Showing posts with label Virus. Show all posts
Showing posts with label Virus. Show all posts

December 13, 2011

Adobe warns of Virus Attacks on Windows


Hackers are exploiting a previously unknown flaw in Reader to attack computers running Windows, Adobe said.
A patch for the critical vulnerability in Reader and Acrobat is expected by next week, the company said in a blog post.
The vulnerability, which is being exploited in "limited, targeted attacks in the wild against Adobe Reader 9.x on Windows," could allow an attacker to take control of the system, Adobe said.
Adobe is finalizing a fix and expects to release an update for Reader and Acrobat 9.x for Windows no later than the week of December 12, according to an Adobe advisory.
"Because Adobe Reader X Protected Mode and Adobe Acrobat X Protected View would prevent an exploit of this kind from executing, we are currently planning to address this issue in Adobe Reader X and Acrobat X for Windows with the next quarterly security update for Adobe Reader and Acrobat, currently scheduled for January 10, 2012," the company said. "We are planning to address this issue in Adobe Reader and Acrobat X and earlier versions for Macintosh as part of the next quarterly update scheduled for January 10, 2012. An update to address this issue in Adobe Reader 9.x for UNIX is planned for January 10, 2012."
The issue does not affect Adobe Reader for Android and Adobe Flash Player.
Adobe's advisory credited Lockheed Martin and members of the Defense Security Information Exchange with reporting the issue. Lockheed spokeswoman Jennifer Whitlow told Reuters that the problem was identified through the company's normal monitoring activities but that the company had not been penetrated in the attempted attack. The defense contractor was targeted in an attack earlier this year believed to be related to a breach at SecurID token maker RSA.

December 12, 2011

What is Duqu Virus - How to Secure computer from Duqu Virus

Symantec Corporation has reported that they have discovered a new virus ‘Duqu’. In the initial investigation it has been found that this virus has been installed on computer using Microsoft Word Document files.Thus far, no-one had been able to recover the installer for the threat and therefore no-one had any idea how Duqu was initially infecting systems. Fortunately, an installer has recently been recovered due to the great work done by the team at CrySyS.

The installer file is a Microsoft Word document (.doc) that exploits a previously unknown kernel vulnerability that allows code execution. We contacted Microsoft regarding the vulnerability and they're working diligently towards issuing a patch and advisory. When the file is opened, malicious code executes and installs the main Duqu binaries. The chart below explains how the exploit in the Word document file eventually leads to the installation of Duqu.

Figure 1: Duqu infection schematics.
The Word document was crafted in such a way as to definitively target the intended receiving organization. Furthermore, the shell-code ensured that Duqu would only be installed during an eight-day window in August. Please note that this installer is the only installer to have been recovered at the time of writing—the attackers may have used other methods of infection in different organizations. Unfortunately, no robust workarounds exist at this time other than following best practices, such as avoiding documents from unknown parties and utilizing alternative software. Fortunately, most security vendors already detect and block the main Duqu files, thereby preventing the attack.
Once Duqu is able to get a foothold in an organization through the zero-day exploit, the attackers can command it to spread to other computers. In one organization, evidence was found that showed the attackers commanding Duqu to spread across SMB shares. Interestingly though, some of the newly infected computers did not have the ability to connect to the Internet and thereby the command-and-control (C&C) server. The Duqu configuration files on these computers were instead configured not to communicate directly with the C&C server, but to use a file-sharing C&C protocol with another compromised computer that had the ability to connect to the C&C server. Consequently, Duqu creates a bridge between the network's internal servers and the C&C server. This allowed the attackers to access Duqu infections in secure zones with the help of computers outside the secure zone being used as proxies.
While the number of confirmed Duqu infections is still limited, using the above techniques we have seen Duqu spread across several countries. At the time of writing, Duqu infections have been confirmed in six possible organizations in eight countries.
The confirmed six possible organizations and their countries of presence include:
•    Organization A - France, Netherlands, Switzerland, Ukraine
•    Organization B - India
•    Organization C - Iran
•    Organization D - Iran
•    Organization E - Sudan
•    Organization F - Vietnam
Note that some organizations are only traceable back to an ISP and therefore all six may not be separate organizations. Furthermore, due to grouping by IP addresses, we cannot definitively identify the organizations.
Other security vendors have reported infections in the following countries:
•    Austria
•    Hungary
•    Indonesia
•    United Kingdom
•    Iran - infections different from those observed by Symantec



Figure 2: Countries with reported Duqu infections. 
Finally, whilst all of the recovered samples are very closely related, we have recently recovered a sample that communicates with a different C&C server. All previously analyzed samples were configured to contact a server hosted in India. This particular Duqu file was configured to communicate with a server in Belgium with the IP address '77.241.93.160'. The server has since been taken offline. We appreciate the cooperation from the hosting provider in taking action immediately after being contacted.
We have shared information and samples with other security vendors so that they can verify protection accordingly.
Key updates in the Symantec whitepaper include:
•    An unpatched zero-day vulnerability is exploited through a Microsoft Word document and installs Duqu
•    Attackers can spread Duqu to computers in secure zones and control them through a peer-to-peer C&C protocol
•    Six possible organizations in eight countries have confirmed infections
•    A new C&C server (77.241.93.160) hosted in Belgium was discovered and has been shut down
We want to thank CrySyS for their continued cooperation and research.

Final Update: Microsoft has issued the following advisory and provided a workaround for the zero-day vulnerability identified as one Duqu infection vector:

November 23, 2011

Fake "VIRUS ALERT" !

Fake Virus Alerts Floating in the Web 


Sophos is warning office workers about an unusual twist on virus alert tactic on the people. The emails warn of recent incidents of corporate data theft 7 instruct users to click on a link which is of course the actual malware payload.

DMCA.com The Techbay | All Rights Reserved.

Designed by "mintJelly"