Translate

Posts mit dem Label Malicious Threat werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Malicious Threat werden angezeigt. Alle Posts anzeigen

12/11/2013

New Malware: escrituras.com - Trojan-Spy.HTML.Fraud.iz

NEW MALWARE:

Trojan-Spy.HTML.Fraud.iz

DOMAIN: escrituras.com

https://www.virustotal.com/de/url/023bdad1bf212b69fc38f942d94a10605e3586e9c13bae9fab12eef580d48f62/analysis/1386595660/

Trojan-Spy.HTML.Fraud.iz

https://www.virustotal.com/de/file/e5a2cf61957340d4e0f991a6df9819636110d687856eae56c54d88ec6b21b86d/analysis/


IP: 200.98.247.12

https://www.virustotal.com/de/url/08f6a35041572c517d0f37b678212f07fd393105cb12a6cb0193b7897e23b2cb/analysis/1386596265/
https://www.virustotal.com/de/ip-address/200.98.247.12/information/
--->
mensagens.host.uol.com.br
https://www.virustotal.com/de/url/023f4a8bdd186e4454df21696a38c99557b7ea48c2f88af4cd87965a6723b1d1/analysis/1386596045/
mensagens.host.uol.com.br/aviso/aviso_compartilhado.html
https://www.virustotal.com/de/url/c2509e06f5edb12d74aa3f1f50eb0774fc2d113246a96e824eaf4d6e08e58cef/analysis/1386596036/
IP: 200.98.199.177:
https://www.virustotal.com/de/url/f5d0fadaea1a2477c78d88e32a3c47f3ee1088ad986960bbefd88f6af44336bc/analysis/1386596399/
https://www.virustotal.com/de/ip-address/200.98.199.177/information/

12/02/2013

Man in the Middle Attack made a 1.65 Million US Dollar Profit for Victimizing Three Businesses 2013

Three Seattle-Area Businesses Targeted in 2013

The FBI Seattle Field Office is aware of a fraud victimizing Washington state-based businesses, nicknamed “Man-in-the-e-mail”-Scheme for being an e-mail variation of a known “man-in-the-middle” attack. The FBI wants the public to learn about this scam in order to avoid being victimized.

In 2013, at least three area companies (in Bellevue, Tukwila, and Seattle) were led to believe they were sending money to an established supply partner in China. Fact is, fraudsters intercepted legitimate e-mails between the purchasing and supply companies and then spoofed subsequent e-mails impersonating each company to the other. The fraudulent e-mails directed the purchasing companies to send payments to a new bank account because of a purported audit. The bank accounts belonged to the fraudsters, not the supply companies.



Total loss experienced by the three area companies is roughly 1.65 million USD. In some cases, the metadata on the spoofed e-mails indicated that they actually originated in Nigeria and/or South Africa.

Under this scam, both companies in a legitimate business relationship can be victimized. The supplier may first ship out the legitimately ordered products and then never receive payment (because the purchasing company was scammed into paying the scammer-controlled bank account). Or, the purchasing company may first make a payment and then never receive the ordered goods (because the supply company never receives that payment).

12/01/2013

Malicious & Sharing Malware Sub-Domain - dc612.4shared.com

dc612.4shared.com REDIRECTS to www.4shared.com


MALICIOUS PHISHING (SHARING MALWARE) DOMAIN:
  • https://www.virustotal.com/de/url/98ca9becdfad946540fde165af8e4e322506b63bcfbee6a5e582ca94c303a544/analysis/1385916108/
  • http://wepawet.iseclab.org/view.php?type=js&hash=02c10884176e12ba2604ea8c7b5b7518&t=1345339776
  • http://www.urlvoid.com/scan/dc612.4shared.com/
THE FOLLOWING URL & FILES HAVE BEEN SHARED THROUGH THIS SUBDOMAIN:

  • https://www.virustotal.com/de/url/7a83d9db1f7417308a9d8a803dca1f51f7a0446e7e3bad664b45d011d18b393b/analysis/
Backdoor.Win32.DarkKomet.bijw (Threat Description) 
https://www.virustotal.com/de/file/8459f1304094579af94d0e73bb125c7888edc243fd17d911cc7a7664ce49d2e5/analysis/1383266175/
------------------------------------------------------------------------------------------------------------
  • https://www.virustotal.com/de/url/52095ed0f4c67f5165a43a863b5edfe36dc2236e5f6e67ecfafc7d924a45e332/analysis/1385918019/
Trojan-Banker.Win32.Banbra.axhv (Threat Description)
https://www.virustotal.com/de/file/4870236ff27e8d560612337d909a529637abe38495f135568fe19d7077aec680/analysis/
------------------------------------------------------------------------------------------------------------
  • https://www.virustotal.com/de/url/47dbf39907bee90a1de4d951422fa6e83e5c94e52feed39adbc828c269d6e107/analysis/
Trojan-Spy.Win32.Banker
https://www.virustotal.com/de/file/f2a2ac45538e7075fce661422206c458587a2a0ae48072c2914629a732e04d39/analysis/1355936554/
------------------------------------------------------------------------------------------------------------
  • https://www.virustotal.com/de/url/cb2d0e5ffe44f93a2fd0c445f1c0f22fe2741b8df9ee331491ef0c8cc0989705/analysis/
Trojan.Win32.ChePro.wh (Threat Description)
https://www.virustotal.com/de/file/4025caad62473392e74efb828ad3214101dc0e8401e87097834317e650b75388/analysis/1357198015/

AND MANY MORE !
******************

11/24/2013

Category MALICIOUS IP: 80.92.67.155
(Trojan) Heuristic.BehavesLike.Win32.Suspicious.H

The IP Address 80.92.67.155 (IP LOCATION: Luxemburg) is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy and/or some other form of botnet. Specific Malware that has been Found: Heuristic.BehavesLike.Win32.Suspicious.H . This Malicious File stood under communication with the Malicious IP. See 80.92.67.155 IP address information at VT for additional information.

Last detection: 20/11/2013 @ CBL

IP 80.92.67.155 is also listed at Spamhaus.org
IP 80.92.67.155 has 66 Bad Host appearances in Spam E-mail or Spam Post URLs

Other information on this IP:


Other Remarkable Detections on this IP:



SCREENSHOT




RELATED POST: Symantec: Blackshades Remote Access Tool still being bargained

11/22/2013

Popular Leicester pub 'The Globe' forced to close after false
anti-military Facebook rumours: Man arrested !

...nothing more important to investigate ( f.ex.: The 3 Slaved Women who have been rescued ) , you have to question this all alone by yourself.

Detectives investigating an offence of malicious communication have arrested a man in connection with the incident. 
The 20-year-old man has been arrested on suspicion of malicious communications against the Globe Public House in Leicester. 
He has since been released on police bail pending further enquiries. 
In August 2013 police began an investigation after threats were received towards the management at the Globe in Silver Street, Leicester following social media posts claiming the establishment was not allowing military personnel to enter the premises as it was upsetting their customers.
Now this i read a couple of hours ago, and asked myself here, what its all about.

What to the Core is: offence of malicious communication
And what does on suspicion of malicious communications mean

I found out afterwards what its all about:


A popular pub in Leicester was forced to close (in August 2013) amid fears of violent reprisals after its Facebook page was hacked and a message was posted claiming it had banned military personnel.

The false posting, which claimed the pub had enforced the new scheme for fear of upsetting ‘local non British citizens’, was picked up by a nationalist blog and led to the pub being flooded with a storm of allegedly abusive phone calls from people who believed the claim.

The owners of The Globe on Silver Street was forced to shut their doors down on August 17th while security staff were brought in. Leicestershire Police were starting Investigation to an offence of malicious communication.


Everards managing director, Stephen Gould, told the BBC:
"We were placed in a position that throughout the day our staff had to respond to very aggressive people obviously believing that the policy was true.""Ourselves and the manager will have to monitor that very, very carefully over the coming days."
Gould added:
"We have no idea why The Globe was targeted but we will be working with police to find out why this happened."
The pub stated on its Twitter feed:
"The globe has been the victim of a malicious and false news story which states we are no longer servin military personnel. This is false. This pub never has and never will adopt a policy towards the service of either current or ex-military personnel. We understand the delicate nature of this situation and we would sincerely ask for people to stop making threats towards the pub or its staff."
Now, after they arrested a person of interest, i would like to know as well, WHY he did this !

But after the year 2013 will close with all those Leaks, Espionage etc. i guess this could get classified as "TOP SECRET", especially because this Incident was ment against Military Personnel. Lets hope the story continues.