Symantec Connect
  • Login
  • Register
  • All of Connect
    • All of Connect
    • Backup and Archiving
    • Endpoint Management & Virtualization
    • Storage and Clustering
    • Security
    • Inside Symantec
    • Vision User Conference
    • Partners
    • Developers
    •  
  • Overview
  • Forums
  • Articles
  • Blogs
  • Downloads
  • Events
  • Videos
  • Groups
  • Ideas

Security Response: Showing posts tagged with Endpoint Protection (AntiVirus)Syndicate content

Login to participate
通过电驴传播的感染型蠕虫病毒W32.Noobert
Livian Ge | December 29, 2009
0 comments
电驴是一个很受欢迎的互联网分享平台,用户可以通过电驴快速共享、高速下载互联网上的各类文件。但是,网络攻击者也会趁机借此途径传播病毒。W32.Noobert就是这样一种蠕虫病毒。
W32.Noobert能感染受害计算机主机磁盘上的.exe和.scr文件。感染后,当用户运行这些文件时,该蠕虫会被解压到%TEMP%\NOO%RANDOM%目录下并且继续执行其文件感染功能。此外,它还会随机地删除以*.avi,*.xls,*.jpg ,*.doc为后缀名的文件,并且会通过修改注册表项键值HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\NT\CurrentVersion\Winlogon\"SFCDisable" = "1"以及修改%System%\和%System%\dllcache\路径下的系统文件SFC_OS.dll来关闭Windows的文件保护功能。
W32.Noobert还会将自身拷贝到电驴的incoming目录下,以达到通过电驴的文件共享网络进行传播的目的。因此,我们建议用户在下载P2P网络共享文件时先使用诺顿安全软件对其进行威胁扫描,确认安全后再打开下载。
Read more
Tags: Endpoint Protection (AntiVirus), Malicious Code, Security, Security Response
Metasploit Releases Module for IIS Local File Include Vulnerability
Patrick Fitzgerald | December 29, 2009
0 comments

Over the last few days there have been many articles written about an issue in Microsoft’s Internet Information Services (IIS).  This issue allows an attacker to bypass normal security restrictions when uploading a file to a Web application running on a vulnerable version of IIS.  This issue could allow an attacker to upload and execute arbitrary code with the privileges of the Web server.

There are varying reports on the severity of this issue, but according to Microsoft only poorly configured Web servers are at risk from this issue:

“An attacker would have to be authenticated and have write access to a directory on the web server with execute permissions which does not align with best practices or guidance Microsoft provides for secure server configuration.”

...

Read more
Tags: Endpoint Protection (AntiVirus), Emerging Threats, Security, Vulnerabilities & Exploits, Security Response
Adobe新漏洞尚无补丁,木马Trojan.Pidief.H伺机攻击
Livian Ge | December 23, 2009
0 comments
病毒类型:木马
受影响的操作系统: Windows 95/98/2000/Me/XP/Vista/NT, Windows Server 2003
 
    Trojan.Pidief.H是一个利用尚无补丁的Adobe Reader和Acrobat零日漏洞(CVE-2009-4324)的木马。它利用此漏洞在被入侵的计算机中释放并运行恶意程序。
 
    恶意的文件将被释放到Temp目录,并重命名为AdobeUpdate.exe以达到迷惑用户的目的。攻击者可以根据其攻击意图来选择使用不同的被释放文件,如盗窃用户的机密信息和偷渡式下载其它恶意文件等。该木马可能通过包含特殊JavaScript的PDF文件以邮件附件的形式来到受害用户的计算机,并会诱导用户点击打开附件;此外网页挂马也是它的一种传播方式。
 
    目前Adobe还没有发布针对该漏洞的补丁,用户需格外小心。建议用户尽量不要访问可疑网站,不要轻易打开来历不明的邮件附件。

Read more
Tags: Endpoint Protection (AntiVirus), Malicious Code, Security, Vulnerabilities & Exploits, Security Response
Qakbot, Data Thief Unmasked: Part II
John McDonald | December 22, 2009
0 comments

Theft
As we discussed in Part I, the primary purpose of Qakbot is to steal information from the compromised computer. In addition to targeting login details for FTP, POP3 and IMAP, the worm also attempts to steal Cookies - not only regular browser session cookies but also Flash cookies. A discussion of Flash cookies is beyond the scope of this article, but be aware that unlike traditional browser cookies, Flash cookies are not controlled through the cookie privacy controls in a browser which means they cannot be cleared or deleted in the simple manner that normal tracking cookies are removed.

Qakbot uses several techniques to collect private keys from the system certificates contained on the compromised computer. First, it replaces all certificate-related dialog boxes so that the “OK” button is automatically pushed as soon as the dialog is created...

Read more
Tags: Endpoint Protection (AntiVirus), Security, Security Response
Qakbot, Data Thief Unmasked: Part I
Shunichi Imano | December 21, 2009
0 comments

Motive
We recently had the opportunity to revisit a threat that first appeared on our radar back in May of this year. W32.Qakbot (hereafter referred to as Qakbot) is a somewhat benign worm that is capable of spreading through network shares, downloading additional files and opening a back door on the compromised computer, all in aid of its ultimate goal. Benign not because it is harmless - stealing login details, reporting keystrokes and uploading system certificates is malicious behavior indeed - but as will become obvious as we describe it in more detail below, because it moves slowly and with caution, trying not to bring attention to its presence.

The motive of Qakbot is quite clear, to steal information. Taking a peak under the proverbial covers, we see that it  uses several components to accomplish the task, including the following:

  • ...
Read more
Tags: Endpoint Protection (AntiVirus), Security, Security Response
Recycled .mp3 Spam for Cheap Pills
Samir Patil | December 18, 2009
0 comments

Spammers are recycling their old spamming methods after more than two years. Symantec reported an .mp3 version of pump-and-dump stock spam back in October 2007.

In this recent spam attack, a small .mp3 file promoting a meds domain is attached in the email messages. These email messages contain no subject line or message body. The .mp3 file is a five-second message recorded in a female voice and promotes a particular meds domain. The file is approximately 11 KB in size and recorded at a 16 kbps bit rate. The voice is heavily distorted with background noise. The domain name described in the file is a recently registered domain in China.

Some of the random filenames used are as follows:

milksoppy.mp3
enwomb.mp3
realiser.mp3
escort.mp3
recarboniser.mp3
unlights.mp3
scathing.mp3
byproduct.mp3
lewes.mp3
micrometers.mp3
...

Read more
Tags: Endpoint Protection (AntiVirus), Security, Spam, Security Response
There's No Such Thing as a Free Movie
Hon Lau | December 18, 2009
0 comments

Those looking to see the latest 3D blockbuster movie, The Avatar, on the cheap will have to take great care in what they search for. We have become aware of at least one site that has been rigged to redirect users to a page that presents the now-familiar "play video/need codec" screen. In an unusual twist, this time it is offering a new ActiveX update rather than the usual codec or Flash player updates.

FreeAvatarMovie_2.png

avatar2_2.png

Clicking on the play button or icon will send a request to update-activex.com, which will then eventually offer you a file named along the lines of Activex_Setup[1].45158.exe from the standardmultimedia.com domain. This is now detected as Trojan.FakeAV.

In addition to this malware page...

Read more
Tags: Endpoint Protection (AntiVirus), Emerging Threats, Malicious Code, Online Fraud, Security, Security Response
New Adobe Acrobat Zero-Day
Mircea Ciubotariu | December 17, 2009
0 comments

We have recently learned of yet another zero-day exploit in Adobe Acrobat. This time it's an overflow for a special type parameter in a function provided by the multimedia.api plugin that can be manipulated from JavaScript in the following manner:

media.newPlayer(null)

Somewhere deep in newPlayer, deinit_obj is set as the handler for deleting the object when it's no longer needed:

code1.png

And eventually deinit_obj calls the destroy function from the object's v_table:

code2.png

So far...

Read more
Tags: Endpoint Protection (AntiVirus), Emerging Threats, Malicious Code, Security, Vulnerabilities & Exploits, Security Response
岁末,Adobe又曝新漏洞
Livian Ge | December 16, 2009
0 comments

    时值年末假期,Adobe和Adobe Reader又被曝出新的零日漏洞(CVE-2009-4324)。

    该Adobe Reader and Acrobat 'newplayer()' JavaScript 漏洞位于多媒体插件Multimedia.api。目前针对该漏洞的攻击主要是通过包含有特殊JavaScript的PDF文件。这类特制的PDF文件可能通过邮件附件的形式进入用户计算机,并会诱导用户点击打开文件。赛门铁克已发布针对该病毒的定义Trojan.Pidief.H。

     当用户打开这类PDF文件时,攻击者会利用newplayer() 函数中出现的系统漏洞进行攻击,该漏洞出现在newplayer() 函数创建player object的过程中,以null作为创建对象的参数,迫使Adobe Reader在创建player object的参数检查时抛出异常,并在其处理函数中访问了未初始化完成的对象指针,造成系统异常,如图一所示。

                                                  ...

Read more
Tags: Endpoint Protection (AntiVirus), Malicious Code, Security, Vulnerabilities & Exploits, Security Response
Chinese Christmas Gift Shopping Options
Vivian Ho | December 16, 2009
0 comments

We’ve monitored a great deal of Christmas sales spam (in English) for the upcoming holiday. Compared to English holiday spam, Chinese spammers seem to have fewer activities for Christmas, most likely because it is not a major holiday in the Chinese calendar. The Christmas holiday is popular among younger Chinese generations, however, and shopping for gifts is still expected. We have observed a couple of notable Chinese samples covering the topic of Christmas shopping. In the first sample, a spammer has sent a random Christmas sales ad, and we found that the spammer purposely set the promotion text background color in gray (<FONT style="BACKGROUND-COLOR: gray" color=gray>); you have to highlight the gray line in order to see the promotion text. In the header we observed a forged and randomized “From” alias. They used a shortened URL service in the body image, which led to an actual business website.

Sample Header:
...

Read more
Tags: Endpoint Protection (AntiVirus), Security, Spam, Security Response
Ho Ho Ho! Spammers’ Christmas Gifts to You
Vivian Ho | December 16, 2009
0 comments

Didn’t shop enough on Black Friday? Still looking for Christmas Gifts? Need to send holiday greetings? Spammers will send them all at your convenience! We started seeing Christmas-related spam just after the Thanksgiving holiday—spammers are just as busy as the rest of us are this holiday season.

We have recently observed many different types of Christmas-related spam, such as medical/replica/gift shopping offers, loan offers, lotto scams, fraud and viruses, etc. Many of them have Christmas themed key words in the header to lure users to open emails. We saw some last year and have already observed the familiar “festive” headers.

The following are some sample headers:

From: "Shop Smart this Christmas" <Details Removed>
From: "X-mas Loan Offer" <Details Removed>
From: "Christmas Gift Ideas" <Details Removed>
From: "Christmas" <Details Removed>  ...

Read more
Tags: Endpoint Protection (AntiVirus), Security, Spam, Security Response
Zero-Day Xmas Present
Joji Hamada | December 14, 2009
0 comments

Earlier today, we received a tip from a source that there is a possible Adobe Reader and Acrobat 0-day vulnerability in the wild. We have indeed confirmed the existence of a 0-day vulnerability in these products. The PDF files we discovered arrives as an email attachment. The attack attempts to lure email recipients into opening the attachment. When the file is opened, a malicious file is dropped and run on a fully patched system with either Adobe Reader or Acrobat installed. Symantec products detect the file as Trojan.Pidief.H.

We have reported our findings to Adobe who have acknowledged the vulnerability in this blog.

The analysis is still ongoing, so more details to follow. In the meantime, I recommend everyone to be extra vigilant during this holiday season, especially when...

Read more
Tags: Endpoint Protection (AntiVirus), Security, Security Response
Spam and Phishing Landscape: December 2009
Dermot Harnett | December 14, 2009
0 comments

Notable highlights this month include the continuing shift of the region of message origin to APJ and South America, and changes in the average size of spam messages.
 
•    The EMEA region has been firmly displaced as the primary region of origin for spam—the APJ region has obtained that mantle. The APJ region currently accounts for 26 percent of all spam, which is a nine percentage point increase since June 2009.
•    With respect to the average size of spam messages, 71.08 percent of messages now have an average message size between 2kb – 5 kb, while 19.53 percent have an average message size between 5kb – 10kb.
•    With respect to spam categories, Internet spam decreased by four percent and now accounts for 35 percent of all spam messages, with leisure and fraud increasing by three and two percent, respectively.

Click...

Read more
Tags: Endpoint Protection (AntiVirus), Online Fraud, Security, Spam, Security Response
AVAR 2009 Conference in Kyoto
Masaki Suenaga | December 13, 2009
0 comments

The AVAR 2009 Conference was held in the historical city of Kyoto, Japan from November 5. As this year's trend is cloud computing, fake antivirus software and massive PDF file attacks, the cloud and PDF topics were covered in the conference.

We had several Japan-specific sessions. Some delegates from the Japanese ministries and governmental agencies spoke about their tasks and statistics on cyber crimes. As with other nations, Japan has its own specialty in computer usage and malware, such as wide-spread usage of the peer-to-peer software called Winny and the related malware W32.Antinny and a destructive Trojan horse Trojan.Haradong that was discovered in the Winny network (the creator was eventually arrested). Another trend in Japan is the so-...

Read more
Tags: Endpoint Protection (AntiVirus), Security, Security Response
The Phishing of Applications on Social Networking Websites
Mathew Maniyara | December 11, 2009
0 comments

The popularity of applications on social networking websites has increased a great deal this year. This has led to a new wave of phishing attacks targeting the users of these applications. Symantec has examined phishing websites exploiting three major social networking brands. The fake websites display attractive offers on the social networking applications to lure end users. Some of the applications that the phishing sites were based on are:

1.    Social networking on mobile – Due to the rise in the number of users accessing the Internet through smart phones, social networking websites have expanded their services on smart phones, including messaging, chatting, photo viewing, etc. This increase in users has opened more doors to attackers because there are now more potential victims. Hence, attackers have created phishing websites on social networking brands claiming to provide these services on smart phones.
2.    ...

Read more
Tags: Endpoint Protection (AntiVirus), Online Fraud, Security, Security Response
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • …
  • next ›
  • last »

About Security Response Blog

Our security research centers around the world provide unparalleled analysis of and protection from malware, security risks, vulnerabilities, and spam.
Filter by:

Blog Tags

10.x 11.x 9.x and Earlier Antivirus2010 Backdoor.Tidserv Brightmail Gateway Emerging Threats Endpoint Encryption Endpoint Protection (AntiVirus) Endpoint Protection Small Business Enterprise Security Manager Evolution of Security General Symantec IT Healthcare Landscape IT Risk Management Internet Security Threat Report Live PC Care Malicious Code Misleading Applications Mobile & Wireless Online Fraud Password Management Restore Security Security Risks Spam Sykipot SymbOS.Exy Symbian Trojan.FakeAV Trojan.Zbot VirusDoctor Vulnerabilities & Exploits Windows Zeus
© 2010
  • Symantec Corporation
  • Contact Us
  • Get RSS
  • Privacy Policy
  • Symantec.com