F-Secure warns in their blog about a network worm that takes advantage of Remote Desktop Protocol (RDP) as a way to spread itself. Once this Morto worm has infected the system it starts scanning the local network for machines having Remote Desktop Connection enabled. This thing creates much traffic for RDP port, port number 3389/TCP.
More information about Morto in F-Secure blog and there is also a discussion going on at Microsoft's Technet forums.
Showing posts with label worm. Show all posts
Showing posts with label worm. Show all posts
Monday, August 29, 2011
Thursday, January 20, 2011
New Twitter Worm Redirects To Rogue AV
Nicolas Brulez, Kaspersky Lab malware researcher, warns about new Twitter worm that's currently abusing Google's goo.gl redirection service to push surfers via chain of redirections to rogue AV site. Technical details and other related information can be read from correspondent Securelist blog entry.
Saturday, November 13, 2010
Links Temporarily Disabled In Messenger 2009 To Prevent A Malicious Worm
Microsoft has temporarily turned off links (=made links appear as normal text instead of them being clickable) in Windows Live Messenger 2009 clients. Reason behind this is currently actively in instant messaging and social networks spreading worm. "The worm spreads by inserting a link into an IM conversation with a person whose computer is already infected. When someone clicks the link, it opens in a browser, downloads the worm on the recipient’s computer, and then repeats this process."
New Messenger 2011 isn't known to be affected in the same way thanks to its "Link Safety" feature.
More information can be read about related post in Windows Live Blog.
New Messenger 2011 isn't known to be affected in the same way thanks to its "Link Safety" feature.
More information can be read about related post in Windows Live Blog.
Tuesday, February 2, 2010
Watch Out IQ Test Posing Pest
ESET and BitDefender researchers have discovered malicious worm that disguises itself as IQ test. So far, two variants, Win32/Zimuse.A and Win32/Zimuse.B, have been seen.
"Upon execution, the malware will attempt to spread through removable media using a time-based logic bomb, and overwrite the MBR (Master Boot Record) of all available drives after 40 days for variant A, and 20 days for variant B, making the host’s data inaccessible."
Since 64 bit versions of Windows Vista and Windows 7 require digitally signed drivers the pest fails to install itself on machine with either of these operating systems installed.
Both BitDefender and ESET have Zimuse removal tool available.
More information:
BitDefender blog entry
ESET press release
Source
"Upon execution, the malware will attempt to spread through removable media using a time-based logic bomb, and overwrite the MBR (Master Boot Record) of all available drives after 40 days for variant A, and 20 days for variant B, making the host’s data inaccessible."
Since 64 bit versions of Windows Vista and Windows 7 require digitally signed drivers the pest fails to install itself on machine with either of these operating systems installed.
Both BitDefender and ESET have Zimuse removal tool available.
More information:
BitDefender blog entry
ESET press release
Source
Wednesday, August 26, 2009
Pink Floyd Worm Spreads In Chinese Social Networking Site
Virus Researcher Boris Lau from SophosLabs writes in their blog about a worm that is spreading on Chinese social networking website, renren.com. The worm, known as W32/PinkRen-A by Sophos, poses as a flash file for the “Pink Floyd - Wish You Were Here” video - which tries to execute an external javascript file.
"The technique used in this worm exploits a simple XSS hole in the website - with a payload which has a flash component with the AllowScriptAccess=”always” attribute to allow the above “non-malicious” javascript to spread the worm via renren.com’s API", Lau writes.
First analysis of the found variant show that W32/PinkRen-A doesn't seem to do anything else than just spreads itself across renren site.
"The technique used in this worm exploits a simple XSS hole in the website - with a payload which has a flash component with the AllowScriptAccess=”always” attribute to allow the above “non-malicious” javascript to spread the worm via renren.com’s API", Lau writes.
First analysis of the found variant show that W32/PinkRen-A doesn't seem to do anything else than just spreads itself across renren site.
Sunday, May 24, 2009
Google Users Targeting Gumblar Worm Spreads Fast
"A computer virus that targets Google users is mutating rapidly, turning it into what some are calling the biggest threat to online security today," writes The Guardian.
Gumblar worm exploits vulnerabilities in some unpatched Adobe PDF Reader and Flash player versions. After infecting the system the worm redirects victim's Google search results to sites that serve malware or allow criminals to do "phishing" attacks to steal login details.
The worm has been spreading for a while already but recently its authors changed attacking method so that malicious code is downloaded from a China based website. New techniques have also been developed to avoid worm getting detected.
According to security company Sophos the spread of Gumblar has over doubled itself in a week. The worm was responsible for 42% of all cases of malicious code found on websites.
US-Cert has issued a related warning about Gumblar. Security company ScanSafe recommends that people concerned about the security of their own sites should visit a third-party site called "Unmask Parasites".
Gumblar worm exploits vulnerabilities in some unpatched Adobe PDF Reader and Flash player versions. After infecting the system the worm redirects victim's Google search results to sites that serve malware or allow criminals to do "phishing" attacks to steal login details.
The worm has been spreading for a while already but recently its authors changed attacking method so that malicious code is downloaded from a China based website. New techniques have also been developed to avoid worm getting detected.
According to security company Sophos the spread of Gumblar has over doubled itself in a week. The worm was responsible for 42% of all cases of malicious code found on websites.
US-Cert has issued a related warning about Gumblar. Security company ScanSafe recommends that people concerned about the security of their own sites should visit a third-party site called "Unmask Parasites".
Tuesday, March 3, 2009
New Koobface Variant Spreads In Facebook
Security company Trend Micro warns in its blog about new Koobface worm variant.
Facebook user may get a message that looks like it was coming from friend's Facebook account. The message contains friend's picture and name with a link to a video.
The link opens a spoofed version of YouTube site. In the centre of the site there's a message telling that user must install Adobe Flash Player Update.
By clicking install -button user won't get any Flash update. Instead of it Koobface worm's new variant (detected as WORM_KOOBFACE.AZ) is downloaded.
Facebook users are not the only group in danger. The worm searches for cookies created by the following sites first:
* facebook.com
* hi5.com
* friendster.com
* myyearbook.com
* myspace.com
* bebo.com
* tagged.com
* netlog.com
* fubar.com
* livejournal.com
Then it connects to a respective site using login credentials stored in the gathered cookies. It then searches for an infected user’s friends, who are then sent messages containing a link where a copy of the worm is downloaded. It also sends and receives information from an infected machine by connecting to several servers. This allows hackers to execute commands on the affected machine.
Users of mentioned social networking domains are advised to ignore described messages, and refrain from clicking links in unsolicited messages.
Facebook user may get a message that looks like it was coming from friend's Facebook account. The message contains friend's picture and name with a link to a video.
The link opens a spoofed version of YouTube site. In the centre of the site there's a message telling that user must install Adobe Flash Player Update.
By clicking install -button user won't get any Flash update. Instead of it Koobface worm's new variant (detected as WORM_KOOBFACE.AZ) is downloaded.
Facebook users are not the only group in danger. The worm searches for cookies created by the following sites first:
* facebook.com
* hi5.com
* friendster.com
* myyearbook.com
* myspace.com
* bebo.com
* tagged.com
* netlog.com
* fubar.com
* livejournal.com
Then it connects to a respective site using login credentials stored in the gathered cookies. It then searches for an infected user’s friends, who are then sent messages containing a link where a copy of the worm is downloaded. It also sends and receives information from an infected machine by connecting to several servers. This allows hackers to execute commands on the affected machine.
Users of mentioned social networking domains are advised to ignore described messages, and refrain from clicking links in unsolicited messages.
Sunday, February 22, 2009
New Variant of Conficker Worm Released
"The criminals behind the widespread Conficker worm have released a new version of the malware that could signal a major shift in the way the worm operates", writes Computerworld.
The new variant, dubbed Conficker B++, was spotted a few days ago by SRI International researchers, who published details of the new code on Thursday. To the untrained eye, the new variant looks almost identical to the previous version of the worm, Conficker B. But the B++ variant uses new techniques to download software, giving its creators more flexibility in what they can do with infected machines.
All variants of Conficker have now infected about 10.5 million computers. Users with MS08-067 patch installed are safe also from this latest variant.
The new variant, dubbed Conficker B++, was spotted a few days ago by SRI International researchers, who published details of the new code on Thursday. To the untrained eye, the new variant looks almost identical to the previous version of the worm, Conficker B. But the B++ variant uses new techniques to download software, giving its creators more flexibility in what they can do with infected machines.
All variants of Conficker have now infected about 10.5 million computers. Users with MS08-067 patch installed are safe also from this latest variant.
Saturday, February 14, 2009
ISC Lists Third Party Information Sources On Conficker
Internet Storm Center has released a good list of links containing third party information on Conficker worm. The list can be found here.
Tuesday, January 20, 2009
Downadup Worm Fooling Vista And Windows 7 Beta
Worm epidemy that has infected over 10,000,000 systems so far doesn't spread using network only. F-Secure warns that Downadup worm uses also sneaky social engineering way to spread itself. Windows Vista and Windows 7 beta users must be careful with removable USB drives now.
F-Secure warns in its blog namely about sneaky USB functionality of Downadup aka Conficker worm. The worm copies autorun.inf file to USB removable drive. If USB drive is plugged into other computer parasite tries to start up from the drive using modified Vista Autoplay notification window.
Normally, when USB drive is plugged in a window opens up asking if user wants to run the program on removable drive. Under that option there's an option that can be used to explore the contents of USB drive. What the worm does is that it modifies the first option. Icon is changed and program name is modified. Instead of showing a question if user really wants to run program named autorun.inf, system shows an icon and name that by first look may fool user to think it's just an option to browse USB memory contents (pic). If user gives permission attacking code on the USB memory will be run.
F-Secure says that it made test on Windows 7 beta and says the trick was successful on it too.
F-Secure warns in its blog namely about sneaky USB functionality of Downadup aka Conficker worm. The worm copies autorun.inf file to USB removable drive. If USB drive is plugged into other computer parasite tries to start up from the drive using modified Vista Autoplay notification window.
Normally, when USB drive is plugged in a window opens up asking if user wants to run the program on removable drive. Under that option there's an option that can be used to explore the contents of USB drive. What the worm does is that it modifies the first option. Icon is changed and program name is modified. Instead of showing a question if user really wants to run program named autorun.inf, system shows an icon and name that by first look may fool user to think it's just an option to browse USB memory contents (pic). If user gives permission attacking code on the USB memory will be run.
F-Secure says that it made test on Windows 7 beta and says the trick was successful on it too.
Subscribe to:
Posts (Atom)