account "upd4t3" (now suspended) been used to send commands to botnet of infected computers.
More details in Arbor Networks' blog.
More details in Arbor Networks' blog.
Friday, June 5, 2009
FTC Shuts Down Web Hosting Firm
US Federal Trade Commission (FTC) has shut down web hosting provider Pricewert that operated at least under 3FN and APS Telecom names. FTC states that Pricewert was criminal ISP that sold services to other cyber criminals. Company hosted botnet servers and also helped in distributing spam, child pornography and rogue antivirus products.
It's not clear yet how the shutdown will affect. Similar shutdown happened in last November when net provider McColo was sent offline. That time spam amounts decreased a lot. Though 3FN was a major provider for Cutwail spam botnet it's possible that criminals have learnt their lessons and have programmed the botnet to use backup commands.
More on the subject:
Washington Post article
The Register article
Court documents
It's not clear yet how the shutdown will affect. Similar shutdown happened in last November when net provider McColo was sent offline. That time spam amounts decreased a lot. Though 3FN was a major provider for Cutwail spam botnet it's possible that criminals have learnt their lessons and have programmed the botnet to use backup commands.
More on the subject:
Washington Post article
The Register article
Court documents
Saturday, October 18, 2008
Emerging Cyber Threats Report for 2009
On October 15, 2008, the Georgia Tech Information Security Center (GTISC) hosted its annual summit on emerging security threats and countermeasures affecting the digital world. At the conclusion of the event, GTISC released Emerging Cyber Threats Report—outlining the top five information security threats and challenges facing both consumer and business users in 2009.
Interesting report can be obtained here.
Interesting report can be obtained here.
Saturday, October 11, 2008
Fast-Flux Botnet Observations
New research brings more light into the matter of how botnets work. Domain names and victim systems used by attacking network are changed all the time. Single victim or domain won't last very long.
Two professionals from Arbor Networks company and University of Mannheim have researched botnets. Especially they researched how the criminals hide themselves behind captured systems and several domains. Interesting report can be found here.
Two professionals from Arbor Networks company and University of Mannheim have researched botnets. Especially they researched how the criminals hide themselves behind captured systems and several domains. Interesting report can be found here.
Wednesday, August 27, 2008
Asprox Botnet Punishes Of Incorrectly Filled Forms
SecureWorks reports that Asprox botnet, used specially for phishing banking details, has adopted a "special" way to treat users who fill out for phishing used forms incorrectly. Wrongly filled out form causes a malware attack which tries to exploit web browser's and Windows operational system's vulnerabilities.
This kind of action will be taken if form is filled out with details that doesn't seem to be real or contains words like "phish" or NSFWUYAS (Not Safe For Work Unless You’re a Sailor) language. If system is vulnerable against these exploits it will end up as a part of Asprox botnet.
According to SecureWorks if the form is filled out with details that looks correct system won't be attacked.
This kind of action will be taken if form is filled out with details that doesn't seem to be real or contains words like "phish" or NSFWUYAS (Not Safe For Work Unless You’re a Sailor) language. If system is vulnerable against these exploits it will end up as a part of Asprox botnet.
According to SecureWorks if the form is filled out with details that looks correct system won't be attacked.
Friday, August 15, 2008
Shadow Botnet Smashed By The Authority Of The Netherlands
The Dutch High Tech Crime Unit has arrested two persons and closed down Shadow botnet which is estimated to be consisted of over 100,000 computers. A 19-year-old Dutch national is accused of running the botnet. Another arrested person is a Brazilian man who tried to rent the botnet. Security company Kaspersky is asked to help close the botnet down.
Eddy Willems, security evangelist with Kaspersky Labs Benelux, who worked closely with the High Tech Crime Unit, believes this case clearly illustrates how the security industry can help law enforcement in the fight against cybercrime.
The Dutch police is asking anyone who finds that they were part of the Shadow botnet to contact them and register a complaint. Kaspersky provides instructions for locating and removing the Shadow bot malware on its web site.
FBI is also reported to have taken part in the case.
Source
Eddy Willems, security evangelist with Kaspersky Labs Benelux, who worked closely with the High Tech Crime Unit, believes this case clearly illustrates how the security industry can help law enforcement in the fight against cybercrime.
The Dutch police is asking anyone who finds that they were part of the Shadow botnet to contact them and register a complaint. Kaspersky provides instructions for locating and removing the Shadow bot malware on its web site.
FBI is also reported to have taken part in the case.
Source
Saturday, August 2, 2008
Malware Spreads In Social Networking Services
Security company Kaspersky Lab warns about new worm named as Koobface which uses social networking services, Facebook and MySpace to spread itself. Thus far four different variants of the worm exist.
Koobface makes infected systems part of botnet which clients spread malware links using friends lists of MySpace & Facebook. "The messages and comments include texts such as Paris Hilton Tosses Dwarf On The Street; Examiners Caught Downloading Grades From The Internet; Hello; You must see it!!! LOL. My friend catched you on hidden cam; Is it really celebrity? Funny Moments and many others."
Links in messages guide user to site containing video clip. If the user tries to watch the clip (s)he's been shown a message that asks to get the latest version of Flash Player to be able to watch the clip. Instead of the latest version of Flash Player, a file named as codesetup.exe is downloaded to the victim machine. That file is actually Koobface worm.
“Unfortunately, users are very trusting of messages left by 'friends' on social networking sites. So the likelihood of a user clicking on a link like this is very high. At the beginning of 2008 we predicted that we'd see an increase in cybercriminals exploiting MySpace, Facebook and similar sites, and we're now seeing evidence of this. I'm sure that this is simply the first step, and that virus writers will continue to target these resources with increased intensity”, says Alexander Gostev, Senior Virus Analyst at Kaspersky Lab.
Koobface makes infected systems part of botnet which clients spread malware links using friends lists of MySpace & Facebook. "The messages and comments include texts such as Paris Hilton Tosses Dwarf On The Street; Examiners Caught Downloading Grades From The Internet; Hello; You must see it!!! LOL. My friend catched you on hidden cam; Is it really celebrity? Funny Moments and many others."
Links in messages guide user to site containing video clip. If the user tries to watch the clip (s)he's been shown a message that asks to get the latest version of Flash Player to be able to watch the clip. Instead of the latest version of Flash Player, a file named as codesetup.exe is downloaded to the victim machine. That file is actually Koobface worm.
“Unfortunately, users are very trusting of messages left by 'friends' on social networking sites. So the likelihood of a user clicking on a link like this is very high. At the beginning of 2008 we predicted that we'd see an increase in cybercriminals exploiting MySpace, Facebook and similar sites, and we're now seeing evidence of this. I'm sure that this is simply the first step, and that virus writers will continue to target these resources with increased intensity”, says Alexander Gostev, Senior Virus Analyst at Kaspersky Lab.
Saturday, July 12, 2008
Malware Targets Simpsons Cartoon Series Fans On AIM
FaceTime Security Labs writes in its blog about malware that's spread in AIM (AOL Instant Messenger) network. To be more exact spreader is username 'Chunkylover53' which has its status set to away and away message contains a link to a malicious file. So, what's so special with name Chunkylover53? Well, in one old episode of Simpsons cartoon series it was revealed that Homer Simpson's (one of the main characters of the series) email address was Chunkylover53@aol.com. This malware link spreading username may not necessarily be related to this email address in anyway but the 'Chunkylover53' name itself is enough to attract Simpsons fans and possibly make them add it to their AIM contact list.
In its away message 'Chunkylover53' adverts a link saying that by downloading its contents user gets "a new internet-only exclusive Simpson's episode that is only being released to the internet fans". According to FaceTime Security Labs user ends up with 'Kimya.exe' file that is in fact a trojan that among other bad things deposits the infected PC into a Turkish origin botnet.
Thus far Chunkylover53's away message has been changed a couple of times. It's also possible that party behind Chunkylover53 may use botnet to spread malicious messages or urls in IM network. Keeping that possibility in mind infected users are advised to keep an eye on all Instant Messaging activity until they can clean the infection from their computer.
FaceTime Security Labs identifies the trojan as Kimya.
In its away message 'Chunkylover53' adverts a link saying that by downloading its contents user gets "a new internet-only exclusive Simpson's episode that is only being released to the internet fans". According to FaceTime Security Labs user ends up with 'Kimya.exe' file that is in fact a trojan that among other bad things deposits the infected PC into a Turkish origin botnet.
Thus far Chunkylover53's away message has been changed a couple of times. It's also possible that party behind Chunkylover53 may use botnet to spread malicious messages or urls in IM network. Keeping that possibility in mind infected users are advised to keep an eye on all Instant Messaging activity until they can clean the infection from their computer.
FaceTime Security Labs identifies the trojan as Kimya.
Monday, May 19, 2008
Srizbi Is World's Largest Botnet At The Moment
"The prodigious Srizbi botnet has continued to grow and now accounts for up to 50 percent of the spam being filtered by one security company", says PC World's article. Estimated amount of spam currently sending out daily is about 60 billion spam messages.
"Srizbi is the single greatest spam threat we have ever seen. At its peak, the highly publicized Storm botnet only accounted for 20 percent of spam. Srizbi now produces more spam than all the other botnets combined." said Bradley Anstis from security company Marshal. What has probably made Srizbi so successful is that it appears to spread by as part of the spam messages it sends, meaning that its lifecycle extends to reproducing itself and not just distributing email.
Microsoft told recently about its success combating the Storm botnet with their Malicious Software Removal Tool (MSRT) and now Anstis expects it to turn its sights on Srizbi and the other major botnets.
"Srizbi is the single greatest spam threat we have ever seen. At its peak, the highly publicized Storm botnet only accounted for 20 percent of spam. Srizbi now produces more spam than all the other botnets combined." said Bradley Anstis from security company Marshal. What has probably made Srizbi so successful is that it appears to spread by as part of the spam messages it sends, meaning that its lifecycle extends to reproducing itself and not just distributing email.
Microsoft told recently about its success combating the Storm botnet with their Malicious Software Removal Tool (MSRT) and now Anstis expects it to turn its sights on Srizbi and the other major botnets.
Wednesday, April 30, 2008
Microsoft Helps In Hacker Busting With Its Botnet-hunting Tool
Microsoft is giving law enforcers access to a special tool that keeps tabs on botnets. It's done by using data compiled from the 450 million computer users who have installed the Malicious Software Removal tool coming with Windows.
"The tool includes data and software that helps law enforcers get a better picture of the data being provided by Microsoft's users", said Tim Cranton, associate general counsel with Microsoft's World Wide Internet Safety Programs.
Botnets are networks consisting of hacked computers. This kind of network is like a super computer that is used for example to send spam and attack servers on the Internet. Botnets have been on Microsoft's radar for about four years - since the company identified them as a significant emerging threat.
Microsoft hasn't come to public with the tool before this but it turns out that it was used in Canadian police's bust made in February. The Sûreté du Québec used botnet-buster to break up a network that had infected nearly 500,000 computers in 110 countries according to Captain Frederick Gaudreau, who heads up the provincial police force's cybercrime unit.
Source
"The tool includes data and software that helps law enforcers get a better picture of the data being provided by Microsoft's users", said Tim Cranton, associate general counsel with Microsoft's World Wide Internet Safety Programs.
Botnets are networks consisting of hacked computers. This kind of network is like a super computer that is used for example to send spam and attack servers on the Internet. Botnets have been on Microsoft's radar for about four years - since the company identified them as a significant emerging threat.
Microsoft hasn't come to public with the tool before this but it turns out that it was used in Canadian police's bust made in February. The Sûreté du Québec used botnet-buster to break up a network that had infected nearly 500,000 computers in 110 countries according to Captain Frederick Gaudreau, who heads up the provincial police force's cybercrime unit.
Source
Subscribe to:
Posts (Atom)