Malware News http://www.malware-news.com Latest internet security news blog Mon, 04 May 2009 13:12:14 +0000 http://wordpress.org/?v=2.7 en hourly 1 Top 20 malware programs. Conficker is on the 1st place http://www.malware-news.com/top-20-malware-programs-conficker-is-on-the-1st-place.html http://www.malware-news.com/top-20-malware-programs-conficker-is-on-the-1st-place.html#comments Mon, 04 May 2009 13:10:41 +0000 admin http://www.malware-news.com/?p=453 According to the report published today by Kaspersky Lab,it has been detected over 45 190 of unique harmful, advertising and potentially dangerous programs during last month. This digit practically does not differ from a metrics for March.

malware

In a rating of twenty most widespread harmful programs worm Conficker known also as Downadup and Kido continues to the the leading position. By some estimations, Conficker could infect up to 20 million computers worldwide. The last days this worm has started to form the infected computers in a botnet for distribution of spam emails and spyware.

The second string of “charts”, as well as one month ago, holds the virus Sality with spyware functionality. This harmful program intercepts the information entered by means of the keyboard, and sends gathered information to malefactors.

It is remarkable that the harmful code CodeBaseExec which first versions have been detected in 2004 has returned to April virus “twenty”. The program gets on the PC of a victim through old “hole” in a browser of Internet Explorer of versions 5.01, 5.5 and 6.0.

The complete rating of harmful programs for April under the version «Kaspersky’s Laboratory» looks like this:

1. Net-Worm.Win32.Kido.ih
2. Virus.Win32.Sality.aa
3. Trojan-Dropper.Win32.Flystud.ko
4. Trojan.Win32.Chifrax.a
5. Trojan.Win32.Autoit.ci
6. Trojan-Downloader.Win32.VB.eql
7. Packed.Win32.Krap.b
8. Worm.Win32.AutoRun.dui
9. Exploit.HTML.CodeBaseExec
10. Packed.Win32.Black.a
11. Virus.Win32.Sality.z
12. Virus.Win32.Virut.ce
13. Trojan.JS.Agent.xy
14. Worm.Win32.Mabezat.b
15. Virus.Win32.Alman.b
16. Packed.Win32.Krap.g
17. Packed.Win32.Klone.bj
18. Worm.Win32.AutoIt.ar
19. Exploit.JS.Agent.agc
20. Email-Worm.Win32.Brontok.q

]]>
http://www.malware-news.com/top-20-malware-programs-conficker-is-on-the-1st-place.html/feed
A critical hole in Adobe products http://www.malware-news.com/a-critical-hole-in-adobe-products.html http://www.malware-news.com/a-critical-hole-in-adobe-products.html#comments Wed, 29 Apr 2009 09:36:13 +0000 admin http://www.malware-news.com/?p=449 A critical vulnerability has been found out in Adobe Acrobat and Adobe Reader, the patch for which does not exist now.

Adobe Acrobat vulnerability

As it is informed, the problem is related to processing of JavaScript code. With help of the document generated in special way malefactors theoretically can organise DoS-attack, provoke emergency end of work of the program or execute any operations on the remote computer.

Adobe has confirmed the existence of the problem, having underlined, that it mentions all delivered versions of Reader and Acrobat packages , including 9.1, 8.1.4, 7.1.1 and earlier updatings. The situation is aggravated with that there were examples of the harmful code on the Internet, allowing to involve vulnerability.

]]>
http://www.malware-news.com/a-critical-hole-in-adobe-products.html/feed
Conficker worm is active again http://www.malware-news.com/conficker-worm-is-active-again.html http://www.malware-news.com/conficker-worm-is-active-again.html#comments Mon, 27 Apr 2009 11:22:31 +0000 admin http://www.malware-news.com/?p=445 As mark security experts form Symantec, Conficker step-by-step transforms thousands of infected PCs into zombie network for spam and spyware distribution. The worm loads it’s code under the name Waledac which unites the infected machines in the botnet.

conficker worm


Employees of Trend Micro underline that the network of zombie computers, formed by Conficker, probably, is one of the most difficult and thought over the history of botnets. The creation of this network proceeds rather slowly, however experts do not eliminate possibility of application the botnet in the organisation of massed attacks and distribution of millions undesirable emails.

Conficker has been detected in November of last year, however the peak of its activity was on the beginning of January. By various estimations, for today the harmful program could infect up to 20 million computers worldwide. For a trustworthy information about authors of worm Conficker the award at a rate of 250 thousand dollars is offered.

]]>
http://www.malware-news.com/conficker-worm-is-active-again.html/feed
Database of startup files http://www.malware-news.com/database-of-startup-files.html http://www.malware-news.com/database-of-startup-files.html#comments Fri, 24 Apr 2009 13:06:12 +0000 admin http://www.malware-news.com/?p=437 The new database of startup programs has been published. Each entry in the database is classified according to security risk. (Malware, Suspicious, Infected, Trusted, etc.)

startups-database

The database currently contains over 90 thousand of autorun items, and is constantly being updated.

Visit CESAM Startup files database

]]>
http://www.malware-news.com/database-of-startup-files.html/feed
Hackers have stolen the data about superexpensive military project of the Pentagon http://www.malware-news.com/hackers-have-stolen-the-data-about-superexpensive-military-project-of-the-pentagon.html http://www.malware-news.com/hackers-have-stolen-the-data-about-superexpensive-military-project-of-the-pentagon.html#comments Wed, 22 Apr 2009 12:27:30 +0000 admin http://www.malware-news.com/?p=433 Unknown malefactors managed to receive unauthorized access to the information on the most expensive military project of the Pentagon — a hardly noticeable fighter-bomber of fifth generation F-35 Lightning II.

f35_430
F-35 Lightning II is being developed by companies Lockheed Martin, Northrop Grumman and BAE Systems within the limits of program Joint Strike Fighter. Project cost is estimated in 300 billion dollars.

As network sources inform, malefactors managed to penetrate into a computer network of one of participants of the Joint Strike Fighter program and copied several terabytes of information about electronic components and the plane construction. Theoretically this data can simplify development of protection against American fighter of fifth generation.

Attack, presumably, has been carried out from territory of China. It is marked that cybercriminals did not manage to reach the most important information on a fighter as it is stored on computers which are not connected to the Internet. Nevertheless the damage put to program Joint Strike Fighter, can be calculated by millions dollars.

Let’s notice that computer networks of the governmental departments of the USA regularly are exposed to cyberattacks. Last year the president George Bush even has signed the decree which assumes the essential extension of powers of Agency of national safety of the USA for the purpose of preventing of hacker’s attacks.

]]>
http://www.malware-news.com/hackers-have-stolen-the-data-about-superexpensive-military-project-of-the-pentagon.html/feed
First botnet based on Apple computers http://www.malware-news.com/first-botnet-based-on-apple-computers.html http://www.malware-news.com/first-botnet-based-on-apple-computers.html#comments Tue, 21 Apr 2009 09:20:21 +0000 admin http://www.malware-news.com/?p=430 Security experts from Symantec company inform of appearance of the first botnet, which structure includes computers under control of Apple Mac OS X operating system.
Apple botnet
The analysis has shown that creation of new zombie network, named iBotnet, has started in January. The structure of the botnet includes computers infected with malicious program OSX.iServices. This trojan was distributed as an utility for removal of copy protection of pirated versions of Photoshop CS4 and iWork ‘ 09.

At a rough guess, the iBotnet network can include up to several thousand computers. Some time ago the botnet has been already used by malefactors for the purpose of carrying out of the distributed DoS-attack. Probably in the long term cybercriminals will try to use iBotnet for the organisation of a mass spam distribution. Experts mark that the majority of anti-virus programs for Mac OS X platform already contain detection and removal procedures for the iServices trojan. Users are strongly recommended not to neglect elementary security measures.

]]>
http://www.malware-news.com/first-botnet-based-on-apple-computers.html/feed
New trojan blocks access to Windows http://www.malware-news.com/new-trojan-blocks-access-to-windows.html http://www.malware-news.com/new-trojan-blocks-access-to-windows.html#comments Mon, 20 Apr 2009 07:54:48 +0000 admin http://www.malware-news.com/?p=427 Doctor Web company warns about appearance of the new harmful program locking access to the infected computer.

locked-computer

The trojan was named Winlock.19. The program extends through the Internet under the pretext of counterfeit codecs and suggests to enter the special code ostensibly necessary for registration of a counterfeit copy of the operating system of Windows. To receive this code, it is necessary to send the text message from a mobile phone on a paid number.

It is remarkable that Winlock it is supplied by function of self-destruction and deletes itself in two hours after start. The Doctor Web company does not recommend to users to follow the malefactors and to send SMS anywhere. For those who does not wish to wait two hours to an automatic uninstall, Doctor Web has prepared the special form into which it is possible to enter the text of the prospective short message and to receive an unblocking code.

]]>
http://www.malware-news.com/new-trojan-blocks-access-to-windows.html/feed
Conficker worm: new version detected http://www.malware-news.com/conficker-worm-new-version-detected.html http://www.malware-news.com/conficker-worm-new-version-detected.html#comments Thu, 16 Apr 2009 09:13:09 +0000 admin http://www.malware-news.com/?p=424 The “Kaspersky’s Labs” warns about appearance of the new version of the Conficker also known as Kido and Downadup.

conficker

Conficker has been detected in November of last year, however the peak of its activity has been on the beginning of January: for a few days the worm has infected about ten millions computers worldwide.

New variant of Conficker has started to extend in the end of last week: the infected computers, co-operating with each other through P2P-connections, have given the command to other infected computers on loading of upgrades and two files — FraudTool. Win32.SpywareProtect2009.s and Email-Worm. Win32.Iksmas.atz. The first of these units represents a counterfeit antivirus which is placed on the servers allocated in territory of Ukraine. At start the program suggests «to delete the found viruses», demanding for it about 50 dollars. The second file — a mail worm possessing a functional of theft of the data and a spam sending.

«Kaspersky’s labs» marks that for 12 hours one bot infected with the new version of Conficker has sent over 42 thousand spam emails. If to assume that the total amount of infected computers is about 5 million it turns out that the Conficker botnet is capable to dispatch approximately 400 billions spam messages daily.

Different sources also inform that in the end of last week the Conficker has penetrated into computer network of University of Utah (USA), having infected about 700 computers at medical school, medical nursing care college and so forth the Primary analysis of a code of new variant Conficker allows to say that it will function till May, 3rd.

]]>
http://www.malware-news.com/conficker-worm-new-version-detected.html/feed
Next attack of Conficker is expected on April 1st http://www.malware-news.com/next-attack-of-conficker-is-expected-on-april-1st.html http://www.malware-news.com/next-attack-of-conficker-is-expected-on-april-1st.html#comments Thu, 26 Mar 2009 10:56:58 +0000 admin http://www.malware-news.com/?p=421 On April, 1st worm Conficker, probably, will force not to laugh, and to cry very many Internet users.

Conficker

Conficker has been detected in November of last year, however the peak of its activity was on the beginning of January: for few days the worm infected about ten millions computers worldwide. The malicious program, capable to extend in the various ways, including through removable disk drives, allows malefactors to inspect the infected computers far off.

Computer security experts warn that on April 1st Conficker will receive a certain upgrade. Experts believe that the malicious program can be used for the purpose of the organisation of DDoS-attacks, and also for realisation of a mass spam sending or the infected letters.

Microsoft with support of some the organisations (including OpenDNS) has already launched campaign for struggle against a worm, providing locking of domain names which can be used by the worm.

]]>
http://www.malware-news.com/next-attack-of-conficker-is-expected-on-april-1st.html/feed
The worm of new type unites Linux-routers in a botnet http://www.malware-news.com/the-worm-of-new-type-unites-linux-routers-in-a-botnet.html http://www.malware-news.com/the-worm-of-new-type-unites-linux-routers-in-a-botnet.html#comments Wed, 25 Mar 2009 16:30:03 +0000 admin http://www.malware-news.com/?p=418 Experts from DroneBL have detected very unusual botnet, consisting not from personal computers of Internet users, but from DSL-modems and routers.

hacker2

According to the research, a worm under the name psyb0t is responsible for the creation of the botnet. Network devices on the basis of Mipsel platform — variant of Debian Linux for processors MIPS are the subject of infection. Attack is made by exhaustive search of combinations of a login and the password under the list; after successful breaking psyb0t closes access to a router for other users and incorporates with the botnet.

DroneBL experts mark that they have detected the malicious program during reflexion of the DDoS-attack routed on their servers. The worm, presumably, is unique and extends in the Network from the beginning of the year. At a rough guess, the botnet, organised with the help psyb0t, can consist of more than 100 thousand network devices.

It is informed also that some days ago the botnet has ceased to show activity. However the given information is not confirmed yet.

]]>
http://www.malware-news.com/the-worm-of-new-type-unites-linux-routers-in-a-botnet.html/feed