Archive for the ‘Debate’ Category

A Stormy Valentines Day ahead of us…

Tuesday, January 15th, 2008

It looks like the Storm Worm is with us once again.

Emails have been spammed out with a Subject Line that contains one of the following,

loveheart.jpgFalling In Love with You
Special Romance
You’re In My Thoughts
Sent with Love
Our Love Will Last
Our Love is Strong
Your Love Has Opened
You’re the One
A Toast My Love
Heavenly Love

If a user clicks on the link in the email then they are brought to a website that gets unsuspecting users to download their Love ecard. If run, the “ecard” will turn the users PC into a bot. The PC will then join the many others in the Storm Worm Botnet.

It seems a bit early for Valentines Day though! Maybe the authors mistakenly released it?

If not, then we could be in for a long run in to Valentines Day.

Keep Safe

Steo – www.antirootkit.com

 

Self help credit repair
Credit repair attorney
Understanding credit report
A credit report
Commercial mortgage refinance
Auto loan interest rates
Consumer debt settlement
Credit repair after bankruptcy
Uk credit card offer
Debt consolidation loan denver
Health insurance premium
Online credit report
California best refinance mortgage rate california home loan
For credit reporting
Card credit debt free
Free equifax credit report
Online credit scores
Discover business credit card
Instant experian credit report
Auto home insurance
Credit score of
Student loans without credit check
Application aspen card credit
Consumer credit report
Free credit rating report
Life insurance uk
Disability insurance canada
Of fair credit reporting
Credit free instant report
Auto loans for people with bad credit
Home equity loan rate
Home equity loans online
New home loans
0 credit card offers
Creditscore
Accept credit card services
Fax payday loan
Cash til payday loan
College student loan consolidation
Credit card processing terminals
California health insurance quote
Mbna credit card application
Credit score management
Free instant credit reports
Missouri payday loan
Lower payment debt consolidation ma
Refinance home mortgage interest rates
Instant payday loan
Home loan mortgage rates com refinance
Insurance sexual health clinics
Lincoln long term care insurance
Insurance barts sexual health
Florida repay teacher student loans title i
Credit plus score
Bad credit debt consolidation
Your credit score in
Credit counseling debt consolidation
Credit card debt counseling
Credit card application canada
By credit score
Nj disability insurance
Equifax credit reporting agency
Obtain free credit report
Debt negotiation credit card
Illinois auto insurance
Home insurance quote
Quick cash payday loan
Deal on credit card
Mortgage loan home mortgage rates mortgage refinance rates
Types of home loans
Just credit score
Credit reporting burea
Debt consolidation loan
Commercial construction loans
Credit report repair services
Chase secured credit card
When is the right time to refinance your mortgage

Anti Rootkit Software Scanners for Vista

Friday, January 11th, 2008

We are often asked what Anti Rootkit Scanners are available for Windows Vista. There are currently only 7, out of the 20 or so scanners available, that will work with Vista. These scanners will also only work with 32 Bit versions of Vista.

Here is a list of the 7 in alphabetical order. Please click on the scanner name or screenshot to bring you to a more detailed page where you can download the software.

F-Secure Blacklight

blacklight-frontend

 

GMER

gmer-frontend

 

Icesword

Icesword Frontend

 

Rootkit Hook Analyser

rootkit-hook-analyser-frontend

 

Rootkit Revealer

 

Rootkit Unhooker

Rootkit Unhooker

 

Unhackme

Unhackme

Keep Safe,

Steo – www.antirootkit.com

Security Flaw in Vista and XP – Rootkit exploit in the wild

Thursday, January 3rd, 2008

In early Devember 2007 a new rootkit that hides itself in the Master Boot Record (MBR) of a users disk was spotted in the wild. Up until then this was more of a proof of concept (POC).

This goes to show how much effort rootkit authors are putting in to creating new ways of evading Anti Rootkit software. This is a new vector of attack for malware writers and gives them control from outside the Operating System.

This rootkit is using the MBR flaw. The MBR can be written to from within Windows.

The rootkit installs itself ( 244K ) on the last sectors of the users disk and then modifies other sectors including sector 0. The code is run before your PC boots up into XP, Vista or NT and has full control of the boot process which means it can install and run any application it wants without you, XP, Vista or NT knowing about it.

GMER has written an excellent write up on the MBR Rootkit and goes into more depth on the issue.

Indeed GMER’s Anti Rootkit Software can find the rootkit.

 gmer-finds-mbr-rootkit.jpg

The rootkit files cannot be removed from within XP, Vista or NT and must be removed without the PC running the rootkit code.

Until the MBR Security flaw within the NT code is fixed then we will all be soon riddled with MBR Rootkits.

Keep Safe,

regards,

Steo – www.antirootkit.com

 

How to promote your Storm Worm Peacomm Rootkit via Google and newyearcards2008.com

Saturday, December 29th, 2007

Whats the first thing people all over the world do when they want to find out about something…they Google it!!! “Googling” something has become a keyword in so many people’s lives these days. Googling has an entry on popular online dictionaries http://dictionary.reference.com/browse/google which means it wont be long before you can actually use the word Googling “legally”.

So when millions of people recently got an email with a link to newyearcards2008.com where they could pick up their New Years E Card Greeting they went to Google and did a search for newyearcards2008.com and they would have seen newyearcards2008.com at the very top,

newyearcards2008

From Google….

Happy New Year!

Your download should begin shortly. If your download does not start in approximately 15 seconds, you can click here to launch the download and then press
newyearcards2008.com/ – 1k – CachedSimilar pages

Most Google users would think it is legitimate such is the trust in Google these days. When clicked on the user would have seen a page delivered via someones PC whether it be in their front room, bedroom, office, factory floor even unsuspecting Internet Cafe’s all over the world.

newyearcards2008-site
Snapshot from newyearcards2008.com

These infected PC users do not suspect a thing because their Anti Virus program shows that everything is ok, all is well. Why? The latest Storm Worm is using a rootkit … http://www.antirootkit.com/blog/2007/12/27/happy-new-rootkit/ . Nothing shows because of the stealth capabilities of the rootkit. It hides all traces of itself from normal anti virus and anti spyware scanners. Different scanners are now required for checking for rootkits. Scanners that know exactly how the rootkit operates are required, check out the Antirootkit Software page for list of new scanners.

Why does a search of newyearcards2008.com show the main infection site up first on a Google search? It’s all about how many pages on the internet link to newyearcards2008.com. Even by me putting newyearcards2008.com in this blog will help the name climb the Google ladder so that it shows at the very top and stays top for as long as it can, fooling people into thing it is legitimate ( I mention newyearcards2008.com a lot here so that this blog entry will raise higher than newyearcards2008.com and people will read this warning before getting their New Year’s “Surprise” E-Card).

The people who registered newyearcards2008.com, they went about getting the domain name mentioned on a lot of internet pages around the world, mostly on blog pages belonging to Google. Most of the Blogspot pages have been disabled by Google but many Blogspot and Blogger owners who are using their own domain name have links to newyearcards2008.comnewyearcards2008-blog-site in thier “hacked” blogs.

 

 

If you suspect a site as being unusual with unusual activity then you can report it to Google and help them mark it as suspect. You can report to Google, suspect sites, via http://www.google.com/safebrowsing/report_badware/

A recent Trend Micro Blog entry highlights Blogger pages being used to harbor links to newyearcards2008.com… http://blog.trendmicro.com/hundreds-of-blogger-pages-harboring-new-years-storm-links/trackback/
So far as of 29th Dec GMT newyearcards2008.com is showing tops, lets see when it is highlighted as a suspect site by Google on a web search.

Also keep an eye out for newyearwithlove.com

(Asked whois.nic.ru:43 about newyearwithlove.com)

 Domain name:             NEWYEARWITHLOVE.COM
 Name Server:             ns.newyearwithlove.com 24.161.84.89
 Name Server:             ns10.newyearwithlove.com 69.179.23.34
 Name Server:             ns11.newyearwithlove.com 70.241.145.212
 Name Server:             ns12.newyearwithlove.com 69.137.25.197
 Name Server:             ns13.newyearwithlove.com 82.67.135.130
 Name Server:             ns2.newyearwithlove.com 71.201.48.186
 Name Server:             ns3.newyearwithlove.com 68.114.62.80
 Name Server:             ns4.newyearwithlove.com 76.226.178.239
 Name Server:             ns5.newyearwithlove.com 70.128.122.94
 Name Server:             ns6.newyearwithlove.com 76.201.158.149
 Name Server:             ns7.newyearwithlove.com 75.49.2.123
 Name Server:             ns8.newyearwithlove.com 67.8.191.249
 Name Server:             ns9.newyearwithlove.com 71.12.83.79
 Creation Date:           2007.12.26
 Updated Date:            2007.12.26
 Expiration Date:         2008.12.26
 Status:                  DELEGATED
 Registrant ID:           XHAEJUS-RU
 Registrant Name:         Bill Gudzon
 Registrant Organization: Bill Gudzon
 Registrant Street1:      1920 str.  office 345
 Registrant City:         Los-Angeles
 Registrant State:        CA
 Registrant Postal Code:  32089
 Registrant Country:      US
 Administrative  Technical Contact
 Contact ID:              XHAEJUS-RU
 Contact Name:            Bill Gudzon
 Contact Organization:    Bill Gudzon
 Contact Street1:         1920 str.  office 345
 Contact City:            Los-Angeles
 Contact State:           CA
 Contact Postal Code:     32089
 Contact Country:         US
 Contact Phone:           1 320 5427834
 Contact E-mail:          bgudzon1956@hotmail.com
 Registrar:               ANO Regional Network Information Center dba RU-CENTER
 Last updated on 2007.12.29 05: 07: 05 MSK/MSD

Keep Safe,

Steo – www.antirootkit.com

 

EP_X0FF and Rootkit Unhooker off to Microsoft

Sunday, December 23rd, 2007

EP_E0FFMicrosoft have just gained one of the best anti rootkit teams on the planet. EP_X0FF and the development team of Rootkit Unhooker have joined Microsoft. They are currently making plans to ship off to Wittenberg in Germany ( where Martin Luther is buried ) where the Rootkit Unhooker team will finish off work on their, up to now,secret project called Secured Eye (SEye),“…in a two words this is project mix of software/hardware related to distributed calculations and virtualization technologies based on Vanderpool / Pacifica extensions. Not a Blue Pill. To be more correct some parts of SEye can be used as a pill for any kind of Blue Pill variations ;)

Old MS LogoMicrosoft now owns Rootkit Unhooker and SEye….”As you can guess all our source code and concept were sold to MS. This was happened in the beginning of November and includes all variants of our test programs, RkU, including last 4.1 version and SEye which is ready on 3/4.”

It is a great thing that EP_X0FF and the team are off to Microsoft. Just like Mark Russinovitch before them, their vision and knowledge alongside money and resources from Microsoft will bode well for us all in the future.

Best of Luck to you all and keep in touch.

You can read EP_X0FF’s blog here…http://www.rootkit.com/blog.php?user=EP_X0FF

Keep Safe

Steo

 

Phoney Free iPhone but a Real Rootkit

Monday, July 2nd, 2007

Secure Computing has released information about a new Spammed email telling users that they have won a new iPhone from an online store. The email has a link that promises the email reader a free iPhone and when the user clicks on the link they are brought to a website that then downloads a Spam Bot and a Rootkit.

The subject of the message is “Congratulations, you have won a new iPhone from our store!”

“Should the victim fall for the social engineering attack, clicking on a link directs the user’s browser to a web page that contains malware that exploits 10 Active X vulnerabilities in order to install a malicious payload including an MSODataSourceControl vulnerability.”

There  is also website analysis on the servers that host the malware. If a person is seen to revisit the malware site then they are being redirected to the correct authentic site. This is to make it hard for researchers to have a good look at the site.

This technique of infecting websites and in turn getting them to infect PC’s is being used more and more by hackers and malware authors. Using social engineering and spam techniques malware authors have a great platform to spawn their creations.

Take Care,

regards

Steo

References:
http://www.itpro.co.uk/news/118791/new-malware-exploits-iphone-popularity.html

http://www.itwire.com.au/content/view/13268/53/