Отправляет email-рассылки с помощью сервиса Sendsay
  Все выпуски  

Caphaw Trojan Found in Youtube Ads


Антивирусный "хостинг"

Клуб пользователей антивирусных услуг (Saas, Cloud)

добавить на Яндекс
Антивирусы и безопасность (SaaS, Cloud ...)
av-host.net

Caphaw Trojan Found in Youtube Ads
2014-02-27 11:48

KMM поделился ссылкой

Caphaw Trojan Found in Youtube Ads

youtube-logoLast Friday – under the shadow of two critical zero day exploits on Internet Explorer and Adobe Flash – researchers at Bromium Labs discovered malware in an advertising network connected to Youtube.  Specific details are yet unknown and the threat has yet to be completely mitigated.  As of Friday, Google Security was made aware of the issue and is currently investigating the matter with Bromium.

What is Known

The malware being served is a Caphaw banking Trojan.  Emsisoft detects Trojans from this family as Trojan.Win32.Caphaw.

The attackers are infecting Youtube users through third-party Youtube ads, using the drive-by download technique.

Further investigation has revealed that the ad network serving the Caphaw malware is also hosting the Styx exploit kit.  An exploit kit is a toolkit hackers can purchase ready-made and then place on malicious websites to automatically target common vulnerabilities present on un-updated computers.  The Styx exploit kit targets Java vulnerabilities in particular.  Research indicates that in this attack Styx is being used to target CVE-2013-2460.

Research has also indicated that this attack connects users to a C&C server in Europe.  As yet, this server’s specific location remains unknown.

Am I at Risk?

Anyone running Emsisoft is automatically protected from Caphaw.  Users not running a comprehensive anti-virus software who have recently clicked on a Youtube ad may be infected.

The Caphaw Trojan allows attackers remote control of your PC.  With such control, attackers may directly access your files, monitor your Internet usage, or use your PC for any number of malicious activities.

If you recently clicked on a Youtube ad, Emsisoft recommends an immediate scan with Emsisoft Anti-Malware.  The software will detect and remove Caphaw, and protect your PC from future attacks.

More Details on this Threat

Bromium published an initial analysis of the attack in a blogpost on Friday.  The research firm is currently working with Google Security to investigate the attack in greater detail.  Updates are sure to follow.

Targeting a high profile website such as Youtube is a watering hole tactic.  Youtube receives thousands if not millions of visitors per day, so attacks like this one have a greater chance of infecting more users.  People often think that they are safest when visiting such websites, as security is generally much tighter and the odds of being targeted among so many other users seem slim, but this is somewhat of a misconception.  From an attacker’s perspective, poisoning just one giant waterhole can be much more profitable and can take much less time than poisoning one hundred smaller ones.

This recent attack acts as an important reminder.  No website is 100% secure.  And, whether malicious or not, Internet advertising exists to make money.  So be careful where you click.

Here’s to a Malware-Free Week Ahead!



RIP Mt.Gox
2014-02-27 12:40

KMM поделился ссылкой

RIP Mt.Gox

gox2About two weeks ago, Emsisoft published a blog post on the transaction malleability crisis at Mt.Gox.  Today, the headlines read that the Bitcoin exchange is dead.

The Mt.Gox website has been taken offline.  The Mt.Gox Twitter is gone.  A leaked Crisis Strategy Draft has hit the web, apparently authored by Mt.Gox executive leadership.  This document states:

"At this point 744,408 BTC are missing due to 
malleability-related theft which went unnoticed 
for several years."

744,408 BTC = 350 million USD.

The remainder of the document reads like an exit strategy, with plans to re-launch the corporation under new leadership and branding.  Assuming this document is legitimate, Mt.Gox knew they were through.  The corporation was more or less blindsided by transaction malleability.

Is Cryptocurrency Worth it?

Small details matter.  Glitches propagate.  One small bug has enabled $350 million in theft and has crippled a multibillion dollar corporation.

This is a principle of engineering that pops up time and time again.  The devil is in the details.  The more complex a system becomes, the more chaotic too.  Grammarians like to illustrate this principle through the comparison of two sentences:

“Let’s eat Grandma!”  vs.  “Let’s eat, Grandma!”

One comma changes everything.

Computer security is the exact same way.  Overcomplicated structures built on weak foundations topple.  The temptation to make a quick buck is immense, but the methodologies necessary to do so cannot coexist with a sustainable business model.

At least we think so.

The question remains: Is cryptocurrency worth it?  Has Bitcoin met its end?

We’d love to hear your thoughts in the comment section below.



Preview: Emsisoft Mobile Security offers protection for your Android device
2014-02-27 12:42

KMM поделился ссылкой

Preview: Emsisoft Mobile Security offers protection for your Android device

Emsisoft Mobile Security [beta]  is a next-gen security solution for Android devices focused on little (to zero) system or battery impact while providing access to a number of security functions in order to help you have a safer and more informed Android experience.

Emsisoft Mobile Security

Protects your Android smartphone and tablet from dangers awaiting on the internet.

  • Scans all stored files for malware infections.
  • Real time protection that blocks malicious apps as they arrive.
  • Surf protection that blocks access to dangerous websites.
  • Anti-Theft to lock or wipe the device remotely when stolen or lost.
  • Privacy audit for installed apps.

Preview of the Beta:

 

We’d like to invite interested users to join our beta test and download Emsisoft Mobile Security now! 



Нашелся обладатель смартфона и другие призеры аукциона ВебIQметра!
2014-02-27 12:55

KMM поделился ссылкой

Нашелся обладатель смартфона и другие призеры аукциона ВебIQметра!

27 февраля 2014 года

На интерактивном образовательном проекте ВебIQметр разыграны лоты восемнадцатого аукциона. Наиболее ценными артефактами на этот раз стали смартфон Sony Xperia M (с лицензией Dr.Web Mobile Security на 1 год) и электронная книга Prestigio MultiReader 3664 – и достаются они соответственно пользователям amonn (г. Муром) и lexy (г. Санкт-Петербург). Наши поздравления победителям!

Участники ВебIQметра под псевдонимами Elenusik (Украина, г. Харьков), SSahapov (г. Набережные Челны) и Таулан (г. Черкесск) выигрывают компьютерные мыши A4 Tеch X 710. Что касается Grand Theft Auto V, то играть в эту видеоигру посчастливится пользователям Nike, Soulcatcher (г. Дивногорск) и timofiozi (г. Москва).

Фирменные футболка и бейсболка Dr.Web, скрывавшиеся на аукционе под наименованием «Кот в мешке», достаются М...ч (г. Тобольск).

Полный перечень победителей – как обычно, в таблице ниже. Мы искренне рады за всех, чье имя в ней присутствует, – и желаем дальнейших успехов!

Псевдоним Ставка (баллы) Ставка (Dr.Web-ки)
Смартфон Sony Xperia M с лицензий Dr.Web Mobile Security на 1 год
amonn2760.502440
Электронная книга Prestigio MultiReader 3664
lexy1727.001499
Игровая клавиатура Mad Catz S.T.R.I.K.E.7
Snegger769.00413
Мышь A4 Tеch X 710
Elenusik50.0020
SSahapov600.00250
Таулан40.0021
Видеоигра Grand Theft Auto V
Nike948.00773
Soulcatcher109.0089
timofiozi40.0013
Кот в мешке
М...ч1362.002330
Dr.Web Security Space 1 ПК/Mac + 1 моб. устройство на 1 год
mr.dsa1262.001180
loki1022.001040
Е...ч1270.50842
Pikar1090.00798
DFoul1392.50811
softscamehater862.00562
mytant728.00620
Van_Helsing516.00899
А...ч1200.00700
xilyt1512.00600
Внешний жесткий диск 1 Тб
tosya2762.502268
Ключница
DoC116.5086
AThousandDolphins300.00300
Е...ч1182.00767
Портмоне кожаное
daniil778.00526
Кружка-хамелеон
К...ч300.00250
W1nd505.00308
BES62.50405
Ш...а265.0070
arturik200.00150
Н...м211.00135
Г...ч251.0033
visasus207.00205
™НаТаЛьЯ™220.0050
magrul300.0030
Часы настенные
max555.55555
Лицензия для школы на 1 год (защита рабочих станций и файловых серверов)
Absolut668.50200



В избранное