Posts mit dem Label malware werden angezeigt. Alle Posts anzeigen
Posts mit dem Label malware werden angezeigt. Alle Posts anzeigen

Mittwoch, 29. August 2012

BKA-Trojaner geht um

Da sich in meinem Freundes- und Bekanntenkreis die Meldungen zu häufen beginnen, habe ich den Eindruck, dass die neueste Version des BKA-Trojaners virulenter als die bisherigen ist. Leider können oder wollen die Betroffenen nicht genau sagen, welche Seiten sie in der letzen Zeit angesteuert haben, aber es scheint mir unabhängig davon ein guter Rat, sich über die möglichen Konsequenzen im Klaren zu sein, wenn man tonganische Kinoplattformen ansteuert. Rechtlich mag man vielleicht noch einigermaßen sicher sein, aber selbst wenn man die dort lauernden Abofallen noch einigermaßen umgangen bekommt, traue ich persönlich dem Seitencode nicht weiter als ich dessen Entwickler werfen könnte.

Damit es auch der Letzte gelesen hat: Schutzgelderpressung gehört nicht zum Geschäftsmodell des BKA. Wir wissen zwar, dass deutsche Ermittlungsdienste mitunter ein sehr entspanntes Verhältnis zu Menschen- und Bürgerrechten pflegen, aber das Infizieren eines Privatrechners mit einer Software, die den gesamten Systemzugang sperrt verstößt so offensichtlich gegen so viele Gesetze gleichzeitig, dass eine auf positive Außenwirkung bedachte Behörde wie das BKA nicht auf solche Mittel zurückgriffe. Auch die GVU, die GEZ oder die GEMA, die schon längst jeden Versuch aufgegeben haben, ihre Geisteshaltung zu beschönigen, dürften nicht auf diese Weise Geld eintreiben. Davon abgesehen böte jede dieser Einrichtungen nicht-anonyme Zahlungsmethoden an.

Ich frage mich zweierlei: Was treiben einige Leute mit ihren Rechnern, wenn sie Meldungen wie diese ernst nehmen? Vor allem aber: Wie schlecht muss der Leumund dieser Institutionen sein, dass man ihnen solche klar widerrechtlichen Methoden zutraut?

Wer den Kram übrigens wieder loswerden will: https://www.botfrei.de/rescuecd.html und zwei bis drei Stunden sollten ausreichen. Sicherheitsexperten mögen sich angesichts der vollautomatischen Vorgehensweise der Software auf dieser CD die Nackenhaare sträuben, aber ich interessiere mich für Lösungen, die ich einem Laien in die Hand drücken kann. Sollte wider Erwarten die CD das System zerschießen, lernen die Betroffenen vielleicht endlich die zwei wichtigsten Regeln der Computerbenutzung: Wenn ihr nur einen Bruchteil der Zeit, die ihr auf Schmuddelseiten verbringt, zur Absicherung eures Systems aufwendet, kann euch nichts passieren. Zweitens: Legt euch endlich Backups an.

Freitag, 19. Februar 2010

Yahoo virus scan for attachments still brittle

The best malware scanner exists between keyboard and chair - I hope so at least. As I wrote some weeks ago, Yahoo has serious trouble with their virus scanner that automatically scans all attachments before being allowed for download. In general, I think this mechanism is quite a good idea - as long as it does what it is supposed to to. Instead, I got the impression that Yahoo's scanner is not much more than a window that automatically pops up when you press the "download attachment" button, telling you that everything is all right and thus giving you a good feeling. The sad thing is that feeling well is not much worth in security. Either a piece of software is dangerous or not - regardless what you feel.

That's what I thought when today I received this mail:

Your order has been paid! Parcel NR.4178.
Freitag, den 19. Februar 2010, 20:59:33 Uhr
Von:
Amazon Support Janette Akins
An: (erased)


Postal_package_NR624.zip (44KB)
Hello!

Thank you for shopping at Amazon.com
We have successfully received your payment.

Your order has been shipped to your billing address.
You have ordered " HP W2338H "

You can find your tracking number in attached to the e-mail document.
Print the postal label to get your package.


We hope you enjoy your order!
Amazon.com

The thing was quite clear in my eyes. I am no Amazon customer, and the mail wasn't even addressed to me. Of course, I didn't expect Yahoo to relieve the attachment's true nature, but I thought that the usual virus scanners should raise an alert.

Dr Web didn't.

Neither did Antivir, Avast, AVG and several famous antivirus laboratories. When I scanned the file at 20 h GMT, only 7 out of 41 scanners were able to detect the malicious content.

This quite puzzles me, I didn't think that the big players react that slowly.

http://www.virustotal.com/analisis/92264ce207d1a341469e4c191d1a4eb093776f9ad236855ebe4d534e8da43cfb-1266605153

Mittwoch, 13. Januar 2010

Malware attachement not detected by Yahoo scanner

This mail just arrived in my Yahoo account:

UPS Tracking Number 5600012.
Mittwoch, den 13. Januar 2010, 17:59:28 Uhr
Von:
UPS Manager Merlin Villarreal
An:




UPS_invoice_NR67974.zip (27KB)

Hello!

The courier company was not able to deliver your parcel by your address.
Cause: Error in shipping address.

You may pickup the parcel at our post office personaly!

Please attention!
The shipping label is attached to this e-mail.
Please print this label to get this package at our post office.


Please do not reply to this e-mail, it is an unmonitored mailbox.



Thank you.
United Parcel Service of America.

Although it was obvious for me that there must be something wrong with this mail (my address was not in the "to:" field, I don't use my Yahoo address for shipping issues and I've never been in contact with UPS before), I was surprised that the automatic Yahoo attachment scanner did not raise an alert. So I first entered the mail body in Google and found this article. Wait a minute, this article was written in October 2009, nearly 3 months ago. I clicked some other addresses that were shown by Google and found that this malware is broadcasted since August 2009, more than enough time for Yahoo to adapt its signatures. Maybe the malware has already been deleted without Yahoo telling me. So I decided to download the attachment onto my Linux box:

c0274669838712565b1ff5f36a5e8886 UPS_invoice_NR67974.zip

Yahoo still did not complain. So let's see what's in the Zip file:

Archive: UPS_invoice_NR67974.zip
End-of-central-directory signature not found. Either this file is not a zipfile, or it constitutes one disk of a multi-part archive. In the latter case the central directory and zipfile comment will be found on the last disk(s) of this archive.
unzip: cannot find zipfile directory in one of UPS_invoice_NR67974.zip or
UPS_invoice_NR67974.zip.zip, and cannot find UPS_invoice_NR67974.zip.ZIP, period.

Ah, this looks much more like I expected. If it's not a Zip, what is it?

UPS_invoice_NR67974.zip: RAR archive data, v1d, os: Win32

And unpacking this file revealed

2149ae56fffb57b17b55221c8922db96 UPS_invoice_NR67974.exe

An online malware check with Virustotal returned this result. What strikes me most, is that only 20% of the scanners used by this site were able to detect the malware.

Today's lesson: Don't trust your antivirus software too much. The best antivirus program is worth nothing if you don't use your brain. Keep your eyes open even if your system says that there's no need.

Update: Yahoo's scanner still does not recognize attached malware. I just received this message:

UPS Tracking Number 2527010.

Dienstag, den 19. Januar 2010, 16:31:07 Uhr
Von:
UPS Manager Wilson Akins
An:




UPS_invoice _Nr78155.zip (43KB)

Dear customer!

The courier company was not able to deliver your parcel by your address.
Cause: Error in shipping address.

You may pickup the parcel at our post office personaly!

Please attention!
The shipping label is attached to this e-mail.
Please print this label to get this package at our post office.

Please do not reply to this e-mail, it is an unmonitored mailbox.

Thank you.
United Parcel Service.


Again, Yahoo's scanner did not complain. This time an attachmend with this MD5 sum slipped through:

f44d4410401a43380077a0bf769fa49c UPS_invoice _Nr78155.zip


Virustotal thinks differently about this, although only 6 out of 41 raised an alert. Kaspersky detected Packed.Win32.Krap.w.

I wouldn't make such a fuss about it, if it weren't that obvious that these files are infected. I would expect every common scanner to find the malicious content.

Second update:

MD5 sum:

dc4a1e661cab4b9b062d78b5c4efd989 DHL_Label _Nr34791.zip

contains:

28d798d6021e600101ba68ea87345656 DHL_Label _Nr34791.exe

Zip file has been uploaded to different online malware scanners and returned these results:

Yahoo is informed and shows no reaction. Come on guys, is it really that difficult? I know it's a free service, but does this mean they have to be exposed to malware. Think about it, you're not only putting in danger your non-paying customers, but all the people they have contact with. Is it that what you want?

Third update:

Md5 sum:

0369b2f18a421c9b7a6939ebca4ce575 UPS_invoice_NR45675.zip

Yahoo scores 0:4. Hopefully the paying customers get a better service.

Fourth update:

MD5 sum:

e0c80f8b6b859b4aa19937384931a91b UPS_invoice_Nr19373.zip

  • Kaspersky is currently working on their scanner page, so this service is not available right now.
  • Dr Web runs into timeout.
  • Did anyone ever succed in sending a file to Jotti? I keep trying this for weeks, but I always get stuck after pressing the "send" button.
Anyhow, the case is clear: Yahoo has a security hole, knows about it and couldn't care less.

I don't know what song Yahoo's security guys like best, but it's not "She works hard for her money".