Spyware and Malware Archive

Express Shipment Notification emails contain malware

Posted March 25, 2013 By National Cyber Security
Express 2jpg

Have you received an email with the subject line “Express Shipment Notification”?

If so, be on your guard – you could be at risk of infecting your Windows computers.

Online criminals have spammed out a large number of messages, claiming to come from DHL Express International, that are designed to install malware onto the computers of unsuspecting PC users.

Here is what a typical example of an email spammed out in the attack looks like:

 

express1jpg

 

 

 

 

 

 

 

 

DHL Express
Tracking Notification: 449762627

Custom Reference: 594078O440
Tracking Number: XFLNH94244
Pickup Date: Mon, 18 Mar 2013 12:39:03 +0100
Service: AIR
Pieces: 1

Mon, 18 Mar 2013 12:39:03 +0100 – Processing complete successfully
Refer to attached report for full details.

Attached to the emails is a ZIP file, containing malware. The filename of the ZIP file can vary, but takes the form “DHL reportXXXXXX.zip” (where the ‘X’s are a random code).

Sophos products detect the malicious attachment as the Troj/BredoZp-S Trojan horse.

Of course, the emails don’t really come from DHL – and the fact that you may have received an email which has DHL in its “From:” field does not mean that any computer systems at DHL have been compromised, but just that the attackers have forged the email headers.

Time and time again we have seen cybercriminals using the disguise of shipping companies like DHL and FedEx to spread their malware attacks and hijack the computers of the unwary.

Your best protection is to not just run an up-to-date anti-virus, but also to live and breathe computer security in your every day life.

How do you do that? Well, you can start by learning to never open attachments in unsolicited emails – however tempted you might be.

Source: http://nakedsecurity.sophos.com/2013/03/18/express-shipment-notification-emails-malware/

Hi Tech Crime Solutions

Beware Infrared X-Ray: Latest Android Malware Spams Victim’s Contacts

Posted March 25, 2013 By National Cyber Security
spam

The latest malware targeting users of Android devices is trying to lure victims into downloading an app called Infrared X-Ray, and is spreading quickly by tapping into victims’ contacts and spamming them with SMS messages.

The new SMS Trojan was analyzed by Symantec (NSDQ:SYMC) researchers in Japan. The cybercriminals behind the campaign are using a malicious application to tap into the victim’s contacts rather than sending out text messages themselves, wrote Joji Hamada, a Symantec threat researcher in the company blog.

“This allows the recipients of the spam to be tricked easier because the invitation to download the app is coming from someone they know rather than from an unknown sender,” Hamada said.

[Related: Malware Rising: Trojans Dominate Rankings, Study Finds ]

The app steals all details in the device’s contact list. “Not surprisingly, the app does not work as per advertised and a picture of man holding up his middle finger stating that the victim is a pervert is displayed,” Hamada wrote.

Several variants of the malware exist and some versions attempt one-click fraud, Hamada said. Victims are given details about pornographic websites while their contact information is uploaded to a remote server. The app attempts to charge a registration fee and threatens the victim that it will send a message to every person in the contact list if the fee isn’t paid promptly.

“In order to make it difficult for the victim to uninstall the app, it removes itself from the launcher after it is initially executed, although it can be removed in Applications under Settings,” Hamada wrote.

SMS Trojans are among the most virulent threats on Android devices, according to studies provided by security firms. A recent mobile threat report issued by antivirus vendor F-Secure found that nearly 80 percent of all mobile malware targeted Android devices in 2012, primarily driven by malicious apps in third-party app stores.

F-Secure warned that malware authors are developing more sophisticated attack techniques for mobile devices, using encryption and randomization or hiding malicious code in image files. Malware also was discovered on bootleg copies of the Angry Bird game, the firm said.

“Over the year, Android threats have continued to improve their techniques in evading detection and their methods of infection, yet nothing much has changed in their operation in collecting profit,” F-Secure said. “The majority of malware discovered in Android markets are SMS-sending malware that reap profit from sending messages to premium numbers.”

Symantec’s Hamada said all device owners should refrain from clicking links in emails and SMS messages that aren’t expected. Only download apps from trustworthy sources, he said.

Source: http://www.crn.com/news/security/240150979/beware-infrared-x-ray-latest-android-malware-spams-victims-contacts.htm

High Tech Crime Solutions

Trojan Horses, Malware and Other Cyber Attack Tools are Just a Click Away

The Washington Post News Service with Bloomberg News

(c) 2012, The Washington Post.

Ryan Linn’s hacks into corporate networks have become almost a matter of routine. On one recent morning, he woke up at his home near the Research Triangle in eastern North Carolina and walked down to an extra bedroom that he uses as an office.

He sat at a workbench laden with computers, signed on to one of them and loaded a program called Metasploit. Sipping a Diet Coke, Linn typed out a few commands and casually launched an attack on a network thousands of miles away. A few seconds later, a report came back: The network had been penetrated. How would he like to proceed?

Chalk up another one for Metasploit, an automated tool kit that makes breaking into networks almost as easy for experienced hackers as ordering food off an online menu.

Metasploit and a host of similar tools are becoming as commonplace for many hackers as Firefox and Microsoft Office are for regular computer users.

They are part of an escalating arms race in cyberspace, where millions of attacks and intrusions occur every day. By prepackaging the myriad computer commands that penetrate and exploit target networks, hackers have dramatically eased the process.

Security researchers and consultants, including Linn, use such hacking tools to identify vulnerabilities and help organizations patch them. Bad-guy hackers, known as black hats, and cyberwarriors use similar illicit kits to spy on, steal from and wreak havoc in corporate and government computers.

Metasploit and many other hacker tool kits are available free to anyone who has an Internet connection.

Linn acknowledges the irony. But he likened Metasploit and other tool kits to a “Swiss army knife” and said the positive features “far outweigh the negatives.”

“Metasploit is a tool designed for researchers and security professionals, but just like many tools there are uses for it that are illegal,” said Linn, a security consultant at Trustwave’s SpiderLabs. “We don’t outlaw screwdrivers and hammers because someone might use them for murder, though. We prosecute those people who use them illegally.”

A researcher named H.D. Moore began working on Metasploit in 2002. Moore, now 31, is the chief security officer with Rapid7, a security firm that sells a commercial version of Metasploit and helps offset the cost of maintaining the free system. A computer researcher and hacker based in Austin, Moore wanted to simplify the development of computer hacks known as exploits. To keep pace with growing numbers of criminal cyberattacks, he wanted to make security hacking, or “penetration testing,” more systematic.

Metasploit works by creating ready-made packages of computer code, known as “modules,” that can be downloaded from metasploit.com. Once they are launched, the tools can find network vulnerabilities and take control of the systems.

Metasploit also serves as something of a global clearinghouse of hacker knowledge, tools and practices. Because it is an “open source” system, it relies on contributions from experienced hackers. Its popularity has soared during the past several years. Starting with 11 exploits in 2003, Metasploit now has close to 1,000.

About 300 people in at least 20 countries have donated exploits so far. The contributors also collaboratively review the offerings to be sure they work effectively. Moore estimated that about 1 million people downloaded the free version during the past year, with about 5 million since its inception. It appears that about 200,000 penetration testers, including the U.S. military’s cyberwarriors, use it regularly, he said.

No one knows how many bad guys employ Metasploit and similar tools. Fears about that potential have been raised in Germany and elsewhere. But Moore said black-hat hackers typically rely on other tool kits that are less focused on research and more focused on swift, illegal break-ins.

Moore said the fact that criminals, spies and others with ill intent can access Metasploit is a necessary trade-off. To keep Metasploit up to date, hackers have to be able to contribute details about the newest vulnerabilities and attack methods.

An organization that keeps track of known vulnerabilities said it has documented more than 53,000, a number that rises every day.

“All we’re trying to do is put everyone on a level playing field,” Moore said.

When Metasploit emerged, even veteran hackers marveled at its design and simplicity. A 2004 presentation about it at Black Hat Las Vegas, the annual hacker conference, was titled “Hacking Like in the Movies,” according to a 290-page online book called “Metasploit Toolkit” by David Maynor and several other security researchers.

“The hall was packed to the gills. People stood in the aisles, and the crowd was spilling over to the main corridor,” the authors wrote. “Applause flowed freely throughout the session, and the consensus was clear, ‘Metasploit had come of age.’ But we should have known better. That was only a taste of things to come.”

The extraordinary thing about Metasploit is the digital architecture that streamlined what had been a laborious process of exploit development. That process invariably involved several steps for anyone, good or bad: the discovery of a software vulnerability; the analysis of the code to see whether the vulnerability could be exploited; the writing of the exploit itself, including the commands that tell a target system to open up to an intruder; and testing to ensure the exploit worked.

With Metasploit, all those steps are already done and packaged together with still other features, including tailor-made “payloads” that take effect and hand over control of a system after a hacker gets in.

Other systems have been created to ride on top of Metasploit and make it even easier to use. One called Armitage was created by Raphael Mudge, who was recently hired under contract by the Defense Advanced Research Projects Agency to develop new cybertools.

“Armitage recommends exploits and will optionally run active checks to tell you which exploits will work,” Mudge said in an Armitage tutorial. “If these options fail, use the Hail Mary attack to unleash Armitage’s smart automatic exploitation against your targets.”

In some cases, Moore said, researchers use the Metasploit framework to apply pressure on software vendors to improve the security of their products. If the vendors neglect to fix a known bug, the researchers write an attack module to spur them to act.

That happened this year when a group of researchers created attack modules for six industrial control systems, the computers that operate the power grid, water plants and other critical infrastructure.

“It forces the security vendors to take that vulnerability seriously,” Moore said. “And it forces the vendors responsible for that software to provide a patch or a work-around.”

Alan Paller, director of research at the Sans Institute, one of the world’s leading cybersecurity training organizations, said Metasploit contributors are playing a crucial role in highlighting the pervasive vulnerabilities in systems throughout cyberspace.

“They solve a critical problem for us,” Paller said. “They are necessary tools right now when much of the world is still in denial.”

No one knows how many illicit attack kits are sold to black-hat hackers. Offers appear every day across the Internet. Moore said exploit kits that employ “botnets” in criminal schemes often sell for up to $10,000.

A botnet is a network of computers that have been infected by malicious software and are controlled by bad guys. They often send spam, but they are also used to send malicious code, or malware, in coordinated attacks on networks.

Moore said that in several cases, the bad guys have used botnets to attack Metasploit as punishment for spurring fixes to widely attacked vulnerabilities.

“We do a good job killing bugs,” Moore said. “When the Metasploit adds a new attack, it instantly raises the visibility of that vulnerability.”

Robin Jackson sat in his Helena, Mont., office and prepared to launch his next hack. The target: a Chinese company’s website.

Jackson is a security researcher for a firm called WT Forensics. He said he also participates in informal networks of hacker-intelligence specialists who try to keep watch on the black hats and cyberwarriors across the globe.

He described his China effort as an exploratory “gray hat” hack to see if the target company’s Web page was vulnerable. He decided he would use a set of commands to make his attack seem as though it were coming from a computer in London. To penetrate the Web server, he would turn to the collection of tool kits he keeps on his computer.

In addition to Metasploit, Jackson relies on a number of other automated attack kits almost every day to do his job. There are many of them: Nmap scans the configuration of networks. John the Ripper and Hashcat crack passwords. The Social Engineering Toolkit combines automation with manipulation techniques to help hackers trick people into giving them access to networks.

A host of commercial systems, including a premium version of Metasploit, make it possible to attack multiple client machines at a time. A firm called Immunity, maker of a security tool kit called Canvas, recently released a related commercial system called Swarm. It enables security researchers to scan and attack up to a million servers an hour.

For this exploratory mission, Jackson decided to use a more focused free tool called Havij. With a few clicks on his keyboard, he directed Havij at the targeted Internet address in China. He typed “%Inject Here%” to launch the program.

Havij has been built to send thousands of permutations of commands to implement something known as an SQL Injection attack. Havij would keep hammering the targeted Web server until it sent a command that slipped by the server’s security.

A few years ago, Jackson would have had to type each attack command by hand. With Havij, he can launch the attack, sip his coffee and wait. “Unlike the manual process, Havij automatically does everything seamlessly and much more quickly,” he said.

For all their benefits, Jackson said, the kits are lowering the barriers to entry for inexperienced hackers. Criminal hackers and “hacktivists” can simply download the tool kit and then watch an instructional video on YouTube to get started.

Members of the hacktivists group Anonymous have used the system to target police and military networks. A group called Team GhostShell relied on it to compromise hundreds of Chinese websites.

“The Internet not only enables the distribution of hacking tools, but it also offers the hands-on instruction and training on how to use these,” Jackson said. “There are literally thousands upon thousands of videos . . . which show the neophyte how to install and use these tools.”

bc-cyber

Source: http://www.oregonlive.com/newsflash/index.ssf/story/trojan-horses-malware-and-other-cyber-attack/451b14de7e0d161129e54ba0e7267a3f

High Tech Crime Solutions


http://www.GregoryDEvans.com, http://www.Locatepc.net, http://stolencomputeralert.com, http://computersecurityexpert.net, http://www.hackerforhireusa.com, http://www.GregoryDEvans.net, AmIHackerProof.com, http://ParentSecurityOnline.com, http://TheCyberWars.com, http://hiphopsecurity.com, http://HackerForHireinternational.com, http://www.computersecurityguru.com, http://computer-security-expert.com

While Jeff Schmidt, the CEO of JAS Global Advisors, was surfing the Web on his new Android smartphone (his first Android phone) earlier this year, what appeared to be an ad popped up on his screen. The "ad" looked like the prompt that appears when his phone rings. He clicked the button on the ad to pick up the putative call, and the ad began downloading a binary file – malware – onto his Android …

View full post on spyware jail – Yahoo! News Search Results

Other links you may like:

Gregory Evans on Television http://gregorydevans.com/video-gallery/, LocatePC, Fake Emails go to SPOOFEM.COM, LIGATT Security, Hacker Gear OnlineStolen Computer Alert

The former Rutgers University student convicted last week of spying on his gay roommate who later jumped off the George Washington Bridge spoke out for the first time Wednesday — and adamantly stuck to his decision to reject a no-jail plea deal. “I’m never going to regret not taking the…

View full post on spyware jail – Yahoo! News Search Results

Other links you may like:

, LocatePC, Fake your caller ID go to SPOOFEM.COM, LIGATT Security, Hacker Gear OnlineStolen Computer Alert

Last June, three men squeezed inside a wind turbine in China’s Gobi Desert. They were employees of American Superconductor Corp., a maker of computer systems that serve as the electronic brains of the device. From time to time, AMSC workers are required to head out to a wind farm in some desolate location — that’s where the wind usually is — to check on the equipment, do maintenance, make …

View full post on spyware jail – Yahoo! News Search Results

Other links you may like:

Recommendations & Credentials For Gregory Evans: http://gregorydevans.com/recommendations-credentials/, LocatePC, Fake your caller ID go to SPOOFEM.COM, LIGATT Security, Hacker Gear OnlineStolen Computer Alert

A website belonging to antivirus software and Internet security firm Panda Security was targeted by members of the hacking collective Anonymous Tuesday in what various media outlets are calling retaliation for the arrest of five members of the Lulzsec group earlier this week. According to BBC News reports Wednesday, the hackers identified themselves as members of AntiSec, a collaborative …

View full post on spyware jail – Yahoo! News Search Results

Other links you may like:

, LocatePC, Fake your caller ID go to SPOOFEM.COM, LIGATT Security, Hacker Gear OnlineStolen Computer Alert

Right away, investigators knew that whoever killed 55-year-old Arunkumar Ingle had no interest in robbery. They found no signs of a break-in at his modest ranch home in the Glen Riddle section of Middletown Township, Delaware County, no knocked-over furniture, no ransacking, no TVs or jewelry taken.

View full post on spyware jail – Yahoo! News Search Results

Other links you may like:

Recommendations & Credentials For Gregory Evans: http://gregorydevans.com/recommendations-credentials/, LocatePC, Fake Emails go to SPOOFEM.COM, LIGATT Security, Hacker Gear OnlineStolen Computer Alert

Rugby-loving couch potatoes beware: RBS expects you to flex your brain, if not your muscles, during the Six Nations tournament this year. The sports-sponsoring bank has created an interactive quiz, fixtures and social app for 2012, with game-related questions that sync with the on-screen action, live score tables and Facebook integration for those particularly competitive. [...]

View full post on spyware jail – Yahoo! News Search Results

Other links you may like:

Gregory D Evans, LocatePC, Fake Emails go to SPOOFEM.COM, LIGATT Security, Hacker Gear OnlineStolen Computer Alert

OLYMPIA — A measure that would decriminalize use and possession of small amounts of marijuana for adults was sent to the Washington Legislature today after the Secretary of State's office certified it has more than enough signatures.

View full post on spyware jail – Yahoo! News Search Results

Other links you may like:

The Worlds No 1 Security Consultant: http://www.youtube.com/no1hacker#p/u/0/KaOnRsc16Ls, LocatePC, Fake your caller ID go to SPOOFEM.COM, LIGATT Security, Hacker Gear OnlineStolen Computer Alert

MegaUpload founder and CEO Kim Dotcom has again been denied bail by a New Zealand court, after his appeal to the High Court was rejected over fears he might abscond to avoid extradition. The appeals judge agreed with a lower court decision in late January that Dotcom – who has a track record of avoiding arrest, as [...]

View full post on spyware jail – Yahoo! News Search Results

Other links you may like:

Gregory Evans, LocatePC, Fake your caller ID go to SPOOFEM.COM, LIGATT Security, Hacker Gear OnlineStolen Computer Alert

Megaupload's hosting services agree to preserve the digital files stored at the cyberlocker service for at least two weeks ( ZDNet UK – Security Threats )

View full post on spyware jail – Yahoo! News Search Results

Other links you may like:

Gregory Evans on Television http://gregorydevans.com/video-gallery/, LocatePC, Fake Text Messages go to SPOOFEM.COM, LIGATT Security, Hacker Gear OnlineStolen Computer Alert

SEOUL, South Korea, January 11, 2012 /PRNewswire/ – Mass distribution of Malware that targets application and OS vulnerabilities – ´Zombie smartphone´ expected to emerge – AhnLab cautions users to use Smartphone vaccines and the official …

View full post on spyware jail – Yahoo! News Search Results

Other links you may like:

Recommendations & Credentials For Gregory Evans: http://gregorydevans.com/recommendations-credentials/, LocatePC, Fake Text Messages go to SPOOFEM.COM, LIGATT Security, Hacker Gear OnlineStolen Computer Alert

Sites we like

Stolen Computer Alert
How to become the world’s No. 1 hacker
Gregory Evans is the World’s No. 1 Security Consutlant

Join the mailing list

Check your email and confirm the subscription