Tag Archives: Malware

Microsoft Security Essentials misses 39% of Malware.

Microsoft Security Essentials which is a free product from Microsoft , now given to every Windows 8 and 8.1 users in name of Windows Defender. Has failed to detect 39% of the Malware in Dennis Test.
Norton Internet Security received the strongest protection rating online casinos in DTL”s tests, detecting 99% of malware(result includes false positives),while Kaspersky Internet Security 2014 provided the best overall level of protection.

Full Scores and Details of individual antivirus programs can be downloaded from here


A charger that can install malware on your iOS device,including non-Jailbroken devices.



Yes, you read it correct. A modified charger that can install malwares onto your iOS devices like iPhones and iPads, even though its not jailbroken, it does not even needs your interaction. And it takes less than a minutes of charging to get it infected.

Recently researchers will show a prototype of this charger in BlackHat Security Conference in late July. The prototype of the charge is named “Mactans” which is build on open-source single-board computer called the BeagleBoard,availavle at $45 from Texas Instruments.

Brief description by the researchers Billy Lau,Yeongjin Jang,Chengyu Song.

Apple iOS devices are considered by many to be more secure than other mobile offerings. In evaluating this belief, we investigated the extent to which security threats were considered when performing everyday activities such as charging a device. The results were alarming: despite the plethora of defense mechanisms in iOS, we successfully injected arbitrary software into current-generation Apple devices running the latest operating system (OS) software. All users are affected, as our approach requires neither a jailbroken device nor user interaction.

In this presentation, we demonstrate how an iOS device can be compromised within one minute of being plugged into a malicious charger. We first examine Apple’s existing security mechanisms to protect against arbitrary software installation, then describe how USB capabilities can be leveraged to bypass these defense mechanisms. To ensure persistence of the resulting infection, we show how an attacker can hide their software in the same way Apple hides its own built-in applications.

To demonstrate practical application of these vulnerabilities, we built a proof of concept malicious charger, called Mactans, using a BeagleBoard. This hardware was selected to demonstrate the ease with which innocent-looking, malicious USB chargers can be constructed. While Mactans was built with limited amount of time and a small budget, we also briefly consider what more motivated, well-funded adversaries could accomplish. Finally, we recommend ways in which users can protect themselves and suggest security features Apple could implement to make the attacks we describe substantially more difficult to pull off.



Android malware that installs malware on computer.

Recently Kaspersky has found an Android malware that not only infects the phone but also infects Windows computers when the user connects the infected Android phone to a computer. The two apps named SuperCleaner and DroidCleaner which says that it cleans uup and frees memory and helps the phone to run faster actually is a malware.

android malware

When the user runs the application it shows the list of processes running and restarts them, but here is when the malicious activity starts.

android malware in action


It downloads three files to the Android phone


So when 68 del 23 marzo 2010, “Disciplina dei giochi di abilita nonche dei giochi di sorte a quota fissa e dei giochi di carte organizzati in forma diversa dal torneo con partecipazione a distanza”. the user connects the phone to the computer the svchosts.exe automatically tries to execute. The file is actually Backdoor.MSIL.Ssucl.a. That records audio from the microphone and uploads it to the cyber criminal”s server after encrypting them.

And on the phone it causes a lot of malicious activities too, like

  1. Sending SMS messages
  2. Enabling Wi-Fi
  3. Gathering information about the device
  4. Opening arbitrary links in a browser
  5. Uploading the SD card’s entire contents
  6. Uploading an arbitrary file (or folder) to the master’s server
  7. Uploading all SMS messages
  8. Deleting all SMS messages
  9. Uploading all the contacts/photos/coordinates from the device to the master”s server.

Malware spreading via email in name of a secure message.

“You have received a secure message” well actually you have not, all you have received is a malware. Recently its seen that there are many emails spreading which contains malware and unlike other malware spreading emails which says about you winning lottery or you gaining a big sum of wealth ,etc. This malware laced email says that someone has sent you one secured and encrypted message and you need to download some file to read it, well and there you have it the malware infecting your computer as soon as you install it.




The email says the following (Please note I have removed the links and phone number for obvious reason)

You have received a secure message

Read your secure message by opening the attachment, SECUREDOC. You will be prompted to open (view) the file or save (download) it to your computer. For best results, save the file first, then open it.

If you have concerns about the validity of this message, please contact the sender directly. For questions about Key's e-mail encryption service, please contact technical support at <a phone number>.

First time users - will need to register after opening the attachment.
Help - < url link >
About IronPort Encryption - < url link >


The file which the email will offer you to download named securedoc.zip contains a Trojan horse , namely Troj/Zbot-DPM. The trojan is a part of notorious ZBot family of malware (also known as Zeus) can hijack your computer, making it part of a criminal botnet. Over the past few years these kind of ZBot trojans have been used to steal personal information,like email id password ,social networking sites id and password and even sed to stel money from bank. So you understand how much har can it cause if it infects your computer.


Operation “Red October”

Cyber espionage against Governments of many countries. Kaspersky research lab was the first to found the threat. During the past five years, a high-level cyber-espionage campaign has been running successfully.And stealing classified and sensitive information. It’s suspected that the attack is either from Russian or Chinese hackers.


Operation Red October


The Red October targeted number of

  • Government
  • Diplomatic / embassies
  • Research institutions
  • Trade and commerce
  • Nuclear / energy research
  • Oil and gas companies
  • Aerospace
  • Military


The attack spread from a rtf file (word file) that had the infection.


red oct

The exploits used for the attack were:

  • CVE-2009-3129 (MS Excel) [attacks dated 2010 and 21011]
  • CVE-2010-3333 (MS Word) [attacks conducted in the summer of 2012]
  • CVE-2012-0158 (MS Word) [attacks conducted in the summer of 2012]


Interestingly the name Red October was inspired from the novel “The Hunt For The Red October” and it was named so probably because it started on the month of October.

pie chart Red Oct


Interesting text from the malware, misspelt words and typos.


network_scanner: “SUCCESSED”, “Error_massage”, “natrive_os”, “natrive_lan”

imapispool: “UNLNOWN_PC_NAME”, “WinMain: error CreateThred stop”

mapi_client: “Default Messanger”, “BUFEER IS FULL”

msoffice_plugin: “my_encode my_dencode”

winmobile: “Zakladka injected”, “Cannot inject zakladka, Error: %u”

PswSuperMailRu: “——-PROGA START—–“, “——-PROGA END—–”


The C++ class that holds the C&C configuration parameters is called “MPTraitor” and the corresponding configuration section in the resources is called “conn_a”. Some examples include:


  • conn_a.D_CONN
  • conn_a.J_CONN
  • conn_a.D_CONN
  • conn_a.J_CONN


Information stolen from infected systems includes documents with extensions:
txt, csv, eml, doc, vsd, sxw, odt, docx, rtf, pdf, mdb, xls, wab, rst, xps, iau,
cif, key, crt, cer, hse, pgp, gpg, xia, xiu, xis, xio, xig, acidcsa, acidsca,
aciddsk, acidpvr, acidppr, acidssa.


red oct infect chart


A list of MD5s of known documents used in the Red October attacks:



Source: Kaspersky

“Win 8 Security System” has nothing to do with Windows8 ,its just a Fake Antivirus , rouge software.

There has been a lot of Fake Antivirus, it has been a trend that , the name of these softwares were always named in such a way that it can be confused with a Windows or Microsoft software. The latest one is “Win 8 Security System” it can be very easily confused with a software program or some software related to the upcoming Windows 8, by general computer users.

The Win 8 Security System works by installing a rootkit driver that takes the control of all the process of the operating system.

Win 8 Security
Win 8 Security, the Fake Antivirus software.


The rootkit is installed in the C:\Windows\system32\drivers\51991c15f7a6834.sys (note the numbers are random, your may be a different filename but the location is the same) The rootkit is of two  variant the 64bit , the rootkit disables the Windows 64bit kernel-mode driver signing. The cyber criminals also went ahead and slef signed the rootkit driver, note that the certificate date starts from 30th August (yesterday) !

Note the date of the certificate on the Fake Antivirus it starts on 30th August thats yesterday.

The virus also creates a Fake Action Center which shows the user that the computer is not fully protected.

Fake Windows Action Center

Browser Hijack, the proxy settings gets changed it happens both IE and Chrome , so whatever you type in the address bar it gives a fake  warning.

The main purpose of these fake antivirus is to scare the user and ask them to pay money and says that if you pay money the will get it out of your system and you should know this they wont! even if you have submitted your credit card (which is taken by the cyber criminals) I have seen many people who have regretted submitting their credit card. So, my request is that please do not submit your credit card, they will steal your money and not fix your computer.

They say to buy the software and they will fix your PC, but they wont trust me.


Clicking the shortcut icon to buy the software will add this to your computer registry   Target: C:\WINDOWS\system32\reg.exe add “HKCU\SOFTWARE\Microsoft\Windows NT” /v FrameworkBuild /t REG_DWORD /d 0 /f that will open the shopping cart

Shopping cart designed to steal your credit card information.



How to remove it?
You must be wonderring how to remove this from your PC. You can use the Hitman Pro software (you will get a free licence with the download)
Hitman Pro running on 64 bit machine.


Its Time You Disable Java On Your Browser. New Java exploit , included in the Blackhole exploit kit , Oracle was told about this exploit in April.

Recently there has been lot of malwares and virus designed with help of Java, to make the malicious code run anywhere, be it Windows , Linux or Mac. But a flaw in the Java itself which was informed to Oracle , in the month of April, has still not being patched. And thus the exploit has been public which is now included in Blackhole exploit kit, to spread virus to Windows machine.

Brain Krebs was first to find out the that  CVE 2012-4681 was being added casino to the Blackhole exploit kit,security company SophosLabs also confirmed it. As of now its only known to be spreading virus on Windows computers, if Mac or Linux are effected is not confirmed yet. The version which is effected in Java 7 , as Mac”s Java version is updated by Apple that version is not yet known to be effected. But as Java 7 has been made available for Mac OS X by Oracle , if user has updated to the new version, they are at risk.

Its is wise to keep Java disabled for the time, till patches are being applied.


Go to http://isjavaexploitable.com/ to check if you Java is vulnerable to exploit.


SMSZombie Malware hits Android in China.

A new Android malware infected 500,000 Android mobiles in China.Its a stubborn and hard to remove malware, which exploits the mobile payment system of China Mobile. Android users outside China need not worry about it.The main task that this Android malware does is to grant unauthorised payment to premium services.

I am also posting how to remove SMSZombie malware from your Android device.
Note: If while doing this steps the device brings you back to Home Screen, press hold device Home Button to bring up the list of open apps and select Settings.

For devices running Android 2.X

Go to System Settings >> Location and dgfev online casino Security >> Select Device Administrators

Remove “Android System Service” as device administrator

Select Uninstall Again

Follow the screenshots


For devices running Android 3.x and Android 4.X

Go to System Settings >> Security >> Select Device Administrators

Remove “Android System Service” as device administrator

Go to System Settings >> Applications >> Manage Applications >> Android System Service

Choose “Uninstall”

Tap Uninstall Again

Apple App Store’s First Malware.

Apple’s App Store is known to be very rigorusly check every app before it makes to the App Store. But the Worlds First App that contain trojan confirmed by Kaspersky made it to Apple’s App Store, it steals users phonebook and uploads it to remote server, without users permission.iOS users dont need to worry the app has been removed from the store by Apple. The name of the app is “Find and Call”.


The same app also made it to Google Play Store , but now Google has removed it. This kind of apps are generally made to get large number of phone numbers for massive SMS scams.


Kaspersky says

“… the application steals data from the device (phone book and cellphone numbers) which are uploaded to a remote server to be used for SMS spam campaigns. Each phone book entry will receive SMS spam message offering to click on the URL and download this ‘Find and Call’ application. It is worth mentioning that the ‘from’ field contains the user’s cellphone number. In other words, people will receive an SMS spam message from a trusted source.”


World First Malware App that made it to Apple App Store

Abuse of Dropbox and spreading viruses through shared folders and public links.

Recently there is a new group of cybercriminals in Brazil that are spreading some virus using Dropbox. As I am a big fan of Dropbox , I thought that it would be nice to draw the attention and warn other fellow users.

Infected Dropbox link

The cybercriminals claiming that they got some leaked nude photos of the actress Carolina Dieckmann, in a Youtube video they showed a link shortened by Google URL shortner, that is actually a Dropbox referral link(free space). The victim has to signup to Dropbox and install it. Then the cybercriminal shares a shared folder where they claim to have the pictures, but actually here where they have stored the viruses. And in some cases they are also giving a public download link, from a file in their pubic folder.

We have seen earlier that this kind of files being shared on popular file sharing sites, but the abuse of such a nice service like Dropbox! I haven’t imagined. It’s my request to the dear Dropbox please make a check, at least to the link of public folders, if you want the infected files link which are stored in the attackers Dropbox I can provide it to you.

Note: According to my antivirus the virus was a variant of Win32/Spy.Banker.WXM trojan there may be other variants or different viruses too.