<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<atom:link href="http://www.securelist.com/en/rss/latesthackeranalysis" rel="self" type="application/rss+xml" />
<title>Securelist / Blog</title>
<link>http://www.securelist.com/en/</link>
<description></description>
<lastBuildDate>17 May 2012 06:29:43 +0400</lastBuildDate>
<image>
<title>Securelist / Blog</title>
<url>http://www.securelist.com/en/rss/klogo.gif</url>
<link>http://www.securelist.com/en/</link>	
</image>
	<item>
		<author>webmaster@securelist.com (Dmitry Bestuzhev)</author>
		<description>    &lt;a href=&quot;https://secure.wikimedia.org/wikipedia/en/wiki/Carolina_Dieckmann&quot;&gt;Carolina Dieckmann&lt;/a&gt;, a famous Brazilian actress, recently became the victim of cyber attacks that allowed cybercriminals to steal personal property - nude pictures of her- from her computer. Many pictures or maybe all of them got leaked to the Internet. This incident has served as a good incentive for the Brazilian government to have new cybercrime laws in the country (the current law to fight cybercrime in Brazil was approved back in the 40&amp;#8217;s of XX century). As a result of this incident, a new cybercrime law that carries a punishment of up to 2 years in prison for such crimes has finally been proposed for consideration. This is a good and right move! A press article in Portuguese can be</description>
		<guid>http://www.securelist.com/en/blog/208193496/Carolina_Dieckmann_Brazilian_cybercrime_legislation_and_la_Viveza_criolla</guid>
		<link>http://www.securelist.com/en/blog/208193496/Carolina_Dieckmann_Brazilian_cybercrime_legislation_and_la_Viveza_criolla</link>
		<pubDate>16 May 2012 22:58:22 +0400</pubDate>
		<title>Carolina Dieckmann, Brazilian cybercrime legislation and la &#8220;Viveza criolla&#8221;</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Dmitry Bestuzhev)</author>
		<description>    &lt;span style=&quot;font-weight: bold; font-style: italic;&quot;&gt;&amp;#8220;Forgetting&amp;#8221;&lt;/span&gt; or &lt;span style=&quot;font-weight: bold; font-style: italic;&quot;&gt;&amp;#8220;underestimating&amp;#8221;&lt;/span&gt; are the main reasons for data loss around the world. In an airport lounge during my last trip I came across  some cool tab devices running on Android integrated with an external keyboard available for public use and connected to the Internet.     &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193495.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;a href=&quot;http://www.securelist.com/en/blog/396/Your_very_own_personal_Wiki_leaks&quot;&gt;As in the past&lt;/a&gt; I performed a quick check of downloaded files, most visited sites and browser history and found a huge list of sensitive information. Here are some examples:  &lt;ul style=&quot;font-style: italic;&quot;&gt;   &lt;li&gt;Access via OWA to a corporate email of a Latin American bank.&lt;/li&gt; &lt;li&gt;Medical files from Spanish hospitals.&lt;/li&gt; &lt;li&gt;Commercial offers with personal banking information of a service provider.&lt;/li&gt; &lt;li&gt;Personal traveller information with full names, IDs, frequent flyer number and the destination of the flight. &lt;/li&gt; &lt;li&gt;Audit control released by a Latin American government to local companies. &lt;/li&gt; &lt;/ul&gt; I didn&amp;#8217;t check if the browser function &amp;#8220;save passwords&amp;#8221; was enabled. &lt;span style=&quot;font-style: italic;&quot;&gt;Just imagine if it was!&lt;/span&gt; I also didn&amp;#8217;t check the saved cookies. Anyway enough sensitive information was already exposed out there.     Lots of people are not very good at safeguarding their personal information on standard PCs; they are even worse when it comes to tab computers. More often than not, they just don&amp;#8217;t know where a file was downloaded on a tab, and they have no idea how to delete it afterwards.     I wonder how much sensitive information is already exposed in this way at airports around the globe! Without any doubt it&amp;#8217;s a huge advantage for cybercriminals who know how to use social engineering and a big pain for security officers of the companies who have to train employees. Another important point is when people fly on business - they are usually managers, so any leaked information can compromise not only their personal identity but also a company&amp;#8217;s secrets.  </description>
		<guid>http://www.securelist.com/en/blog/208193494/Public_points_of_data_loss</guid>
		<link>http://www.securelist.com/en/blog/208193494/Public_points_of_data_loss</link>
		<pubDate>14 May 2012 15:18:34 +0400</pubDate>
		<title>Public points of data loss</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Roel)</author>
		<description>&lt;p&gt;At the recent SOURCE Boston conference, one presentation that caught my attention was called &lt;a href=&quot;http://www.sourceconference.com/boston/speakers_2012.asp#iamit&quot;&gt;SexyDefense - Maximizing the home-field advantage&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;p&gt;This was quite a thought-provoking &lt;a href=&quot;http://www.sourceconference.com/publications/bos12pubs/Amit%20-%20SexyDefense.pdf&quot;&gt;presentation&lt;/a&gt; that was based on the old concept that offense is always the best defense.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193493/Is_SexyDefense_The_Future_of_Anti_Espionage</guid>
		<link>http://www.securelist.com/en/blog/208193493/Is_SexyDefense_The_Future_of_Anti_Espionage</link>
		<pubDate>01 May 2012 22:39:58 +0400</pubDate>
		<title>Is &#8216;SexyDefense&#8217; The Future of Anti-Espionage?</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Kurt Baumgartner)</author>
		<description>&lt;P&gt; The Fbi's &quot;Operation Ghost Click&quot; announcement in Nov 2011, involving the Rove Digital botnet delayed cleanup efforts that we &lt;a href=http://www.securelist.com/en/blog/208193404/DNSChanger_Cleaning_Up_4_Million_Infected_Hosts target=_blank&gt;previously discussed&lt;/a&gt;, continues to haunt both the internet networks and the mass media. A &lt;a href=http://www.forbes.com/sites/adriankingsleyhughes/2012/04/23/fbi-disinfect-your-computer-or-risk-losing-internet-access-come-july/ target=_blank&gt;Forbes article &lt;/a&gt;and a &lt;a href=http://techland.time.com/2012/04/23/dnschanger-fbi-warns-infected-computers-will-lose-web-email-access-in-july/ target=_blank&gt;Times article &lt;/a&gt;  yesterday brought the apparition back to the front, with some claiming that the site offered by the DNSChanger Working Group is a new one, which it is not. The 2011 Operation being described, and the temporarily outsourced DNS server replacements and delayed cleanup, is the same. This phantom is nothing supernatural, so why all the discussion? The federal judge's extension allowing the Fbi to run these replacement DNS servers still cuts off access in early July. When those replacement servers are removed in early July, the infected systems resolving DNS queries at these previously-owned Rove Digital servers will simply not be able to resolve DNS requests. July 9th will arrive soon, and notifications continue to go out related to the hundreds of thousands of systems in the US alone that are still infected. &lt;/P&gt; &lt;P&gt; In the simplest terms, connectivity will not be severed for DNSChanger-infected systems, but internet communications will not function for infected systems that have not been cleaned up. In the US, government agencies, home users, and other organizations still infected with the malware will have systems that effectively can't get online, can't send email, etc. It will look like they are connected to their network, but they just won't communicate with anything. &lt;/P&gt; &lt;P&gt; At the same time, there seems to be issues with some existing identification efforts. Yesterday, I infected a system with DNSChanger and visited dns-ok.us. Results here: &lt;/P&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193492.PNG&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;P&gt; Regarding the dns-ok site visit, my ISP's support team isn't aware of any &quot;DNS redirections&quot; that would cause the test to fail, and I will update this post with any update from our network admin that they are redirecting my system's dns queries. But that piece is highly doubtful. My point here is that infected system owners may be confused by &lt;a href=http://www.dns-ok.us/ target=_blank&gt;this check&lt;/a&gt;. And the ip address was within the Fbi-provided ranges run by Rove Digital - perhaps a reader knows differently? &lt;BR&gt; UPDATE (1:40 p.m. MST) - I received some details from my local ISP network admin. They are not redirecting any related DNS queries. However, one of their large upstream providers is redirecting DNS requests to another DNS server of their own. The other upstream link to the net does not seem to be re-routing DNS requests. So my infected client's traffic must be favoring routes through the larger upstream provider, and poof, the green/clean response banner appears. Any way you look at it, the response from the site can be inconsistent - sometimes red, sometimes green. Unfortunately, this sort of situation is going to confuse cleanup efforts. So, here we are again. To the potentially millions of folks running DNSChanger infected systems and are listening to the cacophony of incident responder consultants tossing out cheap cynicism that &quot;AV is dead!&quot;, go ahead and download an &quot;&lt;a href=http://www.dcwg.org/fix/ target=_blank&gt;AV product&lt;/a&gt;&quot; to scan your system. Of course, I like recommending our scanners (just visit http://www.kaspersky.com) because I have cleaned up DNSChanger infected systems with it (and the products have fully functional trial periods), along with our TDSSKiller rootkit removal tool to clean up especially complex DNSChanger infections. &lt;/P&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193491/Update_to_DNSChanger_Cleaning_Up_4_Million_Infected_Hosts</guid>
		<link>http://www.securelist.com/en/blog/208193491/Update_to_DNSChanger_Cleaning_Up_4_Million_Infected_Hosts</link>
		<pubDate>24 Apr 2012 21:22:24 +0400</pubDate>
		<title>Update to &quot;DNSChanger - Cleaning Up 4 Million Infected Hosts&quot;</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Kurt Baumgartner)</author>
		<description>&lt;P&gt; Market share! It&amp;#8217;s an easy answer, but not the only one. &lt;/P&gt; &lt;P&gt; In 2011, Apple was estimated to account for over 5% of worldwide desktop/laptop market share. This barrier was a significant one to break - Linux maintains under 2% market share and Google ChromeOS even less. This 15 year peak coincided with the first exploration by the aggressive FakeAv/Rogueware market targeting Apple computers, which we discovered and posted &lt;a href=http://www.securelist.com/en/blog/6178/Odd_FakeAv_Marketing target=_blank&gt;in April 2011&lt;/a&gt; and later &lt;a href=https://www.securelist.com/en/blog/6211/Rogueware_campaign_targeting_Mac_users target=_blank&gt;in May 2011&lt;/a&gt;, which no longer seem to be such an odd coincidence. Also, the delay in Apple malware until now most likely was not because Apple exploits were unavailable, or because the Mac OS X system is especially hardened. The 2007 &quot;Month of Apple Bugs&quot; demonstrated that the Mac OS X and supporting code is full of exploitable flaws. Safari, Quicktime, and other software on Apple devices is regularly exploited during pwnage contests, but widespread cybercrime attention hadn&amp;#8217;t caught on until this past year. &lt;/P&gt;  &lt;P&gt; At this point, we still don't know who is behind Flashfake, so we don&amp;#8217;t know for sure that they were the same Mac OS X FakeAv/Rogueware group. Speculating that eastern euro-cybercrime is behind the botnet would be a pretty confident way to go right now. There are known groups from the region that have succeeded at wringing ad revenues from traffic hijacking. We don't believe that other sensitive data has been targeted. And the exploit distribution URLs that we are aware of have only targeted mac users. These factors limit the operational and technical needs of a financially motivated cybercrime gang. &lt;/P&gt; &lt;P&gt; In a sense, it would appear that their activity was somewhat similar to the Koobface or Tdss gangs. They haven't commited large unique financial crimes to attract the attention of law enforcement, and their malware contains hooks and other code to perform more sophisticated banking crime than search traffic hijacking, but they most likely were looking to make a multitude of small financial gains. On the other hand, thankfully, Apple hasn't given these guys ample notice to make their run. There can be plenty of money in that business - it is estimated that the Koobface guys ran off with millions after Facebook &quot;outted&quot; their operation under investigation. But based on the domain registrations we have examined, the individuals are not quite so public and they are hiding their identities while they hijack search engine traffic. The malware itself injects a number of hooks into running applications, much like the Zeus, SpyEye, and other spyware. If these were used for financial crimes, the group operating this botnet would need to organize money mules and accomplices to launder their stolen money, which would grow the group and attract the attention of other authorities. &lt;/P&gt; &lt;P&gt; On the technology side, Java is a big part of the puzzle. Although the Trojan is called Flashfake because users were being convinced to install the malware as an Adobe Flash update, more recent versions of the malware were being installed via client-side Java exploitation.  &lt;/P&gt; &lt;P&gt; Three vulnerabilities were targeted with client-side exploits, none of them were 0day, which seem to have become much more difficult to come by. Besides, this set worked just as well for these operators. It is interesting to note the duration of time from the original Oracle Java security update to the Apple Java security update, and when in that timeframe the release offensive security research publicly appeared. And, when were Metasploit open source exploit modules were released targeting the related Java vulnerabilities? The windows of time may be alarming - these are not 0day exploits, but Apple simply hasn&amp;#8217;t released patches, leaving their customers exposed to the equivalent of known 0day exploits. &lt;/P&gt; &lt;P&gt;  &lt;a href=http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0507 target=_blank&gt;CVE-2012-0507&lt;/a&gt; &lt;/P&gt; &lt;P&gt;  2012-02-15 Oracle patches &lt;a href=http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html target=_blank&gt;Atomic Reference Array vulnerability&lt;/a&gt;  &lt;/P&gt; &lt;P&gt; 2012-03-10 First Itw exploits targeting the vuln  &lt;/P&gt; &lt;P&gt; 2012-03-30 Metasploit developers  &lt;a href=https://community.rapid7.com/community/metasploit/blog/2012/03/29/cve-2012-0507--java-strikes-again https://github.com/rapid7/metasploit-framework/commit/f069a3222359908afec6c6366c0c27244cc18cb6 target=_blank&gt;add Java atomicreferencearray exploit module&lt;/a&gt;  &lt;/P&gt; &lt;P&gt; 2012-04-03 Apple &lt;a href=http://support.apple.com/kb/HT5228  target=_blank&gt;patches their code&lt;/a&gt;  &lt;/P&gt; &lt;P&gt;&lt;a href=http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3544  target=_blank&gt;CVE-2011-3544&lt;/a&gt; &lt;/P&gt; &lt;P&gt; 2011-05-12 &lt;a href=http://www.zerodayinitiative.com/advisories/ZDI-11-305/ target=_blank&gt;Reported to vendor&lt;/a&gt;  &lt;/P&gt; &lt;P&gt; 2011-11-18 Oracle &lt;a href=http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html target=_blank&gt;patched their Java SE&lt;/a&gt;  &lt;/P&gt; &lt;P&gt; 2011-11-30 Metasploit developers &lt;a href=https://community.rapid7.com/community/metasploit/blog/2011/11/30/test-results-for-javarhino http://schierlm.users.sourceforge.net/CVE-2011-3544.html target=_blank&gt;add &quot;Rhino exploit&quot; module&lt;/a&gt;  &lt;/P&gt; &lt;P&gt; 2011-11-30 Krebs reports operational Blackhole site with the    &lt;a href=http://krebsonsecurity.com/2011/11/public-java-exploit-amps-up-threat-level/ target=_blank&gt;new Java exploit&lt;/a&gt; &lt;/P&gt; &lt;P&gt; 2012-3-29 &lt;a href=http://support.apple.com/kb/HT5045 target=_blank&gt;Patched by Apple&lt;/a&gt;  &lt;/P&gt; &lt;P&gt; &lt;a href=http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5353 target=_blank&gt;CVE-2008-5353&lt;/a&gt;  &lt;/P&gt; &lt;P&gt; &quot;Deserializing Calendar objects&quot; &lt;/P&gt; &lt;P&gt; 2008-08-01  Reported to Sun with &lt;a href=http://slightlyrandombrokenthoughts.blogspot.com/2008/12/calendar-bug.html target=_blank&gt;first instance of the vulnerability&lt;/a&gt; &lt;/P&gt; &lt;P&gt; 2008-12-03 Sun patches their code  (Sun link down) &lt;/P&gt; &lt;P&gt;  2009-05-15 Apple &lt;a href=http://support.apple.com/kb/HT3632  target=_blank&gt;patches MacOSX code&lt;/a&gt;  &lt;/P&gt; &lt;P&gt; 2009-06-16 Metasploit developers &lt;a href=http://dev.metasploit.com/redmine/projects/framework/repository/changes/modules/exploits/multi/browser/java_calendar_deserialize.rb target=_blank&gt;add Java deserialization exploit&lt;/a&gt;  &lt;/P&gt; &lt;P&gt; Also on this list &lt;a href=http://dev.metasploit.com/redmine/projects/framework/repository/entry/modules/exploits/multi/browser/java_signed_applet.rb target=_blank&gt;is a lame exploit&lt;/a&gt; described as a signed applet social engineering trick.  &lt;/P&gt; &lt;P&gt; I'd prefer to call it the &quot;the terribly confused user presented with the Java 'do you want to trust this applet?' dialog and will run anything you present them&quot; gamble. It first became a part of the Metasploit exploit module list on 2010-01-27. Basically, these guys present the user with a file that the user thinks is a JavaUpdate provided by Apple Inc themselves, which they grant trust to perform any action on their machine. The downloader will then communicate with a couple of sites to register and download new Flashfake components. These components in turn, collect the system UUID and timestamp, then auto-generate with a crypto algorithm a set of C2 domains, along with maintaining a list of hard coded domains. A couple of the newer components inject into running processes on the system hooking software functionality and hijacking traffic, much like past TDS malware. &lt;/P&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193490/OS_X_Mass_Exploitation_Why_Now</guid>
		<link>http://www.securelist.com/en/blog/208193490/OS_X_Mass_Exploitation_Why_Now</link>
		<pubDate>19 Apr 2012 17:32:33 +0400</pubDate>
		<title>OS X Mass Exploitation - Why Now?</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Kurt Baumgartner)</author>
		<description>&lt;P&gt; Dan Geer's fantastic &lt;a href=http://geer.tinho.net/geer.sourceboston.18iv12.txt target=_blank&gt;Keynote Speech&lt;/a&gt;  kicked off Day 2 of SOURCE Conference Boston this morning. The talk itself was heady and complex, something to keep up with. Notable talks also were Jeremey Westerman's &quot;Covering *aaS - Cloud Security Case Studies for SaaS, PaaS and IaaS&quot;, and Dan Rosenberg's &quot;Android Modding for the Security Practitioner&quot;. &lt;/P&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193487.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;P&gt; &quot;The internet will never be as free as it is this morning.&quot; Dan Geer is one of the best, sharpest  computing/network security speakers around. His talk descended from a high-level, lengthy, example-laden description of most every developed nation's dependency on the internet: &quot;Dependence with respect to the internet is transitive, dependence on television is not...We are at the point where it may no longer be possible to live your life without having a critical dependence on the Internet, even if you live at the end of a dirt road but still occasionally buy nails or gasoline.&quot; And, he wound through multiple examples of failures in US systems to provide fallback options. He talked about his little local bank, whom he wrote a letter to close down the auto-created online account he wouldn't use. They, as an exception, closed it down immediately. His 401k account administrator Fidelity Investments, on the other hand, would not accept customer instructions from him in writing. The company continues to send him mailed marketing content of all kinds in writing at the address from which he sends his letters. Their auditors apparently approve of Fidelity's rejection of customer-initiated hand-written delivered communications, instead, accepting email/online chat messaging or instructions over the phone. This discussion made its way through systems design, unified field theory, and fault tolerance, eventually landing on key points that intrusion prevention is agreed not to be a workable model, instead, the elegance of &quot;intrusion tolerance&quot; must be built into systems, and countries and organizations that cannot build tolerance into their systems are not sustainable. Favorite quotes: &quot;forget the banks, it is the internet that is too big to fail&quot;, &quot;Is there room for those who choose simply to not participate in the internet?&quot;, &quot;HTML5 is Turing complete. HTML4 is not&quot;, and &quot;Should we preserve a manual means? Preserving fallback is prudent if not essential.&quot; &lt;/P&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193489.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;P&gt; Jeremy Westerman's &quot;Covering *aaS - Cloud Security Case Studies...&quot; presented several design cases for Universities and other organizations. The single most important point to learn from this talk is that API key management is unfortunately not handled with as much urgency and awareness as private SSL keys for large organizations. This API key, in the context of multiple, popular single sign-on (SSO) solutions in use at large universities, is the key to tens of thousands, if not hundreds of thousands, of email accounts. Similar API key schemes are implemented on IaaS solutions like the Xen supported Amazon EC2 environment and VMWare vCloud Teramark environments. Without appropriate awareness, developers are storing that key in improper locations like the hard drive of the sign-on machine, or the developers themselves are storing keys on their development system hard drives in non-obvious places, emailing/&quot;dropboxing&quot; them around to each other and then simply transferring the API keys to the production environment, instead of re-issuing production API keys. It is practically imperative that these keys are taken out of the hands of developers. These loose handling practices are bad news - viral code like Sality and other viral code and worms previously high in our prevention stats have maintained functionality to steal FTP and web admin account passwords in order to silently host malicious code, encrypted or otherwise, on legitimate web sites without the owner's knowledge. In other words, developers have been effective and weak targets in the past for credential theft, enabling silent site compromise and malicious use. Most schools don't want that - I remember one unfortunate notification at a small Arts college, where the web admin really didn't want to believe that the encrypted blob of data hosted on his school's web server was a viral payload updating other students' infected systems, located there because his credentials were Sality-stolen after trying to run cracked software distributed over a P2P network. Anyway, it happens and it can be planned for and prevented. &lt;/P&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193484/SOURCE_Boston_Security_Conference_and_Training_2012_Day_2_Dan_Geer_Keynote_Android_Modding_and_Cloud_Security</guid>
		<link>http://www.securelist.com/en/blog/208193484/SOURCE_Boston_Security_Conference_and_Training_2012_Day_2_Dan_Geer_Keynote_Android_Modding_and_Cloud_Security</link>
		<pubDate>19 Apr 2012 07:46:09 +0400</pubDate>
		<title>SOURCE Boston Security Conference and Training 2012 Day 2 - Dan Geer Keynote, Android Modding and Cloud Security</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Nicolas Brulez)</author>
		<description>&lt;p&gt;Early today, Kaspersky Lab discovered a new ongoing spam campaign on Twitter. hundreds of compromised accounts are currently spamming malicious links, hosted on .TK and .tw1.su domains, leading to Rogue Anti Virus softwares.&lt;/p&gt;&lt;p&gt;&lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193478.jpg&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;Here is an analysis of the infection at a given time. Keep in mind that it is just a snapshot of the infection, and that the numbers are actually lower than reality.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193477/New_Spam_campaign_on_Twitter_Leads_to_Rogue_AV</guid>
		<link>http://www.securelist.com/en/blog/208193477/New_Spam_campaign_on_Twitter_Leads_to_Rogue_AV</link>
		<pubDate>18 Apr 2012 20:17:31 +0400</pubDate>
		<title>New Spam campaign on Twitter Leads to Rogue AV</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Kurt Baumgartner)</author>
		<description>&lt;P&gt;2012 SOURCE Boston kicked off the first of three days with an opening talk on hacktivism and the Anonymous movement, Costin Raiu and Vitaly Kamluk presented the latest in Duqu C2 research, and Vercode's Shyama Rose talked about designing and building out strategic programs for complex organizations. It's a difficult subject to get right, finding the right fit, the right competence, avoiding hype, and getting these folks to work together to build the right implementation requires all sorts of magic that fly over the heads of many technical solution focused folks. &lt;/P&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193475.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;P&gt; There were many others, but I thought that the most interesting talks included the full assessment of the ~Duqu operators' C2 infrastructure and a review of the comical mistakes and activities of this group of humans working under pressure. Kaspersky's Vitaly Kamluk included a review of the ~Duqu targets and delivery, and binaries. Hard to pick, but I suppose that the most interesting thing here is the visualization providing more proof that ~Duqu is the 2008 precursor to ~Stuxnet, found in Iran, Sudan, and a few European countries. Costin Raiu focused on the C2 and infrastructure itself. Because Kaspersky Lab was able to gain access to 6 of the 10 C2 servers, our research team was able to comb through the trail of bits on these hard drives. Implications of the data left behind led to statements about login times, informed speculation of the location and workday schedule of the attackers, the (sometimes lack of) experience of the operators, and tools used to assess the data were all provided. If you haven't seen this one, it's really good. And who knew full on nation state cyber-conflict C2 operations could be so comical? The whole room was laughing along at the unexpected junior operator mistakes that turned up during the sensitive Duqu operation. &lt;/P&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193476.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;P&gt; Also very interesting was the Shyama Rose presentation on strategically building a successful security program. It's not often that security conference speakers include real world operational talks that discuss culture and fit within development and security teams. And it is operations that can break defender successes quickly. She discussed distributed vs. centralized security team models and their application, significant buy-in from executives and development teams, and how to get these strategic security programs done successfully.  &lt;/P&gt; &lt;P&gt; I personally am most excited that Dan Geer is speaking tomorrow for the conference second day keynote. The guy developed a bit of a following on the DailyDave list with incredibly insightful comments on the world of technical and operational security that you don't get anywhere else. He's a wicked good thinker and speaker. We'll have more later. &lt;/P&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193474/SOURCE_Boston_Security_Conference_and_Training_2012_Hacktivism_Duqu_and_Building_Successful_Security_Programs</guid>
		<link>http://www.securelist.com/en/blog/208193474/SOURCE_Boston_Security_Conference_and_Training_2012_Hacktivism_Duqu_and_Building_Successful_Security_Programs</link>
		<pubDate>18 Apr 2012 09:47:01 +0400</pubDate>
		<title>SOURCE Boston Security Conference and Training 2012 - Hacktivism, Duqu and Building Successful Security Programs</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Costin Raiu)</author>
		<description>Late last week, &lt;a href=&quot;https://www.securelist.com/en/blog/208193467/SabPub_Mac_OS_X_Backdoor_Java_Exploits_Targeted_Attacks_and_Possible_APT_link &quot;&gt;we found evidence&lt;/a&gt; of a possible link between a Mac OS X backdoor trojan and an APT attack known as &lt;a href=http://t.co/BYJ1lnBX&gt;LuckyCat&lt;/a&gt;. The IP address of the C&amp;C to which this bot connects (199.192.152.*) was also used in other Windows malware samples during 2011, which made us believe we were looking at the same entity behind these attacks. &lt;p&gt;  For the past two days, we have been monitoring a &amp;#8220;fake&amp;#8221; infected system - which is a typical procedure we do for APT bots. We were extremely surprised when during the weekend, the APT controllers took over our &amp;#8220;goat&amp;#8221; infected machine and started exploring it. &lt;p&gt; On Friday Apri 13, port 80 on the C&amp;C server located at rt*****.onedumb.com and hosted on a VPS in Fremont, U.S. was closed. Saturday, the port was opened and bot started communicating with the C&amp;C server. For the entire day, the traffic was just basic handshakes and exchanges, nothing more. &lt;p&gt; On the morning of Sunday April 15, the traffic generated by the C&amp;C changed. The attackers took over the connection and started analysing our fake victim machine. They listed the contents of the root and home folders and even stole some of the goat documents we put in there!</description>
		<guid>http://www.securelist.com/en/blog/208193470/New_Version_of_OSX_SabPub_Confirmed_Mac_APT_attacks</guid>
		<link>http://www.securelist.com/en/blog/208193470/New_Version_of_OSX_SabPub_Confirmed_Mac_APT_attacks</link>
		<pubDate>16 Apr 2012 01:17:24 +0400</pubDate>
		<title>New Version of OSX.SabPub &amp; Confirmed Mac APT attacks</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Costin Raiu)</author>
		<description>Last week, Apple released two urgent updates to Mac OS X to: &lt;p&gt;  1. Remove the Flashback malware about which we have already &lt;a href=&quot;http://www.securelist.com/en/blog/208193441/Flashfake_Mac_OS_X_botnet_confirmed&quot;&gt;written&lt;/a&gt; &lt;p&gt; 2. Automatically deactivate the Java browser plugin and Java Web Start, effectively disabling java applets in browsers &lt;p&gt;   Particularly, the second step shows the severity of the &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0507&quot;&gt;CVE-2012-0507 vulnerability&lt;/a&gt; exploited by Flashback to infect almost 700,000 users via drive-by malware downloads. &lt;p&gt; Actually, it was the right decision because we can confirm yet another Mac malware in the wild - &lt;b&gt;Backdoor.OSX.SabPub.a&lt;/b&gt; being spread through Java exploits. &lt;p&gt; This new threat is a custom OS X backdoor, which appears to have been designed for use in targeted attacks. After it is activated on an infected system, it connects to a remote website in  typical C&amp;C fashion to fetch instructions. The backdoor contains functionality to make screenshots of the user&amp;#8217;s current session and execute commands on the infected machine. &lt;p&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193468.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;Backdoor connects to remote server to fetch work&quot;&gt;&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193467/SabPub_Mac_OS_X_Backdoor_Java_Exploits_Targeted_Attacks_and_Possible_APT_link</guid>
		<link>http://www.securelist.com/en/blog/208193467/SabPub_Mac_OS_X_Backdoor_Java_Exploits_Targeted_Attacks_and_Possible_APT_link</link>
		<pubDate>14 Apr 2012 18:59:48 +0400</pubDate>
		<title>SabPub Mac OS X Backdoor: Java Exploits, Targeted Attacks and Possible APT link</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Kurt Baumgartner)</author>
		<description>&lt;P&gt; This month's patch Tuesday fixes a small set of critical vulnerabilities in a variety of client side software and one &quot;important&quot; server side Forefront UAG data leakage/information disclosure issue. Six bulletins have been created to address eleven exploitable flaws. Three of the six bulletins are top priority and should be addressed ASAP. These are the MS12-023 bulletin, patching a set of five Internet Explorer vulnerabilities leading to remote code execution, and the MS12-027 bulletin, patching the MSCOMCTL ActiveX Control currently receiving some attention as a part of very limited targeted attacks. If they must prioritize deployment, administrators should start their work here. Most folks should have automatic updates enabled and will silently receive the patches, or they can simply navigate their start menu and manually begin the Windows update process. &lt;/P&gt; &lt;P&gt; RCE attacks abusing these six IE and ActiveX vulnerabilities would look like web browser redirections to malicious sites hosting web pages attacking Internet Explorer and emails carrying malicious attachments constructed to appear familiar to the targeted victim. These are currently significant vectors of attack for both consumer/home and corporate Microsoft product users.  &lt;/P&gt; &lt;P&gt; Microsoft also is recommending that administrators prioritize the Authenticode flaw and rated it critical, which could be used as a part of targeted attacks. And ActiveX controls can be delivered leveraging this vulnerability, so some distribution vectors may become enhanced. But this flaw allows for additions and modifications to existing code that in turn won't invalidate the existing signature.  &lt;/P&gt; &lt;P&gt; A vulnerability exists in the .Net framework, allowing for XBAP applications to be run from the Internet Zone with a prompt. But anytime a decision like that is left to a user, it seems that we have a 50/50 chance of successful exploitation. The remaining vulnerabilty in the Office converter is significant and may result in RCE, but is much less likely to be attacked. &lt;/P&gt; &lt;P&gt; Dangerous, but manageable. &lt;/P&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193459/Patch_Tuesday_April_2012_Patching_Multiple_Web_Based_Client_Side_and_Spearphishing_Exposures</guid>
		<link>http://www.securelist.com/en/blog/208193459/Patch_Tuesday_April_2012_Patching_Multiple_Web_Based_Client_Side_and_Spearphishing_Exposures</link>
		<pubDate>10 Apr 2012 21:30:04 +0400</pubDate>
		<title>Patch Tuesday April 2012 - Patching Multiple Web Based Client Side and Spearphishing Exposures</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Tim)</author>
		<description>&lt;p&gt;I really like the new app by OMGPOP called Draw Something. I play this game with my friends possibly a little too much. Draw Something has attracted more than 50 million downloads, and was just acquired by Zynga for $200 million dollars. It was surprising the other day when I noticed an advertisement at the bottom of the screen for a battery optimizer app. In fact it even told me two upgrades were available!&lt;/p&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193461.jpg&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193460/Beware_of_deceptive_in_app_advertising</guid>
		<link>http://www.securelist.com/en/blog/208193460/Beware_of_deceptive_in_app_advertising</link>
		<pubDate>10 Apr 2012 20:51:24 +0400</pubDate>
		<title>Beware of deceptive in-app advertising</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Aleks)</author>
		<description>&lt;p&gt; After intercepting one of the domain names used by the Flashback/Flashfake Mac Trojan and setting up a special sinkhole server last Friday, we managed to gather stats on the scale and geographic distribution of the related botnet. We published information on this in our &lt;a href=http://www.securelist.com/en/blog/208193441/Flashfake_Mac_OS_X_botnet_confirmed&gt;previous blog&lt;/a&gt; entry.&lt;/p&gt; &lt;p&gt; We continued to intercept domain names after setting up the sinkhole server and we are currently still monitoring how big the botnet is. We have now recorded a total of 670,000 unique bots. Over the weekend (7-8 April) we saw a significant fall in the number of connected bots: &lt;/p&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193455.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;p&gt; This doesn&amp;#8217;t mean, however, that the botnet is shrinking rapidly - these are merely the numbers for the weekend. &lt;/p&gt; &lt;p&gt; Over the last few days our server has registered all the data sent by bots from the infected computers and recorded their UUIDs in a dedicated database. Based on this information we have set up an online resource where all users of Mac OS X can check if their computer has been infected by Flashback.&lt;/p&gt; &lt;p&gt; To find out if your computer is infected and what to do if it is, visit: &lt;a href=http://flashbackcheck.com&gt;flashbackcheck.com&lt;/a&gt;&lt;/p&gt;  &lt;p&gt; Also users can check if they&amp;#8217;re infected with Flashfake by using Kaspersky Lab&amp;#8217;s &lt;a href=http://support.kaspersky.com/downloads/utils/flashfake_removal_tool.zip&gt;free removal tool&lt;/a&gt;. &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193458.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193454/Flashfake_Removal_Tool_and_online_checking_site</guid>
		<link>http://www.securelist.com/en/blog/208193454/Flashfake_Removal_Tool_and_online_checking_site</link>
		<pubDate>10 Apr 2012 02:08:00 +0400</pubDate>
		<title>Flashfake Removal Tool and online-checking site</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Costin Raiu)</author>
		<description>At the moment, there are more than 100 million Mac OS X users around the world. The number has grown switfly during the past years we expect this growth to continue. Until recently, Mac OS X malware was a somehow limited category and included trojans such as the &lt;a href=&quot;https://www.securelist.com/en/blog/208193404/DNSChanger_Cleaning_Up_4_Million_Infected_Hosts&quot;&gt;Mac OS X version of DNSChanger&lt;/a&gt; and more recently, fake anti-virus/scareware attacks for Mac OS X which boomed in 2011. In September 2011, the first versions of the &lt;a href=&quot;https://www.securelist.com/en/blog/208193441/Flashfake_Mac_OS_X_botnet_confirmed&quot;&gt;Mac OS X trojan Flashback&lt;/a&gt; have appeared, however, they didn&amp;#8217;t really become widespread until March 2012. According to data collected by Kaspersky Lab, almost 700,000 infected users have been counted at the beginning of April and the number could be higher. Although Mac OS X can be a very secure operating systems, there are certain steps which you can take to avoid becoming a victim to this growing number of attacks.  &lt;p&gt;&lt;p&gt; Here&amp;#8217;s our recommendation on 10 simple tips to boost the security of your Mac: &lt;p&gt;&lt;p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193448/10_Simple_Tips_for_Boosting_The_Security_Of_Your_Mac</guid>
		<link>http://www.securelist.com/en/blog/208193448/10_Simple_Tips_for_Boosting_The_Security_Of_Your_Mac</link>
		<pubDate>09 Apr 2012 20:33:00 +0400</pubDate>
		<title>10 Simple Tips for Boosting The Security Of Your Mac </title>
	</item>
	<item>
		<author>webmaster@securelist.com (Igor Soumenkov)</author>
		<description>&lt;p&gt;Earlier this week, Dr.Web &lt;a href=http://news.drweb.com/show/?i=2341&amp;lng=en&amp;c=14&gt;reported&lt;/a&gt; the discovery of a  Mac OS X botnet Flashback (Flashfake). According to their information, the estimated size of this botnet is more than 500, 000 infected Mac machines.&lt;/p&gt; &lt;p&gt; We followed up with an analysis of the latest variant of this bot, &lt;b&gt;Trojan-Downloader.OSX.Flashfake.ab&lt;/b&gt;.&lt;/p&gt;&lt;p&gt; It is being distributed via infected websites as a Java applet that pretends to be an update for the Adobe Flash Player. The Java applet then executes the first stage downloader that subsequently downloads and installs the main component of the Trojan. The main component is a Trojan-Downloader that continuously connects to one of its command-and-control (C&amp;C) servers and waits for new components to download and execute. &lt;/p&gt;&lt;p&gt; The bot locates its C&amp;C servers by domain names, and these names are generated using two algorithms. The first algorithm depends on the current date, and the second algorithm uses several variables that are stored in the Trojan&amp;#8217;s body and encrypted with the computer&amp;#8217;s hardware UUID using RC4 cipher.  &lt;/p&gt; &lt;p&gt; We reverse engineered the first domain generation algorithm and used the current date, 06.04.2012, to generate and register a domain name, &quot;&lt;i&gt;krymbrjasnof.com&lt;/i&gt;&quot;. After domain registration, we were able to log requests from the bots. Since every request from the bot contains its unique hardware UUID, we were able to calculate the number of active bots. Our logs indicate that a total of &lt;b&gt;600 000+&lt;/b&gt; unique bots connected to our server in less than 24 hours. They used a total of &lt;b&gt;620 000+&lt;/b&gt; external IP addresses. More than 50% of the bots connected from the United States.&lt;/p&gt; &lt;p class=c&gt;&lt;a href=http://www.securelist.com/en/pictures/klblog/208193442.png&gt;&lt;img src=&quot;images/pictures/klblog/208193446.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/a&gt;&lt;/p&gt; &lt;center&gt;Geographical distribution of active Flashfake bots&lt;/center&gt;&lt;/p&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193443.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;p&gt;We cannot confirm nor deny that all of the bots that connected to our server were running Mac OS X. The bots can be only identified by a unique variable in their User-Agent HTTP header named &amp;#8220;id&amp;#8221;, the rest of the User-Agent is statically controlled by the Trojan.  See example below:&lt;/p&gt; &lt;p&gt;&lt;font color=green&gt;&lt;i&gt;&quot;Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0.1; sv:2; id:9D66B9CD-0000-5BCF-0000-000004BD266A) Gecko/20100101 Firefox/9.0.1&quot;&lt;/font color&gt;&lt;/i&gt;&lt;/p&gt; &lt;p&gt; We &lt;a href=http://lcamtuf.coredump.cx/p0f3/&gt;have used&lt;/a&gt; passive &lt;a href=http://en.wikipedia.org/wiki/TCP/IP_stack_fingerprinting&gt;OS fingerprinting techniques&lt;/a&gt; to get a rough estimation. More than 98% of incoming network packets were most likely sent from Mac OS X hosts. Although this technique is based on heuristics and can&amp;#8217;t be completely trusted, it can be used for making order-of-magnitude estimates.  So, it is very likely that most of the machines running the Flashfake bot are Macs.&lt;/p&gt; &lt;p class=c&gt;&lt;img src=&quot;http://www.securelist.com/en/images/pictures/klblog/208193447.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;center&gt; Approximate distribution of OSes used to connect to our server&lt;/center&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193441/Flashfake_Mac_OS_X_botnet_confirmed</guid>
		<link>http://www.securelist.com/en/blog/208193441/Flashfake_Mac_OS_X_botnet_confirmed</link>
		<pubDate>06 Apr 2012 20:54:00 +0400</pubDate>
		<title>Flashfake Mac OS X botnet confirmed</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Dmitry Tarakanov)</author>
		<description>&lt;h2&gt;Spam&lt;/h2&gt; &lt;p&gt;On 20 March, we detected a spam campaign targeting passengers of US Airways.  Almost the entire week cybercriminals were sending users the following email allegedly from US Airways:&lt;/p&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193440.jpg&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;p&gt;There is a brief description of the check-in procedure and a confirmation code is provided for online reservation.&lt;/p&gt; &lt;p&gt;The criminals are obviously banking on any recipients flying on the flight mentioned in the email clicking on the link &quot;Online reservation details&quot;.&lt;/p&gt; &lt;p&gt;Different emails contained different links - for example, we noticed the following domains: sulichat.hu, prakash.clanteam.com, panvelkarrealtors.com.&lt;/p&gt; &lt;p&gt;After clicking the link a series of redirects eventually leads to a domain hosting BlackHole Exploit Kit.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193439/A_gift_from_ZeuS_for_passengers_of_US_Airways</guid>
		<link>http://www.securelist.com/en/blog/208193439/A_gift_from_ZeuS_for_passengers_of_US_Airways</link>
		<pubDate>03 Apr 2012 16:58:29 +0400</pubDate>
		<title>A gift from ZeuS for passengers of US Airways</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Stefan Ortloff)</author>
		<description>&lt;p&gt;&lt;b&gt;Q: What is the Hlux/Kelihos botnet?&lt;/b&gt;  A: Kelihos is Microsoft's name for what Kaspersky calls Hlux. Hlux is a peer-to-peer botnet with an architecture similar to the one used for the &lt;a href=http://en.wikipedia.org/wiki/Waledac_botnet&gt;Waledac botnet&lt;/a&gt;. It consists of layers of different kinds of nodes: controllers, routers and workers. &lt;/p&gt; &lt;p&gt;&lt;b&gt;Q: What is a peer-to-peer botnet?&lt;/b&gt;  A: Unlike a classic botnet,  a peer-to-peer botnet doesn't use a centralized command and control-server (C&amp;C). Every member of the network can act as a server and/or client. The advantages from the malicious user&amp;#8217;s point of view is the omission of the central C&amp;C as a single-point-of-failure. From our point of view, this makes it a lot harder to take down this kind of botnet.   Architecture of traditional botnet vs P2P:  &lt;/p&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193435.jpg&quot; border=&quot;1&quot; alt=&quot;Traditional botnet with centralized C&amp;C&quot; title=&quot;Traditional botnet with centralized C&amp;C&quot;&gt;&lt;center&gt;Traditional botnet with centralized C&amp;C&lt;/center&gt;&lt;/p&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193436.jpg&quot; border=&quot;1&quot; alt=&quot;Architecture of a P2P botnet&quot; title=&quot;Architecture of a P2P botnet&quot;&gt;&lt;center&gt;Architecture of a P2P botnet&lt;/center&gt;&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193438/FAQ_Disabling_the_new_Hlux_Kelihos_Botnet</guid>
		<link>http://www.securelist.com/en/blog/208193438/FAQ_Disabling_the_new_Hlux_Kelihos_Botnet</link>
		<pubDate>28 Mar 2012 18:23:04 +0400</pubDate>
		<title>FAQ: Disabling the new Hlux/Kelihos Botnet</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Stefan Ortloff)</author>
		<description>&lt;p&gt;&lt;a href=&quot;http://www.securelist.com/en/en/blog/208193137/Botnet_Shutdown_Success_Story_How_Kaspersky_Lab_Disabled_the_Hlux_Kelihos_Botnet&quot; &gt;Last September&lt;/a&gt;, in partnership with Microsoft&amp;#8217;s Digital Crimes Unit (DCU), SurfNET and Kyrus Tech, Inc., Kaspersky Lab successfully disabled the dangerous Hlux/Kelihos botnet by sinkholing the infected machines to a host under our control.&lt;/p&gt; &lt;p&gt;A few months later, our researchers stumbled upon a new version of the malware with significant changes in the communication protocol and new &amp;#8220;features&amp;#8221; like flash-drive infection, bitcoin-mining wallet theft.&lt;/p&gt; &lt;p&gt;Now, we are pleased to announce that we have partnered with the CrowdStrike Intelligence Team, the Honeynet Project and Dell SecureWorks to disable this new botnet.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193431/Botnet_Shutdown_Success_Story_again_Disabling_the_new_Hlux_Kelihos_Botnet</guid>
		<link>http://www.securelist.com/en/blog/208193431/Botnet_Shutdown_Success_Story_again_Disabling_the_new_Hlux_Kelihos_Botnet</link>
		<pubDate>28 Mar 2012 17:27:10 +0400</pubDate>
		<title>Botnet Shutdown Success Story - again: Disabling the new Hlux/Kelihos Botnet</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Aleks)</author>
		<description>&lt;p&gt;At the end of the last year the authors of Duqu and Stuxnet tried to eliminate all traces of their activity. They wiped all servers that they used since 2009 or even earlier. The cleanup &lt;a href=&quot;http://www.securelist.com/en/blog/625/The_Mystery_of_Duqu_Part_Six_The_Command_and_Control_servers&quot;&gt;happened&lt;/a&gt; on October 20.&lt;/p&gt;&lt;p&gt;&lt;p&gt;There were virtually no traces of Duqu since then. But several days ago our colleagues in Symantec &lt;a href=&quot;http://www.symantec.com/connect/blogs/new-duqu-sample-found-wild&quot;&gt;announced&lt;/a&gt; that they found a new &quot;in-the-wild&quot; driver that is very similar to known Duqu drivers. Previous modifications of Duqu drivers were compiled on Nov 3 2010 and Oct 17 2011, and the new driver was compiled on Feb 23 2012.&lt;/p&gt;&lt;p&gt;&lt;p&gt;So, the authors of Duqu are back after a 4 months break.&lt;/p&gt;&lt;p&gt;&lt;h2&gt;Duqu is back&lt;/h2&gt;&lt;p&gt;&lt;p&gt;The newly discovered driver does not contain any new functionality compared to its previous versions. The code contains only minor modifications, and they were most likely done to evade detection from antivirus programs and detection tools such as the CrySyS Duqu Toolkit. Here&amp;#8217;s a list of changes compared to older versions:&lt;/p&gt;&lt;p&gt;&lt;ul&gt; &lt;li&gt;The code was compiled with different optimization settings and/or inline attributes of functions.&lt;/li&gt; &lt;li&gt;The size of the EXE stub that is injected with the PNF DLL was increased by 32 bytes.&lt;/li&gt; &lt;li&gt;The LoadImageNotifyRoutine routine now compares the module name with &amp;#8220;KERNEL32.DLL&amp;#8221; using hash checksums instead of simple string comparison.&lt;/li&gt; &lt;li&gt;The size of the encrypted configuration block was increased from 428 to 574 bytes. There are no new fields in in the block, but the size of the registry value name (&amp;#8220;FILTER&amp;#8221;) field was increased. This makes the registry value name easily modifiable - probably for future use.&lt;/li&gt; &lt;li&gt;The algorithm of the two subroutines that decrypt the encrypted config block, registry value and PNF DLL has been changed. This is the third known algorithm used in the Duqu encryption subroutines.&lt;/li&gt; &lt;li&gt;The algorithm of the hash function for the APIs has changed. All the hash values were changed correspondingly.&lt;/li&gt; &lt;/ul&gt;&lt;p&gt;&lt;p&gt;Old hash function, used in previous versions of the Duqu driver:&lt;/p&gt;&lt;p&gt;&lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193426.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;New hash function:&lt;/p&gt;&lt;p&gt;&lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193427.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;The fact that the new driver was found in Iran confirms that most of Duqu incidents are related to this country.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193425/The_mystery_of_Duqu_Part_Ten</guid>
		<link>http://www.securelist.com/en/blog/208193425/The_mystery_of_Duqu_Part_Ten</link>
		<pubDate>27 Mar 2012 19:48:00 +0400</pubDate>
		<title>The mystery of Duqu: Part Ten</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Vyacheslav Zakorzhevsky)</author>
		<description>&lt;p&gt;On 20 March, Russian law enforcement agencies announced the arrest of a cybercriminal gang involved in stealing money using the &lt;a href='http://www.securelist.com/ru/blog/207763876/Zaderzhany_grabiteli_rossiyskikh_sistem_DBO'&gt;Carberp Trojan&lt;/a&gt;. This is very good news, but unfortunately does not mark the end of the Carberp story.&lt;/p&gt; &lt;p&gt;&lt;p&gt;Evidently, those arrested were just one of the criminal gangs using the Trojan. At the same time, those who actually developed Carberp are still at large, openly selling the Trojan on cybercriminal forums.&lt;/p&gt;&lt;p&gt;&lt;p&gt;Here is a recent offer for the &amp;#8216;multifunctional bankbot&amp;#8217;, which appeared on 21 March:&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/694/Carberp_its_not_over_yet</guid>
		<link>http://www.securelist.com/en/blog/694/Carberp_its_not_over_yet</link>
		<pubDate>26 Mar 2012 18:59:00 +0400</pubDate>
		<title>Carberp: it&#8217;s not over yet</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Fabio Assolini)</author>
		<description>&lt;p&gt;Since November 2011, according to recent statistics, Google Chrome has become the most popular browser in Brazil (more than 45% of the market share).&lt;/p&gt;&lt;p&gt;&lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193416.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;The same has is true for Facebook, which now is the most popular social network in Brazil, with a total of 42 million users, displacing Orkut.&lt;/p&gt;&lt;p&gt;&lt;p&gt;These two facts are enough to motivate Brazil&amp;#8217;s bad guys to turn their attentions to both platforms. This month we saw a huge wave of attacks targeting Brazilian users of Facebook, based on the distribution of malicious extensions. There are several themes used in these attacks, including &amp;#8220;Change the color of your profile&amp;#8221; and &amp;#8220;Discover who visited your profile&amp;#8221; and some bordering on social engineering such as &amp;#8220;Learn how to remove the virus from your Facebook profile&amp;#8221;:&lt;/p&gt;&lt;p&gt;&lt;p&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193417.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt; &lt;p class=&quot;c&quot;; style=&quot;font-size:8pt;&quot;&gt;&lt;b&gt; 1) Click on Install app, 2) Click on Allow or Continue, 3) Click on Install now, After doing these steps, close the browser and open again&lt;/b&gt;&lt;/p&gt; &lt;p&gt;&lt;p&gt;&lt;p&gt;This last one caught our attention not because it asks the user to install a malicious extension, but because &lt;b&gt;&lt;span style=&quot;font-weight: bold; color: rgb(153, 0, 0);&quot;&gt;the malicious extension it&amp;#8217;s hosted at the official Google's Chrome Web Store&lt;/span&gt;&lt;/b&gt;. If the user clicks on &lt;i&gt;&amp;#8220;Install aplicativo&amp;#8221;&lt;/i&gt; he will be redirected to the official store. The malicious extension presents itself as &amp;#8220;Adobe Flash Player&amp;#8221;:&lt;/p&gt;&lt;p&gt;&lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/208193418.png&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193414/Think_twice_before_installing_Chrome_extensions</guid>
		<link>http://www.securelist.com/en/blog/208193414/Think_twice_before_installing_Chrome_extensions</link>
		<pubDate>23 Mar 2012 21:26:09 +0400</pubDate>
		<title>Think twice before installing Chrome extensions</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Igor Soumenkov)</author>
		<description>&lt;h2&gt;The Quest for Identification&lt;/h2&gt;&lt;p&gt;&lt;p&gt;In my &lt;a href=&quot;http://www.securelist.com/en/blog/667/The_Mystery_of_the_Duqu_Framework&quot;&gt;previous blogpost&lt;/a&gt; about the Duqu Framework, I described one of the biggest remaining mysteries about &lt;a href=&quot;http://www.securelist.com/en/blog?topic=199380362&quot;&gt;Duqu&lt;/a&gt; - the oddities of the C&amp;C communications module which appears to have been written in a different language than the rest of the Duqu code. As technical experts, we found this question very interesting and puzzling and we wanted to share it with the community.&lt;/p&gt;&lt;p&gt;&lt;p&gt;The feedback we received exceeded our wildest expectations. We got more than 200 comments and 60+ e-mail messages with suggestions about possible languages and frameworks that could have been used for generating the Duqu Framework code. We would like to say  a big &amp;#8216;Thank you!&amp;#8217; to everyone who participated in this quest to help us identify the mysterious code.&lt;/p&gt;&lt;p&gt;&lt;p&gt;Let us review the most popular suggestions we got from you:&lt;/p&gt;&lt;p&gt;&lt;ul&gt; &lt;li&gt;Variants of LISP&lt;/li&gt; &lt;li&gt;Forth&lt;/li&gt; &lt;li&gt;Erlang&lt;/li&gt; &lt;li&gt;Google Go&lt;/li&gt; &lt;li&gt;Delphi&lt;/li&gt; &lt;li&gt;OO C&lt;/li&gt; &lt;li&gt;Old compilers for C++ and other languages&lt;/li&gt; &lt;/ul&gt;</description>
		<guid>http://www.securelist.com/en/blog/677/The_mystery_of_Duqu_Framework_solved</guid>
		<link>http://www.securelist.com/en/blog/677/The_mystery_of_Duqu_Framework_solved</link>
		<pubDate>19 Mar 2012 17:42:39 +0400</pubDate>
		<title>The mystery of Duqu Framework solved</title>
	</item>
	<item>
		<author>webmaster@securelist.com (David Jacoby)</author>
		<description>&lt;p&gt;Sweden recently experienced a large banking scam where over 1.2 million Swedish kronor (about $177,800) were stolen by infecting the computers of multiple victims. The attackers used a Trojan which was sent to the victims and, once installed, allowed the attackers to gain access to the infected computers. Luckily these guys were caught and sentenced to time in jail, but it took a while to investigate since over 10 people were involved in this scam.&lt;/p&gt;&lt;p&gt;&lt;p&gt;It's possible that these attacks are no longer as successful as the bad guys would like, because we are now seeing them use other methods to find and exploit new victims. For quite some time now we have seen how hijacked Facebook accounts have been used to lure the friends of whose account has been  hijacked to do everything from click on malicious links to transfer money to the cybercriminals&amp;#8217; bank accounts.&lt;/p&gt;&lt;p&gt;&lt;p&gt;Please note that this is not a new scam - it has been out there for quite some time. But what we are now seeing is the use of stolen/hijacked accounts, or fake accounts, becoming very common on Facebook. So common, in fact, that there are companies creating fake accounts and then selling access to them to other cybercriminals. As you might expect, the more friends these accounts have, the more expensive they are, because they can be used to reach more people.&lt;/p&gt;&lt;p&gt;&lt;p&gt;The problem here is not just technical - it&amp;#8217;s primarily a social problem. We use Facebook to expand our circle of friends. We can easily have several hundred friends on Facebook, while we in real life we may only have 50. This could be a problem because some of the security and privacy settings in Facebook only apply in your interactions with people who you are not friends with. Your friends, on the other hand, have full access to all the information about you.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193413/Fake_or_hijacked_Facebook_accounts_used_in_scams_to_steal_money_are_on_the_rise</guid>
		<link>http://www.securelist.com/en/blog/208193413/Fake_or_hijacked_Facebook_accounts_used_in_scams_to_steal_money_are_on_the_rise</link>
		<pubDate>19 Mar 2012 16:54:32 +0400</pubDate>
		<title>Fake or hijacked Facebook accounts used in scams to steal money are on the rise</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Kurt Baumgartner)</author>
		<description>&lt;P&gt; The twitter infosec sphere last night and the blogosphere this morning is in a bit of a frenzy about the public leak of a DoS PoC targeting CVE-2012-0002, the RDP pre-auth remote. This vulnerability was highlighted at our previous Securelist post on this month's patch Tuesday &quot;&lt;a href=http://www.securelist.com/en/blog/2354/Patch_Tuesday_March_2012_Remote_Desktop_Pre_Auth_Ring0_Use_After_Free_RCE target=_blank&gt;Patch Tuesday March 2012 - Remote Desktop Pre-Auth Ring0 Use-After-Free RCE!&lt;/a&gt;&quot;.  First off, patch now. Now. If you can't, use the mitigation tool that Microsoft is offering - the tradeoff between requiring network authentication and the fairly high risk of RCE in the next couple of weeks is worth it. You can see the list of related links on the side of this page, one was included for MS12-020.  &lt;/P&gt; &lt;P&gt; Some interesting additional information has surfaced about the vulnerability, including the fact that the bug was generated in May of 2011 and &quot;reported to Microsoft by ZDI/TippingPoint in August 2011&quot;. The researcher, Luigi Ariemma, discusses that this work wasn't disclosed by him (often, he fully discloses his work). After some careful investigation of the poorly coded &quot;rdpclient.exe&quot; posted online in Chinese forums, he found that it was a cheap replica of the unique code he provided to ZDI and in turn, Microsoft, when privately reporting the bug. This is bad. And already, researchers with connections to Metasploit open source exploit dev like Joshua Drake are tightening up the code, developing and sharing improved PoC. As Microsoft pointed out, confidence in the development of a reliable public exploit within 30 days is very high.  &lt;/P&gt; &lt;P&gt; Regardless, the implications of a leak in the highly valuable MAPP program could hinder strong and important security efforts that have been built on years of large financial investment, integrity, and maturing operational and development processes. Thoughts and opinions on the leak itself can be found over at &lt;a href= http://www.zdnet.com/blog/security/exploit-code-published-for-rdp-worm-hole-does-microsoft-have-a-leak/10860?tag=nl.e539 target=_blank&gt;Zero Day&lt;/a&gt;. At the same time, I think that this event may turn out to be nothing more than a ding in the MAPP program's reputation, but it's important that this one is identified and handled properly. With the expansion of the program, an event like this one is something that certainly should have been planned for. &lt;/P&gt; &lt;P&gt; UPDATE: Early this afternoon over at the MSRC blog, Microsoft acknowledges that the PoC leaked on Chinese forums &quot;&lt;a href=http://blogs.technet.com/b/msrc/archive/2012/03/16/proof-of-concept-code-available-for-ms12-020.aspx target=_blank&gt;appears to match the vulnerability information shared with MAPP partners&lt;/a&gt;&quot;, note that an RCE exploit is not publicly circulating just yet, advises patching or mitigating with the Fix-It, and initiates investigation into the disclosure. &lt;/P&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193412/Update_to_this_Month_s_Patch_Tuesday_Post_on_MS12_020_CVE_2012_0002</guid>
		<link>http://www.securelist.com/en/blog/208193412/Update_to_this_Month_s_Patch_Tuesday_Post_on_MS12_020_CVE_2012_0002</link>
		<pubDate>16 Mar 2012 21:41:12 +0400</pubDate>
		<title>Update to this Month's Patch Tuesday Post on MS12-020/CVE-2012-0002</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Sergey Golovanov)</author>
		<description>&lt;p&gt;In early March, we received a report from an independent researcher on mass infections of computers on a corporate network after users had visited a number of well-known Russian online information resources. The symptoms were the same in each case: the computer sent several network requests to third-party resources, after which, in some cases, several encrypted files appeared on the hard drive.&lt;/p&gt;&lt;p&gt;&lt;p&gt;The infection mechanism used by this malware proved to be very difficult to identify. The websites used to spread the infection are hosted on different platforms and have different architectures. None of our attempts to reproduce the infections were successful. A quick analysis of KSN statistics that might help to identify the connection between compromised resources and the malicious code being distributed did not yield any results, either. However, we did manage to find something that the news sites had in common.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/687/A_unique_fileless_bot_attacks_news_site_visitors</guid>
		<link>http://www.securelist.com/en/blog/687/A_unique_fileless_bot_attacks_news_site_visitors</link>
		<pubDate>16 Mar 2012 19:12:00 +0400</pubDate>
		<title>A unique &#8216;fileless&#8217; bot attacks news site visitors</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Tim)</author>
		<description>&lt;p&gt;While Google is obviously trying to create a safer environment in regard to the Android operating system, some of these changes are leaving me a bit confused. I recently discovered some interesting behavior in regard to the default email client in 4.0 Ice Cream Sandwich.&lt;/p&gt; &lt;p&gt;It seems that if you try to download or open a zip file attachment from within the email client, Google warns of the possibility of malware:&lt;/p&gt; &lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/2349.JPG&quot; border=&quot;1&quot; alt=&quot;&quot; title=&quot;&quot;&gt;&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/2348/Is_Google_confused_about_Android_security</guid>
		<link>http://www.securelist.com/en/blog/2348/Is_Google_confused_about_Android_security</link>
		<pubDate>16 Mar 2012 18:45:13 +0400</pubDate>
		<title>Is Google confused about Android security?</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Vyacheslav Zakorzhevsky)</author>
		<description>&lt;p&gt; &lt;b&gt;Post was updated 19.03.2012 (see below)&lt;/b&gt;&lt;/p&gt; &lt;p&gt; In the last few days a malicious program has been discovered with a valid signature. The malware is a 32- or 64-bit dropper that is detected by Kaspersky Lab as Trojan-Dropper.Win32.Mediyes or Trojan-Dropper.Win64.Mediyes respectively.&lt;/p&gt;&lt;p&gt;&lt;p&gt;Numerous dropper files have been identified that were signed on various dates between December 2011 and 7 March 2012. In all those cases a certificate was used that was issued for the Swiss company Conpavi AG. The company is known to work with Swiss government agencies such as municipalities and cantons. &lt;/p&gt;&lt;p&gt;&lt;p class=&quot;c&quot;&gt;&lt;img title=&quot;&quot; border=&quot;0&quot; alt=&quot;&quot; src=&quot;images/pictures/klblog/683.jpg &quot;/&gt;&lt;br/&gt;&lt;span class=&quot;small&quot;&gt;&lt;strong&gt;Information about the Trojan-Dropper.Win32.Mediyes digital signature&lt;/strong&gt;&lt;/span&gt;&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/682/Mediyes_the_dropper_with_a_valid_signature</guid>
		<link>http://www.securelist.com/en/blog/682/Mediyes_the_dropper_with_a_valid_signature</link>
		<pubDate>15 Mar 2012 16:31:00 +0400</pubDate>
		<title>Mediyes - the dropper with a valid signature</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Kurt Baumgartner)</author>
		<description>&lt;P&gt; Patch Tuesday March 2012 fixes a set of vulnerabilities in Microsoft technologies. Interesting fixes rolled out will patch a particularly problematic pre-authentication ring0 use-after-free in Remote Desktop and a DoS flaw, a DoS flaw in Microsoft DNS Server, and several less critical local EoP vulnerabilities.  &lt;/P&gt; &lt;P&gt; It seems to me that every time a small and medium sized organization runs a network, the employees or members expect remote access. In turn, this Remote Desktop service is frequently exposed to public networks with lazy, no-VPN or restricted communications at these sized organizations. RDP best practices should be followed requiring strong authentication credentials and compartmentalized, restricted network access.   &lt;/P&gt; &lt;P&gt; Some enterprises and other large organizations continue to maintain a &quot;walled castle&quot; and leave RDP accessible for support. The problem is that RDP-enabled mobile laptops and devices will make their way to coffee shops or other public wifi networks, where a user may configure a weak connection policy, exposing the laptop to attack risk. Once infected, they bring back the laptop within the walled castle and infect large volumes of other connected systems from within. To help enterprises that may have patch rollout delays, Microsoft is providing a fix-it that adds network layer authentication to the connection, protecting against exploit of the vulnerability. &lt;/P&gt; &lt;P&gt; This past fall, we observed the RDP worm Morto attacking publicly exposed Remote Desktop services across businesses of all sizes with brute force password guessing. It was spreading mainly because of extremely weak and poor password selection for administrative accounts! The Morto worm incident brought attention to poorly secured RDP services. Accordingly, this Remote Desktop vulnerability must be patched immediately. The fact that it's a ring0 use-after-free may complicate the matter, but Microsoft's team is rating its severity a &quot;1&quot; - most likely these characteristics will not delay the development of malicious code for this one. Do not delay patch rollout for CVE-2012-0002. &lt;/P&gt; &lt;P&gt; Finally, for less technical readers, allow me to explain a little about what a &quot;Remote Desktop pre-auth ring0 use-after-free RCE&quot; really is. Remote Desktop is a remotely accessible service that enables folks to connect remotely to a Windows system and open a window to the desktop in an application as though you were sitting in front of the computer. Usually, you need to log in to the system to do that, so the system is fairly protected. Unfortunately, this bug is such that a remote attacker that can connect to the system's Remote Desktop service over the network can successfully attack the system without logging in. The &quot;ring0&quot; piece simply means that the vulnerable code exists deeply in the Windows system internals, or the kernel, of the operating system (most applications running on a system run in &quot;ring3&quot;, or &quot;user-mode&quot;). &quot;Use-after-free&quot; is the type of vulnerability enabling the exploit, and this type of flaw is something that continues to be extremely  difficult to weed out as predicted years ago, even as many of the more traditional low hanging stack and heap overflows have been stomped out by automated code reviews and better coding practices. And finally, RCE applies to the type of exploit enabled by the vulnerability, or &quot;remote code execution&quot;, meaning an attacker can deliver malicious code of their choosing to the system and steal everything. There you go, &quot;pre-auth ring0 use-after-free RCE&quot;. &lt;/P&gt;</description>
		<guid>http://www.securelist.com/en/blog/2354/Patch_Tuesday_March_2012_Remote_Desktop_Pre_Auth_Ring0_Use_After_Free_RCE</guid>
		<link>http://www.securelist.com/en/blog/2354/Patch_Tuesday_March_2012_Remote_Desktop_Pre_Auth_Ring0_Use_After_Free_RCE</link>
		<pubDate>13 Mar 2012 21:41:01 +0400</pubDate>
		<title>Patch Tuesday March 2012 - Remote Desktop Pre-Auth Ring0 Use-After-Free RCE!</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Roel)</author>
		<description>&lt;p&gt;Today is the last day of CanSecWest - a security conference taking place in Vancouver, Canada. On Wednesday I filled in for Costin Raiu and talked about our forensics work into Duqu's C&amp;C servers.&lt;/p&gt;&lt;p&gt;&lt;p&gt;As I'm writing this, Google Chrome just got popped. &lt;a href=&quot;http://www.zdnet.com/blog/security/teenager-hacks-google-chrome-with-three-0day-vulnerabilities/10649&quot;&gt;Again.&lt;/a&gt; The general feeling is that $60k, even with a sandbox escape, isn't a whole lot of money for a Chrome zero-day. So, to see multiple zero-days against Chrome is quite the surprise, especially when considering the browser's Pwn2Own track record.&lt;p&gt;&lt;p&gt;Separately, I found the Q&amp;A session following Facebook's Alex Rice&amp;#8217;s presentation immensely intriguing.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/208193410/CanSecWest_Let_s_talk_about_non_targeted_attacks</guid>
		<link>http://www.securelist.com/en/blog/208193410/CanSecWest_Let_s_talk_about_non_targeted_attacks</link>
		<pubDate>10 Mar 2012 09:33:06 +0400</pubDate>
		<title>CanSecWest: Let's talk about non-targeted attacks</title>
	</item>
	<item>
		<author>webmaster@securelist.com (Igor Soumenkov)</author>
		<description>&lt;p&gt;While &lt;a href=&quot;http://www.securelist.com/en/blog?topic=199380362&quot;&gt;analyzing the components of Duqu&lt;/a&gt;, we discovered an interesting anomaly in the main component that is responsible for its business logics, the Payload DLL. We would like to share our findings and ask for help identifying the code.&lt;/p&gt;&lt;p&gt;&lt;h2&gt;Code layout&lt;/h2&gt;&lt;p&gt;&lt;p&gt;At first glance, the Payload DLL looks like a regular Windows PE DLL file compiled with Microsoft Visual Studio 2008 (linker version 9.0). The entry point code is absolutely standard, and there is one function exported by ordinal number 1 that also looks like MSVC++. This function is called from the PNF DLL and it is actually the &amp;#8220;main&amp;#8221; function that implements all the logics of contacting C&amp;C servers, receiving additional payload modules and executing them. The most interesting is how this logic was programmed and what tools were used.&lt;/p&gt;&lt;p&gt;&lt;p&gt;The code section of the Payload DLL is common for a binary that was made from several pieces of code. It consists of &amp;#8220;slices&amp;#8221; of code that may have been initially compiled in separate object files before they were linked in a single DLL. Most of them can be found in any C++ program, like the Standard Template Library (STL) functions, run-time library functions and user-written code, except the biggest slice that contains most of C&amp;C interaction code.&lt;/p&gt;&lt;p&gt;&lt;p class=c&gt;&lt;img src=&quot;images/pictures/klblog/668.png&quot; border=0 width=381 height=449 alt=''&gt;  &lt;span class=small&gt;Layout of the code section of the Payload DLL file&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;p&gt;This slice is different from others, because it was not compiled from C++ sources. It contains no references to any standard or user-written C++ functions, but is definitely object-oriented. We call it the Duqu Framework.&lt;/p&gt;</description>
		<guid>http://www.securelist.com/en/blog/667/The_Mystery_of_the_Duqu_Framework</guid>
		<link>http://www.securelist.com/en/blog/667/The_Mystery_of_the_Duqu_Framework</link>
		<pubDate>07 Mar 2012 19:58:50 +0400</pubDate>
		<title>The Mystery of the Duqu Framework</title>
	</item>

</channel>
</rss>



