<?xml version="1.0" encoding="utf-8"?>
<rss version="0.92">
<channel>
<title>SecuObs.com</title>
<link>http://www.secuobs.com</link>
<description>Observatoire de la securite Internet</description>
<language>fr</language>
<webMaster>webmaster@secuobs.com</webMaster>
 <item><title>Microsoft Advance Notification for July</title><description>2009-07-10 18:28:28 - FSecure Antivirus Research Weblog :  As there are currently 0-day vulnerabilities being exploited in the wild— you may wish to read this July's advance security bulletinMicrosoft Security Bulletin, July 2009Be prepared for next Tuesday's updates — see the Microsoft SecurityBulletin Advance Notification for July 2009 for detailsOn 10/07/09 At 02:37 PM</description><link>http://www.secuobs.com/revue/news/118908.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/118908.shtml</guid></item>
<item><title>Sexy Space Symbian Worm</title><description>Secuobs.com : 2009-07-09 18:38:02 - FSecure Antivirus Research Weblog -  Dancho Danchev of ZDNet's Zero Day blog has an interesting postregarding TransmitterC — which is supposedly a significantmodification of the Sexy View SMS worm that we posted about inFebruaryWe've analyzed this new variant, which we call Worm:SymbOS/YxeD, andfrom our point of view there are no major differences from ouroriginal detectionExcept for one thing…This YxeD variant is signed with a certificate from yet anothercompanyyxed certificate infoSo now there are two Symbian approved worm vendors for S60 3rd EditionphonesSee our Worm:SymbOS/Yxe description for additional detailsOn 09/07/09 At 01:11 PM</description><link>http://www.secuobs.com/revue/news/118495.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/118495.shtml</guid></item>
<item><title>Lyzapo DDoS attack on US and South Korean websites</title><description>Secuobs.com : 2009-07-09 00:16:01 - FSecure Antivirus Research Weblog -  There's a fairly large-scale DDoS attack underway, targeting severalSouth Korean and US websitesThe sites hurt most at the moment seem to be FTCGOV andusauctionslivecomusauctionslivecom ftcgovOther targets, like whitehousegov seem to be unaffected then again,whitehousegov runs under Akamai, making it a much harder targetSome sources have linked this attack to the 5-year old Mydoom wormfamily Here's what we know of this: a pack of sample files related tothis attack has been making rounds between antivirus labs One ofthose files MD5: 93322e3614babd2f36131d604fb42905 really is a Mydoomvariant We detect it as Email-WormWin32Mydoomhw However, we can'tfind any evidence that this particular file would attack any of thetargets currently under DDoSOn 08/07/09 At 08:05 PM</description><link>http://www.secuobs.com/revue/news/118219.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/118219.shtml</guid></item>
<item><title>Poll: What's your favorite web browser</title><description>Secuobs.com : 2009-07-08 15:17:29 - FSecure Antivirus Research Weblog -  There's a TechCrunch post that claims Internet Explorer has lost 114percent market share since March of this yearOthers question the data sources, but while they may doubt thepercentages, they agree that IE's market share is generally fallingWhatever its market share, one thing is certain — web browsercompetition is quite healthy at the moment and consumers have plentyof options to choice fromChrome, IE, Firefox, Safari, OperaWe hosted a June 2008 poll asking about our reader's preferredbrowserLet's do it againWhich of the following options is your preferred web browserOn 08/07/09 At 11:23 AM</description><link>http://www.secuobs.com/revue/news/118014.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/118014.shtml</guid></item>
<item><title>F-Secure ISTP and the 0-day vulnerability in MSVIDCTLDLL</title><description>Secuobs.com : 2009-07-07 03:02:37 - FSecure Antivirus Research Weblog -  As mentioned in the previous post there's a new 0-day vulnerability inMicrosoft ActiveX Video Control, more specifically in the filemsvidctldll Microsoft has now published an advisory about thevulnerability and in the advisory they recommend that you set thekillbit to disable the vulnerable CLSIDs, all 45 of them As thisvulnerability is actively being used in drive-by downloads it's a goodidea to do this Or, you could download our free beta of ISTP orExploitShield which also protects against this - without the need forupdatesWe tried our F-Secure Internet Security Technology Preview theupcoming 2010 product and its Browsing Protection against the newexploit and it worked like a charm It blocked the exploit attemptwithout the need for any updates The generic exploit protection ispretty awesome as is ExploitShield itselfHere's a video of how ISTP does against the new vulnerability and whathappens if you disable parts of the protection technologiesISTP in actionOn 06/07/09 At 11:54 PM</description><link>http://www.secuobs.com/revue/news/117423.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/117423.shtml</guid></item>
<item><title>0-Day Vulnerability in DirectShow</title><description>Secuobs.com : 2009-07-06 18:02:47 - FSecure Antivirus Research Weblog -  A 0-Day vulnerability that's being used to exploit Microsoft DirectShowhas been discovered in the wildDrive-by attacks using thousands of compromised websites arereportedly involvedSANS Internet Storm Center has details including a killbit in theirHandler's Diary There is not yet a Microsoft AdvisoryWe detect the exploit as Exploit:W32/AgentLBVThe exploit targets Microsoft Internet Explorer… so one work around iskind of obviousUse some other browser besides Internet Explorer until thisvulnerability is patchedOn 06/07/09 At 02:36 PM</description><link>http://www.secuobs.com/revue/news/117232.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/117232.shtml</guid></item>
<item><title>Bait files</title><description>Secuobs.com : 2009-07-03 12:24:28 - FSecure Antivirus Research Weblog -  It's always interesting to browse through the bait document files usedin targeted attacks These are files that have been used to infectspecific individuals in different organizations in order to gainaccess to their computerAll the documents shown below contained exploits that installedbackdoors Targets of these attacks are not knowntargeted attacktargeted attacktargeted attacktargeted attacktargeted attacktargeted attacktargeted attackThis is just a quick sampling; we get a lot of theseOn 03/07/09 At 09:50 AM</description><link>http://www.secuobs.com/revue/news/116691.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/116691.shtml</guid></item>
<item><title>SMS remote code execution vulnerability in iPhone</title><description>Secuobs.com : 2009-07-02 22:52:08 - FSecure Antivirus Research Weblog -  Charlie Miller, a well-known security researcher who specializes in Macand iPhone security, yesterday revealed information about a newvulnerability in iPhone that allows remote code execution via SMS Nota lot is known about the vulnerability, which was announced at theSyScan conference in Singapore, except that Charlie is working withApple to get it fixed as soon as possibleIMAGEpicture from applecomThis is about as bad as it gets as the vulnerability seems to allowunsigned code to run which circumvents a core part of iPhone'ssecurity model as it's usually only able to run signed code, ie Appsthat have been approved by Apple No user-interaction required whichis unlike current mobile malware InfoWorld has the original storyherePS Im shift manager for one of our three daily response shifts thisweek and I'm tweeting about what were doing in the shift over athttp://twittercom/patrikrunaldOn 02/07/09 At 06:30 PM</description><link>http://www.secuobs.com/revue/news/116482.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/116482.shtml</guid></item>
<item><title>China's Dam Delay</title><description>Secuobs.com : 2009-07-02 18:20:42 - FSecure Antivirus Research Weblog -  The Wall Street Journal reports that Beijing has delayed its mandate tohave Green Dam Youth Escort filtering software installed on all newWindows computers sold in China The deadline was originally July 1sthttp://enwikipediaorg/wiki/File:Green_Dam_Youth_Escort_logopngPC World's take is that implementation of Green Dam is only a matterof timeOur takeIf China wants to require anti-pornography filtering software that'sChina's business, not oursBut the same software on EVERY computer sold in China That'smonocultureAnd as we've noted before, monoculture's are subject to catastrophicfailure in the event of a successful attack—————More: China's Web filtering starts in the WestOn 02/07/09 At 01:22 PM</description><link>http://www.secuobs.com/revue/news/116362.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/116362.shtml</guid></item>
<item><title>Private Browsing</title><description>Secuobs.com : 2009-07-01 21:06:01 - FSecure Antivirus Research Weblog -  Firefox 35 was released yesterday I've been waiting to try out thePrivate Browsing Mode, so I installed it todayHere are the privacy settings from my installation of Firefox 301Firefox 301 Privacy OptionsAnd when I installed Firefox 35 the Private Browsing option wasdisabled WhatFirefox 35 Tools MenuSeems that the installation recognized my 301 settings as theequivalent of Private Browsing and preconfigured 35 to "Automaticallystart Firefox in a private browsing session"Very nice workFirefox 35 Privacy OptionsSo, nothing changed at all Except now I have easy options toreconfigure por… paranoi… err, Private Browsing if I opt to do soTime to experimentSigning off,Sean---------------------------------------------------------------------On 01/07/09 At 03:46 PM</description><link>http://www.secuobs.com/revue/news/115996.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115996.shtml</guid></item>
<item><title>King Of Pop SMSes</title><description>Secuobs.com : 2009-07-01 06:17:40 - FSecure Antivirus Research Weblog -  With all the talk of Michael Jackson spam and Michael Jackson malwaregoing on, it was mildly interesting today when a Fellow in our KUL Labreceived an SMS - with link - that mentioned the King of Pop as well:SMS_MJThe IP appears to be registered in Malaysia but fortunately the linkdoesn't seem to workOn 01/07/09 At 02:10 AM</description><link>http://www.secuobs.com/revue/news/115691.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115691.shtml</guid></item>
<item><title>Security Threat Summary Q2/2009</title><description>Secuobs.com : 2009-06-30 17:39:25 - FSecure Antivirus Research Weblog -  Our Q2 Security Threat Summary is available from:http://wwwf-securecom/2009/Q2 SummaryVideo is available via our Video Channel, and also the Lab's YouTubeChannelOn 30/06/09 At 11:57 AM</description><link>http://www.secuobs.com/revue/news/115322.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/115322.shtml</guid></item>
<item><title>Michael Jackson Malware</title><description>Secuobs.com : 2009-06-29 11:49:06 - FSecure Antivirus Research Weblog -  There has been a couple of malware attacks that have tried to use thenews coverage of the death of Michael Jackson as the lure to getpeople infectedLast night we saw this one: a file called Michael-wwwgooglecomexeThis file was distributed through a site called photos-googlecom andpossibly also through photo-msnorg, facebook-photonet andorkut-imagescom Do not visit these sitesWhen executed, Michael-wwwgooglecomexe drops files calledreptileexe and winudpexe These are IRC bots with backdoorcapability The file also shows this fake error message:michael jackson malwareWe detect the dropper and the backdoors as TrojanWin32BuzusbjyoOn 29/06/09 At 08:36 AM</description><link>http://www.secuobs.com/revue/news/114768.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114768.shtml</guid></item>
<item><title>Sad News Generate Bad Things</title><description>Secuobs.com : 2009-06-26 15:39:27 - FSecure Antivirus Research Weblog -  The "King of Pop", Michael Jackson, died last night after suffering acardiac arrest The news is currently spreading through a lot ofdifferent media outlets and they are being printed worldwideAnother recent death, Farrah Fawcett, is also making headlinesThe subjects themselves are not related to information security, buthow long do you think it will take until the bad guys pick up the newsas well and start using it Usually it has taken a few days at mostSo remember, if or more likely when you start receiving e-mails onthese subjects, please be extra careful when opening any links as theymight be taking you in for a rough rideOn 26/06/09 At 11:44 AM</description><link>http://www.secuobs.com/revue/news/114083.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/114083.shtml</guid></item>
<item><title>Government, Military - Aviation</title><description>Secuobs.com : 2009-06-25 06:10:43 - FSecure Antivirus Research Weblog -  US Secretary of Defense Robert Gates recently confirmed the creation ofa US Cyber Command aimed at dealing with cyberthreats to militaryresources A previously announced White House "cybersecuritycoordinator" is already in the works to deal with similar threats tocritical government infrastructuresOn the whole, thats good news It would be great however to hear ofsimilar efforts in protecting a particular commercial resource thatsdefinitely "critical infrastructure"  civil aviation electronicsystemsEarlier this year, the US Department of Transportation released anaudit report in pdf here in which it determined the national airtraffic control systems administered by the Federal AviationAdministration FAA had significant weaknesses and vulnerabilities,potentially allowing an unauthorized party to access and control vitalservices and systemsThis isnt the first time the FAA has been criticized for theweaknesses in civil aviation electronic system security, with thefirst such criticisms coming as early as 1998The report cites incidences that took place in 2006, 2008 and 2009 assupporting evidence that the administrative and operational systemscan be breached The FAA contends this claimNot cited in the report, but of possible interest, is a 1998 incidentin which a teenager successfully disabled vital airport control towerservices at a regional Massachusetts airport CNet article hereHopefully, with the current government enthusiasm for improvingcomputer security, the current civil aviation systems get someattention tooOn 25/06/09 At 02:25 AM</description><link>http://www.secuobs.com/revue/news/113476.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/113476.shtml</guid></item>
<item><title>Would You Give Your Facebook Password for A Job Application</title><description>Secuobs.com : 2009-06-24 05:47:25 - FSecure Antivirus Research Weblog -  CNNcom carried a recent news article about the city of Bozeman,Montana, USA, which has been pressured into removing an item in itsbackground-check waiver form requesting all applicants for to disclosetheir login names and passwords for online social networking websitessuch as Facebook, MySpace and Youtube The change in policy isattributed to a furore that arose after one applicant contacted theMontana's News Station expressing concern about that particular aspectof the background checkThe city justified the login details request as just another part ofan extensive background check they perform on all employees Theprecautions were meant to ensure that those holding positions wherethey'd be handling the city's funds or operations will be reputableand honest And presumably smart enough not to post details of anyobjectionable activity they might engage in onlineThe Bozeman Daily Chronicle also mentioned that elected citycommissioner's weren't affected by the policy, only city employeesPresumably elected city commissioners are already assumed to bereputable and honest And smart enough not to post details of anyobjectionable activities they might engage in onlineWhat's actually rather interesting to consider is that the policy hasapparently been in force for about three years and according to cityattorney Greg Sullivan, "No one has ever removed his or her name fromconsideration for a job due to the request" Rather begs the question,did they really give up their login details Provide fake ones Orjust ignore the requestAnd yes, legally, the policy does appear to be on some seriously shakyground Unlike some states - or countries - Montana's stateconstitution explicitly guarantees a citizen's right to privacyThe request for login details was quickly removed last week Still, itappears the city is still keen on checking applicants' onlinebehavior, as "officials are looking at ways to alter the policy sothat they might view an applicants online information without askingfor log-in codes"On 24/06/09 At 01:53 AM</description><link>http://www.secuobs.com/revue/news/112980.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/112980.shtml</guid></item>
<item><title>Hacktivist Tweets</title><description>Secuobs.com : 2009-06-24 01:13:26 - FSecure Antivirus Research Weblog -  The collision of politics and technology is often interesting and therecent Iranian presidential election has seen a great deal of bothFrom the New York Times: Web Pries Lid of Iranian CensorshipAnd while the Internet is a source of information for politicalactivists, there is also something else more questionable takingplace… DDoS attacks against government servers in IranA Twitter search for Iran and DDoS yields numerous results Some folksare urging against DDoS attacks, but not in principle, rather becausethey might affect the bandwidth of political protesters What arethose concerned for the protesters promoting insteadTargeted hackingWe saw this earlier today on Twitter: "Please, use SURGICAL hackingonly"Our recommendation No one should hack servers It's a crime PeriodPrivate citizens can participate in organized peaceful protestsOrganizing surgical strikes against someone else's servers is virtualviolenceAnd violence begets violenceVigilante cyberwar is not a productive path upon which to proceedOn 23/06/09 At 03:56 PM</description><link>http://www.secuobs.com/revue/news/112907.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/112907.shtml</guid></item>
<item><title>Scareware Attacks</title><description>Secuobs.com : 2009-06-22 20:43:27 - FSecure Antivirus Research Weblog -  Rogue Antivirus AKA scareware continues to be a pervasive threatagainst consumersByron Acohido recently posted an excellent article on the topicThe related posts on the business of scareware and rogues are alsowell worth readingThe Last Watchdog, June 10thCheck them outOn 22/06/09 At 12:29 PM</description><link>http://www.secuobs.com/revue/news/112353.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/112353.shtml</guid></item>
<item><title>ISTP 950 is Available</title><description>Secuobs.com : 2009-06-18 19:24:20 - FSecure Antivirus Research Weblog -  Our Internet Security Technology Preview has been updated and it islooking and performing greatHere's a short video demo via our YouTube channelYou can download it from hereOn 18/06/09 At 01:47 PM</description><link>http://www.secuobs.com/revue/news/111267.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/111267.shtml</guid></item>
<item><title>Mac Protection Updates</title><description>Secuobs.com : 2009-06-17 20:01:35 - FSecure Antivirus Research Weblog -  We've been focused on testing our ISTP and almost failed to notice thatour Mac Protection beta was updated last weekMac Protection 4766Signature updates are now in the database channel You can try it fromhereOn 17/06/09 At 04:29 PM</description><link>http://www.secuobs.com/revue/news/110862.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/110862.shtml</guid></item>
<item><title>Working to Protect You</title><description>Secuobs.com : 2009-06-15 15:00:15 - FSecure Antivirus Research Weblog -  It's a busy day in the LabOnly it's not in the way that we normally consider it to be a "busyday" We're having strategy review meetings todayThe security landscape changes rapidly and everyone needs to be up tospeed on our future goalsThese are the guys working to protect you06152009The meeting is still in progress… I'd better get back to itSigning off,SeanOn 15/06/09 At 12:36 PM</description><link>http://www.secuobs.com/revue/news/109771.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109771.shtml</guid></item>
<item><title>Waiting for Mobile Malware Wave</title><description>Secuobs.com : 2009-06-15 12:40:14 - FSecure Antivirus Research Weblog -  For the last couple years there has been talk – like thisiGillotResearch report in pdf – about how the convergence of mobilephones and the Internet would unleash a new wave of threats targetedto the phone and distributed over the Internet We've definitely seena number of attacks on mobile network operators Yet up until now,most users haven't been hit by Internet-based attacksFor example, the Apple iPhone last year saw its first Trojan to bedistributed via the Internet Still, that was more "script-kiddieprank program" than "serious crimeware" Heck, it wasn't even thefirst Internet-based mobile threat – technically, you could argue the2006 ElilesA worm has that distinction Halfway through 2009, therehasn't yet been any major outbreaks of Internet-distributed mobilemalwareSo what's this, another bogeyman story about mobile security Wellkinda Today Apple announced the release of its iPhone 3G S model onJune 19 It's supposed to be faster, more feature-loaded and so oniphonesource: attcomIn offering a neat package of enhanced phone, easy surfing with theonboard Safari browser and the appeal of a huge variety of programsfrom the App store, Apple looks set to spur even more people into intogetting online via their mobile phonesAnd as seems to be the case with mobile phones these days – whereApple leads, others will follow Most mobile phone producers have beenracing to provide the same level of online browsing user-friendlinessin their products If they get it right, that means even more userspicking up mobile surfingWhich means that malware authors will have even more reason to starttargeting the mobile phone Let's hope's the phone producers andmobile network operators consider that first Trojan a kind of "warningshot" and set up some strong security measuresFor now, it seems like all is quiet on the mobile frontOn an unrelated note, the new iPhone model also formally introduces anInternet Tethering functionality allowing users to connect a computerto the phone and surf the Internet – no Wi-Fi hotspot required Someusers have been asking for the feature for a while now, so – wishgranted EnjoyOn 09/06/09 At 02:41 AM</description><link>http://www.secuobs.com/revue/news/109728.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109728.shtml</guid></item>
<item><title>Quarterly Updates</title><description>Secuobs.com : 2009-06-15 12:40:14 - FSecure Antivirus Research Weblog -  Microsoft delivered lots of updates yesterday See the MicrosoftSecurity Bulletin Summary for June 2009 for full detailsRunning your Microsoft Updates is all you'll need to patch yoursystemHowever, there is something new on this particular update cycle —AdobeBack on May 20th, Brad Arkin stated on Adobe's ASSET blog that thecompany would be moving to a quarterly update cycleAdobe Regular Security UpdatesAnd that's a promising move as it helps to highlight the need to keepyour Adobe applications up-to-dateAs we've noted before, Adobe Acrobat/Reader exploits account fornearly half of the targeted attack cases we've analyzedSo you want to stay updatedTargeted attacks 2009 ytdYou can find this quarter's Adobe updates from Adobe's Securitybulletins and advisoriesOn 10/06/09 At 03:49 PM</description><link>http://www.secuobs.com/revue/news/109727.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109727.shtml</guid></item>
<item><title>Wreck A Movie</title><description>Secuobs.com : 2009-06-15 12:40:14 - FSecure Antivirus Research Weblog -  The folks at Wreck A Movie make collaborative films and the Lab isinvolved with one of their current projectsWreck A Movie was founded by the folks that made Star Wreck: In thePirkinningwreck-a-movieFrom wreckamoviecom:"Project Worm will be a six-part web TV series about internationalcyber crime Initial development goals are concept development, storyline, synopsis and a screen play for part one This early developmentwill run from May to July 09 Shooting of the actual TV series willtake place in six different countries in 2010"A series about cybercrime Cool Members of the Lab are assisting as"technical consultants" or something like thatIf you're interested in participating, check out the Project WORMproduction pageOn 12/06/09 At 03:34 PM</description><link>http://www.secuobs.com/revue/news/109726.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/109726.shtml</guid></item>
<item><title>ISTP Network Reputation is Pretty Cool</title><description>Secuobs.com : 2009-06-08 18:22:37 - FSecure Antivirus Research Weblog -  I've been testing our ISTP for several weeks now here in the LabThe more I that use our ISTP — the more I find to like — and I'm verymuch looking forward to this year's product releasesThis past weekend I tested some new ISTP features from home One thingI've never really had a need for is anti-spam for a POP mail accountI've been using webmail since 1997That's why I was curious to test our new Browsing protection ratingsfor webmail based links And I have to say, it does a pretty crediblejob so far I'm looking forward to it being in full productionHere's a sample screenshot using a malware domain list pulled frommalwaredomainscom, a useful blocklist site The red "X" icons showthe domains that our network reputation services already recognize asmaliciousISTP Browsing protectionNext I e-mailed myself some Facebook phishing linksISTP Browsing protectionThe fourth URL in my test isn't detected, so I clicked on the "" iconto report that particular linkISTP Browsing protectionThen all I needed to do was to select "It is harmful to use" and toclick on the OK buttonISTP Browsing protectionThat then submits information to be analyzed by our Network Reputationteam and their automationTo Jay-R and team — Keep up the good work This is a great serviceSigning off,SeanOn 08/06/09 At 03:12 PM</description><link>http://www.secuobs.com/revue/news/107002.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/107002.shtml</guid></item>
<item><title>Visit to IMPACT Global Response Center</title><description>Secuobs.com : 2009-06-05 20:49:17 - FSecure Antivirus Research Weblog -  Last week we had a chance to visit the Global Response Center of IMPACTimpactIMPACT is the first global public-private initiative against cyberthreats The headquarters are in Cyberjaya, MalaysiaTheir HQ building is quite impressiveimpactThe Global Response Center is getting ready for actionimpactMore about IMPACT:The IMPACT initiative has been underway since 2007 Hopefully it willget more traction and international acceptance, as this is the kind ofaction we need if we really want to fight online threatsOn 05/06/09 At 06:21 PM</description><link>http://www.secuobs.com/revue/news/106352.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/106352.shtml</guid></item>
<item><title>Exploit Shield vs DirectShow</title><description>Secuobs.com : 2009-06-02 13:17:28 - FSecure Antivirus Research Weblog -  We posted a link to Microsoft Advisory 971778 / CVE-2009-1537 last weekThe advisory details a vulnerability in Microsoft's DirectShow,quartzdll, affecting QuickTime parsing Not a QuickTimevulnerability Microsoft has reported some use of an exploit in thewildAn analyst from our Exploit Shield team, Victor, tested a workingsample against our Exploit Shield technologyHis efforts can be seen below, click the image for a larger viewExploit Shield vs DirectShow ExploitExcellent Exploit Shield proactively blocks this threat withheuristic detection of shellcode exploitationThe screenshot above is from one of the Lab's internal builds It isalso integrated into our Internet Security Technology PreviewBrowsing protection ISTP950And this is the block page that will be displayed to clientsExploit Shield Block of DirectShow ExploitPS And just so you know, there is ALSO a QuickTime vulnerabilitythat's been patched See our vulnerability description for detailsUpdate your QuickTime to version 762On 02/06/09 At 08:49 AM</description><link>http://www.secuobs.com/revue/news/104738.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/104738.shtml</guid></item>
<item><title>Poll: Cyber Defense</title><description>Secuobs.com : 2009-06-01 17:23:34 - FSecure Antivirus Research Weblog -  Just over a year ago, Col Charles W Williamson III posed questionsregarding the US Air Force's Cyber Defense plansOur post included a poll on the matter — US Air Force Colonel ProposesSkynetNow that the Pentagon has made its proposal to Barack Obama; and nowthat the President has announced his civilian agency goals, let's aska slightly different questionAre you in favor of President Obama's Cyber Security StrategyJune 2009 PollOn 01/06/09 At 01:35 PM</description><link>http://www.secuobs.com/revue/news/104441.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/104441.shtml</guid></item>
<item><title>Securing Cyberspace</title><description>Secuobs.com : 2009-05-30 19:16:01 - FSecure Antivirus Research Weblog -  Yesterday President Barack Obama announced his plans for securingcyberspaceIt would have been hard to imagine George Bush to give a talk aboutmalware and bots And that's exactly what Obama didFrom Obama, phrases like this sound perfectly natural: "we've had tolearn a whole new vocabulary just to stay ahead of the cyber criminalswho would do us harm -- spyware and malware and spoofing and phishingand botnets"cyberobamaPresident Obama also mentioned Conficker by name, which wasinteresting The full text of his speech is available onlineAnother quote: "Our Information Age is still in its infancy We'reonly at Web 20"My comments on President Obama's announcment are available in the NewYork Times---------------------------------------------------------------------On 30/05/09 At 09:01 AM</description><link>http://www.secuobs.com/revue/news/103607.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103607.shtml</guid></item>
<item><title>Microsoft DirectShow is Vulnerable</title><description>Secuobs.com : 2009-05-29 18:31:08 - FSecure Antivirus Research Weblog -  There's a vulnerability in Microsoft's DirectShow DirectX It affectsWindows 2000 / XP / Server 2003MSA971778The vulnerability exploits quartzdll Quicktime parsing However, youdon't have to have QuickTime installedMSA971778Microsoft has some workarounds to offerMSA971778See Microsoft Security Advisory 971778 for detailsMSA971778Microsoft is currently reporting limited use against thisvulnerability in the wildOn 29/05/09 At 03:07 PM</description><link>http://www.secuobs.com/revue/news/103151.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/103151.shtml</guid></item>
<item><title>Put Your Passwords on a Post-it</title><description>Secuobs.com : 2009-05-26 20:48:35 - FSecure Antivirus Research Weblog -  Facebook is slowly but surely defending itself against aggressive spamrunsThere's some speculation among experts Why Facebook Has Facebookbecome a keystone from which to launch and steal all of anindividual's passwords ie banking and commerce sites Once youhave Facebook, can you then compromise the primary e-mail account andeverything else along with itMaybe so, but regardless of why — the sheer gravity of Facebook makesit a target Its growth and size is tremendousLet's take Finland as an example There are over one million estimatedFacebook accounts and there are only 53 million people living inFinland The regional network has over 544,000 members Anything thatsize will be a target for scammersWherever good people go, miscreants will followSo of course it's an excellent policy to maintain complex passwordsthat are unique to each site RightHere's an idea Write down your passwords SeriouslyAnd once you write them down, put them in your wallet Think about itWhat else do you carry in your wallet That's right, your bank cardsAnd your bank cards contain your account name and account numberThat's kind of like your online account names and passwordsOnly this is the key — It's a two part password Because your accountname and bank card number also requires your PINSo take a look at this screenshot What do you seePasswords on a post-itPasswords on a Post-it, only examples of course… non-dictionary onesat thatKeep another three common characters in your head, and you'll havecomplex 10 character passwords And you can insert those extracharacters in the front, middle, or endWhat do we mean It's like thisThe first three characters in this example are based on the website, "aMA"represents Amazoncom And it can be written several ways, such as "AMa"or "aMa" or "AMA", etc A good method should be easy for you torememberThe next or other part, "2242" as in our example, should besomething completely random This is the part that you really need towrite down and keep safe so that you don't forget itAnd then you should use a method to add three more characters your"PIN" to every password Something such as "35" So the full passwordthen becomes "aMA224235" or "aMA352242" or "35aMA2242"Our other example would be "gMA35N135"Your PIN should never be written down, keep that bit of information inyour head Just like your bank card's PINNote that our example does not include an e-mail address on thePost-itWhat happens if your wallet is stolen You call the bank and cancelyour cardsAnd what about your Post-it If it doesn't include your e-mail addressor your PIN, you can reset your passwords in a timely fashion on a newpiece of paper You're good to goUsing this methodology, you can maintain complex and unique passwords,and still have something handy for when you forget them Because weall do forget stuff from time to timeAnd if you're phished on one site, such as Facebook, your otheraccounts aren't sharing the same passwordOh, one last piece of adviceDon't put the Post-it on your monitor And not on the underside ofyour keyboard either… everyone's familiar with that location too---------------------------------------------------------------------On 26/05/09 At 04:07 PM</description><link>http://www.secuobs.com/revue/news/101843.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/101843.shtml</guid></item>
<item><title>RaiTV NeaPOLIS</title><description>Secuobs.com : 2009-05-26 16:15:18 - FSecure Antivirus Research Weblog -  We recently hosted an Italian reporter from neaPOLIS, a technologyprogram broadcast on Italian television RaiIf you speak Italian, you'll find the clip from here… or perhaps youjust want to see our Helsinki Security LabFSecure's Paolo Palumbo on RaitvOn 26/05/09 At 11:26 AM</description><link>http://www.secuobs.com/revue/news/101694.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/101694.shtml</guid></item>
<item><title>H1N1 Themed Targeted Attack</title><description>Secuobs.com : 2009-05-26 03:44:51 - FSecure Antivirus Research Weblog -  The H1N1, formerly known as swine, flu continues to make headlines…though the trends peaked earlier this monthAnd while there hasn't been widespread use of H1N1 themes formalicious attacks, we have seen some limited use Here's somethingthat our honeypots collected last weekIt's a malicious PDF file that's nothing newWhen the PDF is opened, it exploits Adobe Reader, drops a backdoor,and shows a file referring to H1N1 fluHere's a screenshotH1N1What happens behind the scenes The exploit drops a malicious filecalled "AcrRd32exe" into the computer's temp folderThe malicious file connects to three IP addresses in order to "callhome" These addresses are, or were, in Texas 2072004512,Budapest 8922318193 and Hyderabad 2025369130The individuals targeted by this attack are unknown to usOn 25/05/09 At 01:02 PM</description><link>http://www.secuobs.com/revue/news/101528.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/101528.shtml</guid></item>
<item><title>Do Facebook Phishers Prefer Macs</title><description>Secuobs.com : 2009-05-26 03:44:51 - FSecure Antivirus Research Weblog -  Facebook phishing has been on the increase latelyIt's nothing new however, PhishTankorg has been tracking Facebook asa "Targeted Brand" for quite some timeHere's a screenshot of the real Facebook login page:Facebook login, realAnd here's a screenshot of a fake courtesy of PhishTank:Facebook login, fakeNotice the differenceThere's a grammatical mistake, "We helps you"… and then the fake loginpage looks as if it is being rendered by the Safari browserSo perhaps phishers prefer using Macs---------------------------------------------------------------------On 25/05/09 At 03:21 PM</description><link>http://www.secuobs.com/revue/news/101527.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/101527.shtml</guid></item>
<item><title>Malicious IFrame on Gadgetadvisorcom</title><description>Secuobs.com : 2009-05-22 12:32:57 - FSecure Antivirus Research Weblog -  Are you a gadget geek Do you often seek advice from Gadget Advisorbefore making a purchaseOur Web Security Analyst discovered a malicious IFrame on the populartech website that redirects visitors to a malicious websitegadgetdvisor_01If the site detects a PDF browser plugin for Adobe Acrobat and Reader,it loads a specially-crafted malicious PDF file that exploits astack-based buffer overflow vulnerability CVE-2008-2992The net effect of the attack is to plant a trojan, detected asTrojan-DownloaderWin32Agentbrxr, on vulnerable systems by callingthe utilprintf JavaScript function, which connects back to themalicious website in order to download the trojan to the machine Aremote attacker can access the user's machine once it has beeninfected with the trojanBelow are the readable codes contained within the malicious PDF filegadgetadvisor_exploit_1gadgetadvisor_exploit_2This attacks is targeted against older, unpatched version of Adobeprograms, as the latest Adobe updates have already fixed this problemMore information and the updates can be found at Abobe athttp://wwwadobecom/support/security/bulletins/apsb08-19htmlDisabling the JavaScript function in Acrobat and Reader will alsoprevent the threat from proceedingOn 22/05/09 At 06:35 AM</description><link>http://www.secuobs.com/revue/news/100487.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/100487.shtml</guid></item>
<item><title>Mac Protection</title><description>Secuobs.com : 2009-05-20 19:51:11 - FSecure Antivirus Research Weblog -  Take a look at this:F-Secure Mac ProtectionLooks like our recently mentioned Internet Security Technology Preview,rightBut look closely and you'll see that the image above is for MacProtectionWe used to have a Mac solution back in the days of sneakernets Theupdates were distributed via floppies This new Mac Protection withantivirus is part of our Technology Preview program and you candownload it from our Beta Programs page An Intel processor based Macwith OS X version 105 Leopard is a requirementMacs are popular, with consumers… and also with malware authorsThere's plenty of Zlob codec trojans that will infect a Mac if giventhe chance Mac's popularity is such that we feel it's time once againfor our own Mac solution Give it a try — CheersOn 20/05/09 At 03:12 PM</description><link>http://www.secuobs.com/revue/news/99608.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/99608.shtml</guid></item>
<item><title>We've Moved</title><description>Secuobs.com : 2009-05-19 12:49:39 - FSecure Antivirus Research Weblog -  We've moved Our Kuala Lumpur Security Lab that is…We successfully transplanted the entire Kuala Lumpur office to newpremises over the weekend The new location offers much more room forexpansion as we continue to growHere's an exterior shot of the office building — "Menara F-Secure"F-Secure Tower is the second tower from the rightNew KL OfficeAnd here's a shot of the much larger Security Lab, before all theAnalysts completed setting up their workstations:New Security LabThere were still boxes, cables and other paraphernalia lying around atthe time, as you can see in the background Today though everythinghas been set up, all the boxes are being cleared and everyone isgetting comfortable againDuring the entire move, we were able to maintain full responseservices by creatively working around the organized turmoil, but it'sgood to finally settle down and get to work in the new lab So as anunofficial salute to mark the end of the move:"Cheers from the KUL Lab"On 19/05/09 At 09:26 AM</description><link>http://www.secuobs.com/revue/news/98232.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/98232.shtml</guid></item>
<item><title>Rogue Browser Agents</title><description>Secuobs.com : 2009-05-18 20:11:36 - FSecure Antivirus Research Weblog -  How big an issue are Rogue antivirus applications Let's take a lookWhat is your browser's user agent Any ideas The Firefox browsershould look something like this:What is my user agentYou can determine yours from whatsmyuseragentcom Now let's take alook at this user agent:Mozilla/40 compatible; MSIE 70; Windows NT 51; AntivirXP08; NETCLR 114322; NET CLR 2050727Do you see it Right there in the middle, "AntivirXP08" What is thatall aboutSome rogues modify the browser's user agent We've seen hundreds ofAntivirXP08 string variations The modified string is possibly used toidentify the affiliates responsible for the installation which drives"business" to the rogue's websiteModified user agents could also be used deliver different content Avictim with AntivirXP08 doesn't need to be convinced to download aninstaller, instead they can be targeted to complete the scam and tobuy the rogueHow many infected user agents are out there Toni examined one of oursinkholes and its April 2009 logs contained 63,000 unique IP addressesusing agents that contain AntivirXP0863 thousand That's a lot of infections, right And that doesn'tinclude other strings we've seen such as "Antimalware2009"It's a small measure of a very large problemOn 18/05/09 At 03:30 PM</description><link>http://www.secuobs.com/revue/news/97880.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/97880.shtml</guid></item>
<item><title>twittercom/FSLabs</title><description>Secuobs.com : 2009-05-14 19:37:12 - FSecure Antivirus Research Weblog -  Our Twitter account can be used to follow the blog at twittercom/FSLabs,#Blog designates something from our RSS feedOther links of interest may be tweeted there as wellOn 14/05/09 At 04:13 PM</description><link>http://www.secuobs.com/revue/news/96413.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/96413.shtml</guid></item>
<item><title>Fake Adobe Flash Player Site</title><description>Secuobs.com : 2009-05-13 12:40:07 - FSecure Antivirus Research Weblog -  One of our Web Security Analysts came across a website 118,000 rankingin Alexa that drives users into installing a fake Adobe Flash Playerfile The site prompts a message requesting the user download "a newversion of Adobe Flash Player" in order to view a video on the siteFake Adobe FlashplayerOn clicking "Continue", visitors are taken to this page:Fake Adobe FlashPlayerLooks pretty authentic, right It even offers to download an"install_flash_playerexe" file for you The analyst was using a Linuxsystem though, so this seemed slightly oddTurns out the site is a pretty good fake Unless a visitor takes ahard look at the address bar, it's pretty easy to be fooledThe downloaded installer also looks like the original Adobe FlashPlayer installer, though the checksum and digital signatures point outthe differenceFake Adobe Flashplayer installerinstall_flash_playerexe version 1002287md5: 51F26C0051E97A91145971FE5BC632FFmalware_install_flash_playerexemd5: 71AD0C4A4168AA98BB20E3561E505CC7Based on a reverse domain lookup on the malware link, the fake site ishosted in BulgariaUpdates to the latest antivirus definitions detect this threat---------------------------------------------------------------------On 13/05/09 At 07:40 AM</description><link>http://www.secuobs.com/revue/news/95655.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/95655.shtml</guid></item>
<item><title>Update on updates</title><description>Secuobs.com : 2009-05-13 08:13:15 - FSecure Antivirus Research Weblog -  A bunch of updates were made available by several vendors yesterdayGet'em while they're hotMicrosoft - patch for PowerPoint fixes 14 vulnerabilitiesAdobe - Patch for two Adobe Reader vulnerabilitesApple - fixes 67 security issues in OS XSecurity Updates en masseOn 13/05/09 At 05:04 AM</description><link>http://www.secuobs.com/revue/news/95594.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/95594.shtml</guid></item>
<item><title>l337 Beta Testers Needed</title><description>Secuobs.com : 2009-05-11 18:54:03 - FSecure Antivirus Research Weblog -  Do you enjoy installing and trying out new software Do you want thechance to win an iPod Yes Okay, then keep reading…Our most recent build of F-Secure Internet Security Technology PreviewISTP was released last Friday, version 940 build 172 Some bigchanges are being implemented into our products and ISTP 940 is ourfirst look at them The Security Lab has been testing 940 and we'dlike to encourage our blog readers to do so as well Download BetaProgramsThe most immediate change you'll notice is the first-level GUIF-Secure Technology Preview 940It is quite different from our present design and will eventually thebasis of the entire GUI It's still evolving so feedback is veryformative at this point, if not this year's releases, then nextThere are also numerous changes in the technology:• Scanning performance improvements• Boot optimization• Processes optimization• DeepGuard enhancements• New Spam Control• New network-based Parental ControlHere's an example of our new Browsing Protection optionsF-Secure Technology Preview 940  Browsing ProtectionExploit Shield and a network based reputation protection is nowintegrated IE and Firefox Known bad sites will be blocked, andunknown sites will be "shielded" against And when the Shield isactivated, we'll learn about yet another bad site… and that builds aprotective feedback loop The next visitor will be blocked fromvisiting rather than shieldedThose of you familiar with our current lineup know that DeepGuard isfound within our Real-time scanning "System Control" settingsDeepGuard is now uncoupled from Real-time scanning options andincludes enhanced process monitoringF-Secure Technology Preview 940  DeepGuardISTP's DeepGuard utilizes our "Cloud" of coursenhips_dialogAnd known malicious applications are blocked on the basis of serverqueriesnhips_dialog_highlightedIf you're offline, DeepGuard can automatically block maliciousapplications using our latest behavioral engine technologyDeepGuard FlyerAlright, so there are a number of important changes and there's lotsof testing and work to be done still And even though we're testinginternally, you know that real-world testing by actual users is veryimportant to the processThis time around, we'd really like some significant feedback Anybodytesting ISTP 940 build 172 that submits detailed feedback to the BetaProgram will be eligible for a prize drawing We'll grandfather inthose of you that have already provided detailed feedback on build165 The Beta Program team is gathering up the budget for some iPodsand/or other cool stuff; details will soon be posted on the BetaProgram pageAnother cool thing about the technology… it's updated automaticallyWhich means that if you are running ISTP 930 — It should updateitself to Build 172 today via our update channel If it doesn't soon,that's the kind of feedback we want to read aboutDownload ISTP from the Beta Programs page CheersOne additional note that's very important to us here in the Lab — thisISTP 940 release includes lots of changes to our detectiontechnologies They are more proactive and heuristic than in previousproduct releases DeepGuard being a good example This shouldenhance our detection of undefined/unknown malware If you discoverany new samples, we want them Also, if you encounter a detectionthat's too aggressive, you can help us with feedback there as wellPlease use our Sample Analysis System to provide the Lab feedback ondetection related issuesAnd the Beta Program Feedback form should be used for product relatedissuesOn 11/05/09 At 02:23 PM</description><link>http://www.secuobs.com/revue/news/94486.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/94486.shtml</guid></item>
<item><title>What did Darkmarketws look like</title><description>Secuobs.com : 2009-05-09 14:46:07 - FSecure Antivirus Research Weblog - Keith MularskiFBI agent Keith Mularski gave an interview yesterday to Elinor MillsIn the interview he talks for the first time about the background ofthe infamous Darkmarketws sting operationSpecial Agent Mularski worked undercover for two years, operating amessage forum for online criminals, posing as one of them Theoperation ended last fall with 60 arrests around the worldThe most famous arrest to come out of this sting operation was thearrest of Çağatay Evyapan in Turkey Mr Evyapan, known online as"cha0" was arrested in a raid by a special unit of the Turkish policeHere's a video of cha0's arrest from our Security Wrapup:cha0 aka Çağatay EvyapanThe Darkmarket case has received a lot of media coverageBut what did the actual site look like when it was still operationalFor the first time, we're now publishing a series of screenshots takenof DarkmarketwsWe took these pictures mostly in 2006 and 2007 They detail how thisforum was used to conduct all kinds of online crimesdarkmarketLogin page of DarkmarketwsdarkmarketHere's a user who is interested in buying access to 3000-4000 infectedmachines a weekdarkmarket"Get more $$$ for your logs" - this user is advertising cashingservices for various banks, used to steal money from online bankaccounts Credentials for these accounts have been stolen viakeyloggersdarkmarketUser 'aloaster' has hacked several online shops Now he's sellingadministrator access to themdarkmarketDistributed-denial-of-service attacks for sale "This is a great dealon DDOS attacks and cannot be beat by anyone"darkmarket200 "dove" stickers for $1500 "Dove stickers" are VISA credit cardhologramsdarkmarketAnother ad for credit card hologramsdarkmarketMalware for sale, $350On 09/05/09 At 10:58 AM</description><link>http://www.secuobs.com/revue/news/93997.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/93997.shtml</guid></item>
<item><title>Security Advisory FSC-2009-1</title><description>Secuobs.com : 2009-05-07 18:11:56 - FSecure Antivirus Research Weblog -  Our readership may be interested in this vulnerability descriptionregarding a ZIP and RAR archive evasion vulnerability in our productsOn clients and servers, the worst case is a delay in detection and soit's considered to be low severityOn the other hand, if you admin a gateway, read this and apply theavailable patches — Security Advisory FSC-2009-1Roger Mickael gets the credit for bringing this issue to ourattention CheersOn 07/05/09 At 02:02 PM</description><link>http://www.secuobs.com/revue/news/93174.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/93174.shtml</guid></item>
<item><title>QA: Windows 7 File Extension Hiding</title><description>Secuobs.com : 2009-05-07 18:11:56 - FSecure Antivirus Research Weblog -  We got plenty of good comments on the previous blog post about Windows7, including feedback from people who are actually working in theExplorer development team at MicrosoftMany of the comments included questions on the topic, so here's a QetA:Q: What is this all aboutA: It's about Windows, by default, hiding file extensions such as EXEVirus writers exploit this by creating malicious files withdouble-extensions PICTUREJPGEXE Such a file would typically alsouse a misleading iconQ: How long has Windows Explorer been hiding file extensions "Forknown file types"A: Since Windows NTQ: Why do they do itA: We don't knowQ: Is this a real risk If user already has such a file on his harddrive, it's too late, rightA: Not really The file could have come from the Internet, from a fileshare or a removable drive and the user hasn't necessarily executed ityetQ: But if the file came from the Internet, Explorer will warn you thatit came from an "Untrusted Zone"A: Only if you use Internet Explorer to browse the web and Outlook todownload your e-mail attachments There are plenty of other ways todownload files from the net: 3rd party web and e-mail clients,BitTorrent and other P2P clients, chat programs etc Also, you can'trely on such warning dialogs if the file is on a network share or an aUSB driveSucksQ: There is no problem Even in your own screenshot the file islabeled by Explorer as "Application" Thus, nobody would click on itEven though the file is called somethingtxt And it has the icon of atext fileA: Right…Q: Do real worms really use such filenamesA: Oh yes They typically spread by copying themselves with temptingfilenames to random folders on removable drives or network shares,with filenames along these lines:E:PRESENTATIONPPTexeE:DOCUMENTDOCexeE:PORNVIDEOAVIexeEtcMany would click on these, especially if the icon of the file lookslike a document icon — and when Windows hides the "exe" part of thenameQ: So, the solution is turn off "Hide extensions for known file types"in Explorer settingsA: YeahWindows 7 Folder OptionsQ: Will that make all file extensions visibleA: Well, no There are executable extensions that will STILL be hiddeneven if you turn the option offQ: WhatA: For example PIF This file type was meant to be a shortcut to oldMS-DOS programs Problem is, you can rename any modern WindowsExecutable to PIF and it will happily run when double-clickedFor example, the Scamo worm uses exactly this flaw, dropping filessuch as these:HARRY POTTER 1-6 BOOKTXTpifANTHRAXDOCpifRINGTONESMP3pifBRITNEY SPEARS FULL ALBUMMP3pifEMINEM BLOWJOBJPGpifVISTA REVIEWDOCpifOSAMA BIN LADENMPGpifNOSTRADAMUSDOCpifQ: How do you I make PIF files visible thenA: Via a registry key called "NeverShowExt" We'd link you to anarticle in the Microsoft Knowledgebase… except we couldn't find anyBut here's a Web page on the topic, from GeoCities, made by somehobbyist a couple of years ago Maybe it's the best source ofinformation on the topicQ: Do you still expect Microsoft to change the behavior of Explorer inWindows 7A: No, not reallyBottom line: We still fail to see why Windows insists on hiding thelast extension in the filename It's just misleading---------------------------------------------------------------------On 07/05/09 At 02:25 PM</description><link>http://www.secuobs.com/revue/news/93173.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/93173.shtml</guid></item>
<item><title>PDF most common file type in targeted attacks</title><description>Secuobs.com : 2009-05-06 23:25:07 - FSecure Antivirus Research Weblog -  We've covered targeted attacks many times in the past and we've alsocovered PDF and vulnerabilities in Adobe Acrobat Reader being used toinstall malware So we decided to take a look at targeted attacks andsee which file types were the most popular during 2008 and if that haschanged at all during 2009Targeted attacks 2008In 2008 we identified about 1968 targeted attack files The mostpopular file type was DOC, ie Microsoft Word representing 3455%Targeted attacks 2009So far in 2009 we have found 663 targeted attack files and the mostpopular file type is now PDF Why has it changed Primarily becausethere has been more vulnerabilities in Adobe Acrobat Reader than inthe Microsoft Office applications Like the two vulnerabilities wementioned a week ago These are scheduled to be fixed by Adobe on May12More info about targeted attacks and how they work can be found in ourYouTube videoOn 06/05/09 At 06:40 PM</description><link>http://www.secuobs.com/revue/news/92865.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/92865.shtml</guid></item>
<item><title>Windows 7 Fail</title><description>Secuobs.com : 2009-05-05 19:45:00 - FSecure Antivirus Research Weblog -  Windows 7 RC is out todayThis is great newsBecause surely by now they've fixed Windows ExplorerYou see, in Windows NT, 2000, XP and Vista, Explorer used to Hideextensions for known file types And virus writers used this "feature"to make people mistake executables for stuff such as document filesThe trick was to rename VIRUSEXE to VIRUSTXTEXE or VIRUSJPGEXE,and Windows would hide the EXE part of the filenameAdditionally, virus writers would change the icon inside theexecutable to look like the icon of a text file or an image, andeverybody would be fooledSurely this won't work in Windows 7Lets tryHmm It sure looks like a text file in Explorer:7 sucksBut it actually is an executable:7 sucksWindows 7 FailOn 05/05/09 At 01:25 PM</description><link>http://www.secuobs.com/revue/news/92323.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/92323.shtml</guid></item>
<item><title>H1N1 Domains</title><description>Secuobs.com : 2009-05-04 21:52:41 - FSecure Antivirus Research Weblog -  As a follow up to last Monday's post, here is a list of domainsregistered over the weekend using the words swine fluThere are 1,344 on the list Again, so far, none of the domains we'vechecked are hosting any malicious filesIn fact, the only malicious file we've seen is something that Symantecposted about last weekIt's a PDF "Swine Flu FAQ" exploit which drops a password stealer andthen opens a clean PDF file as a decoyPDF based exploit using swine flu FAQOne interesting thing about the exploit that hasn't been mentioned yetis the file name, The Association of Tibetan journalists PressReleasepdfTibet themed exploits are very popular with targeted attacksOn 04/05/09 At 03:18 PM</description><link>http://www.secuobs.com/revue/news/91866.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/91866.shtml</guid></item>
<item><title>Facebook Security Questions</title><description>Secuobs.com : 2009-04-30 18:51:34 - FSecure Antivirus Research Weblog -  Facebook has excellent granular privacy controlsFacebook Privacy_ControlsBut here's the thing…What's the deal with Facebook's Security QuestionsFacebook Security QuestionsMother's birthday — Father's middle name — Third grade teacherSecurity challenge questions based on social information is probablynot the best of ideas on a social networking site Particularly nowthat Facebook's user base is as expansive as it isAfter all, who's going to know personal details about yourselfThat's right — your friendsFacebook should revise this sooner than laterOn 30/04/09 At 02:59 PM</description><link>http://www.secuobs.com/revue/news/90567.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/90567.shtml</guid></item>
<item><title>Targeted Examples</title><description>Secuobs.com : 2009-04-29 17:53:14 - FSecure Antivirus Research Weblog -  We continue to see targeted attacks More and more of them We'recurrently collecting some statistics on the frequency of these attacksand hope to publish them here later this weekHere's some recent examples of documents that we've seen in targetedattacks All of them use known vulnerabilities to drop backdoors totake over the computerThe examples cover all popular file types: DOC, XLS, PPT and PDFJust to be fairWe've seen all of these cases exactly once, worldwide So whomever gothit by these, it wasn't just bad luck and it wasn't just acoincidenceOur first example looks like an average in-house purchase agreement…but when viewed, it drops a backdoor that connects tolemondtreefreetcpcom XLS fileAssetsConnects to heet25ucom PDF fileUNICEFDrops files called hlwin32dll, hlsvc32dll and svchostexe toSYSTEM32 or TEMP folders PPT fileUSFood"Fertilizer news and analysis" What Drops a backdoor that connectsto wolfdu5166info PDF fileMarketDrops a variant of Poison Ivy remote access trojan PDF fileMedvedevWe don't have any information on the identities of the partiestargeted with these attacksOn 29/04/09 At 02:22 PM</description><link>http://www.secuobs.com/revue/news/89913.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/89913.shtml</guid></item>
<item><title>Two new vulnerabilities in Adobe Acrobat Reader</title><description>Secuobs.com : 2009-04-29 09:26:44 - FSecure Antivirus Research Weblog -  Two new vulnerabilities have been found in Adobe Acrobat Reader and areunder investigation by Adobe The vulnerabilities exist in twoJavaScript functions; getAnnots and spellcustomDictionaryOpen andboth allow remote code execution This means they both could be usedin targeted attacks and drive-by downloads There are PoCs Proof ofConcept available for both vulnerabilities but so far no in-the-wildattacksWe've said it before but it's worth repeating - use an alternative toAdobe Acrobat Reader We won't recommend any reader over another as itwould be better if people use a wide variety of them A list ofreaders can be found here, http://pdfreadersorg/ Others are FoxIT,CutePDF etcIf you can't change from Adobe Acrobat Reader we strongly recommendthat you disable the ability for it to run JavaScript This is easilydone via by going to Edit - Preferences - JavaScript - Un-check"Enable Adobe JavaScript"Disable JavaScripts in Adobe Acrobat ReaderAdobe has a blog post with more information hereOn 29/04/09 At 04:18 AM</description><link>http://www.secuobs.com/revue/news/89640.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/89640.shtml</guid></item>
<item><title>Estonia</title><description>Secuobs.com : 2009-04-28 23:08:39 - FSecure Antivirus Research Weblog -  Today is the 2nd anniversary of the nation-scale DDoS attacks againstEstoniaavailability graph of the website of Estonian government on 30th of April 2007Here's the very first blog post I made on these developments onSaturday, the 28th of April 2007, as things started happening Here'sa follow-up post couple a days later Reading these now, they reallyfeel sort of historic Things changed in April 2007By co-incidence, I've spent the day in Estonia, participating the EUMinisterial Conference on Critical Information InfrastructureProtectionToday's first presentation was by president of Estonia, Mr ToomasHendrik IlvesilvesI was really impressed by the talk by Mr Ilves It was a rhetoricallysound and masterfully executed talk by an European statesman And eventhough it was on the topic of my own expertese, I still found itinsightful It was also refreshing to listen him mention technicaldetails like botnets, DNSSEC and DDoS Impressive Watch this manSigning off,Mikkohttp://wwwtwittercom/mikkohypponenOn 28/04/09 At 07:51 PM</description><link>http://www.secuobs.com/revue/news/89402.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/89402.shtml</guid></item>
<item><title>CAPTCHA me if you can</title><description>Secuobs.com : 2009-04-27 19:26:14 - FSecure Antivirus Research Weblog -  Last week, a Vietnamese security company located a worm thatmass-registers Gmail accounts for spamming purposes In order to dothat, the worm needs to crack the Gmail CAPTCHA security imagesgmail captchaIn order to do that, the worm uploads the CAPTCHA images to a RussianCAPTCHA Cracking Serviceanti-captchaThis service offers 1000 cracked codes for $1 with a money-backguarantee in case of mistakes, or with codes that took too long tocrack over 60 secondsSuch services typically use humans to crack the codes manually It'shard to image a more repetitive or boring job The people behind suchservices exploit cheap labor or possibly – child labor Read more fromthis article by Byron AcohidoPerhaps the most surprising twist in the whole story is that Google isnot just a victim hereSurprisingly, if you go searching for terms like "crack captcha" or"break captcha", you will get sponsored ads in Google search results —for CAPTCHA cracking servicescaptchalinksDoes anyone else see any irony in here---------------------------------------------------------------------On 27/04/09 At 02:36 PM</description><link>http://www.secuobs.com/revue/news/88737.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/88737.shtml</guid></item>
<item><title>Swine Flu SEO</title><description>Secuobs.com : 2009-04-27 13:29:47 - FSecure Antivirus Research Weblog -  Swine Flu is in the news worldwide and search trends are spiking inNorth America:Swine Flu, Google TrendsWe're seeing lots of domains being registered Here's a list of theones registered over the weekendSwine FluNo malware sites… yet But plenty of them are opportunistic:NoSwineFlucomClick on the "Add to Cart" button at noswineflucom and you'll beasked to buy a PDF file called "Swine Flu Survival Guide" for $1995Swine Flu Survival Guide $1995You'd be better off spending your money on thisOn 27/04/09 At 09:34 AM</description><link>http://www.secuobs.com/revue/news/88536.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/88536.shtml</guid></item>
<item><title>Taking Cyberwar Seriously</title><description>Secuobs.com : 2009-04-23 07:27:37 - FSecure Antivirus Research Weblog -  Techies and non-techies have been debating about "cyberwar" - is theresuch a thing Is it a threat Who would do it Who cares - since themovie WarGames came out in 1983No consensus on the topic as yet, but it looks like some militaryofficials are taking the threat seriously Computerworld reports thatthe Obama administration may be setting up a military command centerdedicated to combating and "developing offensive cyberwarfarecapabilities"Not everyone thinks all the concern is warranted Marcus Ranum, CSO ofTenable Network Security gave a keynote speech at the 2008 Hack In TheBox conference in Kuala Lumpur entitled "Cyberwar is Bullsh*t" Thetitle says it all, really You can get the slides from the speech herepdfNot everyone dismisses the threat though Interesting commentary to MrRanum's contentions come from Richard Bejtlich's TaoSecurity blog,hereFor those interested, there are plenty of debates on the topicfloating around the Internet Thoughts, anyoneOn 23/04/09 At 03:50 AM</description><link>http://www.secuobs.com/revue/news/87036.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/87036.shtml</guid></item>
<item><title>Online Scanner 4 with Support for Firefox</title><description>Secuobs.com : 2009-04-22 18:37:51 - FSecure Antivirus Research Weblog -  F-Secure Online Scanner 4 will soon be released There are somenoteworthy changesThe UI has been updated, improved performance — AND — there's nowsupport for the Firefox browserHere's what the beta looks like:OptionsScanning in progress:ScanningAnd the finished results:FinishedOur Support News has more details and you can find a link to the BetaProgram thereOn 22/04/09 At 03:11 PM</description><link>http://www.secuobs.com/revue/news/86633.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/86633.shtml</guid></item>
<item><title>25,000 Bank Robbing Mobile Phones</title><description>Secuobs.com : 2009-04-21 17:27:51 - FSecure Antivirus Research Weblog -  Many European banks provide their customers with a paper list ofsequential numbers and randomly requested checksums Without thisphysical list, an attacker might be able to access the online bankingGUI, but they should not be able to complete a fund transactionNow, carrying around a card and scratching off numbers is fairlysecure but it isn't always convenientotpWhat's more convenient and is something you always have with you YourphoneMore and more banks are beginning offer transaction authenticationnumbers TAN via SMS text messages The customer registers theirphone to receive the one-time passwords, and the TAN is providedon-demand Easy, secureAnd that brings us to this headline: Criminals Pay Top Money forHackable Nokia PhoneA company called Ultrascan Research Services claims that East Europeangangs are paying big money for certain versions of Nokia 1100 phonesNokia 1100According to Ultrascan's post, some Nokia 1100 phones can be used tointercept SMS messagesWe don't have the details, we only know what's been stated byUltrascan We've also been unable to find a hacker forum or an auctionsite with actual requests for such phonesTo be worth the prices being paid up to 25,000 the phone wouldsomehow need spoof the victim's phone number without using their SIMcard If that's possible, then it's a very clever trick and suddenlyenables the use of all of the past compromised account informationthat's been gathered by banking trojansAnd that's a very sizable return on investment Even for a 25,000phoneOn 21/04/09 At 01:53 PM</description><link>http://www.secuobs.com/revue/news/86078.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/86078.shtml</guid></item>
<item><title>False alarm with BackdoorWin32Agentafqs</title><description>Secuobs.com : 2009-04-20 10:21:12 - FSecure Antivirus Research Weblog -  In the last couple of hours, we had a false alarm on a Windows XP systemfile called wmiprvseexemd5:798A9E6828997EEF4517ADA8A2259831This file was updated by Windows updates earlier this year Though theexecutable is not signed by Microsoft, it is indeed a clean fileThe file may appear on your system in the following locations:• C:WINDOWSsystem32wbemwmiprvseexe• C:WINDOWSsystem32dllcachewmiprvseexe•C:WINDOWSSoftwareDistributionDownload51401b498f4675531d9efb941ee01ef3_ctcSP3GDRwmiprvseexeWe have fixed the false alarm and apologize for any inconvenienceFix is included in the database release 2009-04-20_02On 20/04/09 At 05:15 AM</description><link>http://www.secuobs.com/revue/news/85459.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/85459.shtml</guid></item>
<item><title>Malware Analysis Course Materials Now Available</title><description>Secuobs.com : 2009-04-19 20:30:00 - FSecure Antivirus Research Weblog -  As we blogged on New Year's Eve, we have been teaching malware analysisand antivirus technologies at Helsinki University of Technology againthis SpringTKK Main Building in OtaniemiAbove: TKK Helsinki University of Technology main building Phototaken February 2009 on a fairly "white sky" dayAntti giving a lectureAbove: Antti Tikkanen giving a lecture on dynamic analysis of malwareThe lectures are now over and the students have about a month to turnin their final assignments Even though the "last hurrah" for the 2009Spring course is is still missing, I would like to thank TKK staff andFS Labs lecturers for the course I would also like to thank thestudents; It was again a real pleasure to teach motivated and smartpeople I'm really looking forward to receiving the final projectsubmissionsFor those interested, slides for all of the lectures are available inPDF format from the course homepagesLecture schedule-- Mika, Principal lecturer of T-1106220, Spring 2009On 19/04/09 At 03:54 PM</description><link>http://www.secuobs.com/revue/news/85336.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/85336.shtml</guid></item>
<item><title>Mikey and the Mysterious Treqz</title><description>Secuobs.com : 2009-04-19 12:52:14 - FSecure Antivirus Research Weblog -  One more post on Twitter wormsWhat's up with Mikey Mooney He wrote a series of Twitter worms, gothired, got hacked hey, nice passwords, Mikeyy and released yetanother worm last nightThis one did extensive modifications to infected profiles; changingthe name and bio to "Mikeyy" and the title of the profile to "Mikeyand the Mysterious Treqz"Mikey and the Mysterious TreqzThis variant downloaded additional scripts from runebashnet/xssjscareful, it's still upThe messages it sent were more philosophical in nature:Be nice to your kids They'll choose your nursing home Womp mikeyyIf you are born ugly blame your parents, if you died ugly blame your doctor Womp mikeyyEvery man should marry After all, happiness is not the only thing in life Womp mikeyyAge is a very high price to pay for maturity Womp mikeyyNinety-nine percent of all lawyers give the rest a bad name Womp mikeyyIf your father is a poor man, it is your fate, but if your father-in-law is a poor man, it's your stupidity Womp mikeyyMoney is not the only thing, it's everything Womp mikeyySuccess is a relative term It brings so many relatives Womp mikeyy'Your future depends on your dreams', So go to sleep Womp mikeyyGod made relatives; Thank God we can choose our friendsWomp mikeyy'Work fascinates me' I can look at it for hours  Womp mikeyyI have enough money to last me the rest of my life unless I buy something Womp mikeyyRT @spam Watch out for the Mikeyy worm bitly linkFUCK NEW MIKEYYY WORM REMOVE IT: bitly linkMikeyy worm is back Click here to remove it: bitly linkHow many users got infected We can't tell the total count However,Mikeyy seeded the infection via three new Twitter user accounts he hadcreated and we can see how many clicks they got:Account 54321ana: 4,833 clicksAccount er1kaaa: 4,895 clicksAccount chicostickgirl: 8,066 clicksThe only thing we haven't seen yet is that a really popular Tweeterwith tons of followers would get infected think Oprah or BritneySpears or Lance ArmstrongOn 19/04/09 At 10:31 AM</description><link>http://www.secuobs.com/revue/news/85300.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/85300.shtml</guid></item>
<item><title>Yet another Twitter worm</title><description>Secuobs.com : 2009-04-18 04:01:04 - FSecure Antivirus Research Weblog -  A new Twitter cross-site scripting worm is going around on Twitter Justlike the previous Twitter worms it talks about Mikeeytwitter_041709_1jpgOther messages used by the worm is:Twitter, this sucks Fix your codingTwitter Security Team Really You need to be firedHorrible Coding@oprah - sup welcome to twitter - mikeyy@aplusk - hey, homo - mikeyy@souljaboyellem - your music sucks dude - mikeyy@TheEllenShow - hey baby, love me long time - mikeyy@StephenColbert - you funny - mikeyy@cnnbrk - he's back ; - mikeyy@nytimes - yep, it's true - mikeyyTwitter, do you know about the before_save model callback - mikeyyThis exploit only affects Internet Explorer users Thanks - mikeyyTwitter, BeforeSave: ForEach: DataArray: EscapeHtmlCars - mikeyyGet Firefox, thanks wwwFirefoxcomTwitter, you should be paying me now - mikeyyOnce a user views an already infected profile they get infected aswell The name, location, website and bio all gets changed to Mikeyyand they start posting messages randomly picked from the list abovetwitter_041709_1jpgThe malicious script itself is downloaded from 74200253195 Twitteris working on fixing the problemThis happens on the same day as media reports that Michael Mooney gota job because of him writing the first Twitter worms So if he didthis one too, what was the motivation To get an even better offerfrom someone else StupidFor now, stay away from looking at user's profiles Firefox andNoScripts is a good comboUpdated to add: Michael Mooney Mikeey confessesto writing thislatest worm as wellOn 17/04/09 At 10:03 PM</description><link>http://www.secuobs.com/revue/news/84969.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/84969.shtml</guid></item>
<item><title>Now this is just wrong</title><description>Secuobs.com : 2009-04-17 04:00:57 - FSecure Antivirus Research Weblog -  Searching for good things with bad results is something that now happenson a regular basis, like the example we blogged about the other dayBut now it's personal - searching for "f-secure" leads to rogueproducts This time it's not via SEO Search Engine Optimization butthrough malicious Google ads As you can see in the screenshot belowthere's an ad pointing to update-xpcom You have to click on searchtwice for it to come up and it doesn't seem to happen every timegoogle_fssearch_1jpgLet's check it out It leads to a page talking about Fix F-SecureProblemsgoogle_fssearch_2jpgLet's download and install this fix tool on a clean XP SP3 machine andsee what it isgoogle_fssearch_3jpgAmazing 1303 total problems found whereof 1277 couldn't be removed inthe unregistered version Let's try to registergoogle_fssearch_4jpgSurprise We have to pay $3495 to register and remove all the"problems"Last bit of irony, it claims that Windows is up-to-date but as you cansee from the screenshot below 36 updates are actually missinggoogle_fssearch_5jpgThis has been reported to Google so hopefully it will be removed soonOn 16/04/09 At 11:03 PM</description><link>http://www.secuobs.com/revue/news/84533.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/84533.shtml</guid></item>
<item><title>Waledac offering a fake SMS spying tool</title><description>Secuobs.com : 2009-04-16 14:52:09 - FSecure Antivirus Research Weblog -  The Waledac botnet has been actively used to push malware since lastyearThe tactics employed by Waledac are so similar to the old Storm Wormthat we have reason to believe they are closely connectedLast night, the websites used to push Waledac infections got anoverhaulWe started seeing infection reports of filenames like smsexe,trialexe, smstrapexe, freetrialexe and smsreaderexeWhen we went searching, we noticed that the Waledac sites now lookedlike this:smstrapexeNice graphics, jerksAnyway, these sites had domain names like downloadfreesmscom,chinamobilesmscom and smsclubnetcomIf you check the DNS records for these domains, you'll notice thatthey have a time-to-live set to zero And they use that to changetheir IP address every time you query it This is fast fluxing ineffectLets monitor the IP address of smsclubnetcom for two minutes:TimeIP11:00:1711823221820911:00:2221110522020411:00:281211797318511:00:331248892911:00:3869553015811:00:441161271844911:00:492014213621411:00:548935182711:01:00247725013111:01:051181308320211:01:11777815019911:01:162111801187011:01:211891111973611:01:27121183328011:01:3221121819722011:01:38121183328011:01:431251291513311:01:4815160887011:01:541211797318611:01:59210207217154And all those IP addresses are infected home computers, where theowner of the computer has no idea he's actually running a webserver -which is serving virusesThis botnet is not just used to server the malware: the malware itselfuses it when calling home When Waledac is executed, it does dozens ofHTTP posts to IP addresses belonging to this botnetwaledac_animationWaledac gang has registered over 100 com domains for their purposesYou can actually tell a bit about their operations if you arrangetheir domains into groups Practically all the domains they own areregistered to these email addresses: hanlin_425@126com, lijian@qqcomand wusong_ccc@126comHere they are:News:bestgoodnewscombestbreakingfreecombreakinggoodnewscombreakingnewsltdcombreakingkingnewscombreakingnewsfmcomeasyworldnewscomgoodnewsreviewcomgoodnewsdigitalcomreportradiocomlinkworldnewscomtntbreakingnewscomusabreakingnewscomwapcitynewscomworldtracknewscomworldnewseyecomworldnewsdotcomworldtracknewscomspacemynewscomyourbreakingnewcomBlogs:bestusablogcombestjournalguidecombestlifeblogcombestblogdirectcomboarddiarycomblogsitedirectcomblogginhellcomfarboardscommobilephotoblogcomphotoblogsitecomFear et Terror:againstfearcomantiterroriscomantiterroralliancecomantiterrornetworkcomfearalertcomglobalantiterrorcomterroralertstatuscomterrorfearcomterrorismfreecomurbanfearcomCoupons et sales:bestcouponfreecomcodecouponsitecomgonesitecomgreatcouponclubcomgreatsalesgroupcomgreatsalestaxcomsmartsalesgroupcomthecoupondiscountcomyourcountycouponcomLove et sex:adorelyriccomadorepoemcomadoresongcomadoresongscombestadorecombestlovehelpcombestlovelongcombluevalentineonlinecomchatloveonlinecomcherishlettercomcherishpoemscomextendedmancomfunloveonlinecomfunnyvalentinessitecomgreatsvalentinecomorldlovelifecomgreatvalentinepoemscomlovecentralonlinecomlovelifeportalcomromanticslovingcomthevalentineloverscomwhocherishcomwirelessvalentinedaycomworldlovelifecomworshiplovecomyouradorecomyourgreatlovecomyourlengthcomyourvalentinedaycomyourvalentinepoemscomyourvalnetinepoemscomand here are the latest additions:SMS Spying:chinamobilesmscomdownloadfreesmscomfreecolorsmscomfreeservesmscommiosmsclubcomsmsclubnetcomsmspianetacomvirtualesmscomThis leaves us with a handful of domains we can't categorize to any ofthe above groups They are:batchoosecombayhousehotelcomcoralarmcomlongballonlinecommoneymedalcomquickjustcomsoundroyalcomyourbarriercomyourlolcomyourwentcomMaybe these domains could give us a hint on their next moveDoes anybody have any ideas If so, leave us a comment---------------------------------------------------------------------On 16/04/09 At 12:22 PM</description><link>http://www.secuobs.com/revue/news/84205.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/84205.shtml</guid></item>
<item><title>Twitter worm Google searches leads to malware</title><description>Secuobs.com : 2009-04-15 00:12:53 - FSecure Antivirus Research Weblog -  No surprise at all that Google searches for information about theTwitter worm would lead to malware sites, it was really just a matterof time Especially not after all the talk about it over the weekendand the guy behind it even confessing everything Malicious searchresults about popular news is something we see very oftenunfortunatelyBy searching for "Twitter worm" on Google one of the top 10 hits looklike this:twitterworm_google_searchjpgWhich leads to this site:twitterworm_google_2jpgBut you'll never see that as you immediately will get redirected tovidexxxxxscn which immediately redirects you to loyxxxxxxnocom whichtricks you into downloading a fake video codec from cxxxxxxxxazcomNo exploits are used, it's just social engineering At least for nowtwitterworm_google_3jpgAnd the fake codec is of course malware In fact, it's a trojandownloader that downloads some additional malware, including a roguesecurity product called WinPC Defender which shows fake malwaredetectionstwitterworm_google_4jpgLike all rogue security products it will tell you that you havemalware on your PC and that you have to buy the product to removethem This is more expensive then usual though as they want you to pay$6999 the usual rate seem to be $3995twitterworm_google_5jpgSo, unfortunately we're not surprised that this happned As usual, getyour news and information from sources you trust Random Googlesearches can't be trustedOn 14/04/09 At 08:47 PM</description><link>http://www.secuobs.com/revue/news/83324.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/83324.shtml</guid></item>
<item><title>April security updates from Microsoft</title><description>Secuobs.com : 2009-04-14 22:03:34 - FSecure Antivirus Research Weblog -  Microsoft just released the security updates for April and this includesthe fix for Excel which have been exploited in targeted attacks forover a month now Make sure you download these patches, including theone for Excel if you use Microsoft Office 2007, right nowUnfortunately a fix for the PPT vulnerability wasn't part of thismonth's updateMS Updates April 2009On 14/04/09 At 05:29 PM</description><link>http://www.secuobs.com/revue/news/83240.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/83240.shtml</guid></item>
<item><title>Ongoing problems at Twitter</title><description>Secuobs.com : 2009-04-13 13:10:54 - FSecure Antivirus Research Weblog -  Twitter administrators don't seem to be able to shut down the variousXSS / CSRF worms that have been plaguing the service over the weekendThe actual problems to end users haven't been devastating - so farMost of the Twitter worms simply modify people's profiles to infectmore usersHowever, attacks like these could be much worse if the attackers wouldincorporate nastier attacks, such as browser exploitsThe attacks have been credit to "Mikey" or "Mikeyy", who apparentlywas the administrator of a site called Stalkdaily Stalkdaily was acompetitor for Twitter and apparently the original motive of theattack was to "steal" Twitter users to join this new service Web pagefor Stalkdaily is currently downLatest round of worms just started minutes ago Apparently this runwas started by a freshly registered user called cleaningUpMikey:mikeyyThis is what the attack looked like:mikeyyIf you clicked on the name or the image of the person sending themessage, you would get infected as well and would send the samemessage - and anyone viewing your profile would do the sameWe can't confirm whether "Mikeyy" is really behind these attacks Wecan't confirm the above phone number either However, it was likelypicked up from this page from a social networking site:mikeyyFor now, don't view profiles in TwitterUpdated to add:A quick look at another incarnation of the same worm This one wasinteresting, as it was using bitly redirector in the messagesInfected users were sending Tweets like this: "How TO remove newMikeyy worm RT http://bitly/yCL1S"A message like this is particularily nasty, as there were plenty ofre-tweets of this malicious message sent by genuine usersThe bitly link got redirected back to Twitter, to user reberbrerber'sprofile Which would infect Twitter users who would view itThe good part about using a URL redirector is that now we can getexact statistics on how much traffic this link received Turns out theURL got clicked over 18,000 times - and the figure is still growingmikeyyAnd where were these users frommikeyyOn 13/04/09 At 09:37 AM</description><link>http://www.secuobs.com/revue/news/82607.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/82607.shtml</guid></item>
<item><title>Twitter worm outbreak over Easter</title><description>Secuobs.com : 2009-04-12 12:53:38 - FSecure Antivirus Research Weblog -  A cross-site scripting worm was spreading in Twitter profiles forseveral hours last nightPeople started reporting that their profile had sent Twitter messageswithout their knowledge Messages looked like this:stalkdailystalkdailyLater on the messages morphed several times:stalkdailyMany people followed the links to stalkdailycom, as they believe themessages to be genuine Tweets from their friends A cross-site scripton the site then caused new users to start to Tweet the same messagesstalkdailyThe problems continued for several hours until Twitter shut theproblem downMore info on the technical internals of the attack are available atdcortesicomstalkdailyAs expected, the whole worm was a publicity stunt by stalkdailycomstalkdailyYou can see the latest official status of Twitter from their statuspage at statustwittercomstalkdailyWe will detect the script file as Worm:JS/TwettirA in the nextupdate, due in 30 minutesOn 12/04/09 At 09:35 AM</description><link>http://www.secuobs.com/revue/news/82371.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/82371.shtml</guid></item>
<item><title>New Conficker action</title><description>Secuobs.com : 2009-04-09 23:48:38 - FSecure Antivirus Research Weblog -  A new variant of Conficker was found yesterday We're stillinvestigating the files but here's what we know so far* On April 8th a new update was made available to ConfickerCinfected machines via the P2P network* The new file, which we call ConfickerE, is executed and co-existsalongside the old infection* It re-introduces spreading via the MS08-067 vulnerabilitySpreading functionality was removed in ConfickerC and the gangbehind this maybe realized they made a mistake and added it again* There's a possible connection to Waledac, a spambot SomeConfickerC infected computers connected to a well known Waledacdomain and downloaded Waledac from there* There's also a connection to rogue anti-virus products as we'veseen it end up on ConfickerC infected machines The rogue productwas Spyware Guard 2008* ConfickerE deletes itself if the date is May 3, 2009 or laterSound complicated and strange It is and unfortunately nothing is easywhen it comes to Conficker so we'll continue to update this post as wefind out more about its behavior We detect the new ConfickerE sinceyesterday and all the related files it downloadsOn 09/04/09 At 07:08 PM</description><link>http://www.secuobs.com/revue/news/81698.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/81698.shtml</guid></item>
<item><title>The Dove</title><description>Secuobs.com : 2009-04-09 16:33:52 - FSecure Antivirus Research Weblog -  You can buy anything online nowadaysCase in point, here's Wenzhou Fuyuan Printing Co, ltd:hologramThis company is based in the South-Eastern shores of China Theyspecialize in manufacturing stationary, stickers, bagsand hologramsHere's some examples of their products, taken from the alibabacomsupplier directory:hologramLet's have a closer look at this hologram sticker sheet with "perfectquality", "standard size" and "3D effect":hologramHere's a close-up:hologramHmmThat looks familiarLooks like a birdMaybe a dovevisaVISA credit card image credit: PaylifeatLike I said: You can buy anything online nowadays---------------------------------------------------------------------On 09/04/09 At 12:30 PM</description><link>http://www.secuobs.com/revue/news/81475.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/81475.shtml</guid></item>
<item><title>Spying via XLS files</title><description>Secuobs.com : 2009-04-08 15:31:34 - FSecure Antivirus Research Weblog -  We see targeted attacks and espionage with trojans regularily Here's atypical caseA malicious Excel XLS file md5: 3c740451ef1ea89e9f943e3760b37d3b wasemailed to a target - apprently to just one personWhen opened, this is what the XLS looked like:pc-officerHowever, in reality the malicious file had already exploited Excel andtaken over the computer by the time you saw thisThe exploit code creates two new DLL files to the SYSTEM32 folder"apimgrdll" and "netservdll" and executes themThese DLL files are backdoors that try to communicate back to theattackers, using these sites:* fengpc-officercom* ihe19793322orgRight now, host ihe19793322org does not resolve at all, andfengpc-officercom resolves to a placeholder IP which is63646364 The attackers can temporarily make the hostname resolveto the real IP address and then turn it back, to hide their tracksThe domain name pc-officercom is a weird one It has been registeredalready in 2006, and it has been used in targetted attacks beforeSee this ISC blog entry from September 2007 Here the attack was donevia a DOC files, instead of XLS And the reporting server was dingpc-officercom,not fengpc-officercomIf you haven't read about Ghostnet yet, now would be a good timePS We don't know what area is shown in the map image If you do,please leave a CommentUpdated to add: We kept monitoring the host fengpc-officercom Asexpected, it became alive for a short period yesterdayHere's what our logs look like:Tue 7 Apr 2009 16:13:21 63646364Tue 7 Apr 2009 16:14:17 63646364Tue 7 Apr 2009 16:15:13 63646364Tue 7 Apr 2009 16:16:09 216255196154Tue 7 Apr 2009 16:17:04 216255196154Tue 7 Apr 2009 16:18:00 216255196154Tue 7 Apr 2009 17:40:33 216255196154Tue 7 Apr 2009 17:41:29 216255196154Tue 7 Apr 2009 17:42:25 216255196154Tue 7 Apr 2009 17:43:21 63646364Tue 7 Apr 2009 17:44:17 63646364Tue 7 Apr 2009 17:45:13 63646364IP 63646364 is just a placeholder; 216255196154 is the realcontrol server They only bring it online sporadically, trying toavoid detectionThe IP is located in Spokane, USA:% whois 216255196154OrgName:    One Eighty NetworksOrgID:      OEN-1Address:    118 N StevensCity:       SpokaneStateProv:  WAPostalCode: 99201Country:    US---------------------------------------------------------------------On 07/04/09 At 11:10 AM</description><link>http://www.secuobs.com/revue/news/80990.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/80990.shtml</guid></item>
<item><title>Security Threat Summary Q1/2009</title><description>Secuobs.com : 2009-04-08 15:31:34 - FSecure Antivirus Research Weblog - f-secureWe've just published our threat summary for the first quarter of 2009This one focuses on Conficker, the first SMS worm and threats insocial networksMore info at http://wwwf-securecom/2009/---------------------------------------------------------------------On 08/04/09 At 09:13 AM</description><link>http://www.secuobs.com/revue/news/80989.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/80989.shtml</guid></item>
<item><title>Understanding the Spreading Patterns of Mobile Phone Viruses</title><description>Secuobs.com : 2009-04-06 17:02:13 - FSecure Antivirus Research Weblog -  The latest issue of Science publishes a research paper titledUnderstanding the Spreading Patterns of Mobile Phone VirusesThe paper is by Pu Wang, Marta C González, César A Hidalgo andAlbert-László BarabásiScienceAbstractWe model the mobility of mobile phone users to study the fundamentalspreadingpatterns characterizing a mobile virus outbreak We find that whileBluetoothviruses can reach all susceptible handsets with time, they spreadslowly due tohuman mobility, offering ample opportunities to deploy antiviralsoftware Incontrast, viruses utilizing multimedia messaging services could infectall usersin hours, but currently a phase transition on the underlying callgraph limitsthem to only a small fraction of the susceptible users These resultsexplain thelack of a major mobile virus breakout so far and predict that once amobileoperating system´s market share reaches the phase transition point,viruses willpose a serious threat to mobile communicationsThe paper more or less ignores the effects of technical safeguardsbuilt into modern smartphones operating systemsAnother weird thing: the paper mentions that the reason why therehasn't been more mobile outbreaks is that no smartphone operatingsystem is dominating enough Then in the next paragraph it mentionsthat Symbian has, oh, 65% market share of all smartphonesIn any case, an interested paper And lots of pretty picturesmobile phone spreading patternsmobile phone spreading patternsmobile phone spreading patternsmobile phone spreading patternsLink to the paper PDFLink to the supporting data PDF:Thanks for the links to Nick Fitzgerald---------------------------------------------------------------------On 06/04/09 At 12:42 PM</description><link>http://www.secuobs.com/revue/news/80012.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/80012.shtml</guid></item>
<item><title>Post April 1st Conficker QetA</title><description>Secuobs.com : 2009-04-02 23:36:27 - FSecure Antivirus Research Weblog -  As we posted Conficker QetA prior to April 1st it wouldn't be right if wedidn't do one after the eventQ: First off, how do I know if I'm infectedA: Joe Stewart has created a very simple test that's available at theConficker Working Group's site Click here to try it out If it saysyou're infected you can find a bunch of removals tools on the samesite, including F-Secure'sQ: So April 1st came and went Was there any doomsday activity, didthe Internet break downA: No If it did you wouldn't be able to read this And we neverreally expected anything to happenQ: So what really happened then, what was all the fuss aboutA: ConfickerC was programmed to start generating a list of websiteson April 1st in an attempt to download updates to itselfQ: And did itA: Yes it did That part of the worm worked just as intendedQ: So why didn't something major happen thenA: Because the people behind Conficker didn't publish an update on anyof the websites Conficker tried to contactQ: Was it a mistake on their part, did they forget about the April 1stactivation dateA: Very unlikely What really happened was that the Conficker WorkingGroup was able to prevent them from registering any of the domainsused by the worm Never before have we seen such a global cooperationwithin the industry and we're proud to be a member of that groupAlso, it would've been pretty stupid for the people behind Confickerto do something on the day everyone expected them toQ: But isn't it so that the worm can also update itself using thepeer-to-peer P2P technologyA: That's right, it can And it could've done this prior to April 1stQ: I didn't turn on my PC on April 1st so I should be OK, rightA: If your computer is infected then no, the worm will still be thereand it will try to download updates to itself when you turn it onQ: What's this I've heard about two people arrested in Belarus inconnection with ConfickerA: It was just an Aprils fools joke More hereQ: So what happens now, can we forget about Conficker and worry aboutother thingsA: No, not really April 1st was just the activation date Infectedcomputers will continue to reach out to 500 websites daily in anattempt to update itself And let's not forget the P2P technology, itcan update itself using that as wellQ: So that means we'll have to deal with this for a long timeA: Yes, until all the computers are cleaned up or until the peoplebehind it decide it's not worth it anymore So we'll keep onmonitoring the situationQ: What if I have more questionsA: Hopefully they're already answered by our previous QetA If not,make a comment to this post and we'll answer it for youOn 02/04/09 At 08:40 PM</description><link>http://www.secuobs.com/revue/news/78604.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/78604.shtml</guid></item>
<item><title>Conficker World Maps</title><description>Secuobs.com : 2009-04-02 10:34:54 - FSecure Antivirus Research Weblog -  Where in the world are the Conficker-infected machines todayShadowserver and Conficker Working Group have the maps:Conficker World MapConficker World MapConficker World MapFor more maps, visit the website of the Conficker Working GroupOn 02/04/09 At 06:55 AM</description><link>http://www.secuobs.com/revue/news/78324.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/78324.shtml</guid></item>
<item><title>April Fools jokes and Conficker</title><description>Secuobs.com : 2009-04-01 10:55:58 - FSecure Antivirus Research Weblog -  It's first of April today There's going to be April Fools jokes aboutConficker todayHere's some examples from the web and from Twitter:April Fools ConfickerApril Fools ConfickerApril Fools ConfickerFor the record, we plan on having no April Fools jokes in our blogthis timePS1 Here's what we posted on April 1st in 2007 and 2008PS2 This post from 2005 was not a joke, but many people though itwas Go figurePS3 Hey, check out what news Google hasPS4 Excellent Conficker Coverage from CNNOn 01/04/09 At 06:50 AM</description><link>http://www.secuobs.com/revue/news/77875.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/77875.shtml</guid></item>
<item><title>Conficker - what's going on</title><description>Secuobs.com : 2009-04-01 09:04:48 - FSecure Antivirus Research Weblog -  So it's been April 1st for almost 18 hours now in New Zealand and it'sthe early hours of April 1st on the east coast of the United States sowhat's going on So far - nothing Infected computers are generatingthe list of 50'000 domains and trying to go to 500 of those like we'vedescribed earlier but so far no update has been made available And wedon't really expect one, at least not right nowThe Conficker worm is still creating headlines though as can be seenfrom the front page of cnncomCNN and ConfickerMyself and Mikko will post updates on Twitter---------------------------------------------------------------------On 01/04/09 At 04:51 AM</description><link>http://www.secuobs.com/revue/news/77845.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/77845.shtml</guid></item>
<item><title>Conficker's domain routine has already started</title><description>Secuobs.com : 2009-03-31 23:23:58 - FSecure Antivirus Research Weblog -  Mikko posted earlier about how the domain generation algorithm inConficker works Just to make it clear to everyone - this has nowstartedInfected computers use the local time as the trigger of when to startgenerating the list of 50,000 domains so in places where the localtime is already April 1st, these computers are now actively pollingfor domainsAnd, until the GMT date is April 1st they are in fact polling fordomains for 31st March So far there hasn't been any updates availableon those sitesIn summary: Conficker has activated So far nothing has actuallyhappenedConfickerC polling for domainsOn 31/03/09 At 07:08 PM</description><link>http://www.secuobs.com/revue/news/77554.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/77554.shtml</guid></item>
<item><title>Video - Case Conficker</title><description>Secuobs.com : 2009-03-31 19:11:44 - FSecure Antivirus Research Weblog -  The Lab's YouTube Channel has been updated with a conficker presentationgiven by Mikko et Patrik back in FebruaryCase ConfickerYou'll find it here:• Case Conficker — Part 1• Case Conficker — Part 2---------------------------------------------------------------------On 31/03/09 At 03:06 PM</description><link>http://www.secuobs.com/revue/news/77423.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/77423.shtml</guid></item>
<item><title>When will it start</title><description>Secuobs.com : 2009-03-31 15:11:19 - FSecure Antivirus Research Weblog -  April 1st, 2009 has arrivedAs I'm posting this, it's 00:18 on the 1st of April in Auckland, NewZealandNew Zealand isn't particularly badly affected by ConfickerBut South Korea is in the TOP 5 infected countries And it's already20:18 on the 31st in Seoul right nowSo, when exactly is Conficker activatingIt goes like this:* Conficker checks the local clock every 90 minutes in some caseseven more frequently* The check is done with Windows GetSystemTime function* GetSystemTime ignores time zones, and always replies in GMT timeaka UTC time* Because of this, machines around the world should report the sametime* However, clock skew affects this as well* But not by much, as Windows machines will sync their local clockwith timewindowscom once a week* Once the local clock says it's April 1st, Conficker will check thedate from the netConficker's net time check uses several large websites Sites such as:* adobecom* answerscom* baiducom* bbccouk* comcastnet* disneygocom* ebaycouk* facebookcom* imdbcom* megaporncom* miniclipcom* rapidsharecom* torrentzcom* typepadcom* wikimediaorg* yahoocom* youtubecomThe HTTP header time on these sites is very accurateYou can check these yourself: simply connect to port 80 of any websitewith netcat or telnet In Windows, simply run "telnet googlecom 80"Once connected, type blindly "GET /" and hit enter a couple oftimes You'll get a screenful of results, including a "Date:" fieldTimeHere's some sample HTTP HEAD date values from sites that Confickeruses These were checked earlier this morning:GooglecomDate: Tue, 31 Mar 2009 06:27:42 GMTClient-Date: Tue, 31 Mar 2009 06:27:42 GMTClient-Peer: 20985171103:80FacebookcomDate: Tue, 31 Mar 2009 06:28:24 GMTExpires: Mon, 26 Jul 1997 05:00:00 GMTClient-Date: Tue, 31 Mar 2009 06:28:24 GMTClient-Peer: 6963184143:80wwwbaiducomDate: Tue, 31 Mar 2009 06:31:47 GMTExpires: Tue, 31 Mar 2009 06:31:47 GMTClient-Date: Tue, 31 Mar 2009 06:31:48 GMTClient-Peer: 2201815222:80wwwyoutubecomDate: Tue, 31 Mar 2009 06:32:30 GMTExpires: Tue, 27 Apr 1971 19:44:06 ESTClient-Date: Tue, 31 Mar 2009 06:32:31 GMTClient-Peer: 20865153253:80Conficker changes the operation mode from calculating 250 domains aday to calculating 50,000 domains a day when these sites report thatit's April 1stSo in the end, time zones and clock skews will not affect theactivationThe machines that are infected by ConfickerC and are turned on, willchange modes between 00:00 and 01:30 on April 1st GMT The ones thatare turned off, will change modes soon after they are booted upWe have few hours left and then we'll all see if there's anything toseeBelow is the GMT time for you When it turns from 23:59 to 00:00, it'sApril 1st for ConfickerTime nowCheers,MikkoPS I'm on Twitter http://twittercom/mikkohypponen---------------------------------------------------------------------On 31/03/09 At 11:18 AM</description><link>http://www.secuobs.com/revue/news/77313.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/77313.shtml</guid></item>
<item><title>Not A MacCinema Installer</title><description>Secuobs.com : 2009-03-31 12:58:23 - FSecure Antivirus Research Weblog -  We recently received a Mac sample, with a Disk Image File DMGextension, that claims to be a MacCinema Installer The file wasdownloaded from the following link:• http://power-bestcom/download//FlashPlayerUpdatev919dmgThis is a fake video site that serves a fake Adobe Flash Player updatefor Macs, supposedly to watch a videoAnyway, when mounted the DMG file has a package file named"installpkg" Here's the snapshot of what you get when you open thepackage:InstallThe "installpkg" file contains the following files:installpkgWe extracted the "Archivepaxgz" which contains the following files:ArchivepaxgzWe analyzed each file and found that "AdobeFlash", "preinstall" and"preupgrade" are all the same thing, which is actually an obfuscatedbash script:bashSo here's the de-obfuscated script:bash1Based on the above code, the script searches for the string"AdobeFlash" in the Schedule Jobs list; if the string doesn't exist,the script creates the following Schedule Job to run the "AdobeFlash"file every 5 hours"* */5 * * * "/Library/Internet Plug-Ins/AdobeFlash" vx 1/dev/null2et1"Here's the de-obfuscated script after crontab instructions:bash2The above code reveals that it will download and execute files fromthe following site: http://942472/cgi-bin/generatorplAlong with these downloads, it also sends the following informationabout the infected system:• System Information Processor Type• Computer NameThe downloaded file is also an obfuscated bash script:bash3Again, here's the de-obfuscated script of the downloaded file:bash4The above code shows that it will modify the infected systems DNSserver to one of the following:• 85255112205• 85255112237This range of IP Addresses is actually owned by UkrTeleGroup We'drecommend blocking DNS traffic to 852551120 – 85255127255Response Team post by — LordianOn 31/03/09 At 09:37 AM</description><link>http://www.secuobs.com/revue/news/77274.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/77274.shtml</guid></item>
<item><title>Conficker hype used by rogue gangs</title><description>Secuobs.com : 2009-03-31 00:35:13 - FSecure Antivirus Research Weblog -  Oh the ironyAs you're all aware Conficker has been in the news a lot lately,especially with regards to if anything will happen on April 1st ornot We found out that rogue security software folks have picked up onthis For example, lets have a look at remove-confickerorg, a domainwhich was registered today:remove-confickerorgThey advertise a tool called MalwareRemovalBot It's fakeInterestingly, it doesn't always find non-existing malware infectionson your PC - only sometimes But one thing is for sure, it does notremove ConfickerC We tried it and it didn't do a thing to remove itWhen it did find something that it claimed to be malware it lookedlike this:MalwareRemovalBots scanningAnd then it asked us to register and pay $3995 for the removalfunctionalityMalwareRemovalBots purchaseWhen following up on this we did a Google search for "removeconfickerc" and saw several purchased ads that lead to the same typeof "security" software as wellGoogle search for ConfickerCLike AdwareAlert and AntiSpy2009 It's clear that it's an affiliateprogram going onRogue softwareGet your facts from known sites and download your removal tools fromrespected companies Such as ours that you can find hereOn 30/03/09 At 08:20 PM</description><link>http://www.secuobs.com/revue/news/77111.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/77111.shtml</guid></item>
<item><title>Behind GhostNet</title><description>Secuobs.com : 2009-03-30 18:30:19 - FSecure Antivirus Research Weblog -  The GhostNet spy network was built by infecting sensitive computers withbackdoor/Remote Administration Tools RAT Most of these are modifiedand obfuscated versions of Poison Ivy description or Gh0st RATThese tools are Chinese open source backdoors, maintained by loosegangs of hackersAnd these gangs operate openlyHere's the website for Poison Ivy:Poison IvyWith a nice collection of screenshots:Poison IvyAnd the gang behind Gh0st RAT is known as CRufus aka Wolfexp:CRufus WolfexpSome quotes from the above page:• "Our desire for success is like wolf's desire for blood"• "We work together against the enemy like a pack of wolves…"Wolfexp website also feature a demo video on how to use Gh0st RAT totake over computers:CRufus WolfexpAmazingly, the video ends by showing 10 live webcam sessions, snoopingon unsuspected victims without their knowledgeCRufus WolfexpOn a related note, see this CNN video which interviews of the Chineseunderground in 2008 Some of the hackers claim that they were paid bythe Chinese governmentOn 30/03/09 At 03:32 PM</description><link>http://www.secuobs.com/revue/news/76910.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/76910.shtml</guid></item>
<item><title>Ghostnet</title><description>Secuobs.com : 2009-03-29 15:51:40 - FSecure Antivirus Research Weblog - Typical document used in a targeted attackUniversity of Toronto published today a great research paper ontargeted attacksWe've talked about targeted attacks for years These cases usually golike this:1 You receive a spoofed email with an attachment2 The email appears to come from someone you know3 The contents make sense and talk about real things and in yourlanguage4 The attachment is a PDF, DOC, PPT or XLS5 When you open up the attachment, you get a document on your screenthat makes sense6 But you also get exploited at the same time7 The exploit drops a hidden remote access trojan, typically GreyPigeon or Gh0st Rat variant8 No one else got the email but you9 You work for a government, a defense contractor or an NGOgh0st ratBut the real news is that Greg Walton et co actually managed to get aninside view of some of the servers used in these spying attacks Thismeans they got to see what was being done with the infected machinesand where in the world they wereghostnetClick the image to read John Markoff's articleThe release of the paper was synchronized with the New York Timesarticle University of Cambridge released a related research paper atthe same time as well The Cambridge paper goes all the way to pointthe finger directly at the Chinese Government Most other parties, usincluded, have not done such direct accusations without concrete proofof government involmentFor a reason or another, infowar-monitornet has been down all day Sowe've made a mirror of the research papers available here:ghostnetdoc ghostnetdocMore resources: Here's a video that we posted earlier about targetedattacks:youtubeAnd here are selected blog posts on the topic:* Several examples of what the attack documents looked like* The mystery of Sergeant "nbsstt"* How we found the PDF generator used in some of these attacksOn 29/03/09 At 02:21 PM</description><link>http://www.secuobs.com/revue/news/76511.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/76511.shtml</guid></item>
<item><title>Questions and Answers: Conficker and April 1st</title><description>Secuobs.com : 2009-03-26 17:39:38 - FSecure Antivirus Research Weblog - Conficker and DownadupQ: I heard something really bad is going to happen on the Internet onApril 1st Will itA: No, not reallyQ: Seriously, the Conficker worm is going to do something bad on April1st, rightA: The Conficker aka Downadup worm is going to change it's operation abit, but that's unlikely to cause anything visible on April 1stQ: So, what will it do on April 1stA: So far, Conficker has been polling 250 different domain names everyday to download and run an update program On April 1st, the latestversion of Conficker will start to poll 50,000 domains a day to do thesame thingQ: The latest version There are different versions out thereA: Yes, and the latest version is not the most common Most of theinfected machines are infected with the B variant, which becamewidespread in early January With B variant, nothing happens on April1stQ: I just checked, and my Windows machine is clean Is something goingto happen to me on April 1stA: NoQ: I'm running a Mac, is something going to happen to meA: NoQ: So… this means that the attackers could use this download channelto run any program on all the machinesA: On all the machines that are infected with the latest version ofthe worm, yesQ: But what's this peer-to-peer functionality I've heard aboutA: The worm has some peer-to-peer functionality which means thatinfected computers can communicate with each other without the needfor a server This enables the worm to update itself without the needfor any of the 250 or 50,000 domainsQ: But doesn't that mean that if the bad guys wanted to run somethingon those machines, they don't need to wait for April 1stA: Yes Which is another reason why it's unlikely anything major willhappen on April 1stQ: Is there going to be media hypeA: Oh yes Like there always is when a widespread worm has a datetrigger Think cases like Michelangelo 1992, CIH 1999, Sobig2003, Mydoom 2004 and Blackworm 2006Q: But in those cases nothing much happened even though everybodyexpected something to happenA: ExactlyQ: So, should I keep my PC shut down on April 1stA: No You should make sure it's clean before April 1stQ: Can I change the date on my machine to protect meA: No The worm does not use the system clock to check the dateQ: I'm confused How can you know beforehand that there will be aglobal virus attack on April 1st There must be a conspiracy hereA: Yes, you're confused There is not going to be a "global virusattack" The machines that are already infected might do something newon April 1st We know this because we have reverse engineered the wormcode and can see that this is what it has been programmed to doQ: Would the downloaded program execute with admin privilegesA: Yes, with local admin rights Which is pretty badQ: And they could download that program not just on April 1st but alsoon any day after thatA: Correct So there's no reason why they wouldn't do it on, say,April 5th instead of April 1stQ: Ok, they could run any program To do whatA: We don't know what they are planning to do, if anything Of course,they could steal your data, send spam, do DDoS, et cetera But wedon't knowQ: They Who are they Who's behind this wormA: We don't know that either But they seem to be pretty professionalin what they doQ: Professional Is it true that Conficker is using the MD6 hashalgorithmA: Yes This was probably one of the first real-world cases where thisnew algorithm was usedQ: Why can't you just infect a PC, set the clock to April 1st and seewhat happensA: That's not the way it works The worm connects to certain websitesto get the time-of-dayQ: Oh yeah Then shut down the websites where it gets the time-of-dayand the problem will go awayA: Can't These are websites like googlecom, yahoocom andfacebookcomQ: But surely you could spoof googlecom in the lab to get a honeypotmachine to connect to a download site todayA: Sure And the download sites do not have anything to download,today They might, on April 1st Or they might notQ: Now I'm worried How do I know if I'm infectedA: Try to surf to wwwf-securecom If you can't reach our website youmight be infected, as Downadup/Conficker blocks access to securityvendor's websites Don't tell anybody, but users who can't accessf-securecom because of this can surf to wwwfsecurecom insteadQ: Where does the name "Conficker" come fromA: Conficker is an anagram of sorts from trafficconverter – a websiteto which the first variant was connectingQ: Why does the worm have two names – Downadup and ConfickerA: It was found at about the same time by multiple security companiesand therefore got multiple names Today most companies use the nameConficker There's further confusion about the variant letters amongvendors We're all sorry for thatQ: How many computers are currently infected by Downadup/ConfickerA: About 1-2 million How many of those are infected with the latestversion We don't have an exact countQ: How is the industry reacting to all thisA: We reacted by setting up the Conficker Working Group Membersinclude security vendors including us, registrars, research unitsand so onQ: I want more technical details on the wormA: Sure Here's our description, and here's SRI's excellent writeupQ: When was the first variant of Downadup/Conficker discoveredA: It was found on November 20, 2008Q: More than four months ago I want a time line on what happenedwhenA: Byron Acohido has oneQ: Is F-Secure able to detect and block this malwareA: YesQ: Do you have cleaning tool availableA: Yes, and it's free Click here to get itQ: Are you going to follow this throughA: Yes Stay tuned for updatesOn 26/03/09 At 02:32 PM</description><link>http://www.secuobs.com/revue/news/75569.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/75569.shtml</guid></item>
<item><title>Ad Supported Phone Applications and Proximity Services</title><description>Secuobs.com : 2009-03-25 19:17:34 - FSecure Antivirus Research Weblog -  We saw the following on my-symbiancom:My-Symbian have teamed up with ZingMagic to offer you a selection ofpremium quality applications for FREE These applications aread-fundedThe ads are shown on your phone's display when you receive calls andtext messagesThey are delivered via an application called adtronic It soundedinteresting so we decided to test it out for ourselves The adtronicapplication is produced by Liquid Air Lab GmbHThey have a Flash based demo herehttp://liquidairlabcomOur tests demonstrated adtronic to be a well behaving application thatdid exactly what it said it wouldThe user interface was easy to locate, the instructions to set theminimum/maximum limits were clear, and the ads themselves weren'tactually all that intrusive Downloading the ad banners requires adata connection and that is clearly stated It was also easy touninstall when we were done testingCombined with a set of free applications that people really want, thiscould be a successful business model Success interests us because amoney making business model will be noticed by eCrimeAdvertising revenue is the target of many DNSChanger PC malwarefamiliesAlso, while there are still some good Windows based ad supportedapplications, there are many more that crossover into adware andspywareTell us, what do you think Would you use ad supported software onyour phoneAnd something else we're interested in… What about mobile phoneproximity based servicesStuff like ad2hand, BlueBlitz, and HypertagThe basic idea is special offers and promotions are pushed out tothose within Bluetooth rangeCome visit our shop and receive a 10% discountHow would you feel if you were pushed an ad via BluetoothPerhaps it would make a difference if the marketing material is pulledrather than pushedYour comments are welcome---------------------------------------------------------------------On 25/03/09 At 04:21 PM</description><link>http://www.secuobs.com/revue/news/75161.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/75161.shtml</guid></item>
<item><title>Another Day, Another Video Site with Malware</title><description>Secuobs.com : 2009-03-25 11:03:54 - FSecure Antivirus Research Weblog -  We recently received reports of a file named "ActiveXsetupexe", whichwas downloaded from http://world-tube bizWorld-tubeFor people that want to play the video, there's a notice written onthe page on red font that "You may need to download an ActiveX videocodec VAC…" This old trick is well-known and commonly used by othermalwareRemember the Facebook site that attempts to trick people intodownloading and executing a fake Adobe Flash PlayerStill, what happens when an unsuspecting user downloads the"ActiveXsetupexe codec", thinking it is legitimate software Heresthe snapshot of it, as it is executed:TDSS installerThe file is a NSIS setup file, with a "Playmeexe" file inside thearchive Turns out the setup file is detected as Trojan:W32/TDSSBR,while the Playme file is detected as Worm:W32/TDSSBUSo, more video sites serving malware Watch out for these sites andstick to the trusted onesResponse Team post by — LordianOn 25/03/09 At 06:53 AM</description><link>http://www.secuobs.com/revue/news/74983.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/74983.shtml</guid></item>
<item><title>Something's Going Down @Twitter</title><description>Secuobs.com : 2009-03-24 22:01:50 - FSecure Antivirus Research Weblog -  Twittercom is really slow today, most likely due to spammers using itto flood the system with messages such as this:Free Range RoverI created a new dummy account to test this and literally withinseconds of signing up I had two followersOne was DowningStreet which is the official Twitter account for theguy who runs the UK The other follower was Kristen Andrews If wetake a look at her Twitter page we see a link:Kristen AndrewsThe link goes to… a Casino siteCasino siteThis page asks you to download the file goldencasinoexe which is aCasino gameMy "follower" Kristen's account was deleted within 10 minutes so itseems as Twitter is aware of the problemBut let's follow the link from the first screenshot to really see whatthese scams are about Who doesn't want a free Range Rover Clickingon the link takes us to a page talking about how we can make $5000 USDper month What happened to my free Range RoverGoogle CashIt still sounds like a good deal so let's go on Clicking on any ofthe links takes us to after a redirect via krovscom toonlinewizardsnet where it says we can now make $6500 per monthGoogle CashThis is getting better and better So let's sign upGoogle CashSo this is what it's really about, they want my credit card info andmy personal details Stay away from itTweeting off,PatrikOn 24/03/09 At 06:41 PM</description><link>http://www.secuobs.com/revue/news/74718.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/74718.shtml</guid></item>
<item><title>Trafficconverternet going down</title><description>Secuobs.com : 2009-03-20 19:39:46 - FSecure Antivirus Research Weblog -  One of the more notorious pay-per-install programs, Trafficconverter hasbeen taken down todayThese sites work like this:1 Trafficconverter developes a "rogue" antivirus product2 The product will find viruses even on clean systems3 It won't "clean" those viruses unless you register the product4 Trafficconverter does not market their software at all5 Instead, all the marketing is done through affiliates6 Affiliates have existing botnets of thousands of infected computers7 They remotely install these rogue products to those computers8 Confused end users see warning messages about viruses on theirscreens9 and register the rogue product for $50 to "fix" their machine10 Affiliates get $30 per customer, Trafficconverter get $2011 12 PROFITSo, it's good to see these guys going offlineHere's the front page of trafficconverter2biz yesterday:trafficconverterSame page today:trafficconverterKudos to Brian KrebsOn 20/03/09 At 02:22 PM</description><link>http://www.secuobs.com/revue/news/73217.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/73217.shtml</guid></item>
<item><title>Note, you may need to turn off your Anti-Virus</title><description>Secuobs.com : 2009-03-19 18:18:03 - FSecure Antivirus Research Weblog -  The YouTube video promoting a supposed Wii Points Generator, which weblogged about yesterday, has been removed due to terms of useviolationWhat's more, the entire "ItunesGenerator" channel has been removedNiceToday we took another look and found some more videos to flagThis video links to a file called Nintendo_Wii_Points_v2exe Wait,what does it say underneath the tooltipYouTube, willyspunkNote, you may need to turn off your Anti-VirusYouTube, willyspunkRight… that doesn't sound at all suspiciousLet's search for "note, you may need to turn off your" and see whathappensHmm Seems that there are plenty of videos to flag as malware pushers:Note, you may need to turn off your anti-airusOn 19/03/09 At 03:09 PM</description><link>http://www.secuobs.com/revue/news/72760.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/72760.shtml</guid></item>
<item><title>Skinny Guy Eats 53 Hot Dogs</title><description>Secuobs.com : 2009-03-19 18:18:03 - FSecure Antivirus Research Weblog -  YouTube is once again being used as a lure to spread malwareSome clown is sending out e-mails such as this:SkinnyUnlike most of the other similar cases, this one does not try to trickthe user into downloading and installing a Flash "update"Instead, if you follow the link, this one actually uses a Java appletcomplete with a fake signature to push a variant of Parite to themachinesSkinnyThe fake webpage runs on youtubeikwbcom, the malware is downloadedfrom adobe-flash-playerserveftpnetWatch outOn 19/03/09 At 03:17 PM</description><link>http://www.secuobs.com/revue/news/72759.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/72759.shtml</guid></item>
<item><title>Comcast High Speed Internet</title><description>Secuobs.com : 2009-03-19 18:18:03 - FSecure Antivirus Research Weblog -  Just a quick note on a new spam run that's going on It's from the samegroup that used Bank Of America as the lure late last week andNorthern Bank on MondayToday it's Comcast and it might actually have a higher success ratethen the previous run as users always want faster broadband,especially if there's no fee involved And the page looks reallyconvincingOnce installed the malware does the same as in the other spam runs -steals data and sends it to Hong KongComcastClick on the picture for a full page screen shotOn 19/03/09 At 04:17 PM</description><link>http://www.secuobs.com/revue/news/72758.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/72758.shtml</guid></item>
<item><title>YouTube Videos Promoting Wii Points Generator are Backdoors</title><description>Secuobs.com : 2009-03-18 19:14:04 - FSecure Antivirus Research Weblog -  Christopher Boyd of FaceTime Security Labs wrote an interesting postregarding YouTube videos that promote Nintendo Wii Points GeneratorsThey're a scam of course… and greedy victims attempting to steal WiiPoints will get a malicious backdoor called Bifrose for their troubleWiiPoints01Checking out some of the videos for ourselves, we discovered that thevideo information sections linked to a RapidShare download calledGeneratorexe That's the trojan-dropper that installs BifroseThere are a number of such Wii scams on YouTube, and for severalmonths tooWiiPoints02At the top of the list is itunesGenerator, age 18:WiiPoints06His Wii Points video has almost 36,000 viewsAnd his channel has 252 Subscribers We thought that wasinterestingWiiPoints05Who are these people Fake accounts to support his feedback Oraffiliates that have purchased backdoor accessAnd here's a selection of his "positive" feedback:WiiPoints03Of course the comments are moderated Do you think our comment will beapprovedWiiPoints04No — Not very likelyWe flagged the video with YouTube, but as Mikko's post from last weekshows, YouTube doesn't really have an exact match for this type ofscam You can flag videos for visual content promoting physical bodilyharm, but it's more difficult to warn of content with harmfulconsequences to your computer, should you follow its adviceWe hope this is something that YouTube acts on soonOn 18/03/09 At 05:33 PM</description><link>http://www.secuobs.com/revue/news/72205.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/72205.shtml</guid></item>
<item><title>Geburtstagsgeschenke</title><description>Secuobs.com : 2009-03-17 09:52:41 - FSecure Antivirus Research Weblog - germanyHey, our German office is ten years old F-Secure is over 20 yearsold as a companyAs part of the celebrations, we were asked to come up with a list ofthe most important viruses for the past 10 yearsThat wasn't too hard For most years it's easy to name THE virusincident of the year:1999: Melissa2000: Loveletter2001: Code Red2002: Nimda2003: Slammer2004: Sasser2005: Sony rootkit2006: Warezov2007: Storm2008: 2009: DownadupBut what about year 2008What was the most important malware for the year 2008 MebrootAntivirus XP Banker Something elseLet us know your suggestionsOn 17/03/09 At 07:09 AM</description><link>http://www.secuobs.com/revue/news/71664.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/71664.shtml</guid></item>
<item><title>Malicious spam run  Again and again and again</title><description>Secuobs.com : 2009-03-13 18:44:46 - FSecure Antivirus Research Weblog -  The type of spam runs we saw late last year Obama and BofA arestarting to pick up again in volume We've seen Classmates being usedas a theme and two days ago it was fake Facebook messages Today it'sback to fake Bank of America certificatesFake BofA siteAs in all previous spam runs it leads to a site prompting you todownload a fake Adobe Flash player This malware steals confidentialinformation and sends it to a web server In previous attacks thisserver was in Ukraine but it has now been moved to Hong Kong If yousee network traffic to the IP address 586523217 it's a bad signOn 13/03/09 At 04:37 PM</description><link>http://www.secuobs.com/revue/news/70879.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/70879.shtml</guid></item>
<item><title>New Online Backup Beta Available</title><description>Secuobs.com : 2009-03-12 22:19:10 - FSecure Antivirus Research Weblog -  You may remember the pilot project for our Online Backup back inDecemberVersion 200 is now available; its beta piloting project has juststarted Online Backup makes it possible to back up your importantdata — photos, e-mails, documents and so forth — over the Internet tosecure backup servers Because you know that it's not a matter of ifyour hard drive fails, but whenIt also allows you to share items with friends via the InternetOnline BackupWe're now releasing the Windows version for beta piloting A bit latera brand new Mac version will also be made availableWe have a limited number of beta licenses to give out so if you wantto try it out, act now Once the licenses are given out, the betaprogram will close You can join it at this address:http://wwwf-securecom/en_EMEA/support/home-office/beta-programs/olb/On 12/03/09 At 07:47 PM</description><link>http://www.secuobs.com/revue/news/70628.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/70628.shtml</guid></item>
<item><title>It's PDF Patching Day</title><description>Secuobs.com : 2009-03-11 18:59:04 - FSecure Antivirus Research Weblog -  Get the patches while they are hot:Update Foxit Reader if you have it alreadyUpdate Adobe Reader if you still have itFoxit 3020091506Do note that while we are recommending users move away from AdobeReader, we are not recommending any particular replacementSo, we're not recommending Foxit We're not recommending Sumatra OrPDF-Xchange, CoolPDF or eXPert PDFInstead, we recommend users to find their own Adobe ReaderreplacementThis way we get more heterogeneous userbase, which is a good ideasecurity-wise Nobody wants to repeat what happened with the great IE— Firefox switch As 40% of users switched to Firefox, about 40% ofthe attacks switched to target FirefoxMonocultures are badOn 11/03/09 At 03:59 PM</description><link>http://www.secuobs.com/revue/news/70159.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/70159.shtml</guid></item>
<item><title>Follow Patrik on Twitter</title><description>Secuobs.com : 2009-03-10 10:52:01 - FSecure Antivirus Research Weblog -  Our Chief Security Advisor, Patrik Runald, is based in San Jose, USAYou can follow his Tweets from http://twittercom/patrikrunaldOn 10/03/09 At 08:42 AM</description><link>http://www.secuobs.com/revue/news/69430.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/69430.shtml</guid></item>
<item><title>Nominate Your Favorite Security Blog</title><description>Secuobs.com : 2009-03-09 19:15:20 - FSecure Antivirus Research Weblog -  Only a short post today — it's been very busy lately…Do you like our blog If you do, consider nominating us for the firstannual Social Security AwardsHeld in conjunction with the Security Bloggers Meet-Up at RSAConference 2009,the Social Security Awards give readers a chance to recognize thebest, brightest,and most entertaining bloggers and podcasters in the fieldThe categories:http://wwwSocialSecurityAwardscom/And the link:http://wwwsocialsecurityawardscom/Nominations close March 31, 2009On 09/03/09 At 04:27 PM</description><link>http://www.secuobs.com/revue/news/68743.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/68743.shtml</guid></item>
<item><title>Illegal Trading on YouTube</title><description>Secuobs.com : 2009-03-04 12:16:03 - FSecure Antivirus Research Weblog -  Online criminals regularly post their ads on YouTube, looking for buyersfor their productsSome recent examples:YouTube cardingYouTube cardingYouTube cardingYouTube cardingYouTube cardingYouTube cardingYouTube cardingYouTube cardingYouTube cardingYouTube cardingYouTube cardingYouTube cardingNo big surprises thereA bit more surprisingly, when you want to report such videos toYouTube admins, they actually don't have an option for reportingcriminal use like thisYouTube cardingOn 04/03/09 At 10:20 AM</description><link>http://www.secuobs.com/revue/news/67224.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/67224.shtml</guid></item>
<item><title>Hiring : This Job is Not Safe For Work</title><description>Secuobs.com : 2009-03-02 21:55:23 - FSecure Antivirus Research Weblog -  Forget about malicious software for a minute…Let's take a look at another kind of content that's more or lessavailable on the Internet — PornographyNot Safe For WorkHow to find it How to detect itHow to tell "good pornography" from "bad pornography" Odd question,rightGood is safe for your credit card, and is legally produced Bad equalspeople who want to steal your money, abuse children or have otherillegal intentionsWhy do we bring this upOur Security Research Lab has a team dedicated to technology thatidentifies and classifies the content of websites This technology isthe primary underlying element of our F-Secure Parental Control Wealso do quite a bit of manual researchWe *suffer* so your kids don'tIn case you're interested in this line of work, we have a job opening"F-Secure Corporation is looking for a technically skilled individualto fill a position in Security Research You will develop and trackthe quality and value of detection software, platform solutions andprocesses that enable the F-Secure Parental Control and other contentrelated detection services"Our Careers page has more details Look for the "Quality Engineer withDevelopment skills, Security Research Program" positionOn 02/03/09 At 06:29 PM</description><link>http://www.secuobs.com/revue/news/66626.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/66626.shtml</guid></item>
<item><title>Phishing Sites are Compromised and Re-compromised</title><description>Secuobs.com : 2009-03-02 16:49:13 - FSecure Antivirus Research Weblog - Tyler Moore of Harvard and Richard Clayton of Cambridge have studied theusage of search engines in the compromise of Web servers in order tohost fraudulent content, eg phishing sites"Although the use of evil searches has been known about anecdotally,this is the first paper to show how prevalent the technique hasbecome,and to report upon the substantial rates of recompromise thatcurrently occur"Anecdotal evidence of multiple attacksOur May 21st, 2008 post is one such example We've seen compromisedsites becoming re-compromised for quite some time nowMoore and Clayton's paper offers some fascinating analytics on thetopic They've found that compromised machines accounted for 758% ofall the attacks analyzed And 20% of the sites that were compromisedwere successfully attacked again within six monthsThe paper is called Evil Searching: Compromise and Recompromise ofInternet Hosts for PhishingYou'll find a download link from Richard Clayton's post on Light BlueTouchpaperOn 02/03/09 At 02:56 PM</description><link>http://www.secuobs.com/revue/news/66528.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/66528.shtml</guid></item>
<item><title>Downadup, Good News / Bad News</title><description>Secuobs.com : 2009-02-27 21:59:00 - FSecure Antivirus Research Weblog -  First the bad news: There's still a lot of Downadup Confickerinfections out thereOur February 5th post noted 19 million unique IP addresses connectingto our sinkhole We're now logging something around 21 to 25million The log files are huge and can be very time consuming…Here's the good news: Despite the ongoing infections, progress wasmade against the wormDomains monitored by our sinkhole can no longer be registered Theworm's ability to phone home has been crippled This is due to acollaborative effort within the industryOn February 12, 2009, Microsoft announced a US $250,000 reward forinformation Microsoft's Conficker Worm page has details Bountieshave been successful in the past, eg Netsky's author, Sven JaschenOur January 30th post provided a Downadup domain blocklist for themonth of February While the domains no longer need to be blocked,such a list can still be useful to monitor for infected machineswithin your own networkYou can download a ZIP file with domains in use until June 30th fromthe Microsoft Security Response CenterOur Removal Tool is called f-downadupOn 27/02/09 At 06:59 PM</description><link>http://www.secuobs.com/revue/news/66080.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/66080.shtml</guid></item>
<item><title>About the Adobe and Excel Vulnerabilities</title><description>Secuobs.com : 2009-02-26 15:50:27 - FSecure Antivirus Research Weblog - Adobe/ExcelThere are two notable vulnerabilities currently beingexploited Both of them are not yet patchedOne fortunate mitigating factor is that the exploits are being usedfor targeted attacksThough that isn't very much of a mitigation if you happen to be thetargetHere are our vulnerability reports:• Microsoft Excel Invalid Object Reference Vulnerability• Adobe Reader/Acrobat JBIG2 Stream Array Indexing VulnerabilityMicrosoft published Security Advisory 968272 on Tuesday andrecommends using the Microsoft Office Isolated Conversion EnvironmentMOICE as a workaround High risk "targets" may want to consider thisas standard operating procedureAdobe is planning to release an update on March 11th That's March11th, like in two weeks from nowAdobe's mitigation steps involve disabling JavaScript However, seediscussion here as wellAdobe's steps are as follows:1 Launch Acrobat or Adobe Reader2 Select EditPreferences3 Select the JavaScript Category4 Uncheck the "Enable Acrobat JavaScript" option5 Click OKI'd show you a screenshot of the options, only I don't have AdobeReader installedI find it a bit confusing how commonplace Adobe Reader has become Forsome reason everybody seems to be using it for reading PDF files Eventhough there are plenty of free alternatives And the alternatives aremuch smaller and faster And start up in under a minuteFrom my point of view, Adobe Reader has become the new IE Forsecurity reasons, avoid it if you canRanting off,MikkoOn 26/02/09 At 01:21 PM</description><link>http://www.secuobs.com/revue/news/65505.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/65505.shtml</guid></item>
<item><title>Adobe Flash Vulnerability</title><description>Secuobs.com : 2009-02-25 17:03:37 - FSecure Antivirus Research Weblog - Patch your Flash: There's a vulnerability in multiple versions of AdobeFlashSee our report:• Adobe Flash Player remote code execution vulnerabilityHere's a tip — examine the following folder to see what you haveinstalled:• C:WINDOWSsystem32MacromedFlashYou may have multiple files from previous versions just sittingaround…You don't need much more than these files:C:WINDOWSsystem32MacromedVersion 1002287 is the updated versionHere's the IE version properties:Flash OCX 1002287Here's the Firefox version properties:Flash NPSWF 1002287You can download the update from Adobe and our Health Check service isalso of assistanceOn 25/02/09 At 12:45 PM</description><link>http://www.secuobs.com/revue/news/65122.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/65122.shtml</guid></item>
<item><title>Error Check System, Kenny Glenn, and Parking Tickets</title><description>Secuobs.com : 2009-02-24 18:47:40 - FSecure Antivirus Research Weblog - Error Check System: As we pointed out in yesterday's post, the timing ofthe Facebook "Error Check System" application and the subsequentGoogle search results pointing to rogue antivirus sites was almost tooperfect to be a coincidenceIt's entirely possible that the whole situation was designed topromote XP Antivirus variants such as "Antivirus 360" and "XP Police"Rogue:W32/XPAntivirus That's the formula, create something thatspawns a search, then be ready to provide results that redirect tomalicious sitesXP-Police dialogEither that or the bad guys are very quick on their feet and areruthlessly opportunistic… They're bothLet's take a look at some other recent examplesKenny Glenn: Just over a week ago, on February 15th, an anonymousteenage boy abused a cat called Dusty and posted video on YouTubeThe Dusty video rapidly ignited a vigilante campaign and three hourslater the boy was identified as Kenny Glenn from Lawton, Oklahoma Thelocal Sheriff was called in and Dusty was removed from the boy's homeBut things went further still: Facebook groups were formed calling forGlenn's punishment; Glenn's MySpace page was defaced; the family'spersonal information was posted online; and the Glenn Oil Companywebsite, owned by Glenn's father, was hackedWhen it occurs, this type of Internet vigilantism moves very quicklyand soon takes on a life of its own That then starts the news cycleand presents an opportunity for abuseWhile following the Dusty story ourselves, we read this post fromblogSpywareGuideRogue vendors attempted to capitalize from the growing interest in theKenny Glenn meme and searching for Glenn directed to rogue sitesHere's a screenshot of the Google search results for "kenny glenn cat"from last Thursday:Kenny Glenn CatThe highlighted freewebscom result redirected to a site thatattempted to push XP PoliceThe SpywareGuide blog was posted on Wednesday; our search 24 hourslater still yielded roguesTesting the XP Police site with a Mac demonstrates just how bogusthese scams are:XP-Police, Mac OS XImages: 1, 2Now obviously the bad guys didn't know in advance that Kenny Glennwould abuse poor Dusty They were just taking advantage of thesituation and jumped into actionBut are there situations where rogue affiliates have createdopportunity Yes there are…Parking Tickets: That's right, Parking tickets in North DakotaSANS blogged about it earlier this monthSome North Dakotans found a yellow ticket on their windscreen reading:• "PARKING VIOLATION This vehicle is in violation of standard parkingregulations"That sounds kind of familiarThe supposed ticket then instructed the victim to visit a websitewhere the driver could:• "view pictures with information about your parking preferences"To view the pictures, a toolbar needed to be installed, that thenpushed rogues at the victimThe BBC reported on it hereMicrosoft: Last October, Microsoft and Washington state started suingscareware purveyors There are also some recent cases in which roguebank funds were seized Perhaps that's a good start, but it isn'tnearly enough The real bad guys aren't scaredHow's this for boldMany XP Antivirus variants hamper analysis by checking for an Internetconnection Our test networks need be configured to provide theexpected reply if we want to automate our analysisAnd what page does the rogue check for• http://updatemicrosoftcom/windowsupdate/v6/thanksaspxThe XP Antivirus gang has been doing this for some time now… seems tous like a slap in Microsoft's faceWe would like to see Microsoft slap them back Using a hammerOn 24/02/09 At 04:55 PM</description><link>http://www.secuobs.com/revue/news/64743.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/64743.shtml</guid></item>
<item><title>Don't Seach for Error Check System</title><description>Secuobs.com : 2009-02-23 19:09:12 - FSecure Antivirus Research Weblog -  A Facebook application called "Error Check System" apparently spreaditself over the weekend utilizing misleading messages"Name has faced some errors when checking your profile – View TheErrors Message"The Errors MessageAttempting to view the error prompted for the application to beAllowed The allowing of Error Check System provided access to theuser's Friends to which the application then spammed additionalnotificationsAll Facebook and Graham Cluley have screenshots and additionaldetailsWhat is more interesting to us at the moment is that performing aGoogle search for the words "Error Check System" will result innumerous links pointing to Rogue Antivirus scamsYou do not want to visit the sites highlighted in red:Error Check System Search ResultsThe timing of this is almost too much of a coincidenceThe Facebook application didn't do very much other than spread itself,but it did create a newsworthy story And now people will be searchingfor that story and will stumble upon fake antivirus sitesRogues are jumping aboard the search bandwagon with ever increasingspeed Use caution when you searchOn 23/02/09 At 04:27 PM</description><link>http://www.secuobs.com/revue/news/64347.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/64347.shtml</guid></item>
<item><title>Mebroot</title><description>Secuobs.com : 2009-02-19 11:04:14 - FSecure Antivirus Research Weblog -  One of 2008's most interesting research cases proved to be the MebrootrootkitMebroot has been characterized as possessing a "commercial-gradeframework" and as being a "malware Operating System" The most notableof its features is the fact that the rootkit replaces the infectedcomputer's Master Boot Record MBR Mebroot therefore compromises thecomputer at a very low levelThe malware has apparently gone through some extensive qualityassurance It rarely ever crashes the systems it infects, even thoughit runs at the kernel level It's even been designed to send crashdumps back to its authors, so that they can improve upon their code ifrequiredMebroot VBPaperWe contributed our first bit of Mebroot analysis last March While thepost is quite technical, it only scratched the surfaceElia Florio of Symantec is another researcher that has analyzedMebroot in depth I collaborated with Elia and our efforts produced apaper for the Virus Bulletin: VB2008 conference I delivered apresentation on the opening day of the conference You can find ourVB2008 post with PowerPoint slides hereMebroot VBPaperWe can now make the paper itself available Click the link below todownload the PDF fileYour Computer is Now Stoned Again The Rise of MBR Rootkits3169KB PDFSigning off,KimmoOn 19/02/09 At 08:22 AM</description><link>http://www.secuobs.com/revue/news/63145.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/63145.shtml</guid></item>
<item><title>Sexy View Trojan on Symbian S60 3rd Edition</title><description>Secuobs.com : 2009-02-18 21:33:48 - FSecure Antivirus Research Weblog -  We've an interesting mobile case to report…One of today's samples is a trojan compiled for S60 3rd Editionphones It's detected as Trojan:SymbOS/YxeAThis is something we don't see very often There are spy tools andother privacy threats directed at S60 3rd Edition phones, but malwareis still mainly an issue on S60 2nd Edition phonesS60 3rd Edition uses a different binary structure than 2nd Edition,and then all 3rd Edition applications must be signed What's specialabout Yxe is that all evidence suggests it uses a valid SymbianCertificateWith this certificate, the trojan was signed And being a signedapplication it gains privileged accessThe source of this trojan is ChinaHere you can see the language options, EN and ZH:Trojan:SymbOS/Yxe package infoDid you also notice the "Sexy View" and "Play Boy" That should giveyou a good idea of the Social Engineering that's being utilizedOur mobile analysts are still working the case We'll have more foryou as it developsOn 18/02/09 At 06:14 PM</description><link>http://www.secuobs.com/revue/news/62955.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/62955.shtml</guid></item>
<item><title>Exploit Shield protects against new IE7 vulnerability</title><description>Secuobs.com : 2009-02-18 08:11:31 - FSecure Antivirus Research Weblog -  As Sean predicted a week ago, we now have exploit code in-the-wild forMS09-002, a vulnerability in Internet Explorer 7 This particularvariant of the exploit downloads a file named jcexe from a server inChina We detect the exploit as Exploit:W32/JSShellA and thedownloaded file as Trojan-Dropper:W32/AgentJLA The file jcexe dropsa backdoor detected as Backdoor:W32/AgentJLAIt was great to see that F-Secure Exploit Shield proactively protectedagainst the exploit without the need for an update Below is ascreenshot of the exploit being blockedExploit Shield blocks MS09-002If you haven't installed the update already, do so nowOn 18/02/09 At 06:04 AM</description><link>http://www.secuobs.com/revue/news/62759.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/62759.shtml</guid></item>
<item><title>Exploit Shield 060 Beta</title><description>Secuobs.com : 2009-02-16 18:07:59 - FSecure Antivirus Research Weblog -  A new version 060 of our F-Secure Exploit Shield Beta is nowavailable Our first public beta was released two months agoYou may also remember that Microsoft patched MS08-078 around the sametime Multiple versions of Internet Explorer were affected on multipleversions of the Windows OS and exploit code was circulating at thetime Exploit Shield 05 was able to proactively protect against thoseexploitsExploit Shield is designed to shield Web browsers between thedevelopment of an exploit and the release of the vendor's patchTo sum up, Exploit Shield provides:• Zero Day Defense: Protects unpatched machines• Patch-Equivalent Protection: Vulnerability "shield" updates• Proactive Measures: Heuristic detection techniques• Protects Against All Websites: Regardless if untrusted or trustedand malicious or hacked• Automatic Feedback: detected exploit attempts are automaticallyreported to F-SecureHere's the main menu:Exploit Shield 060 BetaHere's a view of the Proactive Measures menu:Exploit Shield Beta 060, ProactiveVersion 060 now includes 32-bit Vista support, includes morevulnerability coverage and also includes engine improvementsLook for the download link from: wwwf-securecom/labsIf you want or need a reason to test Exploit Shield, consider thismonth's Microsoft Updates There were two vulnerabilities in InternetExplorer 7 for Windows XP and Windows Vista that were patched lastweek…Firefox isn't completely immune either, see Mozilla's Security Centerfor details on recent vulnerability patchesNote: Version 05 users will now see a prompt that their installationhas expired The database channel is now closed, but the existingshields and the proactive protections remainOn 16/02/09 At 02:34 PM</description><link>http://www.secuobs.com/revue/news/62173.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/62173.shtml</guid></item>
<item><title>Google Earth KML</title><description>Secuobs.com : 2009-02-12 18:26:01 - FSecure Antivirus Research Weblog -  One of the tasks our stats server has is to provide data feeds — fromwhich Google Earth KML files can be createdWe often use Google Earth for presentations as it makes for a veryeffective demonstrationHere's part of Eurasia:Stats, Google Earth ImageThis is an example from Fiji:Stats, Google Earth ImageVersion 5 of Google Earth has some very cool new features…Download some of today's data: 20090212 Statistics 95MBLegend:Google Earth LegendAn extra icon in the data set represents use of our Online ScannerThose are detection, not source locationsOn 12/02/09 At 04:18 PM</description><link>http://www.secuobs.com/revue/news/61284.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/61284.shtml</guid></item>
<item><title>MS09-002/MS09-004, Consistent Exploit Code Likely</title><description>Secuobs.com : 2009-02-11 14:16:02 - FSecure Antivirus Research Weblog -  Two of yesterday's Microsoft Updates have Exploitability IndexAssessments of 1 — Consistent exploit code likelyFirst there's MS09-002 which addresses two vulnerabilities in InternetExplorer 7MS09-002And then there is MS09-004 which patches a vulnerability in MicrosoftSQL ServerYou can see from the bulletin that exploit code has already beenpublished for the SQL vulnerabilityMS09-004The Internet Explorer 7 vulnerability allows for Remote Code Executionon Windows XP SP2/3 and Windows Vista Considering the installed base,and the high Exploitability assessment, expect to see exploitsin-the-wild very soonOur Vulnerability Description for IE7 provides links to each of theindividual updates should you need to manually updateOn 11/02/09 At 12:23 PM</description><link>http://www.secuobs.com/revue/news/60782.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/60782.shtml</guid></item>
<item><title>Safer Internet Day 2009</title><description>Secuobs.com : 2009-02-10 12:22:16 - FSecure Antivirus Research Weblog -  Today is Safer Internet Day 2009 — an annual event coordinated by InSafeBlog reader MJ sent us a reminder, some links, and highlighted thisyear's anti-cyberbullying campaignGerman speakers can find more information from klicksafede Englishinformation about the klicksafe projectFrance's safe Internet site is called Internet Without FearThen there's the Finnish based Security School Tietoturvakoulu andInformation Security Guide TietoturvaopaswwwtietoturvaopasfiAnother excellent resource is digizenorg The site has sectionsregarding cyberbullying films as well as social networkingSocial Networking sites can often be the location of cyberbullyingDo you have any additional resource suggestions If so, please post acomment Have a good Safer Internet DayOn 10/02/09 At 09:57 AM</description><link>http://www.secuobs.com/revue/news/60293.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/60293.shtml</guid></item>
<item><title>Social Networking Hack</title><description>Secuobs.com : 2009-02-09 18:36:44 - FSecure Antivirus Research Weblog -  We recently read an interesting story from MSNBC's "The Red TapeChronicles" regarding an emerging Social Networking scamThere's also videoThe victim of the scam had his Facebook account hacked The attackerthen targeted his friends by changing the Status message to "BRYAN ISIN URGENT NEED OF HELP" And at least one of his friends fell forit, and wired $1,200 to the hackerDiscussing this article in our San Jose office, we discovered that oneof our employees knew someone that was targeted in the same way Only,he didn't fall for the scam We asked for permission to post his chatlogs"Lisa" is the hacked account "Bob" is the targetHere's the conversion:Facebook 419Bob's skepticism proved to be invaluable His next action was tocontact Lisa so that she could recover her account accessWe know of many Social Networking sites that are targeted by PhishingThis type of scam could occur on any of them A healthy amount ofcaution is very helpful if you wish to fully enjoy your SocialNetworking experienceWe're curious about our readership How many of you use Social NetworksitesOn 09/02/09 At 04:59 PM</description><link>http://www.secuobs.com/revue/news/59976.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/59976.shtml</guid></item>
<item><title>Microsoft Updates, February 2009</title><description>Secuobs.com : 2009-02-06 18:08:59 - FSecure Antivirus Research Weblog -  Next Tuesday's Microsoft Update notification has been released Thedetails are in Microsoft's Security Bulletin Advance NotificationCritical fixes for Internet Explorer 7 and Exchange are coming:Microsoft's Advance Bulletin FebXP, Server 2003, Vista, and Server 2008 are among the affectedoperating systemsLooks like network administrators should begin scheduling some timenext week for testing and deploymentOn 06/02/09 At 03:47 PM</description><link>http://www.secuobs.com/revue/news/59330.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/59330.shtml</guid></item>
<item><title>Downadup Sinkhole Numbers</title><description>Secuobs.com : 2009-02-05 16:50:47 - FSecure Antivirus Research Weblog -  Our Downadup sinkhole logged 19 million unique IP addresses yesterday;our last reported count was just over one millionNow, this doesn't necessarily reflect a growth in infections Oursinkhole has been monitoring a greater number of domains during thepast two weeks It's more sensitive and 19 million is the resultThe source of the IP addresses hasn't changed much China, Brazil andRussia still rank at the topHere's the top ten:Downadup, Top Ten Countries by IP CountYou can also review the complete listOn 05/02/09 At 02:32 PM</description><link>http://www.secuobs.com/revue/news/58841.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/58841.shtml</guid></item>
<item><title>How Much Latitude</title><description>Secuobs.com : 2009-02-05 15:37:39 - FSecure Antivirus Research Weblog -  A new mobile phone application, Google Latitude, was introducedyesterday It's an interesting new addition to Google MapsAccording to Google, with Latitude you can:• See where your friends are and what they are up to• Quickly contact them with SMS, IM, or a phone call• Maintain complete control over your privacyErr… Complete control True, only the friends that you add/allow areable to follow your movements and Latitude does have a manual overridefunction But complete control Perhaps it would be more accurate toclaim that there are strong controlsAssuming that you remember to use those controls of courseIf you want to maintain complete control over your privacy, youprobably won't be installing LatitudeGoogle LatitudeOn the other hand, if you're willing to share some of your personaldetails, Latitude could prove itself to be a really useful featureOn 05/02/09 At 01:20 PM</description><link>http://www.secuobs.com/revue/news/58777.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/58777.shtml</guid></item>
<item><title>Nine Million Dollar Bank Heist</title><description>Secuobs.com : 2009-02-04 17:33:38 - FSecure Antivirus Research Weblog -  How much money is lost due to online crimeWe're frequently asked about it It can be challenging to provide areally good answer…It's an underground economy, it's global, and no one organization canreally understand the true costs without extensive amounts of researchand cooperation And victims don't always for quite valid reasonswant to cooperateBut how much is itWired has an excellent post about a nine million dollar ATM hack bankjob, with video from FOX:Wired: Kevin Poulsen, Global ATM CaperIt probably says something that we're not surprised by stuff like thisanymoreAnd while nine million dollars is definitely a very impressive amountof cash to steal during a single coordinated attack, based on theconversations we've had with banking industry insiders, that'scertainly just the smallest tip of the overall icebergOn 04/02/09 At 03:04 PM</description><link>http://www.secuobs.com/revue/news/58305.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/58305.shtml</guid></item>
<item><title>Species 2009</title><description>Secuobs.com : 2009-02-04 15:03:23 - FSecure Antivirus Research Weblog -  Greetings from a snowy Netherlands where a bunch of us are at our annualSpecies conference, an event for our ISP partnersKeynote from Species 2009Partnering with ISPs to provide Security as a Service has been a corestrategy for several years and we now have over 180 partners workingwith us to secure end-users In fact, we have more ISP partners inEurope, US and Asia than any other antivirus vendor This means thatwe have millions of users around the world running our software whohave never heard of F-Secure — and that's fine with usCustomizable User InterfaceAt this year's conference we have participants from over 22 differentcountries and it's been a great event where we've been able to, notonly share our views and ideas on what F-Secure and our products willlook like in the future; but the partners can share their experienceson everything from customer support and marketing, to implementationof new servicesOn 04/02/09 At 10:58 AM</description><link>http://www.secuobs.com/revue/news/58255.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/58255.shtml</guid></item>
<item><title>Sample Analysis System</title><description>Secuobs.com : 2009-02-03 18:01:04 - FSecure Antivirus Research Weblog -  Our Lab Development LabDev team has produced a new service that wewant to tell you aboutIt's called F-Secure Sample Analysis SystemThe system has undergone testing for several weeks and now we wouldlike you, our readers, to try it out It is a significant upgrade fromour current sample submission formCreate an account: Sample Analysis System accounts display details andinformation regarding your submissions Regular users will now be ableto track their submission results as a groupHere's an example of the My Samples view:Sample Analysis System, My Samples ViewSo, with this new system, you'll know what we know And when we knowmore, your account view will be updated automaticallyAnonymous submissions have been simplified, but there is currently a5MB limit on file size Registered accounts have less restrictedupload limitsThe system is designed to be flexible, and has additional featuresthat are available based on the user's needs and requirements We'lldiscuss more on that later…For now, please try it @: https://analysisf-securecomOn 03/02/09 At 03:47 PM</description><link>http://www.secuobs.com/revue/news/57876.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/57876.shtml</guid></item>
<item><title>Google is Broken</title><description>Secuobs.com : 2009-01-31 18:14:34 - FSecure Antivirus Research Weblog -  Right now, Google does not workResults for any search will be labeled as "This site may harm yourcomputer"In which case, Google won't allow you to access any of the searchresults via links as they're using info from StopBadwareorg to warnpeople away from harmful sitesGoogle BrokenWe don't remember such big worldwide outage of Google since a variantof Mydoom caused an indirect DDoS on it in 2004Oh wellBack to Alta VistaUpdated to add: Google came back to life 15:26 GMTUpdated to add: The StopBadware Blog has some additional informationOn 31/01/09 At 03:15 PM</description><link>http://www.secuobs.com/revue/news/57122.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/57122.shtml</guid></item>
<item><title>Our Blog is 5IVE Years Old, Happy Birthday to You</title><description>Secuobs.com : 2009-01-30 15:34:53 - FSecure Antivirus Research Weblog -  This blog's first entry was posted five years ago, January 30, 2004:Our first postOurs was the first antivirus blog in the industry and many others havesince followed our leadThe members of the Security Lab have always been early adopters oftechnology, and blogging has proved itself to be an importantconnection to our customers, partners, and the security community atlarge Thank you for reading and participatingSo, it's OUR "birthday", but it's YOU that can receive a present Howabout some of our laptop stickersThe first 100 people to leave us a comment here will get a setCheersOn 30/01/09 At 12:57 PM</description><link>http://www.secuobs.com/revue/news/56758.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/56758.shtml</guid></item>
<item><title>Preemptive Downadup Blocklist for February</title><description>Secuobs.com : 2009-01-30 13:03:09 - FSecure Antivirus Research Weblog -  Blog reader iautran requested us to post a new Downadup preemptiveblocklistThank you for the reminder sir, it's been a busy month…Toni has generated a new list of potential domains for the month ofFebruary The list reflects what we think to be the most commonvariant of Downadup in-the-wild Click the image below to view thelistDownadup Domain Blocklist Feb 2009On 30/01/09 At 10:33 AM</description><link>http://www.secuobs.com/revue/news/56733.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/56733.shtml</guid></item>
<item><title>Remotely Exploitable Hole in Bluetooth</title><description>Secuobs.com : 2009-01-29 19:54:11 - FSecure Antivirus Research Weblog -  Alberto Moreno Tablado has found an interesting vulnerability in theWindows Mobile 6 OBEX FTP service, in the Microsoft Bluetooth stackIt's used by devices such as the HTC TyTn II and other similarsmartphones Devices that use other Widcomm or other non-MicrosoftBluetooth stacks are not affectedThe vulnerability is a classical path traversal vulnerability, whichmeans that an attacker can send path information along with the filename to the Windows Mobile device, and thus cause the file to becopied anywhere in device file systemIn theory this might be really serious vulnerability, as attackercould copy something to a location where the application wouldautomatically start at next boot But in practice, the vulnerabilityis of limited use for an attacker as it would require the victim topair his phone, before OBEX FTP can be used So this vulnerability hasquite low exploitabilityThe same basic caution that protects against other Bluetooth attacksalso protects from this oneDo not form Bluetooth pairs with devices that you do not fully trustAnd if you are not using Bluetooth file sharing, do disable it fromthe Bluetooth FTP settings in Bluetooth connection settingsWindows Mobile Bluetooth FTPOn 29/01/09 At 02:43 PM</description><link>http://www.secuobs.com/revue/news/56458.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/56458.shtml</guid></item>
<item><title>Do Android Phones Dream of Electric Sheep</title><description>Secuobs.com : 2009-01-28 19:05:11 - FSecure Antivirus Research Weblog - Android logoWe've been following news during the past few days regardinga possible rogue Android application, available in the Android marketA number of forum discussions were focusing on an application calledMemoryUp which is produced by eMobiStudio emobistudiocom Therewere reports of Android phones deleting information, sending spam tocontact lists, and installing adware All of this was supposedly doneto the phone without permission by MemoryUpWe did a bit of digging into the issue but couldn't verify any of theclaims made about MemoryUp's maliciousness We studied a couple of theversions that are readily available and none of them attempted tobreak anything on the Android platform nor did they attempt to dothings other than what the application promises to doGoogle has investigated, and their spokeswoman stated: "In theversions we tested, MemoryUp cannot perform any of the maliciousthings it is reported to have done"See Wired: Android App No Malware, Says GoogleWe agree with Google There's nothing malicious about MemoryUpIf you think you're one of those that has actually seen theapplication misbehave, please send us a commentGoogle AdroidAdditional links:Android app destroying G1 users' memoryRogue Android App Allegedly Destroying G1 Memory, Installing AdwareMemoryUp wreaks havoc on Android phonesOn 28/01/09 At 03:38 PM</description><link>http://www.secuobs.com/revue/news/56012.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/56012.shtml</guid></item>
<item><title>Is it Time for Internetpol</title><description>Secuobs.com : 2009-01-27 22:25:24 - FSecure Antivirus Research Weblog -  Our recent sinkhole research on Downadup has generated some debate inour CommentsSome readers are asking why we don't take it upon ourselves todisinfect the worms that visit our sinkholesToni has provided a good answer to that questionPutting it briefly, we are not the law, and as a publicly tradedcompany bound by laws, we simply cannot act as vigilantesWhy Well, a few of the infected IP addresses that we have logged areregistered to an army or two, a navy, and few governments We arecertain that unauthorized use will most definitely not be appreciatedHowever, we do NOT sit idly byEach and every day we collect data from our analysis and forward it torelevant law enforcement authorities, ISPs, partners, various CERTs,et ceteraThey are the ones that have the legal authority to take action withintheir territoriesStill — it seems that people want a champion that can make big commanddecisions Perhaps it would be a good time to bring up the idea ofInternetpol again Mikko briefly mentioned it on December 12th, it wasthe topic of his AVAR 2008 keynote The idea was also mentioned in ourthird quarter security summaryDo you want an organization with international legal authority to actagainst Internet threatsYou do Then perhaps it's time for some kind of Internetpol…InterpolOn 27/01/09 At 08:49 PM</description><link>http://www.secuobs.com/revue/news/55691.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/55691.shtml</guid></item>
<item><title>Where is Downadup</title><description>Secuobs.com : 2009-01-23 19:46:50 - FSecure Antivirus Research Weblog - Downadup infections appear to have peaked during the weekAs time passes, the number of estimated Downadup infections becomesmore problematic to calculate as we are monitoring a varying number ofdomains Re-infections may also be inflating the count In any case,today seems better than the day before and we think that growth ofDownadup has been curbed Disinfection of the worm remains achallengeSo let's look at Thursday's IP count, where are the infectedcomputersOur sinkhole logged just over one million unique IP addressesyesterday This is compared to 350,000 last Friday Remember, theremay be any number of computers sitting behind a single IP addressChina, Russia, and Brazil have the highest IP count Combined, theyaccount for nearly 41 percent of the totalOnly a bit over 1 percent came from the United States…Here's the breakdown by country:Number of IPsRegistered Country of the IP1388Sweden1394Peru1555Yemen1669Canada1723Hong Kong1803Czech Republic1906Sri Lanka2178Croatia2179Austria2249Moldova2486Lithuania2839Ecuador2971Slovakia3127Bosnia and Herzegovina3269Jordan3451Vietnam4310Portugal4423Saudi Arabia4666Spain4895Japan5572Iran5763Republic of Macedonia6758Poland6822Hungary6900Bulgaria7857United Kingdom7973Pakistan8088France8328Turkey10249Venezuela10527Mexico10683EU11779United States 117%12629Kazakhstan14785Colombia15697Germany16154Taiwan16924Philippines17285Malaysia17312Thailand17322Chile21263Indonesia36070Argentina39156Romania39712Italy39731South Korea63939Ukraine64035India120197Brazil 119%139934Russia 139%152016China 151%1005941On 23/01/09 At 05:34 PM</description><link>http://www.secuobs.com/revue/news/54544.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/54544.shtml</guid></item>
<item><title>ISTP and F-Downadup Removal Tool</title><description>Secuobs.com : 2009-01-20 17:11:21 - FSecure Antivirus Research Weblog -  Our F-Downadup Removal Tool was updated on the 19thIf you are working to disinfect the Downadup worm from your network,check that you have the most recent version of F-Downadup You cancompare the modification dates from our FTP serverOur Worm:W32/Downadupgen description is a good index of DownadupinfoLinks have been added recently, such as one to Microsoft's KnowledgeBase Article 962007 The KB article include numerous details on manualdisinfection The Microsoft MSRT application was updated to scan forDownadup alias Conficker this monthOne important note: Downadup disables Automatic Updates, so updatedversions of MSRT will need to be downloaded manually, it will not beautomatically installed on infected machinesThe team members developing F-Downadup have also updated our scanningand removal engines Internet Security 2009 and Client Security 8among others utilize updateable engine architectureAnd that brings us to…Internet Security Technology PreviewTomi, from our Customer Involvement Team, would like to point out thatthe latest version of ISTP 910 build 129 was released on January14th ISTP receives signature and engine updates from our beta updatechannel So, the ISTP engine architecture will use our latest removalengine, which was released to beta todayIf you would like to try ISTP, you'll find more information from hereISTP feedback enrolls users into prize giveawaysWe recently received another batch of our very popular laptopstickers, so as a bonus, we'll pass along a stack to TomiOn 20/01/09 At 03:14 PM</description><link>http://www.secuobs.com/revue/news/53178.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/53178.shtml</guid></item>
<item><title>Obama's Inaugural DDoS Event Scheduled for 11:30 EST</title><description>Secuobs.com : 2009-01-20 15:02:37 - FSecure Antivirus Research Weblog - What is a Distributed Denial of Service DDoS eventIt is different than a DDoS "attack" Some, such as Arbor Networks,have dubbed it "The Tiger Effect"June 2008's US Open Golf Championship 19-hole playoff resulted inmassive traffic spikes from those seeking real-time scores andstreaming video feedsDDoS events are a massive focus of interest that sometimes take placeon the Internet They are something that greatly exceeds normaldemand, and the result is a Denial of Service effect Web servers justcan't meet demand when focus points occur and the timing is not soeasily predictedAnd even though DDoS events lack malicious intent, the results canoften be just as painful as an attack…Here's a recent example from two weeks ago:Shepard Fairey's Obama PosterNorth Carolina's unemployment rate is at its highest level in 25years, and a delugeof out-of-work people has strained the state's jobless systems to thebreaking pointState websites have crashed twice in the past month as people applyor renewtheir employment benefitsListen to the full story at NPRThat brings us to today and Barack Obama's Inauguration as thePresident of the USAWe expect that The Obama Effect may well dwarf that of Tiger WoodsWorldwide interest in Obama's inauguration is very high and livestreaming Web video is more readily available than ever beforeThere will be very interesting data produced today And this timeresearchers should be ready to observe the effect—US Mobile operators are also preparing for today's demand on theirWashington DC networksOn 20/01/09 At 12:45 PM</description><link>http://www.secuobs.com/revue/news/53082.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/53082.shtml</guid></item>
<item><title>Social Engineering Autoplay and Windows 7</title><description>Secuobs.com : 2009-01-19 18:29:23 - FSecure Antivirus Research Weblog -  The Downadup worm utilizes autoruninf files to spread via removabledevices such as USB drivesOur January 7th post, When is AUTORUNINF really an AUTORUNINF,provided analysis The autoruninf uses some tricks, such as variablesize, to help avoid detectionBojan Zdrnja at SANS Internet Storm Center recently posted someadditional analysis Downadup attempts a social engineering trick inWindows VistaDownadup's autoruninf file uses an action keyword and icon extractedfrom shell32dll to produce the following:Windows Vista, Open folder to view filesThe category is "Install or run program" but the text and icon are for"Open folder to view files"The first option will run Downadup, not good The second "general"option is the choice that will safely open the USB driveBeing curious, we tried this autoruninf with Windows 7:Windows 7, Downadup AutoruninfAnd the results for Windows 7 were the same as Vista's:Windows 7, Open Folder to View FilesDownadup attempts to disguise the installation option as an openfolder actionWe would click on 7's "Send Feedback" link, but the lab's Windows 7system is not connected to the Internet It's being used to test ourClient Security 8 application Client Security 8 and InternetSecurity 2009 can generically detect Downadup's autorun file asWorm:W32/DownaduprunAWorm:w32/DownaduprunAOn 19/01/09 At 04:44 PM</description><link>http://www.secuobs.com/revue/news/52772.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/52772.shtml</guid></item>
<item><title>Watch out for fake Obama sites</title><description>Secuobs.com : 2009-01-17 12:33:19 - FSecure Antivirus Research Weblog -  In the middle of all the Downadup-related activity see below, we'reseeing spam runs trying to cash in with the inauguration of BarackObama next weekMails like this have been spammed around the world:superobamamailIf you follow the link not recommended, you get to a site like this:superobamaAll the links point to a file called speechexe, which is a Waledecmalware variantThe site is hosted via fast fluxing all over the worldsuperobamaThere's plenty of different domains, too We've seen at least:wwwgreatobamaguidecomwwwsuperobamaonlinecomwwwgreatobamaonlinecomstoresuperobamadirectcomstoregreatobamaguidecomOn 17/01/09 At 10:08 AM</description><link>http://www.secuobs.com/revue/news/52480.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/52480.shtml</guid></item>
<item><title>Calculating the Size of the Downadup Outbreak</title><description>Secuobs.com : 2009-01-16 16:47:39 - FSecure Antivirus Research Weblog -  The number of Downadup infections are skyrocketing based on ourcalculations From an estimated 24 million infected machines to over89 million during the last four days That's just amazingWe've received a number of queries on just how exactly we're producingour estimatesThere's been interest from Internet operators, CERTs, and fellowantivirus researchersThere's also been several posts to our blog comments, doubting ournumbers Here's some sample quotes:8976038Kitschen: Yeah right As if you could "estimate" infectionto a precision of 10 machines This is just PRYour "special techniques" are at best able to estimate 100000wastedimage: This number looks like total guessworkHow did you go from ~100k ip's to 24 million boxesI realize *some* might be nat but how many Did you just assume each ip really was some arbitrary numberof vulnerable machines or somethingSpreading FUD like this is incredibly unprofessionalwastedimage: So your trusting the counter built into the bot itselfwhich may be rigged to indicate larger numbers to entice spammersto pay more for its use Sure that sounds like a solid planSo let us explain how we are generating the numbersThere are several different variants of Downadup out there Thealgorithm to create the domain names vary a bit between the variantsWe've been tracking the variant we believe to be most common Itcreates 250 possible domains each day We've registered some selecteddomains out of this pool and are monitoring the connections being madeto themThis is what the connections look like:Downaup logsAs you can see, this is a standard httpd log showing the IP address ofthe machines connecting our domains, the time stamp the queries inthe above image all come on the same second: 18:16:05 yesterday,actual query "GET /searchq=29 HTTP/10", and the User-Agent of themachineThese are the raw connections coming to our sinkhole systems Millionsof them every day When we sort these connections by source, we seehundreds of thousands of unique IP addresses every day over 350,000todayIt's hard to tell the real number of infections since NAT boxes andproxies tend to spoil the fun and Downadup doesn't include a uniqueidentifier within the User-Agent string for us to seeWe first tried to count unique User-Agent headers per IP address, butthe results weren't very good as in a standardized corporate network,most machines have identical User-AgentsSo, with a little digging we discovered that in the /search/q=NUMBERquery, the number is not random It's basically a global variable inthe code, getting incremented thread-safely throughInterlockedIncrement every time the malware has successfullyexploited a machine via MS08-067 The incrementation is done in thehttpd thread of the malware, after it has exploited a machinesuccessfullySo this number tells us how many other computers this machine hasexploited since it was last restarted In the above log you can seeone of the machines has exploited 116 computersDo bear in mind that this number only shows how many machines gotinfected via the MS08-067 exploit Downadup spreads at least as muchvia network shares and USB sticksWe wrote a program that parses the logs, extracting the highest "q"value for the IP/User-Agent pairs These are then added together toget our figures As you can see now, they are very conservativeAnd they are showing more than 8 million infected machines right nowThe situation with Downadup is not getting better It's getting worseOn 16/01/09 At 01:59 PM</description><link>http://www.secuobs.com/revue/news/52221.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/52221.shtml</guid></item>
<item><title>Preemptive Blocklist and More Downadup Numbers</title><description>Secuobs.com : 2009-01-16 14:24:53 - FSecure Antivirus Research Weblog -  We have an update on the number of infected computersToday's calculation is a total of 8,976,038 infections worldwide and353,495 unique IP addressesThat's a quite a big difference compared to our last number — therewill be a follow up post coming soon to explain the methodology—Our post last Monday provided a preemptive Downadup domain blocklistA new list of potential domains for January 17th to the 31st is nowavailable Click the image below to view the listDownadup Domain Blocklist 17th to 31stOn 16/01/09 At 12:08 PM</description><link>http://www.secuobs.com/revue/news/52192.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/52192.shtml</guid></item>
<item><title>Hilton not the hotel Compromised</title><description>Secuobs.com : 2009-01-15 16:33:36 - FSecure Antivirus Research Weblog -  We've been reading reports regarding the compromise of Paris Hilton,err… parishiltoncomA malicious IFrame was inserted on the site sometime last week TheIFrame content directed visitors to install "updated" softwareRemember, if you must update an application to take advantage of a newfeature, it's always advisable to go directly to the vendor's websitein order to install it Most of our regular readers already know thisof courseThe offending IFrame appears to have been removed at this time Youcan read more about the compromise here and/or hereThe infection of "Paris Hilton" highlights a popular trend amongonline attackers Hacking a trusted name worthy site can yield manynew victims It's worth the investment of time So there really is nosuch thing as a trusted site 100% of the timeWould you like to spend the night at the Paris HiltonParis Hilton, ParisOn 15/01/09 At 02:50 PM</description><link>http://www.secuobs.com/revue/news/51697.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/51697.shtml</guid></item>
<item><title>More Than One Million New Infections</title><description>Secuobs.com : 2009-01-14 16:37:25 - FSecure Antivirus Research Weblog -  Our previous post calculated the worldwide Downadup infection count atapproximatively 24 million computersToni Koivunen from our Response Team has once again used his specialtechniques to update his previous resultsToday's total infection count is an estimated 3,521,230 infectionsworldwideThat's over one million new infections since yesterday and we stillconsider this to be a conservative estimateOn 14/01/09 At 02:33 PM</description><link>http://www.secuobs.com/revue/news/51272.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/51272.shtml</guid></item>
<item><title>How Big is Downadup Very Big</title><description>Secuobs.com : 2009-01-13 14:39:09 - FSecure Antivirus Research Weblog - Downadup worms attempt to call homeThey do this by trying to connect to various Web addresses And if theworm finds an active Web server at one of these domains, it willdownload and run a particular executable — thus giving the malwaregang a free hand to do whatever they want with all of the infectedmachinesThey could build a large botnet for example The framework is inplaceNormally malware uses only one or maybe a handful of websites Suchsites are generally easy to locate and shut downThen there is Downadup It uses a complicated algorithm which changesdaily and is based on timestamps from public websites such asGooglecom and Baiducom With this algorithm, the worm generates manypossible domain names every dayHundreds of names such as: qimkwaify ws, mphtfrxs net, gxjofpj ws,imctaef cc, and hcweu orgThis makes it impossible and/or impractical for us good guys to shutthem all down — most of them are never registered in the first placeHowever, the bad guys only need to predetermine one possible domainfor tomorrow, register it, and set up a website — and they then gainaccess to all of the infected machines Pretty cleverBut we can play this game as wellSo we've determined the possible domains and have registered some ofthem for ourselvesWhich means the infected machines will also connect to usWe could attempt to manipulate the infected machines But of course wewon't In fact, we won't be doing anything at all to them – not evendisinfect them – as that could be seen as "unauthorized use" That isillegal, at least in many jurisdictions Doing something withoutbeing asked is also a very large ethical question… Look but don'ttouch is the golden ruleBut this looking and listening does gain us a unique visibility insideand we can see just how large the number of infected machines isRight now, we're seeing hundreds of thousands of unique IP addressesconnecting to the domains we've registeredA very large part of that traffic is coming from corporate networks,through firewalls, proxies, and NAT routers Meaning that one uniqueIP address that we see could very well be 10,000 infected workstationsin real lifeToni Koivunen from our Respone Team has used some additional tricks tocome up with an estimate on just how many infected machines therereally areToni's final count is: 2,395,963 infections worldwide This figure isconservative; the real number is certainly higherIt would make for one big badass botnetAnd where in the world are these infections We're glad you asked Weresolved the IPs to countries and here are the resultsNumber of IPsRegistered country of the IP38,277China34,814Brazil24,526Russia16,497India14,767Ukraine13,115Italy11,675Argentina11,117Korea8,861Romania6,166Indonesia5,882Chile5,531Taiwan5,162Malaysia4,392Germany4,261Philippines3,958United States3,719Colombia3,307Spain3191Thailand2,871Kazakhstan2,828Venezuela2,685Mexico2,518Europe resolved to EU2,337France1,901Bulgaria1,789United Kingdom1,655Pakistan1,636Turkey1,544Saudi Arabia1,399Hungary1,389Iran1,272Poland1,259Macedonia1,193Japan1,052Portugal1,029VietnamThese are the raw unique IPs; you could think of this as China having38,277 infected companies, not personsOn 13/01/09 At 11:21 AM</description><link>http://www.secuobs.com/revue/news/50928.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/50928.shtml</guid></item>
<item><title>Preemptive Downadup Domain Blocklist, Jan 13-16</title><description>Secuobs.com : 2009-01-12 16:55:12 - FSecure Antivirus Research Weblog -  Downadup variants use algorithmically determined URLs to report back tothe bad guysReverse engineering the worm's code provides us with the method topredict which domains may be used in the futureToday's preemptive blocklist includes an additional 1,000 URLs thatWILL BE used by the Downadup from the 13th to the 16thNetwork administrators can use this list as a preventive measureClick the image below to view the list:Downadup Domain Blocklist for January 13-16On 12/01/09 At 03:06 PM</description><link>http://www.secuobs.com/revue/news/50611.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/50611.shtml</guid></item>
<item><title>Downadup Blocklist</title><description>Secuobs.com : 2009-01-09 16:02:25 - FSecure Antivirus Research Weblog -  Our post on Tuesday included a list of domains used by the DownadupwormToday's list includes 1,500 additional sites used by the worm Clickthe image below to download:Downadup Domain BlocklistOn 09/01/09 At 02:41 PM</description><link>http://www.secuobs.com/revue/news/50156.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/50156.shtml</guid></item>
<item><title>MS08-067 Worm, Downadup/Conflicker</title><description>Secuobs.com : 2009-01-08 22:35:50 - FSecure Antivirus Research Weblog - Tuesday's post refers to Downadup/Conflicker as an MS08-067 worm variantWhat do we mean by thatDownadup and other such similar worms exploit a vulnerability in theWindows Server serviceServer Service Vulnerability — CVE-2008-4250The vulnerability is detailed by October 23rd's Microsoft SecurityBulletin MS08-067There are a few important notes to be made about this particularSecurity Bulletin…First — It was an out-of-band updateMS08-067 Oct23 Out-of-BandSecond — It was given an "Exploitability Index Assessment" of "1 –Consistent exploit code likely"That kind of speaks for itself, doesn't itThird — It allows for Remote Code Execution, in numerous versions ofWindows particularly critical for 2000, XP, and Server 2003MS08-067 Remote Code ExecutionAll of these combined factors equals something quite serious thatshould be patched as soon as possible If you are having difficultieswith Automatic Updates, the bulletin links to manual downloadsSecurity Update for Windows XPSecurity Update for Windows Server 2003It's always a good idea to be ready for out-of-band updates You cansubscribe to Microsoft Security Notifications hereDownadup has "old school" worm functionality no user interactionrequired, the likes of which we haven't really seen for a while nowIt also knows some current tricks; it's a worm that spreads via theInternet, local area networks, and removable media While it doesn'tseem to be gaining very much traction on the Internet, it's rapidlyspreading once it's inside of local area networks that aren't patchedIf you're a network administrator, a proactive scan for vulnerablemachines may be well worth your timeMake sure that your antivirus software is up-to-date and disableAutoplay *and* Autorun functionality if possible Downadup spreadsitself via Network Shares and Removable Storage Devices such as USBmemory Downadup also attempts to brute-force account passwords somake sure that your administrator accounts are secure and use strictpasswordsAlright, that covers prevention — what about those of you that haveinfected computers within your networksRemember, Downadup is a network worm You must clean all of thecomputers within your network or else you risk reinfections Serversfirst, then workstations Disinfect, then use the manual Microsoftupdate to patch, then manually update your antivirus, then do a fullsystem scan for all filesIf you use one of our Anti-Virus products, you can download our manualupdates from hereDownadup uses random extensions for some of its components so you'llneed to scan all file types on the system once you have disinfectedWe have a disinfection tool that may assist in your efforts It can bedownload from here It's a command line utility and you shouldcarefully review the included readmetxt fileOur DownadupAL description provides additional detailsOn 08/01/09 At 07:49 PM</description><link>http://www.secuobs.com/revue/news/49890.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/49890.shtml</guid></item>
<item><title>When is AUTORUNINF really an AUTORUNINF</title><description>Secuobs.com : 2009-01-07 16:24:57 - FSecure Antivirus Research Weblog -  In addition to everything else, Downadup is also a USB wormUSB worms work by creating a file called AUTORUNINF on the root ofUSB drives These INF files then use Autorun or Autoplay not the samething to execute themselves either when the stick is inserted, ormore commonly, when the user double-clicks on the USB drive icon fromMy Computer Windows ExplorerRemovable USB DriveSuch malicious AUTORUNINF files are easy to spot Here's what theytypically look like:Typical AutorunINFBut Downadup does not create files such as this What it drops on USBdrives are AUTORUNINF files that look like this:Downadup AutorunINFSo, that's binary garbage Won't work RightLook closerDownadup AutorunINFThe noteworthy text is found somewhere around the middle of this 90kBfile At the bottom of the screenshot See itOpen=RUNDLL32EXE RECYCLERjwgvsqvmx…which would execute a DLL called jwgvsqvmx from a hidden folder onthe USB driveThe rest of the binary junk are comments and will be ignored byWindows And of course, the file size and amount of binary junk isdifferent every timeNice trickOn 07/01/09 At 12:52 PM</description><link>http://www.secuobs.com/revue/news/49360.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/49360.shtml</guid></item>
<item><title>MS08-067 worms</title><description>Secuobs.com : 2009-01-06 22:00:40 - FSecure Antivirus Research Weblog -  Over the last days, we've received reports of corporate networks gettinginfected with various variants of MS08-067 worms These are mostlyDownadup/Conficker variantsThe malware uses server-side polymorphism and ACL modification to makenetwork disinfection particularily difficult A sign of infection isthat user accounts gets locked out in the Active Directory domain asthe worm tries to crack user's passwords using a built-in dictionaryWhen it fails it leads to those accounts being lockedWe have detailed information about the malware functionality in ourdescriptionWe also have a separate tool available to assist in disinfecting Thetool is available from hereWe also recommend system administrators to block access to web sitesused by the malware The sites keep changing, but the current domainsto block are:64701933gwkizcbfxscomaifzigcvcnrexvnvucomnynhjlgtccjjlpshzvcnqjspgcwsidmctcntfxrunhcomjorgpnettxjonwsbqbhosagnetenukaxdshcomuwgpfmbbcnsiaeowinforhhlojswqhgorghsmyiodabyinfovvjwyinfowalbkceobizpwkaowshyenncnbsjhicnntennetwucomsnrbfmuuwsxorbhjumcnvygsszouzyinforgfyqusccyurkdgrrcccnpzjcoqbizpwokmxqxuwszmtndgbfccbotvmepccomtidvgkjnetorfwvrhincnqlidexmcmccztnzqtcomfacoxfzytddnetmupmibyvgorgbzjcgpgndinfoxijykokyoinfojzrjojinfolkiafdoccrqphujhgnbizomrzgdpqgxbizrwrzsnhcniwkellccchbrcojkbcomnildslfdcomvnpzbfnetlyuzbxwumznetklzizccrksarzfopoccmcyrrcchmxxvpazpakorgtdyilbmptiinfoicyjfmsvsndcnmmaytjkonettfqexhqwwswvzwincnvuexwsccmsnbfhucomrphrtdyccdszhntorgycimzccpoerbbizjxxneevycchejktcixccvsdgrolowwskqzhlbhainfotmfyucompgrhporgubimwzracjnetjfrcwccwkheaqvorgpkxnjnjucnsptfgbgnccwrqeibnetnhhaoraajbizsxfgsrxvhyinfobezmvgydcomnwhdkaymlinwsxnylnnetqrgyuwsmcqloqacinfoaszerjbinforuhciwyzorgdehkjdjfgpbiznhqfsbizxjuokaiccsqkjycccwnozdfdporgrjcvhhcbizkhukycqborgxxshfasvxrorgkqhflzjnetacucwbuqbizjxbouorgleywvorglhakjmpujbizzehbfqiinfoouclprommforgcsyotypmrcckzndzkgcomcvjpvghacorgjywlngsklzorgjcgldecminfociliytjvjccnvfiqgaccinfoucpqawxbizoqdlfkjkmcomzozzjezacnixpnkncfcnvbbiyjbizvopqjdgnetsldjmhdllorgufoeaxhhwsvuubkeazywcctaeiwxgmgwsfcrovorgurujtbizmbdpldxcnruiixxeftbizxzarbvminfoaowdpspvubwskinlrfaccnaewfhtcnetgxbbmwbizadglruiubizdjlbhgvzxcomfvtmsxbrxsnetaypmyrxinfonuggporgaqpbxhtuoorgyzpvyovrlenetsqejcjgkslobizbuqidpgcwssyxdgozzcomfslvhnetwamwosbmawwsrozfggavcwdorgzjwyamwjginforbooqduoccuywkvinfopyxzpvbjcnqogarydescciwikvfcombddsxxnvbizwjtwuygwswsrgncomdzyeosjuovcommarojdxwnwscbewjjkqwsvfbhmkzibizkuwoiwbtjinfovwtrsctainfoWe'll update this list as neededOn 06/01/09 At 06:15 PM</description><link>http://www.secuobs.com/revue/news/49112.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/49112.shtml</guid></item>
<item><title>Flashy botnet is Flashy</title><description>Secuobs.com : 2009-01-05 19:29:05 - FSecure Antivirus Research Weblog -  We did some co-operation recently with a company called ClarifiedNetworks Some of you might remember them as the guys who did the*wow* visualization of the Kaminsky DNS hole for his Black HatpresentationSo we collected some botnet data and asked them to visualize itclarified networksThe end result is a quite nice animation You can get more info andthe actual end result from their blog at wwwclarifiednetworkscomOn 05/01/09 At 04:56 PM</description><link>http://www.secuobs.com/revue/news/48711.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/48711.shtml</guid></item>
<item><title>Video - SMS Exploit Effects</title><description>Secuobs.com : 2008-12-31 15:32:26 - FSecure Antivirus Research Weblog -  Our post from yesterday mentioned a video demonstration coming soonIt's online now and you can find it from our YouTube ChannelThe video highlights the symptoms experienced on exploited phones; itdoesn't show how to perform the attack The attacking phone has beenkept off screen It isn't difficult to find the CCC video at thispointCurse of Silence EffectsThe "Curse of Silence" was disclosed to several telecommunicationsoperators about seven weeks ago and we were brought into the loop afew weeks later The timing has been a real pain in the neck for thoseof us in the lab We'd rather be researching something else orenjoying a relaxed holiday than dealing with a detection for anexploit that will mostly likely be used by jealous boyfriendsStill, it is a safe bet that the Curse will be used to harass people,so support personnel should know what to look forOn 31/12/08 At 12:09 PM</description><link>http://www.secuobs.com/revue/news/47650.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/47650.shtml</guid></item>
<item><title>Malware Analysis Course Rides Again</title><description>Secuobs.com : 2008-12-31 15:32:26 - FSecure Antivirus Research Weblog -  Those of you that missed the Helsinki University of Technology's malwareanalysis and anti-malware technologies course in the Spring of 2008,have the possibility to participate during Spring 2009The course curriculum is pretty much the same as it was last year andso are most of the lecturers One notable addition will be more focuson Windows kernel malware Kimmo Kasslin will be lecturing on thetopic and there will be some homework fun on it as wellHomework FunPlease check out the course pages, slides, and assignments from Spring2008 to get an idea of what the course is all aboutCourse web pages for 2009 are already available but still incomplete;students can already enlist, thoughOn 31/12/08 At 12:10 PM</description><link>http://www.secuobs.com/revue/news/47649.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/47649.shtml</guid></item>
<item><title>Your Friendster Contacts Are Belong To Us</title><description>Secuobs.com : 2008-12-31 09:24:52 - FSecure Antivirus Research Weblog -  Addendum to our earlier post, Fake Friendster and Facebook Sites withOne IP Address:A lot of Friendster users have been complaining about receiving lotsof invitations to view a fake video from their contacts whopresumably would not usually send malicious content to their friendsHere is an example of such an invite, from a known contact:friendster_msgSo how are the spammers getting access to the contacts listsWell, as we mentioned in our earlier post, a phishing site that mimicsthe real Friendster site steals the user's e-mail address and passwordinformation Once the bad guys have that information, they can use itto access the account, and then use the account to start spammingmalicious links to all contacts Simple and effective, really Usersreceiving these messages from a contact are more likely to disregardcaution and click on itThis particular link leads the user to the legitimate domain,filesmyoperacom, and a file named videogif But wait  to check thecontents of the file, try using view-source in Firefox As it turnsout, users will be redirected to a malicious, fake video siteviewsourceOf course, the new site will prompt users to 'update the video player'with a certain file in order to view the videosetupThe file the site would like you to download is cunningly named'setupexe', but we detected it as networmwin32koobfacedd - a wormthat, incidentally, also spreads on social interaction websitesAs usual, beware of clicking any URL links, whether from a known orunknown sender Don't forget to change your Friendster accountpassword regularly to avoid abuseOn 31/12/08 At 06:51 AM</description><link>http://www.secuobs.com/revue/news/47612.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/47612.shtml</guid></item>
<item><title>Curse of Silence, a Symbian S60 SMS Exploit</title><description>Secuobs.com : 2008-12-30 19:37:20 - FSecure Antivirus Research Weblog -  An easily reproducible SMS exploit was disclosed and demonstrated todayat the 25th Chaos Communication Congress 25C3 The exploit iseffective against a wide range of Symbian S60 smartphones and willeffectively prohibit victims from receiving SMS messagesThe Chaos Communication Congress is a popular event amonginternational "hacker" enthusiasts It has been organized by the ChaosComputer Club since 1984, has been held in Berlin since 1998 andtypically takes place between December 27th and 30thToday's Security Nightmares 2009 presentation included a demonstrationof the Curse of Silence exploit, which was researched by Tobias Engelof the CCCAccording to Engel's research, the exploit affects the messagingcomponents of Nokia Series 60 phone versions 26, 28, 30, and 31Our own tests determined that Sony Ericsson UiQ devices are vulnerableas wellVersions 26, 28, 30, and 31 are also better known as S60 2ndEdition, Feature Pack 2; S60 2nd Edition, Feature Pack 3; S60 3rdEdition initial release; and S60 3rd Edition, Feature Pack 1respectivelyThat's a lot of numbers…S60com has a handy comparison view of many Series 60 phonesS60com, Compare DevicesAccording to Engel's research, the vulnerable phones fall into twocamps: S60 versions 26/30 2FP2/3 and versions 28/31 2FP3/3FP1That's still too many numbers, so let's just select two phonesNokia 6680 — 2nd Edition, Feature Pack 2Nokia N95 — 3rd Edition, Feature Pack 1The vulnerability is very simple to exploit via an SMS message Nospecial software is required and the message can be drafted from alarge number of phones The message just needs to be formatted in aparticular way We will not provide exact details hereWhat happens when a vulnerable phone receives the exploit messageExample 1 — on the older 6680 nothing happens Nothing at all… Thefirst exploit message is enough to crash the SMS messaging service Itis a completely silent attack and there are no hints of troublepresented to the victim The phone will simply stop receiving SMS aswell as MMS messagesClick here to see some of the phones that fall into the 6680 example'scategoryExample 2 — on the newer N95, nothing will happen until severalmessages have been sent by the attacker Then, once the critical limithas been reached, the phone will prompt an alert: "Not enough memoryto receive messages Delete some data first"SMS Curse ErrorThe attack messages will not be visible from the Inbox, and deletingpreviously received messages will not resolve the problemThere will also be one additional notification on the N95 A blinkingenvelope, indicating that the Inbox is full, appears in the upperright-hand corner of the displayTurning the N95 off and on again may return some limitedfunctionality, but that functionality is very fragile One multi-partmessage was enough to completely disable our test phone's SMS/MMSservice, at which point even cycling the power did not helpClick here to see some of the phones that fall into the N95 example'scategoryExploited phones will remain otherwise completely functional; only theSMS/MMS messaging is affected Practically speaking, this also meansno SMS notifications of voicemail, though the phone log will displaythe missed callA firmware fix is not yet available Performing a hard-reset is theonly manual solution And backing up the phone also backs up theexploit messages and the damaged messaging serviceShameless self-promotion begins:However — Engel practiced reasonable disclosure, which is why we havehad time to test the exploit ourselves before today's CCCdemonstration Our Mobile Security solution will detect the exploitand can repair affected phonesThe exploit is detected as Exploit:SymbOS/SMSCurse and Mobile Securityis capable of repairing exploited phones so that it will not lose anymessages Messages that have been sent while the messaging service isjammed will of course be lostHopefully this exploit will not be widely used We don't see much of aprofit motive after all Still, there were thousands of participantsat this year's CCC and many of them saw the demonstration As easy asit is to utilize the Curse of Silence, someone will surely try thisfor harassment…A free seven day trial of Mobile Security can be directly download tophones from hereWe will have a video demonstration available soonOn 30/12/08 At 03:34 PM</description><link>http://www.secuobs.com/revue/news/47336.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/47336.shtml</guid></item>
<item><title>Safe to Open</title><description>Secuobs.com : 2008-12-24 13:40:13 - FSecure Antivirus Research Weblog -  A few weeks ago, I received the following Instant Message:Safe to OpenWas it some kind of clever social engineering IM-wormNope — It was just Mikko sharing a link that he found from AlexEckelberryGlobal Energy Connection PDFEven though I was sure, I still called out across the room to confirmthat he had sent the link…That's just one of the habits that's reinforced when working in theResponse LabStay safe during the holidays See you next weekSigning off,SeanOn 24/12/08 At 12:13 PM</description><link>http://www.secuobs.com/revue/news/46275.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/46275.shtml</guid></item>
<item><title>websupportacercomtw</title><description>Secuobs.com : 2008-12-19 18:55:22 - FSecure Antivirus Research Weblog -  Our File Analysis Team — they collect non-malicious files — came acrossan interesting case yesterday Aslamo was researching available driverdownloads from Acer's Taiwanese tw site and discovered somethingout of placeThe list for WindowsXP Desktop drivers…websupportacercomtw…included "ncexe" That's a bit suspicious, don't you thinkwebsupportacercomtwThat's probably a "driver" that you don't want to downloadThe team e-mailed Acer and the issue seems to have been resolvedpromptlySo, even those that aren't looking for trouble may still find it StayvigilantOn 19/12/08 At 05:14 PM</description><link>http://www.secuobs.com/revue/news/45427.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/45427.shtml</guid></item>
<item><title>Your Computer Is Under Investigation</title><description>Secuobs.com : 2008-12-19 09:20:34 - FSecure Antivirus Research Weblog -  A mildly amusing sample came in todayThe sample itself is a very simple Visual Basic application Whenexecuted, the unlucky user is shown this message:FBI_WARNINGClicking the 'Warning' button will play an alarm sound over thecomputer's speakers Clicking 'FBI' will close the formThe sample also launched the default browser and opened the pagewwwfbigov - the legitimate FBI websiteOther than that, it seems to have no malicious intent and may havebeen a prankSeems rather old-fashioned, considering today's more monetized threatlandscapeA Response team post by - KMOn 19/12/08 At 07:03 AM</description><link>http://www.secuobs.com/revue/news/45313.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/45313.shtml</guid></item>
<item><title>iSpy an iPhone Spy</title><description>Secuobs.com : 2008-12-18 18:08:08 - FSecure Antivirus Research Weblog -  There are some new developments on the mobile security front Spy toolapplications are now available for Apple's iPhone Symbian and WindowsMobile spy tools have been around from two and a half to almost threeyearsNow it would seem that it's finally the iPhone's turnOne of the two spy vendors appears to require a jailbroken iPhoneThey also claim to be the "first and only" spy software If only thatwere true Their application can be installed on 3G model iPhonesMobile spy dot com…and on December 21st, a second option will be available Thisvendor's comparison chart claims quality and features over costsNote that their application lets you "secertely" spyFlexi spy dot comIt doesn't seem entirely sure based their promotional promises, but itappears that vendor number two may be able to jailbreak, install, andthen un-jailbreak the iPhone during its installation It can beinstalled on older iPhones as well as currentWe wonder what Apple's position on this will be; will they do anythingabout it What do you thinkWe won't bother providing these spy vendors with a backlink to ourweblog, so if you want to see more, use the addresses in the imagebelowThe first link in the set is a blog, not a vendorLinks to iPhone spy tool informationOn 18/12/08 At 03:44 PM</description><link>http://www.secuobs.com/revue/news/45114.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/45114.shtml</guid></item>
<item><title>Firefox and Opera Patches</title><description>Secuobs.com : 2008-12-18 15:20:02 - FSecure Antivirus Research Weblog -  Just in case you were distracted by yesterday's Internet Explorerupdate; there are some other browser updates that you should beapplyingBoth Mozilla Firefox and Opera have vulnerabilities that should bepatchedFirefox 305 Security UpdatesSee our Vulnerability Reports for Firefox 3x and Firefox 2xOpera 963 Security UpdatesOur report for Opera 9x is located hereOn 18/12/08 At 01:07 PM</description><link>http://www.secuobs.com/revue/news/45082.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/45082.shtml</guid></item>
<item><title>Update: Patch for Internet Explorer Security Hole</title><description>Secuobs.com : 2008-12-18 04:32:24 - FSecure Antivirus Research Weblog -  A quick update to our earlier post about the recent criticalvulnerability MS08-078 in all available versions of InternetExplorer - Microsoft has released a patch for the vulnerability Moreinformation, including the patch, can be found hereThere have been a number of reports citing thousands of websites bothintentionally malicious and legitimate but compromised exploitingthis vulnerability You can read more at BBC and The RegisterAll users are strongly encouraged to download and apply the patchwithout delayOn 18/12/08 At 02:22 AM</description><link>http://www.secuobs.com/revue/news/44935.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/44935.shtml</guid></item>
<item><title>Exploit Shield  F-Secure's Solution to Zero-Day Exploits</title><description>Secuobs.com : 2008-12-17 13:20:24 - FSecure Antivirus Research Weblog -  Our previous post highlighted a recently disclosed vulnerability whichexists in Microsoft Internet Explorer… and that there are currentlywebsites hosting exploits targeting the vulnerability Today ourVulnerability Response team would like to offer you our Security Labs'solution, which is now publicly available for downloadWe call it Exploit ShieldExploit Shield protects against exploits both responsively andproactively It has both shields and generic heuristics that monitorfor and block suspected malicious activity It logs attack attempts;and will also report suspicious URLs to our Real-time ProtectionNetwork1 New shields are delivered via our automatic update channelserversExploit Shield Technology PreviewVulnerability Shields offer "Patch-equivalent protection" OurVulnerability Analysts, primarily based in Kuala Lumpur, publishvulnerability advisories and detections used by our Health Check2service The Vulnerability team then uses the analysis to createexploit shields The shields utilize either a hotpatch or else willdisable the vulnerable ActiveX pluginExploit Shield Technology PreviewThis is what shield details look like:Exploit Shield Beta, CVE-2008-3008The Proactive Measures currently block suspected malicious activity inInternet Explorer and Mozilla Firefox This component of the betamonitors for heuristic behavioral techniques common to many types ofexploits We've tested the proactive component against a couple ofmalicious sites targeting the vulnerability, and the attacks have beensuccessfully blockedExploit Shield Technology PreviewAs noted above, Exploit Shield has the option to report maliciouswebsites that are blockedExploit Shield Technology PreviewWhat do we do with the reported URL The Response Lab will use it torespond faster We have "HoneyMonkey" like systems to collect theexploit samples Thus we'll have a greater ability to collectionexploits and add signature detections to protect all of our customersExploit Shield users will help contribute to everyone's protectionwhile remaining protectedYou can download a wmv video by Patrik demonstrating Exploit Shield inactionExploit Shield wmv—You will find the download link on our Labs siteDownload Exploit Shield—Our Vulnerability Response team has been working very hard in the lastfew day to make this beta release ready at this time Remember, it'sstill in beta, and you can help them by testing and by providingfeedback A big thank you is due to all those involved—Footnote1 The current version of our DeepGuard Technology utilizescloud-based networking lookups to our Real-time Protection NetworkWe'll cover that in a future weblog postFootnote2 Try Health Check It's free and assists in updating andpatching third-party applicationsOn 17/12/08 At 10:45 AM</description><link>http://www.secuobs.com/revue/news/44630.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/44630.shtml</guid></item>
<item><title>Extremely Dangerous Internet Explorer Security Hole - Beware</title><description>Secuobs.com : 2008-12-15 20:17:01 - FSecure Antivirus Research Weblog -  Zero-day exploits are actively targeting an unpatched Internet ExplorervulnerabilityMicrosoft recently expanded their Security Advisory 961051 to includeall versions of Internet Explorer The vulnerability was originallythought to only affect IE7As you can see, it's now a very long list of related software:Microsoft Security Advisory 961051There are a number of perhaps cumbersome workarounds that mayprovide some mitigation:Microsoft Security Advisory 961051More bad news, SQL Injection attacks are being used to hack legitimatewebsites in order to host exploits, turning trusted sites intomalicious exploit hostsYou can read additional details at Security Fix and eWeekcomhttp://wwweweekcom/c/a/Security/Hackers-Compromise-Legit-Web-Sites-to-Target-Microsoft-IE-Flaw/kc=rssSomeone in the eWeek advertising department is trying to tell yousomething…and a tip of the hat goes to Camillo for providing the subject lineto this postOn 15/12/08 At 06:21 PM</description><link>http://www.secuobs.com/revue/news/43995.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/43995.shtml</guid></item>
<item><title>Fake Friendster and Facebook Sites with One IP Address</title><description>Secuobs.com : 2008-12-15 18:34:13 - FSecure Antivirus Research Weblog -  One IP address that provides twice the fakery…We spotted this fake Friendster website at http://friendtercomThe website steals the e-mail address and password information enteredby an unsuspecting visitor who arrives at this page thinking it's theactual Friendster siteFake FriendsterLinks to the fake website are propagating through malicious commentssent from the compromised accounts of friends in the Friendsternetwork The links are also included in the infected friend's profileCommentsInterestingly, on further analysis, the domainhttp://friendtercom also pointed to a fake Facebook page as itsmain pageFake FacebookThis fake domain was registered recently in China, and is hosted inChina as well We traced the IP address and noticed that it washosting quite a few other fake social networking websites — MySpace,Friendster, Facebook, et ceteraregisterIP addressWebSecurity team post by — Chu KianOn 15/12/08 At 02:20 AM</description><link>http://www.secuobs.com/revue/news/43958.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/43958.shtml</guid></item>
<item><title>Greetings from India</title><description>Secuobs.com : 2008-12-12 16:40:52 - FSecure Antivirus Research Weblog - AVAR 2008The AVAR 2008 conference is in full swing in New Delhi Almost allantivirus companies are represented in this global conferenceRecent terror attacks in India were fresh in memory and indeed theconference was started with one minute of silence to honor thevictimsAVAR 2008The terror attacks had an indirect toll on the conference as well, asseven speakers had canceled their trips The organizers were happy toget replacement talks from the brave Peter Szor Symantec, Andrew LeeK7 and Randy Abrams ESETMy keynote presentation covered the initiative for "Internetpol" — theneed to get better global IT law enforcement in action to really focuson getting online criminals behind the barsAVAR 2008Other notable presentations included "Exploiting anti-virtualizationtechniques" by Andrew Lee Many viruses won't execute if they detectthe presence of a virtual machine Andrew was using this featureagainst the malware itself by installing a fake VM on a real machineAs an end result, many types of malware wouldn't run at all NeatEugene Kaspersky also did an excellent overview of the worseningsituation He highlighted how criminals are using business modelsexcept here, instead of B2B business-to-business we're now seeingC2C criminal-to-criminal modelsAVAR 2008And Vincent Weafer from Symantec presented their latest research intounderground IRC networks and how large scale this is Over a year,they monitored over 60,000 distinct advertisers on these boards,selling malware, botnets and stolen informationAnother interesting presentation was by Swanand Dattaram Shinde fromIndia's Quick Heal He spoke about how the local terrorist groups usethe Internet for communication, recruiting and propaganda, and even tomake online threats No cases of real cyber-terrorism thoughAnd here's something you don't see everyday All electricity got shutdown twice during the second day of the conference Andrew Lee was onstage and he did not miss a beat He simply raised volume and carriedon…AVAR 2008Signing off,MikkoAVAR 2008On 12/12/08 At 01:48 PM</description><link>http://www.secuobs.com/revue/news/43347.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/43347.shtml</guid></item>
<item><title>Video - Data Security Summary</title><description>Secuobs.com : 2008-12-11 19:15:45 - FSecure Antivirus Research Weblog -  The video that we mentioned last week is now onlineThere's a link from the security summary, or else you can check it outfrom the lab's YouTube channel2008Q4H2 Security Summary VideoOn 11/12/08 At 05:16 PM</description><link>http://www.secuobs.com/revue/news/43039.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/43039.shtml</guid></item>
<item><title>Faking It</title><description>Secuobs.com : 2008-12-11 07:12:19 - FSecure Antivirus Research Weblog -  Got a copy of the 'Homeview Installer' today which looked harmlessenoughDuring installation, it runs the user through a series of proceduresthat look pretty routineagentfln fake installation screen 1If I try to cancel the installation at the first screen, it is niceenough to ask me if I really want to continueagentfln quit installation screenAnd if I change my mind and install it anywayagentfln fake installation screen 2agentfln fake installation screen 4agentfln fake installation screen 3But when installation is "completed successfully", it turns outHomeview isn't really installedagentfln no homeviewThere's just an uninstaller file that, true enough, really does removethe Homeview folder from the Program Files, and the Homeview-relatedregistry entriesSo it really just came and went without doing anything Oh wait, itinstalled Trojan:W32/DNSChangerARNF and none of my clicks evenmatteredCrafty little thingJust a reminder - do be wary of executing any file you download orreceive via e-mail, if you are unsure of its trustworthinessResponse team post by - ChristineOn 11/12/08 At 05:20 AM</description><link>http://www.secuobs.com/revue/news/42883.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/42883.shtml</guid></item>
<item><title>Bank of America's new banking site</title><description>Secuobs.com : 2008-12-09 20:37:06 - FSecure Antivirus Research Weblog -  As Christine mentioned earlier today in her post about Koobface and howit uses fake Flash players to trick people into downloading malware, asmart move is to only download Adobe Flash player from AdobeHere's another example of a social engineering scam, this time using anew Bank of America online banking systemboa_flash_mailjpgClicking on the link leads to a fake BoA page with a "video" showingwhat the new site looks like To view you have to download the updatedFlash playerboa_flash_videojpgIf you run the fake Flash player it downloads another file frompremierinetcom which in turn is a trojan that hides itself with arootkit, steals confidential information and posts it to a server inUkraineAgain, we recommend that you only download Adobe Flash Player fromAdobe's website hereOn 09/12/08 At 07:22 PM</description><link>http://www.secuobs.com/revue/news/42259.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/42259.shtml</guid></item>
<item><title>You've Got Comment</title><description>Secuobs.com : 2008-12-09 06:41:35 - FSecure Antivirus Research Weblog -  There's nothing like social networking sites to keep people connectedand worms propagating - like the all new and improvedNet-Worm:W32/KoobfaceCZ A little infection equals a little commentin someone's little site somewhereThis version for Koobface has the following sites in its body:- bebocom- myyearbookcom- blackplanetcom- facebookcom- myspacecom- friendstercomIt also has its own site, where it can query for more data, updatesand of course the comments that it posts to the targeted websites Thesite hosts plenty of comments and of course the corresponding linksfor the worm to use Here are some of them:- COMMENT: Are you sure this is your first acting experience- LINK:http://finditandcom/go/bephp0e9c60ch=d41d8cd98f00b204e9800998ecf8427e- COMMENT: is it u there- LINK:http://findit12com/go/bephpe7883ch7=d41d8cd98f00b204e9800998ecf8427e- COMMENT: impressive i'm sure it's you on this video- LINK:http://find-notallcom/go/bephp70dd4ch=d41d8cd98f00b204e9800998ecf8427e- COMMENT: How can anyone get so busted by a spy camera- LINK:http://find-allherecom/go/bephp50ch=d41d8cd98f00b204e9800998ecf8427e- COMMENT: You're the whole show i'm admired with you- LINK:http://freemarksearchcom/go/bephpch23=d41d8cd98f00b204e9800998ecf8427eHere is a sample comment that made it to a user site:koob blogAnd of course when the user clicks the link, out comes Youtubefake youtubeEr, I mean YuoTube momentary dyslexia there my badkoob titleWhich of course contains an 'update' for your Adobe Flash player,because the site is so sure that your player is outdated Don't arguewith its superior wisdomAnd when you execute that file in your system well, let's just sayyou've gone and summoned his older brother - Net-Worm:W32/KoobfaceCY- A Response team post by ChristineOn 09/12/08 At 02:19 AM</description><link>http://www.secuobs.com/revue/news/42013.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/42013.shtml</guid></item>
<item><title>Macs are totally secure out of the box</title><description>Secuobs.com : 2008-12-05 19:17:44 - FSecure Antivirus Research Weblog -  There has been a lot of talk link 1, link 2, link 3 during the lastfew days about a support article that seemingly appeared on the Applewebsite In the article, Apple advised users to install an anti-virussoftware to make sure their computers are safe The reason it tookpeople by surprise is that Apple has previously said that Mac usersdoesn't have to worry about antivirus softwareTurns out the support article was from 2007 and now has been pulledfrom the Apple website Apple also issued a statement saying that thearticle was outdated and that Macs really don't need antivirus becausethey are so secure Quoting a spokesperson from Apple:"The Mac is designed with built-in technologies that provideprotection against malicious software and security threats, right outof the box"That's just sillyWhile there is much less malware out there for Macs, they definitelyexist, and Mac users are as likely to fall victim for traditionalemail based phishing attacks as PC users Not to mention all thesecurity vulnerabilities that Apple has fixed this year thatfortunately weren't exploited but easily could have beenApple SecurityThe fact is that yes, Mac user are much less likely to get hit bymalware but that doesn't mean that they can be totally careless andignore potential threats all together Use common sense and if theywant to be extra safe, do install an antivirus softwareOn 05/12/08 At 05:11 PM</description><link>http://www.secuobs.com/revue/news/40986.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/40986.shtml</guid></item>
<item><title>Creating MS08-067 Exploits</title><description>Secuobs.com : 2008-12-05 13:28:31 - FSecure Antivirus Research Weblog -  We are seeing fair amounts of infections using the MS08-067vulnerabilityMost of these belong to a worm family that goes by the names Downadup,Conficker, or KidoWe have also discovered several Chinese tools that are being used bythe underground to create files that exploit this vulnerabilityBelow you'll see some screenshots of such toolsms08-067ms08-067ms08-067ms08-067On 05/12/08 At 11:10 AM</description><link>http://www.secuobs.com/revue/news/40929.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/40929.shtml</guid></item>
<item><title>Data Security Summary - July to December 2008</title><description>Secuobs.com : 2008-12-03 17:40:17 - FSecure Antivirus Research Weblog -  Our end-of-year data security wrap-up is online at f-securecom/2008Threat Summary H2-2008The video will follow next weekOn 03/12/08 At 03:45 PM</description><link>http://www.secuobs.com/revue/news/40327.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/40327.shtml</guid></item>
<item><title>Pimp My Backup</title><description>Secuobs.com : 2008-12-01 16:25:35 - FSecure Antivirus Research Weblog -  One of our project teams has a beta that they'd like to advertise"How many photos do you have on your computer Documents E-mailmessages, letters, and receipts of your online purchases What happensto your files if — when — your hard drive fails"We currently have an active beta piloting program for F-Secure OnlineBackup 11 and would like you to try it out However, act quickly — aswe have only a limited number of beta licenses to give For moreinformation and to join this project, please click hereSetup:F-Secure Online Backup Service for ConsumersOn 01/12/08 At 02:36 PM</description><link>http://www.secuobs.com/revue/news/39653.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/39653.shtml</guid></item>
<item><title>Spam on the Rise</title><description>Secuobs.com : 2008-11-28 16:36:47 - FSecure Antivirus Research Weblog -  Weblog reader Steve H forwarded this BBC News story to us, "Spam onrise after brief reprieve"If you remember, the shutdown of McColo two weeks ago resulted in asignificant drop in spam No one expected it to last foreverAnd a drop in spam is relative we suppose A good deal of spam isstill just as annoying as a great deal of spam, isn't itSpam SubjectsOn 28/11/08 At 03:06 PM</description><link>http://www.secuobs.com/revue/news/39175.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/39175.shtml</guid></item>
<item><title>VirusRemover2008 The Nerve</title><description>Secuobs.com : 2008-11-27 08:08:56 - FSecure Antivirus Research Weblog -  The site powerfulvirusremover2008com has been reported to have beenusing dodgy practices in order to push their product, and really,what's new Yet another rogue antispyware on the looseFunny thing is though, it even has specific websites for differentcountries, so that they can cater to specific audiences Here are someof the sites that they host for different countries:jppowerfulvirusremover2008comespowerfulvirusremover2008comnlpowerfulvirusremover2008comfrpowerfulvirusremover2008comdkpowerfulvirusremover2008comitpowerfulvirusremover2008comdepowerfulvirusremover2008comnopowerfulvirusremover2008comAnd what's the difference for each Oh, just the way they say "If youaren't redirected automatically, please click here" and the languageof the webpage that strongbillingcom the third party site it uses toprocess payments uses on its page when the user wants to purchase theprogram It gives the user a certain comfort level and the illusionthat he actually understands what he is buyingOK, so let's say the user by some stroke of luckless chance, orcourtesy of a trojan downloader ends up with the demo installer ofRogue:W32/VirusRemover2008C on their hands and it runsEnter the End User License Agreement EULA Who really reads the EULAnowadays All we do is click, click, click, then done Then we wonderwhy our computers are sputtering malware every day And if wecomplain, the product pushers will just say, "You've been warned" Butwhere "In paragraph 100 of the EULA"But really, the EULA actually does contain some of the indecenciesthat they do to your system They have some nerve putting it there:Exhibit A:rogue_w32_virusremover2008c_eula crap 2What kind of products You mean my valid AVExhibit B:rogue_w32_virusremover2008c_eula crap 2Lack of viruses Oh, right You mean those malware your product toldme existed in my system - but actually don'tWhoa People should really start reading some of these stuff It'spretty scary what they put thereOK, say that, through the universal law of click-click-click, youskipped the EULA and happily installed the rogue antispywaresinceit's the usual senseless stuff reallyit'll do this:1 Scans your system:rogue_w32_virusremover2008c_scanning2 Tells you you have an infection:rogue_w32_virusremover2008c_doneAnd of course it comes with a link to buy the stuff, yada-yadaDon't bother checking the files listed, they don't exist in yoursystem And you know where they exist In a text file that theydropped into the system A very readable text filetext_fileHow insulting is thatResponse team post by  ChristineOn 27/11/08 At 02:59 AM</description><link>http://www.secuobs.com/revue/news/38984.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/38984.shtml</guid></item>
<item><title>Being too helpful</title><description>Secuobs.com : 2008-11-25 20:12:21 - FSecure Antivirus Research Weblog -  Here's a screenshot of a site:gIt's a phishing site using Google AdWords as the lureWhat it really tries to do is to steal your Google AdWords accountusername and passwordAnd your credit card numberNow look again Look at what the browser is offeringgNo thanks, I'd rather not save my password for this site, thank youvery muchOn 25/11/08 At 06:41 PM</description><link>http://www.secuobs.com/revue/news/38626.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/38626.shtml</guid></item>
<item><title>Search-and-Destroy</title><description>Secuobs.com : 2008-11-21 13:51:27 - FSecure Antivirus Research Weblog -  Some rogue antivirus applications are overtly malicious XP Antivirus2008 and XP Antivirus 2009 have numerous affiliates utilizing rootkitsand plenty of other nasty techniques in order to get themselvesinstalled and purchased They're a real pain in the… neckAs an interesting aside – XP Antivirus 2008 and XP Antivirus 2009 areactually produced by two different gangs Variants of one sometimesattempt to uninstall and disable the otherThen there are some "rogues" that are just kind of sad… we're temptedto call them lame-ware rather than scarewareLast week, someone calling himself "Mirando" submitted this to ourmoderated comment system:Search-and-Destroy AntispywareWhat are the odds that such a comment, promoting a dubiousapplication, will be approved by us Not likelyThis is how the search-and-destroy com site appears:Search-and-DestroyThe site just uses a simple Flash graphic for basic animation; thereare no fake "scans" that attempt to scare the visitor It's all veryquiet, relying perhaps on its nameThis application, search-and-destroy, should not of course be confusedwith Spybot Search et Destroy, a well known and respected antispywareapplicationWe downloaded and tested the Search-and-Destroy AntispywareapplicationFirst it prompted a warning that there were zero risksStartup RiskThen we performed the scan and there were 159 "problems" discoveredAll 159 were not fixable in the trial versionScan FinishedWithin the "malicious threats" that were discovered, were invalidshortcutsThreat DetailsTrue, the links were invalid, but that's hardly a threatSo we uninstalled the application, and it left behind a registry key:After UninstallTypical The scan warned us about invalid shorts, and then leavesbehind an invalid registry keyMirando has posted to other forums as wellCommentsBased on the IP address used when posting to our comments system,Mirando lives in New Delhi, India We suspect that he's young and thatthese posts are early attempts at making money via an affiliateprogramWe hope that he'll consider quiting while he's ahead, and doesn't moveon to the hard-roguesOn 21/11/08 At 12:07 PM</description><link>http://www.secuobs.com/revue/news/37690.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/37690.shtml</guid></item>
<item><title>German, Finnish and Swedish</title><description>Secuobs.com : 2008-11-20 12:20:33 - FSecure Antivirus Research Weblog -  German, Finnish and Swedish versions of E:VOLUTION are now available onour YouTube ChannelYouTube FSLabsOn 19/11/08 At 06:12 AM</description><link>http://www.secuobs.com/revue/news/37294.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/37294.shtml</guid></item>
<item><title>Video - E:VOLUTION en francais</title><description>Secuobs.com : 2008-11-18 18:38:04 - FSecure Antivirus Research Weblog -  Bonjour By popular demand, E:VOLUTION has been translated into severaldifferent languages You can now find the French version via ourYouTube ChannelE:VOLUTION — French language versionwwwyoutubecom/fslabs E:volutionAdditional language versions will soon followOn 18/11/08 At 03:36 PM</description><link>http://www.secuobs.com/revue/news/36909.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/36909.shtml</guid></item>
<item><title>VirusResponse Lab 2009</title><description>Secuobs.com : 2008-11-17 18:36:24 - FSecure Antivirus Research Weblog -  Last Friday, we came across a rogue application, VirusResponse Lab 2009,that used a fake 404 page as part of its social engineering attackMany rogue affiliate sites will use script to generate animated"online scans" and then attempt to convince the visitor intodownloading the rogue installer file via a pop-up dialog404dnswebsite com took a different approach Rather than producing afake scan and prompting for a download, it instead simply hosted afake 404 error message:FraudToolWin32Agenteh 404dnswebsitecomIf the victim fell for the trick, they would have downloaded what wedetect as FraudToolWin32AgentehAs you can see from the screenshot above, the fraud page is not at alldynamic Even though we opened the page with Firefox on a Linux basedsystem, the page displays the text "Internet Explorer"The 404dnswebsite account is now suspendedFraudToolWin32AgentehOn 17/11/08 At 04:24 PM</description><link>http://www.secuobs.com/revue/news/36501.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/36501.shtml</guid></item>
<item><title>Termination of EstDomains, 24 November 2008</title><description>Secuobs.com : 2008-11-13 18:30:00 - FSecure Antivirus Research Weblog -  The termination of ICANN-accredited registrar EstDomains is to go ahead,effective 24 November 2008There are approximately 281,000 domain names managed by EstDomains,many of which shouldn't be touched with a ten-foot pollICANN is now seeking expressions of interest from registrars toreceive a bulk transfer of those domains Anyone interestedSee our past posts here, here, and here for additional detailsOn 13/11/08 At 03:54 PM</description><link>http://www.secuobs.com/revue/news/35821.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/35821.shtml</guid></item>
<item><title>Web Trail</title><description>Secuobs.com : 2008-11-13 18:30:00 - FSecure Antivirus Research Weblog -  One of our development teams would like you to try their betaapplication, Web TrailThey want feedback before moving on to the RTM versionF-Secure Web TrailF-Secure Web TrailYou can download it from hereOn 13/11/08 At 04:49 PM</description><link>http://www.secuobs.com/revue/news/35820.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/35820.shtml</guid></item>
<item><title>McColo Mole Wacked</title><description>Secuobs.com : 2008-11-13 16:35:25 - FSecure Antivirus Research Weblog -  Kudos to Brian Krebs, whose excellent investigation produced some ratherdramatic resultsWhat's the story McColo Corp — major source of spam — was knockedoffline earlier this week And now there's a large decrease in theamount of spam being distributedSpamCopnet, SpamweekWhy is that Because McColo Corp was hosting a large number of spambot control and command servers Knocking them offline has left thespam bots temporarily without mastersUnfortunately the bots themselves are still out there, so the spamwill eventually returnYou can download a very detailed report on McColo from hostexploitcomhostexploitcom, McColo CyberCrimeOn 13/11/08 At 03:11 PM</description><link>http://www.secuobs.com/revue/news/35783.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/35783.shtml</guid></item>
<item><title>We're on Security Focus</title><description>Secuobs.com : 2008-11-12 16:08:04 - FSecure Antivirus Research Weblog -  This is just a short note to mention that Security Focus is nowsyndicating our weblog posts:Security Focus, Security BlogsYou can find them, and others, at http://wwwsecurityfocuscom/blogsCheersOn 12/11/08 At 02:34 PM</description><link>http://www.secuobs.com/revue/news/35511.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/35511.shtml</guid></item>
<item><title>Researchers Hack Storm Botnet for Economics Study</title><description>Secuobs.com : 2008-11-12 04:27:22 - FSecure Antivirus Research Weblog -  Interesting study on the economics of spamming reported today at BBC andThe Register The 'Spamalytics: An Empirical Analysis of SpamMarketing Conversion' report was authored by researchers from theUniversity of California, Berkeley and UC San DiegoSummary: the Storm botnet sends out spam leading interested parties totwo sites, a malware-infected site designed to expand the botnetitself and a pharmacy site promoting "male enhancement drugs" It hasbeen assumed that even a few people buying such products would beenough for spammers to make a huge profit, but few studies have beenperformed to investigateIn this study, the researchers hacked into the Storm botnet's commandand control system to modify a subset of spam already being sent outThe change redirected "any interested recipients to servers under theresearcher's control, rather than those belonging to the spammer",where the researchers could track sales attempts They could then usethe date to figure out how many actual sales the entire spam operationwould be likely to generateInteresting points from the analysis: even with a tiny conversion rateof "000001 per cent" from spam to sale, spammers can still net a fairbit of profit, but not as much as suggested Since the conversion rateis so minuscule however, spammers can be really pressured bycountermeasures that affect it, like anti-spam filters, blacklists andso onThe study also clearly documented the reasoning the researchers usedto handle the legal and ethical issues they faced, the key pointsbeing that they: 1 did not actively send out the spam itself, orcreate new spam; 2 none of the actions performed based on themethodology were "intrinsically objectionable"; and 3 where there waspotential for harm, they worked to "strictly reduce" it InterestingstuffOn 12/11/08 At 02:03 AM</description><link>http://www.secuobs.com/revue/news/35400.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/35400.shtml</guid></item>
<item><title>Antivirus Professional 2008</title><description>Secuobs.com : 2008-11-11 18:06:31 - FSecure Antivirus Research Weblog -  Yesterday's post, Stupid Rogue Trick, took a look atantivirus-online-scanner com and a rogue application called AntivirusProfessional 2008The antivirus-online-scanner site was using GeoIP Lookup to customizethe supposed threat that would be displayed to visitors If youvisited from Helsinki, Finland then the threat was called somethingsuch as Win32IRCBotHelsinkiA nasty trick for the unsuspecting…Taking a look today, we discovered that the site is offline Goodnews, such sites are often difficult to get shutdown So, who was theICANN RegistrarEstDomains You remember Case EstDomains from two weeks ago don't youAntivirus Online Scanner, ESTDomainsHmm The site was created back in JuneWell, at least it's suspended nowAntivirus Online Scanner, ESTDomains SuspendedOn 11/11/08 At 04:38 PM</description><link>http://www.secuobs.com/revue/news/35260.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/35260.shtml</guid></item>
<item><title>Stupid Rogue Trick</title><description>Secuobs.com : 2008-11-10 15:42:08 - FSecure Antivirus Research Weblog -  We came across a rogue today called Antivirus Professional 2008 thatuses GeoIP Lookup as part of its scare tacticsThis site uses Flash and script to create the effect of an onlinescan, that then attempts to push an installer at the visitorThe NoScript extension for Mozilla Firefox is an excellent way tomitigate against this kind of garbageAntivirus Professional 2008 HelsinkiBut here's the interesting thing…The "antivirus online scanner" site now uses the visitor's IP addressto customize the so-called threatOh no TrojanHelsinkiDownloader26 RightTrojanHelsinkiDownloader26Refreshing the page regenerates the supposed threatAntivirus Professional 2008 HelsinkiOn 10/11/08 At 02:02 PM</description><link>http://www.secuobs.com/revue/news/34994.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/34994.shtml</guid></item>
<item><title>There Goes WPA</title><description>Secuobs.com : 2008-11-10 10:19:14 - FSecure Antivirus Research Weblog -  It seems to be "bad news" season for WPA, as researchers keep findingways to crack it faster and fasterLast month, Elcomsoft found a way to use GPU computing architecture toboost a cracking utility's brute-force attack in order to breakthrough WPA encryption "100 times faster than with just a CPU"Now there's another, newly reported way to attack WPA's Temporal KeyIntegrity Protocol TKIP, which can crack an encrypted AddressResolution Protocol ARP packet in "less than 15 minutes" Moredetails are available at The RegisterOn 10/11/08 At 04:02 AM</description><link>http://www.secuobs.com/revue/news/34955.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/34955.shtml</guid></item>
<item><title>Critical Updates for Adobe</title><description>Secuobs.com : 2008-11-07 18:25:21 - FSecure Antivirus Research Weblog -  There is a critical security update available for Adobe Reader 8 andAcrobat 8 Here's the Security AdvisorySANS Internet Storm Center is reporting that the Adobe Readervulnerability is being exploited in the wildYou want to update as soon as possibleYou can read more about the vulnerability from Security Fix Read thisSC Magazine article for additional background material…and if you would like assistance with keeping your home Windowscomputer up to date, watch this:Health CheckThen try our Health Check applicationOn 07/11/08 At 04:18 PM</description><link>http://www.secuobs.com/revue/news/34133.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/34133.shtml</guid></item>
<item><title>We Hate WinDefender</title><description>Secuobs.com : 2008-11-06 16:08:02 - FSecure Antivirus Research Weblog -  Not Windows Defender — WinDefenderWinDefender 2009 is a supposed update of the WinDefender 2008 rogueVersion 2009 promises to Get rid of mailware nowWinDefender 2009Perhaps future versions will also get rid of "maleware"On 06/11/08 At 02:14 PM</description><link>http://www.secuobs.com/revue/news/33895.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/33895.shtml</guid></item>
<item><title>Obama and McCain Campaigns Hit with Targeted Attacks</title><description>Secuobs.com : 2008-11-06 09:18:06 - FSecure Antivirus Research Weblog - Newsweek CoverNewsweek has a breaking story about how both the Obama and McCaincampaign computer systems were hit by targeted attacks earlier thisyearAt the Obama headquarters in midsummer, technology experts detectedwhat they initially thought was a computer virus—a case of "phishing,"a form of hacking often employed to steal passwords or credit-cardnumbers But by the next day, both the FBI and the Secret Service cameto the campaign with an ominous warning: "You have a problem waybigger than what you understand," an agent told Obama's team "Youhave been compromised, and a serious amount of files have been loadedoff your system" The following day, Obama campaign chief DavidPlouffe heard from White House chief of staff Josh Bolten, to the sameeffect: "You have a real problem … and you have to deal with it" TheFeds told Obama's aides in late August that the McCain campaign'scomputer system had been similarly compromised A top McCain officialconfirmed to NEWSWEEK that the campaign's computer system had beenhacked and that the FBI had become involvedOfficials at the FBI and the White House told the Obama campaign thatthey believed a foreign entity or organization sought to gatherinformation on the evolution of both camps' policypositions—information that might be useful in negotiations with afuture administration The Feds assured the Obama team that it had notbeen hacked by its political opponents Obama technical experts laterspeculated that the hackers were Russian or ChineseWe have no further information on the case, but this does not reallysurprise us We've talked about similar attack techniques severaltimes in the pastOn 06/11/08 At 05:55 AM</description><link>http://www.secuobs.com/revue/news/33853.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/33853.shtml</guid></item>
<item><title>US Presidential malware</title><description>Secuobs.com : 2008-11-05 19:11:28 - FSecure Antivirus Research Weblog -  Not a big surprise at all that a spam run distributing malware talkingabout Obama being elected the new US President started this morningUS timeThe email looks like this:IMAGEThe link points to a website that looks like it contains a video andto view it the user has to download a new flash player,adobe_flash9exe MD5 47c86509a78dc1edb42f2964bea86306IMAGEWe detect this as Trojan-PSW:W32/PaprasCL which is a trojan thathides itself using a rootkit The trojan attempts to stealconfidential information from the computer and upload it to a serverin UkraineOn 05/11/08 At 05:22 PM</description><link>http://www.secuobs.com/revue/news/33712.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/33712.shtml</guid></item>
<item><title>Got Root</title><description>Secuobs.com : 2008-11-05 15:13:36 - FSecure Antivirus Research Weblog -  Mobile phone enthusiasts have discovered a method to gain Root access tothe T-Mobile G1 Android mobile deviceJailbreaking phones is a popular activity Many Apple iPhone ownerschoose to unlock their phones And we have also seen methods to unlockSymbian S60 phones so that one gains full access to the deviceNow there's a way to acquire full access to the G1 which usesGoogle's Android using the PTerminal application from the AndroidMarket The details were posted today on the xda-developers forumGoogle's Android is a largely open platform, so this may only be oflimited use only to those that for some reason really want to havecore access to the operating systemKind of like breaking out of a minimum security jail…On 05/11/08 At 01:43 PM</description><link>http://www.secuobs.com/revue/news/33642.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/33642.shtml</guid></item>
<item><title>Poker in the ZBot</title><description>Secuobs.com : 2008-11-05 12:52:37 - FSecure Antivirus Research Weblog -  Toni ran into an interesting ZBot sample yesterday During his analysis,he was surprised to discover a big bunch of poker sites among theconfiguration file's targetsTargeting gaming sites is new behavior for the ZBot gangWhy online poker Because the sites payout real money, and often lotsof it Additionally, if you have access to a compromised pokeraccount, you can use it to fix games and/or to launder funds Fundssuch as those stolen from bank accounts…Image Copyright PokerHuntingcomDoing a quick search on other ZBots variants seen in the last few daysyielded the encrypted configuration files from a number of CetCservers There were 22 of them online Decrypting the files led tosome additional discoveriesSpanish banks are being widely targeted for some reasonEven more surprising is that there are also many Russian ru sitesamong the targets Taking into consideration that ZBot is a Russiantrojan and many of the attackers are probably from Russia, this is abit unusual to see Typically skilled individuals tend not to operatein their own countries, in order to make prosecution against them moredifficultAfter seeing this list, it isn't too difficult to imagine how much indamages these guys might be responsible for annuallySee our Trojan-Spy:W32/ZBotXF description for a list of the onlinepoker sitesOn 05/11/08 At 10:41 AM</description><link>http://www.secuobs.com/revue/news/33625.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/33625.shtml</guid></item>
<item><title>Pirates and Internet Crime</title><description>Secuobs.com : 2008-11-04 17:37:16 - FSecure Antivirus Research Weblog -  One of the radio programs that I regularly listen to, via podcast, isMarketplace from American Public MediaLast Thursday's program included a very interesting segment about apirateNot a software pirate A Indonesian sea pirate"I want to stop It's dangerous out at sea I have a dream that oneday I will make so much money I can quit this work…, But until then,what else can I do" — Agus Laodi, PirateAPM MarketplaceBeing an Indonesian pirate involves boarding a cargo ship on a darkmoonless night, holding a large knife to the ship's captain, anddemanding money from the safe Agus Laodi doesn't like his job But hedoes it because it seems like an opportunity to him under thecircumstancesRead/listen to more hereAgus Laodi's situation reminded me of Ronit… He wants to be anInternet criminal"Hi, i Am Ronit I am In 9th grade And I Struggled A Lot In My Life ,But I Still Happy Bcoz My Family Is With Me , But Now i didn't haveany friend here , all people's are very bad , i really wana change mylife , please teach that how to hack cc's or shop admin's"…In other words, Ronit wants to "improve his life" by stealing creditcard account information And why not As long as he has Internetaccess, stealing CC's has got to beat many of the other possiblealternatives to which some people turnHere's a screenshot of the forum where Ronit posted his message:Hack CC's and Shop Admin's"When you have poor people next to rich people, you have piracy" TheInternet has no borders — so rich and poor exist together As Internetaccess expands to everyone, so too will Internet crime expand It's asocial issue as much as it is a technology issue Perhaps we need tobegin thinking of solutions for bothOur Q3 2008 Security Wrap-up, has more on crime and punishmentSigning off,SeanOn 04/11/08 At 03:38 PM</description><link>http://www.secuobs.com/revue/news/33420.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/33420.shtml</guid></item>
<item><title>Worm Exploiting MS08-067 in the Wild</title><description>Secuobs.com : 2008-11-03 15:19:25 - FSecure Antivirus Research Weblog -  Code building on the proof of concept binaries that were mentioned lastweek has moved into the wildWe've received the first reports of a worm capable of exploiting theMS08-067 vulnerability The exploit payload downloads a dropper thatwe detect as Trojan-DropperWin32AgentyhiThe dropped components include a kernel mode DDOS-bot that currentlyhas a selection of Chinese targets in its configurationThe worm component is detected as ExploitWin32MS08-067g and thekernel component as RootkitWin32KernelBotdgOn 03/11/08 At 01:34 PM</description><link>http://www.secuobs.com/revue/news/33135.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/33135.shtml</guid></item>
<item><title>Proof of Concept binaries for MS08-067 targeting english Windows OS's</title><description>Secuobs.com : 2008-10-31 14:16:16 - FSecure Antivirus Research Weblog -  We are seeing the first Proof of Concept binaries that target theMS08-067 vulnerability on the following English localized systems:Windows XP Service Pack 2Windows XP Service Pack 3Windows 2003 Service Pack 2The payload is encrypted as normal It's function is to add the guestaccount to the administrators group, thus allowing unlimited access tothe machine We detect the binaries as follows:Backdoor:W32/AgentDINBackdoor:W32/AgentDIOBackdoor:W32/AgentDIPWe'll continue to keep an eye on the eventsOn 31/10/08 At 12:53 PM</description><link>http://www.secuobs.com/revue/news/32762.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/32762.shtml</guid></item>
<item><title>Statements, reports, tracking numbers and tickets</title><description>Secuobs.com : 2008-10-30 17:58:51 - FSecure Antivirus Research Weblog -  Over the last 48 hours we've seen a huge increase in ZIP'd maliciousemail attachments being spammed The subjects have been:Your Tracking #xxxxxxxx where xxxxxxx is a random numberNew Ticket #xxxxx where xxxxx is a random numberAccounts Operations ReportYour Statement between 1/1/08 and 10/30/08IMAGEThe ZIP file typically contains a file that looks like a documentDOC but it is really an EXE, there's just a lot of whitespacesbetween DOC and EXEIMAGESome of these ZIP files are protected by a password which makes itmore likely to be allowed through an email server The password isalways in the email message so that a user can easily see itIMAGEUsing email attachments have made a comback in popularity amongstmalware writers during the last few months We detect this latestbatch as variants of the Worm:W32/Autorun familyOn 30/10/08 At 04:02 PM</description><link>http://www.secuobs.com/revue/news/32527.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/32527.shtml</guid></item>
<item><title>EstDomains Update</title><description>Secuobs.com : 2008-10-30 17:05:32 - FSecure Antivirus Research Weblog -  The EstDomains story continuesICANN received a response from EstDomains, and the termination hasbeen stayed You can read the details hereCommentsOn 30/10/08 At 03:15 PM</description><link>http://www.secuobs.com/revue/news/32520.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/32520.shtml</guid></item>
<item><title>Case EstDomains</title><description>Secuobs.com : 2008-10-29 16:33:24 - FSecure Antivirus Research Weblog -  EstDomains is a domain registrar operating from Estonia They've been onour map for years as they've been the largest registrar used by onlinecriminals for their domain name registration needsEstDomainsYesterday we received good newsICANN has finally pulled the plug on EstDomains, and is removingEstDomains from the list of ICANN-accredited registrarsSee below for the official letterEstDomains LetterEstDomains LetterWe probably first ran into EstDomains in 2005, when investigating theinfamous WMF vulnerability Initially the main site distributingmalicious WMF files, unionseekcom, was registered via this newEstonian registrarSince then, tens of thousands of malicious domains have beenregistered with EstDomains These include drive-by-download sites,botnet command-and-control servers, spammed domains and so onexample of a malicious domainMany of the recent fake antivirus tools as well as rogue codecs havebeen running via EstDomainsIn fact, EstDomains is among the largest registrars in the world andthey've registered over 280,000 domains Not all of them are bad, ofcourse But a big part of them areEstDomainsThe EstDomains operation is run by Mr Vladimir Tšaštšin, from theEstDomains office in downtown TartuLai, Tartu, Tartumaa 51005, EstoniaVladimir Tšaštšin aka "SCR" was sentenced earlier this year to sixmonths of jail for credit card fraud, money laundering, and relatedchargesimage copyright  Maris Ojasuu, ÄripäevMr Tšaštšin is also the CEO and largest owner of Rove Digital Rovegenerates revenues of several million Euros a year, as shown in thislisting of TOP Estonian IT companies by the Äripäev magazine:EstDomainsAnd EstDomains is just a small part of a larger picture, outlined hereby the researchers at HostexploitcomEstDomainsFor more on Atrivo and EstDomains, see this article at Security FixThank you ICANN, for doing the right thingOn 29/10/08 At 02:45 PM</description><link>http://www.secuobs.com/revue/news/32298.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/32298.shtml</guid></item>
<item><title>Here's what has been going on with MS08-067 since Friday</title><description>Secuobs.com : 2008-10-27 12:57:14 - FSecure Antivirus Research Weblog -  As most of you likely know, Microsoft released an out-of-band update onOctober 23, 2008 This usually indicates a worm-capable vulnerabilitywhen there are already in-the-wild exploits MS08-067 is very similarto MS06-040, the netapi vulnerability few years backWe've been working through the weekend, monitoring the situationaround this vulnerabilityF-Secure Helsinki Security LabWe did some time line analysis on Trojan-Spy:W32/Gimmiv which exploitsthe vulnerability As far as we can see, the first versions of Gimmivwere compiled around the 19th of September which is well over a monthago We also did code comparison between the variants, and mostly, thechanges in the variants are because the attackers were changingparameters instead of introducing new featuresAnalysis of the code inside the Gimmiv trojan clearly shows thatwhomever is behind it is an inexperienced coder Their code is riddledwith bugs in places where the author clearly didn't read his APIdocumentation closely enoughInterestingly also, Gimmiv has a self-destruction date On the earliersamples the date was set to October 5th 2008 23:59 local time, whichof course fails to work at this point, unless your computer's date isincorrectly set On the newest samples the self-destruction date isset to November 30th 2008 23:59 local time which gives the latestround of Gimmiv a month to spreadThe weekend was really quiet We received about a handful of Gimmivvariants and no other malware that uses the same vulnerability Thoughlast night, a new proof of concept for the exploit was released thattargets Chinese language Windows systems We are keeping a reallyclose eye on the situation since all it takes is a single working"universal" public exploit for things to go downhill pretty fastOn 27/10/08 At 08:59 AM</description><link>http://www.secuobs.com/revue/news/31782.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/31782.shtml</guid></item>
<item><title>Out-of-band patch from Microsoft</title><description>Secuobs.com : 2008-10-24 06:12:53 - FSecure Antivirus Research Weblog -  It doesn't happen very often, but when it does, it's for a good reasonYesterday, Microsoft released an out-of-band patch for a new, criticalvulnerability in WindowsThe patch MS08-067 fixes a remote procedure call RPC issue thatwould, if successfully exploited, enable an attacker to remotelyexecute applications on a computer running all currently supportedversions of WindowsThis is exactly the type of vulnerability Blaster and Sasser used toinfect millions of computers back in 2003 and 2004IMAGEThe reason for the out-of-band patch is that there is already malwareactively using the vulnerability to infect computers, which we detectas Trojan-Spy:W32/GimmivA This trojan steals confidentialinformation from the computer and sends it back to the attackerThe situation is not as dire as in earlier years, as Windows XP SP2and newer have a firewall in place by default If you have file orprinter sharing enabled however, your computer may be affectedWe recommend that everyone apply the update as soon as possibleOn 24/10/08 At 04:07 AM</description><link>http://www.secuobs.com/revue/news/31480.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/31480.shtml</guid></item>
<item><title>VirusVBSConfi</title><description>Secuobs.com : 2008-10-22 17:16:13 - FSecure Antivirus Research Weblog -  One of our Web Security Analysts — Chu Kian — came across a relativelyold threat this weekIt was during his day-to-day work that he encountered a VBS malware,VirusVBSConfiIt's not something new, detection was added in 2005, but it stillworks and it can still infect some unpatched systems if they browsewebsites with the malware code presentVisiting an infected website with the malicious code will prompt for aJava virtual machine component installation, shown below:VirusVBSConfiOn one of our test machines, after selecting to download, the sampledisplayed a script error Luckily Windows Script Debugger was open toprompt of any scripting errors, and so up came the actual decodedscript of the malwareVirusVBSConfiInspecting the decoded script shows that it will try to save thedownloaded file as KERNELDLL or KERNEL32DLL detected asVirusVBSConfi depending on where WSCRIPTEXE is located Thisdownloaded file is also used to reference the startup registry key aswell as in its shell spawning routine which is achieved by modifyingthe registry key in opening DLL files It can also infect files thathave extensions of HTM, HTML, ASP, PHP, and JSPTaking a look at the infected website and viewing the page source, wesaw that the site is actually embedded with the malware code Maybethis is unknown to the website owner that is why it's still thereWe've now sent abuse messages regarding thisVirusVBSConfiHaving come across one site, we looked further using Google You caneasily discover more websites that contain the same malware code Hereare some sample search results:VirusVBSConfiSo even though most of today's threats live and die within a few days,there's still some old script malware that exists it can still infectunwary travelersOn 22/10/08 At 03:22 PM</description><link>http://www.secuobs.com/revue/news/31093.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/31093.shtml</guid></item>
<item><title>JavaScript Injection Attack</title><description>Secuobs.com : 2008-10-15 15:50:18 - FSecure Antivirus Research Weblog -  JavaScript injection attacks seem to be the in thing these days Malwarewriters are increasingly utilizing such attacks as a better means tospread their workAs little as a year ago, the bad guys were dependent on enticingpeople to follow links that pointed to malicious websites via e-mail,search links, or IM worms Today, they are using JavaScript injectionattacks to simply "steal" a website's visitors, and it has becomesomething of a Swiss Army Knife for underground hackers to spreadtheir malware worldwideJS InjectionWe've seen numerous high traffic, legitimate websites attacked usingthis technique One recent example is MegaGames, a very popular USgaming portal with a 3172 rank in Alexa The JavaScript injectionattack successfully exploited one of MegaGames' servers to insert acouple extra lines of code This addition redirects unsuspectingwebsite visitors to a malicious European site where the main infectionattempts are carried outThe malicious site attempts two different methods to attack itsvisitors The first is an attempt to exploit a Microsoft MDACRDSDataspace ActiveX Control Remote Code Execution VulnerabilityMS06-014JS AttackThis attack would only affect website visitors using versions ofMicrosoft's Internet Explorer IE browser, as the website basicallyrequires visitors to use an ActiveX Control, then uses a loophole inthe way the ActiveX Control interacts with the IE browser to provideremote attackers complete control over a victim's systemThe second attack attempted is a drive-by download, which affects notonly the IE browsers, but also Firefox 10 et 20 browsers This attackuses JavaScript to detect the browser's type, then uses Adobe Flashexploits to download and execute a malicious binary file onto thesystemFlash ExploitsThe MegaGames website is currently still compromised and itsmisfortune illustrates a good point Many Internet users are under theimpression that they can only get infected with malware if they visit"obviously risky" dodgy websites, such as "pr0n" or "warez" sitesUnfortunately, that's not true Malware writers have been getting moresophisticated and today, even legitimate news or business sites canget surreptitiously compromisedAnother good example that no site is safe — BusinessWeekcom — a verylegitimate and high traffic site It has fallen victim to an SQLInjection attack, and such attacks inject JavaScript…The Register has more detailsWeb Security team post by — Choon HongOn 18/09/08 At 09:13 AM</description><link>http://www.secuobs.com/revue/news/29113.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/29113.shtml</guid></item>
<item><title>Do spammers get spam</title><description>Secuobs.com : 2008-10-15 15:50:18 - FSecure Antivirus Research Weblog -  Spam is still a problemProblem is, spam still works So it won't be going away any time soonOne spam vendor was recently spamming yes their own ads to a fewmillion e-mail addresses The message contained this PDF file:info@bulk-mailorgTwo things worthy of noting here:First: The old e-mail spam vendors are selling mobile phone textmessage spam lists as wellSecond: The vendor here is trying to avoid getting spammed themselves,by writing their e-mail addresswhich is info@bulk-mailorg as info at bulk-mail dot orgWe suppose they are worried that an e-mail collecting spider mightfind their e-mail address info@bulk-mailorg and add it to a spamdatabase Then their address which was info@bulk-mailorg would getspam too We guessAnyway, their address seems to be info@bulk-mailorg Make sure youdon't post it to a public web page or they might otherwise get spamOn 19/09/08 At 03:06 PM</description><link>http://www.secuobs.com/revue/news/29112.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/29112.shtml</guid></item>
<item><title>You're Not Paying Attention</title><description>Secuobs.com : 2008-10-15 15:50:18 - FSecure Antivirus Research Weblog -  You're not listening to what we're saying at allWe quite clearly told you in our last blog post not to post theaddress "info@bulk-mailorg" to a public web pageNow look what you've done The address is all over the web and allover the blogospherePlease try to pay more attention in the futureOn 22/09/08 At 09:14 AM</description><link>http://www.secuobs.com/revue/news/29111.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/29111.shtml</guid></item>
<item><title>A Different Twist on the Path to the Kernel</title><description>Secuobs.com : 2008-10-15 15:50:18 - FSecure Antivirus Research Weblog -  Now here's something we don't see every dayIt's an interesting twist on an old tactic — a worm that uses a localelevation of privilege vulnerability to access the kernel and executecodeMost malware with rootkit functionality will tamper with the Windowskernel and attempt to execute code in kernel mode Typically, aspecial driver is used to do thisWormWin32AutoRunnox has a payload that restores the originalfunction pointers back to the kernel's System Service Table SST Theusual motivation for malware to do this is to remove any SST hooksinstalled by security software or other malware that might affect itssuccessful operationAs noted, normally a special driver or the physical memory device isused to get access to kernel-mode memory to restore the pointersAutoRunnox is different — it uses "GDI Local Elevation of PrivilegeVulnerability CVE-2006-5758" to do the job For malware, its ratherunique to see such a technique being usedThis vulnerability is due to an error in handling a shared memorystructure, which allows the structure to be remapped from read-only towritable April 2007's update patched the vulnerabilityAntivirus :  Worm:W32/AutoRunGMAfter remapping the memory, the malware will initialize a CPaletteobject It will then search for the palette object in the sharedkernel memory structure Since the memory is now writable, it can bealtered to include a pointer to a special function that will removeany existing SST hooks Finally, a call to GetNearestPaletteIndex willindirectly cause the function to be executed Afterwards, the paletteobject is restored leaving no trace of the attackIf attacking this vulnerability fails, the worm goes back to thetried-and-true "special driver" method The driver is detected by usas Rootkit:W32/AgentUGEither way, if the attack is successful, the machine is compromised asthe attacker can access the kernel and execute code, or cause a denialof serviceThis attack will only work on unpatched machines running without thelatest updates Microsoft ranks this vulnerability as Important andrecommends that users apply the update immediatelyForesight From:http://technetmicrosoftcom/en-us/library/cc750820aspx"With this new release, the Window Manager, GDI, and related graphicsdevice drivers have been moved to the Windows NT Executive running inkernel mode"Response team post by  Lordian, Kimmo, Antti and MikaOn 26/09/08 At 02:52 PM</description><link>http://www.secuobs.com/revue/news/29110.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/29110.shtml</guid></item>
<item><title>Really Legal Stuff</title><description>Secuobs.com : 2008-10-15 15:50:18 - FSecure Antivirus Research Weblog -  WinDefender 2008 is a rogue application Rogues are also sometimes knownas scarewareSpyware Rogue : WinDefender 2008Looks sort of familiar, doesn't it Do you recognize the shape of theboxThe website creators appear to have "borrowed" a few thingsLet's check out the legal disclaimerSpyware Rogue : WinDefender 2008 : Really Legal StuffHey — Really Legal Stuff — That's impressive From where else we canfind really legal stuffSpyware Rogue : Antivirus XP 2008 : Really Legal StuffOh, Antivirus XP 2008 That particular rogue is a huge pain in the…neckThe guys that produce this stuff are crooks and swindlersSpyware Rogue : Antivirus XP 2008Here's a tip: If they claim to be REALiable — they're probably FAKEPS Performing a search for "really legal stuff" produces some veryinteresting but definitely NOT safe for work resultsAvoid following the linksOn 30/09/08 At 04:16 PM</description><link>http://www.secuobs.com/revue/news/29109.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/29109.shtml</guid></item>
<item><title>John Doe is a Criminal Mastermind</title><description>Secuobs.com : 2008-10-15 15:50:18 - FSecure Antivirus Research Weblog -  WinDefender 2008 was the subject of yesterday's post It's a roguesecurity application, and part of an ever increasing consumer scamA search for "Really Legal Stuff" ties WinDefender 2008 to AntivirusXP 2008, another persistent and very nasty rogueRogue WinDefender 2008 and Antivirus XPHere's another *really* related rogue, Spyware Guard 2008Rogue SpywareGuard 2008 - Really Legal StuffSpyware Guard 2008's legal page makes references to Pandora SoftwareThere are other rogue websites that refer to Pandora Software, andclaim it to be located in Dortmund, Germany with a support contact ofOleg Dvorezky Right… sureWhois records list the registrant of Pandora as Trans Eurogroup S Awith a physical address of Victoria, SC Where the heck is SC It'sthe Republic of Seychelles, an archipelago nation that's located inthe Indian OceanOn sites that refer to Pandora Software, you'll also find manycross-references to Innovagest2000 The innovagest2000com websitelists their contact address as Madrid, SpainInnovagest2000 claims to provide simply the best entertainment onlineAnd just what kind of entertainment do they provideEntertainment such as SystemDefender, yet another rogue MorescarewareRogue SystemDefender ScanOh no, 324 threats Is it the animation that's supposed to be fun… It isn't that much fun if you click on the Free Scan Now buttonDo that and you'll get a file that we detect asTrojan-DownloaderWin32AdloadmaRogue SystemDefender - Trojan-DownloaderWin32AdloadMATrojan-downloaders are kind of a killjoy when it comes toentertainmentSysCleaner's website is also one of Innovagest2000's efforts from thelooks of itRogue SysCleaner ScanHuh SysCleaner also detects 324 things to fix, just likeSystemDefender does Guess that's part of the entertainmentUsing a selection of text from SysCleaner's privacy policy page, welocated another batch of roguesAntiMalware 2009Rogue AntiMalware 2009Total EliminatorRogue TotalEliminator - Privacy PolicyeKerberosRogue_eKerberos_400x360FileShredder 2008Rogue FileShredder 2008Andromeda AntiVirusRogue Andromeda AntiVirusReal AntivirusRogue Real AntivirusPC AntispyRogue PC AntispyAnother selection of text from these sites yields many search resultsthat are definitely not safe for work, ie pornography Reallyobscene stuff Morally upright citizens of the world, these guys —notThe company that provides this so called entertainment isurbangestdesarrolloscom The Urbangestdesarrollos site, which alsoclaims a contact address of Madrid, Spain, is a carbon copy ofInnovagest2000 Both Urban and Innova state that credit cardstatements may show New Concept Business SLNew Concept Business SL claims to be from Barcelona, Spain Hmm,Spain again Whois records list the location as Barcelona but thecontact person is located in Amsterdam, ES and has a phone numberstarting with +1800ES as in Spain Amsterdam, Spain With a US toll-free phone numberRight, that's probably accurate, you thinkThese creeps are really anonymousWhich brings us to this bit of news: Microsoft and Washington stateare suing scareware purveyorsAnd just who is the target of their lawsuit Texas-based BranchSoftware and its owner James Reed McCreary RegistryCleanerXP is thename of his scareware application The Whois information forregistrycleanerxpcom, which is still online by the way, actuallyseems to have legitimate contact detailsWhy isn't McCreary more anonymous It's probably because he isn't theworst of the scareware that's out there Yeah, he's guilty ofdeceptive and misleading advertising, and we're happy to see somethingbeing attempted, but there's lots worse out thereThe lawsuit against McCreary could very likely devolve into a FirstAmendment speech case attempting to define deceptive practices, andthen eventually he'll walk Just like spam king Jeremy Jaynes, who hadhis spam conviction overturned a few weeks ago Jaynes was incrediblyguilty, and yet the Virginia law just wasn't good enough Too broadWe can always hope that Washington has better laws, and a judge thatunderstands all of the technical details, but we aren't holding ourbreath while waiting for the resultsWhat about the worst of the purveyors The ones behind stuff such asAntivirus 2009, Malwarecore, WinDefender, WinSpywareProtect andXPDefenderBrian Krebs' has the key details, as he very often does, in thisSecurity Fix postIn a separate action, Microsoft filed five "John Doe" lawsuits tolearn the identities of individuals responsible for marketing otherscareware productsOh, John Doe lawsuits That will take care of the problem, no Once welearn the identities of the individuals, we'll just have to track themdown in Dortmund/Madrid/Barcelona/Victoria/Amsterdam inGermany/Spain/Seychelles… and that's just the supposed locations forthe John Does involved with the WinDefender chain of appsThe Antivirus 2009 gang… is located in an entirely different set ofEuropean countriesWe applaud the effort, but we think it's going to take a lot more thanthe Attorney General of Washington to fix this problem The Internethas no borders Perhaps the effort would be better spent to create aninternational agency with the enforcement power to shut down roguesites, many of which are hosted in the USHere's some final screenshots for you Do see the tiny little redasterisk above the "y" in the word "Utility"Rogue WinDefender 2008 - Online Scanning UtilityThat's a disclaimerRogue WinDefender 2008 - DisclaimerIs the text to small for you to readIt says Typical system scan that shows how the real WinDefenderproduct will be scanning your computer Advertising purposes onlyJohn Doe truly has no shameOn 01/10/08 At 06:54 PM</description><link>http://www.secuobs.com/revue/news/29108.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/29108.shtml</guid></item>
</channel>
</rss>
 
<?xml version="1.0" encoding="utf-8"?>
<rss version="0.92">
<channel>
<title>SecuObs.com</title>
<link>http://www.secuobs.com</link>
<description>Observatoire de la securite Internet</description>
<language>fr</language>
<webMaster>webmaster@secuobs.com</webMaster>
 <item><title>OnionDuke  APT Attacks Via the Tor Network</title><description>2014-11-14 07:17:55 - F Secure Antivirus Research Weblog :  Recently, research was published identifying a Tor exit node, located in Russia, that was consistently and maliciously modifying any uncompressed Windows executables downloaded through it Naturally this piqued our interest, so we decided to peer down the rabbit hole Suffice to say, the hole was a lot deeper than we expected  In fact, it went all the way back to the notorious Russian APT family MiniDuke, known to have been used in targeted attacks against NATO and European government agencies The malware used in this case is, however, not a version of MiniDuke It is instead a separate, distinct family of malware that we have since taken to calling OnionDuke But lets start from the beginning When a user attempts to download an executable via the malicious Tor exit node, what they actually receive is an executable  wrapper  that embeds both the original executable and a second, malicious executable By using a separate wrapper, the malicious actors are able to bypass any integrity checks the original binary might contain Upon execution, the wrapper will proceed to write to disk and execute the original executable, thereby tricking the user into believing that everything went fine However, the wrapper will also write to disk and execute the second executable In all the cases we have observed, this malicious executable has been the same binary  SHA1  a75995f94854dea8799650a2f4a97980b71199d2, detected as Trojan-Dropper W32 OnionDukeA  This executable is a dropper containing a PE resource that pretends to be an embedded GIF image file In reality, the resource is actually an encrypted dynamically linked library  DLL  file The dropper will proceed to decrypt this DLL, write it to disk and execute it A flowchart of the infection process A flowchart of the infection process Once executed, the DLL file  SHA1  b491c14d8cfb48636f6095b7b16555e9a575d57f, detected as Backdoor W32 OnionDukeB  will decrypt an embedded configuration  shown below  and attempt to connect to hardcoded C C URLs specified in the configuration data From these C Cs the malware may receive instructions to download and execute additional malicious components It should be noted, that we believe all five domains contacted by the malware are innocent websites compromised by the malware operators, not dedicated malicious servers Screenshot of the embedded configuration data A screenshot of the embedded configuration data Through our research, we have also been able to identify multiple other components of the OnionDuke malware family We have, for instance, observed components dedicated to stealing login credentials from the victim machine and components dedicated to gathering further information on the compromised system like the presence of antivirus software or a firewall Some of these components have been observed being downloaded and executed by the original backdoor process but for other components, we have yet to identify the infection vector Most of these components don't embed their own C C information but rather communicate with their controllers through the original backdoor process One component, however, is an interesting exception This DLL file  SHA1 d433f281cf56015941a1c2cb87066ca62ea1db37, detected as Backdoor W32 OnionDukeA  contains among its configuration data a different hardcoded C C domain, overpictcom and also evidence suggesting that this component may abuse Twitter as an additional C C channel What makes the overpictcom domain interesting, is it was originally registered in 2011 with the alias of  John Kasai  Within a two-week window,  John Kasai  also registered the following domains  airtravelabroadcom, beijingnewsblognet, grouptumblercom, leveldeltacom, nasdaqblognet, natureinhomecom, nestedmailcom, nostressjobcom, nytunioncom, oilnewsblogcom, sixsquarenet and ustradecompcom This is significant because the domains leveldeltacom and grouptumblercom have previously been identified as C C domains used by MiniDuke This strongly suggests that although OnionDuke and MiniDuke are two separate families of malware, the actors behind them are connected through the use of shared infrastructure A graph showing the infrastructure shared between OnionDuke and MiniDuke A visualization of the infrastructure shared between OnionDuke and MiniDuke Based on compilation timestamps and discovery dates of samples we have observed, we believe the OnionDuke operators have been infecting downloaded executables at least since the end of October 2013 We also have evidence suggesting that, at least since February of 2014, OnionDuke has not only been spread by modifying downloaded executables but also by infecting executables in torrent files containing pirated software However, it would seem that the OnionDuke family is much older, both based on older compilation timestamps and also on the fact that some of the embedded configuration data make reference to an apparent version number of 4 suggesting that at least three earlier versions of the family exist During our research, we have also uncovered strong evidence suggesting that OnionDuke has been used in targeted attacks against European government agencies, although we have so far been unable to identify the infection vector s  Interestingly, this would suggest two very different targeting strategies On one hand is the  shooting a fly with a cannon  mass-infection strategy through modified binaries and, on the other, the more surgical targeting traditionally associated with APT operations In any case, although much is still shrouded in mystery and speculation, one thing is certain While using Tor may help you stay anonymous, it does at the same time paint a huge target on your back It's never a good idea to download binaries via Tor  or anything else  without encryption The problem with Tor is that you have no idea who is maintaining the exit node you are using and what their motives are VPNs  such as our Freedome VPN  will encrypt your connection all the way through the Tor network, so the maintainers of Tor exit nodes will not see your traffic and can't tamper with it Samples    a75995f94854dea8799650a2f4a97980b71199d2   b491c14d8cfb48636f6095b7b16555e9a575d57f   d433f281cf56015941a1c2cb87066ca62ea1db37 Detected as  Trojan-Dropper W32 OnionDukeA, Backdoor W32 OnionDukeA, and Backdoor W32 OnionDukeB Post by   Artturi  lehtior2  On 14 11 14 At 05 00 AM </description><link>http://www.secuobs.com/revue/news/545446.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/545446.shtml</guid></item>
<item><title>What grade does your favorite app get </title><description>Secuobs.com : 2014-11-12 15:50:53 - F Secure Antivirus Research Weblog -  Forbes' Parmy Olson published a short article about PrivacyGrade on Tuesday What is PrivacyGrade  From PrivacyGrade's FAQ  The goal of PrivacyGradeorg is to help raise awareness of the behaviors that many smartphone apps have that may affect people's privacy PrivacyGrade provides detailed information about an app's privacy-related behaviors We summarize these behaviors in the form of a grade, ranging from A   most privacy sensitive  to D  least privacy sensitive  Here's our App Permissions' grade  PrivacyGrade, F-Secure App Permissions A  Grading apps can be a very subjective thing For example, social network integration might be of more concern to some than ad networks and location permissions   but whatever your personal criteria   the folks at PrivacyGrade have compiled some very interesting statistics   Most Popular Permissions   Third Party Libraries On 12 11 14 At 01 31 PM </description><link>http://www.secuobs.com/revue/news/545079.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/545079.shtml</guid></item>
<item><title>Remember, Remember the Fifth of November</title><description>Secuobs.com : 2014-11-05 15:48:34 - F Secure Antivirus Research Weblog -  Remember remember the fifth of November Gunpowder, treason and plot I see no reason why gunpowder, treason Should ever be forgot  Switch On Freedom The Economist  How Guy Fawkes became the face of post-modern protest On 05 11 14 At 01 27 PM </description><link>http://www.secuobs.com/revue/news/543909.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/543909.shtml</guid></item>
<item><title>Vote For Freedome Beta</title><description>Secuobs.com : 2014-11-04 17:39:11 - F Secure Antivirus Research Weblog -  We recently invited testers to try our Freedome VPN Beta for Android Well, now it's even easier to try It's now available on Play The B is for Beta F-Secure Freedome VPN Beta This version of Freedome includes an App Security feature which scans for bad apps Besides three months of free service, testers are eligible to win a Freedome-themed hoodie Karen, Päivi ja Nemo So, make Päivi's day  Freedome's Senior Product Manager, seen on the right  and install the Beta Check the app's page on Play for the feedback address On 04 11 14 At 03 19 PM </description><link>http://www.secuobs.com/revue/news/543755.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/543755.shtml</guid></item>
<item><title>Multi-language support  Not your everyday spam</title><description>Secuobs.com : 2014-10-31 18:09:00 - F Secure Antivirus Research Weblog -  Sometime during the beginning of the year, we have encountered a surge in Fareit spams Fareit is a downloader used to deliver Zeus and Cryptowall Lately, we have been noticing yet another downloader being spammed It seems that the spammer for this downloader has spent more effort to trick the user into believing that it s a legitimate email A recent spam was a fake KLM e-ticket which was tailored to pretend to come from the Sales   Service Center of Air France KLM klm_eticket_ready  39k image  However, this spammer did not only tend to English language speakers Recently, we also saw quite a number of its spam sent in Polish This email, for example, supposedly comes from dotpaypl, a service for online transaction payment that is based in Poland dotpay_blurred_ready  34k image  While this one uses an ISP that s popular in Poland nowy_kontrakt_listopad_ready  23k image  And just when we thought the spammer s language skills ends there, it gave us a sample of its Finnish-themed spam lomake_ready  24k image  The grammar seems to be quite convincing enough considering that even the subject and attachments are using the correct Finnish terms Not only that, the email address used,  suomi24fi , is one of Finland s most popular websites Obviously, spammers are also doing their research in customizing their messages to produce more effective scams Not only do they use the language of the target country or people, but they have also achieved to make use of popular email or service providers The payload of these spams is a Trojan Downloader known as Wauchos Here are its recent filenames  attachments_ready  3k image  For the two sample attachments, it confirms internet connection by trying to connect to http wwwgooglecom webhp It makes the following network connections    http 188 22532207 ssdc32716372 loginphp   http 188 22532208 ssdc32716372 filephp   http 188 22532209 ssdc32716372 filephp   http 188 22532209 ssdc32716372 filephp   http 188 22532209 ssdc32716372 filephp   http 92 5397194 ssdc32716372 filephp   http 46 2855113 ssdc32716372 filephp And it downloads these additional trojans from the following    http auto it jeveexe   http dd ru oldexe The Wauchos variants we ve seen in these emails downloaded either Zbot or Cridex, which are both information stealers We detect these families as Trojan-Downloader W32 Wauchos, Trojan-Spy W32 Zbot, and Trojan W32 Cridex On 31 10 14 At 04 01 PM </description><link>http://www.secuobs.com/revue/news/543382.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/543382.shtml</guid></item>
<item><title>It's Not a Game - It's a Violation of Human Dignity</title><description>Secuobs.com : 2014-10-29 17:52:53 - F Secure Antivirus Research Weblog -  Still don't set a passcode on your phone  From Matthias Gafni and Malaika Fraley at the Contra Costa Times  The California Highway Patrol officer accused of stealing nude photos from a DUI suspect's phone told investigators that he and his fellow officers have been trading such images for years The five-year CHP veteran called it a  game  among officers, according to an Oct 14 search warrant affidavit CHiPs, theft of images Source  Contra Costa Times A game  IT'S A CRIME  Or it certainly ought to be  Again from the Contra Costa Times  CHP Commissioner Joe Farrow said in a statement that his agency too has  active and open investigations  and cited a similar case several years ago in Los Angeles involving a pair of officers  The allegations anger and disgust me,  Farrow said  We expect the highest levels of integrity and moral strength from everyone in the California Highway Patrol, and there is no place in our organization for such behavior  Let's hope Commissioner Farrow, who began his tenure in 2008, truly means what he says Here's an incident from 2006 for him to consider  CHiPs, violation of dignity Source  The New Yorker It appears that the CHP has a culture problem which goes back quite some time With great power comes great responsibility Anybody who thinks violating the dignity of another human being is  a game  doesn't deserve to be a cop   Offer the California Highway Patrol your feedback here and or here On 29 10 14 At 03 14 PM </description><link>http://www.secuobs.com/revue/news/543063.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/543063.shtml</guid></item>
<item><title>101 Bad Android Apps</title><description>Secuobs.com : 2014-10-28 15:47:17 - F Secure Antivirus Research Weblog -  Flash Player installers, so-called Android security updates, pirated games, and XXX-video players  there's almost never a shortage of suspicious Android apps We have automation which analyzes such apps and takes screenshots in the process Some examples  101 bad Android apps 101 Bad Android Apps Here's one particular example  Activate device administrator  Activate device administrator  Erase all data  Reset password  Limit password China Mobile customers should select   Cancel  On 28 10 14 At 12 54 PM </description><link>http://www.secuobs.com/revue/news/542917.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/542917.shtml</guid></item>
<item><title>A Tale of Two Powerpoint Vulnerabilities</title><description>Secuobs.com : 2014-10-24 15:45:05 - F Secure Antivirus Research Weblog -  It's been already a week after the announcement of the CVE-2014-4114 vulnerability, and the tally of the exploiters have only increased There are even files where the metadata has remained the same, which clearly shows that they have been copied from the original as in the case of Mirtec and Cueisfry  a trojan linked to Japanese-related APT attacks  Authors behind these malware copied the PowerPoint Document originally used by BlackEnergy and just replaced the payload and the content with legitimate material found online file_properties  110k image  BlackEnergy, Mirtec, Cueisfry document metadata, respectively Well, if another party's winning formula already worked, there is no need to reinvent the wheel Until a patch is pushed out, that is Which brings us to Taleret, a malware family known to be behind certain Taiwanese APT attacks After CVE-2014-4114 was patched, there was a need to improvise and as such, Taleret this time grabbed a clean PowerPoint and embedded its payload to get it executed via the CVE-2014-6352, a weakness left over from CVE-2014-4114 file_properties_update  49k image  Although Microsoft has released a patch for CVE-2014-4114, CVE-2014-6352 has yet to be patched However, a Fix it tool is available here It seems that most of the content used by the malicious PowerPoint documents have been harvested from educational institutions or R D materials that are available in the Internet, thus making it quite challenging to tell them apart Here are some examples of both the clean documents and their malicious counterparts  clean_malware  145k image  While, there isn't a patch for the other vulnerability yet, if you couldn't tell which one is clean and malicious, please verify the documents received from the source Or, you can update your antivirus signatures to check if they are detected product_scan  60k image  Hashes  8f31ed3775af80cf458f9c9dd4879c62d3ec21e5 - Mirtec - C C  11621212720 66addf1d47b51c04a1d1675b751fbbfa5993a0f0 - Cueisfry - C C  msprivacyserveorg 488861f8485703c97a0f665dd7503c70868d4272 - Taleret - C C  7088151213 e9020a3cff098269a0c878a58e7abb81c9702691 02b9123088b552b6a566fc319faef385bec46250 98841ea573426883fdc2dad5e50caacfe08c8489 7d0cecfad6afbe9c0707bf82a68fff44541a2235 On 24 10 14 At 01 10 PM </description><link>http://www.secuobs.com/revue/news/542495.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/542495.shtml</guid></item>
<item><title>Wanted  Testers For The Greatest Android App Ever</title><description>Secuobs.com : 2014-10-22 21:53:49 - F Secure Antivirus Research Weblog -  Okay  so the greatest Android app  ever  is a bit of friendly hyperbole But still, it's a really is a great app What app  Well, F-Secure Freedome of course  currently available for Android and iOS  The Freedome team  along with a Labs team  is developing a new Android feature   cloud-based reputation scanning And we need numerous testers for the beta app  You  Here's a preview  Freedome beta, App security  See it in action  The function is entirely cloud-based, ie, no database updates to download So it's very light People wanting to exercise their freedom of speech are increasingly turning to VPN services to circumvent censorship And in return, many are being targeted by government-sponsored malware We need your help Even just using the beta contributes Participants will receive three months of free service, and active participants are eligible to receive Freedome hoodies But wait, there's something more  We've designed a new  labs sticker  And testers will be the first people offered a chance to get one So join the beta now  Don't worry if you already have Freedome installed, this beta can be installed side-by-side, so you can also participate Cheers    F-Secure's Privacy Principles On 22 10 14 At 07 20 PM </description><link>http://www.secuobs.com/revue/news/542189.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/542189.shtml</guid></item>
<item><title>RATs threatening democracy activists in Hong Kong</title><description>Secuobs.com : 2014-10-15 09:26:16 - F Secure Antivirus Research Weblog -  Hong Kong has been in the headlines lately thanks to the Occupy central campaign  occupycentral,  OccupyHK  and the umbrella revolution  umbrellarevolution,  UmbrellaMovement  DPHK, Democratic Party Hong Kong and Alliance for True Democracy  ATD  are central players in this movement Recent development has turned this into more than a fight for democracy The sites of these organizations were infected with malware, and that turned it into a fight for  digitalfreedom as well Volexity has the story with all the technical details It seems to be RATs  Remote Access Trojans  that could be used for a variety of purposes And the purpose of this is really the interesting question Who did it and why    Cybercrime of today is to a large extent social engineering aiming to lure victims to run malware and infecting their devices It s very common for cybercriminals to drive more users to infected sites or phishing pages by riding on shocking headlines So infecting sites that are in the middle of global attention is attractive for any cybercriminal, even without any kind of political motivation   These organizations are involved in a political struggle against one of the world s leading cyber-superpowers So it sounds very plausible that China would be behind this malware attack out of political motives A lot of the visitors on these sites are involved in the movement somehow, either as leaders or at grass root level Their enemy could gain a lot of valuable information by planting RATs even in a small fraction of these peoples  devices   The publicity around the issue will also scare people away from the sites Twitter can be used efficiently to orchestrate the protests, so an infected site will probably have little practical impact Blocking services like Twitter is possible but a very visible and dramatic action, and even that can be circumvented with VPNs like F-Secure Freedome But the site is more important for spreading the protesters  message to a global audience The impact may be significant at this level Here again, China would be the one who benefits The moral of the story is naturally that political activists are attractive targets for cyber-attacks There s no evidence that these cases have political motives But you don t have to be a genius to figure out that China is the prime suspect And that makes this case noteworthy Criminals usually target private people and states other states But here we seem to have a state targeting ordinary people belonging to a political organization This kind of attack is a very real threat for people running opposition movements And the threat is not limited to less democratic countries The police forces in many western countries already have both technology and legal support for using malware against suspects And usually without proper transparency and control of its usage Frankly speaking, I would not be very surprised if a similar case was discovered here in Europe We do currently not have democratic movements of the same magnitude as the Umbrella movement But we do have a lot of organizations that are being watched by the authorities Ultra-right groups is an obvious example Micke On 15 10 14 At 07 00 AM </description><link>http://www.secuobs.com/revue/news/540153.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/540153.shtml</guid></item>
<item><title>One Doesn't Simply Analyze Moudoor</title><description>Secuobs.com : 2014-10-14 18:47:03 - F Secure Antivirus Research Weblog -  Today we are pleased to see an important milestone reached in a coordinated campaign against a sophisticated and well-resourced cyber espionage group We have recently been participating in a Coordinated Malware Eradication initiative led by Novetta, in cooperation with other security vendors particularly iSight, Cisco, Volexity, Tenable, ThreatConnect, ThreatTrack Security, Microsoft and Symantec, in the aims of disrupting the operations of this particular group Today, we are jointly releasing an improved level of coverage against the threats utilized by the group This espionage group, which we believe to have a strong Chinese nexus, has been targeting several industry sectors from finance, education and government to policy groups and think tanks They have been operational at least since 2010 The attackers use several different tools to conduct their operations One of the tools used by these criminals is Moudoor Moudoor is a derivative of the famous Gh0st RAT  remote access tool  that spawned many derivatives over time In fact, its source code has been circulating across the internet at least since 2008 Moudoor was named after the functions that were exported by the malware components screenshot1_mydoor  21k image  screenshot2_door  21k image  Later versions of this malware have dropped such explicit strings, however, the name of the threat remains One of the things that allows us to distinguish between Moudoor from other many derivatives of Gh0st is the particular magic value that it uses to communicate with its C C This value has been consistently set to  HTTPS , and that is one of the key distinguishers that we have used to track this particular strain over time At its core, Moudoor is a powerful remote access tool The chain of events that lead to Moudoor infections usually begins with the exploitation of 0-day vulnerabilities through watering hole attacks For example, the attackers used CVE-2012-4792 before to eventually have Moudoor land on the victim machines Moudoor has an impressive list of capabilities, some of which are inherited from being a derivative of the Gh0st RAT Gh0st features extensive file system manipulation functionalities, advanced spying, monitoring features and more Of course, Moudoor's authors have continued to customize their  fork  over time by adding new features and removing those which were not needed For example, earlier variants of Moudoor kept Gh0st's ability to open a remote shell, but this capability has disappeared in the newer versions On the other hand, the attackers have worked to tailor which information is extracted from the victim machines to their specific needs and interests Analysis of the code of Moudoor also gave us hints that the authors of this threat are of Chinese origin During its execution, the malware builds a string containing the current time information  such string uses Chinese characters to represent the time in human-readable format screenshot3_chinese  24k image  You can read a more detailed summary of the whole operation here Microsoft has also published information about this operation, which is available from this link We are detecting this family as Backdoor W32 Moudoor Our customers have received automatic updates to detect the tools known to be used by the attackers You can also use our Online Scanner to check for signs of compromise Our Online Scanner is a stand-alone tool that does not require installation, thus will allow you to quickly check for infections simply by downloading and running it Moudoor hashes  0fb004ed2a9c07d38b4f734b8d1621b08be731c1 83f3babe080ef0dd603ea9470a4151354f0963d5 b315fe094bb444b6b64416f3c7ea41b28d1990a4 On 14 10 14 At 04 06 PM </description><link>http://www.secuobs.com/revue/news/540020.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/540020.shtml</guid></item>
<item><title>Bob and Alice Discover a Mac OPSEC Issue</title><description>Secuobs.com : 2014-10-13 15:44:54 - F Secure Antivirus Research Weblog -  The following is a true story The names have been changed because the identity of those involved is none of your business Bob uses Linux Alice uses Mac Bob gave Alice a file via FAT32 formatted USB drive Alice inserted the USB drive into her Mac, copied the file, and then gave the USB drive back to Bob Later, Bob inserted the USB drive into his Linux computer and saw Mac files Lots and lots of Mac files And that's typical Mac files on a USB drive as seen via Linux Anybody who has exchanged files with a Mac user knows that Mac OS X copies various  hidden  files to USB drives Here's the interesting part  Bob was curious about the function of the files  And why so many, what do they do  Being a reverse engineer, Bob naturally examined the files with a hex editor And that's when he discovered that a file called  storedb  contained e-mail addresses, subject lines, and in a few cases, the opening sentence of Alice's messages Alarmed that such data metadata was copied to his USB drive, Bob investigated further and found that the information couldn't be seen using a forensic tool designed specifically for viewing such db files From a conventional view,  storedb  appeared to be identical to  storedb  Only a hex editor view revealed the leaked info embedded within storedb   so it isn't at all obvious with standard forensic tools We have examined Bob's USB drive and can confirm that there is data in the storedb file that really shouldn't be there We have been unsuccessful in reproducing the issue with our own Mac computers We don't have access to Alice or her computer, so we can only speculate The data may have leaked due to an unknown configuration, it may have leaked due to third-party software, or it may have leaked due to malware Here's the concern  Imagine you're a reporter Do you want data about the e-mail to your sources leaking to somebody else's USB drive  Definitely not  In some countries, an OPSEC failure such as this could easily land people in jail We don't normally write about unknowns But we do so in this particular case in the hope that somebody will be able to identify the source of the issue And if somebody does   we'll update this post On 13 10 14 At 01 21 PM </description><link>http://www.secuobs.com/revue/news/539804.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/539804.shtml</guid></item>
<item><title>NCR ATM API Documentation Available on Baidu</title><description>Secuobs.com : 2014-10-07 17:51:59 - F Secure Antivirus Research Weblog -  A recent ATM breach in Malaysia has caused havoc for several local banks According to reports, approximately 3 million Malaysian Ringgit  almost 1 million USD  was stolen from 18 ATMs There is no detailed information on how the attack was performed by the criminals, but according to one local news report, police claimed the criminals installed malware with the file name  ulssmexe  which was found on the compromised ATMs Based on the file name, we know that the malware in question was first discovered by Symantec and it is known as  PadPin  The basic technical information of this malware can be found here We have no confirmation that PadPin is the same malware used in the Malaysian ATM hacks But even so, we have discovered something interesting by doing our own analysis of PadPin's code We searched through our backend sample collection system and quickly located a few samples related to the aforementioned file name Our automated sample analysis system did not determine the samples to be malicious because the sample will not work on a typical Windows computer  it requires a DLL library which appears to be available on machines such as ATMs or self-service terminals running Windows Embedded operating system The DLL library is known as Extension for Financial Services  XFS  Malware import Extension for Financial Services library Image  Malware import Extension for Financial Services library When we took a look at the code, we saw some unfamiliar API functions which are apparently imported via MSXFSdll as shown in the image above Unfortunately Microsoft does not provide official documentation for these APIs which makes understanding of the malware code more difficult Questions continued until we came across a part of the malware code in which the malware attempts to establish a communication channel with the ATM pin pad device via one of the APIs Basically, its purpose is to listen and wait for the key entered into the pin pad by the criminals in order to carry out different tasks as described in Symantec's write-up In other words, the commands supported by the malware are limited to the keys available on the pin pad device For instance, when the criminal enters  0  on pin pad, it will start dispensing money from the ATM machine Analyzing the code, we started wondering how the malware author knows which pin pad service name to provide to the API so that the program is able to interact with the pin pad device It's a valid question because the pin pad service name used in the code is quite unique and it is very unlikely one can figure out the service name without documentation Therefore, we did some web searches for the API documentation using the API name and the pin pad service name And the result  We easily found the documentation from a dedicated ebooks website hosted on Baidu which appears to be the NCR programmer's reference manual WOSA XFS Programer's Reference Manual After skimming through the documentation, we concluded that writing a program interacting with the ATM machine becomes handy even for someone without any prior knowledge on how to write software communicating with these ATM devices The documentation is helpful enough to give programmers some sample code as well Coincidentally, we also found that the alleged malware targeting Malaysian banks ATM machines attempt to remove the  AptraDebuglnk  shortcut file from the Windows startup folder as well as the launch point registry key  AptraDebug  on the infected machine Its purpose is presumably to disable the default ATM software running on the machine and replaced it with the malware when the machine is rebooted This file and registry key seem to be referring NCR APTRA XFS software, so it is safe to assume that the malware aims to target only the machine running this self-service platform software In conclusion, it's possible this documentation was leaked by somebody who then uploaded it, and it was then used by PadPin's authors But we should not rule out that the malware could be written by some experienced programmers who are or were bank employees It is practically impossible to stop somebody from viewing or downloading the documentation once it is available on the Internet, but there are some countermeasures that banks can use to prevent such breaches from happening again One of the most straightforward mitigation methods is to prevent the ATM machine from running files directly from USB or CD-ROM Post by   Wayne On 07 10 14 At 02 28 PM </description><link>http://www.secuobs.com/revue/news/538951.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/538951.shtml</guid></item>
<item><title>CryptoWall updated to 20</title><description>Secuobs.com : 2014-10-02 17:22:03 - F Secure Antivirus Research Weblog -  One of this summer's most followed ransomware families is CryptoWall Over time CryptoWall has seen minor updates and changes but its core functionality has stayed pretty much the same Once a machine has been infected, CryptoWall will attempt to encrypt the contents of the victims hard drive and then demand a ransom payment in exchange for the decryption key required to get the contents back The only major break from this was a few months ago when we observed a few CryptoWall samples that were using a custom Tor-component to communicate with their command   control servers This Tor component was downloaded as an encrypted binary file from compromised websites It was then decrypted and used to set up a connection to the Tor network through which the C C server could be reached Interestingly, we only observed a few of these  Torified  versions of CryptoWall The majority of the samples we have seen have stuck to the original C C communication method That may now have changed Just yesterday, the first samples of ransomware calling itself  CryptoWall 20  were spotted in the wild Screenshot of CryptoWall 20 ransom page The CryptoWall 20 ransom page CryptoWall 20 appears to use a new packer obfuscator with an increased amount of anti-debugging and anti-static analysis tricks Upon reaching the final malicious payload, however, CryptoWall 20 is almost identical to the Torified CryptoWall 10 samples seen earlier this summer CryptoWall 10 CryptoWall 20 On the left, Torified CryptoWall 10 and on the right the same function in CryptoWall 20 Perhaps it was the efforts of security researchers to shut down CryptoWall C C servers that was hurting the gangs business Or maybe they just felt it was time for change In any case the author s  clearly felt a new C C communication method was needed And like professional software developers, the CryptoWall author s  seem to believe in first testing new versions thoroughly alongside previous versions before completely switching over to the new one We believe the Torified versions of CryptoWall 10 were exactly that, testing Therefore we expect to see a lot more of CryptoWall 20 in the near future List of compromised Tor-component download locations  hxxp wwwm redacted urgch wordpress f0k1ats hxxp wwwar redacted acom blog-trabajos n65dj17i1836 hxxp wwwar redacted ercz o515ujx2f hxxp wwwfd redacted rgde wp-content themes fdp-asz vrf8iu27h hxxp wwwcu redacted nde z6lub76lz295x hxxp wwwho redacted tcom 5gr4hl2tvv hxxp wwwme redacted ocom wp-content themes mh 3sbgwh hxxp ep redacted nca blog eo7ycomyy hxxp wwwpr redacted alcombr site hr38xc4 hxxp wwwji redacted ebe s5eroewr hxxp wwwje redacted rat jesneu wp-content themes Girl 0l9u4lc6che hxxp wwwdr redacted ende wordpress 3uh2e hxxp wwwye redacted akcom kf4bv hxxp wwwro redacted escom l449jbc0 hxxp wwwmc redacted ldcom u2m8bbkln3fqpe hxxp wwwfe redacted ancom wp-content themes s431_Blue bh7u09cpppg5h hxxp wwwsp redacted escouk blog f040z4d5d21z5rd hxxp wwwch redacted ngcouk blog wp-content themes the-beach-house 6k8elm10bin hxxp wwwgr redacted encom wp-content themes jarrah ghd4vowtha0sbin List of onion C C domains  crptarv4hcu24ijvonion crptbfoi5i54ubezonion crptcj7wd4oaafdlonion crptdtykhkmux333onion crpterfqptggpp7oonion Hashes for CryptoWall 20 samples  e6325fc7f7168936aa9331ac707b4c3cc186b46e Hashes for Torified CryptoWall 10 samples  00e0960099ec6381aa9bf1f11b536e3e32ffa635 3370f29350115af162b613c45fd5a6a44315a213 6698bb2df60685863a664e282e493ca1e886fec3 672d6b7e31fe8f6250c6831d139012b87440274c f21c073e57ad8a5b73139fbd4361c8985a83c9c9 Post by Artturi Lehtiö  lehtior2  On 02 10 14 At 02 47 PM </description><link>http://www.secuobs.com/revue/news/538189.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/538189.shtml</guid></item>
<item><title>Terms of Service</title><description>Secuobs.com : 2014-10-02 15:26:20 - F Secure Antivirus Research Weblog -  We recently published a report called  Tainted Love   How Wi-Fi Betrays Us  as part of a public Wi-Fi experiment The project required a  terms of service  and so for a bit of fun we added something  out of the ordinary Herod Clause Do you see it above  Your First Born Child In using this service, you agree to relinquish your first born child to F-Secure, as and when the company requires it In the event that no children are produced, your most beloved pet will be taken instead The terms of this agreement stand for eternity One never knows what might be found in the fine print The full terms of service used in our experiment are here On 02 10 14 At 01 06 PM </description><link>http://www.secuobs.com/revue/news/538160.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/538160.shtml</guid></item>
<item><title>Are malware authors targeting people via marketing services </title><description>Secuobs.com : 2014-09-26 15:38:18 - F Secure Antivirus Research Weblog -  We spotted an interesting case of a person complaining about e-mail malware with social engineering content which hits home almost too well, and decided to investigate a bit The person had been talking to his friend about possibly booking tickets to San Francisco in near future And 6 hours after the phone call he got an e-mail about an electronic plane ticket to San Francisco with an attachment The person was cautious enough not to touch the attachment, which was a good decision, as in our analysis it was identified as a variant of TrojanKryptAU This may be just a case of mass spammed malware and with social engineering text which hit this particular user at just exactly the right moment But when we checked our sample collection, there was only 1250 instances of related malware, which would indicate that this particular malware is not being spammed to large audiences And thus possibilities of getting exactly the right hit are very small Over the last year providers of targeted advertising have become a lot better at profiling users For example, when I have been browsing for flight or hotel information I have started to receive e-mail about flight and hotel offers in that particular destination from Trip advisor and other companies Of course in order to experience this one has to have Freedome disabled, so that I can be tracked, but that is the price of wanting to experience the net like a regular user So this case looks very much like some targeted advertising services were misused for victim discovery by malware authors We have seen advertising misused a lot with search engines, but this is the first case where we have indications that e-mail advertising services would be used in similar manner So far there is no proof the victim selection was done by abusing targeting profiling, and if profiling was used, was it based on phone call analysis Perhaps the person searched for something which provided a match for profilers But this is an interesting case and we will be keeping an eye out for future developments Fake Delta e-mail Post by   Jarno On 26 09 14 At 11 38 AM </description><link>http://www.secuobs.com/revue/news/536997.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/536997.shtml</guid></item>
<item><title>BlackEnergy 3  An Intermediate Persistent Threat</title><description>Secuobs.com : 2014-09-25 19:26:05 - F Secure Antivirus Research Weblog -  We have a new white paper available BlackEnergy   Quedagh  The convergence of crimeware and APT attacks The convergence of crimeware and APT attacks The paper's author, Broderick Aquilino, first wrote about BlackEnergy in June    BlackEnergy Rootkit, Sort Of   Beware BlackEnergy If Involved In Europe Ukraine Diplomacy BlackEnergy is a kit with a long history and this new analysis is quite timely In fact, malware researchers Robert Lipovsky and Anton Cherepanov from ESET will present a BlackEnergy paper at Virus Bulletin today Broderick's latest concurrent analysis focuses on a variant he has dubbed  BlackEnergy 3  Among BE3's new features is support for proxy servers when connecting to C Cs In this case, the proxies are based in Ukraine and there is compelling evidence the Quedagh gang is targeting Ukrainian government organizations Who is behind BlackEnergy 3  Here are some theories  1  The Kremlin is directly responsible and using a crimeware kit provides plausible deniability 2  Useful idiots  as in purely political patriotic hacktivists  3  Current or former cyber-criminals  aka privateers  BE3 is evolving to reflect  market  interests 4  All of the above 5  Perhaps all of this is wrong and it's the Dutch  it's not the Dutch  Whomever is behind Quedagh's campaign, they're using what is  or at least was  generally considered to be a  commodity threat  to achieve  advanced persistent threat  goals This appears to be a trend Why Quedagh  Quedagh Merchant Quedagh Merchant is the name of a ship which was captured by Captain William Kidd, an infamous 17th-century Scottish privateer  Privateering was a way of mobilizing armed ships and sailors without having to spend treasury resources or commit naval officers  Our working theory is that the emergence of  intermediate persistent threats  such as BlackEnergy 3 is being driven by market forces and that cyber-criminals are expanding their capabilities into espionage and commoditized information warfare On 25 09 14 At 04 50 PM </description><link>http://www.secuobs.com/revue/news/536854.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/536854.shtml</guid></item>
<item><title>Notice  Freedome v201 Issue on iOS 8</title><description>Secuobs.com : 2014-09-23 16:07:32 - F Secure Antivirus Research Weblog -  If you  like me  have an Apple device running iOS 8 and use F-Secure Freedome, please avoid updating to version 201 FreedomeVPN 514314954283819008 If you  like me  have already updated, you may see this after opening the app  Freedome 201 on iOS 8 Do not  Remove Old VPN configurations    just close the app Version 201 should work with its existing configurations If you need to toggle Freedome on off  Use  Settings, General, VPN Click the info button for your configuration and toggle  Connect On Demand  iOS 8 VPN settings You'll be limited to only the locations that you currently have installed But the ones that you have should work based on my testing The developers have already submitted a fixed version  v202  to Apple earlier this morning which is pending Apple's review More details are available from our community forum Also, Freedome's Twitter account We are very sorry for the inconvenience Post by   Sean On 23 09 14 At 01 45 PM </description><link>http://www.secuobs.com/revue/news/536385.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/536385.shtml</guid></item>
<item><title>CosmicDuke and the latest political news</title><description>Secuobs.com : 2014-09-19 00:00:08 - F Secure Antivirus Research Weblog -  After we had published the CosmicDuke report in July 2014, we continued to actively follow the malware Today, we discovered two new samples that both leverage timely, political topics to deceive the recipient into opening the malicious document The first one discusses the Ukraine crisis and EU sanctions over Russia and the original document was published here less than a week ago  IMAGE  The topic of the second document is definitely focusing on current affairs  Scotland votes on independence today The original article was published early this week Here is the decoy document   IMAGE  It is obvious that the attackers are keeping abreast of the latest political news, and they are very agile  they have the capability and capacity to rapidly utilize the information to increase the odds of social engineering If you are interested in learning more about CosmicDuke, these latest samples, as well as other interesting discoveries, will be discussed in detail at T2, an information security conference during October 23-24 in Helsinki, Finland On 18 09 14 At 09 13 PM </description><link>http://www.secuobs.com/revue/news/535618.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/535618.shtml</guid></item>
<item><title>Paying for content</title><description>Secuobs.com : 2014-09-18 10:38:58 - F Secure Antivirus Research Weblog -  I remember setting up our first website That was 20 years ago, in 1994 When the Web was very young and there were only a handful of websites, it was easy to forecast that the Web was going to grow And indeed, during these past 20 years, it has exploded in size What s even more important, the Web brought normal everyday people online Before the Web, you would only find geeks and nerds online Now everybody is online Back in 1994, we were guessing what would fuel the upcoming growth of the Web For it to grow, there has to be online content content like news or entertainment And for news and entertainment to move online, somebody has to pay for it How would users pay for online content  We had no idea Maybe newspapers would start charging an annual online subscription fee, just like they did for their paper version  Or maybe the web would incorporate some kind of an online on-demand payment system  the user would have an easy way of doing in-browser micropayments in order to access content This would enable the user pay, say, one cent to read today s Dilbert cartoon As we know now, such a micropayment system never happened even though it looked like such an obvious thing 20 years ago Instead, a completely different way of paying for online content surfaced  ads I remember seeing the first banner ad on a website, maybe in 1995 or 1996 I chuckled at the idea of a company paying money for showing their ad on someone else s website I should not have chuckled  that same idea now fuels almost all of the content online And highly efficient ad profiling engines create practically all the profit for companies like Google and Facebook Google is a particularly good example of just how profitable user profiling can be Its services   like Search, Youtube, Maps and Gmail   are free You don t pay a cent for using them These services are massively expensive to run  Google s electricity bill alone is more than  100 million a year You would think that a company that runs very expensive services but doesn t charge for them would be making losses   but it isn t In 2013, Google s revenue was  60 billion And their profit was  12 billion So, if we make a modest estimate that Google has one billion users, every user made 12 dollars of profit for Google last year   without paying a cent Frankly, I d be happy to pay Google  12 a year to use their services without tracking or profiling Heck, I would be ready to pay  100 a year  But they don t give me that option We   the users   are more valuable in the long run by having our data and our actions profiled and saved Of course, Google is a business And they are doing nothing illegal by profiling us we volunteer our data to them And their services are great But sometimes I wish things would have turned out otherwise and we would have a simple micropayment system to pay for content and services Now, with the rise of cryptocurrencies, that might eventually become a reality Mikko Hypponen This was originally published as a foreword for F-Secure Threat Report H1 2014 On 18 09 14 At 08 37 AM </description><link>http://www.secuobs.com/revue/news/535482.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/535482.shtml</guid></item>
<item><title>Why do Apple's security questions still suck </title><description>Secuobs.com : 2014-09-16 16:06:37 - F Secure Antivirus Research Weblog -  It's been two weeks, so why do Apple's security questions still suck  Here's an example of questions you'll be asked when you create an Apple ID  Apple Security Questions And here's the full list  Security Question 1    What is your favorite children's book    What is your dream job    What was your childhood nickname    What was the model of your first car    Who was your favorite singer or band in high school    Who was your favorite film star or character in school  Security Question 2    What was the first name of your first boss    In what city did your parents meet    What was the name of your first pet    What is the first name of your best friend in high school    What was the first film you saw in the theater    What was the first thing you learned to cook  Security Question 3    What is the last name of your favorite elementary school teacher    Where did you go the first time you flew on a plane    What is the name of the street where you grew up    What is the name of the first beach you visited    What was the first album that you purchased    What is the name of your favorite sports team  The problem is painfully obvious   the questions are far too subjective or else are based on easily obtainable information What then does one do  Whatever the question, create a nonsense answer But then you'll have another problem  you'll forget the nonsense when needed So what next then  Use your password manager's note field  Childhood nickname  SvenHjerson Hopefully you'll never need to use your answer   make sure nobody else can either   For related advice, please see our article on dealing with passwords On 16 09 14 At 01 46 PM </description><link>http://www.secuobs.com/revue/news/535144.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/535144.shtml</guid></item>
<item><title>A Twitch of Fate  Gamers Shamelessly Wiped Clean</title><description>Secuobs.com : 2014-09-12 14:15:50 - F Secure Antivirus Research Weblog - Twitchtv is a video gaming focused live streaming platform, which has more than 50 million viewers It was acquired recently by Amazoncom for nearly a billion dollars We recently received a report from a concerned user about a malware that is being advertised via Twitchtv s chat feature A Twitchtv bot account bombards channels and invites viewers to participate in a weekly raffle for them to get a chance to win Counter-Strike  Global Offensive items such as  items  165k image  The link provided by the Twitchtv bot leads to a Java program which asks for the participant's name, email address and permission to publish winner's name, but in reality it doesn't store those anywhere Those who have fallen victim to this fake giveaway will be shown this message after entering their details  congrats  17k image  After this message, the malware proceeds to dropping a Windows binary file and executing it to perform these commands    Take screenshots   Add new friends in Steam   Accept pending friend requests in Steam   Initiate trading with new friends in Steam   Buy items, if user has money   Send a trade offer   Accept pending trade transactions   Sell items with a discount in the market This malware, which we call Eskimo, is able to wipe your Steam wallet, armory, and inventory dry It even dumps your items for a discount in the Steam Community Market Previous variants were selling items with a 12pourcents discount, but a recent sample showed that they changed it to 35pourcents discount Perhaps to be able to sell the items faster code_sell_discount  67k image  Being able to sell uninteresting items will allow the attacker to gather enough money to buy items that he deems interesting The interesting items are then traded to an account possibly maintained by the attacker Victims have reported in forumssteamrepcom that their items were being traded to this Steam account without receiving anything in return  steamaccount  113k image  All this is done from the victim's machine, since Steam has security checks in place for logging in or trading from a new machine It might be helpful for the users if Steam were to add another security check for those trading several items to a newly added friend and for selling items in the market with a low price based on a certain threshold This will lessen the damages done by this kind of threat On 12 09 14 At 11 29 AM </description><link>http://www.secuobs.com/revue/news/534658.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/534658.shtml</guid></item>
<item><title>H1 2014 Threat Report</title><description>Secuobs.com : 2014-09-08 15:38:32 - F Secure Antivirus Research Weblog -  Our latest Threat Report is now available H1 2014 at a glance The report includes our statistics, incidents calendar and threatscape summaries for H1 Q1 Q2  2014 Download  H1 2014 Threat Report  PDF  Additional case studies  Whitepapers On 08 09 14 At 01 05 PM </description><link>http://www.secuobs.com/revue/news/533467.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/533467.shtml</guid></item>
<item><title>Security Privacy Identity</title><description>Secuobs.com : 2014-09-05 14:27:35 - F Secure Antivirus Research Weblog -  Key components of digital freedom  Things we defend This is F-Secure Labs On 05 09 14 At 12 07 PM </description><link>http://www.secuobs.com/revue/news/533190.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/533190.shtml</guid></item>
<item><title>Wi-Fi Sense </title><description>Secuobs.com : 2014-09-04 16:16:45 - F Secure Antivirus Research Weblog -  Windows Phone 81  Lumia Cyan  updates are currently rolling-out to various Lumia devices One of the new features is Microsoft's  Wi-Fi Sense  which will automatically connect to Wi-Fi networks and accept terms Wi-Fi Sense Your phone will automatically accept Wi-Fi network terms  Yes Wi-Fi Sense  Not all Wi-Fi networks are secure   At least you're able to edit the infomation provided on your behalf  Wi-Fi Sense Also, Wi-Fi Sense will share Wi-Fi network access with your contacts and  friends  Wi-Fi Sense So  if your phone knows the password to your company's Wi-Fi network, now your Facebook friends can access it too  Information security managers are going to love that On 04 09 14 At 01 26 PM </description><link>http://www.secuobs.com/revue/news/532987.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/532987.shtml</guid></item>
<item><title>Pitou Q A</title><description>Secuobs.com : 2014-08-28 11:52:36 - F Secure Antivirus Research Weblog -  What is Pitou  A recently spotted spambot malware that shares many similarities from the notorious kernel-mode spambot Srizbi After further analysis, we confirmed it is a revival of Srizbi We named this latest malware Pitou After some in-depth analysis, we found some other interesting technical features and wrote a whitepaper on it Why it is called Pitou  The name Pitou came from our colleague's existing detection name for it We decided to use this family name to avoid confusion Another reason why we think this spambot deserves a new name  rather than continuing with the Srizbi moniker, that is  is because the malware code has been completely rewritten with more robust features, including now being equipped with a bootkit Where was it first discovered  We first encountered the threat on a client machine that reported a suspicious system driver file to our automated analytical systems After some manual analysis, we found it to be malicious and containing a payload that is highly obfuscated and protected by Virtual Machine  VM  code This implied that there was something the malware was trying to hide from researchers So naturally we decided to do an in-depth analysis When was it first seen  The threat was first found in April 2014 based on the dates from our sample collection systems, though it may have existed in the wild at an earlier date The whitepaper includes more timeline information Who should be concerned by this threat  This threat could cause havoc or bring inconvenience to both corporate and home users The spambot will utilize an infected machine to spread spam emails, which can lead to the spamming IP address being blacklisted in Realtime Black List  RBL  by an Internet Service Provider  ISP  A blacklisted IP address is blocked from sending  even legitimate  email via standard Simple Mail Transfer Protocol  SMTP , which is commonly configured in most corporate email servers A regular home users meanwhile would be concerned if they use a non-Web based email client, for example Microsoft Outlook, that ends up having its IP address blacklisted by an ISP What are some of Pitou's indicators of compromise  IOC  The threat is not particularly stealthy compared to other modern rootkits We list a couple of IOCs in our document for someone  reasonably technically astute  who is interested in quickly identifying if their machine is Pitou-infected Where can I get the Pitou whitepaper  Click the image below, or visit the technical papers section of our Labs site  pitou_whitepaper_cover  96k image  Post by - Wayne On 28 08 14 At 08 25 AM </description><link>http://www.secuobs.com/revue/news/531960.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/531960.shtml</guid></item>
<item><title>Ransomware Race  part 5  SynoLocker's unkept promises</title><description>Secuobs.com : 2014-08-22 14:54:39 - F Secure Antivirus Research Weblog -  We believe you should never pay a ransom to online criminals The reason is quite simple File-encrypting ransomware holds the victim's personal files  at ransom  until a payment is made For the scheme to work, the victim has to believe that paying up will help However, the only certain outcome from paying criminals is to encourage them to continue their malicious activities  paying the ransom might not actually get you your files back Case in point, a recent ransomware family commonly known as SynoLocker SynoLocker targets network attached storage devices manufactured by Synology Once a device has been infected with SynoLocker, the malware will proceed to encrypt files stored on the device It will also present the victim with a ransom message demanding payment in return for decryption of the files Here, however, the criminals behind SynoLocker make a false promise In many of the cases we have observed, the decryption process didn't actually work or the decryption key provided by the criminals was incorrect Even after being double-crossed by the criminals, all hope is not lost If a victim is able to obtain the correct decryption key, the files can still be restored For this purpose, we are today releasing a small tool, a Python script, written by us This tool can be used to safely decrypt SynoLocker-encrypted files as long as the correct decryption key can be provided The tool does not in any way break the encryption of files created by SynoLocker and it does not attempt to bruteforce the decryption key It will only work, if the decryption key is already known Screenshot of encrypted and decrypted file headers On the left, the beginning of a file encrypted by SynoLocker and, on the right, the beginning of the same file decrypted Another use case for our decryption tool is a situation where a user has paid the ransom but can't use the decryption key as they have removed the SynoLocker malware from the infected device Instead of reinfecting your device with the malware  which is a bad idea , you can use the key together with our script to decrypt your files By releasing this tool to the community at large, we hope that we can contribute to undoing the harm caused by these criminals We never recommend anyone to pay a ransom Our decryption tool, as well as installation and usage instructions, can be found here Post by Artturi  lehtior2  On 22 08 14 At 12 44 PM </description><link>http://www.secuobs.com/revue/news/531067.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/531067.shtml</guid></item>
<item><title>Data vs Metadata</title><description>Secuobs.com : 2014-08-20 15:45:14 - F Secure Antivirus Research Weblog -  Google uses HTTPS for all search queries That's good, because it means that all of the questions you ask  aka your data  will be encrypted However  regardless of HTTPS, inferences about your searches can still be made by somebody with accesses to your network traffic For example  Network Traffic Analysis, Google to AA In the screenshot above, a popular  packet analyzer  displays DNS queries  aka metadata  We first connected our test device to googlecom and performed a search   and then we clicked on the top search result link   and connected to aaorg The deductive reasoning skills of Sherlock Holmes aren't required to figure out  alcoholics anonymous  was searched for And even if aaorg used HTTPS encryption  it doesn't , using DNS metadata, we can still infer the contents of the search data The connections made offer all the evidence needed And that's why metadata matters On 20 08 14 At 01 10 PM </description><link>http://www.secuobs.com/revue/news/530682.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/530682.shtml</guid></item>
<item><title>Ransomware Race  Part 4  Adult Content, Browlock's Staying Power</title><description>Secuobs.com : 2014-08-15 17:00:30 - F Secure Antivirus Research Weblog -  Lately, our eyes have been caught by the rise of Ransomware families It is very evident that the bad guys are constantly developing this type of malware family as seen in our previous posts about CryptoWall and CTB-Locker and Synolocker In addition to these families, we have also been observing a rather simpler type of Ransomware, yet pretty active and very much alive since it was first encountered in 2013 - Browlock Compared to other Ransomware families, Browlock does not encrypt the victim's files, and does not add nor run any files on the victim's machine It only scares the user by  locking  the browser with an alert that claims to be from the police or authorities, stating that the victim has committed a crime by viewing child pornography website or downloading pirated software It prevents the user from closing the browser, but terminating the browser process using task manager, for example, resolves the problem The following are statistics taken from Browlock hits in our telemetry from June onwards HitCount2  51k image  According to our statistics, the target victims were users visiting adult sites More than half of them were redirected to Browlock pages after going to adult-related websites Others were redirected through the use of ad networks We didn t notice any adult website that stood out from our data, however, for the ad networks percentage, almost 60pourcents were from trafficbrokercom alone referer  63k image  Browlock's landing pages have different IPs and URLs from time to time You may see more observation of this from malekal s website  The URLs may look random, however it has noticeable patterns Below are some examples    http  alert policecoin info  FI clsphp   http  alert porschepolice net  FI clsphp   http  alert xraypolice com  FI clsphp   http  alert-police barbrastreisandagent com    http  alert-police estateagentsolutions net    http  attentionstarpolice biz FI clsphp   http  attentionstarpolice co FI clsphp   http  police grantscards com    http  police redunderground com    http  security-scan-nuqbqakx in    http  security-scan-jdytiujg in    http  system-check-abevbrye in    http  system-check-ipxmjdry in    http  security-akechksv-check in    http  security-zxqkcohl-chk in    http  law-enforcement-tqvrlbqb in    http  law-enforcement-icgkjyrr in  From the month of June, we have observed the following most reported URLs in our upstream, with its corresponding IPs where it is hosted  IPtable3  62k image  The graph below shows the duration of these URL patterns being actively reported in our upstream It seems that on average, Browlock was able to keep a single URL pattern of its landing pages for about two weeks to a month long ip_graph2  92k image  We have also noticed that United States, United Kingdom, and countries in Europe were the most affected top5countries  8k image  We ve seen this operation going on for quite a while now, wondering if the bad guys are really getting money from this very simple mechanism We don t really know for sure how many victims have given in into paying a ransom from its fake alert message But what we know for sure, is that while we see this ransomware families being active, we will keep our eyes open to keep protecting our customers from this threat On 15 08 14 At 02 51 PM </description><link>http://www.secuobs.com/revue/news/530092.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/530092.shtml</guid></item>
<item><title>Testing the Xiaomi RedMi 1S - now with OTA update</title><description>Secuobs.com : 2014-08-14 10:27:14 - F Secure Antivirus Research Weblog -  On August 10 Xiaomi addressed privacy concerns related to the MIUI Cloud Messaging function of its smartphones by releasing an OTA update intended to make this an opt-in feature, rather then a default one Since we already had the phone set up, we downloaded and applied the update to the same Redmi 1S phone we used in the previous testing  xiaomi_otaupdate  48k image  xiaomi_phone  124k image  Then we factory reset it Once the phone restarted, we noted that cloud messaging is now by default set to Off under Settings  xiaomi_phone_settings  42k image  We then went through the following steps    Add a new contact   Send and receive an SMS message   Make and receive a phone call During these activities, we did not see any data being sent out from the phone Next, we activated the cloud messaging function and logged into the Mi Cloud At this point, we saw base-64 encoded traffic being sent to https apiaccountxiaomicom  for_xm_cropped  181k image  Note that this is now over HTTPS rather than HTTP, as seen in our previous testing We had to use a HTTPS proxy in order to view what was being passed  traffic_cropped  33k image  This was a quick test to check if the update had addressed points highlighted in various media reports Xiaomi VP Hugo Barra has also posted more details of the MIUI Cloud Messaging implementation On 14 08 14 At 05 42 AM </description><link>http://www.secuobs.com/revue/news/529884.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/529884.shtml</guid></item>
<item><title>Ransomware Race  Part 3  SynoLocker Under The Hood</title><description>Secuobs.com : 2014-08-13 16:30:43 - F Secure Antivirus Research Weblog -  Last week we wrote about a new ransomware family called SynoLocker that was targeting network attached storage devices manufactured by Synology Initial rumours suggested SynoLocker might be related to the infamous CryptoLocker, so we decided to dig deeper On the surface, SynoLocker and CryptoLocker share many similarities, not the least of which are a similar name, similar choice of encryption algorithms and the idea of extorting money from victims Under the surface however, the similarities quickly end When first infected with SynoLocker, a unique RSA key pair is generated for the victim The private key never leaves the malware operator s  but the public key is stored onto the victim device This public key can be used to encrypt data in such a way that it can only be decrypted with the associated private key As long as the malware operator s  are in control of the private key, they can deny the victim access to their encrypted files For encrypting the actual contents of the victims files, SynoLocker uses AES First an initialization vector  IV  is generated from the size and name of the file to be encrypted This IV is later used by the encryption algorithm, but it is also used, combined with a randomly generated string, to generate the actual encryption key Next, the contents of the original file are encrypted Simultaneously, a so-called keyed-hash message authentication code  HMAC , commonly used to verify the integrity of data, is also generated from the unencrypted data Finally, the random string used to generate the key is encrypted using the RSA public key This ensures, that the only way to regenerate the key for decrypting the data, is by first decrypting the random string using the RSA private key Diagram of the encryption process and resulting file Diagram of the encryption process and resulting file Once finished with the encryption of a file, SynoLocker will replace to original with a new one To the new file, SynoLocker first writes the RSA-encrypted random string Next, it writes a marker string  THE_REAL_PWNED_XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX_1337   for those counting, there are 40 Xs  which it uses to identify files it has encrypted After the marker, the IV used in the encryption process is written Next, the encrypted version of the original file contents is written to the new file Finally, the HMAC generated during the encryption process is written to the end of the new file All this is done by SynoLocker in such a way, that were anything to fail or go wrong at any point during the process, the original data would not be lost Only once everything is done, will SynoLocker replace the original file with the new one Finally, it will also attempt to overwrite the original file with random data to make recovery more difficult File encrypted by SynoLocker, as viewed in a hex editor A file encrypted by SynoLocker, as viewed in a hex editor  Arrows pointing to beginning of marker string  When attempting to decrypt files, the above described process is essentially reversed First SynoLocker obtains the random character string by decrypting it with the victims RSA private key Next, the string is used together with the IV obtained from the encrypted file, to generate the actual AES key Finally, the file data is decrypted using this key At the same time, SynoLocker generates a new HMAC from the decrypted data Finally, the HMAC of the original data is compared with the newly generated HMAC and only if they match, is the decryption process deemed successful Again, this ensures, that if anything goes wrong during the process, existing data is not lost In addition to the encryption methods used by SynoLocker, we were also interested in finding out more about the infection vector s  used Despite our best efforts, we have so far been unable to identify the exact infection vector used by SynoLocker It is however clear, that SynoLocker is more a collection of files uploaded to the device through the infection vector, rather than just a single malicious binary These files all have specific purposes and are often dependent on each other to fully function A list of SynoLocker related files is available at the end of this post While analysing the SynoLocker binaries, we have also continued monitoring other aspects of the operation, and it seems the operator s  are on the move Recently, the website where victims are instructed to go to for payment instructions, has been updated The page now includes the notice  This website is closing soon  The operator s  also claim that they are still in possession of over 5500 private keys but that they are willing to sell the entire collection for 200 bitcoins Recent screenshot of SynoLocker website Recent screenshot of SynoLocker website Whether the operator s  follow through with their plans and what that might entail for victims will remain to be seen List of SynoLocker related files   etc synolock server  etc synolock synosync  etc synolock synolock  etc synolock cryptedlog  etc synolock decrytpedlog  spelling mistake in SynoLocker   etc synolock RSA_PUBLIC_KEY  etc synolock RSA_PRIVATE_KEY  etc synolock restore  etc synolock decrypt  etc synolock watchsh  etc synolock uninstallsh  etc synolock watchdogtestsh  usr syno synoman cryptedlog  usr syno synoman decryptedlog  usr syno synoman indexhtml  usr syno synoman redirecthtml  usr syno synoman lockpng  usr syno synoman stylecss  usr syno synoman synolockcodetxt  tmp SYNO_ENCRYPT_LOCK  tmp SYNO_DECRYPT_LOCK  tmp SYNO_SERVER_LOCK  tmp server  usr syno etcdefaults rcd S99bootsh  usr syno etcdefaults rcd S99checksh Sample hashes  9ccd05d4afe6bedac7aa6695c78d5475df5f9b0d  server  c160c1fd18841ebb5e4186ef5ac7ef223b688bc4  synosync  We detect these as Trojan Linux SynoLockerA Post by Artturi  lehtior2  On 13 08 14 At 01 17 PM </description><link>http://www.secuobs.com/revue/news/529729.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/529729.shtml</guid></item>
<item><title>Timo Discusses Dynamic Analysis of Flash Files</title><description>Secuobs.com : 2014-08-12 15:52:56 - F Secure Antivirus Research Weblog -  Senior Researcher Timo Hirvonen presented at Black Hat USA 2014, and publicly released a tool which enables dynamic analysis of malicious Flash files He spoke about it with SC Magazine's Adam Greenberg last week  Video source Download the tool from GitHub  F-Secure   Sulo On 12 08 14 At 01 24 PM </description><link>http://www.secuobs.com/revue/news/529479.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/529479.shtml</guid></item>
<item><title>Testing the Xiaomi RedMi 1S</title><description>Secuobs.com : 2014-08-07 06:18:08 - F Secure Antivirus Research Weblog -  Xiaomi phones have made the news off and on in the last few months for their cheap, value for money phones and corporate moves More recently, there were also reports that these popular devices also silently sent out user details to a remote server That news came on the heels of other reports of smartphones being pre-installed with suspect apps We thought we'd take a quick look into this, so we got our hands on a brand new RedMi 1S  xiaomi_redmi  164k image  We started with a 'fresh out of the box' test, so no account setup was done or cloud service connection was allowed Then we went through the following steps    Inserted SIM card   Connected to WiFi   Allowed the GPS location service   Added a new contact into the phonebook   Send and received an SMS and MMS message   Made and received a phone call We saw that on startup, the phone sent the telco name to the server apiaccountxiaomicom It also sent IMEI and phone number to the same server  xiaomi_data  137k image  The phone number of contacts added to the phone book and from SMS messages received was also forwarded Next we connected to and logged into Mi Cloud, the iCloud-like service from Xiaomi Then we repeated the same test steps as before This time, the IMSI details were sent to apiaccountxiaomicom, as well as the IMEI and phone number At this point, this was just a quick test to see if the behavior being reported can be confirmed In response to the reports, Xiaomi itself has released a statement addressing potential privacy concerns  In Chinese on the company's Hong Kong Facebook page, with an English translation linked  On 07 08 14 At 03 42 AM </description><link>http://www.secuobs.com/revue/news/528712.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/528712.shtml</guid></item>
<item><title>Ransomware Race  part 2  Personal media the next frontier </title><description>Secuobs.com : 2014-08-06 12:18:25 - F Secure Antivirus Research Weblog -  It seems malware authors have recently taken a liking to the network-attached storage  NAS  devices manufactured by Synology Inc First they were hit by Bitcoin mining malware in the beginning of this year and now by file encrypting ransomware similar to CryptoLocker NAS devices are used by home and business users alike to easily store and share files over a network Many, like ones manufactured by Synology, also feature remote access In this case, it would seem hackers were able to abuse the remote access feature, possibly by exploiting a vulnerability in older versions of the Synology DSM -operating system, to gain access to the devices Once they had access, they proceeded to install a ransomware they have dubbed  SynoLocker  Once the device has been infected with SynoLocker, the malware will proceed to encrypt files stored on the device It will search the device for files with extensions matching a hardcoded list  shown below  Extensions are matched such, that only the beginning of the extension needs to match the hardcoded list This means, for instance, that both doc and docx files will be encrypted, since the list contains  do  Screenshot of extension list hardcoded inside SynoLocker Extension list hardcoded inside SynoLocker Once all files have been encrypted, SynoLocker will present the user with a ransom message The ransom message instructs the user to first download and install the Tor Browser Bundle Next, users are to browse to a specific website on the Tor network On that website, users will be further instructed to make a payment of 06 BTC  approximately 260  or 350USD  to a specific Bitcoin wallet Once payment has been received, the malware author s  promise to supply the user with a decryption key for recovering their files synolocker  98k image  Screenshot of the SynoLocker page on the Tor network as presented to victims The ransom message presented by the malware also purports to describe the technical details of the encryption process The process described is very similar to the process used by the infamous CryptoLocker ransomware family The process begins with the generation of a unique RSA-2048 keypair on a remote server Next, the generated public key is passed to the malware When encrypting files, the malware will generate a separate, random 256-bit key that is used to encrypt the files with the AES-256 CBC symmetric cypher The key used for this encryption process is next encrypted with the RSA-2048 public key and stored on the device before being removed from the device memory If implemented correctly, this process ensures, that the only way to restore the encrypted files is by obtaining the RSA-2048 private key and first decrypting the file containing the 256-bit encryption key used Based on our analysis of SynoLocker, the malware author s  have followed through with their threats and have properly implemented the process described Sadly this means any files stored on the NAS device will have been lost unless the user has kept a separate backup There have also been reports of users paying the malware author s  and successfully receiving the RSA-2048 private key and decrypting their files, but we strongly discourage ever paying malware authors It only encourages them to continue their malicious work For users of Synology NAS devices, we highly recommend following Synology's official advice on mitigating or remediating this threat Sample hashes  9ccd05d4afe6bedac7aa6695c78d5475df5f9b0d c160c1fd18841ebb5e4186ef5ac7ef223b688bc4 We detect these as Trojan Linux SynoLockerA Post by Artturi  lehtior2  On 06 08 14 At 09 36 AM </description><link>http://www.secuobs.com/revue/news/528581.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/528581.shtml</guid></item>
<item><title>Ransomware Race  Part 1  CryptoWall ups the ante</title><description>Secuobs.com : 2014-08-05 14:00:14 - F Secure Antivirus Research Weblog -  This summer has included the appearance of two strong new malware families onto the file encrypting Windows ransomware market  CryptoWall and CTB-Locker Of these, CTB-Locker has been the more advanced family, with its use of elliptic curve cryptography for file encryption and Tor for communication with the command   control server CryptoWall, meanwhile, has used the more traditional combination of RSA and AES for file encryption and HTTP for C C communication At the end of last month, however, a new version of CryptoWall emerged into the wild This latest version is mostly identical to earlier versions in functionality but with one important difference CryptoWall now also uses Tor for communicating with its command   control servers Like CTB-Locker, CryptoWall doesn't take the traditional easy approach of using the legitimate Tor-executable obtained from the project's official website, but instead uses it's own obfuscated version of Tor Disassembly of CryptoWall with Tor functionality Disassembly of CryptoWall without Tor functionality On the left, CryptoWall with Tor functionality, and on the right, CryptoWall without Tor functionality Note that except for the call to f_setupTorCommunication , the code is identical The approach used by CryptoWall is interesting First, it attempts to connect over HTTP to a number of hardcoded URLs From these URLs it attempts to download an RC4 encrypted file The file is structured to first contain the length of the encryption key used, followed by the key itself Next it contains the length of the actual payload and finally the payload itself Once the malware has successfully downloaded the payload and decrypted it, it is copied to a newly allocated memory segment and a new thread is created to execute the payload Screenshot of payload in a hexeditor Beginning of the downloaded payload as viewed in a hexeditor The payload itself is a custom version of Tor wrapped inside two layers of obfuscation Once both layers have finished execution and unpacked the final code into memory, the payload will attempt to establish a connection to the Tor network Once the connection has been established, a flag value will be set by the payload in a global memory buffer shared by both the payload thread and the original CryptoWall thread The payload will also set a pointer in the same buffer to point to one of the payload's functions This is the function that is actually responsible for sending and receiving data Once the original CryptoWall thread sees that the global flag has been set, it will then continue with its own execution The addresses of three command   control servers on the Tor -network are hardcoded in the original CryptoWall binary, not in the payload The actual message contents of the C C communication are also handled by code from the original binary The payload is only responsible for handling the Tor-connection and sending and receiving the data Perhaps ransomware operators were switching from CryptoWall to CTB-Locker Or perhaps the author s  of CryptoWall just don't like being second best In any case, the competition for nastiest piece of ransomware is still on  CryptoWall samples with Tor functionality  3370f29350115af162b613c45fd5a6a44315a213 6698bb2df60685863a664e282e493ca1e886fec3 Post by Artturi  lehtior2  On 05 08 14 At 11 23 AM </description><link>http://www.secuobs.com/revue/news/528428.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/528428.shtml</guid></item>
<item><title>BackdoorGates  Also Works for Windows</title><description>Secuobs.com : 2014-08-01 11:11:59 - F Secure Antivirus Research Weblog -  We have received reports about a Linux malware known as BackdoorGates Analysis showed that this malware has the following features    Collects information on the compromised system, such as OS version, hard disk size etc   Connects to a C C server for further information The server address and port are RSA-encrypted   Can perform a host of different DDoS attacks    TCP-SYN flood   UDP flood   DNS flood   ICMP flood   HTTP flood   DNS Amplification It's notable that this backdoor makes use of this file for its installation   etc initd DbSecuritySpt Interestingly, the string  DbSecuritySpt  is a service name also used by another, a Windows malware After a closer look, we found out that they are more alike than we initially thought Both of them use the same names for the main file and the dropped components For example, the main component is named as  gates  in the Linux version, and  Gatesexe  in the Windows version The attack tool is called  bill  in the Linux version and  Billexe  in the Windows version The DNS amplification library is  libamplifyso  or  libamplifydll , and so on This was too much of a coincidence, so it turned out pretty quickly that they are actually recompiled ports of the same malware The malware is written in C  and the compiled code, by a quick glance, looks quite different, but closer investigation reveals that they must share the some code base There are some OS-centric portions of the code, such as thread handling, service installation  on Windows, it is installed as a service  DbSecuritySpt , while on Linux it is a startup script in  etc initd DbSecuritySpt  However, there are other similar parts, such as a simple file handling which uses fopen  and fread  among others Using those standard C-functions is quite uncommon for a Windows programmer It is then most likely that both variants are compiled from the same code base, with some heavy platform-specific  ifdef's Screenshot of Windows code  windows  139k image  Screenshot of Linux code  linux  141k image  With a multi-platform malware like BackdoorGates, it is always interesting to find out how it is installed We don't fully understand this yet Based on initial analysis, there seems to be no automatic propagation or exploit functionality in the malware The reports that we have received indicate that the malware was installed using weak SSH-server passwords, at least on Linux boxes More analysis on the Linux part of BackdoorGates have also been published by Kaspersky and DrWeb -- Post by Jarkko On 01 08 14 At 08 47 AM </description><link>http://www.secuobs.com/revue/news/527937.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/527937.shtml</guid></item>
<item><title>Diving Deep into Mayhem</title><description>Secuobs.com : 2014-07-24 10:03:14 - F Secure Antivirus Research Weblog -  Malware targeting Linux servers has been increasingly hitting the headlines over the past year In this post we will present research on an advanced and highly versatile malware operation targeting Linux and FreeBSD servers We have named the malware family at the heart of this operation GalacticMayhem, as a reference to some of the C C urls It is the same family of malware that was written about by a team of researchers from Yandex Overview Infection of a server with Mayhem begins with a PHP dropper script This script is responsible for dropping a malicious ELF shared object file and executing it The dropped binary is usually named libworkerso but our research has also uncovered cases where the binary was called atom-aggregatorso or rss-aggrso The dropper script always includes both a 32-bit and a 64-bit version of the malware These are of identical functionality and configuration The dropper script first kills all running  usr bin host -processes Next it checks whether the host is 32-bit or 64-bit and Linux or FreeBSD The script then picks the correct binary for the host architecture, adjusts its ELF header to take into account the operating system and finally writes the binary to disk The dropper also writes to disk a shell script named 1sh The shell script is responsible for clean up and for executing the malware It accomplishes this using the so called 'LD_PRELOAD' -technique in which an environment variable, 'LD_PRELOAD' is set with the path to the dropped binary Next, the executable  usr bin host is executed The OS loader loads the malicious binary allowing it to hook the exit -function that will eventually get called by  usr bin host Once  usr bin host calls exit, execution gets passed to the malicious binary Our research has so far uncovered 47 unique Mayhem samples The earliest of these samples are at least half a year old, the newest possibly less than a week old From analysing the samples, it is clear that Mayhem has gone through three major iterations during its development Each iteration has made the malware increasingly more complex and advanced In addition, smaller, incremental updates have been observed This shows that the Mayhem family of malware is under active development The rest of this post will focus on the latest and most feature-rich iteration of Mayhem The Mayhem malware is designed to be highly modular It consists of a main component and multiple optionally loaded modules The main component is responsible for communicating with the C C as well as loading, unloading and executing the modules The malware also uses a hidden, encrypted filesystem to store the modules themselves as well as other files used by the modules This filesystem is stored on disk, in a file whose name is specified as part of the malware's configuration data In most cases the file has been named sd0 However, we have recently observed the malware author s  switching to naming the file caches This is possibly in response to the name of the hidden filesystem file being published in multiple sources and being used to search for infected systems Again, it is clear that the malware is under active development It should be noted that the size of the hidden filesystem file is also specified in the malware configuration data and has been exactly 12MB in all the cases we have observed The Mayhem malware communicates with its C C server using specially crafted HTTP post -requests The headers of these requests are highly distinctive because they only contain 3 specific fields, the 'Host', 'Pragma' and 'Content-Length' -fields Of these, the value of the 'Pragma' -field is always '1337' Additionally, the HTTP version is always specified as 10 An example of a request from the malware to its C C server can be seen below Packet capture of malware communicating with C C As can be seen, the actual body of the request consists of one or more lines specifying commands or messages These lines always begin with a single character specifying the message type followed by a comma-delimited list of parameters The supported message types enable, among others, the sending and receiving of data and files, the starting and stopping of jobs, the loading and updating of modules and reporting malware status to the C C After infection and setup, the malware will attempt to send a request to the C C server hardcoded in its configuration data This request will contain information on the host system and the environment the malware is operating under Once the malware receives a satisfactory reply from the C C server, it will revert to regurlarily sending a request to the C C server reporting its current status If the C C server is currently not participating in any specific activity, it will reply instructing the malware to sleep and ping back again later The C C server can also reply to the malware with a new job In this case, the C C will first instruct the malware on a module to load as well as optionally instructing additional files for the module to load, like rule files or password lists In this case, the malware will first search its hidden filesystem for the module specified and if found, reply to the C C server with a CRC-32 checksum of the module The C C server will then reply informing the malware whether the module found is the latest version or whether the malware should request a newer version from the C C server If the module found is an old version or if the module is not found at all, the malware will request the module from the C C server as base64 encoded data in a HTTP response Once the module has been acquired, the main component of the malware will load the module and call an entrypoint function This entrypoint function will perform additional setup and possibly request additional files from the hidden filesystem or C C server This function will also register one to four callback functions to be called by the main component under specific circumstances This is how the main functionality of the module will get executed After the module has been successfully loaded, the C C server may instruct the main component to start a new job This will result in the main component creating an operator-specified number of threads each executing the functionality of the loaded module Finally the C C server will begin sending argument strings to the malware for the module to process The contents of these argument strings depend on the loaded module, but usually contain at least a target domain or URL for the malicious activity Modules During our research, we have encountered, in the wild, 11 different modules used by the Mayhem malware For most of these, we have observed multiple distinct versions This clearly shows that also the modules are under active development The modules we have encountered are    bruteforceso - used to brute force login credentials of WordPress and Joomla sites   bruteforcengso - same as above, but with HTTPS and regex support and higher configurability   cmsurlsso - used to identify WordPress login pages   crawlerso - used to crawl websites to find WordPress and Joomla sites   crawlerngso - an improved version of the above, with HTTPS and regex support, capable of finding webpages matching any regular expression   crawleripso - same as above, but receives a list of target IPs instead of domains   ftpbruteso - used to brute force login credentials of FTP servers   rfiscanso - used to look for websites with RFI vulnerabilities   wpenumso - used to enumerate users of WordPress sites   opendnsso - used to search for open recursive DNS resolvers   heartbleedso - used to identify servers exhibiting the so called Heartbleed-vulnerability  CVE-2014-0160  This post will not go into great detail about each module individually, but will cover some of our more interesting findings bruteforceso The bruteforceso -module is the by far the most common module in active use right now  more on this later  It is quite simple in functionality It takes a target url pointing to the login page of a WordPress or Joomla site, a file listing usernames and a file listing passwords Then it tries to log in with every possible username and password combination bruteforcengso This module is an advanced version of the bruteforceso -module with added support for HTTPS and regular expressions In addition to taking as input a target url, a file of usernames and a file of passwords, this module also requires a rule file The rule file is used to specify the login interface of the targets Therefore this module can be used to brute force the login credentials of any web-based interface We have observed this module being used mainly to brute force the login credentials of WordPress and Joomla sites However, we have reason to believe it has also been used against other kinds of sites, for example cPanel Web Host Manager sites What is interesting to note is that we recently uncovered new versions of the bruteforceso and bruteforcengso modules Whereas the old versions tried all the usernames in the username -file against all targets, the new versions allow the C C to specify a single username to use The command string used by the C C to specify target urls is  Q,target  where 'target' is the url Commands to the new versions however support a longer command string,  Q,target username  Note the addition of a semi-colon and another parameter This additional parameter can specify a single username that is then combined with all passwords in the password file If, however, the username string is 'no_matches' or no second parameter is specified, the module falls back to the old method of trying every username in a separate username file crawlerngso The crawlerngso -module is used to crawl websites It takes as argument a file containing regular expressions It then searches target domains for content matching those regular expressions It seems to be mainly used for identifying login pages of WordPress and Joomla sites However, due to its rules being regular expressions, the module can be instructed to identify essentially any kinds of pages As an example, we have also observed the crawlerngso -module being used to identify PhpMyAdmin, DirectAdmin and Drupal login pages In some cases, the module has been used to find websites featuring content matching specific keywords, for instance pharmacy -related keywords In one case we even observed the malware operator s  getting creative and using the crawlerngso -module to look for local file inclusion -vulnerabilities Most of the rulesets we have observed have also instructed the module to search for links leading to other HTTP-, HTTPS- or FTP-sites In this way the module keeps finding new targets to crawl Screencapture of LFI rule file Some of the rules used to look for LFI vulnerabilities opendnsso This module is used to search for open recursive DNS resolvers that could be used in DNS amplification attacks The module takes as argument an IP address range and a threshold size It then iterates through all IPs in the range attempting to connect to port 53 at each one If it successfully connects to port 53, it next sends a DNS request asking for ANY records for the domain 'ripenet' with recursive and extended DNS 'DNSSEC OK' -bits set If the target is running an open recursive DNS resolver, it will reply with a large DNS answer The size of the reply is compared to the previously set threshold size and if it is larger, the IP address is reported back to the C C Packet capture of the DNS request Packet capture of the DNS request sent by the module heartbleedso This module tries to identify whether a target domain is vulnerable to the Heartbleed-vulnerability It does this by first connecting to the target, then sending it a TLSv11 ClientHello packet followed by a heartbeat request with a payload size of 64KB  0xFFFF bytes  but an actual payload of only 3 bytes TLSv11 ClientHello packet Malicious heartbeat request The payloads of the ClientHello packet  above  and the malicious heartbeat request Finally, the size of the payload in the server reply is checked If it is larger than 3 bytes, the server is probably vulnerable and this is reported to the C C Code that checks the server reply Code that checks the server reply Current activity Our research has uncovered 19 C C domains used by the Mayhem malware family Of these, 7 are currently active Most of the current activity is related to the brute forcing of WordPress and Joomla login credentials However we have also observed the brute forcing of FTP login credentials as well as the crawling of domains in search of WordPress and Joomla login pages We also have evidence of other modules being used in the wild at one time or another From our observations of the brute forcing activity, it seems highly opportunistic The malware operator s  seem to focus on volume and rely on enough sites using common and weak credentials During a week of logging target urls from the active C C servers, we identified over 350 000 unique targets Of these, a single C C server was responsible for over 210 000 unique targets It should be noted, that these are only the targets given to single instances of the malware, so the total volume is probably much larger Based on our analysis of target domains, we don't believe the malware operator s  to be targeting anyone or anything specifically Rather, we believe they are simply searching for the web's low hanging fruit This is further supported by the geographic distribution of target domains as seen below The absence of China from the top 10 is notable, but we believe this to be an anomaly rather than an intentional choice on the part of the malware operator s  Piechart showing geographic distribution of target domains Conclusions We believe the malware operator s  use Mayhem primarily as a reconnaisance tool and to gain access to easily compromised servers that can later be used as a base for more sophisticated attacks As an example, the operator s  might first use the crawlerngso -module to find WordPress sites, then enumerate potential victim usernames from those sites using the wpenumso -module Armed with a list of usernames, the operator s  can turn to the bruteforceso -module to attempt to gain access to those sites Once they have gained access, they can either infect it with Mayhem to expand their botnet, or possibly use it for mounting other operations The Mayhem family of malware is an advanced and extremely versatile threat operating on Linux and FreeBSD servers It is clearly under active development and its operator s  actively try to counter the efforts of researchers and server administrators The size of the operation is also significant taking into account the fact that all of the infected hosts are servers with high capacity and bandwith, not your run-of-the-mill home PCs behind a slow ADSL Sample hashes Version 1   0f1c66c3bc54c45b1d492565970d51a3c83a582d   5ddebe39bdd26cf2aee202bd91d826979595784a   6c17115f8a68eb89650a4defd101663cacb997a1 Version 2   7204fff9953d95e600eaa2c15e39cda460953496   772eb8512d054355d675917aed30ceb41f45fba9 Version 3  newest    1bc66930597a169a240deed9c07fe01d1faec0ff   4f48391fc98a493906c41da40fe708f39969d7b7   6405e0093e5942eed98ec6bbcee917af2b9dbc45   6992ed4a10da4f4b0eae066d07e45492f355f242   71c603c3dbf2b283ab2ee2ae1f95dcaf335b3fce   7b89f0615970d2a43b11fd7158ee36a5df93abc8   90ffb5d131f6db224f41508db04dc0de7affda88   9c7472b3774e0ec60d7b5a417e753882ab566f8d   a17cb6bbe3c8474c10fdbe8ddfb29efe9c5942c8   ab8f3e01451f31796f378b9581e629d0916ac5a5   c0b32efc8f7e1af66086b2adfff07e8cc5dd1a62   c5d3ea21967bbe6892ceb7f1c3f57d59576e8ee6   cb7a758fe2680a6082d14c8f9d93ab8c9d6d30b0   e7ff524f5ae35a16dcbbc8fcf078949fcf8d45b0   f73981df40e732a682b2d2ccdcb92b07185a9f47   fa2763b3bd5592976f259baf0ddb98c722c07656   fd8d1519078d263cce056f16b4929d62e0da992a We detect these as Backdoor Linux GalacticMayhemA Written and researched by Artturi Lehtio  lehtior2  Author's note I'm a computer science student at Aalto University in Helsinki, Finland After attending a course this spring on malware analysis, offered by Aalto University and run by F-Secure, I was lucky enough to get hired by F-Secure for a summer internship A month ago I was given a new task   go find an interesting looking piece of Linux malware with the goal of writing a blog post about it  The above post and the research to back it up, are the results of my adventure into the mysterious world of Linux malware On 24 07 14 At 07 24 AM </description><link>http://www.secuobs.com/revue/news/526693.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/526693.shtml</guid></item>
<item><title>Trojan W32 Lecpetex  Bitcoin miner spreading via FB messages</title><description>Secuobs.com : 2014-07-09 06:17:00 - F Secure Antivirus Research Weblog -  In early March this year, while investigating various threats as part of our Facebook malware cleanup effort, we ran across an interesting one that was spreading in zipped files attached to messages The messages themselves were classic social engineering bait that lead the users to install the executable file in the attachment, which turned out to be a Bitcoin miner, which we identify as Trojan W32 Lecpetex Some of the more interesting details of our analysis are presented in our Lecpetex whitepaper lecpetex_cover  66k image  Post by   Mangesh On 09 07 14 At 03 22 AM </description><link>http://www.secuobs.com/revue/news/524263.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/524263.shtml</guid></item>
<item><title>Do you take your coffee with  Free  Wi-Fi </title><description>Secuobs.com : 2014-07-03 17:40:19 - F Secure Antivirus Research Weblog -  Colleagues of ours recently visited a Starbucks in San Francisco and used the Wi-Fi Starbucks WiFi, Welcome And while there, they grabbed a copy of AT T's T C It's rather standard stuff, nothing there as surprising as last week's post Here's the bit about security  Starbucks WiFi, AT T Terms and Conditions  The unsecured nature and ease of connection to public Wi-Fi hotspots increases the risk that unauthorized persons can access your phone, laptop or other device or your communications over the Wi-Fi network Wi-Fi customers should take precautions to lower the security risks If you have VPN, AT T recommends that you connect through it for optimum security  So there you have it  AT T recommends that you use a VPN for  optimum  security But wait  AT T Wi-Fi  That's on the way out  coming soon  Google Google Starbucks Starbucks' WiFi goes Google Google Wi-Fi at Starbucks  Those Terms and Conditions are undoubtedly worth a read   we'll try to  track  them down  Privacy On 03 07 14 At 03 20 PM </description><link>http://www.secuobs.com/revue/news/523591.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/523591.shtml</guid></item>
<item><title>CosmicDuke  Cosmu With a Twist of MiniDuke</title><description>Secuobs.com : 2014-07-02 18:08:25 - F Secure Antivirus Research Weblog -  The backdoor known as  MiniDuke  was identified in Feburary 2013, discovered in a series of attacks against NATO and European government agencies During MiniDuke analysis in April 2014, we determined that another malware family was using the same loader as MiniDuke stage 3 That malware is part of the Cosmu family of information-stealers which have been around for years What makes the connection to MiniDuke interesting is that, based on compilation timestamps, it was Cosmu, not MiniDuke, which originally used the common shared loader Moreover, we found that the loader was updated at some point, and both malware families took the updated loader into use Since Cosmu is the first malware known to share code with MiniDuke, we decided to name the samples showing this amalgamation of MiniDuke-derived loader and Cosmu-derived payload as CosmicDuke Duke on the Craters Edge, GPN-2000-001132  Image  NASA   Charles M Duke, lunar module pilot of Apollo 16  The filenames and content used in CosmicDuke's attack files to lure victims contain references to the countries of Ukraine, Poland, Turkey, and Russia, either generally in use of language or included detail, or in allusions to events or institutions The filenames and content chosen seem to be tailored to their target s interests, though we have no further information on the identity or location of these victims yet CosmicDuke infections start by tricking targets into opening either a PDF file which contains an exploit or a Windows executable whose filename is manipulated to make it look like a document or image file Some of the samples display a decoy document to the user This one was named Ukraine-Gas-Pipelines-Security-Report-March-2014pdf  CosmicDuke decoy Here's a rather different kind of a decoy, showing a receipt of a payment in Russian An interesting detail about the image file is that it contains EXIF metadata, including the date when the photo was taken and the model of the mobile phone that was used to take the photo CosmicDuke decoy Once the target opens the malicious file, CosmiDuke gains persistence on the system and starts collecting information The data collection components include a keylogger, clipboard stealer, screenshotter, and password stealers for a variety of popular chat, e-mail and web browsing programs CosmicDuke also collects information about the files on the system, and has the capability to export cryptographic certificates and the associated private keys Once the information has been collected, it is sent out to remote servers via FTP In addition to stealing information from the system, CosmicDuke allows the attacker to download and execute other malware on the system F-Secure has detections for all of the different malicious components used by the CosmicDuke samples known to us To learn more about the technical details, please see our CosmicDuke malware analysis report Post by   Timo On 02 07 14 At 03 55 PM </description><link>http://www.secuobs.com/revue/news/523339.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/523339.shtml</guid></item>
<item><title>Beware BlackEnergy If Involved In Europe Ukraine Diplomacy</title><description>Secuobs.com : 2014-06-30 10:59:45 - F Secure Antivirus Research Weblog -  The universe is full of  Black Energy  and so is cyberspace Not so very long ago, we wrote about a sample of the BlackEnergy family discovered via VirusTotal The family is allegedly the same malware used in the cyber-attack against Georgia in 2008 Last Friday, another fresh variant was submitted to VirusTotal And this time it is more obvious on how it was being distributed  a zip file containing an executable Again, as was the case earlier this month, the sample was submitted from Ukraine Zip file screenshot The filename of the zip file means  password list  spelled out in the Cyrillic alphabet For the executable, it means the same but spelled out in the Latin alphabet Take note that the executable has a doc extension It is not clear how the sample can be run by the victim Our guess is that there might be a zip application used by the intended target which supports opening samples based on their true file type regardless of their extension Of course it is also possible that the attackers just made a mistake Checking the instance of the executable in VirusTotal, it was submitted from Belgium just a few minutes earlier Given the current situation in Ukraine, and that Belgium is the center of the European Union government  and where NATO Headquarters is located , we cannot discount the theory that they are related We think the sample is possibly sent as attachment in spear-phishing e-mails pretending to be IT advisories warning people to avoid certain passwords Unlike the earlier variant, the sample no longer uses a kernel mode component to inject the user mode DLL into svchostexe This time it just uses a user mode dropper to load the DLL via rundll32exe Ditching the kernel mode component might be an attempt to get around the driver signing enforcement protection found in modern Windows systems The user mode DLL has also been rewritten  timestamp of June 26, 2014  to support the change It now has a different configuration format but still uses a C C that falls under the same IP address block  New BlackEnergy configuration The dropper will also open a decoy document to hide its malicious activity  Decoy document Take note that there is no software vulnerability or exploit involved The decoy document is created and opened by the dropper programmatically This is something similar to what we have seen before in what might be the first documented APT attempt in OS X The malware did however exempt its host process  rundll32exe  from DEP, which may open up an attack surface for future exploitation  Routine that disables DEP via registry Bottom line  if you're involved in European Ukrainian diplomacy  beware BlackEnergy On 30 06 14 At 05 08 AM </description><link>http://www.secuobs.com/revue/news/522831.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/522831.shtml</guid></item>
<item><title>ICS-CERT  Amber  ALERT-14-176-02</title><description>Secuobs.com : 2014-06-27 17:19:34 - F Secure Antivirus Research Weblog -  ICS-CERT has posted a TLP Amber report to its secure portal related to our analysis of ICS SCADA-focused Havex components ICS-Alert-14-176-02 For more information  ICS_CERT  ICS-ALERT-14-176-02 Dark Reading  As Stuxnet Anniversary Approaches, New SCADA Attack Is Discovered On 27 06 14 At 03 04 PM </description><link>http://www.secuobs.com/revue/news/522587.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/522587.shtml</guid></item>
<item><title>You Are Responsible For Your Security And Privacy</title><description>Secuobs.com : 2014-06-26 15:19:02 - F Secure Antivirus Research Weblog -  I visited London on Monday And I decided to try Heathrow Express  HEX  to get from the airport to London's center I'm glad that I did   it was a smooth, fast, and quiet ride Oh  Also, HEX offers  free  Wi-Fi  Me being me, I decided to actually read the Terms   Conditions Heathrow Express CONSENT TO MONITORING  Consent To Monitoring  INCLUDING THEIR CONTENT  YOU ARE RESPONSIBLE FOR YOUR SECURITY AND PRIVACY  You Are Responsible For Your Security And Privacy You know what  Yeah, that's true, you are in fact responsible for your own security and privacy Protip  there's no such thing as free Wi-Fi To utilize open Wi-Fi without your content to be monitored while you do so  try Freedome Regards   5ean5ullivan PS I plan to post more terms and conditions as I discover them I welcome your submissions On 26 06 14 At 12 46 PM </description><link>http://www.secuobs.com/revue/news/520836.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/520836.shtml</guid></item>
<item><title>Havex Hunts for ICS SCADA Systems</title><description>Secuobs.com : 2014-06-24 09:02:39 - F Secure Antivirus Research Weblog -  During the past year, we've been keeping a close eye on the Havex malware family and the group behind it Havex is known to be used in targeted attacks against different industry sectors, and it was earlier reported to have specific interest in the energy sector The main components of Havex are a general purpose Remote Access Trojan  RAT  and a server written in PHP The name  Havex  is clearly visible in the server source code  Havex server source code During the spring of 2014, we noticed that Havex took a specific interest in Industrial Control Systems  ICS  and the group behind it uses an innovative trojan horse approach to compromise victims The attackers have trojanized software available for download from ICS SCADA manufacturer websites in an attempt to infect the computers where the software is installed to We gathered and analyzed 88 variants of the Havex RAT used to gain access to, and harvest data from, networks and machines of interest This analysis included investigation of 146 command and control  C C  servers contacted by the variants, which in turn involved tracing around 1500 IP addresses in an attempt to identify victims The attackers use compromised websites, mainly blogs, as C C servers Here are some examples of command and control servers used  Havex C2 servers We also identified an additional component used by the attackers that includes code to harvest data from infected machines used in ICS SCADA systems This indicates that the attackers are not just interested in compromising the networks of companies they are interested in, but are also motivated in having control of the ICS SCADA systems in those organizations The source of this motivation is unclear to us Trojanized Software as an Infection Vector The Havex RAT is distributed at least through following channels    Spam email   Exploit kits   Trojanized installers planted on compromised vendor sites The spam and exploit kit channels are fairly straightforward distribution mechanisms and we won't analyze them in more detail here Of more interest is the third channel, which could be considered a form of  watering-hole attack , as the attackers chose to compromise an intermediary target - the ICS vendor site - in order to gain access to the actual targets It appears the attackers abuse vulnerabilities in the software used to run the websites to break in and replace legitimate software installers available for download to customers Our research uncovered three software vendor sites that were compromised in this manner The software installers available on the sites were trojanized to include the Havex RAT We suspect more similar cases exist but have not been identified yet Based on the content of their websites, all three companies are involved in development of applications and appliances for use in industrial applications These organizations are based in Germany, Switzerland and Belgium Two of them are suppliers of remote management software for ICS systems and the third develops high-precision industrial cameras and related software As an example, we can see the partial results of dynamic analysis for one of the trojanized installers  Trojanized installer The normal, clean installer does not include a file called  mbcheckdll  This file is actually the Havex malware The trojanized software installer will drop and execute this file as a part of the normal installation The user is left with a working system, but the attacker now has a backdoor to access and control the computer Target Organizations We were able to locate some of the infected systems and identify the organization affected by the samples analyzed in this report by tracing the IP addresses communicating to the C C servers used by the Havex RAT All of these entities are associated in some way with the development or use of industrial applications or machines The majority of the victims are located in Europe, though at the time of writing at least one company in California was also observed sending data to the C C servers Of the European-based organizations, two are major educational institutions in France that are known for technology-related research  two are German industrial application or machine producers  one is a French industrial machine producer  and one is a Russian construction company that appears to specialize in structural engineering ICS SCADA Sniffer Our analysis of Havex sample codes also uncovered its  ICS SCADA sniffing  behavior The C C server will instruct infected computers to download and execute further components, and one of these components appeared very interesting While analyzing this component, we noticed that it enumerates the local area network and looks for connected resources and servers  Havex scans LAN We then noticed that it uses Microsoft Component Object Model  COM  interfaces  CoInitializeEx, CoCreateInstanceEx  to connect to specific services  Havex calls COM To identify which services the sample is interested in, we can simply search for the identifiers seen above, which tell us what kind of interfaces are being used A bit of googling gives us these names    9DD0B56C-AD9E-43EE-8305-487F3188BF7A   IID_IOPCServerList2   13486D51-4821-11D2-A494-3CB306C10000   CLSID_OPCServerList Note the mention of  OPCServer  in the names There are more hints pointing in the same direction -- the strings found in the executable also make several references to  OPC  Havex OPC strings It turns out that OPC stands for OLE for Process Control, and it's a standard way for Windows applications to interact with process control hardware Using OPC, the malware component gathers any details about connected devices and sends them back to the C C for the attackers to analyze It appears that this component is used as a tool for intelligence gathering So far, we have not seen any payloads that attempt to control the connected hardware Summary The attackers behind Havex are conducting industrial espionage using a clever method Trojanizing ICS SCADA software installers is an effective method in gaining access to target systems, potentially even including critical infrastructure The method of using compromised servers as C C's is typical for this group The group doesn't always manage the C C's in a professional manner, revealing lack of experience in operations We managed to monitor infected computers connecting to the servers and identify victims from several industry sectors The additional payload used to gather details about ICS SCADA hardware connected to infected devices shows the attackers have direct interest in controlling such environments This is a pattern that is not commonly observed today SHA-1 hashes of the samples discussed  7f249736efc0c31c44e96fb72c1efcc028857ac7 1c90ecf995a70af8f1d15e9c355b075b4800b4de db8ed2922ba5f81a4d25edb7331ea8c0f0f349ae efe9462bfa3564fe031b5ff0f2e4f8db8ef22882 F-Secure detects this threat as Backdoor W32 HavexA -- Post by Daavid and Antti On 23 06 14 At 02 46 PM </description><link>http://www.secuobs.com/revue/news/520372.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/520372.shtml</guid></item>
<item><title>SLocker Android Ransomware Communicates Via TOR And SMS</title><description>Secuobs.com : 2014-06-16 17:49:37 - F Secure Antivirus Research Weblog -  A little over two weeks ago, we found a new family of Android ransomware  SLocker We have no evidence that SLocker is related to Koler, the most recently discovered Android ransomware It does however carry through on the threat Koler made Unlike Koler   which pretended to, but didn't actually encrypt files   SLocker will actually scan the device's SD card for specific file types  slocker  3k image  When the SLocker app is launched, it encrypts these files and then displays a ransom message  Ukraine ransom The message informs the user they must transfer a payment via an online money transfer service in order to recover the files The phone number listed in the message on the left is based in Ukraine Currently there are two versions of this family The first version uses the TOR anonymizing network to communicate between infected phones and the malware's C C-server We suspect this version might be a testing revision because all debug information is available The second SLocker version appeared at the same time as the TOR-enabled version but is simplified This version shares much the same code  including encryption and the same hardcoded decryption key  but the debugging parts are no longer present The main difference though is that this version doesn't use TOR Instead, it takes its commands via SMS messages  SLocker permission Also notable is that unlike the TOR-enabled version, this one lists a Russian phone number and demands Russian currency in the ransom message  Russia ransom Digging deeper into retracing the C C server, we found its IP address had been registered as far back to 2005 to a private person Currently, a Russian-based webhosting service is running there Though this version of SLocker is less sophisticated in that it does not use TOR for its C C communications, it still seems to be under active development, as the latest sample we have of this version now includes capability to take photographs using the device's camera It seems likely that SLocker's author s  will continue to develop it in the future   Post by   Mikko Hyykoski On 16 06 14 At 07 10 AM </description><link>http://www.secuobs.com/revue/news/519082.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/519082.shtml</guid></item>
<item><title>Necurs - Rootkit for Hire</title><description>Secuobs.com : 2014-06-16 17:49:37 - F Secure Antivirus Research Weblog -  Necurs is a kernel mode driver best known at the moment for being used by Gameover Zeus  GOZ  to hinder attempts to detect and remove the malware The technical details of the Necurs driver have already been exhaustively covered in a writeup by Peter Ferrie, but during our analysis we came across some interesting details of Necur's gradual uptake as a 'crimeware for sale' module We saw the earliest version of the Necurs driver as a standalone malware in May 2011  it didn't become associated with another malware until early 2012, when we observed it being dropped by a trojan-downloader, also called Necurs since it was the only user mode component the driver was seen with at the time It was only in February 2014 that we saw the driver included in GOZ, which raised its profile considerably The GOZ botnet is estimated to run into hundreds of thousands of infections and it is mainly used for online banking theft Before Necurs was incorporated, GOZ had been operating without an associated driver Its addition to the botnet's operations was rather curious, as it occurred about 25 months before the United States' Federal Bureau of Investigations  FBI  started their takedown operations The Necurs driver's design is interesting in that it doesn't require any changes by the authors for use by a third party The dropper code used by both the Necurs trojan-downloader and GOZ to create and install the Necurs driver is the same, so the author has provided everything needed for the driver to be taken into use The dropper code has been written in the style of shellcode, so it can be executed as is, and as such it can be easily included into the source code of whatever malware will end up using the driver No source code needs to be given to the customers, and the driver can be easily configured to protect any executable just by correctly setting its service key values The name of the file to be protected is taken from the DisplayName value of the driver's service key The Necurs driver also includes a control interface that allows the user mode component to give commands to the driver, regardless of the actual family Controlling is done with specific IRP_MJ_DEVICE_CONTROL requests, which can be sent with the DeviceIoControl user-mode API The first control code the user-mode component must send is 0x220000  on receiving this, the Necurs driver will store the handle of the process that sent that request as the process that will be able to control the driver This command is only accepted once per bootup To be stored as the controlling process, the IRPAssociatedIrpSystemBuffer for that request must be 12-bytes long and adhere to two checks    first_dword   0xdeadc0de   second_dword   first_dword   third_dword   pid of process that sends the request An additional check is that the name of the process that sends the control code must be the same as the DisplayName field in the Necurs service key This prevents unwanted processes from sending the commands, as any kind of access to a file with that name will be prevented by the driver Necurs listens for a total of 15 different IoControlCodes, including    0x220000 register process as Necurs master   0x22000c get Necurs driver path   0x220010 get Necurs service key name   0x220018 update Necurs driver  driver file content is replaced by data in IRPAssociatedIrpSystemBuffer    0x22001c uninstall Necurs driver   0x220028 terminate process by process identifier   0x22002c terminate process by name The code for calling all of the commands is included in the dropper code that also handles the installation of the driver necurs  18k image  These features essentially make the Necurs driver well suited for resale and use by third parties, as is evident by its use in the GOZ trojan Though the current takedown effort against the botnet is likely to put a crimp in the operations of Necurs' biggest 'customer', at least for a while We detect Necurs driver variants as RootkitNecurs   Post by   Mikko S On 16 06 14 At 03 02 PM </description><link>http://www.secuobs.com/revue/news/519081.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/519081.shtml</guid></item>
<item><title>BlackEnergy Rootkit, Sort of</title><description>Secuobs.com : 2014-06-13 20:31:31 - F Secure Antivirus Research Weblog -  A sample of the BlackEnergy family was recently uploaded to VirusTotal from Ukraine The family is allegedly the same malware used in the cyber attack against Georgia in 2008 The malware provides attackers full access to their infected hosts Check out SecureWorks' detailed analysis from 2010 for more information about the family The new sample is not much of a rootkit anymore, in the sense that it no longer hides files, registries, etc The build is now  0D0B15aaa  according to the embedded XML  Embedded XML Although not used, the sample still have a routine that hides processes This time it uses DKOM Because of this  and to check whether svchostexe is in an alertable state , the malware keeps a hard coded list of offsets in kernel structures that it uses for the different Windows versions What is interesting is that the sample was designed with Windows 8 in mind  Offsets in Windows 8 kernel structures Since the sample is not signed, the driver signing enforcement in modern Windows has to be disabled to work On 13 06 14 At 05 09 PM </description><link>http://www.secuobs.com/revue/news/518828.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/518828.shtml</guid></item>
<item><title>Freedome  Limited-Time Offer</title><description>Secuobs.com : 2014-06-13 15:28:59 - F Secure Antivirus Research Weblog -  Our VPN app, Freedome, was recently updated  on iOS  What's Freedome  It's our VPN service You can use it to stay securely connected to home wherever you roam Just set your home-base  Freedome, Set your location And enjoy Our list of virtual locations has recently expanded  Freedome, Available locations Check it out on Google Play and iTunes And for a limited time  use the code  david  for a free six month trial  Offer expires June 30th  Your feedback helps us to build a better service  Please review the app and or Tweet to  FreedomeVPN Cheers  On 13 06 14 At 01 08 PM </description><link>http://www.secuobs.com/revue/news/518762.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/518762.shtml</guid></item>
<item><title>Black Hat USA 2014</title><description>Secuobs.com : 2014-06-12 18:20:26 - F Secure Antivirus Research Weblog -  F-Secure Labs' Timo Hirvonen will be presenting at Black Hat USA 2014 His presentation is titled  Dynamic Flash Instrumentation for Fun and Profit Dynamic Flash Instrumentation for Fun and Profit  If only there were a decent tool for dynamic analysis Flash files  No pressure Congrats, Timo  On 12 06 14 At 04 04 PM </description><link>http://www.secuobs.com/revue/news/518574.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/518574.shtml</guid></item>
<item><title>We've Set Up a One-Click Test For GameOver ZeuS</title><description>Secuobs.com : 2014-06-09 15:44:47 - F Secure Antivirus Research Weblog -  Today we've published a new, quick way to check if your computer is infected by GameOver ZeuS  GOZ  Last week the GOZ botnet was disrupted by international law enforcement together with industry partners, including ourselves It is of critical importance to realize GOZ was disrupted   not dismantled It's not technically impossible for the botnet administrators to reclaim control in the near future More than one million computers are infected by GOZ, time is of the essence To assist with remediation, starting today, you can simply visit   wwwf-securecom gameoverzeus   to see if your browser has signs of a GameOver ZeuS infection The nice part is you don't have to install any software and it takes only a few seconds  GOZ detection page Our more technical readers might be wondering how the check works It's something we haven't done before, and we thought we'd describe it in more detail here In the end, we get to play a little trick on the malware itself, which is always fun GOZ, or in fact almost any other banking trojan for Windows, infects the browser in order to steal usernames, passwords, and other credentials Let's say you are going into Amazoncom  Amazon login page GameOver ZeuS will notice that you are about to sign in to a site it's interested in and steals your credentials straight from inside the browser How does it do this  By including a configuration file which lists all the addresses it's interested in Here's a partial list of what GameOver Zeus is tracking  Banks in GOZ config As you notice, the list contains many addresses of banks and other financial institutions GameOver ZeuS even supports regular expressions to make creating new rules flexible Some addresses which use regular expressions turn out to be very aggressive  Entries in GOZ config What do I mean by  aggressive  Well, for example, visiting a site with the address https wwwf-securecom amazoncom indexhtml would make GameOver think that you are actually visiting Amazon, because the regular expression still matches Turns out, we can use this to  trick  GameOver bots and make an easy check to see if an infection is present in your browser  So what does GameOver actually do when a user is going to Amazoncom  Since the malware lives inside the browser, not only can it see what you type into the login page, but it can also modify the webpage before you see it When a user with an infected browser goes to Amazon, ZeuS will  inject  more content onto the page Here's a partial snippet of the code which gets injected  GOZ code for Amazon Often this extra code adds new fields to the login page and then sends the content to a server the attacker controls We'll make use of the highlighted string  LoadInjectScript  later How do we put all of this together to make a quick scan for the malware  Our detection page at wwwf-securecom gameoverzeus loads a webpage from an address which has the string  amazon  in it, even though it's just a page from our own site  iframe on GOZ page If you are infected, visiting our page makes GameOver ZeuS think you are going to Amazon, even if you're not  This in turn causes GOZ to add its own code to the webpage When our  fake  Amazon page is loaded, it does a  self-check  and simply searches the page for the modification that GameOver makes We search for the string  LoadInjectScript  we showed above  note that we have to split it up, so we don't just end up finding our own string  goz_check function If the string is found on the page, we know GameOver ZeuS has infected your browser  As always, there are some limitations If you are using a browser which GameOver doesn't support  Lynx anyone , or a native 64-bit browser , it may be that your computer is infected, but the browser has no traces of the malware In such cases, we still recommend running our free Online Scanner to be sure Also, if you do actually have an infection, you'll need to remove it with the scanner Also see US-CERT Alert  TA14-150A  Links to share  http wwwf-securecom gameoverzeus   or   http bitly GOZCheck On 09 06 14 At 06 59 AM </description><link>http://www.secuobs.com/revue/news/517828.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/517828.shtml</guid></item>
<item><title>Fake Pirate Bay Uses Tricks To Push Unwanted Software</title><description>Secuobs.com : 2014-06-06 15:36:22 - F Secure Antivirus Research Weblog -  This is piratebaycom piratebaycom It's a cheap knockoff imitation of The Pirate Bay If you  search  for something   you'll be offered a custom named executable to download Buried at the bottom of the page is this disclaimer  piratebaycom, disclaimer  Additional software may be offered to you  Yeah  indeed it will And the  decline  button is white text on gray on more gray Very duplicitous piratebaycom, app discovery In all, several applications are installed Given the target audience, this probably takes advantage of kids Lame To be avoid Our Internet Security detects the installer accordingly On 06 06 14 At 12 48 PM </description><link>http://www.secuobs.com/revue/news/517523.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/517523.shtml</guid></item>
<item><title>Don't Ask For Your Privacy</title><description>Secuobs.com : 2014-06-05 17:58:21 - F Secure Antivirus Research Weblog -  June 5th  a day to Reset the Net reset-the-net Don't ask for your privacy Take it back How  Give software such as the EFF's HTTPS Everywhere a try HTTPS Everywhere More software suggestions are available via Reset the Net's Privacy Pack On 05 06 14 At 03 19 PM </description><link>http://www.secuobs.com/revue/news/517318.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/517318.shtml</guid></item>
<item><title>How much money did GameOver ZeuS steal </title><description>Secuobs.com : 2014-06-03 16:43:52 - F Secure Antivirus Research Weblog -  Wanted by the FBI  Evgeniy Mikhailovich Bogachev aka  slavik  Tovar, Bogachev Finally  a face and a name to go with an infamous alias Yesterday, the FBI announced a multi-national effort against the operator of GameOver ZeuS  GOZ , a notorious banking trojan We've been waiting for this  Tovar, technical assistance provided by Details here  GameOver Zeus Botnet Disrupted Today we've been  eagerly  going through the associated documents   and the costs attributed to GOZ are very striking Examples of GameOver victims  Tovar, GOZ victims SEVEN MILLION dollars from one Florida bank  Wow Examples of CryptoLocker  ransomware dropped by GOZ  victims  Tovar, CryptoLocker victims A restaurant in Florida had its recipes encrypted  Now THAT is some  secret sauce   30,000 in damage is really a significant cost for such a business According to this FBI graphic, CryptoLocker made  30 million in payments during the last four months of 2013  FBI, CryptoLocker Malware So here's the thing about GOZ  it's a peer-to-peer botnet and is highly resistant to  takedowns  Law enforcement action is currently blocking critical command and control infrastructure   but it could be only a matter of time before slavik regains ownership via side channels In the meanwhile, remediation efforts are underway IP addresses related to GOZ are being directed to removal tools Our own  free  Online Scanner is listed in US-CERT's Alert  TA14-150A  There's already a sizable increase in the number of scans performed according to our metrics Spread the word, and with any luck, the GameOver botnet will implode On 03 06 14 At 02 12 PM </description><link>http://www.secuobs.com/revue/news/516888.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/516888.shtml</guid></item>
<item><title>The Finnish Sprayer virus</title><description>Secuobs.com : 2014-06-02 15:44:39 - F Secure Antivirus Research Weblog -  This virus analysis was published exactly 20 years ago in the Virus Bulletin magazine Finnish Sprayer Finnish Sprayer Republished with the kind permission of Virus Bulletin Ltd On 02 06 14 At 12 51 PM </description><link>http://www.secuobs.com/revue/news/516624.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/516624.shtml</guid></item>
<item><title>ProTip  Use Apple  Turn Passcode On </title><description>Secuobs.com : 2014-05-27 19:57:06 - F Secure Antivirus Research Weblog -  Interesting Apple security news is being reported today Apparently some Apple devices have been hijacked via Apple's  Find My iPhone  feature How  Likely via poorly defended iCloud accounts, ie, iCloud accounts with weak passwords Once you have access to iCloud, you have access to the Find My iPhone's  Lost Mode , which can be used to lock associated devices and send messages such as  Reward if found  Call this number  iCloud, Lost Mode Or then it could be an extortion attempt Here's an example from a German colleague's iPhone  Find My iPhone According to the sources linked above,  Oleg Pliss  is demanding money to a PayPal account If the iPhone user has a passcode, they can unlock their device If they don't have a passcode set  then they have a problem It's also worth mentioning the Find My iPhone feature includes a  Delete  option Besides extortion, your iPhone can also be burned And remember too that iCloud provides access to contacts and calendars So  besides enabling a passcode, you should also be using a strong and unique password for your Apple iCloud iTunes account Sure, it will be annoying to input when you want to buy an app   but that's the price you'll need to pay Or else, disable iCloud functionality  Identify the critical accounts to protect, and then make sure the passwords for those accounts are unique and strong  To do list  1  Turn Passcode On   It doesn't have to be required immediately  2  Reset your Apple iCloud iTunes password Optional  but highly recommend  3  Get yourself a password manager On 27 05 14 At 04 32 PM </description><link>http://www.secuobs.com/revue/news/515709.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/515709.shtml</guid></item>
<item><title>Three Lessons We've Learned From Our Facebook Partnership</title><description>Secuobs.com : 2014-05-21 14:57:06 - F Secure Antivirus Research Weblog -  On Tuesday, Facebook Security announced its new effort to make malware cleanup easier And we're very happy to be part of that effort F-Secure is one of two vendors now partnered with Facebook do to malware clean-up With over one billion users, Facebook has a very unique vantage point from which to detect threats It can see patterns on a scale few others can And user accounts pumping spam links that have uncommon browser plugins installed  well, those accounts are connecting from computers affected by malware So what to do about it  That's where we come in  When Facebook determines a case of Facebook-focused malware, it introduces this prompt during login  Facebook, Your Computer Needs To Be Cleaned The user then has the option to download our Online Scanner  Facebook, F-Secure Online Scanner Once downloaded and started, the user can continue to their Facebook feed Our scanner runs in the background and produces a Facebook notification when it's finished Facebook, F-Secure Online Scanner  finished While Facebook-focused malware is the trigger which prompts the scan, our scanner will of course detect more threats if present If a difficult case is discovered, Facebook will move our UI into the foreground  Chanki    our service manager for this project   makes the following observations  1   There are a tremendous amount of suspect installers out there, which while not necessarily malicious, are difficult to classify as clean by default Separating the wheat from the chaff is a challenge when installers can be configured to install multiple items utilizing a common platform that also has legitimate uses 2   We also needed to come up with approaches for handling the classification, detection and removal of malicious browser extensions on Firefox and Chrome, which represent a significant attack vector against Facebook's platform This is typified by families such as the Turkish-oriented Kilim malware, and older attacks such as FBSuper which we have previously written about on this blog The attack surface is not just Win32 OS  we have to take into account the platforms represented by the browsers as well 3   We also discovered that Bitcoin remains a significant motivation for malware authors We identified at least two malware families, Napolar and Lecpetex, that utilize Facebook as a vector to spread and install Bitcoin miners Great work, Chanki  You don't need to be prompted by Facebook to try our Online Scanner Feel free to download and run it yourself Add it to your USB toolkit, it needs online access for our latest detections, it isn't Web-based If complex threats are discovered, the scanner includes neat tech such as an ability to reboot into a virtual Linux machine and then back to Windows Nice F-Secure Online Scanner UI  Start You'll always find the latest version here  f-securecom online-scanner On 21 05 14 At 12 42 PM </description><link>http://www.secuobs.com/revue/news/514700.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/514700.shtml</guid></item>
<item><title>On The Right To Be Forgotten</title><description>Secuobs.com : 2014-05-20 15:18:15 - F Secure Antivirus Research Weblog -  According to Google, the  right to be forgotten  is  logistically complicated  Last Week Tonight's John Oliver clarifies the issue here  Last Week Tonight   Right To Be Forgotten On 20 05 14 At 12 23 PM </description><link>http://www.secuobs.com/revue/news/514477.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/514477.shtml</guid></item>
<item><title> Police Ransomware  Expands To Android Ecosystem</title><description>Secuobs.com : 2014-05-15 19:32:39 - F Secure Antivirus Research Weblog -  Crimeware has steadily transferred Windows-based technology to Android We've seen phishing, fake-antivirus scams, banking trojan components, and now  ransomware Yep  Police ransomware  on Android Our name for it is, Koler main screen The crimeware ecosystem has long been aware of Android systems it routinely comes into contact with   it's not really much of a surprise to see ransomware attempt to make the jump Here's how it works  Compromise occurs when the user visits a booby trapped  pornographic  website with his Android device The malware then pretends to be video player and requests installation This is dependent upon the  enable unknown sources  setting being configured When the installation is completed, Koler sends the phone's identification information to its remote server After this, the server returns a webpage declaring that the user has visited an illegal porn site and the phone is locked To unlock, the user is told to pay a fine  ransom  Even though Koler claims to encrypt files, in reality, nothing is encrypted These domains are hardcoded to be Koler's remote servers    mobile-policeblockcom   police-guard-mobilecom   police-mobile-stopcom   police-scan-mobilecom   police-secure-mobilecom   police-strong-mobilecom At the moment, Koler's servers are offline Google Cache finds  NSFW  content from only one server but the malware has been removed The servers are were hosted in US Whois lists contact information, such as phone numbers, from Denmark and Russia At present, country-specific versions of localization have been seen for more than 30 countries The content has been ported from Windows versions of  police ransomware  and is formatted for mobile browsers How to remove Koler  The ransomware prevents disables the back button, but the home screen button is active The user has only a few seconds in which to get to the phone's settings to remove the malware, or to restore factory settings Another option is to restart the device to the service menu and remove Koler from there Koler also prevents access to the device via the adbexe You are able to start shell but the viewing of files is not allowed More information can be from our description  Trojan Android Koler Analysis by   Mikko Hyykoski On 15 05 14 At 04 23 PM </description><link>http://www.secuobs.com/revue/news/513804.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/513804.shtml</guid></item>
<item><title>Microsoft SIR v16</title><description>Secuobs.com : 2014-05-13 17:20:24 - F Secure Antivirus Research Weblog -  Microsoft recently released volume 16 of its Security Intelligence Report If you're serious about security issues, SIR is a must read And whad'ya know  Finland is once again among the healthiest locations in the world lowest infection rates in the world Is it a coincidence that Finland is the cleanest country in the world   -  On 13 05 14 At 01 03 PM </description><link>http://www.secuobs.com/revue/news/513310.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/513310.shtml</guid></item>
<item><title>Video  Hypponen and Hasselhoff</title><description>Secuobs.com : 2014-05-08 15:13:06 - F Secure Antivirus Research Weblog -  Mikko at re publica 2014  re publica 2014 - Looking for Freedom Add your thoughts here  F-Secure Digital Freedom Manifesto On 08 05 14 At 12 48 PM </description><link>http://www.secuobs.com/revue/news/512506.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/512506.shtml</guid></item>
<item><title>Video  NEXT Berlin</title><description>Secuobs.com : 2014-05-06 14:52:57 - F Secure Antivirus Research Weblog -  Mikko spoke at NEXT Berlin yesterday  NEXT  Arms race And the video is now online  Arms Race  24m15s  On 06 05 14 At 12 31 PM </description><link>http://www.secuobs.com/revue/news/512063.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/512063.shtml</guid></item>
<item><title>Doing threat analysis big data while preserving user privacy</title><description>Secuobs.com : 2014-04-30 10:25:21 - F Secure Antivirus Research Weblog -  Anti-Virus industry has changed a lot during that past 4-7 years, we like other companies, used to be very file signature and file scanning oriented back in 2008 or so And as that obviously did not scale, we moved into detecting more useful patterns of attacks, and started focusing on preventing infections in the first place rather than trying to detect files dropped by already successful attacks Doing things the smart way requires good visibility, so we had to start doing big data Or should we say big information, since any fool can collect massive amount of data, the trick is in converting big data into small and understandable information However in order to do data mining we have to collect data from our users, which can be a problematic from privacy point of view Which has lead into people asking just what kinds of data we are collecting and how we are processing it So in order to answer these questions we wrote a white paper detailing information collected by our Internet Security range of products The whitepaper is readable here data_whitepaper  187k image  The basic principle of our data collecting is to collect only what we need and anonymize it as early as possible All data that can be sanitized in the client is already stripped there so that we get system data, but will not taint our database with anything that looks like users personal data The data that cannot be sanitized at the client, such as client IP address, will be stripped out in the first server that processes the data We also run regular cleanups in our customer data to remove any user related data that would have escaped multiple layers of import sanitization We do continue out work on knowing everything that is needed to stop attacks, but still making sure that we do not end up knowing anything about our users On 30 04 14 At 07 33 AM </description><link>http://www.secuobs.com/revue/news/511051.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/511051.shtml</guid></item>
<item><title>Q1 2014 Mobile Threat Report</title><description>Secuobs.com : 2014-04-29 11:24:49 - F Secure Antivirus Research Weblog -  Our Mobile Threat Report for Q1 2014 is out  Here's a couple of the things we cover in it  The vast majority of the new threats found was on Android  no surprise there , which accounted for 275 out of 277 new families we saw in this period, leaving 1 new malware apiece on iOS and Symbian In Q1, our Mobile Security product users mostly reported encountering trojans that did some form of silent SMS-sending  mainly from the Fakeinst and SMSSend families  It should be interesting to see how the 42 update to the Android OS  which requires user confirmation when premium-rate SMSes are sent  impacts these trojans This was an active quarter for mobile malware development, with a number of  firsts  reported There was Trojan Android TorsmA, the first one to use Tor to hide its communications with its command and control server The first bootkit, Trojan Android OldbootA, was reported, as well as a trojan that tries to turn the phone into a silent cryptocurrency miner  Trojan Android CoinMinerA  Then there is the Dendroid toolkit, which promises to make creating Android trojans as simple as clicking a few buttons - and apparently comes with a lifetime warranty too Much like virus construction kits and exploit kits did before for PC-based threats, Dendroid would make malware creation much more accessible to anyone without the technical skills to do it themselves And this is all just in the first three months of 2014 More details are in the Mobile Threat Report, which is available on the Labs site, or by clicking on the images below There's two versions of it available    For web  PDF  2014Q1_MTR_web_small   And a printer-friendly version  PDF  q12014_mtr_banner_print_small On 29 04 14 At 08 46 AM </description><link>http://www.secuobs.com/revue/news/510830.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/510830.shtml</guid></item>
<item><title>Browlock Goes Russian</title><description>Secuobs.com : 2014-04-28 16:05:09 - F Secure Antivirus Research Weblog -  In a surprising turn of events, it appears that Browlock is now targeting Russians If for some reason, some unfortunate fellow ends up in an infected site that has been prepended with the Browlock link  IMAGE  This  browser locker  will be served after 5 seconds of being on the infected page   IMAGE  The page appears to be in very well written Russian that is loosely translated to  Ministry of Russian Federation Internal Affairs  Police Ministry   The ministry  detected that your computer has been used for doing wrong things which are illegal such as looking at materials related to violence, gay pornography and pedophilia Such activities are forbidden in accordance with  some law being quoted  Such activity will cause a penalty of 800 to 4000 Rubles and if you don't want to pay, you will go to prison in accordance with  some law being quoted  As it is already done, you now have to pay 1000 rubles The payment of this penalty can be done via any mobile terminal  sample of this below  or you can put this sum to the phone number   79054014516 You have to perform this payment in 12 hours After completing the payment, you will be given a confirmation of payment and there you'll see the unlocking code which should be entered in the field below If you don't want to pay, then all the materials about these illegal activities will be sent to the prosecutor's office for initiating criminal proceedings And a group of policemen will be sent to your place of residence Here is a sample mobile terminal image that was referred above   IMAGE  When the user attempts to close the browser or tab, this will appear   IMAGE  The  browser locker  page appears to render the browser unusable, however, it's just an elongated dialog box and a simple pressing of the ENTER key will close the browser and no harm will be done to your computer So far, it has only worked on the Chrome Browser but the page loads properly when accessed from different countries including Russia Browlock page has now been blocked by Browsing Protection   Post by   Christine, Patricia and Dmitriy On 28 04 14 At 01 11 PM </description><link>http://www.secuobs.com/revue/news/510674.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/510674.shtml</guid></item>
<item><title>F-Secure and David Hasselhoff</title><description>Secuobs.com : 2014-04-22 16:38:39 - F Secure Antivirus Research Weblog -  We first blogged about David Hasselhoff in 2011  see  Don't hassle the Hoff on F-Secure's watch  The case from 2011 involved a remote access trojan which had a feature called  David Hasselhoff Atach  David Hasselhoff And now, in 2014, David Hasselhoff is becoming the Freedome Ambassador for F-Secure David Hasselhoff We will be launching our Digital Freedom Manifesto at the re publica conference in Berlin together with David For real For more information, se our Digital Freedom site On 22 04 14 At 02 04 PM </description><link>http://www.secuobs.com/revue/news/509601.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/509601.shtml</guid></item>
<item><title>xkcd  Heartbleed Explanation</title><description>Secuobs.com : 2014-04-11 12:13:46 - F Secure Antivirus Research Weblog - Heartbleed Explanation xkcd  Heartbleed Explanation On 11 04 14 At 09 53 AM </description><link>http://www.secuobs.com/revue/news/507755.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/507755.shtml</guid></item>
<item><title>Lame  SEO  Android Apps Claim To Be Antivirus</title><description>Secuobs.com : 2014-04-10 20:05:46 - F Secure Antivirus Research Weblog -  On Sunday, Android Police  a popular news and review site  published a post on  Virus Shield    an app which reached top ranking in Play, and yet, was a complete fraud In a follow up, DailyTech did some digging and believes the app was written by a 17 year-old Texan Apparently he's good at SEO Whether he's the guy or not  it fits the typical profile A young person with good SEO skills pushing a rather useless app Virus Shield Lame  SEO apps  are prevalant on Google Play They're easy to find if you look For example    Best Antivirus Lite   SAFE antivirus Limited   Skulls Antivirus   Shnarped Hockey antivirus lite Best and SAFE link to one  developer    while Skulls and Shnarped Hockey link to another Though there are two different developers  the apps are identical apart from their name The apps appear to be based on a template  there are markets for app templates  and all the so-called developers have done is to add their own graphics Android apps  no developer skills required So what do the apps do  Well, the  antivirus  open sa screen label  anti spyware  Shnarped Hockey antivirus lite Hmm, the terms changed That ought to be a warning sign Click  Start Scan  and the app does a basic scan of permissions for installed apps Apps with a large number of permissions are categorized as a risk and those with a low number of permissions are called safe And if you want to see the details  Well, then you need to buy the  full  version of the app for about a buck In our humble opinion, the folks who bought the full versions  more than one thousand  completely wasted their money Google Play  caveat emptor PS If you want an app that does an advanced scan of permissions and provides excellent details entirely FREE of charge  Check out F-Secure App Permissions for Android On 10 04 14 At 05 03 PM </description><link>http://www.secuobs.com/revue/news/507587.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/507587.shtml</guid></item>
<item><title>Admins  why not review config standards as you fix Heartbleed </title><description>Secuobs.com : 2014-04-09 12:53:55 - F Secure Antivirus Research Weblog -  As you have to update your SSL anyway, why not make sure your configuration is up to modern standards  There has been plenty of noise about Heartbleed, so if you're an admin, you already know what to do 1 Find everything you have using vulnerable versions of OpenSSL 2 Update to the latest OpenSSL version 3 Create new SSL certificates as the old ones may have leaked But since you have to touch your server configuration and create new SSL certificates, we would recommend that you also go through certificate generation settings and server configuration Heartbleed is not the only problem in SSL TLS implementations, a poorly chosen protocol or weak cipher can be just as dangerous as the Heartbleed bug As recommended reading we would suggest  OWASP Transport Layer Protection Cheat Sheet Bonus points opportunity  4 Implement Perfect Forward Secrecy  PFS  It's the  Prefer Ephemeral Key Exchanges  rule in the OWASP cheat sheet See this EFF post for details  Why the Web Needs Perfect Forward Secrecy More Than Ever Edited to add  And one more thing  5 Do not rely ony on transport layer security If your data is critical, use additional protection in your implementation Example  Younited See the support question  How do I turn on advanced login authentication  younited's 2FA Two factor authentication PROVIDE IT Please On 09 04 14 At 09 39 AM </description><link>http://www.secuobs.com/revue/news/507235.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/507235.shtml</guid></item>
<item><title>Bliss</title><description>Secuobs.com : 2014-04-08 16:34:38 - F Secure Antivirus Research Weblog -  Farewell  Bliss Obituary  Windows XP dies at 12 1 2 after long illness RIP On 08 04 14 At 02 04 PM </description><link>http://www.secuobs.com/revue/news/507030.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/507030.shtml</guid></item>
<item><title>DeepGuard 5 vs Word RTF zero-day CVE-2014-1761</title><description>Secuobs.com : 2014-04-04 23:47:50 - F Secure Antivirus Research Weblog -  Now that we got our hands on a sample of the latest Word zero-day exploit  CVE-2014-1761 , we can finally address a frequently asked question  does F-Secure protect against this threat  To find out the answer, I opened the exploit on a system protected with F-Secure Internet Security 2014, and here is the result  Screenshot of DeepGuard 5 blocking CVE-2014-1761 exploit IS2014 blocked the threat using the exploit interception feature introduced in DeepGuard version 5 The best part is that we did not need to add or modify anything   the zero-day was blocked by the exact same detection that was included already in the initial release of DeepGuard 5 in June 2013 This means that our users were protected against this threat long before we even got a sample, and also several months before the attack was reported by Microsoft DeepGuard 5 shows the power of proactive, behavior based protection again  and again  Microsoft will release a patch for the vulnerability on Tuesday April 8, 2014 In the meantime, you should check the mitigations and workarounds Microsoft recommends We have also added a generic detection Exploit W32 CVE-2014-1761A to detect the exploit before the document is opened Exploit SHA1  200f7930de8d44fc2b00516f79033408ca39d610 Post by   Timo On 04 04 14 At 09 36 PM </description><link>http://www.secuobs.com/revue/news/506603.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/506603.shtml</guid></item>
<item><title>April 8th  Not Just About XP</title><description>Secuobs.com : 2014-04-04 15:11:20 - F Secure Antivirus Research Weblog -  April 8th will soon be upon us  And that means  Countdown Clocks  the end of extended support for Windows XP But not just XP Office 2003 is also reaching its life And that's especially important to know because there's currently an Office vulnerability in the wild Microsoft released its Security Bulletin Advance Notification yesterday  Microsoft Security Bulletin Advance Notification for April 2014 And the good news is  a patch for the Word vulnerability appears to be in the pipeline It's critical that everybody still using Office 2003 apply this update Why  Because it will only take days for the patch to be reversed and for related exploits to be injected into exploit kits At which point, browsing the web becomes considerably more hazardous for anybody with Office installed Particularly if your browser is configured to  open  RTF files So prepare to patch next Tuesday  Do it Do you still have plans to use XP post-April 8th  Check out this Safe and Savvy post  7 things to do if you re going to keep using Windows XP after April 8, 2014 Carefully note that step 3 also includes advice to tighten Office security settings Something you can do before next Tuesday On 04 04 14 At 12 43 PM </description><link>http://www.secuobs.com/revue/news/506524.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/506524.shtml</guid></item>
<item><title>Coremex Innovates Search Engine Hijacking</title><description>Secuobs.com : 2014-04-01 16:51:04 - F Secure Antivirus Research Weblog -  Malware that targets search engine results is nothing new Malicious browser extensions are also familiar  which typically contribute to stuff such as Facebook scam campaigns  But very recently, we've identified a noteworthy malware family that attempts to do both We've named it  Coremex It takes advantage of plugin functionality provided by browsers to hijack different search engine results   taking on online advertising giants such as Google and Yahoo Coremex comes as a single NullsoftInstaller executable file which acts as both dropper and downloader Upon execution of the executable, the downloader will start collecting basic information from the infected machine For example  the username, the infected workstation name, processor, memory, et cetera The information will be sent to a command-and-control  C C  server address, 178861732, which is hard-coded in the binary The information is encrypted with RC4 with a key of  2AJQ8NA4  and the final result will be encoded with Base64 There are some anti-sandbox features implemented by Coremex that prevents it from downloading the main payloads, such as the browser extension scripts, from the C C server These features consist of checking blacklisted process names and looking for well-known sandbox fingerprints such as a  VMware  string on the infected machine by using Windows Management Instrumentation  WMI  Figure 1 Blacklisted process name in hash  Coremex_Blacklisted_ProcessName_By_Hash Figure 2 Anti-Sandbox name in hash  Coremex_AntiSandbox_By_Hash If the anti-sandbox component does not raise a red alert, Coremex will then proceed to download additional payloads from the C C server However, the author uses a different C C server to download payloads  at least during the time of our analysis  The C C server addresses consist of    178250245198   17412782213   19215494253 After the payload is downloaded successfully, they will be silently installed by Coremex Afterwards, the browser extension will reside in the browser process whenever the victim opens Chrome or Firefox Coremex's JavaScript is highly obfuscated with 3 layers of obfuscation to make the analysis harder Behind the scenes, Coremex's JavaScript will register a couple of events using the API provided by the browser and wait for these events to be triggered Figure 3 Malicious browser extension register multiple event listeners  Coremex_Scripts_Event_Listener One of the event listeners will be run once in an hour Upon execution of the event callback function, it will start connecting to the following bogus search engine websites    onlinetrackorg   zvtrackercom While the other event listeners are responsible to parse the URL that the affected browser is going to visit The callback function of these event listeners will look for the search query entered to the following search engine platforms    Google   Bing   Yahoo   ASK   AOL   AVG   MyWebSearch   Search-Results   Comcast   Delta-Search Figure 4 A list of search engine platforms targeted by Coremex  Coremex_Search_Engine_Hijack When a targeted search engine platform is found and after successfully parsing the search query from the URL, Coremex first transforms the victim's entered search query into a JSON format  Coremex_yoursearchquery The JSON object will then be encrypted with RC4 algorithm with key  http  and the result will be encoded with Base64 The Base64 encoded string will be sent to presumably the author's controlled search engine platform  Coremex_RC4 In the server's response, it contains an encrypted JSON object with a list of destination website that will determine where a webpage that has ads-like URL will be redirected to An example of Google AdWords URL might look like this  Google Adwords URL Figure 5 Code responsible to parse Google AdWords URL pattern  Coremex_Google_Ads_URL_Hijacked The decrypted JSON object might look like  decrypted JSON objet The following screenshot shows Coremex script in action when an ad's URL is clicked by the victim which leads to the ad's page being hijacked and redirected to author's intended destination website Figure 6 Google AdWord URL is being hijacked  Coremex_Google_Ads_Url_Car_For_Sale_768x335 Click image to embiggen Figure 7 Google AdWord page is hijacked with IFRAME  Coremex_Google_Ads_Page_Hijacking_With_IFrame_768x333 Click image to embiggen Regarding the injected IFRAME to the hijacked ad's page  during analysis, the server never replied with the destination website So we have not yet seen examples of where the hijacked Ad will be redirected But it is clear that the author's intention is to take advantage of popular online advertising services SHA1  62b5427b10f70aeac835a20e71ab0d22dd313e71   Post by   Wayne --------------------------------------------------------------------- On 01 04 14 At 01 58 PM </description><link>http://www.secuobs.com/revue/news/505938.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/505938.shtml</guid></item>
<item><title>Targeted Attacks and Ukraine</title><description>Secuobs.com : 2014-04-01 14:52:46 - F Secure Antivirus Research Weblog -  Lets start by stating that we know this blog post is dated April 1st However, this is not an April Fools joke In 2013, a series of attacks against European governments was observed by Kaspersky Lab The malware in question, known as MiniDuke, had many interesting features  it was tiny in size at 20KB It used Twitter accounts for Command   Control and located backup control channels via Google searches It installed additional backdoors onto the system via GIF files that embedded the malware As most APT attacks, MiniDuke was distributed via innocent looking document files that were emailed to targets In particular, PDF files that exploited the CVE-2013-0640 vulnerability were used To investigate similar cases, we have created a tool for extracting the payloads and the decoy documents from MiniDuke PDF files With this tool we were able to process a large batch of potential MiniDuke samples last week While browsing the set of extracted decoy documents, we noticed several ones that had references to Ukraine This is interesting considering the current crisis in the area Here are for examples of such documents  Ukraine MiniDuke Ukraine MiniDuke Ukraine MiniDuke The attackers have collected some of these decoy documents from public sources However this decoy file that resembles a scanned document is unlikely to be found from any public source  Ukraine MiniDuke The document is signed by Ruslan Demchenko, the First Deputy Minister for Foreign Affairs of Ukraine The letter is addressed to the heads of foreign diplomatic institutions in Ukraine When translated, it's a note regarding the 100th year anniversary of the 1st World War We don't know where the attacker got this decoy file from We don't know who was targeted by these attacks We don't know who's behind these attacks What we do know is that all these attacks used the CVE-2013-0640 vulnerability and dropped the same backdoor  compilation date 2013-02-21  We detect the PDF as Exploit W32 MiniDukeC  SHA1  77a62f51649388e8da9939d5c467f56102269eb1  and the backdoor as Gen VariantMiniDuke1  SHA1  b14a6f948a0dc263fad538668f6dadef9c296df2    Research and analysis by Timo Hirvonen On 01 04 14 At 12 05 PM </description><link>http://www.secuobs.com/revue/news/505899.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/505899.shtml</guid></item>
<item><title>Gameover ZeuS Targets Monster</title><description>Secuobs.com : 2014-03-25 14:13:18 - F Secure Antivirus Research Weblog -  Recently, we obtained a current Gameover ZeuS configuration file and we noticed that in addition to CareerBuilder   Gameover now also targets Monster Here's the legit hiringmonstercom URL  hiringmonster A computer infected with Gameover ZeuS will inject a new  Sign In  button, but the page looks otherwise identical  hiringmonster, gameover And then the following  security questions  are requested via an injected form  hiringmonster, gameover question injection Here's the full list    In what City   Town does your nearest sibling live    In what City   Town was your first job    In what city did you meet your spouse significant other    In what city or town did your mother and father meet    What are the last 5 digits   letters of your driver 's license number    What is the first name of the boy or girl that you first dated    What is the first name of your first supervisor    What is the name of the first school you attended    What is the name of the school that you attended aged 14-16    What is the name of the street that you grew up on    What is the name of your favorite childhood friend    What is the street number of the first house you remember living in    What is your oldest sibling 's birthday month and year   eg, January 1900    What is your youngest sibling 's birthday    What month and day is your anniversary   ie January 2    What was the city where you were married    What was the first musical concert that you attended    What was your favorite activity in school  A cookie called  qasent  is spawned by the process HR recruiters with website accounts should be wary of any such irregularities If the account is potentially tied to a bank account and a spending budget   it's a target for banking trojans It wouldn't be a bad idea for sites such as Monster to introduce two factor authentication, beyond mere security questions   Analysis by   Mikko Suominen On 25 03 14 At 11 57 AM </description><link>http://www.secuobs.com/revue/news/504679.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/504679.shtml</guid></item>
<item><title>Vero Phishing Sighted</title><description>Secuobs.com : 2014-03-20 12:26:39 - F Secure Antivirus Research Weblog -  It's not exactly the perfect timing for tax refunds in Finland, but that did not deter impatient phishers to do it Earlier today, we received a tip regarding an email that has been going around pretending to be a Vero refund  IMAGE  When the link on the page is visited, the user will end up in a page that looks like this   IMAGE  It contains all the fields that the user of course needs to fill up, not to get a refund, but to give their credit card numbers and personal information away Folks, please delete that email It's not from Vero -- Post by Christine On 20 03 14 At 11 08 AM </description><link>http://www.secuobs.com/revue/news/503954.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/503954.shtml</guid></item>
<item><title>Gameover ZeuS Jumps on the Bitcoin Bandwagon</title><description>Secuobs.com : 2014-03-14 13:16:05 - F Secure Antivirus Research Weblog -  We're always asking our analysts the following question  seen anything interesting  And yesterday, the answer to our query was this  Gameover ZeuS has some additional strings Very interesting, indeed Here's a screenshot of the decrypted strings  Gameover ZeuS Bitcoin strings   aBitcoinQt_exe   aBitcoind_exe   aWallet_dat   aBitcoinWallet   aBitcoinWalle_0 Bitcoin wallet stealing has really moved up from the bush leagues Gameover ZeuS is a pro Analysis is ongoing Here's the SHA1  657b1dd40a4addc1a6da0fb50ee6e325fff84dc4 Analysis by   Mikko Suominen On 14 03 14 At 11 14 AM </description><link>http://www.secuobs.com/revue/news/502935.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/502935.shtml</guid></item>
<item><title>On NSA Hijacking of IRC Bots</title><description>Secuobs.com : 2014-03-13 15:43:04 - F Secure Antivirus Research Weblog -  Hijacking a botnet Is it ethical  No Not without very careful coordination with law enforcement   and in that case, you want to shut it down You don't want to hijack it At least  not if you're ethical But what if you're an intelligence agency  When then apparently the answer is  absolutely, yes According to recently disclosed documents, the NSA had hijacked up to 140,000 bots by 2007 Quantumbot, Takes control of idle IRC bots Quantumbot Quantumbot, Highly Successful Source  There Is More Than One Way to Quantum And they didn't stop in 2007 Another document includes details about Quantumbot 2 Combination of Q-Bot Q-Biscuit Source  The NSA and GCHQ s QUANTUMTHEORY Hacking Tactics The NSA  a morally and ethically bankrupt institution that makes others feel silly for bothering with due process Thanks On 13 03 14 At 02 03 PM </description><link>http://www.secuobs.com/revue/news/502767.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/502767.shtml</guid></item>
<item><title>Governments, The Web and Surveillance</title><description>Secuobs.com : 2014-03-12 12:02:02 - F Secure Antivirus Research Weblog -  When the web became commonplace, the decision-makers ignored it, considering it irrelevant As a result, freedom flourished online People weren't just consuming content  they were creating it But, eventually, politicians and leaders realised how important the internet is And they realised how useful the internet can be for other purposes   especially for surveillance of citizens The two chief inventions of our generation   the internet and the mobile phone   changed the world However, they both turned out to be perfect tools for the surveillance state And in such a state, everybody is assumed guilty US intelligence agencies have a full legal right to monitor foreigners   and most of us are foreigners to the Americans So when we use US-based services, we are under surveillance   and most of the services we use are US-based Advancements in computing power and data storage have made wholesale surveillance possible But they've also made leaking possible, which will keep organisations worrying about getting caught over any wrongdoing The future of the web is hanging in the balance between parties that want to keep us under surveillance and parties that want to reveal the nature of such surveillance Both parties have the data revolution on their side While governments are watching over us, they know we're watching over them Mikko Hypponen This column was originally published in Wired's Web at 25 Special Be sure to read the other columns from Tim Berners-Lee, Jimmy Wales, Vint Cerf and others On 12 03 14 At 10 35 AM </description><link>http://www.secuobs.com/revue/news/502513.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/502513.shtml</guid></item>
<item><title>How many Beliebers will blindly click on a link </title><description>Secuobs.com : 2014-03-11 16:01:23 - F Secure Antivirus Research Weblog -  Somebody with access to Justin Bieber's Twitter account was  hacked  on March 8th And for a brief period of time, the attacker was able to publish as Bieber It's hardly worth mentioning except for the fact that the Tweets included a bitly link   and offers a few interesting statistics How many Beliebers clicked on the bitly links  Clicks 70,381 in total And where did the clicks come from  Location The USA was the source of nearly 24,000 clicks  Finland apparently has 348 true Beliebers  Map 70 thousand clicks from more than 50 millions followers   that's not a very big percentage overall But still, not a bad result for the spammer considering the account was only compromised for 15 minutes You can examine the stats for yourself at  bitlycom 1ezBYiQ   for now  On 11 03 14 At 02 02 PM </description><link>http://www.secuobs.com/revue/news/502293.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/502293.shtml</guid></item>
<item><title>Download  Threat Report</title><description>Secuobs.com : 2014-03-10 19:47:09 - F Secure Antivirus Research Weblog -  Our Threat Report covering the second half of 2013  with some forecasting of 2014  was released last week F-Secure Labs Threat Report for H2 2013 You'll find it, and all of our previous reports in the Labs section of f-securecom On 10 03 14 At 06 24 PM </description><link>http://www.secuobs.com/revue/news/502128.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/502128.shtml</guid></item>
<item><title>Tuesday  Threat Report Webinar</title><description>Secuobs.com : 2014-03-03 15:07:45 - F Secure Antivirus Research Weblog -  We'll be having a discussion about our forthcoming H2 Threat Report tomorrow  Tuesday, March 4th, at 15 00 GMT Threat Report Webinar The details are available via Google Plus Including how you can view the live stream without logging into Google Plus  On 03 03 14 At 01 53 PM </description><link>http://www.secuobs.com/revue/news/500803.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/500803.shtml</guid></item>
<item><title>TrustyCon Video</title><description>Secuobs.com : 2014-02-28 15:20:08 - F Secure Antivirus Research Weblog -  TrustyCon, the first  Trustworthy Technology Conference  was held yesterday in San Francisco And Google YouTube volunteered a camera crew Nice  The full event can be viewed here  Mikko's presentation begins at 15 minutes and 45 seconds Other speakers  Alex Stamos, Cindy Cohn, Marcia Hofmann, Christopher Soghoian, Joseph Menn, Bruce Schneier, Garrett Robinson, Yan Zhu, Chris Palmer, Dan Boneh, Steve Weis, Jeff Moss, and Ed Felten TrustyCon's agenda has all the details And Eventifier has a great collection of related Tweets and photos On 28 02 14 At 12 48 PM </description><link>http://www.secuobs.com/revue/news/500487.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/500487.shtml</guid></item>
<item><title>Questions I'd Ask RSA's Coviello</title><description>Secuobs.com : 2014-02-26 15:28:59 - F Secure Antivirus Research Weblog -  RSA's Executive Chairman, Arthur W Coviello, gave his RSA Conference 2014 keynote on February 25th We're at a crossroads, he said Arthur W Coviello, RSA Conference And he called upon the nations of the world to adopt the following principles    1  To renounce the use of  cyber weapons  and the use of the Internet for waging war   2  To cooperate internationally in the investigation, apprehension, and prosecution of cybercriminals   3  To ensure that economic activity on the Internet can proceed unfettered and that intellectual property rights are respected around the world   4  To respect and ensure the privacy of all individuals My questions for Coviello  1  Trendy term Renouncing  cyber weapons  is easy lip service My take  Cyberwar Is Mostly Bunk I suggest that Coviello should avoid hype terms, like the US Army does, and develop a more nuanced and informed opinion Can Coviello provide a working definition of  cyber weapons  so that we may all renounce them  2  That's difficult to argue with Unless  what's Coviello's definition of a  cybercriminal  Aaron Swartz  I would like to know Coviello views on Computer Fraud And Abuse Act reform 3  I didn't realize the Internet's primary purpose was to allow  unfettered  economic activity Hmm  not sure what to make of this Seems an awful lot like he is demanding that the world respect  American  intellectual property rights Does Coviello support copyright reform  4  No question here Coviello should have led with this Seriously   Thanks in advance to anybody attending  RSAC who manages to get a straight answer from Mr Coviello on any of these questions Regards,  5ean5ullivan On 26 02 14 At 01 18 PM </description><link>http://www.secuobs.com/revue/news/499972.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/499972.shtml</guid></item>
<item><title>CryptoLocker Decryption Service</title><description>Secuobs.com : 2014-02-25 19:43:05 - F Secure Antivirus Research Weblog -  Bitcoin markets have been experiencing significant ups and downs recently  so we thought we'd check on the current rate at the CryptoLocker Decryption Service A specific keyword search located  a non-Tor  CDS at pyidtyncbecmgnet   hosted in Moscow We uploaded a CryptoLocker encrypted file from November KEY PAIR FOUND And when our key pair was found  The asking price was 4 BTC   the same as November Only the value of Bitcoin has fluctuated quite a bit since then At today's price, 4 BTC is worth about 2,000 USD, one thousand dollars cheaper than the last time we wrote about CDS A bargain  On 25 02 14 At 06 26 PM </description><link>http://www.secuobs.com/revue/news/499794.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/499794.shtml</guid></item>
<item><title>Obligatory  Hacker in a Hoodie  Photo</title><description>Secuobs.com : 2014-02-21 15:55:44 - F Secure Antivirus Research Weblog -  As you may already know  Poika on the Town , our Client Security was recently awarded AV-TEST's Best Protection 2013 2014 marks the third consecutive year we've won an AV-TEST Best Protection Award and we've decided to celebrate with a party for the fellows  as we call ourselves  involved in the effort We got some gear for the party, including hoodies for the fellows  Karmina in a hoodie Karmina and Sarogini Did you notice there's something different about our logo on the hoodie  Here's what it looks like close-up  ASCII version of logo  Click image for code  You'll notice the logo is made up of valid JavaScript code, so you can also  run the code  Oh, we got some drinks coasters and stickers, too This merchandise is super-popular around the office Thanks to Eero Kurimo from Security Research for the awesome design  And also to Milla  for the budget  Post by   Andy and Eero On 21 02 14 At 01 47 PM </description><link>http://www.secuobs.com/revue/news/499169.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/499169.shtml</guid></item>
<item><title>Android Malware Charges For Flash Player</title><description>Secuobs.com : 2014-02-20 17:01:48 - F Secure Antivirus Research Weblog -  Fake  malicious  Flash Player apps for Android are nothing new It's very typical bait But recently, we came across a  Flash Installer  whose audacity is off the scale The so-called installers are dropped by other Android malware and look like this  So-called Flash Player installers  SHA1  1398b8369e16a632dae67f3382bc7bcea748749a  When the app is opened, the user is prompted to pay five bucks  Instant Download PayPal And what do you get if you pay  A download link for Adobe Flash Player 11111581 at adobecom  That's right Pay five bucks and you'll receive a download link to the authentic source Biggest Ripoff Ever You can also pay for download links to a YouTube MP3 downloader and Flappy Bird Flash, YouTube, Flappy Bird Caveat emptor   Analysis provided by   Marko On 20 02 14 At 03 28 PM </description><link>http://www.secuobs.com/revue/news/498945.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/498945.shtml</guid></item>
<item><title>The End is Nigh</title><description>Secuobs.com : 2014-02-19 11:08:26 - F Secure Antivirus Research Weblog -  It's coming  Countdown Clocks On 19 02 14 At 09 36 AM </description><link>http://www.secuobs.com/revue/news/498645.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/498645.shtml</guid></item>
<item><title>Hacker  for Facebook  on Google Play</title><description>Secuobs.com : 2014-02-18 19:16:26 - F Secure Antivirus Research Weblog -  We were recently asked about the numerous  Facebook password hacker  apps available on Google Play We decided to take a look at one called  Hacker  for Facebook  Hacker  for Facebook  It's a lair right out of the gate   In order to work properly, you should rate the app with 5 stars  Hacker  for Facebook  Hacker  for Facebook  Rate an app to work properly  Bollocks And here's an example of an advertisement which is shown  Hacker  for Facebook  Hacker  for Facebook  Fake AV scams Nice So, would you trust this app when prompted to login to Facebook  Hacker  for Facebook  Here's the app's description   Hacker  for Facebook   previously Facebook Hacker  is the ideal app that automatically is gaining access to any Facebook user account and his data If you want to hack the password of some user this is an ideal app for you In a simple way by just entering the victim's username or email our system will crack the password and show it to you This application uses very sophisticated and advanced algorithm to get the data from the users account and there is no possibility for mistake  The features    Facebook password hacking   Very intuitive interface   Easy and simple to run And the disclaimer   This is only a prank app Any not allowed hacking of a Facebook account with a real app would be illegal  Ah It's a prank Adding a disclaimer makes it all okay  on Google Play at least  Lying about the need for a 5 star rating and fraudulent ads  Sure, why not, it's just a  prank  app Google Play Apps is the new Zango On 18 02 14 At 05 35 PM </description><link>http://www.secuobs.com/revue/news/498539.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/498539.shtml</guid></item>
<item><title>Taking Poika Out on the Town  2014</title><description>Secuobs.com : 2014-02-14 19:44:29 - F Secure Antivirus Research Weblog -  Our F-Secure Client Security recently received the AV-TEST Award for Best Protection 2013 And, as the tradition goes, we took our  poika  for a tour of the town Poika's from the past   Best Protection 2012   Best Protection 2011   AV-Comparatives Product of the Year 2010 Numerous companies are tested   dedication is required to run at the front of the pack Congratulations team  Poika Poika at HQ Poika Poika outside the Helsinki Cathedral Poika Poika on the rocks  Poika Poika with Veli-Jussi Kesti, Director of Security Products   Photos by Paolo Palumbo On 14 02 14 At 05 51 PM </description><link>http://www.secuobs.com/revue/news/497969.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/497969.shtml</guid></item>
<item><title>Flappy Bird SID PSA</title><description>Secuobs.com : 2014-02-11 14:28:01 - F Secure Antivirus Research Weblog -  The delightfully strange phenomenon known as  Flappy Bird  has been removed from app stores by its creator, Dong Nguyen But removal from Google Play is no obstacle for some dedicated Android fans At the moment, a search for  flappy bird apk  will yield multiple links to legitimate copies of the app Flappy Bird And while that's all well and good at present  we fully expect counterfeit copies with unwanted spyware to enter the mix before long So as a public service, in the spirit of Safer Internet Day, we offer you the following information Flappy Bird v13 SHA1  9f472383aa7335af4e963635d496d606cea56622 First seen by our back end systems  2014-01-31 02 05 50 Except no substitutes    Or better yet, stick to reputable app stores and don't download APKs from the Web On 11 02 14 At 01 12 PM </description><link>http://www.secuobs.com/revue/news/497133.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/497133.shtml</guid></item>
<item><title>App Permissions 170</title><description>Secuobs.com : 2014-02-10 19:45:25 - F Secure Antivirus Research Weblog -  Released today  version 170 of our very popular F-Secure App Permissions  for Android  F-Secure App Permissions 170  What's new  UI improvements, shareable screenshots, small bug fixes, additional languages Still requires ZERO permissions of its own On 10 02 14 At 05 38 PM </description><link>http://www.secuobs.com/revue/news/496962.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/496962.shtml</guid></item>
<item><title>Malware and Winter Olympics</title><description>Secuobs.com : 2014-02-07 15:33:04 - F Secure Antivirus Research Weblog -  Whenever there's a global sporting event, we get questions about the  cyber  angle Could an event like The Olympics be targeted by malware outbreaks, or maybe DDoS attacks  And while there are some real security concerns, most coverage of cyber attacks during Olympics end up to be incorrectly reported or just hype This is not a new phenomenon Let us reprint an article from 20 years ago The below analysis was first published in the March 1994 edition of the Virus Bulletin magazine Enjoy    Olympic Games Virus Bulletin, March 1994 Analysis by Mikko Hypponen A new virus, known as Olympic  aka Olympic Aids , has featured prominently on the television, on the radio, and in the newspapers of Northern Europe since the beginning of February Its newsworthy factors are its Olympic-theme activation routine, and suspicions that it had infected the computer systems of the Lillehammer 1994 Winter Olympics Fortunately this was not the case Despite being reported in the wild in Norway, Olympic is not of Norwegian origin  it is made in Sweden by a new virus group which calls itself  Immortal Riot  Into the Underground Swedish soil seems to provide particularly fertile ground for raising virus groups  clans like Beta Boys, Demoralized Youth, and the Funky Pack of Cyber Punks have been active in Sweden in the past The latest group of virus writers, Immortal Riot, seems to consist of four members, known only by their aliases, or  handles  So far, the group has published and distributed about thirty viruses, most of which are new variants of existing strains The viruses thus far seen are not examples of technical brilliance  quite the opposite Most simply crash the computer, or manifest their presence in some other obvious way Immortal Riot also publishes an electronic magazine, 'Insane Reality', containing articles by the group members and their associates, source codes of viruses, and back-patting and back-stabbing of other members of the virus community The group seems to be little more than an ego trip for this gang of teenagers - it seems to be  cool  to be a virus writer olympic Virus Operation Olympic is a fairly typical COM file infector, which does not remain in memory, and spreads only when an infected file is executed Its method of searching for files for infection is not very efficient Once a number of files on the hard disk have been infected, it may take half a minute to find a new victim  such a slowdown is likely to make the virus easier to spot When it finds a suitable candidate for infection, the virus first checks the size of that file to ensure that the infected code will be greater than 64 Kbytes, the largest permissible size for a COM file The first bytes of the file are checked for a jump construct which the virus is about to insert If found, the virus considers the file already infected and starts to search for another victim This process is repeated until five files are infected The virus does not check the internal structure of the host file when it infects Thus, EXE files with a COM extension will be infected by the virus When such a corrupted file is executed, the virus will infects other files on the machine, but is unable to return control to the original program In most cases, the machine will crash The infection process consists of storing the original first three bytes of the file at the file end, replacing them with a jump to a setup routine, which the virus adds to the end of the file An encrypted version of the virus code is appended to the end of the file, and, finally, the virus adds a short plain-text note and the decryption routine Olympic uses a single pseudo-random variable key based on infection time to encrypt its code The routine uses either the SI or DI register as work-registers in the decryption loop, alternating between infections Thus, there are only 25 constant bytes between different virus generations These are located in two different parts of the virus The encryption method is not truly polymorphic, and is unlikely to cause problems for anti-virus vendors Olympic can infect files which have the DOS Read-Only attribute turned on, and will also restore the date and time stamps of infected files However, files grow in size by 1440 bytes, which is visible in the directory listing The virus has no directory-stealth routines, as it does not stay resident Olympian Trigger The virus was programmed to trigger on the day after the start of the 1994 Winter Olympics  12 February , and has a one-in-ten chance of activating after this date  Dice throwing  is done by checking whether the system timer s hundredth-of-seconds field is below 10 The virus does not check the current year If the trigger conditions are not met, the virus returns control to the host file On activation, the virus draws the Olympic circles on the screen, displaying comments on the Games and its mascots, Haakon and Kristin Next, it overwrites the first 256 sectors of the first hard disk in the system To ensure destruction, the virus disables Ctrl-C and Ctrl-Break checking during the destruction routine Finally, the machine hangs olympic Much of Olympic s code resembles that of viruses generated with VCL, up to the point of the standard VCL-like note  a short message in the end of the virus, which is not displayed at all The virus  note text reads   Olympic Aid s   94  c  The Penetrator  This virus is probably based on VCL- created code, modified to avoid detection by some scanners As the virus displays a picture before starting to overwrite the disk, aware computer users might be able to switch the machine off before the virus has a chance to overwrite data areas, making recovery much easier olympic --------------------------------------------------------------------- On 07 02 14 At 01 52 PM </description><link>http://www.secuobs.com/revue/news/496601.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/496601.shtml</guid></item>
<item><title>Using Hashtags Correctly</title><description>Secuobs.com : 2014-02-07 13:26:04 - F Secure Antivirus Research Weblog -  So Timo Laaksonen, head of our Content Cloud business, asked for a BIG  hashtag campaign for younited and this is what he got   younited Just kidding  Mostly  One never knows what's going to show up in our HQ's lobby these days On 07 02 14 At 11 33 AM </description><link>http://www.secuobs.com/revue/news/496581.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/496581.shtml</guid></item>
<item><title>Silicon Plagues</title><description>Secuobs.com : 2014-02-06 16:09:39 - F Secure Antivirus Research Weblog -  Every academic year since 1986, Darwin College  University of Cambridge  holds a series of eight public lectures The theme of this year's series is  Plagues Recently, Mikko presented the third lecture  Silicon Plagues Silicon Plagues The lecture covers 28 years of computer virus history The lecture is now available online, as well as via several download options Silicon Plagues, Available Formats Video   Audio On 06 02 14 At 02 35 PM </description><link>http://www.secuobs.com/revue/news/496351.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/496351.shtml</guid></item>
<item><title>FISA Transparency</title><description>Secuobs.com : 2014-02-04 20:29:25 - F Secure Antivirus Research Weblog -  On February 3rd, Facebook, Google, LinkedIn, Microsoft  including Skype , and Yahoo posted summaries of Foreign Intelligence Surveillance Act  FISA  requests made by the US Government US DOJ's FISA reporting Deputy Attorney General James M Cole   Pursuant to my discussions with you over the last month, this letter memorializes the new and additional ways in which the government will permit your company to report data concerning requests for customer information We are sending this in connection with the Notice we filed with the Foreign Intelligence Surveillance Court today   Source  The numbers  permitted  are severely limited   to ranges of 1000  or 250 if National Security Letters  NSL  are combined with FISA court requests in aggregate Oh, and nothing about  new capabilities  can be reported for two years US DOJ, FISA, New Capability Order That seems like a pretty huge loophole, doesn't it  All of the companies involved claim they want to say more As Google states in its summary   Specifically, we want to disclose the precise numbers and types of requests we receive, as well as the number of users they affect in a timely way  Here's a fun thought experiment  What do you suppose would happen if European countries passed transparency reporting laws requiring what Google says it wants to be permitted  On 04 02 14 At 06 54 PM </description><link>http://www.secuobs.com/revue/news/495947.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/495947.shtml</guid></item>
<item><title>2004-01-30  Weblog for Mydoom Incident Started</title><description>Secuobs.com : 2014-01-30 14:44:49 - F Secure Antivirus Research Weblog -  Monday, the 26th of January, 2004  Mydoom started spreading Today it's been exactly 10 years since the massive Mydoom email worm outbreak http tco SLskpyrgnw pictwittercom Ip03yD2gRb   Mikko Hypponen  mikko  January 26, 2014 And on Friday, the 30th of January, 2004  the universe's first antivirus blog was born  Weblog for Mydoom Incident Started Then Sunday  It's Sunday Continuing to this very day  Thank you, loyal readers To quote Mikko   I've never had an uninteresting day at work  And the mission of this blog  To share some of the fun Code Warriors  FSHQ's lobby Lab coats  Nerds Alexey, Jusu, Jarno, and Jarkko  AJJJ Helsinki   Kuala Lumpur  Everybody together Ero in action  Ero in action Mika the virenjager  Virenjager Antti's phish story  Fishing Bagles  Not really bagels, just bagel shaped bread Testing laptop locks  Putting a Kensington lock to the test Most people don't even know what a rootkit is  Most people, I think, don't even know what a Rootkit is, so why should they care about it  Happy Anniversary, News from the Lab  On 30 01 14 At 01 06 PM </description><link>http://www.secuobs.com/revue/news/495021.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/495021.shtml</guid></item>
<item><title>It looks like you're trying to redact a document</title><description>Secuobs.com : 2014-01-28 11:36:55 - F Secure Antivirus Research Weblog - The New York Times, ProPublica, and The Guardian have just published articles with details on how the NSA and GCHQ use  leaky  mobile phone apps to track targets Unfortunately, one of the source documents published by The New York Times wasn't properly redacted And the end result is that an NSA employee's name has been disclosed  and well as information about an NSA target  It looks like you're trying to redact a document Information wants to be free it seems  More details on the SNAFU from  The Daily Banter On 28 01 14 At 10 18 AM </description><link>http://www.secuobs.com/revue/news/494486.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/494486.shtml</guid></item>
<item><title>City of Franca Website Compromised</title><description>Secuobs.com : 2014-01-23 00:13:28 - F Secure Antivirus Research Weblog -  While analyzing the URLs of malicious redirectors our product had detected, a Flash object hosted on govbr domain caught my eye Since my Portuguese is a little rusty, I turned to a colleague in our office in Brazil, and she confirmed that the domain belongs to the city of Franca in São Paulo, Brazil One of the JavaScript files on the website has been appended with malicious code that loads the Flash redirector Here is a snippet of the Fiddler session  Screenshot of Fiddler session The request highlighted in yellow loads the malicious Flash object which injects an iframe that redirects the browser to another domain  blurred in the screenshot  It seems that the website was compromised by exploiting the outdated version 15 of open-source content management system Joomla Most likely this is not the only govbr website running the unpatched version  Senior Security Researcher Fabio Assolini pointed out in his tweet that incidents on govbr domain are very common We have contacted the Computer Security and Incident Response Team - CTIR Gov about the incident F-Secure detects the malicious Flash object  SHA1 b0c68dbd6f173abf6c141b45dc8c01d42f492a20  as Trojan SWF RedirectorEQ In addition, our Browsing Protection component blocks access to the compromised URLs until the website has been cleaned Post by    Timo On 22 01 14 At 10 27 PM </description><link>http://www.secuobs.com/revue/news/493424.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/493424.shtml</guid></item>
<item><title>Policeware   good or bad </title><description>Secuobs.com : 2014-01-21 19:31:47 - F Secure Antivirus Research Weblog -  The malware scene is changing constantly, and one of the remarkable changes is that today the bad guys might be the good guys That is, the guys who were supposed to be good To express it slightly less confusing, authorities have become one of the major malware players and US agencies are already the world's largest buyers of exploits This makes an old ethical question for us malware fighters more important than ever How to deal with policeware  Should this kind of malware be detected or not  F-Secure's stance has been clear Yes, we do detect any kind of malware And no, we do not keep any whitelists for authorities' policeware We have not received any requests to whitelist policeware, and we would refuse to do so if requested This might raise mixed feelings as there no doubt are cases where the police work for our common good There are dangerous criminals that should be behind bars, so why not use any available weapon against them  Aren't we protecting them by refusing to whitelist policeware  Let's take a closer look at the problem and we'll see why there really is no alternative to our current policy Why is it a bad idea for an anti-malware vendor to whitelist policeware    Authorities' powers are always restricted to a defined geography, but our anti-malware technology is used globally There is no reliable way for the scanner engine to verify that the policeware is used within its author's jurisdiction   Legit warrants always define the suspect But our anti-malware technology is generic for all customers and can't verify that the policeware is used against the right target   When encountering a whitelisted file, our scanner can't verify who is controlling it and who it reports back to Whitelisting would be irresponsible as real malware could sneak through that way   We have an obligation to protect our customers from malware as well as we can That's what we promise when selling the product We could naturally make an exception in cases where there is a valid warrant against the user But as stated above, it is impossible to verify that condition   Laws are different in every country The policeware might be legal in one country but illegal in another This is complex and unfeasible for us to investigate   Which countries' authorities should we serve  We might trust our own country's police, but what about Spain, Brazil, Canada, Israel, Egypt, China, North Korea or USA  Just to mention some randomly picked countries Should we serve them too  How can we verify that they have legit motives for using spying tools    If policeware is misused without an appropriate warrant or otherwise against the law, we have a moral obligation to inform the victim Otherwise we take part in the crime So the problem is really that valid warrants target a well-defined individual or group, but a whitelisting of policeware would be targeting our whole user-base globally That makes the downside of whitelisting magnitudes larger than the upside But that's not all Here's why it is an even worse idea for agencies to ask for whitelisting   Whitelisting requires us to know what to whitelist The policeware must have a unique and reliable identification mechanism A core goal for malware is to be as hard as possible to detect, and such an identifier will make the policeware easier to detect and less effective It could be used for both white- and blacklisting   Whitelisting forces agencies to reveal details about their policeware programs to outsiders, which increase the risk for leaks They also need to reveal the mere existence of the program Keep in mind that they would need to talk to many anti-malware vendors to get effective whitelisting, not just to us   The reliable identifier needed to whitelist policeware ties it to the agency It gives the suspects a way to know that they are being watched by the authorities A malware infection that is detected could otherwise blend in with the overall malware threat and not necessary alert the suspects   As recent news coverage reveal, a significant part of the policeware seems to be outright illegal or at least on shaky ground This makes it even less sensible for the agencies to talk to outsiders about it The best strategy for agencies is to play the same game as the bad boys To change the policeware constantly and try to fly under the anti-malware products' radar When their program gets caught, they change it and try again, and the target may think it was an ordinary malware attack Law enforcement agencies have plenty of resources and are well able to play this game successfully And many criminals are probably not that tech savvy Even big organized gangs might operate without properly protected computers Reality is not like in the movies where the villain is both a global drug dealer and a super-hacker at the same time Many criminals are soft targets even without whitelisting policeware Our policy to never whitelist is old already, but today it's more important than ever The police used to be trustworthy in the good old days Warrants and targeted actions against suspects have been seen as a legit part of crime-fighting It's sad to see how this traditional police work blends into secret mass surveillance with totally different motives It's not only sad, it's scary as this is creating a chasm between citizens and the authorities With this in mind, it is easy to see why a strict policy against whitelisting really is the only alternative It has always been an easy choice, now it is a no-brainer Post by   Micke On 21 01 14 At 05 09 PM </description><link>http://www.secuobs.com/revue/news/493091.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/493091.shtml</guid></item>
<item><title>Was  Metadata  leaked in the Target breach </title><description>Secuobs.com : 2014-01-17 15:27:29 - F Secure Antivirus Research Weblog -  The Target data breach has been big news ever since Brian Krebs broke the story several weeks ago And our analysts have been investigating the related malware samples, all very interesting, but one thing I'd like to know is this  if Target knows you're pregnant  do the hackers now know, too  Back in February of 2012, the New York Times published an article by Charles Duhigg based on his book, The Power of Habit And one of the more interesting things revealed in the article, was that Target very actively analyzes customer behavior patterns life events pregnancy prediction score In other words  Target generates lots of metadata and customer analytics According to Bloomberg, Target has said the theft of customer data may have affected anyone who provided it basic information over the past several years Provided  As in data that was filled out on an application for credit   or does  provided  include data that was learned based on shopping patterns  The breach of 70 million records which included name and home address hints at a back end compromise that is far deeper than point of sale malware We've all learned the value of metadata in the last half-year Forget about the breached credit card numbers Target's analytics would be an identity theft goldmine Post by    Sean On 17 01 14 At 01 43 PM </description><link>http://www.secuobs.com/revue/news/492406.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/492406.shtml</guid></item>
<item><title>Compromised Sites Pull Fake Flash Player From SkyDrive</title><description>Secuobs.com : 2014-01-15 21:34:57 - F Secure Antivirus Research Weblog -  On most days, our WorldMap shows more of the same thing Today is an exception 1_wmap  106k image  One infection is topping so high in the charts that it pretty much captured our attention Checking the recent history of this threat, we saw that these past few days, it has been increasing in infection hits 2_spike  9k image  So we dug deeper It wasn't long before we saw that a lot of scripts hosted in various websites got compromised Our telemetry actually showed that almost 40pourcents of the infected websites were hosted in Germany In those sites, malicious code has been appended to the scripts which could look as simple and short as this  4_script  12k image  Or a bit longer to include the use of cookies, such as this  3_code  132k image  Successful redirection leads to a fake flash download site that look similar to these pages  5_flash1  64k image  6_flash2  32k image  6_main_page_after_clicking_download  40k image  The user would have to manually click on the Download Now link before a file called flashplayerexe could be downloaded from a certain SkyDrive account When the malicious flashplayerexe is executed, this message is displayed to the user 7_dialog  1k image  While in the background, it is once again connecting to the same SkyDrive account in order to download another malware 8_skydrive  21k image  Initial analysis showed that the sample is connecting to these locations 9_post  59k image  SHA1 Hashes  804d61d9d363d2ad412272043744701096e4b7f8 b9af02020389459d01911c7c4f4853bf3b5eafe4   Post by   Karmina and Christine --------------------------------------------------------------------- On 15 01 14 At 07 40 PM </description><link>http://www.secuobs.com/revue/news/491834.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/491834.shtml</guid></item>
<item><title>Fake Minecraft Android app using Smalihook</title><description>Secuobs.com : 2014-01-15 13:16:45 - F Secure Antivirus Research Weblog -  While we were analyzing the fake Minecraft app the other day, we noticed that it was using a hacking tool called Smalihook, so we took a look at it The tool is for hooking Java functions and it works just like any other hooking library After the hooked function triggers, it can return anything to the caller In this case, the following functions were hooked    getInstallerPackageName String packageName    getPackageInfo String packageName, int flags  The function getInstallerPackageName does the following    Retrieve the package name of the application that installed a package This identifies which market the package came from When this hook triggers, it returns the value  comgoogleandroidfeedback , even though the app wasn't downloaded from the Google Play Store  it just wants to look like it came from there The function getPackageInfo does the following    Retrieve overall information about an application package that is installed on the system smalihook  6k image  The hook monitors if the second parameter is using constant 0x00000040  64  GET_SIGNATURES, then will return the original Mojang certificate from inside the dex file  the trojanized app itself is signed with a debug certificate  This is done because the legitimate app it was based on includes an authentication routine that causes it to fail to run if it does a certificate verification check and doesn't find the correct certificate Mojang developers apparently didn't want their application to be spread in packages signed using a developer cert, especially since their app is not free Smalihook seems to be part of the AntiLVL  Android License Verification Library Subversion  cracking tool The purpose of these tools is to break license protection systems and they are aimed at developers who wants to test their own protections against common types of attacks The tool is publicly available and can be downloaded from the link below    http androidcrackingblogspotfi p antilvl_01html Smalihook is also available in the same page    http androidcrackingblogspotfi 2011 03 original-smalihook-java-sourcehtml The author of smalihook seems to use the tag  lohan  the author's contact information is also available on the same page Incidentally, the site included this notice  androidcracking  7k image   For educational purposes only oh wait ------- Post by - Marko On 15 01 14 At 11 13 AM </description><link>http://www.secuobs.com/revue/news/491702.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/491702.shtml</guid></item>
<item><title>Android   Fake  Minecraft App</title><description>Secuobs.com : 2014-01-14 17:54:54 - F Secure Antivirus Research Weblog -  Every other Monday, our Threat Research team contributes to PC Magazine's Mobile Threat Monday And yesterday's post is about a fake  hijacked  Minecraft app PC Magazine, Mobile Threat Monday  Fake Minecraft Scams Android Gamers Max Eddy   F-Secure told SecurityWatch that the phony Minecraft PE is currently available on several Russian app stores This isn't surprising as not all third party stores vet their apps as thoroughly as Google, making some of them havens for malicious applications Careful readers will probably remember that cloned versions of popular apps are nothing new  in fact, it's a common tactic to trick victims into downloading and installing malicious applications These fake apps are generally free, to further entice victims, but this ersatz Minecraft PE bucks the trend by charging 250 Euros for the app the real app costs 549 Euros  Fake_Minecraft_Added_Permission The real game is included but includes this  androidpermissionSEND_SMS, and the payment system has been  enhanced  Check out PC Magazine for the full story  Mobile Threat Monday  Fake Minecraft Scams Android Gamers On 14 01 14 At 03 56 PM </description><link>http://www.secuobs.com/revue/news/491529.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/491529.shtml</guid></item>
<item><title>NSA  We Are Heavily Biased Toward Defense</title><description>Secuobs.com : 2014-01-13 17:47:32 - F Secure Antivirus Research Weblog -  On January 7th, Wired magazine published an article by Steven Levy titled  How the NSA Almost Killed the Internet It's definitely worth a read But among other things there's this bit from Rick Ledgett, a deputy director who heads the NSA s Media Leaks Task Force   We are heavily biased toward defense,  Ledgett adds, citing one case in which the NSA discovered a serious vulnerability in one company's software that could have impacted users all over the world  We talked about it for a few days internally and decided it was so critical to the entirety of the US government and most of America that we disclosed  the vulnerability to that company  We could have made hay on that forever on a huge range of targets  Rick Ledgett Wow The NSA responsibly disclosed  a  serious vulnerability Well  kudos to the NSA  That one anecdotal story of disclosure almost  but not even quite  makes up for the numerous zero-day exploits, drivers signed with stolen  JMicron and Realtek  certificates, MD5 hash collisions, and the CPLINK vulnerability unleashed upon the world via Stuxnet, Duqu, and Flame We are heavily biased toward defense  Please That just doesn't pass the straight face test On 13 01 14 At 04 34 PM </description><link>http://www.secuobs.com/revue/news/491308.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/491308.shtml</guid></item>
<item><title>Polar Vortex Special  iPhone 5s in a Freezer</title><description>Secuobs.com : 2014-01-09 14:53:53 - F Secure Antivirus Research Weblog -  Folks in the USA are experiencing some very cold weather this week   and so there are many media stories referencing  sub-zero  weather and the  polar vortex  And of smartphones failing in the cold  NPR  Forget Tweeting The Polar Vortex Phones Fail In Subzero Temps Source  NPR Being no strangers to cold in Finland   we recently replicated our 2007 iPhone in a freezer experiment YouTube  iPhone 5s in a Freezer Don't have an iPhone  Check out Ossi Jaaskelainen's article  Sub-Zero Weather  Can Your Smartphone Stand The Cold  On 09 01 14 At 12 46 PM </description><link>http://www.secuobs.com/revue/news/490603.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/490603.shtml</guid></item>
<item><title>Spam Overdose Yields Fareit, Zeus and Cryptolocker</title><description>Secuobs.com : 2014-01-09 14:53:53 - F Secure Antivirus Research Weblog -  Somebody has been busy these past two days We have seen a massive spam surge with the same subjects and attachments in our spam traps emails  40k image  emailstats  28k image  The attachments usually have the following filenames attachname  11k image  The binary attachment is a threat that is often referred to as Fareit Fareit is known to steal information such as credentials and account information from installed FTP clients and cryptocurrency wallets, and stored passwords in browsers For the two samples coming from these spam, we've seen them connecting to these to send information    networksecurityxhoptoorg   18816738131   941361312   66241103146   37950200 In addition to stealing data, these samples download other malware including Zeus P2P from    ip-97- net zA6exe   119 4 fF3krryexe   rot com 124Tzhexe   ww ngnet bpuMpexe   dev com 1mHifVuexe   surfa com DJmexe   kl com Q4EzTexe Other malware seen installed in the system was Cryptolocker btc  182k image  Apparently, spam overdose results in malware overdose Samples are detected as TrojanPwsTepfer and TrojanGenericKD variants --------------------------------------------------------------------- On 09 01 14 At 01 15 PM </description><link>http://www.secuobs.com/revue/news/490602.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/490602.shtml</guid></item>
<item><title>'Tis the Season of the Canada Goose</title><description>Secuobs.com : 2014-01-07 18:58:16 - F Secure Antivirus Research Weblog -  Scammers are getting creative Since online pharmacies, fake watches and selling generic goods are becoming commonplace, they are now switching to peddling seasonal products Starting around last September, registrations of websites selling suspicious Canada Goose jackets have begun sprouting like mushrooms People living near the poles have a love affair with this brand They are one of the manufacturers of down jackets that make someone's winter experience a little warmer As such, they have a loyal following Apparently, the scammers are now aware of this Recently, advertisements for these sites have appeared in Facebook for users in Finland This is pretty sad because considering the prices for Canada Goose jackets here in Finland, this can really cause someone's eyes to pop fb3-blur  94k image  fb-mobile  232k image  Upon clicking the ads, one ends up in a normal-looking shopping site Complete with all the online shopping bells and whistles canada_goose  332k image  The ads have some mixed comments, from people saying that this is too good to be true, to those who almost bought them Now why do we think this site smells foul  - Website has only 1 year validity - Registrant is not local to the country continent it's selling to  currently registered in China  - Website is selling goods at 50-70pourcents discount  Have you ever seen Canada Goose at these prices  - Website has no encryption when user is filling in personal information - The store site is not an official Canada Goose retailer according to Canada Goose's online retailer search tool  arctic_parka3  21k image  Oakley was also victimized by this scamming method last year and they took strong measures by seizing sites down and giving visitors some information on it  oakley_legal2  188k image  Kudos to Oakley for being so vigilant against this  Although these reputable brands are taking strong measures to take down these fake sites, it's possible that a potential buyer may stumble unto them before the actual brand owners do As such, we can't emphasize it strongly enough, please be extra careful when shopping online Scam sites are sprouting everywhere and are selling anything that anyone can possibly want If this is the first time you have heard of the website, you are unsure of its reputation, and the offers are very tempting, it would be best not to shop there There is no certainty that you will get the right product, or even anything at all in return F-Secure Users with their browsing protection enabled are protected from these suspect sites Post by   Karmina and Christine On 07 01 14 At 05 01 PM </description><link>http://www.secuobs.com/revue/news/490222.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/490222.shtml</guid></item>
<item><title>2013  What Brought Us Together</title><description>Secuobs.com : 2013-12-30 23:57:00 - F Secure Antivirus Research Weblog -  It's almost 2014 This wrap-up video, featured on Mashable, was made by Jean-Louis Nguyen  playlist  On 30 12 13 At 10 49 PM </description><link>http://www.secuobs.com/revue/news/488964.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/488964.shtml</guid></item>
<item><title>An Open Letter to the Chiefs of EMC and RSA</title><description>Secuobs.com : 2013-12-23 22:53:15 - F Secure Antivirus Research Weblog -  23rd of December 2013 An Open Letter to  Joseph M Tucci - Chairman and Chief Executive Officer, EMC Art Coviello - Executive Chairman, RSA Dear Joseph and Art, I don t expect you to know who I am I ve been working with computer security since 1991 Nowadays I do quite a bit of public speaking on the topic In fact, I have spoken eight times at either RSA Conference USA, RSA Conference Europe or RSA Conference Japan You ve even featured my picture on the walls of your conference walls among the 'industry experts' On December 20th, Reuters broke a story alleging that your company accepted a random number generator from the National Security Agency, and set it as the default option in one of the your products, in exchange of  10 million Your company has issued a statement on the topic, but you have not denied this particular claim Eventually, NSA s random number generator was found to be flawed on purpose, in effect creating a back door You had kept on using the generator for years despite widespread speculation that NSA had backdoored it As my reaction to this, I m cancelling my talk at the RSA Conference USA 2014 in San Francisco in February 2014 Aptly enough, the talk I won t be delivering at RSA 2014 was titled  Governments as Malware Authors  I don t really expect your multibillion dollar company or your multimillion dollar conference to suffer as a result of your deals with the NSA In fact, I'm not expecting other conference speakers to cancel Most of your speakers are american anyway   why would they care about surveillance that s not targeted at them but at non-americans Surveillance operations from the US intelligence agencies are targeted at foreigners However I m a foreigner And I m withdrawing my support from your event Sincerely, Mikko Hypponen Chief Research Officer F-Secure On 23 12 13 At 09 46 PM </description><link>http://www.secuobs.com/revue/news/488123.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/488123.shtml</guid></item>
<item><title>TED Talk, in Your Language</title><description>Secuobs.com : 2013-12-20 15:01:08 - F Secure Antivirus Research Weblog -  All talks on TEDCOM are translated to various languages And all this work is done by volunteer TED Translators TEDx My talk on NSA Surveillance has now been translated to following languages  Dutch Finnish French German Greek Hebrew Hungarian Indonesian Italian Korean Persian Brazilian Portuguese Romanian Spanish In fact, there are 16 more translations underway I'd like to thank the people who have translated and reviewed the translations of my Brussels talk  Els De Keyser, Petra van der Burg, Sami Andberg, Gemma Lee, 남준 김, Leslie Louradour, Mira Kraïmia, Stefanie Ramcke, Julia-Carolin Zeng, Chryssa Rapessi, Dimitra Papageorgiou, Shlomo Adam, Ido Dekkers, Mariann Buzás, Laszlo Kereszturi, Gustavo Rocha, Mariana Yonamine, Dewi Barnas, Arief Rakhman, Anna Cristiana Minoli, Alessandra Tadiotto, Maryam Manzoori, Amirpouya Ghaemiyan, Doina Zamfirescu, Ariana Bleau Lugo, Ciro Gomez and Lidia Cámara de la Fuente -- and everyone working on future translations Thanks and Merry Christmas  Mikko On 20 12 13 At 12 45 PM </description><link>http://www.secuobs.com/revue/news/487693.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/487693.shtml</guid></item>
<item><title>We're Hiring  Apply Now, Lots of Perks</title><description>Secuobs.com : 2013-12-18 19:13:24 - F Secure Antivirus Research Weblog -  Today I looked out my 2nd floor window and spied Pekka Usva having lunch in a small ad hoc meeting room Pekka Usva, rear window And that reminded me  I read an e-mail of his last week  while home, attempting to recover from bronchitis    F-Secure is hiring  There are currently two developer positions publicly open in Helsinki    Junior Software Engineer   Senior Lead Software Engineer  Server side, Python  There were some UX designer positions open last week And possibly more stuff in the future A lot of Pekka's hiring revolves around our corporate security business line's goal of developing cloud security for SMBs  combining a lot of our recent consumer offerings into one SMB product  Combining younited, Freedome, and mobile device management with a completely redesigned UX  Plenty of folks will need to be very busy  No wonder this is Pekka's  executive  lunch  Pekka Usva, up close Actually, I've socialized with Pekka outside of the office and he's a rather regular kind of guy, like a lot of our management If he wasn't doing a working lunch while meeting with Jussi  out of frame , then he'd just be next door at the company commissary That's life at a Finnish company  Join us  R, Sean On 18 12 13 At 04 31 PM </description><link>http://www.secuobs.com/revue/news/487222.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/487222.shtml</guid></item>
<item><title>Holiday Shopping Tip  Replace Windows XP </title><description>Secuobs.com : 2013-12-11 17:04:49 - F Secure Antivirus Research Weblog -  Christmas  It's approaching quickly And something else is looming on the horizon  the end is nigh for Windows XP  Windows XP, Support is ending soon Support ends on April 8, 2014 If you're still using XP, please do yourself a big favor this Christmas shopping season and buy yourself a new PC Or maybe a Mac The women in the picture above probably own a Mac in real life, don't you think  Either way, now is an excellent time to make the jump Even a basic, relatively inexpensive PC is far more productive than any hardware which would still be running XP And yeah, if you're reading this blog   you already know that So tell your friends and family already Merry Christmas On 11 12 13 At 03 04 PM </description><link>http://www.secuobs.com/revue/news/485685.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/485685.shtml</guid></item>
<item><title>Sharking  High-Rollers in the Crosshairs</title><description>Secuobs.com : 2013-12-10 15:46:07 - F Secure Antivirus Research Weblog -  We get a lot of samples here at F-Secure Labs, most of them being submitted online But every now and then, somebody visits one of our labs and brings along their computer for forensics Earlier this year, a guy in his early 20's pulled up and parked his Audi R8 just outside our Helsinki HQ His name is Jens Kyllönen   a professional poker player   both in real world tournaments and in the online poker world He's a high-roller by any measure, with wins in the range of 25 million dollars from the past year Jens Kyllonen So why would this poker star detour from his usual routine and drop by for a visit  This is his story  Last September, Jens participated in the European Poker Tour event in Barcelona He was staying at the event hotel, which is a 5-star location, and spent his day mostly at the tournament tables He took a break from the tournament and went to his room And his laptop wasn't there He checked to see if his friend had borrowed it, no, and then when he returned to his room  his laptop was back He knew that something was amiss To add to his suspicion, the OS, Windows, didn't boot properly Jens provided a more detailed scenario of what happened that day in this forum  poker_forum_post Thinking he had possibly been compromised, Jens asked us to investigate his laptop This is quite important, as laptop security is paramount for professional poker players, especially those who play online We agreed to investigate, and so we made full forensic images and started digging After a while, it was obvious that his hunch was correct, the laptop was indeed infected There was a Remote Access Trojan  RAT  with timestamps coinciding with the time when the laptop had gone missing Apparently, the attacker installed the trojan from a USB memory stick and configured it to automatically start at every reboot A RAT, by the way, is a common tool that allows an attacker to control and monitor a laptop remotely, viewing anything that happens on the machine Below are succeeding screenshots to give you a better view on how this particular RAT works In this screenshot, the attacker is able to see his own cards, similar to what any other players would experience poker_attacker_hand Using the trojan, however, he can also see that the infected machine or the victim is holding a pair of queens This gives the attacker an edge, so he knows to hold out for a better hand poker_victim_hand This kind of attack is very generic and works against any online poker site that we know of The trojan is written in Java and uses obfuscation, but isn't all that complicated Since it's in Java, the malware can run in any platform  Mac OS, Windows, Linux  Here is a snippet of the code that takes screenshots of the victim's screen  poker_jrat After analyzing Jens's laptop, we started looking for other victims It turned out that yet another professional player, Henri Jaakkola, who stayed in the same room as Jens at the EPT Barcelona event, had the exact same trojan installed in his laptop This is not the first time professional poker players have been targeted with tailor-made trojans We have investigated several cases that have been used to steal hundreds of thousands of euro What makes these cases noteworthy is that they were not online attacks The attacker went through the trouble of targeting the victims' systems on site  An Evil Maid Attack  The phenomenon is now big enough that we think it warrants its own name  Sharking Sharking attacks are targeted attacks against professional poker players  aka poker sharks  It's similar to Whaling attacks which are targeted at high profile business managers So, what's the moral of the story  If you have a laptop that is used to move large amounts of money, take good care of it Lock the keyboard when you step away Put it in a safe when you're not around it, and encrypt the disk to prevent off-line access Don't surf the web with it  use another laptop device for that, they're relatively cheap  This advice is true whether you're a poker pro using a laptop for gaming or a business controller in a large company using the computer for wiring a large amount of funds   Analysis and post by   Daavid and Antti On 10 12 13 At 12 15 PM </description><link>http://www.secuobs.com/revue/news/485396.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/485396.shtml</guid></item>
<item><title>One Decade Ago</title><description>Secuobs.com : 2013-12-05 12:56:45 - F Secure Antivirus Research Weblog -  If you were running Windows on your computer 10 years ago, you were running Windows XP In fact, you were most likely running Windows XP SP1  Service Pack 1  This is important, as Windows XP SP1 did not have a firewall enabled by default and did not feature automatic updates So, if you were running Windows, you weren't running a firewall and you had to patch your system manually   by downloading the patches with Internet Explorer 6, which itself was ridden with security vulnerabilities No wonder then, that worms and viruses were rampant in 2003 In fact, we saw some of the worst outbreaks in history in 2003  Slammer, Sasser, Blaster, Mydoom, Sobig and so on They went on to do some spectacular damage Slammer infected a nuclear power plant in Ohio and shut down Bank of America's ATM systems Blaster stopped trains in their tracks outside Washington DC and shut down Air Canada check-in systems at Canadian airports Sasser thoroughly infected several hospitals in Europe The problems with Windows security were so bad that Microsoft had to do something And it did In hindsight, the company did a spectacular turnaround in their security processes Microsoft started Trustworthy Computing It stopped all new development for a while to go back and find and fix old vulnerabilities Today, the difference in the default security level of 64-bit Windows 8 is so much ahead of Windows XP you can't even compare them We've seen other companies do similar turnarounds When the Microsoft ship started to become tighter and harder to attack, the attackers started looking for easier targets One favorite was Adobe Reader and Adobe Flash For several years, one vulnerability after another was found in Adobe products, and most users were running badly outdated products as updating wasn't straightforward Eventually Adobe got their act together Today, the security level of, say, Adobe Reader, is so much ahead of older versions of the PDF readers you can't even compare them The battle at hand right now is with Java and Oracle It seems that Oracle hasn't gotten their act together yet And maybe don't even have to  users are voting with their feet and Java is already disappearing from the web The overall security level of end users' systems is now better than ever before The last decade has brought us great improvements Unfortunately, the last decade has also completely changed who we're fighting In 2003, all the malware was still being written by hobbyists, for fun The hobbyists have been replaced by new attackers  not just organized criminals, but also hacktivists and governments Criminals and especially governments can afford to invest in their attacks As an end result, we're still not safe with our computers, even with all the great improvements But at least we don't see flights grounded and trains stopped by malware every other week, like we did in 2003 Mikko Hypponen This article was first published on GrahamCluleycom On 05 12 13 At 09 48 AM </description><link>http://www.secuobs.com/revue/news/484463.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/484463.shtml</guid></item>
<item><title>Good Passwords are KEY</title><description>Secuobs.com : 2013-12-03 17:28:19 - F Secure Antivirus Research Weblog -  Today marks the official launch date of F-Secure KEY  Our new password assistant application  But we're guessing that it hardly feels like an especially busy day for product manager Juha Torkkel He's been in full gear ever since Mikko Tweeted about KEY's  soft  launch one week ago Which then didn't turn out to be so soft Juha was immediately peppered with questions about KEY's encryption And so he produced a quick FAQ for our community knowledge base Here's the FAQ as it currently exists  F-Secure KEY data encryption  in a nutshell    F-Secure KEY uses the Advanced Encryption Standard  AES-256  algorithm in the CCM mode  CTR with CBC MAC  for encryption to protect your sensitive data The security of the AES was carefully analyzed by many crypto experts prior to selecting it as a recommended algorithm for modern data encryption   The encryption key is derived from your master password using the Password-Based Key Derivation Function 2  PBKDF2  algorithm specified in Public-Key Cryptography Standards  PKCS   5 In PBKDF2, we use Hash-based Message Authentication Code  HMAC  SHA256, random salts and 20,000 of iterations This makes it much more difficult to recover the keys through exhaustive search or dictionary attacks even for weak passwords   Each password record is individually encrypted using a unique and strong random encryption key The record-specific keys are encrypted using a master encryption key which is derived from your master password using the PBKDF2 algorithm   Your master password and the master encryption key are never stored anywhere The encryption keys live only when you use the product There is no way to recover your password or data if you forget the master password   When we developed F-Secure KEY, our guiding design principle was   We don't need to know who you are We just hope you like the product  Consequently, all the F-Secure KEY users are fully anonymous We don't track you in any way, even when you synchronize your data across devices   The F-Secure KEY servers are owned and operated by F-Secure within the European Union in compliance with Finnish law and applicable EU rules   And here's an additional Q A  Can F-Secure Key decrypt my information  Question  You state that my information is encrypted What encryption do you use, and are you able to decrypt my information and hand it over to a third party  Answer  We use AES-256 encryption in CCM  counter with CBC-MAC  mode We have no way of decrypting any information that you have saved In addition, anyone using F-Secure Key is anonymous to F-Secure, so we have no way of identifying an individual user's data So we never see any of your information at any stage, and therefore we can't decrypt it or hand it over to a third party Both the choice of encryption and anonymity of users were conscious decisions made to improve the security of the product and protect the privacy of people using it   One password to rule them all A young woman holding what appears to be an Ikea coffee cup in one hand and a smartphone in the other Just another day in Finland   KEY is free for individual device use   an optional paid sync service across devices is available Application download links can be found here  F-Secure KEY On 03 12 13 At 03 47 PM </description><link>http://www.secuobs.com/revue/news/484057.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/484057.shtml</guid></item>
<item><title>Bitcoin fraud gets connected</title><description>Secuobs.com : 2013-11-28 10:09:41 - F Secure Antivirus Research Weblog - Bitcoin  1000 Bitcoin, and other digital currencies such as Litecoin and Peercoin, will change the way we exchange money But they come with a major flaw  they can also be used to turn infected computers into devices that  print  money The beauty of the algorithm behind Bitcoin is that it solves two main challenges for cryptocurrencies - confirming transactions and generating money without causing inflation - by joining them together Confirmations are given by other members of the peer-to-peer network, who in return are given new Bitcoins for their labour The whole process is known as  mining  When Bitcoin was young, mining was easy You could earn Bitcoins by mining on a home computer However, as the currency's value grew  from  8 to  1000 during 2013  - more people applied to do it, and, in response, mining became  mathematically  harder and required more powerful computers Unfortunately, those computers don't have to be your own Some of the largest botnets run by online criminals today are monetized by mining Any infected home computer could be mining Bitcoins for a cybercrime gang Using botnets to mine is big business The second-largest botnet in the world, ZeroAccess made tens of thousands of dollars a day by using the infected machines to mine for cryptocurrencies This is especially effective when the infected machines have a high-end GPU chip on its video card Mining botnets such as these do not require a human user - just processing power and a network connection The internet of things will bring millions more connected computers on to the web, embedded in devices such as cars and rubbish bins And not all of them will have to have as high a spec as even a Windows PC to mine money  Litecoin, for example, uses more memory-intensive algorithms that can be run on a regular CPU rather than on high-end GPUs The mythical internet-connected fridge may at last have found an - admittedly criminal - reason to exist Mikko Hypponen Originally published in Wired UK 12 2013 On 28 11 13 At 08 19 AM </description><link>http://www.secuobs.com/revue/news/483403.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/483403.shtml</guid></item>
<item><title>CryptoLocker  Your  Order  is Being Processed</title><description>Secuobs.com : 2013-11-22 14:30:56 - F Secure Antivirus Research Weblog -  Today we uploaded a CryptoLocker encrypted file to its  Decryption Service  We were promptly provided our Order ID  CryptoLocker Decryption Service, Search in Progress, By using this service, you can purchase private key and decrypter for files encrypted by CryptoLocker We've read that a public private key pair match can take up to 24 hours But ours was found in under one CryptoLocker Decryption Service, Key Pair Found Because our encrypted file was created today, the price of the private key is 05 BTC Note the price will change to 4 BTC on Tuesday  after 72 hours have passed  At the time of this post, that's equal to approximately 3,000 USD or 2,200 EUR On 22 11 13 At 01 01 PM </description><link>http://www.secuobs.com/revue/news/482591.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/482591.shtml</guid></item>
<item><title>CryptoLocker  Pac-Man Fever</title><description>Secuobs.com : 2013-11-21 19:24:10 - F Secure Antivirus Research Weblog -  Two things about CryptoLocker 1 The price of Bitcoin has been wildly volatile lately And that type of commodity volatility affects Bitcoin's ability to act as a currency because prices are quickly driven out of whack Even for ransomware such as CryptoLocker Here's a screenshot from a November 20th variant  CryptoLocker 20131120, Bitcoin The price of decryption is now 05 BTC CryptoLocker 20131120, Send coins to Just a few weeks ago, the going rate was two Bitcoin 2 This is the wallpaper CryptoLocker sets  CryptoLocker 20131120, Download While the text shown above notes the destruction of  your private key    it isn't actually destroyed The site from which CryptoLocker can be downloaded also offers a  Decryption Service  that can be accessed after the countdown  But you'll have to pay more  Because the service isn't tied to a particular computer, a file must be uploaded in order for the service to match it with a key CryptoLocker Decryption Service Uploading a file includes  Pac-Man  animation while you wait  CryptoLocker, Pacman Somebody likes classic video games  On 21 11 13 At 05 31 PM </description><link>http://www.secuobs.com/revue/news/482450.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/482450.shtml</guid></item>
<item><title>CryptoLocker  Please Kindly Find Our New PO</title><description>Secuobs.com : 2013-11-20 13:31:09 - F Secure Antivirus Research Weblog -  Yesterday's CryptoLocker post mentioned that it's spreading via spam It's actually a spam campaign that installs an intermediary, and then CryptoLocker is installed But in any case, the first link in the chain that results in a CryptoLocker infection is spam And here's a fresh example of the message being used   Please kindly find our new PO per attachment Could you provide your PI for confirmation Our Order file is password protected and can be opened accessed with password  TRADING  CryptoLocker, Spam Image source   davidmacdougall The company from which the message claims to be from  blurred in the example above  is of course an innocent bystander whose good name is being abused as part of this scheme Note that the attachments are password protected This allows the threat to bypass gateway security measures If you're an information security manager, don't take it for granted that the people in your organization know not to open attachments On 20 11 13 At 11 56 AM </description><link>http://www.secuobs.com/revue/news/482069.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/482069.shtml</guid></item>
<item><title>CryptoLocker  Better Back Up Your Stuff</title><description>Secuobs.com : 2013-11-19 21:19:07 - F Secure Antivirus Research Weblog -  If you haven't heard much about  CryptoLocker  yet  you will Unlike much of the ransomware we've written about in the past, CryptoLocker doesn't attempt to use police themed trickery or other sleight of hand It's strictly business It infects via e-mail attachments  zip files containing supposed PDF files  and then sets about encrypting all of your personal data files   photos, music, documents, et cetera And then  you have three days to pay the ransom Or else CryptoLocker is trending in the US  US-CERT US-CERT Alert  TA13-309A  And in the UK  NCA Mass ransomware spamming event targeting UK computer users It's largely a problem in English-speaking countries because that's the language used in the e-mail bait For now It's certainly only a matter of time because somebody decides to expand into other languages And here's the kicker One of the ways in which you can pay  Bitcoin Cryptolocker, Bitcoin Source  Microsoft That's right, CryptoLocker accepts everybody's favorite cryptocurrency as payment And that's why this could be a tipping point One of the biggest factors keeping ransomware at bay is the difficulty it takes to get paid Thanks to Bitcoin and other similar digital currencies  that barrier is eroding fast Ransomware economics  the more frictionless Bitcoin becomes   the more prevalent CryptoLocker will become Backup your stuff On 19 11 13 At 07 34 PM </description><link>http://www.secuobs.com/revue/news/481963.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/481963.shtml</guid></item>
<item><title>Don't do business with these companies</title><description>Secuobs.com : 2013-11-14 20:40:00 - F Secure Antivirus Research Weblog -  What do Inteqno, Altran Strategies, Deticaconsulting and Nezux have in common  mule_altran mule_detica mule_integno mule_nezux Well, first of all, they are all one and the same Or actually, none of them are real companies at all They are phony online shells run by online criminals They only serve one purpose  to make it appear that these companies are legitimate, that they really exists and that they have a history These are needed so they have enough credibility to try to hire people So what kind of people are phony companies hiring  Specifically, they are hiring money mules  definition  Of course, these companies don't label their positions as  money mules , they call the job position  Customer Assistant  or  Operations Assistant  mule_careers These companies post job offers on sites like Linkedin and send them out via direct emails Sites involved with money mule scams used to be very easy to tell at first glance No Google history WHOIS data hidden with Privacy Protect Site content lifted directly from a real company Robotstxt preventing site indexing None of those are true for these sites Nevertheless, avoid them like plague On 14 11 13 At 07 26 PM </description><link>http://www.secuobs.com/revue/news/481063.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/481063.shtml</guid></item>
<item><title>New Release of Our Free Android Permissions Dashboard</title><description>Secuobs.com : 2013-11-07 20:19:26 - F Secure Antivirus Research Weblog -  F-Secure App Permissions, our Android permissions dashboard, launched on November 1st And in just under one week, there are thousands of installs and extremely positive feedback Thank you  The developers are very pleased and have been busy implementing some additional features based on the input Today they released version 125 Here's what's new  What's New Some screen shots of the app  App Permissions 125 App Permissions 125 App Permissions 125 App Permissions 125 Best of all   App Permissions requires ZERO permissions It's totally free, small, and easy to use You'll find it on Google Play  F-Secure App Permissions Please give it a try, and for those of you who already have, additional feedback is very welcome Cheers  PS We'll discuss more about App Permissions during tomorrow's webcast --------------------------------------------------------------------- On 07 11 13 At 05 55 PM </description><link>http://www.secuobs.com/revue/news/479640.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/479640.shtml</guid></item>
<item><title>DeepGuard 5 vs the CVE-2013-3906 Zero-Day Exploit</title><description>Secuobs.com : 2013-11-07 15:49:06 - F Secure Antivirus Research Weblog -  On Wednesday, we noted a zero-day vulnerability in the Microsoft Graphics component The vulnerability is being actively exploited in targeted attacks using Word documents Long story short, here's a video of the exploit losing to our Internet Security  DeepGuard 5 vs Microsoft Graphic Component Zero-Day Exploit CVE-2013-3906 The Word document in the video has been used in real attacks and is one of the exploits analyzed by McAfee and Alient Vault The attack has been recreated on an isolated test network with a vulnerable system running Office 2007 on 64-bit Windows 7 As the video demonstrates, the exploit interception feature in DeepGuard 5  our behavioral engine  prevents the system from getting infected Moreover, DeepGuard would have proactively protected our customers from this zero-day exploit already prior to the Microsoft advisory and without us ever having seen the first samples Furthermore, we did not need to add or modify any DeepGuard detections   it blocked the current zero-day with the same set of detection rules as the previous Microsoft zero-day about a month ago That is the power of proactive, behavior-based exploit protection Post by   Timo   Editor's note  Timo is a Senior Researcher and our  justifiably  proud DeepGuard service owner Kudos, Timo  On 07 11 13 At 01 46 PM </description><link>http://www.secuobs.com/revue/news/479584.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/479584.shtml</guid></item>
<item><title>F-Secure Corporation's Answer to Bits Of Freedom</title><description>Secuobs.com : 2013-11-06 22:16:39 - F Secure Antivirus Research Weblog -  We received a letter sent by Bits Of Freedom and signed by 25 different parties, who were interested in our policy on the use of our software for the purpose of state surveillance The same letter was sent to 15 other antivirus companies BOF They had four questions in particular  1 Have you ever detected the use of software by any government  or state actor  for the purpose of surveillance  2 Have you ever been approached with a request by a government, requesting that the presence of specific software is not detected, or if detected, not notified to the user of your software  And if so, could you provide information on the legal basis of this request, the specific kind of software you were supposed to allow and the period of time which you were supposed to allow this use  3 Have you ever granted such a request  If so, could you provide the same information as in the point mentioned above and the considerations which led to the decision to comply with the request from the government  4 Could you clarify how you would respond to such a request in the future   see here for the full letter  Here's our official answer, mailed back to Bits Of Freedom on the 1st of November  letter to bof See http wwwf-securecom en web labs_global policies On 06 11 13 At 09 09 PM </description><link>http://www.secuobs.com/revue/news/479448.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/479448.shtml</guid></item>
<item><title>Mobile Security Webcast  811 1700 EET</title><description>Secuobs.com : 2013-11-06 18:56:04 - F Secure Antivirus Research Weblog -  It's a good thing that I follow  FSecure's Twitter account, because apparently I'm doing a webcast with Mikko on Friday Mobile security is the topic of discussion Mobile Threat Report Q3 I vaguely remember agreeing to it based on Mikko's schedule And November 8th fit his busy travel schedule This is how I normally track his whereabouts  Moscow, Paris, Berlin Or else I receive prank texts  Greetings from Moscow Not really  mostly  Anyway, please join us on Friday, details here    Mobile Threat Report with F-Secure Labs And if you're American  like me  and  811 1700 EET  just looks like a bunch of random numbers strung together  that's November 8, 2013 at 5 00 PM  in Helsinki  which is 10 00 AM on the East Coast of North America Post by    Sean --------------------------------------------------------------------- On 06 11 13 At 04 41 PM </description><link>http://www.secuobs.com/revue/news/479400.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/479400.shtml</guid></item>
<item><title>Microsoft Security Advisory  2896666   APT</title><description>Secuobs.com : 2013-11-06 17:51:06 - F Secure Antivirus Research Weblog -  On Monday, we wrote about motivated attackers And yesterday, Microsoft issued a Security Advisory about a vulnerability which is being exploited  largely in the Middle East and South Asia  Microsoft Security Advisory  2896666  Microsoft Support has a Fix it tool  Microsoft Fix it 51004  available This is the list of affected software  Affected Software Though, there appears to be some questions about that list We recommend InfoWorld's article    Deciphering Microsoft Security Advisory 2896666 on Word zero-day exploit On 06 11 13 At 04 04 PM </description><link>http://www.secuobs.com/revue/news/479387.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/479387.shtml</guid></item>
<item><title>Facebook Name Search Changes</title><description>Secuobs.com : 2013-11-05 15:30:49 - F Secure Antivirus Research Weblog -  Facebook is changing a privacy setting Shocking, right  Anyway, the setting is not used by most people and is called  who can look up your timeline by name Here's the justification from Facebook  This is either a big deal or not, and that may have to do a lot with your name For some of us, the signal to noise ratio already provides a relatively anonymous experience While for others  Probably the key reason that Mikko doesn't really use Facebook Some folks  mostly women from what we've seen  even tweak their names just a bit, so they'll be unsearchable Whatever your privacy tactics, if you have a Facebook account, now is a good time to review the settings at facebookcom settings tab privacy We recommend turning off  Do you want other search engines to link to your timeline  On 05 11 13 At 01 49 PM </description><link>http://www.secuobs.com/revue/news/479099.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/479099.shtml</guid></item>
<item><title>Why Motivated Attackers Often Get What They Want</title><description>Secuobs.com : 2013-11-04 14:29:42 - F Secure Antivirus Research Weblog -  Do you work for a company possessing information which could be of financial value to people outside the organization  Or, perhaps even a foreign state would find it useful to gain access to the documents you're storing on that shared network drive  Yes  Then congratulations, you may already be the target of a persistent and motivated attacker  who sometimes, but rarely, is also advanced  According to this CERT-FI presentation, even Finland has seen nearly a decade of these attacks Nowadays, they're everywhere A good targeted attack case example is the one made against RSA in 2011, which our own Timo Hirvonen analyzed This post tells the whole story of Timo looking for the original source of the infection in RSA's network, which he eventually found  RSA 2011 email RSA was breached with a document sent as an e-mail attachment to an employee The document contained an embedded exploit that infected the employee's computer, which gave the attacker the foothold needed to infiltrate From that computer, they moved on to compromising the rest of the network Timo found the document from the files we receive via Virustotal, which is an online service where you can submit files to be scanned with several antivirus engines The user gets to see the scanning results, thus the likelihood of maliciousness, and the file is sent to antivirus companies for further analysis Virustotal sees hundreds of thousands of files submitted every day We spend a lot of effort analyzing the files submitted through Virustotal, as we want to make sure we detect anything malicious In addition to the day-to-day malware, we also analyze the exploit documents that suspicious users submit for scanning APT animation All these documents contained exploit code that would have automatically installed malware onto a user's computer had they opened them with a vulnerable document reader They give us a small glimpse into the targets as well  who are the people that would expect to receive attachments like this  In our latest Threat Report, Jarno Niemelä took a set these documents, extracted all the text from them and built word clouds Word clouds The word cloud on the left is from documents we categorized as being political in theme The one on the right is from documents we felt were corporate-themed The clouds give you a hint of what kind of sectors are interesting to attackers The same tricks won't work forever, though If you send enough e-mails with exploit attachments your targets will learn and adapt And so we've seen new tricks in the form of  watering hole  attacks Here's how they work  the attacker finds a website that he thinks his targets would be likely to visit If you want to target software companies such as Twitter, Facebook or Apple, perhaps you choose a mobile development website If you are going after government agencies, you might drop a zero-day exploit for IE8 on the US Department of Labor website Then you simply wait for your targets to visit the site and get infected And then there's the good old trick with USB drives Russia USB G20 We don't have any information to confirm the news that the USB drives given to G20 leaders actually contained malware If it's true, at least you can't blame the attackers for lack of optimism So, defending is simple  don't open e-mail attachments from your colleagues, don't browse the Internet and leave those USB drives alone In reality, you of course have to remember many other things too Defending against a motivated attacker is very, very difficult You have to get everything right, every single day, while the attacker just has to find one mistake you made The bad guys have it too easy and that's why so many of the organizations out there are under attack PS For some tips to protect against attacks like this, see the presentation Jarno Niemelä gave at Virus Bulletin this fall On 04 11 13 At 11 07 AM </description><link>http://www.secuobs.com/revue/news/478853.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/478853.shtml</guid></item>
<item><title>Scary Copycat Apps on Google Play</title><description>Secuobs.com : 2013-11-01 17:11:02 - F Secure Antivirus Research Weblog -  All Hallows' Eve was yesterday   aka Halloween And so naturally, there's an app for that Or many apps as the case may be Here's a series of apps designed to  scare your friends  Scare your friends This one has more than 10 million downloads Scare your friends Even these copycats have several hundred thousand downloads Scare your friends Scare your friends Android doesn't really help differentiate between them Scare your friends But if we use our permissions dashboard  App Permissions in Google Play  then we can see some big differences Scare your friends Scare your friends The most popular app only wants three permissions while the copycats want 21  And worse yet, those permissions include the ability to see your personal information That's what the copycat apps are after   your personal details Scary Given that the  legit  version of the app is  borrowing  images from Hollywood films  there's nobody with an incentive to police the copycats And Google, an advertising company, doesn't appear to have much incentive to police them either And so several hundred thousand people shared their personal details Scare you friends, indeed   Analysis provided by   Jose On 01 11 13 At 02 15 PM </description><link>http://www.secuobs.com/revue/news/478437.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/478437.shtml</guid></item>
<item><title>Are you ready for life in a smart_city </title><description>Secuobs.com : 2013-10-31 18:54:57 - F Secure Antivirus Research Weblog -  All sorts of  smart city  data is available online these days For example  here's a real time view of Helsinki's public transportation via HSL Live HSL Live And that's just the start Why stop there  WeareData is a marketing campaign for Ubisoft's upcoming game, WATCH_DOGS We Are Data Image  wearedatawatchdogscom WeareData's visualization is pretty neat, displaying three different cities  Berlin, London, and Paris We Are Data, Berlin Hotspots, ATM, CCTV, and Tweets All laid out for you on one map We Are Data, Types Welcome to the future Do you want to live there  On 31 10 13 At 04 29 PM </description><link>http://www.secuobs.com/revue/news/478267.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/478267.shtml</guid></item>
<item><title>Rent-A-Hacker</title><description>Secuobs.com : 2013-10-29 15:29:35 - F Secure Antivirus Research Weblog -  An example of what can be found on the Deep Web  rent-a-hacker Click image to embiggen This guy claims to be  a proffessional computer expert who could earn 50-100 euro an hour with a legal job  So the question is  why doesn't he  On 29 10 13 At 12 32 PM </description><link>http://www.secuobs.com/revue/news/477782.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/477782.shtml</guid></item>
<item><title>TEDxBrussels</title><description>Secuobs.com : 2013-10-28 14:45:24 - F Secure Antivirus Research Weblog -  Mikko has been presenting on the topic of state surveillance of late He'll soon be on stage at TEDxBrussels  TEDxBrussels, https twittercom mikko status 394805828852928512 Live stream    tedxbrusselseu Updated to add  If you've missed the live stream   don't worry   it will most likely end up on the TEDxBrussels YouTube channel In the meantime   published last week via Google Ideas  Stuxnet  Pandora's Box  On 28 10 13 At 11 53 AM </description><link>http://www.secuobs.com/revue/news/477499.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/477499.shtml</guid></item>
<item><title>Who Controls Free Expression in Cyberspace </title><description>Secuobs.com : 2013-10-24 15:57:26 - F Secure Antivirus Research Weblog -  Monday's BBC News  Facebook lets beheading clips return to social network On Tuesday, Facebook published a  Fact Check  Wednesday's BBC News  Facebook makes U-turn over decapitation video clip UK Prime Minister David Cameron's reaction  I'm pleased Facebook has changed its approach on beheading videos The test is now to ensure their policy is robust in protecting children Despite Cameron's plea to think of the children   there's not very much he can personally do to  ensure  anything related to Facebook's content policy Because he's impotent in the face of  the Deciders  Deciders such as Dave Willner, not yet even 30 years old, who began his career at Facebook on the night shift answering questions about its photo uploader Five years later, he's the head of Facebook's Content Policy A guy who studied anthropology and archeology That guy, and others like him in Silicon Valley are the ones deciding on freedom of expression's future on  the web  Or then, maybe not the web as so many consumers now spend a significant amount of their time in one walled garden or another But  cyberspace  at least Free Speech on the Internet  Silicon Valley is Making the Rules Those who care about future online expression should read Jeffery Rosen's    The Delete Squad Google, Twitter, Facebook and the new global battle over the future of free speech Post by    Sean On 24 10 13 At 12 53 PM </description><link>http://www.secuobs.com/revue/news/476805.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/476805.shtml</guid></item>
<item><title>Neutrino  Caught in the Act</title><description>Secuobs.com : 2013-10-23 19:32:16 - F Secure Antivirus Research Weblog -  Last week, we got a tip from Kafeine about hacked sites serving injected iframes leading to an exploit kit We thought it was quite interesting so we looked at one of the infected websites and found this sneaky piece of code  sitecode  114k image  The deobfuscated code shows the location from where the injected iframe URL will be gathered from, as well as the use of cookie to allow the redirection It also shows that it only targets to infect those browsing from IE, Opera and Firefox And now for some good old snippet from the source site and infected site  injected  90k image  When an infected website successfully redirects, the user will end up with a Neutrino exploit kit that is serving some Java exploit  redirections  88k image  We haven't fully analyzed the Trojan payload yet, but initial checks showed that it makes HTTP posts to this IP  mapp  55k image  Early this week, when it probably was not in full effect yet, the injected URLs were leading to googlecom However, it went in full operation starting yesterday evening when it began redirecting to Neutrino to serve Java exploits first_instance  22k image  Based on that timeline, we plotted the location of all the IP addresses that visited the infected sites to a map These IPs are potential victims of this threat There were approximately 80,000 IPs visitor3  648k image  We also plotted the location of the infected websites and so far, there were around 20,000  domains affected by this threat The infected sites appear to be using either WordPress or Joomla CMS hacked  616k image  You can also find other information about this threat in Kafeine's blog post Samples related to this post are detected as Trojan HTML SORedirA, Exploit Java MajavaA, and Trojan W32 AgentDUOH Post by   Karmina and  Daavid On 23 10 13 At 04 23 PM </description><link>http://www.secuobs.com/revue/news/476580.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/476580.shtml</guid></item>
<item><title>What is the cost of ransomware </title><description>Secuobs.com : 2013-10-23 14:01:48 - F Secure Antivirus Research Weblog -  Here's a question we're often asked  what's the economic cost of malware  We recently assisted in a joint investigation with the Finnish Police and CERT-FI And in this particular case   we estimate that just one gang of  police   themed  ransomware could be responsible for more than 800 million dollars worth of damage and losses Details from the Finnish press release  Press release We'll translate the basics  a single gang using Reveton  police  ransomware netted more than 5 million victims worldwide, with more than 30,000 computers in Finland affected Reveton's current  fee  is 300 USD  USA Reveton The going rate in Europe is EUR 100  French Reveton At 100 euro each, the 30,000 Finnish victims alone represent three million euro of potential profit Between North America and Europe   it's altogether something in the neighborhood of 600 million euro or more than 800 million dollars Now of course, not everybody pays Reveton's random  though quite many do  So that potential profit isn't actually realized But what about economic costs  The victims need to spend time and money to repair and recover their computers Some folks will have lost data in the process And how much is that worth  Last year, a friend's hard drive, full of family photos, crashed The cost of repair  More than 6,000 USD  If just one percent of the Reveton gang's more than 5 million victims lost similar collections of photographs   that's equal to 300 million USD in lost data Disregarding data loss, the time spent on recovery is easily worth the same as the ransom payment Bottom line  ransomware is very costly ransomwarefi Which is why we're highlighting the issue at ransomwarefi as part of cyber security awareness month Are you ransomware aware  From now until the end of October, you can ask our own Antti Tikkanen and Paolo Palumbo questions about Reveton and other ransomware threats in our Community's Ransomware Q A Here's a handy link you can share  bitly RansomQA On 23 10 13 At 10 52 AM </description><link>http://www.secuobs.com/revue/news/476503.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/476503.shtml</guid></item>
<item><title>Touch ID  Biometrics Don't Make For Good Passwords</title><description>Secuobs.com : 2013-10-21 15:54:42 - F Secure Antivirus Research Weblog -  There's an Apple event scheduled for tomorrow which will showcase this year's iPad lineup Among the more credible rumors is that at least one version of the iPad will include Apple's Touch ID, its fingerprint identity sensor iPad Mini 2 And so it seems somewhat inevitable that all of our  smart  devices will soon include fingerprint readers That being the case, we strongly recommend the following by  dustinkirkland    Fingerprints are Usernames, not Passwords We welcome intelligent use of biometrics   but not biometric passwords On 21 10 13 At 01 12 PM </description><link>http://www.secuobs.com/revue/news/476038.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/476038.shtml</guid></item>
<item><title>Who Wants to Spy More, Android or iPhone Users </title><description>Secuobs.com : 2013-10-18 17:27:28 - F Secure Antivirus Research Weblog -  We came across some  installation guides  for a spyware app called  StealthGenie  today It's kind of interesting to note the viewing stats Even though Android has a bigger marketshare, the Android Installation Guide video doesn't have so many more views relative to the iPhone's Android  8,196   iPhone  7,641 StealthGenie Installation Guides BlackBerry  1,334 Poor BlackBerry  no longer 1337 On 18 10 13 At 02 53 PM </description><link>http://www.secuobs.com/revue/news/475655.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/475655.shtml</guid></item>
<item><title>Blackhole, Supreme No More</title><description>Secuobs.com : 2013-10-11 23:18:53 - F Secure Antivirus Research Weblog -  Blackhole exploit kit has always been a favorite example when discussing the impact of kits to internet users We've previously mentioned in our posts how fast it was in supporting new vulnerabilities, how it was related to Cool, and that it was the leading kit in our telemetry data Blackhole and Cool almost always had special mentions in our Threat Reports So you can just imagine how closely we follow this topic Early this week, Maarten Boone tweeted groundbreaking news regarding Paunch's fate, the mastermind behind Blackhole and Cool Though no further details were provided, it has been confirmed that Paunch has been arrested in Russia With this news, we decided to look at our telemetry data once again The graphs below show Blackhole and Cool turning from being at the top of the ranks to being negligible ek_hits_2013  91k image  bh_cool_2013  89k image  bh_cool_oct  26k image  It's as dramatic as a graph can get From dominating the exploit kit charts, Paunch's brainchild, Blackhole, is slowly fading away with its master's arrest So what does the future look like  Will the numbers even out among the different exploit kits out there  Will one exploit kit arise to take over Blackhole's place  Will a new exploit kit come out and take over the market  We can only speculate But one thing that we do hope though, is that other exploit kit authors will take the hint, that even if they may enjoy a few years of invincibility, they are not unreachable by the long arm of the law On 11 10 13 At 08 52 PM </description><link>http://www.secuobs.com/revue/news/474170.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/474170.shtml</guid></item>
<item><title>DeepGuard 5 vs IE Zero-Day Exploit CVE-2013-3893</title><description>Secuobs.com : 2013-10-08 15:16:47 - F Secure Antivirus Research Weblog -  SPOILER ALERT  DeepGuard wins It's Patch Tuesday, and Microsoft will be releasing its monthly security updates later today Installing the updates as soon as possible is highly recommended because one of the patched vulnerabilities in Internet Explorer, CVE-2013-3893, is already being exploited in the wild A Metasploit module for exploiting CVE-2013-3893 has also been released But today is key, as the bad guys will almost certainly now reverse engineer the patches in order to develop exploits for the other vulnerabilities as well Building protection against exploits by creating vulnerability-specific defenses one at a time is not really sustainable More proactive protection can be achieved by putting focus on the exploitation techniques With this in mind, the key feature we introduced in version 5 of our behavioral technology   DeepGuard   is behavior-based exploit interception By monitoring the behavior of commonly exploited software, eg, web browsers, we can protect users against threats we have not yet seen   including zero-day exploits Here's a brief video of DeepGuard protecting the system from compromise via an exploit based on the CVE-2013-3893 vulnerability The IE version in the video is vulnerable, ie, the system does not have today's updates installed The exploit in the video has been used in real attacks and is very similar to ones mentioned by FireEye and Dell, right down to the runrunexe payload encrypted with 0x95 XOR key The attack is replayed from a webserver on an isolated test network The exploit sets and checks a cookie to avoid exploiting the same system twice Once DeepGuard has blocked the exploit and forced the tab to close, IE will try to reopen the tab Because the cookie was set, the JavaScript code skips the exploit and simply redirects the user to navercom YouTube  DeepGuard 5 vs IE Zero-Day Exploit CVE-2013-3893 In other words  our technology offers superior protection to customers   on day zero You can read more about our DeepGuard technology in this white paper Read and enjoy while installing today's updates Post by   Timo On 08 10 13 At 12 19 PM </description><link>http://www.secuobs.com/revue/news/473247.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/473247.shtml</guid></item>
<item><title>Visit From a  Ghost </title><description>Secuobs.com : 2013-10-07 20:21:04 - F Secure Antivirus Research Weblog -  Aww man I had a meeting today with Timo Laaksonen  younited  and missed a chance to meet Kevin Mitnick But  he left me this very nice autograph in my copy of Ghost in the Wires Ghost in the Wires Cool  bookmark  Post by    Sean On 07 10 13 At 05 58 PM </description><link>http://www.secuobs.com/revue/news/473069.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/473069.shtml</guid></item>
<item><title>Cryptocurrency Mining</title><description>Secuobs.com : 2013-10-04 15:33:15 - F Secure Antivirus Research Weblog -  Bitcoin, everybody's favorite cryptocurrency, made news this week with the arrest of Silk Road proprietor, the Dread Pirate Roberts It seems cryptocurrencies are becoming  almost  mainstream And with that  comes cryptocurrency malware schemes Silent Miner A topic which is covered in great detail in our recently published H1 2013 Threat Report  Crypto Currency Mining --------------------------------------------------------------------- On 04 10 13 At 12 41 PM </description><link>http://www.secuobs.com/revue/news/472619.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/472619.shtml</guid></item>
<item><title>Hearing on FISA Oversight of NSA</title><description>Secuobs.com : 2013-10-04 13:30:41 - F Secure Antivirus Research Weblog -  The United States government may have  shutdown  on October 1st  but that didn't stop the US Senate Judiciary Committee from holding a hearing on FISA Oversight of the NSA on October 2nd There's been plenty of press coverage But for such important matters   it's worth watching the source material  if you can stomach  sausage making  Senate Judiciary Cmte Hearing on FISA Oversight The entire three hour and thirty-eight hearing is available via C-SPAN  Intel Chiefs Testify at Senate FISA Oversight Hearing --------------------------------------------------------------------- On 04 10 13 At 10 24 AM </description><link>http://www.secuobs.com/revue/news/472590.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/472590.shtml</guid></item>
<item><title>Adobe Hacked</title><description>Secuobs.com : 2013-10-04 11:30:49 - F Secure Antivirus Research Weblog -  Do you have an adobecom account  If yes  you'll want to sign in and reset your password Why  Because Adobe has been hacked From Adobe   Adobe customer IDs and encrypted passwords on our systems We also believe the attackers removed from our systems certain information relating to 29 million Adobe customers, including customer names, encrypted credit or debit card numbers, expiration dates, and other information relating to customer orders  Encrypted passwords and credit debit card numbers, et cetera So therefore you may also wish to monitor any cards which were on file at adobecom Resetting your password is a straightforward process Sign in  Sign in Required Password Reset  Required Password Reset  Click this link to reset your password  Click this link to reset your password Fortunately, my account was for testing and I used a unique password made up of random letters and numbers Unfortunately, I still have an adobecom account, even though I looked into deleting it a few weeks ago justdeleteme Also of significant interest is the fact that some source code was compromised Read Krebs on Security for more details Post by    Sean On 04 10 13 At 08 53 AM </description><link>http://www.secuobs.com/revue/news/472566.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/472566.shtml</guid></item>
<item><title>IE Vulnerability Update  Japan  Metasploit</title><description>Secuobs.com : 2013-10-02 14:57:06 - F Secure Antivirus Research Weblog -  Microsoft's Security Advisory  2887505 , regarding a vulnerability in Internet Explorer, was issued just over two weeks ago We added exploit detection soon thereafter At the time, Microsoft reported that exploitation of the vulnerability was in limited use Microsoft Security Advisory for CVE-2013-3893 Since then, evidence of attacks on Japanese targets via media sites has surfaced And in the last week, our customer upstream data indicates limited use within Taiwan Most importantly, there is now Metasploit support for CVE-2013-3893 So it's only a matter of time before it's added to popular exploit kits such as Blackhole If not this week, then almost certainly a day or two after Microsoft releases its patch next Tuesday We recommend avoiding IE  if possible  until it's updated If you manage a network, Microsoft has a Fix it tool available --------------------------------------------------------------------- On 02 10 13 At 12 28 PM </description><link>http://www.secuobs.com/revue/news/472110.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/472110.shtml</guid></item>
<item><title>ZeroAccess  The Most Profitable Botnet</title><description>Secuobs.com : 2013-10-02 13:58:00 - F Secure Antivirus Research Weblog -  In March of this year, researchers on Symantec's Security Response team began looking at ways in which they might be able to  sinkhole   takedown  ZeroAcess   one of the world's largest botnets But then  in late June, the botnet started updating itself, removing the flaw that the researchers hoped to take advantage of Faced with the choice of some or nothing, the team moved to sinkhole what they could And that was over 500,000 bots A very commendable effort  Ross Gibb and Vikram Thakur are presenting a paper about lessons learned at this year's Virus Bulletin Unfortunately, the bulk of ZeroAcess is still with us  To learn more about it   download this report   extracted from our H2 2012 Threat Report ZeroAccess On 02 10 13 At 11 17 AM </description><link>http://www.secuobs.com/revue/news/472097.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/472097.shtml</guid></item>
<item><title>Privacy  a Core Finnish Value</title><description>Secuobs.com : 2013-09-30 18:04:22 - F Secure Antivirus Research Weblog -  Enumerated rights are cool And here's an enumeration we're particularly fond of  The Constitution of Finland, Section 10   The right to privacy  Everyone's private life, honour and the sanctity of the home are guaranteed   The secrecy of correspondence, telephony and other confidential communications is inviolable  The Constitution of Finland, Section 10, The right to privacy And there's even more enumeration here  Act on the Protection of Privacy in Electronic Communications Act on the Protection of Privacy in Electronic Communications Privacy   it's a core Finnish value And central to everything we do here at F-Secure On 30 09 13 At 03 05 PM </description><link>http://www.secuobs.com/revue/news/471606.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/471606.shtml</guid></item>
<item><title>New TDL dropper variants exploit CVE-2013-3660</title><description>Secuobs.com : 2013-09-26 12:05:12 - F Secure Antivirus Research Weblog -  Recently, we been seeing a new breed of TDL variants going around These variants look to be clones of the notorious TDL4 malware reported by Bitdefender Labs The new TDL dropper variants we saw  SHA1  abf99c02caa7bba786aecb18b314eac04373dc97  were caught on the client machine by DeepGuard, our HIPS technology  click the image below to embiggen  From the detection name, we can see that the variants are distributed by some exploit kits TDL4_clone_exploited_in_the_wild  295k image  Last year, ESET mentioned a TDL4 variant  some AV vendors refer to it as Pihar  that employs new techniques to bypass HIPS as well as to elevate a process's privileges to gain administrator access The droppers of the variants we recently saw also use the same techniques mentioned in ESET's blog post, but with some minor updates Recap  TDL4 exploits the MS10-092 vulnerability in Microsoft Window's Task Scheduler service to elevate the malware's process privileges in order to load the rootkit driver The new variants instead exploits the CVE-2013-3660 EPATHOBJ vulnerability discovered by security researcher Tavis Ormandy  TDL4_clone_ExploitingCVE_2013_3660  30k image  One of the notable differences between the new variants and classic TDL4 is the configuration file, which is embedded in the resource section of the dropper as RC4 encoded data  TDL4_clone_config_ini  6k image  This is hardly the first malware family to exploit CVE-2013-3660, but it is a neat demonstration of how fast malware authors take up publicly available exploit code - in this case, the exploit code went public three months ago Post by   Wayne On 26 09 13 At 08 48 AM </description><link>http://www.secuobs.com/revue/news/470937.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/470937.shtml</guid></item>
<item><title>H1 2013 Threat Report</title><description>Secuobs.com : 2013-09-24 09:13:46 - F Secure Antivirus Research Weblog -  Our H1 2013 Threat Report is now online  F-Secure Threat Report H1 2013 You'll find it   as well as our previous reports   available for download  here On 24 09 13 At 06 57 AM </description><link>http://www.secuobs.com/revue/news/470426.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/470426.shtml</guid></item>
<item><title>iOS 7 Security Prompts</title><description>Secuobs.com : 2013-09-19 15:07:39 - F Secure Antivirus Research Weblog -  Apple's iOS 7 was released yesterday  And it has some nice new security prompts  iOS7_Microphone_Prompt  WeldPond iOS7_USB_Prompt  mikko If you come across more, Tweet them to  FSecure On 19 09 13 At 12 33 PM </description><link>http://www.secuobs.com/revue/news/469616.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/469616.shtml</guid></item>
<item><title>Vulnerability in IE Could Allow Remote Code Execution</title><description>Secuobs.com : 2013-09-18 14:43:29 - F Secure Antivirus Research Weblog -  This is probably required reading if you're a Windows systems administrator of any sort  Microsoft Security Advisory  2887505  Microsoft Security Advisory for CVE-2013-3893 All versions of Internet Explorer are affected Microsoft is currently aware of  a limited number of targeted attacks specifically directed at Internet Explorer 8 and 9  The limited nature of attacks is very likely to change in the near future as exploit kit providers will now move to add support for an exploit based on the vulnerability Our detection for such exploits is already in progress In the meantime, Microsoft has released a Fix it tool to mitigate potentially attacks until a patch is released On 18 09 13 At 12 26 PM </description><link>http://www.secuobs.com/revue/news/469355.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/469355.shtml</guid></item>
<item><title>September 23rd  Threat Report Webcast</title><description>Secuobs.com : 2013-09-16 18:53:06 - F Secure Antivirus Research Weblog -  Join us September 23rd for a webcast based on our forthcoming Threat Report Join the event and other details Tweet your questions  mikko using the hashtag  WWPY If you don't have a Google account  like some of us  the webcast will be available after completion on YouTube On 16 09 13 At 03 58 PM </description><link>http://www.secuobs.com/revue/news/468919.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/468919.shtml</guid></item>
<item><title>Rootkit Cafe</title><description>Secuobs.com : 2013-09-13 11:04:49 - F Secure Antivirus Research Weblog -  Have you ever wondered about the ads you might have seen being shown on the desktop or in the browser during web browsing sessions at Internet cafes  One of our Analysts, Wayne, certainly did He recently analyzed a sample  SHA1  c8c643df81df5f60d5cd8cf46cb3902c5f630e96  that gave him an interesting answer The sample was a rootkit named in its code as LanEx, though we detect it as Rootkit W32 SfuzuanA  LanEx  55k image  Wayne traced the sample back to an advertising company in China called 58wangwei that runs an affiliate program for cafe operators looking to maximize the profits from a constant stream of eyeballs staring at their PCs Their solution  Display ads to the cafe users The marketing spiel on the advertising site mentions that   a single PC in the Internet Cafe operates 20 hours per day in average, excluding the PC idle time  While we don't have any statistics that would back that claim, very informal personal observation would seem to support it Anyway, interested cafe operators are directed to a webpage where they can download a software package  with the installer for the rootkit  The page includes a control panel to configure various functions in the rootkit, for example the default page it sets the web browser to The various options available are all search engines almost exclusively targeted to mainland China Each option has specified dollar amounts   for example, 26 yuan for 1000 unique visitors to one engine The operator then manually installs the package  which will then download the rootkit  on their computers and presto  They should be coining money right  Not quite - it s not all smooth sailing for the operators At least one support forum  Chinese language only  has operators asking for more details about the package and griping about it causing BSOD on their machines  LanEX_BSOD  427k image   source  bbsicafe8com  Most of the operators aren't actually aware what the rootkit is doing on their machines The program is mainly aimed at displaying advertisements    Hide the processes belong to the advertising modules through SSDT hook   Prevents the advertising modules processes from being terminated through SSDT hook   Prevents access to certain webpages  based on the URL s IP address and port number  through NDIS hook The control panel on the webpage where operators download the installer for the rootkit also include the option to select which processes they want to hide in addition to the ad module-related processes, which are hidden by default Technically, the most interesting part of the rootkit is that it uses an NDIS hook to filter all the HTTP request and response messages sent over the network If a prohibited HTTP request is encountered, the packet is modified and a crafted HTML page is returned by the rootkit The HTML page is either a hidden iframe or HTTP 302 redirection that redirects the user's browser to a specified website  lanex_redirection  107k image  For users, the result of having the rootkit on a machine they're using is inescapable exposure to advertisements They may also be redirected to unsolicited websites Though the rootkit is mainly directed at displaying ads, it isn t adware   it is still fully capable of performing far more malicious actions on the system And it looks like even the Internet cafe operators don t always know quite what they've installed on their machines On 13 09 13 At 08 13 AM </description><link>http://www.secuobs.com/revue/news/468426.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/468426.shtml</guid></item>
<item><title>Post-Office Espionage</title><description>Secuobs.com : 2013-09-11 19:29:01 - F Secure Antivirus Research Weblog -  A good working knowledge of history is crucial Because context is everything Which is why those of you with any kind of interest in recent NSA GCHQ revelations should read historian Jill Lepore's article  The Prism, Jill Lepore The Prism  Privacy in an age of publicity Using poppy seeds, strands of hair, and grains of sand  and then mailing the letter to himself to figure out he was being spied on  Sounds like Giuseppe Mazzini was the  hacker  of his day On 11 09 13 At 04 20 PM </description><link>http://www.secuobs.com/revue/news/467997.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/467997.shtml</guid></item>
<item><title>Limit Exposure to Facebook Friends of Friends</title><description>Secuobs.com : 2013-09-10 12:45:11 - F Secure Antivirus Research Weblog -  Yesterday, Forbes reporter Kashmir Hill asked a question which has been on my mind for years  Forbes, Kashmir Hill, Friend of a Friend Why Doesn't Facebook Show You What A 'Friend of a Friend' Sees On Your Profile  The question is in reference to Facebook's  View As  feature which can be used to audit your account And the answer given is rather a surprise According to Facebook's chief privacy officer Erin Egan   We've never gotten feedback about that before  Never  If that's true, I can only assume it's because they've never bothered to ask anybody I'm frequently asked this question when family and friends ask for Facebook advice  I can see stuff belonging to people I'm not friends with, what can they see on my timeline  And because Facebook lacks a complete set of auditing tools, I usually recommend a full reset with the  Limit Old Posts  option Facebook Settings, Limit Old Posts The option resets all past timeline content to  Friends  only At that point you don't need to audit, friends of friends will see nothing more than what is later made public Limit Old Posts can be found via the Privacy Shortcuts icon and the See More Options link Just the other day, I was helping a neighbor setup a page for his Helsinki-based fudge business and it turned out that a large number of his photos were in an  iPhoto  album which was open to friends of friends Given that there are pictures of his children in that album  the Limit Old Posts is a must Additional view as options would be very welcome, and Facebook should also consider a review page showing photos with people that can be seen by people other than friends Post by   Sean On 10 09 13 At 09 48 AM </description><link>http://www.secuobs.com/revue/news/467607.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/467607.shtml</guid></item>
<item><title>Will the US  Cyber Attack  Syria </title><description>Secuobs.com : 2013-09-06 15:42:27 - F Secure Antivirus Research Weblog -  In what is very surely a disturbing sign of the times  We've been asked  should cyber weapons be included in a  measured military response  to Syria's use of chemical weapons  Some think they should  seattletimescom html opinion 2021755761_johnyoderopedsyria05xmlhtml   Guest  US should launch a cyberattack on Syria   How the US Could Cyber Attack Syria, Too   US may launch cyber attacks on Syria  Experts   US likely to wage cyber attacks against Syria Should May Likely  We remain skeptical  And if you are skeptical as well, may we recommend the following  Cyber War Will Not Take Place CYBER WAR WILL NOT TAKE PLACE by Thomas Rid But don't just take our recommendation, at the very least, read this review  reasoncom archives 2013 08 16 cyberwar-is-mostly-bunk Cyberwar Is Mostly Bunk by Ronald Bailey On 06 09 13 At 12 51 PM </description><link>http://www.secuobs.com/revue/news/467007.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/467007.shtml</guid></item>
<item><title>EU Parliament Civil Liberties Committee on US Surveillance</title><description>Secuobs.com : 2013-09-05 15:17:35 - F Secure Antivirus Research Weblog -  Now  The EU Parliament's Civil Liberties Committee starts the first of a series of hearings examining issues around US surveillance Here's the agenda for Session 1  LIBE_Committee Broadcast link  Committee on Civil Liberties, Justice and Home Affairs On 05 09 13 At 01 02 PM </description><link>http://www.secuobs.com/revue/news/466741.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/466741.shtml</guid></item>
<item><title>Whatever Happened to Facebook Likejacking </title><description>Secuobs.com : 2013-09-04 15:49:29 - F Secure Antivirus Research Weblog -  Back in 2010, Facebook likejacking  a social engineering technique of tricking people into posting a Facebook status update  was a trending problem So, whatever happened to likejacking scams and spam  Well, Facebook beefed-up its security   and the trend significantly declined, at least when compared to peak 2010 numbers But you can't keep a good spammer down Can't beat them  Join them Today, some of the same junk which was spread via likejacking  is now spread via Facebook Advertising Facebook Sponsors The top middle thumbnail above is some kind of malformed egg Typical click-bait The ad links to a Page with localized campaigns Note the  Ca  and the  Fi  Cooking Lessons 101 The landing page uses an  app  trick to automatically redirect to a spam campaign  Work from home scheme We're pretty sure such tricks are a violation of Facebook's ToS But so far, Facebook hasn't reacted to the sample we sent them Apparently Some of the spam campaigns are not exactly  safe for work  depending on the source ads  Jailbait ads Also a concern  some of the ads appear to be linked to compromised websites The spammers may not even be paying for these ads Are you judged by the company you keep  That's probably a question legitimate brands with a Facebook presence should be asking themselves On 04 09 13 At 12 56 PM </description><link>http://www.secuobs.com/revue/news/466537.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/466537.shtml</guid></item>
<item><title>FinFisher range of attack tools</title><description>Secuobs.com : 2013-08-30 15:17:02 - F Secure Antivirus Research Weblog - FinFisher is a range of attack tools developed and sold by a company called Gamma Group Recently, some FinFisher sales brochures and presentations were leaked on the net They contain many interesting details about these tools In the background part of the FinFisher presentation, they go on to explain how Gamma hired the  at-the-time  main developer of Backtrack Linux to build attack tools for Gamma This is a reference to Martin Johannes Münch They also boast how their developers have presented at Black Hat and DEF CON FinFisher The FinUSB tool is used to infect computers via a USB stick  Can be used eg by housekeeping staff  FinFisher According to the documents, the FinIntrusion kit can be used to record Usernames and Passwords from wireless networks even if the sites use SSL  FinFisher They also highlight that FinIntrusion can be used to steal user's online banking credentials  FinFisher The FinFly backdoor  deployed from a USB drive   can even infect switched off target systems when the hard disk is fully encrypted with TrueCrypt  FinFisher FinFly Web exploit can be used to do drive-by-infections and can be integrated by a local ISP to inject the module into Gmail or Youtube when the victim accesses those  trusted  sites  FinFisher Another mechanism to infect the victim is to have the victim's ISP automatically poison all of his downloads to include the malware This can also be done by modifying automatic software updates FinFisher Interestingly, the description of FinSpy Mobile specifically mentions they support Windows Phone This is the first reference of any malware for Windows Phone we are aware of FinFisher On 30 08 13 At 01 07 PM </description><link>http://www.secuobs.com/revue/news/465880.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/465880.shtml</guid></item>
<item><title>Pity Team Lokki, They Have No Time to Enjoy the Sun</title><description>Secuobs.com : 2013-08-29 14:49:31 - F Secure Antivirus Research Weblog -  We've had nearly a week of beautiful summer-like weather in Helsinki  which is not always the case in late August  So why in the world is  Team Lokki  sitting in their room with the blinds closed  Team Lokki No time to enjoy the sun   because they've got a tight schedule to keep, developing updates for Lokki iPhone, Lokki splash What's Lokki  It's kind of a non-tracking tracking app In other words, it's a lifestyle app that lets you share your location with a few select people No social networks No big data No histories Just you, your immediate family, and now also a few friends, sharing your current location You can read more here  lokki blog The team is acting like a startup The  we've maxed out our credit cards to make this dream fly  kind   not the sexy venture capital funded kind   as you can probably tell from the photo above  Pay no attention to the empty bottle on Harri's desk  But in any case, the team's project is in its early stages and they are open to and would very much appreciate feedback And it will directly influence the app's development path Lokki is currently available for Android and iOS It's not yet available in all countries  legal mumbo jumbo is in progress  Here's a link to the Canadian iTunes page If you see this page in Google Play  Lokki_US__Google_Play You can use this link from AppBrain, an Android app portal Cheers  PS   A small word of caution for those of you in the United States, using the AppBrain referrer to circumvent Google's censorship could be considered in violation of the Computer Fraud and Abuse Act Just kidding, but also not Maybe It's time to reform the CFAA On 29 08 13 At 11 41 AM </description><link>http://www.secuobs.com/revue/news/465641.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/465641.shtml</guid></item>
<item><title>Facebook Transparency</title><description>Secuobs.com : 2013-08-28 18:35:19 - F Secure Antivirus Research Weblog -  Facebook released a transparency report yesterday that covers the first six months of 2013 Global Government Requests Report All in all  71 countries requested information on 38,000  people Facebook provided law enforcement information on approximately 25,473 people, based on the percentages of requests where some data was produced I copied the numbers to a CSV file if you feel like doing the math  or making a graph  And just what kind of information might Facebook provide  Well, that you can test that for yourself if you have an account Go to facebookcom settings and click on the link to  Download a copy of your Facebook data  You'll find some interesting details inside the data archive  Data archive, security Including some inferred location data  But such inferences are far from perfect I did in fact visit Germany in April  Germany But I haven't visited southern California in ages  southern California At least, not that I know of  Why does the future suddenly feel like I'll have to start auditing log files for errors as if they were credit reports   Sean --------------------------------------------------------------------- On 28 08 13 At 03 40 PM </description><link>http://www.secuobs.com/revue/news/465463.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/465463.shtml</guid></item>
<item><title>Video  Government-Endorsed Surveillance</title><description>Secuobs.com : 2013-08-28 15:27:07 - F Secure Antivirus Research Weblog -  IBTimes TV  Government-Endorsed Surveillance Mikko on IBTimes TV  This is not what we built the Internet for    Mikko Hypponen On 28 08 13 At 01 00 PM </description><link>http://www.secuobs.com/revue/news/465413.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/465413.shtml</guid></item>
<item><title>Android Malware  Pincer's Author</title><description>Secuobs.com : 2013-08-27 18:05:13 - F Secure Antivirus Research Weblog -  Why does Internet security journalist Brian Krebs follow  senneco  https twittercom senneco Found out the answer in today's Krebs on Security  Who Wrote the Pincer Android Trojan  On 27 08 13 At 03 57 PM </description><link>http://www.secuobs.com/revue/news/465217.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/465217.shtml</guid></item>
<item><title>Wi-Fi Honeypots and MAC Address Surveillance</title><description>Secuobs.com : 2013-08-26 15:15:01 - F Secure Antivirus Research Weblog -  On August 8th, Quartz published a report that recycling bins in the City of London were being used to collect the MAC addresses from phones passing-by The scheme was halted by August 12th On the 13th, I spoke with Danish reporter Jakob Møllerhøj about similar Bluetooth and Wi-Fi tracking that takes place in Denmark   to predict the flow of traffic on roads and human flows in airports And while traffic flow analysis is a very valuable thing for planners   in the light of a  prism    this type of metadata collection is a very worrying trend Several years ago, we had our own Bluetooth honeypot project  Bluetooth Honeypot Had we moved forward with it, we would have needed to find a way to store MAC addresses anonymously Because these days, it's entirely too easy for third-parties to seek or sell  business records  to be correlated Can you just imagine if every CCTV in your city also logged your phone's Wi-Fi Mac  For those of you interested in running an experiment, check out March's Linux Journal  Wi-Fi Mini Honeypot But do be careful on what you collect, and how   it's a dangerously unregulated landscape Regards,  Sean On 26 08 13 At 12 45 PM </description><link>http://www.secuobs.com/revue/news/464972.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/464972.shtml</guid></item>
<item><title>NASDAQ's Community Forum</title><description>Secuobs.com : 2013-08-23 17:51:49 - F Secure Antivirus Research Weblog -  Me, speaking to V3couk's Alastair Stevenson on July 18th   Imagine this  Suppose the NASDAQ community forum wasn't just compromised for its users' passwords   but also to use it as a watering hole You thought the Twitter, Facebook, Apple, Microsoft watering hole attack compromises via the iPhone Dev SDK forum was bad  Well, I think that would be nothing compared to the kind of damage that could be done via NASDAQ  http grahamcluleycom 2013 07 nasdaq-hackers  Image source  grahamcluleycom Given that multiple large Internet companies were compromised via a watering hole attack on a FORUM back in Febuary   I was really quite amazing that folks weren't just a bit more curious about the NASDAQ community forum hack  Because it was vacation season  Was NASDAQ's forum used to host a watering hole attack  And then this week's Goldman Sachs options error and NASDAQ outage  Now I'd really like to see some confirmation that there wasn't a watering hole  How about you  Post by    Sean On 23 08 13 At 03 35 PM </description><link>http://www.secuobs.com/revue/news/464654.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/464654.shtml</guid></item>
<item><title>Android Malware goes SMTP</title><description>Secuobs.com : 2013-08-22 10:07:21 - F Secure Antivirus Research Weblog -  Before we get to thinking that nothing is new under the Android malware sun, we get a small, but quite interesting surprise An android malware that connects to SMTP servers to send an email Other than the SMTP-usage, the malware is pretty vanilla Upon installation, the application asks the user to activate device administrator to stay persistent in the mobile device This threat does not add any significant icons in the application menu, rather the user would need to check the Application Manager before finding out that there is an app masquerading as  Google Service  mobile1  138k image  After installation, the application will collect sensitive user information such as phone number, incoming and outgoing SMS, and recorded audio to an email address Then it makes use of SMTP servers, particularly smtpgmailcom, smtp163com and smtp126com to send the stolen data I smell something very China-ish here code  169k image  Below is a screenshot of the threat's attempt to connect to an SMTP server  smtp  161k image  This threat was found to be usually downloaded in third party Android markets or malicious websites We first saw this malware family a month ago, but has been active since We're already detecting this threat as Trojan Android SMSAgentC msms_android  59k image  Post by   Swee Lai On 22 08 13 At 07 12 AM </description><link>http://www.secuobs.com/revue/news/464349.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/464349.shtml</guid></item>
<item><title>We Need To Talk, Google</title><description>Secuobs.com : 2013-08-21 14:50:48 - F Secure Antivirus Research Weblog -  Dear Google   please don't take this the wrong way, but, well  I think you suck This hasn't always been the case Once upon a time, I actually enjoyed using Google services Google_Products But today   well, today I simply wanted to upload an old video to our Labs YouTube channel Sadly, just after signing in, and before I could upload anything, I was accosted by a  request  to link the YouTube channel to a Google  profile And before I knew it   one Mr  fslabs  had created a Google  profile Not great  Here's a thought  perhaps you should first ask if the YouTube account is an  individual  BEFORE you try linking it to a G  profile  Because you didn't ask,  I  ended up with a new profile s  for which  I  have no use And undoing  deleting  the linkage from the  individual  profile to the  group  channel ended up disabling the channel Then I needed to spend some time re-enabling and restoring it And then I needed to reset the privacy settings for all of the existing videos Felt like extortion  Evil  Now, I'm sure you have good reasons for all of this G   promotion  crap And probably some bad ones, too I'm certain I made mistakes I'm sure I missed some small cancel button during in the process And I think I located the  unlink  option in the YouTube settings somewhere after I had already disabled the channel by killing the G  profile But you know what  I really don't care anymore I've had it with Google et al I'll be looking into alternatives  Vimeo, Dailymotion, et cetera  And my personal Google account  It's underused, but I've kept it around because it's  free  No more I'm done It's no longer worth the hassle And to be clear, it has nothing to do with recent allegations that a person has no legitimate expectation of privacy when using Gmail And it has nothing to do with any sort of concerns that Google provides the NSA direct access to its servers  Google's security engineers can be trusted, I think  My decision to delete my Google account is purely a matter of me being fed up of Google attempting to drive me into yet another unwanted  social  network, just for the sake of its bloody search engine rankings and associated advertising machinery It's not me It's you   Be seeing you, Sean Security Advisor, F-Secure Labs twittercom 5ean5ullivan On 21 08 13 At 11 42 AM </description><link>http://www.secuobs.com/revue/news/464155.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/464155.shtml</guid></item>
<item><title>Recommend  CERT Polska's ZeuS P2P Report</title><description>Secuobs.com : 2013-08-16 13:51:27 - F Secure Antivirus Research Weblog -  For those of you interested in excellent banking trojan analysis  Check out CERT Polska's report on the Gameover version of ZeuS  CERT Polska, ZeuS-P2P internals   understanding the mechanics  a technical report ZeuS-P2P internals   understanding the mechanics  a technical report On 16 08 13 At 11 25 AM </description><link>http://www.secuobs.com/revue/news/463311.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/463311.shtml</guid></item>
<item><title>Blocking  MiniDuke  Type Threats Using Exploit Interception</title><description>Secuobs.com : 2013-08-15 14:54:23 - F Secure Antivirus Research Weblog -  MiniDuke, a cleverly coded Adobe PDF exploit, made news back in February   it was used to target several European governments Now, more than ever, exploit prevention is a critical layer of defense And that's why F-Secure Labs analysts such as Timo Hirvonen have become such experts on exploits   so our technology can be made better  with developers such as Jose Perez  Here's a screenshot of our current DeepGuard  behavioral engine tech vs MiniDuke  Miniduke vs F-Secure Internet Security 2014 Blocked   proactively, without signature-based scanning or back end heuristics Excellent Exploit interception is one of our primary goals   because exploits are the front end of an attack platform More about our technology, and a case study of the ZeroAccess bot, is available from our whitepaper  F-Secure DeepGuard  Proactive on-host protection against new and emerging threats DeepGuard, Behavioral Protection, Exploit Interception On 15 08 13 At 11 52 AM </description><link>http://www.secuobs.com/revue/news/463128.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/463128.shtml</guid></item>
<item><title>Browlock Ransomware Targets New Countries</title><description>Secuobs.com : 2013-08-14 18:29:16 - F Secure Antivirus Research Weblog -  In the past few weeks we have been following the relatively new  police ransomware  family we call Trojan HTML Browlock This ransomware is very simple, and just uses the browser to display a lock screen demanding the victim to pay a fake fine and plays tricks to prevent closing the browser tab Since we first saw it targeting folks in the US, Canada, and UK, we have been expecting it to expand to new countries As expected, users in other regions are now seeing a localized message from their local law enforcement Here are the lock screens for Browlock as seen from different countries  Browlock in UK Browlock in AU Browlock in NL Browlock in ES Almost all the ransomware families seem to have great difficulties in finding a translator to create localized lock pages with good quality Readers that pay close attention  okay, any attention is probably enough  will notice some slight problems with the German localization  Browlock in DE For Canadians, the design of the lock screen has stayed roughly the same  Latest Browlock in CA We did notice that the fine has dropped from 250 CAD to 150 CAD compared to a previous lock screen below It seems that in today's economy, even ransomware victims can't be expected to pay up such high prices Old Browlock in CA While the domain names change, all of the lock screens are currently being hosted on a single server in St Petersburg  Browlock Server We detect the lock screen as Trojan HTML BrowlockA Post by   Antti and Karmina --------------------------------------------------------------------- On 14 08 13 At 03 30 PM </description><link>http://www.secuobs.com/revue/news/462908.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/462908.shtml</guid></item>
<item><title>Java - The Gift That Keeps On Giving</title><description>Secuobs.com : 2013-08-14 12:42:08 - F Secure Antivirus Research Weblog -  I bet vulnerability researchers love Java It seems that especially the 2D sub-component of Java has felt their love lately  since the out-of-band patch for CVE-2013-0809 and CVE-2013-1493 in March 2013, 2D has been the most patched sub-component with a total of 18 fixed vulnerabilities Fortunately, CVE-2013-1493 has been the only one of these exploited in the wild On Monday August 12th, a link to yet another Java exploit was shared  Tweet Unlike the Tweet says, the exploit is not 0day It exploits CVE-2013-2465, yet another vulnerability in the 2D sub-component The issue affects Java 7 versions up to update 21 but it has been patched in the latest version, Java 7 update 25 We have released a detection for the exploit  Exploit Java CVE-2013-2465A  but so far we have not seen in the wild Even though CVE-2013-2465 is not exploited in the wild  yet , another Java vulnerability affecting Java 7 update 21 is  CVE-2013-2460 The exploit was introduced in Private exploit kit in July and since then we have seen it also in Sweet Orange exploit kit In addition, Kaspersky has spotted the vulnerability being exploited in watering hole attacks  the JAR file mentioned in the post exploits CVE-2013-2460, not CVE-2012-4681  To sum up, it does make a difference whether you run Java 7 update 25 or Java 7 update 21 If uninstalling Java or at least disabling the browser plugin is not an option for you, make sure you have the latest version of Java installed Grumpy cat Post by    Timo On 14 08 13 At 08 54 AM </description><link>http://www.secuobs.com/revue/news/462832.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/462832.shtml</guid></item>
<item><title>Are There Good Hackers </title><description>Secuobs.com : 2013-08-13 14:12:29 - F Secure Antivirus Research Weblog -  Guy Raz, host of NPR's TED Radio Hour, really caught up with Mikko while he was attending DEFCON Mikko's DEFCON recommendation  don't trust anybody   pen and pad work very well TED_Radio_Hour_The_Hackers Guy interviewed Mikko as part of last week's TRH episode  The Hackers And Mikko's was the first segment  Are There Good Hackers   which includes a retelling of Mikko's journey to Lahore, Pakistan, to find the authors of the first PC virus  Brain  A journey that you can see for yourself via YouTube  On 13 08 13 At 11 40 AM </description><link>http://www.secuobs.com/revue/news/462605.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/462605.shtml</guid></item>
<item><title>Blaster - 3654 Days Later</title><description>Secuobs.com : 2013-08-12 13:18:48 - F Secure Antivirus Research Weblog -  Yesterday was Blaster's 10th anniversary Do you remember where you were on August 11, 2003  Mikko remembers  and he still has the related press release  PDF  World's First RPC Worm Numerous organizations, including several banks and airlines, suffered serious disruptions because of Blaster which caused affected computers to reboot continuously Can you imagine the difficulties that would cause today  Vanity Fair's The Code Warrior, circa January 2004, offers a very entertaining long read on the topic On 12 08 13 At 10 30 AM </description><link>http://www.secuobs.com/revue/news/462404.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/462404.shtml</guid></item>
<item><title>Encrypted Communications Service Goes Silent</title><description>Secuobs.com : 2013-08-09 14:04:44 - F Secure Antivirus Research Weblog -  A privacy focused e-mail service used by Edward Snowden has shuttered its doors According to the owner and operator, Ladar Levison   I wish that I could legally share with you the events that led to my decision  http lavabitcom  lavabitcom His notification also includes the following words  This experience has taught me one very important lesson  without congressional action or a strong judicial precedent, I would _strongly_ recommend against anyone trusting their private data to a company with physical ties to the United States That's a strong statement So what's this all about  And why can't Levison share the details regarding his decision to shut down Lavabit  Well, his inability to talk is probably either due to a warrant or a national security letter  NSL  Here's the thing about an NSL   a lifetime gag-order comes attached There are only three organizations that have ever won the right to say they received an NSL of the hundreds of thousands issued Nicholas Merrill is one such individual, and he spoke about it to WNYC's Bob Garfield in 2011  National Security Letters and Gag Orders Brewster Kahle, the founder of the  awesome  nonprofit Internet Archive, is another New Yorker  What It s Like to Get a National-Security Letter Lavabit's closure is having a chilling effect Another encrypted communications company, Silent Circle, has followed Lavabit's lead Ars Technica  After Lavabit shutdown, another encrypted e-mail service closes On 09 08 13 At 11 44 AM </description><link>http://www.secuobs.com/revue/news/462078.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/462078.shtml</guid></item>
<item><title>On Fake  F-Secure Security Pack  Malicious Browser Extension</title><description>Secuobs.com : 2013-08-07 12:08:43 - F Secure Antivirus Research Weblog -  We have been following a malicious browser extension that claims to have been developed by various different software companies The extension installs itself into the browser and makes posts to social media sites such as Twitter, Facebook and Google  on the user's behalf One of the variants installs itself as  F-Secure Security Pack    and trust us   it's definitely not coming from us The installer for this malware is commonly a self-extracting Winrar executable, although samples come packed in various other ways as well We can take a peek at the contents of one of the samples  Contents of malware installer The contents give a hint to what the malware installer contains  an extension for both Firefox and Chrome  the xpi and crx files  The executables for this malware are signed using a certificate assigned to a company called  VIDEO TECH PRODUCOES LTDA  Certificate information It's unclear at this point if the certificate has been stolen or if there is some other connection between the company and the malware samples The installer registers an extension with the name of  F-Secure Security Pack  for Chrome  Foobar The same happens for the Firefox browser, with slightly different registration details  ff_ext Depending on the targeted region, the malware uses different brands as the name of the malicious extension For example, we've seen  Chrome Service Pack  for China, Dr Web for France and Kingsoft for Brazil  extension_chrome_pack plugin_drweb plugin_kingsoft The extension itself is quite simple It fetches an update from a command and control server and uses the information in this update to post to different social media sites The comments in the source code are in Portuguese, giving also some hints to the origin of the malware  extension_spanish_text Here's an example of the update information the malware fetches from the command and control servers for Brazilian users  extension_spanish_text One of the settings automatically retweets a message This setting was not enabled at the time of writing, but the message to be retweeted is still visible We can see that this particular message has over 5000 retweets  extension_spanish_text F-Secure detects this malware as TrojanFBSuper or various other heuristic detection names, depending on the variant SHA-1  6287b03f038545a668ba20df773f6599c1eb45a2 On 07 08 13 At 09 19 AM </description><link>http://www.secuobs.com/revue/news/461607.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/461607.shtml</guid></item>
<item><title>Are Apple developers on the hacker hit list </title><description>Secuobs.com : 2013-08-06 11:53:06 - F Secure Antivirus Research Weblog -  Note  this post is condensed from an article I wrote for Digital New Asia Apple s developer website for its Mac, iPhone and iPad products was taken offline about two weeks ago  shortly afterwards, Apple released a statement saying that the site had been suffered an intrusion Soon after, a grey hat Turkish security researcher, Ibrahim Balic, in London claimed responsibility for the intrusion in a video posted on his YouTube channel, in which he claimed that he had filed bug reports prior to the takedown of the website Although there has been no further comments or statements from Apple about Balic s claim, Apple does seem to be taking the occurrence seriously and is currently still working restoring their web services Now the issue is   why are developers, particularly iOS developers, being targeted now more than ever  The intrusion on the developer site, though allegedly done with benign intent, brings greater attention to the importance of securing developer accounts, and the potential consequences if such accounts are compromised and misused This is in light of an attack earlier this year on the popular iOS Mobile developers  forum iPhoneDevSDK, which successfully garnered victims from the big tech companies, like Apple, Facebook and Twitter and so on Notice from IPhoneDevSDK Admin This was a textbook watering hole attack, where a hacker intending to attack specific users first compromises a site those users are likely to visit, in order to gather information or access they can later use for a more direct attack against the targets   in this case, the developers who were visiting the site Gaining access an application developers  personal information, which may be used later to compromise their developer accounts, could lead to great harm for users who trust the developer s products and reputation, particularly on the iOS platform Unlike Google s Play store or other app stores for the Android platform, penetrating and uploading a tainted application into Apple s Apps store has long been a challenge for malware authors, particularly as Apple s strict review policies has successfully prevented much rogue application activity in the 6 years since the first iPhone appeared To get around these barriers, malware authors are now targeting the developers themselves Their real aim   to gain access to the developer s accounts on the App stores, from which they can essentially hijack the developer s reputation and products to push their own wares Read the full article here On 06 08 13 At 09 27 AM </description><link>http://www.secuobs.com/revue/news/461359.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/461359.shtml</guid></item>
<item><title>Can you find Rebecca Taylor </title><description>Secuobs.com : 2013-08-05 15:37:06 - F Secure Antivirus Research Weblog -  Channel 4  a UK broadcaster  News has launched an experimental online identity project called  Data Baby And the data baby's name is  Rebecca Taylor    a very common name in the UK Channel 4 has issued a challenge  Can you find Rebecca Taylor  The first clue on offer is Rebecca's e-mail  RebeccaTaylor0603 gmailcom Well, from that  it's easy to get this  Rebecca Taylor's Facebook And a Google Images search yields this  and more  Rebecca Taylor  Looks like an interesting challenge Info  channel4com news data-baby --------------------------------------------------------------------- On 05 08 13 At 12 47 PM </description><link>http://www.secuobs.com/revue/news/461168.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/461168.shtml</guid></item>
<item><title>xkcd  The Mother of All Suspicious Files</title><description>Secuobs.com : 2013-08-05 12:02:39 - F Secure Antivirus Research Weblog -  From xkcd  The Mother of All Suspicious Files  LOL On 05 08 13 At 09 07 AM </description><link>http://www.secuobs.com/revue/news/461134.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/461134.shtml</guid></item>
<item><title>Windows Version of the Janicab Malware</title><description>Secuobs.com : 2013-07-23 14:46:58 - F Secure Antivirus Research Weblog -  Last week, we wrote about a script-based malware targeting Mac users Yesterday, the folks from avast  revealed a Windows version tweet from Jindrich Kubec Here is a summary of the difference between the Windows and OS X version  Summary table Our Windows users are already protected by our cloud technology On 23 07 13 At 11 56 AM </description><link>http://www.secuobs.com/revue/news/458562.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/458562.shtml</guid></item>
<item><title>Summer Listening  BBC Playlist</title><description>Secuobs.com : 2013-07-22 13:30:08 - F Secure Antivirus Research Weblog -   There are now three certainties in life   there's death, there's taxes and there's a foreign intelligence service on your system    MI5's Head of Cyber BBC Radio 4 recently aired a very interesting series on cyber espionage, theft, and war Under Attack  The Threat from Cyberspace Under Attack  The Threat from Cyberspace Reporter Gordon Corera interviewed numerous individuals including Michael Hayden  Former Director of the NSA , Toomas Hendrik Ilves  President of Estonia , and MI5's Head of Cyber  who preferred not to be named  Episode 3 is still available for a limited time A 50 minute compilation is available from BBC World Service BBC World Service, Documentaries Download  Available indefinitely  And if you're interested in security  you're probably also interested in privacy  Mobile phones really are now tracking devices that let us make calls    Nick Pickles, Director of Big Brother Watch BBC Radio 4  Privacy Under Pressure Rovio   The Golden Egg of Mobile Advertising   gets a mention of course On 22 07 13 At 10 37 AM </description><link>http://www.secuobs.com/revue/news/458330.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/458330.shtml</guid></item>
<item><title>Augmenting Society's Collective IQ</title><description>Secuobs.com : 2013-07-19 16:21:16 - F Secure Antivirus Research Weblog -  Doug Engelbart died on July 2, 2013 He is probably best known, to the general public, as the inventor of the computer mouse But he was much more than that   They called him kooky, and laughed at him for doing weird stuff   The Economist  Doug Engelbart, computer engineer, died on July 2nd, aged 88  Among some technology enthusiasts, he is known for The Mother of All Demos If you're not familiar with it, The Demo included demonstrations of  hypertext, object addressing and dynamic file linking, as well as shared-screen collaboration involving two persons at different sites communicating over a network with audio and video interface  And the best part  The Demo took place on December 9, 1968 Stanford University has an excellent series of annotated clips  here Truly a man ahead of his time, Engelbart's vision was to ask   How do we collectively use technology to map our future with integrity mindful of the perspectives of others and future generations  Doug Engelbart Tribute Video RIP On 19 07 13 At 02 14 PM </description><link>http://www.secuobs.com/revue/news/457989.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/457989.shtml</guid></item>
<item><title>Surveillance Will Soon Be the Lesser of Your Worries</title><description>Secuobs.com : 2013-07-18 18:55:31 - F Secure Antivirus Research Weblog -  The debate continues regarding the US Government's domestic surveillance programs   which US privacy advocates argue are a violation of Fourth Amendment constitutional protections Meanwhile in Europe  Several EU countries such as France, Belgium and the UK already have laws that compel individuals or companies to decrypt data requested by law enforcement authorities for investigations Laws to force suspects to decrypt their data  However, introducing a law that forces suspects to decrypt information could violate Article 6 of the ECHR, which states that a person doesn t have to incriminate oneself  Dutch judges  Decryption orders could violate human rights  The law could be a violation Article 6 of the ECHR As in Article 6 of the European Convention on Human Rights   which like the Fifth Amendment of the US Constitution   provides protections to individuals from being forced to incriminate themselves Refuse to provide your password  Go to jail The issue needs more debate But what happens when you can't refuse  After all, science is getting better at understanding kinesic information leakage  video  And technology is rapidly attempting to automate what science has learned  Wiredcom  Deception Is Futile When Big Brother s Lie Detector Turns Its Eyes on You In the not too distant future   even your own mind won't be able to protect secrets Wanted  a new kind of firewall On 18 07 13 At 04 05 PM </description><link>http://www.secuobs.com/revue/news/457804.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/457804.shtml</guid></item>
<item><title>On  FBI   Ransomware  and Macs</title><description>Secuobs.com : 2013-07-17 19:03:15 - F Secure Antivirus Research Weblog -  On Monday, Malwarebytes researcher Jerome Segura posted a nice write up  and video  about FBI themed ransom scams targeting users of Apple Mac OS X The basics are as such    Segura discovered the scam via a Bing Images search for Taylor Swift   A compromised site hosting the image linked to a webpage mimicking police ransomware   Only it isn't really  ware  in the normal sense of a ransomware trojan   The scam uses clever persistent JavaScript in its attempt to trick people into paying a supposed fine And now we'd like to contribute some additional notes Located in Canada, Segura was directed to an FBI themed webpage This is probably due to his North American IP address, or else he was using a US-based proxy In Europe, the result is Europol themed  Europol_Ransom_Scam_Mac And the scam uses a Europol-themed URL  Europol_Ransom_Scam_Mac_Locked Also, such scams are not just targeting Macs, as this comment from The Safe Mac explains TheSafeMac_FBI_Ransomware Crimeware kits are always targeting everything all the time Windows, Macs, every OS But most of the time  there isn't a good exploit vector with which to target Macs with malware, so they are redirected to something  spammy  instead For example, now that the ransom scam has been exposed, this is what the FBI and Europol URLs are currently redirecting to  Find Your Adult Friend Find Your Adult Friend  a site which uses scraped images  Avoid  On 17 07 13 At 03 34 PM </description><link>http://www.secuobs.com/revue/news/457482.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/457482.shtml</guid></item>
<item><title>Signed Mac Malware Using Right-to-Left Override Trick</title><description>Secuobs.com : 2013-07-15 14:31:09 - F Secure Antivirus Research Weblog - Right-to-left override  RLO  is a special character used in bi-directional text encoding system to mark the start of text that are to be displayed from right to left It is commonly used by Windows malware such as Bredolab and the high-profile Mahdi trojan from last year to hide the real extension of executable files Check out this Krebs on Security post for more details on the trick We've spotted a malware for Mac using the RLO trick It was submitted to VirusTotal last Friday RLO character The objective here is not as convoluted as the one described in Kreb's post Here it's simply to hide the real extension The malware could have just used  Recent Newpdfapp  However OS X has already considered this and displays the real extension as a precaution RLO trick in Finder RLO trick in Terminal The malware is written in Python and it uses py2app for distribution Just like Hackback, it's signed with an Apple Developer ID Apple Developer ID However, because of the RLO character, the usual file quarantine notification from OS X will be backwards just like the Krebs case OS X file quarantine notification The malware drops and open a decoy document on execution Decoy document Then it creates a cron job for its launch point and a hidden folder in the home directory of the infected user to store its components Launch point and drop files The malware connects to the following pages to obtain the address of its command and control server    http wwwyoutubecom watch v DZZ3tTTBiTs   http wwwyoutubecom watch v ky4M9kxUM7Y   http hjdullinknl images rephp It parses for the address in the string  just something i made up for fun, check out my website at  address  bye bye  The YouTube page look like this  YouTube page Doing a Google search for the string reveals that there are other sites being abused besides those mentioned above Google search The malware then continuously takes screen shots and records audio  using a third party software called SoX  and uploads them to the command and control server It also continuously polls the command and control server for commands to execute The malware is detected by F-Secure as Backdoor Python JanicabA On 15 07 13 At 10 48 AM </description><link>http://www.secuobs.com/revue/news/456986.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/456986.shtml</guid></item>
<item><title>Who won the free Bitcoins </title><description>Secuobs.com : 2013-07-09 22:23:35 - F Secure Antivirus Research Weblog -  As mentioned a week ago, I was running a competition where I would give a physical Bitcoin coin to my 50,000th follower on Twitter Well, it happened last night My 50,000th follower was an account called WantBTC WantBTC WantBTC is actually a bot, run by Eric Bauersachs e4ch Eric was running a script with 16 Twitter bots competing for the 50,000th follower slot Hard work paid off, and he won  wantbtc_bot Eric will be getting the Bitcoin and a copy of Thomas Rid's upcoming book Cyber War Will Not Take Place Congratulations  However, I also promised a Bitcoin and the book to a random follower of mine Which one got it  Did you get it  You'll have to watch the video to find out Thanks all   Mikko On 04 07 13 At 08 07 PM </description><link>http://www.secuobs.com/revue/news/455829.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/455829.shtml</guid></item>
<item><title>Redux  Metadata Matters</title><description>Secuobs.com : 2013-07-03 13:37:02 - F Secure Antivirus Research Weblog -  The term  metadata  is nothing new to us One year ago, we linked to the story of German Green party politician, Malte Spitz Given current events, a refresher on just what metadata is seems useful From our June 29, 2012 post   A 2008 German law required all telecommunications providers with more than 10,000 customers to retain six months worth of data on all calls, messages and connections Germany's Constitutional Court ruled the law unconstitutional in 2010 Spitz acquired  meta data from his telecom provider covering a period from August 2009 to February 2010 Zeit Online has made the raw data available via Google Docs To demonstrate just how much of a personal profile can be crafted, Zeit Online augmented the data with publicly available information such as Spitz's tweets and blog entries   Meta data or metadata  it's all data Anyway, the result is an incredibly cool, very revealing, interactive map  Vorratsdatenspeicherung Source  http wwwzeitde datenschutz malte-spitz-data-retention Now you can hear Spitz himself  PRI's The World interviewed Spitz yesterday on its July 2nd broadcast Also of interest, from Geoffrey Nunberg  Calling It  Metadata  Doesn't Make Surveillance Less Intrusive On 03 07 13 At 10 53 AM </description><link>http://www.secuobs.com/revue/news/455194.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/455194.shtml</guid></item>
<item><title>Android Hack-Tool Steals PC Info</title><description>Secuobs.com : 2013-07-01 09:46:09 - F Secure Antivirus Research Weblog -  Yeh, one of our Security Response Analysts, came across an interesting report on a Chinese forum over the weekend about an Android app that basically turns the device into a hack-tool capable of stealing information from a connected Windows machine He managed to find a sample  Md5 283d16309a5a35a13f8fa4c5e1ae01b1  for further investigation When executed, the sample  we detect it as Hack-Tool Android UsbCleaverA  installs an app named USBCleaver on the device  hacktool_android_usbcleaver_0  53k image  When the app is launched, it directs the user to download a ZIP file from a remote server  hacktool_android_usbcleaver_1  188k image  Then unzips the downloaded file to the location  mnt sdcard usbcleaver system folder The files saved are essentially utilities used to retrieve specific pieces of information when the device is connected via USB to a Windows machine Note  we detect most of the files with older detections The following details are grabbed from the connected PC machine    Browser passwords  Firefox, Chrome and IE    The PC's Wi-Fi password   The PC's network information The app gives the user the option of choosing what information they want to retrieve  hacktool_android_usbcleaver_2  178k image  hacktool_android_usbcleaver_3  196k image  hacktool_android_usbcleaver_4  185k image  To run the utilities, the sample creates an autoruninf and gobat file at  mnt sdcard When the device is plugged into a Windows machine, the autorun script gets triggered, which then silently runs the gobat file in the background, which in turn runs the specified files from the usbcleaver system folder The collected details are stored on the device at  mnt sdcard usbcleaver logsThe app's user can click on the 'Log Files' button to view the information retrieved from the PC  hacktool_android_usbcleaver_5  186k image  This isn't the first Android trojan reported this year with PC-infecting capabilities, since that 'distinction' belongs to the trojan-spy apps family we detect as Sscul  listed in our Q1 2013 Mobile Threat Report  Unlike the Sscul malware however, which is more focused on remote eavesdropping, USBCleaver seems to be designed to facilitate a targeted attack by gathering details that would be helpful in a later infiltration attempt Fortunately, the UsbCleaver's Windows-infecting routine can be blocked by a simple measure that's been standard security advice for the last couple years  disabling the Autorun by default  this is already standard on Windows 7 machines  An additional mitigating factor is that most older Windows systems need to have mobile drivers manually installed in order for this attack to work ---------------------- Analysis by - Yeh On 01 07 13 At 07 07 AM </description><link>http://www.secuobs.com/revue/news/454686.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/454686.shtml</guid></item>
<item><title>Bitcoin to Mikko's 50,000th Twitter Follower</title><description>Secuobs.com : 2013-06-27 15:01:32 - F Secure Antivirus Research Weblog -  I started on Twitter in March 2009 Twitter archive of  mikko from 2009 to 2013 I never would have thought this to happen, but I've gained a remarkable amount of followers since Thank You In fact, with almost 50,000 followers, I'm actually one of the most followed Finns on Twitter Follower count from 0 to 50,000 So I want to give something back My 50,000th follower will get a physical Bitcoin coin worth 1 BTC, made by Casascius Casascius 1 Bitcoin coin But rewarding my latest follower and ignoring all the rest wouldn't be fair So, I'll give another 1 BTC coin to a random follower The winners will also get a copy of Thomas Rid's new book Cyber War Will Not Take Place Cyber War Will Not Take Place by Thomas Rid Rules and conditions  I select who wins No complaints Winners get the coins and books via mail Thanks, Mikko On 27 06 13 At 12 24 PM </description><link>http://www.secuobs.com/revue/news/454022.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/454022.shtml</guid></item>
<item><title>The Geography of Malware</title><description>Secuobs.com : 2013-06-26 16:11:54 - F Secure Antivirus Research Weblog -  Yesterday, Google announced on its Online Security Blog that it will now include Safe Browsing statistics in its Transparency Report The Safe Browsing Malware Dashboard is fascinating Here's last week's Malware Distribution by Autonomous System, using just the  Attack Sites  filter  The location of the attack sites by AS    USA   Russia   Ukraine Hmm, the USA  San Diego  is at the top And now let's look at one year's time range  And the locations    Transnistria   Romania   Latvia Specialist Ltd in Transnistria  A search for that yields a result from Dynamoo's Blog   Transnistria, a breakaway part of the former Soviet Republic of Moldavia No UN members recognise Transnistria, and effectively it sits beyond the reach of international law enforcement  There's always something new to learn regarding the geography of malware  A picture gallery from Telegraphcouk  Welcome to Transnistria  a Soviet breakaway territory in Eastern Europe On 26 06 13 At 01 19 PM </description><link>http://www.secuobs.com/revue/news/453779.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/453779.shtml</guid></item>
<item><title>Do you cover up your webcam </title><description>Secuobs.com : 2013-06-20 15:56:04 - F Secure Antivirus Research Weblog -   Web camjacking is in the news This morning from BBC News  Webcams taken over by hackers, charity warns As part of the report, BBC Radio 5 live interviewed a Finnish hacker who supposedly sells  female bots  bbc_uk-22967622 Related audio And last Friday from Forbes  Two-Year-Old Flash Bug Still Allows Webcam Spying On Chrome Users You should update to the latest version of Chrome or else you'll be vulnerable to a bug that allows camjacking via Flash Researcher Egor Homakov's proof of concept  Click and say Cheese homakov_github_io Your software should always be up to date   but perhaps the best advice is to cover up your cam  Sydney Morning Herald  Taping over prying eyes of web spies camjacking_postit This is how Mikko does it  mikko_webcam On 20 06 13 At 01 01 PM </description><link>http://www.secuobs.com/revue/news/452624.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/452624.shtml</guid></item>
<item><title>Post-PC Attack Site  Only Interested in Smartphones Tablets</title><description>Secuobs.com : 2013-06-19 15:17:35 - F Secure Antivirus Research Weblog -  We've discovered a server that only attacks and or spams smartphones and tablets   and not PCs A Swedish-based colleague of ours, Johan, was recently using his  Android  phone to search for boat trips in the Galapagos Islands He found a site called Vagabond And on Vagabond he found an entry with a link to  galacruisescom From a Windows-based browser, the link redirects to a site called islasgalapagostravel But the results are much different if a mobile device is used  Mobile browsers are redirected to a info domain which in turn redirects yet again Sometimes it redirects to a popular game on Google Play  But much of the time, it's NSFW sites  here seen from a Windows Phone  And sometimes  malware   As was the case for Johan  Here you can see that the malicious APK file was blocked by one of our  online  detections Specific  disk  detection identifies the threat as a variant of FakeInstaller  Trojan Android FakeInstAV Our Mobile Security Safe Browser blocks the offending website  Note  visiting the info site without the attack's parameter will result in a redirection to googlecom A site with an index page that redirects to googlecom  Always a clue something's afoot Be Safe Out There On 19 06 13 At 12 50 PM </description><link>http://www.secuobs.com/revue/news/452352.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/452352.shtml</guid></item>
<item><title>Rogue Headlines in Google News</title><description>Secuobs.com : 2013-06-17 11:56:21 - F Secure Antivirus Research Weblog -  A spam campaign is currently abusing Google News Search Engine Optimization  SEO  black hats are injecting  jailbreak  headlines into an iOS thread Google News Here's a view of the full coverage  Google News, Full coverage The so-called  news  link readers to schemes offering iPhone jailbreaks Unlock iPhone spam Here's an iPhone view  Google News SEO Google News SEO Google News SEO Google News SEO The good news  it appears that current SEO abuse is limited to spammers The bad news  where spammers go   exploit kits are surely soon to follow Let's hope Google's search engineers plug this hole quickly On 17 06 13 At 09 12 AM </description><link>http://www.secuobs.com/revue/news/451808.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/451808.shtml</guid></item>
<item><title>Fake Antivirus Scan Scam Via Google Play App Ads</title><description>Secuobs.com : 2013-06-13 15:06:27 - F Secure Antivirus Research Weblog -  Yesterday, we wrote about some very bad piggies  pirated Rovio software being used to push unwanted ads at Google Play users What kind of ads  Here's an example from an ad-network we've been tracking since we came across it back in March Yesterday, the ad-network directed Finnish IP addresses to an ad for a poker game app But today, the ad redirects to a fake  antivirus  scam  Android virus-aakejid Android virus-aakejid The scam's Finnish localization sucks   at least until you scroll down to the legal disclaimer at the bottom which claims it's all for  entertainment  purposes Android virus-aakejid Android virus-aakejid Just enter your phone number for the service and  Ouch  Fifteen euro a week  Do not want Stay Safe Out There On 13 06 13 At 12 39 PM </description><link>http://www.secuobs.com/revue/news/451236.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/451236.shtml</guid></item>
<item><title>Bad Bad Piggies On Google Play</title><description>Secuobs.com : 2013-06-12 17:23:11 - F Secure Antivirus Research Weblog -  One of these things is not like the others Bad Bad Piggies No, not the  Full Guide    we're referring to the  Bad Pigs  by Dan Stokes The app's description  Bad Bad Piggies Wow More than 10,000 installs since May 25, 2013 AppBrain, an Android app portal, doesn't correct for relevance, so  Bad Pigs  ranks first Bad Bad Piggies Dan's contact address is  hgfdhsdgjhd gmailcom That's fishy Bad Bad Piggies AppBrain has a very nice feature which lists  Concerns  as well as permissions required Bad Bad Piggies Boy, that's a long list of extra permissions These particular piggies aren't just bad   they're evil Dan Stokes has a few other apps as well Bad Bad Piggies  Fruit Chop Ninja  also has more than 10,000 installs And here's an interesting note  the app ID, and therefore the URL, includes the word  Rovio  Bad Bad Piggies Our Mobile Security product detects and blocks this as Android FakeInstCI We've reported the issue to Google  and Rovio  and the apps are no longer indexed by Google's search Stay safe out there On 12 06 13 At 03 11 PM </description><link>http://www.secuobs.com/revue/news/450987.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/450987.shtml</guid></item>
<item><title>Not the Mobile Antivirus You Were Looking For</title><description>Secuobs.com : 2013-06-06 09:29:05 - F Secure Antivirus Research Weblog -  While browsing Malaysiakini  a popular local media website in Malaysia  on an Android phone, one of our Fellows spotted this advertisement being displayed  mkini_scam_ad Clicking on the ad led to an external site displaying the following  mkini_scam_ad_download_screen Sounds reminiscent of the kind of text we've seen for years on webpages pushing rogues for Windows systems Clicking on the 'Download and Scan Now' button leads to an image, which looks like an antivirus app  mkini_scam_ad_download_screen_2 Clicking on the image brings you to a page that asks for your phone number and displays some interesting text  mkini_scam_ad_number_submission  This is an ongoing subscription service until you quit You will receive 4 sms per week and chargeable at RM4 per message Only  REMOVED  user will receives max 3 sms per week and chargeable at RM4 per message Data charges are billed separately by mobile operators  So, it's an SMS subscription service If a phone number is entered, the user gets an SMS message with registration instructions for the service Once registered, another SMS is sent providing a download link When we tried the link, the only thing we got was a message saying 'Sorry, you have exceeded the allowed download limit' Fortunately, the SMS with the registration instructions also included instructions for stopping the service We normally recommend users read the permissions requested when downloading a mobile app In this case, reading the text before downloading would also be prudent This was probably not the service a user was looking for when they clicked on the ad Browsing Protection currently rates the site hosting the APK download as Suspicious On 06 06 13 At 07 03 AM </description><link>http://www.secuobs.com/revue/news/449736.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/449736.shtml</guid></item>
<item><title>Our Mac Team Wants Beta Users</title><description>Secuobs.com : 2013-06-04 15:07:32 - F Secure Antivirus Research Weblog -  This is Rasmus twittercom pajp According to his Twitter bio  he's a long-haired over-intoxicated geek from Sweden living in Finland, who likes shiny unixy things He's a senior software engineer developer on our Mac Protection team  and a generally good guy  If you're also a geek   Rasmus thinks it would be  neat   that's a quote  if you'd give our  Safe Anywhere Mac Technology Preview  a try The team is developing a new feature that they want to roll out in a few weeks time So  if you have the skills to run beta software, Rasmus  and team  would really appreciate the feedback Cheers  On 04 06 13 At 12 55 PM </description><link>http://www.secuobs.com/revue/news/449250.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/449250.shtml</guid></item>
<item><title>Coursera Offers Malware MOOC</title><description>Secuobs.com : 2013-06-03 15:08:50 - F Secure Antivirus Research Weblog -   A massive open online course is an online course aimed at large-scale interactive participation and open access via the web  And here's a MOOC we think you'll be interested in  Coursera is offering a class called  Malicious Software and its Underground Economy Coursera, Malicious Software and its Underground Economy  Two Sides to Every Story According to instructor Lorenzo Cavallaro   Students will learn how traditional and mobile malware work, how they are analyzed and detected, peering through the underground ecosystem that drives this profitable but illegal business  Sounds intriguing On 03 06 13 At 12 35 PM </description><link>http://www.secuobs.com/revue/news/449029.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/449029.shtml</guid></item>
<item><title>F-Secure Globe</title><description>Secuobs.com : 2013-05-30 15:23:09 - F Secure Antivirus Research Weblog -  A visualization project using some of our customer upstream data  F-Secure Globe F-Secure Globe By Liew Swee Meng   based on The WebGL Globe On 30 05 13 At 12 40 PM </description><link>http://www.secuobs.com/revue/news/448549.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/448549.shtml</guid></item>
<item><title>The Future  No Hiding Place</title><description>Secuobs.com : 2013-05-29 15:48:22 - F Secure Antivirus Research Weblog -  This week's issue of The Economist has a very interesting article No hiding place  A plan to assess people's personal characteristics from their Twitter-streams No hiding place Researchers at IBM's Almaden Research Centre in San Jose, California think they can determine a person's presumptive personality from just 50 Tweets   In a test of the new system, Dr Haber analysed three months' worth of data from 90m users of Twitter His software was able to parse someone's presumptive personality reasonably well from just 50 tweets, and very well indeed from 200  So  marketers will finally be able to determine truly effective ways to target consumers  We should be so lucky if it were just marketers Here's another Economist article from April How might your choice of browser affect your job prospects  How might your choice of browser affect your job prospects According to  Big Data    you'll be a better employee if you use a non-default web browser One shudders to imagine how HR recruiters will use people's presumptive personalities  Targeted ads will be the least of our worries  It's enough to make you want to cut your tail off  Delete Your Oldest Tweets Using Twitter Archive Eraser On 29 05 13 At 12 42 PM </description><link>http://www.secuobs.com/revue/news/448314.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/448314.shtml</guid></item>
<item><title>Twitter's 2FA  SMS Double-Duty</title><description>Secuobs.com : 2013-05-24 16:51:12 - F Secure Antivirus Research Weblog -  Twitter introduced multi-factor login verification on Wednesday Good news  Well  that depends Twitter's initial implementation of two-factor authentication  2FA  relies on SMS But  Twitter also uses SMS as a way to send and receive Tweets  making use of SMS for double-duty  social and security  It's possible to  STOP  incoming Tweets via SMS, and that makes sense, because people sometimes end up roaming unexpectedly   and there needs to be a way to stop the SMS feature Otherwise it could generate a costly bill Unfortunately, an attacker could use SMS spoofing to disable 2FA if he knows the target's phone number Twitter's SMS 2FA We've done some testing The STOP command removes the phone number from the account   and that in turn disables Twitter's 2FA Not great But there's an even worse possibility at the moment If you don't yet have 2FA enabled, an attacker who gains access to your account via spear phishing could enable it for himself  All that's required is random phone number and SMS spoofing the word  GO  Twitter's SMS 2FA Then the attacker can enable the account's 2FA Twitter's SMS 2FA Then send a message  The message doesn't contain a confirmation code, so it isn't really needed  Twitter's SMS 2FA And then click  Yes  Twitter's SMS 2FA That's it No confirmation code is needed to add a number  Confirmation is required to change the account's associated e-mail address  This is what the victim will see   even if they reset the account's password Twitter's SMS 2FA The victim will be locked out, and cannot recover the account without Twitter's support So  perhaps you should enable your account's 2FA   before somebody else does it for you Fortunately, the majority of Twitter users aren't big targets Unfortunately, accounts such as  AP are And Twitter's SMS-based 2FA could be more harm than help when the use case is a dedicated attacker Twitter's blog post says  this feature has cleared the way for us to deliver more account security enhancements in the future  Let's hope so On 24 05 13 At 12 40 PM </description><link>http://www.secuobs.com/revue/news/447557.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/447557.shtml</guid></item>
<item><title>Mac Spyware Bait  Lebenslauf für Praktitkum</title><description>Secuobs.com : 2013-05-23 12:53:16 - F Secure Antivirus Research Weblog -  As a follow up to yesterday's Kumar in the Mac post  have you received e-mail attachments such as this  Lebenslauf für Praktitkum Attachments    Christmas_Cardappzip   Content_for_Articleappzip   Content_of_article_for_ NAME REMOVED appzip   Interview_Venue_and_Questionszip   Lebenslauf_für_Praktitkumzip If so, you may be the target of a spear phishing campaign designed to install a spyware on your Mac Here's a list of binaries signed by Apple Developer  Rajinder Kumar  Detected as Backdoor OSX HackBackB    1eedde872cc14492b2e6570229c0f9bc54b3f258   6737d668487000207ce6522ea2b32c7e0bd0b7cb   a2b8e636eb4930e4bdd3a6c05348da3205b5e8e0   505e2e25909710a96739ba16b99201cc60521af9   45a4b01ef316fa79c638cb8c28d288996fd9b95a   290898b23a85bcd7747589d6f072a844e11eec65   mentioned in yesterday's post Detected as Backdoor OSX KitMA  includes screenshot feature    4395a2da164e09721700815ea3f816cddb9d676e Though the spear phishing payloads are not particularly  sophisticated , the campaign's use of German localization and the target's name  removed in the example above  does indicate the attackers have done some homework Be vigilant More information  Mac Spyware Found at Oslo Freedom Forum Big Hangover On 23 05 13 At 10 12 AM </description><link>http://www.secuobs.com/revue/news/447273.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/447273.shtml</guid></item>
</channel>
</rss>
 
