Translate

Posts mit dem Label Trojan werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Trojan werden angezeigt. Alle Posts anzeigen

2/01/2014

NEW MALWARE CODE:
Trojan.NSIS.StartPage.ed (CHINA)
MALICIOUS DOWNLOADS Domain:
keaitz.com


MALICIOUS SITE: (Nullsoft Scriptable Install System FROM: CHINA)


DOMAIN:
keaitz.com
  • https://www.virustotal.com/de/url/9b81a505362c1aab403292563a9360f72e8e076fd83794ef36faeb29181ebdf2/analysis/1391274035/
1390472709.keaitz.com
  • https://www.virustotal.com/de/url/d3940fe84e654ea2d17c7d219ae53ca86be9b66d1474683ae0596ed5c8d57f8c/analysis/1391272982/
  • https://www.virustotal.com/de/file/a77b681a6138fdcc50c8be703ee1637fc60f1f90a47f6ba09b1539371ac6f60e/analysis/1391272594/


SPECIFIC LINK:
1390472709.keaitz.com/chat/raffle/raffl.exe
  • https://www.virustotal.com/de/url/510a6e03aa6c4b786a33d25f7d48d2b0c76d16726e2efa83b531137b09fb5651/analysis/1391272314/


INFECTED WITH: Trojan.NSIS.StartPage.ed
  • https://www.virustotal.com/de/file/cb99213503ed1f23bdcca1ef9b95ac1b423036dba3e5f8bbd68743b7dcdb98fe/analysis/

SEE ALSO:
  • http://app.webinspector.com/public/reports/19839594
  • http://zulu.zscaler.com/submission/show/b57c16e6dd5a128c923b1b0555949636-1391272426
  • http://anubis.iseclab.org/?action=result&task_id=1f72b554221efb114f53fcb4a82d166f0&format=html
  • http://www.urlvoid.com/scan/1390472709.keaitz.com/

SCREENSHOT OF DOMAIN (403)

FOR MORE INFO ON THIS THREAT, SEE:


12/14/2013

Security Breach: Former French First Lady Carla Bruni Nude Pictures
allow hackers into G20 delegates' computers

Nude pictures of former French first lady Carla Bruni were used to break into the computer systems of dozens of diplomats. The shocking security breach was first discovered at the G20 summit in Paris in February 2011 and may be ongoing.


                                          Carla Bruni & Sarkozy     Photo: AP
“To see naked pictures of Carla Bruni click here” said a message sent to those attending, zhat included finance ministers and central bank representatives.

Bruni, a former supermodel who became President Nicolas Sarkozy’s third wife in 2008, was well known for taking her clothes off in her early career. This prompted many to open an attachment which turned out to be a ‘Trojan’ with an embedded virus, although all recipients could see were the X-rated photographs.

                                                                     Reuters
Once accessed, the Malware infected the computers of senior officials as well as forwarding the offensive email on to other numbers stored on device.

“Almost everybody who received the email took the bait,” said a government source in Paris, saying that this included representatives from the Czech Republic, Portugal, Bulgaria, Hungary and Latvia.

Sarkozy was first embarrassed by nude pictures of Bruni surfacing shortly after their marriage, while they were staying with the Queen at Windsor Castle during a state visit to Britain. (e.g. ROFL)

Bruni, who still uses her maiden name in her career as a pop singer, later changed her image from a Paris sex kitten into a unassuming politician’s wife. The so-called phishing attacks are thought to have originated in China and were aimed at extracting information.

The attacks are still being investigated, and nobody is yet sure what information was distilled.

The United States is thought to have been the main target of the scam.

The cyber attack on the Paris G20 summit took place before the 6th G20 summit in Cannes, in the south of France, which involved big heads of governments. There have been a number of similar attacks in France, leading the country to be proactive in cyber defence.

                         Getty Images
A recent White Paper on Defence and National Security proclaimed cyber attacks as “one of the main threats to the national territory” and “made prevention and reaction to cyber attacks a major priority in the organisation of national security”.

This led to the creation of the French Agency for National Security of Information Systems in 2009. Nicolas Sarkozy, a conservative, lost the presidential election to the Socialist Francois Hollande in 2012 and is now dealing with a range of corruption charges.

11/24/2013

Category MALICIOUS IP: 80.92.67.155
(Trojan) Heuristic.BehavesLike.Win32.Suspicious.H

The IP Address 80.92.67.155 (IP LOCATIONLuxemburg) is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy and/or some other form of botnet. Specific Malware that has been Found: Heuristic.BehavesLike.Win32.Suspicious.H . This Malicious File stood under communication with the Malicious IP. See 80.92.67.155 IP address information at VT for additional information.

Last detection: 20/11/2013 @ CBL

IP 80.92.67.155 is also listed at Spamhaus.org
IP 80.92.67.155 has 66 Bad Host appearances in Spam E-mail or Spam Post URLs

Other information on this IP:


Other Remarkable Detections on this IP:



SCREENSHOT




RELATED POST: Symantec: Blackshades Remote Access Tool still being bargained

11/09/2013

Trojan: J2ME_FAKEBROWS.A

J2ME_FAKEBROWS.A (FAKE BROWSER)

This Trojan Uses social engineering methods to lure users into performing certain actions that may, directly or indirectly, cause malicious routines to be performed on System or, specifically, disguises as a mobile Web browser Opera Mini. Once the user agreed with the services of the "fake" browser, it sends SMS messages to selected premium numbers.

This Trojan finds itself in the Wild.


      

For further Details on this Threat, visit:
about-threats.trendmicro.com