Author Archives: Sveta
BBC bases TV programme on MRG Effitas Online Banking Browser Security tests
MRG Effitas has been working with the BBC on a programme which investigates and analyses the impact of financial malware on online banking security.
http://www.bbc.co.uk/news/technology-16812064
Chris Pickard, Methodology & Research director of MRG Effitas and CEO of the Effitas Group has worked with Spencer Kelly, presenter of BBC Click in creating the programme which is to be broadcast worldwide on the BBC News channel on Seturday the 4th of February.
The programme features a test by MRG Effitas demonstrating that a custom piece of crimeware is able to bypass a range of security suites and capture the username and password entered in to a banking website.
You can hear Spencer Kelly discussing the upcoming programme here:
http://news.bbc.co.uk/1/hi/programmes/click_online/9692312.stm
We will be publishing a follow up report on Saturday to coincide with the broadcast of the programme.
Single Product Flash Test – IKARUS virus.utilities, January 2012
Single Product Flash Test
Product: IKARUS virus.utilities
Product Version: 2.0.74
Operating System: Windows 7 32-Bit
Amount of samples used: 50
Results Table:
| Trojans Set 1 |
Trojans Set 2 |
Backdoors | Spy/PWS | Other |
| Harig | Jorik | Poison | Adramax | AutoRun |
| Midgare | Vilsel | Bifrose | Zeus | FakeAV |
| Zmunik | Swisyn | Sdbot | Lmir | TDSS |
| Cosmu | Sasfis | Kbot | Banker | Ngrbot |
| Autoit | Pincav | Shark | Papras | PornoAsset |
| Refroso | Buzus | Hupigon | QQShou |
Cerohar
|
| Inject | Liac | DsBot | Dybalom | LockScreen |
| Cidox | Diple | Zegost | Usteal | Krap |
| StartPage | Yakes | Turkojan | SpyEye | Vobfus |
| Vapsup | FakeSysdef | Gbot | LdPinch | Gimemo |
System Status: Secure
Legend:
Green – Passed
Red – Failed
Largest Cyber Attack Ever?
Targets: U.S. Department of Justice, FBI, U.S. Copyright Office, RIAA, Universal Music, Broadcast Music Inc, Motion Picture Association of America…
Damage: Unknown
Attacker(s): Hacktivist Group Anonymous
Carberp Hits Facebook Users
Facebook users are being targeted in a new man-in-the-browser (MitB) attack that attempts to steal money by duping the user into redeeming an e-cash voucher.
The malware is a new configuration of the Carberp Trojan, according to security firm Trusteer. Carberp replaces any Facebook page the user navigates to with a fake page notifying the victim that his or her Facebook account is “temporarily locked”.
The user is then asked to enter their name, email address, date of birth and password, followed by the number of a €20 Ukash voucher to “confirm verification” of their identity and unlock the account. Ukash is an e-money network that allows customers to anonymously exchange cash for vouchers that can be spent online. Continue reading
Cyber Crime Diary , January 2012
1. Target: Symantec corp.
Damage: Surce code stolen
Attacker(s): Dharmaraja group (India)
2. Target: South African Postbank
Damage: $6.7 million
Attacker(s): Unknown
3. Target: Zappos.com
Damage: 24 million customer details compromised
Attacker(s): Unknown
4. Target: Japanese Space Agency
Damage: Login information to gain access to a cargo shuttle that carries food and equipment to the International Space Station (ISS) has been stolen
Attacker(s): Unknown
Single Product Flash Test – Symantec Norton Antivirus, January 2012
Single Product Flash Test
Product: Symantec Norton Antivirus 2012
Product Version: 19.2.0.10
Operating System: Windows 7 32-Bit
Amount of samples used: 50
Results Table:
| Trojans Set 1 |
Trojans Set 2 |
Backdoors | Spy/PWS | Other |
| Rammit | Diple | DsBot | LdPinch | Krap |
| Inject | Menti | Cycbot | Banbra | FakeAV |
| Rozena | Cidox | Zegost | Zeus | Alureon |
| Vilsel | Lampa | Havar | Chekafev | Digitala |
| Injector | Rimecud | Agobot | Adramax | Vobfus |
| Buzus | Midgare | Shiz | Lmir |
Pdfka
|
| Refroso | Pakes | Hupigon | SpyEye | Ransom |
| Liac | Small | Simda | Bjlog | AutoRun |
| Renos | Chifrax | Wuca | Kykymber | VBNA |
| Scar | Otran | Simbot | QQLogger | ZAccess |
System Status: Compromised
Legend:
Green – Passed
Red – Failed
Modern Warfare 2012
Rootkit, Bootkit, Adware, Backdoor, BHO, Downloader, Email Worm, Exploit, Flooder, Hack Tool, Hoax, Script, HTML, VB, JS, Bat, Fat, Net Worm, P2P Worm, Packed, Constructor , Packer, SQL, IM Worm, PWS, Spy, Dropper, Banker, Clicker, Proxy, SMS, GameThief, Ransom, Virus, Worm, Spyware, Fake AV, Fraud, Win32, Win64, Android….
Above is a list detailing just some of the malware categories MRG Effitas processes in its labs. Each individual category of malware may have tens or hundreds of thousands of variants. Each and every day, each category will spawn tens of thousands more variants.
The war is on, let’s work smart and join forces and win it!
MRG Effitas Team.
Single Product Flash Test – Sourcefire Immunet Plus, December 2011
Single Product Flash Test
Product: Sourcefire Immunet Plus
Product Version: 3.0.5.7688
Operating System: Windows 7 32-Bit
Amount of samples used: 50
Results Table:
| Trojans Set 1 |
Trojans Set 2 |
Backdoors | Spy/PWS | Other |
| Cidox | Mudrop | Bifrose | Zeus | TDSS |
| Rimecud | Hiloti | Ursap | Qbot | Obfuscated |
| Cosmu | Ramnit | Dsbot | Banker | Ransom |
| Yakes | Liac | Zegost | Dybalom | Bybz |
| Genome | Midgare | Poison | Kykymber | AutoIt |
| Inject | Banload | Trukojan | LdPinch |
Pdfka |
| Delf | Renos | Begman | Banbra | ZAccess |
| Dipel | Pincav | Cycbot | SpyEye | Alureon |
| Menti | FakeSysdef | Koutodoor | Carberp | Vobfus |
| Jorik | Refroso | Hupigon | Pophot | FakeAV |
System Status: Secure
Legend:
Green – Passed
Red – Failed
Single Product Flash Test – SUPERAntispyware Professional, December 2011
Single Product Flash Test
Product: SUPERAntispyware Professional
Product Version: 5.0.4412
Operating System: Windows 7 32-Bit
Amount of samples used: 50
Results Table:
| Trojans Set 1 |
Trojans Set 2 |
Backdoors | Spy/PWS | Other |
| Menti | Delf | Ruskill | Usteal | Alureon |
| Inject | Frijoiner | Shark | Zeus | FakeAV |
| Sasfis | Vilsel | Bifrose | Banker | Ransom |
| Refroso | Dapato | Hupigon | Bancos | Krap |
| Swisyn | Liac | Kredoor | QQPass | AutoRun |
| Pasta | Scar | DsBot | SpyEye |
ZAccess |
| Rbot | Malf | AgoBot | Carberp | TDSS |
| Yakes | Ircbrute | Poison | Fingotok | VBNA |
| Zmunik | Jorik | Turkojan | Sinowal | Sality |
| Buzus | Small | Optix | Ruftar | Kokab |
System Status: Compromised
Legend:
Green – Passed
Red – Failed
