Wednesday, May 22, 2013

Worldwide Trojan Malware Threat Map

Worldwide Trojan Malware Threat Map

You may select the time period and threat type(s) to display below. The map will be updated to reflect the results.

Top Threats Detected
  Threat Name  Detected Count
     
 Adware.FunWeb.Process6795
 Adware.Shopper.Process5185
 Adware.Yontoo.Process4605
 Heur.Agent/Gen-WhiteBox.Process1871
 Malware.Trace1699
 Trojan.Agent/Gen-FraudPack.Process1626
 Browser Hijacker.Deskbar1624
 Adware.HBHelper.BHO1528
 Adware.Somoto.Process1114
 Trojan.Agent/Gen-Downloader.Process1001


Source: http://www.superantispyware.com/threatmap.html








































Tuesday, May 21, 2013

Filing a Complaint with the Internet Crime Complaint Center IC3

The IC3 accepts online Internet crime complaints from either the actual victim or from a third party to the complainant. We can best process your complaint if we receive accurate and complete information from you. Therefore, we request that you provide the following information when filing a complaint:
  • Your name
  • Your mailing address
  • Your telephone number
  • The name, address, telephone number, and Web address, if available, of the individual or organization you believe defrauded you.
  • Specific details on how, why, and when you believe you were defrauded.
  • Any other relevant information you believe is necessary to support your complaint.
http://www.ic3.gov/default.aspx

File a Complaint

Prior to filing a complaint with the IC3, please read the following information regarding terms and conditions. Should you have additional questions prior to filing your complaint, view FAQ for more information on inquiries such as:
  • What details will I be asked to include in my complaint?
  • What happens after I file a complaint?
  • How are complaints resolved?
  • Should I retain evidence related to my complaint?
The information I've provided on this form is correct to the best of my knowledge. I understand that providing false information could make me subject to fine, imprisonment, or both. (Title 18, U.S. Code, Section 1001)

The IC3 is co-sponsored by the Federal Bureau of Investigation (FBI) and the National White Collar Crime Center (NW3C). Complaints filed via this website are processed and may be referred to federal, state, local or international law enforcement or regulatory agencies for possible investigation. I understand any investigation opened on any complaint I file on this website is initiated at the discretion of the law enforcement and/or regulatory agency receiving the complaint information.
Filing a complaint with the IC3 in no way serves as notification to my credit card company that I am disputing unauthorized charges placed on my card or that my credit card number may have been compromised. I should contact my credit card company directly to notify them of my specific concerns.

http://www.ic3.gov/complaint/default.aspx
Advisory:
You are about to file a complaint with the Internet Crime Complaint Center. The confidentiality of the information you provide may be affected by state law. As such, we cannot guarantee that your complaint will remain confidential. The complaint information you submit to this site is encrypted via secure socket layer (SSL) encryption. Please see the Privacy Policy for further information.
We thank you for your cooperation.

Subject: Affordable Loan at 4% Interest [#Spam]

From: Giant Loan Firm
To: Recipients
Sent: Monday, April 8, 2013 2:11 PM
Subject: Affordable Loan at 4% Interest

GIANT FINANCE LOAN FIRM LONDON.
CONTACT ADDRESS,
14 Lake Drive, LONDON SE18DD.
Email:ukgiantloanfirm@gmail.com
website http://uk.******.com/in/glantloanfirm

Attn:

Once in a year this offer comes,Do you have Low finance. We the GIANT FINANCE LOAN FIRM wish to notify you that we give out loan in the rate of 4% Loan Interest,From (£3,000GBP TO £5,Million GBP) To proceed you are to fill the below information needed.all document will be provided to you. HOW DO WE LOAN CASH Depends on how you want your loan to be credit to you. BANK TRANSFER, OR COURIER by cheque. All you have to do is to fill the below information.
BORROWERS INFORMATION REQUIRED
* Full name of applicant `s:
* Amount requested:
* Loan Purpose:
* Address of applicant:
* Occupation:
* City:
* State:
* Country:
* Sex:
* Marital Status:
* Age:
* Land Phone
* Mobile:
Loan amount .......
Loan duration ..........
Monthly Income .........

Note: we only give out loan from above 20 years,this is in accordance with our working procedure.

Regards,
Mr James Williams.
Loan Consultant.
GIANT FINANCE LOAN FIRM LONDON

Facebook Trojan [#Facebook #Trojan] Alert!

"Recently a Microsoft blog was released describing a new Facebook Trojan classified as JS.Febipos.A by several AV vendors. Febipos is currently active in Brazil and takes control of your Facebook profile using a Firefox and/or Chrome extension that’s installed during execution.  I managed to obtain several copies of the Febipos executable, which uses Facebook-like icons in an attempt to appear legitimate, along with being signed by digital certificates from ‘Updates LTD’.

icons

'According to Microsoft’s report, Febipos beacons to a C2 server and receives the following commands:
-    Liking a page
-    Sharing a post
-    Posting messages
-    Joining a group
-    Inviting your friends to a group
-    Sending messages and links via chat
-    Commenting on posts
Febipos is packaged in a self-extracting archive (SFX) and is coded to silently install into the user’s temporary directory (%temp%). The Trojan’s main component is called ‘fbinstupd.exe’, appearing to be shorthand for ‘Facebook Install Update’. All program strings are in Portuguese, Brazil’s official language.

SFXcomments

Upon execution you’ll also get a confirmation dialog that translates to ‘Installation completed successfully!’  Glad to know there weren’t any errors =)

confirm_dialog

In the image below, you’ll also see the results from a regshot capture; notice the installed Firefox extension that was place in my profile directory.  The Chrome extension was dropped in the %temp% directory along with the Trojan and another PE file.

regshot

Febipos’ main component is heavily armored, and was passed through a software protection system known as ‘Obsidium’. You can check it out at http://www.obsidium.de/ for more information. While many programs like Obsidium, VMProtect, Themida, intend to protect commercial software products from piracy and reverse-engineering, they’re also used frequently to fortify malware. This has caused some AV vendors to flag files as malicious if they’re been processed by these protection systems.

obsidium

Unfortunately, I couldn’t get a copy of Febipos that still had a live C2 server, so I wasn’t too interested in doing any further analysis; however, Febipos along with Facbook scams attest to the fact that social media has come under heavy fire from blackhat cyber-criminals. As platforms like Facebook and Twitter allow everyone to be constantly connected, hackers have a new way to ‘connect’ with us.
On underground forums, for instance, it’s very common to see posts offering techniques to hack accounts, generate likes, etc.  A lot of these tricks involve social engineering and sometimes exploiting Facebook’s password recovery options.

fb_hack


codename-like

This has brought about a whole new market for many, who buy and sell Facbook traffic to the highest bidder. If you remember back in January I did a post on Malwarebiter, a Malwarebytes imitator with a Facebook page containing a suspicious number of likes, probably attributed to this kind of behavior.
With that being said, a word to the wise for our readers: safeguard your social media accounts like you would your email account, bank account, or other online account containing personal information. As sites like Facebook continue to integrate into much of our lives, we find that it’s used for much more than stating what’s on our minds. Now we can login to other websites with our Facebook credentials, and sites like Twitter allow us to retrieve news that may influence our everyday decisions. For example, the Associated Press (AP) Twitter account hack of last month briefly impacted the stock market, causing a noticeable drop in the DOW after a fabricated tweet of White House explosions.

What’s more, the threat of malware targeting social media is becoming more apparent, as evidenced by Febipos. While current threats like Febipos are isolated and aren’t capable of doing irreparable harm, Facebook malware is still in its infancy stages, and is sure to advance given ample time. Reports are already surfacing of users creating Facebook botnets, leveraging the power and connectivity of social media to do their dirty work.

However, in Facebook’s defense, the social media giant hasn’t remained quiet amidst the attacks on its users. In recent times, there have been many security updates to password recovery, account creation, and a huge crackdown on fake profiles. Today if you created a new Facebook profile, you’d notice you have to verify who you are, not only with a captcha, but by providing a phone number to retrieve an SMS code needed for account activation.

Read More: http://blog.malwarebytes.org/intelligence/2013/05/brazilian-facebook-trojan-and-consumer-security/

What can you accomplish in the next two years? [Email #Scam #Fraud]

From: "...info@bryantstratton.edu" <info@greatsuperads.com>
To:
Sent: Tuesday, May 21, 2013 7:57 AM
Subject: What can you accomplish in the next two years?
---Click Show Images To Enable Links.----------------------------------------------------
Learn to do Something you love at


FOLLOW YOUR PASSION AND APPLY FOR ONE OF OUR MANY ONLINE DEGREE OPTIONS.


Associate's and Bachelor's Degrees available in Accounting, Business, Criminal Justice and many more.
Bryant & Stratton College is a private career college offering a wide range of degree programs in fields that are in demand. We're also a place where you'll feel totally supported every step of the way and receive the quality, personal education you need for lifetime success.

© GET MORE INFORMATION
Related Posts Plugin for WordPress, Blogger...