BBC bases TV programme on MRG Effitas Online Banking Browser Security tests

MRG Effitas has been working with the BBC on a programme which investigates and analyses the impact of financial malware on online banking security.

http://www.bbc.co.uk/news/technology-16812064

Chris Pickard, Methodology & Research director of MRG Effitas and CEO of the Effitas Group has worked with Spencer Kelly, presenter of BBC Click in creating the programme which is to be broadcast worldwide on the BBC News channel on Seturday the 4th of February.

The programme features a test by MRG Effitas demonstrating that a custom piece of crimeware is able to bypass a range of security suites and capture the username and password entered in to a banking website.

You can hear Spencer Kelly discussing the upcoming programme here:

http://news.bbc.co.uk/1/hi/programmes/click_online/9692312.stm

We will be publishing a follow up report on Saturday to coincide with the broadcast of the programme.

Single Product Flash Test – IKARUS virus.utilities, January 2012

Single Product Flash Test

Product: IKARUS virus.utilities

Product Version: 2.0.74

Operating System: Windows 7 32-Bit

Amount of samples used: 50

Results Table:

 

Trojans
Set 1
Trojans
Set 2
Backdoors Spy/PWS Other
Harig Jorik Poison Adramax AutoRun
Midgare Vilsel Bifrose Zeus FakeAV
Zmunik Swisyn Sdbot Lmir TDSS
Cosmu Sasfis Kbot Banker Ngrbot
Autoit Pincav Shark Papras PornoAsset
Refroso Buzus Hupigon QQShou
Cerohar
Inject Liac DsBot Dybalom LockScreen
Cidox Diple Zegost Usteal Krap
StartPage Yakes Turkojan SpyEye Vobfus
Vapsup FakeSysdef Gbot LdPinch Gimemo

 

System Status: Secure

Legend:

Green – Passed

Red – Failed

 

Carberp Hits Facebook Users

Facebook users are being targeted in a new man-in-the-browser (MitB) attack that attempts to steal money by duping the user into redeeming an e-cash voucher.

The malware is a new configuration of the Carberp Trojan, according to security firm Trusteer. Carberp replaces any Facebook page the user navigates to with a fake page notifying the victim that his or her Facebook account is “temporarily locked”.

The user is then asked to enter their name, email address, date of birth and password, followed by the number of a €20 Ukash voucher to “confirm verification” of their identity and unlock the account. Ukash is an e-money network that allows customers to anonymously exchange cash for vouchers that can be spent online. Continue reading

Cyber Crime Diary , January 2012

1. Target: Symantec corp.

Damage: Surce code stolen

Attacker(s): Dharmaraja group (India)

2. Target: South African Postbank

Damage: $6.7 million

Attacker(s): Unknown

3. Target: Zappos.com

Damage: 24 million customer details compromised

Attacker(s): Unknown

4. Target: Japanese Space Agency

Damage: Login information to gain access to a cargo shuttle that carries food and equipment to the International Space Station (ISS) has been stolen

Attacker(s): Unknown

Single Product Flash Test – Symantec Norton Antivirus, January 2012

Single Product Flash Test

Product: Symantec Norton Antivirus 2012

Product Version: 19.2.0.10

Operating System: Windows 7 32-Bit

Amount of samples used: 50

Results Table:

 

Trojans
Set 1
Trojans
Set 2
Backdoors Spy/PWS Other
Rammit Diple DsBot LdPinch Krap
Inject Menti Cycbot Banbra FakeAV
Rozena Cidox Zegost Zeus Alureon
Vilsel Lampa Havar Chekafev Digitala
Injector Rimecud Agobot Adramax Vobfus
Buzus Midgare Shiz Lmir
Pdfka
Refroso Pakes Hupigon SpyEye Ransom
Liac Small Simda Bjlog AutoRun
Renos Chifrax Wuca Kykymber VBNA
Scar Otran Simbot QQLogger ZAccess

 

System Status: Compromised

Legend:

Green – Passed

Red – Failed

 

Modern Warfare 2012

Rootkit, Bootkit, Adware, Backdoor, BHO, Downloader, Email Worm, Exploit, Flooder, Hack Tool, Hoax, Script, HTML, VB, JS, Bat, Fat, Net Worm, P2P Worm, Packed, Constructor , Packer, SQL, IM Worm, PWS, Spy, Dropper, Banker, Clicker, Proxy, SMS, GameThief, Ransom, Virus, Worm, Spyware, Fake AV, Fraud, Win32, Win64, Android….

 

Above is a list detailing just some of the malware categories MRG Effitas processes in its labs. Each individual category of malware may have tens or hundreds of thousands of variants. Each and every day, each category will spawn tens of thousands more variants.

The war is on, let’s work smart and join forces and win it!


MRG Effitas Team.

Single Product Flash Test – Sourcefire Immunet Plus, December 2011

Single Product Flash Test

Product: Sourcefire Immunet Plus

Product Version: 3.0.5.7688

Operating System: Windows 7 32-Bit

Amount of samples used: 50

Results Table:

 

Trojans
Set 1
Trojans
Set 2
Backdoors Spy/PWS Other
Cidox Mudrop Bifrose Zeus TDSS
Rimecud Hiloti Ursap Qbot Obfuscated
Cosmu Ramnit Dsbot Banker Ransom
Yakes Liac Zegost Dybalom Bybz
Genome Midgare Poison Kykymber AutoIt
Inject Banload Trukojan LdPinch
Pdfka
Delf Renos Begman Banbra ZAccess
Dipel Pincav Cycbot SpyEye Alureon
Menti FakeSysdef Koutodoor Carberp Vobfus
Jorik Refroso Hupigon Pophot FakeAV

 

System Status: Secure

Legend:

Green – Passed

Red – Failed

Single Product Flash Test – SUPERAntispyware Professional, December 2011

Single Product Flash Test

Product: SUPERAntispyware Professional

Product Version: 5.0.4412

Operating System: Windows 7 32-Bit

Amount of samples used: 50

Results Table:

 

Trojans
Set 1
Trojans
Set 2
Backdoors Spy/PWS Other
Menti Delf Ruskill Usteal Alureon
Inject Frijoiner Shark Zeus FakeAV
Sasfis Vilsel Bifrose Banker Ransom
Refroso Dapato Hupigon Bancos Krap
Swisyn Liac Kredoor QQPass AutoRun
Pasta Scar DsBot SpyEye
ZAccess
Rbot Malf AgoBot Carberp TDSS
Yakes Ircbrute Poison Fingotok VBNA
Zmunik Jorik Turkojan Sinowal Sality
Buzus Small Optix Ruftar Kokab

 

System Status: Compromised

Legend:

Green – Passed

Red – Failed