MRG Effitas BBC Follow Up Test UPDATE

On Tuesday (Feb. 7th), MRG Effitas will be publishing a follow up test to the one we conducted for the BBC Click programme.

We will re-test the latest versions of the applications featured in the BBC report and also include some new ones.

We will use the same type of simulator we used for the programme.

All the vendors who failed in the report were sent the simulator. The purpose of the test will be to see if any of the vendors who failed have since been able to protect against this tool.

The test is replicating a targeted attack using a custom piece of crimeware designed to capture a users banking or corporate logon credentials.

The vendors who will be tested are as follows:

  • AVG Internet Security
  • BitDefender Internet Security
  • Bullguard Internet Security
  • Comodo Internet Security
  • Emsisoft Anti-Malware
  • ESET Smart Security
  • F-Secure Internet Security
  • Ikarus Virus Utilities
  • Immunet  Plus
  • Kaspersky Internet Security
  • Norton 360
  • Panda Internet Security
  • Quarri Protect On Q
  • SoftSphere Defense Wall
  • Sophos Endpoint Security
  • Trend Micro Titanium Internet Security
  • Trusteer Rapport
  • VIPRE Internet Security 2012
  • Webroot SecureAnywhere
  • Zemana AntiLogger
  • ZoneAlarm Internet Security

BBC bases TV programme on MRG Effitas Online Banking Browser Security tests

MRG Effitas has been working with the BBC on a programme which investigates and analyses the impact of financial malware on online banking security.

http://www.bbc.co.uk/news/technology-16812064

Chris Pickard, Methodology & Research director of MRG Effitas and CEO of the Effitas Group has worked with Spencer Kelly, presenter of BBC Click in creating the programme which is to be broadcast worldwide on the BBC News channel on Seturday the 4th of February.

The programme features a test by MRG Effitas demonstrating that a custom piece of crimeware is able to bypass a range of security suites and capture the username and password entered in to a banking website.

You can hear Spencer Kelly discussing the upcoming programme here:

http://news.bbc.co.uk/1/hi/programmes/click_online/9692312.stm

We will be publishing a follow up report on Saturday to coincide with the broadcast of the programme.

Single Product Flash Test – IKARUS virus.utilities, January 2012

Single Product Flash Test

Product: IKARUS virus.utilities

Product Version: 2.0.74

Operating System: Windows 7 32-Bit

Amount of samples used: 50

Results Table:

 

Trojans
Set 1
Trojans
Set 2
Backdoors Spy/PWS Other
Harig Jorik Poison Adramax AutoRun
Midgare Vilsel Bifrose Zeus FakeAV
Zmunik Swisyn Sdbot Lmir TDSS
Cosmu Sasfis Kbot Banker Ngrbot
Autoit Pincav Shark Papras PornoAsset
Refroso Buzus Hupigon QQShou
Cerohar
Inject Liac DsBot Dybalom LockScreen
Cidox Diple Zegost Usteal Krap
StartPage Yakes Turkojan SpyEye Vobfus
Vapsup FakeSysdef Gbot LdPinch Gimemo

 

System Status: Secure

Legend:

Green – Passed

Red – Failed

 

Carberp Hits Facebook Users

Facebook users are being targeted in a new man-in-the-browser (MitB) attack that attempts to steal money by duping the user into redeeming an e-cash voucher.

The malware is a new configuration of the Carberp Trojan, according to security firm Trusteer. Carberp replaces any Facebook page the user navigates to with a fake page notifying the victim that his or her Facebook account is “temporarily locked”.

The user is then asked to enter their name, email address, date of birth and password, followed by the number of a €20 Ukash voucher to “confirm verification” of their identity and unlock the account. Ukash is an e-money network that allows customers to anonymously exchange cash for vouchers that can be spent online. Continue reading

Cyber Crime Diary , January 2012

1. Target: Symantec corp.

Damage: Surce code stolen

Attacker(s): Dharmaraja group (India)

2. Target: South African Postbank

Damage: $6.7 million

Attacker(s): Unknown

3. Target: Zappos.com

Damage: 24 million customer details compromised

Attacker(s): Unknown

4. Target: Japanese Space Agency

Damage: Login information to gain access to a cargo shuttle that carries food and equipment to the International Space Station (ISS) has been stolen

Attacker(s): Unknown

Single Product Flash Test – Symantec Norton Antivirus, January 2012

Single Product Flash Test

Product: Symantec Norton Antivirus 2012

Product Version: 19.2.0.10

Operating System: Windows 7 32-Bit

Amount of samples used: 50

Results Table:

 

Trojans
Set 1
Trojans
Set 2
Backdoors Spy/PWS Other
Rammit Diple DsBot LdPinch Krap
Inject Menti Cycbot Banbra FakeAV
Rozena Cidox Zegost Zeus Alureon
Vilsel Lampa Havar Chekafev Digitala
Injector Rimecud Agobot Adramax Vobfus
Buzus Midgare Shiz Lmir
Pdfka
Refroso Pakes Hupigon SpyEye Ransom
Liac Small Simda Bjlog AutoRun
Renos Chifrax Wuca Kykymber VBNA
Scar Otran Simbot QQLogger ZAccess

 

System Status: Compromised

Legend:

Green – Passed

Red – Failed

 

Modern Warfare 2012

Rootkit, Bootkit, Adware, Backdoor, BHO, Downloader, Email Worm, Exploit, Flooder, Hack Tool, Hoax, Script, HTML, VB, JS, Bat, Fat, Net Worm, P2P Worm, Packed, Constructor , Packer, SQL, IM Worm, PWS, Spy, Dropper, Banker, Clicker, Proxy, SMS, GameThief, Ransom, Virus, Worm, Spyware, Fake AV, Fraud, Win32, Win64, Android….

 

Above is a list detailing just some of the malware categories MRG Effitas processes in its labs. Each individual category of malware may have tens or hundreds of thousands of variants. Each and every day, each category will spawn tens of thousands more variants.

The war is on, let’s work smart and join forces and win it!


MRG Effitas Team.

Single Product Flash Test – Sourcefire Immunet Plus, December 2011

Single Product Flash Test

Product: Sourcefire Immunet Plus

Product Version: 3.0.5.7688

Operating System: Windows 7 32-Bit

Amount of samples used: 50

Results Table:

 

Trojans
Set 1
Trojans
Set 2
Backdoors Spy/PWS Other
Cidox Mudrop Bifrose Zeus TDSS
Rimecud Hiloti Ursap Qbot Obfuscated
Cosmu Ramnit Dsbot Banker Ransom
Yakes Liac Zegost Dybalom Bybz
Genome Midgare Poison Kykymber AutoIt
Inject Banload Trukojan LdPinch
Pdfka
Delf Renos Begman Banbra ZAccess
Dipel Pincav Cycbot SpyEye Alureon
Menti FakeSysdef Koutodoor Carberp Vobfus
Jorik Refroso Hupigon Pophot FakeAV

 

System Status: Secure

Legend:

Green – Passed

Red – Failed