In this case, this is a beta version of this crimeware that apparently is fairly active as in the few days we have been following, after "violating" your authentication scheme, has not achieved a striking level of infection by therefore has not achieved a significant number of zombies.
Still, this threat is active and spreading threats, but before seeing what the malicious code that spreads look a little more about some statistics that allow us to have a sufficiently specific to the activity which has the botnet.
From that we can capture:
- The operating system is exploited by this crimeware Windows XP SP1.
- The second place is occupied by "other" platforms "no windows".
- Windows XP SP2 is the third in the list of most used OS.
- Internet Explorer versions 5.5, 6.0, 7.0 and Firefox 3.0.5 browsers that are more broken through crimeware threats.
- The item "others" in the browser, is a browser such as Opera and Amaya.
However, the module Vparivatel not seem as effective so far as no activity has "positive" for the botmaster ;-P
Among the threats that spread Unique Sploits Pack are as kaspersky identification:
- Exploit.JS.Pdfka.ip (8112e241092a63e13084b14439f87ee8)
- Trojan.Win32.Pakes.nkq (0d89729a0df4f6ad57103d670af62b20)
These malicious codes are spread through various vulnerabilities, some of which are newer than others, but despite the antiquity of most of the vulnerabilities exploited by this crimeware, remain very effective.
Not only exploit vulnerabilities in popular web browsers (IE, Firefox and Opera) but also two vulnerabilities PDF readers currently in widespread use: Adobe Acrobat Reader and Foxit Reader.
As mentioned in the beginning, now this package is spreading malware crimeware proactively exploiting different vulnerabilities on computers victims, and despite not having the time by a significant number of controlled equipment, it's a potential threat the health system which undertakes to maintain the security updates (OS and applications) per day.
Related Information
YES Exploit System. Manipulando la seguridad del atacante
Unique Sploits Pack. Crimeware para automatizar la explotación de vulnerabilidades
# Jorge Mieres
No comments:
Post a Comment