Tag: Worm

  • lloyds message service – debit posted.zip (malware)

    If you got lloyds message service – debit posted in an email then its a virus.  This .zip is malware verified by VirusTotal.com

    lloyds message service
    courtesy of tranquilnet

    Subject: You have received a new debit

    This is an automatically generated email by the Lloyds TSB PLC

    LloydsLink online payments Service to inform you that you have

    receive a NEW Payment.

    The details of the payment are attached.

    This e-mail (including any attachments) is private and confidential

    and may contain privileged material. If you have received this

     

    Scan From VirusTotal:

    Antivirus

    Result

    Update

    Ad-Aware

    20131211

    Agnitum

    20131217

    AhnLab-V3

    Trojan/Win32.Dapato

    20131218

    AntiVir

    20131218

    Antiy-AVL

    20131218

    Avast

    Win32:Malware-gen

    20131218

    AVG

    20131218

    Baidu-International

    20131213

    BitDefender

    20131211

    Bkav

    20131218

    ByteHero

    20130613

    CAT-QuickHeal

    20131218

    ClamAV

    20131218

    CMC

    20131217

    Commtouch

    W32/Trojan.CIRP-9141

    20131218

    Comodo

    20131218

    DrWeb

    20131218

    Emsisoft

    20131218

    ESET-NOD32

    Win32/TrojanDownloader.Waski.A

    20131218

    F-Prot

    W32/Trojan3.GVD

    20131218

    F-Secure

    Trojan.Agent.BBBY

    20131218

    Fortinet

    20131218

    GData

    Trojan.Agent.BBBY

    20131218

    Ikarus

    Trojan-Spy.Agent

    20131218

    Jiangmin

    20131218

    K7AntiVirus

    20131218

    K7GW

    20131218

    Kaspersky

    Trojan.Win32.Bublik.boha

    20131218

    Kingsoft

    20130829

    Malwarebytes

    Trojan.Agent.RV

    20131218

    McAfee

    20131218

    McAfee-GW-Edition

    20131218

    Microsoft

    20131218

    MicroWorld-eScan

    20131218

    NANO-Antivirus

    20131218

    Norman

    20131218

    nProtect

    20131218

    Panda

    20131218

    Rising

    PE:Malware.FakePDF@CV!1.9E18

    20131218

    Sophos

    Troj/Zbot-HEQ

    20131218

    SUPERAntiSpyware

    20131218

    Symantec

    20131218

    TheHacker

    20131217

    TotalDefense

    20131217

    TrendMicro

    20131218

    TrendMicro-HouseCall

    TROJ_GEN.F47V1218

    20131218

    VBA32

    20131218

    VIPRE

    20131218

    ViRobot

    20131218

  • Ed Skoudis lists the Top 5 Worst Attacks of 1998 – 2002

    That which does not kill us makes us stronger.
    -Friedrich Nietzsche

    In the November 2002, Information Security Magazine article, Infosec’s Worst NightMares, Ed Skoudis lists the Top 5 Worst Attacks of 1998 – 2002. Mr. Skoudis is the founders of Intelguardians Network Intelligence, LLC and is a handler of the very popular Internet Storm Center.

    Mr. Skoudis mentions that the Top five major destructive attacks of 1998 – 2002 made many industries “battle-tested” and more likely to be proactive rather than reactive. The 5 year Worst Skoudis list is based on exploits that shook our very faith in the Internet and security of e-commerce.

    1. Code Red (2001). July 13 2001, the worm attacked Microsoft IIS systems. By 19 July 2001, the worm had affected over 350,000 systems. SANS and Honeynet Project set up honey pots to capture the worm. But E-eye Digital Security Programmers did the most intense research on the worm and also named it. The worm exploited a vulnerability in the indexing software distributed with IIS, described in Microsoft’s MS01-033 patch. It was a buffer overflow attack. Some of the lessons learned: Keep systems patched, use of honey pots to capture malware, coordinated response helps to contain worms.

    2. Nimda (2001). Shortly after 9/11, the Nimda worm was unleashed. It caused more damage financially than Code Red. There were rumors that it was China that released it to hurt the US further, but this is unlikely due to the nature of Nimda.

    While it was bad, it had the appearance of a being written by a determined amateur, not a nation-state that spends $1 Billion annually on cyberwarfare capabilities. – Skoudis.

    Nimda affected Windows 95, 98, Me, NT, or 2000 and servers running Windows NT and 2000. It was so affective because it attacked IIS, e-mail, browsers and network shares. This multi dimensional attack method could mark a trend in future cyberfare.

    Lessons Learned: The importance of an incident response capability, disabling arbitrary scripts in e-mail and browsers.

    3. Melissa (1999) & LoveLetter (2000). Both of these exploited malware through e-mail propagation. Melissa used Microsoft Word Macro virus and LoveLetter (I Love You Virus). The worm harvested the victims address book to forward itself to more victims which killed a lot of email servers. Lessons Learned: Many companies got serious about implementing anti-virus applications throughout the network.

    4. Distributed Denial-of-Service (DdoS) attacks (2000)
    . After all the panic of pre-Y2K, a completely new and unexpected storm hit major sites: Yahoo!, Amazon, CNN, E*Trade ZDNet and eBay. All by a single child hacker nicked named Mafiaboy. He had spread zombie flooding agents to hundreds of machines around the world and used them to attack sites with billions of useless packets. Lessons Learned: employ anti-spoofing filters.

    5. Remote Control Trojan Horse Backdoors (1998 – 2000)
    . In 1998, the Cult of the Dead Cow hackers group created the Trojan, Back Orifice which initially targeted Windows NT/9x. The tool allowed unskilled attackers to attack any vulnerable system. It also marked the rise of the “script kiddies” and produced a bunch of spin offs such as Subseven, Netbus and Hack-a-Tack.