Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

failed installation

QxSearch hijacker fakes failed installs

Malwarebytes Labs
https://blog.malwarebytes.com/pups/2019/08/qxsearch-hijacker-fakes-failed-installs/

APT trends report Q2 2019

https://securelist.com/apt-trends-report-q2-2019/91897/

In April, we published our report on TajMahal, a previously unknown APT framework that has been active for the last five years. This is a highly sophisticated spyware framework that includes backdoors, loaders, orchestrators, C2 communicators, audio recorders, keyloggers, screen and webcam grabbers, documents, and cryptography key stealers; and even its own file indexer for the victim’s computer. We discovered up to 80 malicious modules stored in its encrypted Virtual File System – one of the highest numbers of plugins we have ever seen in an APT toolset. The malware features its own indexer, emergency C2s, the ability to steal specific files from external drives when they become available again, and much more. There are two different packages, self-named ‘Tokyo’ and ‘Yokohama’ and the targeted computers we found include both packages. We think the attackers used Tokyo as the first stage infection, deploying the fully functional Yokohama package on interesting victims, and then leaving Tokyo in place for backup purposes. So far, our telemetry has revealed just a single victim, a diplomatic body from a country in Central Asia. This begs the question, why go to all that trouble for just one victim? We think there may be other victims that we haven’t found yet. This theory is supported by the fact that we couldn’t see how one of the files in the VFS was used by the malware, opening the door to the possibility of additional versions of the malware that have yet to be detected.

Exploit kits review

https://blog.malwarebytes.com/threat-analysis/2019/07/exploit-kits-summer-2019-review/

Threat actors continue to buy traffic from ad networks and use malvertising as their primary delivery method. Leveraging user profiling (their browser type and version, country of origin, etc.) from ad platforms, criminals are able to maintain decent load rates (successful infection per drive-by attempts).


Today's Look For:

Any of instance of this User-Agents:
- Microsoft BITS/7.5 
   
rundll32.exe, shell32.dll, OpenAs_RunDLL

Turla renews its arsenal with Topinambour

https://securelist.com/turla-renews-its-arsenal-with-topinambour/91687/

Iran has its turn in limelight

A Mystery Agent Is Doxing Iran's Hackers and Dumping Their Code
https://www.wired.com/story/iran-hackers-oilrig-read-my-lips

Cyber Criminals Target Kodi Media Player For Malware Distribution

https://packetstormsecurity.com/news/view/29344/Cyber-Criminals-Target-Kodi-Media-Player-For-Malware-Distribution.html

RaaS

Russian Hacker Creates Starter Pack Ransomware Service https://packetstormsecurity.com/news/view/27685/Russian-Hacker-Creates-Starter-Pack-Ransomware-Service.html

Analyze Embedded PDF file

https://blog.didierstevens.com/2017/04/20/malicious-documents-the-matryoshka-edition/

Shoney's announces breach

http://www.ibtimes.co.uk/shoneys-restaurants-hit-pos-malware-customers-card-details-compromised-months-1617409

Citadel owner pleads guilty

Russian mastermind of $500m bank-raiding Citadel coughs to crimes

http://www.theregister.co.uk/2017/03/22/russian_citadel_malware_pleads_guilty/

Rootkit Tricks

a few links:
https://msdn.microsoft.com/en-us/library/windows/desktop/ms682489(v=vs.85).aspx
http://stackoverflow.com/questions/4021307/enumprocesses-vs-createtoolhelp32snapshot
https://books.google.com/books?id=ifQPC86G66sC&pg=PA437&lpg=PA437&dq=CreateToolhelp32Snapshot()
https://msdn.microsoft.com/en-us/library/windows/desktop/ms682631(v=vs.85).aspx



A few other windows things:
https://msdn.microsoft.com/en-us/library/windows/desktop/ms724947(v=vs.85).aspx
https://msdn.microsoft.com/en-us/library/windows/desktop/ms646293(v=vs.85).aspx

Introduction to Malware Analysis

introduction to Malware Analysis by  Lenny Zeltser

https://vimeo.com/9474345

SpyEye creators arrested

http://thehackernews.com/2016/04/spyeye-banking-trojan.html