Endpoint Protection

 View Only
  • 1.  Firefox specific exploit popped up today, no solutions yet

    Posted Oct 19, 2010 03:12 PM

    Hi,

    Sry, first time and not sure if this is the right forum/ thing to do. This has happened on my work computer and I am more than a little nervous about it.

    Browsed to a site that firefox identified as a reported attack page. Dialog box popped up and said to "Download secure updates for firefox", so I did and thought nothing of it as it came up after mozilla blocked the page, until I saw the file origin (antimalware-updates.is dot com/firefox-updates/ff_secure_upd.exe) and thought it was suspicious. I deleted the .exe file without runnin it and ran a full scan which only found 1 malware cookie *@at.atwola.com.

    Checked google for something about it and found that it is on the mozilla support forum as of today (oct.19) and 13 ppl have reported it today, so it looks like this is just coming up and I want Norton to be aware of it... so I don't get fired for leaking.

     

    Cheers



  • 2.  RE: Firefox specific exploit popped up today, no solutions yet

    Posted Oct 19, 2010 03:16 PM

    Thanks for heads up..but things like these can be protected in only 2 ways

    User Awareness--Do not open/download from unknown websites

    Hardening--Hardening you machines with strict firewall,Application Control rules.



  • 3.  RE: Firefox specific exploit popped up today, no solutions yet

    Posted Oct 19, 2010 03:53 PM

    I edited your link so our users do not click on it by mistake. In the future , please don't put the full URL to malicious sites in the forum.

    Norton Safe Web shows that site as a security risk.

    http://safeweb.norton.com/report/show?url=antimalware-updates.is.com

    You might consider adding our Norton Safe Web Lite add-on to your browser(s). Norton Safe Web Lite provides a safer search experience by warning you of dangerous Web sites right in your search results, so you can search, browse, and shop online without worry.

     

    http://safeweb.norton.com/lite

     

    Thanks,

    Thomas



  • 4.  RE: Firefox specific exploit popped up today, no solutions yet

    Posted Oct 19, 2010 09:33 PM

    File submitted to Symantec

    Only 6/43 from VirusTotal

    http://www.virustotal.com/file-scan/report.html?id=cd0612566db66dc424b86abc7afaebe40a3c9e49e54e0f2b57be4ac1215af15b-1287537539

    This particular file appears to be the always exciting FakeAV, called Security Tool. Installed via drive-by download



  • 5.  RE: Firefox specific exploit popped up today, no solutions yet

    Posted Oct 20, 2010 09:34 AM

    Thanks guys, this is some good information.



  • 6.  RE: Firefox specific exploit popped up today, no solutions yet

    Posted Oct 20, 2010 12:03 PM

    Good news:

     

    File1: ff_secure_upd.exe (958464 bytes)
    MD5: 497374870EB0D3D1556F5988B3C7ABDA
    SHA-1: 51103BC049B5E90008E608D39BAF64D7AFC2C834
    SHA-256: CD0612566DB66DC424B86ABC7AFAEBE40A3C9E49E54E0F2B57BE4AC1215AF15B
    Machine: Machine
    Determination: Detected
    Determination Detail: This file will be detected as 'SecurityToolFraud, ' with a forthcoming Rapid Release definition set. Protection will be available in Rapid Release definitions with a sequence number of 116308 or greater.
    Signature Protection Name: SecurityToolFraud


  • 7.  RE: Firefox specific exploit popped up today, no solutions yet

    Posted Oct 21, 2010 07:47 AM

    We had an infected PC with the FakeAV trojan (generic). I'm thinking it was related to a driveby install from seeksearchsite<dot>com. Just thought, I throw that out there for people to be aware.

     



  • 8.  RE: Firefox specific exploit popped up today, no solutions yet

    Posted Oct 21, 2010 07:50 AM

    Drive-by malware is the latest craze and only going to get worse.

    Take a look at BLADE:

    http://www.blade-defender.org/



  • 9.  RE: Firefox specific exploit popped up today, no solutions yet

    Posted Oct 21, 2010 10:46 AM

    Nice, thanks!



  • 10.  RE: Firefox specific exploit popped up today, no solutions yet

    Posted Oct 21, 2010 11:08 AM

    More social engineering/trickery, I believe.  Security Response did a blog entry on this recently (4 Oct).

    Misleading Apps Push Browser Security Update Trick
    https://www-secure.symantec.com/connect/blogs/misleading-apps-push-browser-security-update-trick

    sandra