Friday, November 2, 2007

Storm Worm Sent 15 Million Pump-And-Dump E-Mails Last Month

PCWorld 30/10/2007
Website: http://www.pcworld.com


The Storm Worm botnet network may be shrinking in size, but it has managed to send out 15 million annoying audio spam messages in October, according to antispam vendor, MessageLabs.

It's hard to believe that the Storm messages were effective. Recipients had to first click on an attachment-- usually given a misleading name like beatles.mp3 or Britney.mp3-- to hear the stock pitch, which featured a warbly robotic woman advising people to invest in online car seller, Exit Only.

This kind of scam, called "pump-and-dump", tries to nudge up the price of penny stocks by a cent or two, giving the spammers a way to make a quick buck by selling the stock before it crashes. Spammers have been delivering their messages in different formats, including.pdf and Excel files, over the past few years as part of a cat-and-mouse game with spam blockers. This latest move to MP3 spam is the latest development in this battle, observers say.

Spam watchers say that pump-and-dump schemes are the hottest and most lucrative area for spammers today.

The spam run began on Oct. 17, and lasted about 36 hours, using infected computers in the Storm Worm network to send out the mails, MessageLabs said in a statement released Tuesday. The spam sounded strange and warbly because the voice in the message was "synthesized using a very low compression rate of 16K Hz to keep the overall file size small, at around 50 KB, to avoid detection," the company said.

Storm is thought to have landed on as many as 15 million PCs over the past year, but recently its network of infected PCs has been shrinking. University of California, San Diego, researchers recently pegged it at about 160,000 computers, only 20,000 of which are accessible at any one time.

Exit Only said it was not involved in sending the spam. Its stock was trading around US$0.41 on Oct. 18, the day after the Storm spam started. On Tuesday it closed at $0.20.

Virus Definition Updates 2/11/2007

AVG Anti-Virus Free Edition 7.5
Download AVG AVI:269.15.18.1
Download AVG AVI:269.15.18.2
Download AVG AVI:269.15.18.3
Download AVG IAVI:1104
Version: -
Date: 1/11/2007

AntiVir PersonalEdition Classic
Download AntiVir IVDF
Version: 7.00.00.163
Date: 2/11/2007

Avast! 4 Home Edition
Download Avast VPS
Version: 071102-0
Date: 2/11/2007

Symantec
Download Norton VDU
Version: 91101p
Date: 1/11/2007
Supports the following versions of Symantec antivirus software:
Norton AntiVirus 2003 Professional Edition
Norton AntiVirus 2003 for Windows 98/Me/2000/XP Home/XP Pro
Norton AntiVirus 2004 Professional Edition
Norton AntiVirus 2004 for Windows 98/Me/2000/XP Home/XP Pro
Norton AntiVirus 2005 for Windows 98/Me/2000/XP Home/XP Pro
Norton AntiVirus 2006 for Windows 2000/XP Home/XP Pro
Norton AntiVirus 2007 for Windows XP Home/XP Pro/Vista
Norton AntiVirus for Microsoft Exchange (Intel)
Norton SystemWorks (all versions)
Norton Utilities for Windows 95/98 (all versions)
Symantec AntiVirus 3.0 for CacheFlow Security Gateway
Symantec AntiVirus 3.0 for Inktomi Traffic Edge
Symantec AntiVirus 3.0 for NetApp Filer/NetCache
Symantec AntiVirus 8.0 Corporate Edition Client
Symantec AntiVirus 8.1 Corporate Edition Client
Symantec AntiVirus 9.0 Corporate Edition Client
Symantec AntiVirus 10.0 Corporate Edition Client
Symantec AntiVirus 10.1 Corporate Edition Client
Symantec AntiVirus 10.2 Corporate Edition Client
Symantec Mail Security for Domino v 4.0
Symantec Mail Security for Domino v 5.0

Tuesday, October 30, 2007

FTC: More spyware-fighting tools needed

InfoWorld 29/10/2007
Website: http://www.infoworld.com

San Francisco (IDGNS) - Organizations and law enforcement agencies fighting spyware are making progress, but new tools in an antispyware bill stalled in the U.S. Congress could improve the efforts, a member of the U.S. Federal Trade Commission said Monday.

One of the spyware bills passed by the House of Representatives earlier this year, the Spy Act, would give the FTC authority to impose civil fines on companies that distribute spyware to consumers' computers. The bill, along with the Internet Spyware Prevention (or I-SPY) Act, have stalled in the Senate since passing the House in May and June.

The FTC has the authority to collect profits from spyware operations and collect money for consumer redress, but it lacks the authority to impose other fines, as it does when going after spammers, said Commissioner Jon Leibowitz, speaking at a spyware forum in Washington, D.C.

Assigning a dollar figure to consumer harm is tricky in many spyware cases, especially when the spyware delivers pop-up advertisements to computers, Leibowitz said. It's sometimes difficult to get courts to assign large consumer damages to pop-up cases, he said.

In some cases, spyware damages are assessed by judges "who don't even use computers," said Dave Koehler, with the FTC's Bureau of Consumer Protection.

The Spy Act would allow the FTC to fine spyware vendors up to $3 million for hijacking computers, delivering unwanted adware, and other violations, and $1 million for collecting personal data without permission, in addition to going after the vendor's profits and seeking consumer redress.

Additional authority to impose civil fines would give the FTC "an enormous deterrent," Leibowitz said.

"Right now, companies know that the worst they can do is lose their profits," he added. "They're not going to get fined on top of that."

The FTC has brought several spyware actions against companies. In February, the agency settled a case against adware distributor DirectRevenue. In that case, DirectRevenue settled for $1.5 million, based on its profits, but the founders of the company had received more than $20 million in venture-capital funding, Leibowitz said.

While participants in the spyware forum said there continue to be many challenges, including a growing trend of foreign spyware vendors, the cost of spyware to U.S. consumers seems to be falling. Consumer Reports estimated that spyware cost U.S. consumers $2.6 billion in 2006, but only $1.7 billion in 2007, noted Ari Schwartz, deputy director of the Center for Democracy and Technology, a supporter of StopBadware.org, a consumer-protection effort aimed at spyware and other malicious code.

The drop in the cost of spyware can be attributed to a number of factors, Schwartz said. Antispyware technology is getting better, the FTC has taken action against spyware vendors, and StopBadware.org has distributed a list of malicious Web sites, he said. In addition, some states have taken action against spyware, and cybersecurity groups' public education programs seem to be working, he said.

But Ron Teixeira, executive director of the National Cyber Security Alliance (NCSA), noted that consumers may know more about spyware, but they aren't always acting on their knowledge. A survey released by the NCSA and McAfee earlier this month found 78 percent of respondents' computers didn't have all three of what the NCSA calls the "core protection" software: anti-virus, antispyware, and firewall.

"We're not seeing a huge increase in the actual behavior change," he said.


Attack code out for critical Kodak bug in Windows

InfoWorld 27/10/2007
Website: http://www.infoworld.com


San Francisco (IDGNS) - A hacker has released attack code that could be used to exploit a critical bug in some versions of the Windows operating system.

Microsoft patched the flaw, which affects older versions of Windows, on Oct. 9. When the Image Viewer tries to open a maliciously encoded TIFF file, it can be tricked into running unauthorized software on the PC.

A sample of the exploit was posted Monday to the Milw0rm Web site. The code has not yet been used in online attacks, according to Symantec, which issued an alert Monday.

Symantec recommends that Windows users install the MS07-055 update as quickly as possible.

Microsoft took the unusual step of issuing its own security update for Kodak's software, because the image viewer (formerly known as the Wang Image Viewer) had shipped in Windows 2000 systems by default.

Still, many Windows users are not affected by the problem. Windows XP and Windows Server 2003 users should not have the software installed on their PCs, unless they downloaded it directly or upgraded from Windows 2000. Windows Vista users are not affected by the bug.

Also, users would have to open the TIFF file using the Kodak Image Viewer for the attack to work. Because most PCs are set to automatically open TIFFs using some other piece of software, it is unlikely that an attack would succeed.

"Its not a huge deal, though, we don't think," said Marc Maiffret, chief technology officer with eEye Digital Security, via instant message. "You probably have some other program that defaults to open TIFFs like QuickTime or Photoshop."

The sample attack code affects the Korean language version of Windows, but it could be easily modified to affect other versions of the software, Maiffret said.

Saturday, October 27, 2007

PDF files used to attack computers: security firm

Reuters 27/10/2007
Website: http://www.reuters.com

HELSINKI (Reuters) - Emails containing malicious PDF files have been putting computers at risk since Friday, Finnish security software firm F-Secure said on Saturday.

"The emails sent in bulk looked like credit card statements, and contained an attachment called 'report.pdf'," its chief research officer Mikko Hypponen said in a statement.

When such PDF files are viewed on vulnerable machines, they start downloading software from servers in Malaysia or Sweden, which are now being cleaned, he said. "There will be more such attacks."

"We are worried about this case, as PDF attachments are typically not filtered at email gateways."

A security update for Acrobat Reader, which opens PDF files, was made available a few days ago, but many users have not updated the program yet, Hypponen said.

Thursday, October 25, 2007

Adobe Patches Critical PDF Vulnerability

News Factor Network 24/10/2007
Website: http://www.newsfactor.com

Adobe patched its Acrobat and Reader programs on Monday. The fix plugs a hole that exposed Windows XP users to attackers sending PDF files containing malware. According to various reports, exploits are running rampant around the Internet in search of unpatched applications.

"Critical vulnerabilities have been identified in Adobe Reader and Acrobat that could allow an attacker who successfully exploits these vulnerabilities to take control of the affected system," Adobe said in a security bulletin. "A malicious file must be loaded in Adobe Reader or Acrobat by the end user for an attacker to exploit these vulnerabilities."

Windows XP users who also run Internet Explorer 7 are at risk. Adobe first admitted to the bug about two weeks ago and posted a complex workaround that required users to edit the Windows registry. The flaw was first discovered on September 20 by "pdp" on the Gnucitizen Web site.

Anatomy of the Attack

Attackers are still hoping to find unpatched systems. Security firm iSIGHT Partners discovered new Russian Business Network spam containing a hostile PDF file designed to exploit the flaw. Successful exploitation lets attackers download code from a remote server to the victim's machine.

This code installs two rootkit files that sniff and steal financial and other valuable data from the computer. The files are installed in the Windows directory as 9129837.exe and new_drv.sys.

Noteworthy is the fact that the code and servers used in the attack are nearly identical to September 2006 Vector Markup Language (VML) zero-day attacks. Servers used in the attack have a history of malicious abuse, including VML attacks, animated cursor exploitation, and CoolWebSearch installations, according to iSIGHT Partners.

The Hostile e-mails with a malicious PDF exploit file are circulating with subject lines that read "STATEMET indigene." The e-mail attachments are called "YOUR_BILL.PDF" and "INVOICE.PDF."

"Antivirus detection is extremely poor for the exploit files and payloads involved in this attack, averaging only 26 percent out of 39 updated programs tested during the time of attack," said Ken Dunham, director of global response for iSIGHT Partners and a former director at VeriSign's iDefense.

Symantec Antivirus Protection

In addition, Symantec is reporting that its researchers have their eyes on a Trojan, called Trojan.Pidief.A, that is designed to exploit this PDF vulnerability.

Symantec Security Response's Hon Lau said it is likely that the Trojan has been spammed out in targeted attacks on specific businesses. Symantec is assuring its antivirus customers that those with definition sets of October 23 revision 008 or greater are protected.

"This mass mailing of exploit files may be an attempt to leverage the exposure window between patch release and widespread adoption of the fix," said Symantec in a warning to customers of its DeepSight threat intelligence network.

Security researchers recommend treating PDF documents with extreme caution.