Saturday, August 17, 2019

New Post About Rootkits



A clandestine computer program – rootkit allows hackers to have non-stop access to the vulnerable computer by hiding itself under the veil of an application that is not at all suspicious or dubious. When you accept to grant permission to the applications to install or update themselves, the rootkit is introduced to the device along with these apps and waits for the hacker to activate it so that it can start its surveillance. According to Keone Software, Rootkits can be associated with key loggers and malware like worms, viruses, Trojans and other malware that usually initiate their malfunction by hiding themselves in such a way that the user doesn’t realize their presence for quite some time. Read the entire post here: http://secureweb.altervista.org/what-is-a-rootkit/

Article About Advanced Persistent Threat



The Advanced Persistent Threat (APT) is a special type of attack where some unauthorized user avail access to certain network or system and stays there for a long run without even being detected. Such attacks are more dangerous for organizations as hackers may manipulate or steal sensitive data. Note that, APT attacks usually do not cause any harm to the local machines or network; rather, the main motive of the attacker use to steal data.
Such attacks are usually completed in several phases. It may include hacking the system or network, preventing detection, developing a plan for the attack, mapping the sensitive data, and filtering the accessible information. Read more: https://adwarehelp.svbtle.com/what-is-an-apt-advanced-persistent-threat


Wednesday, August 14, 2019

POST ABOUT LOCKY VIRUS

Locky file virus makes users desperate as their most important files get locked with a sophisticated encryption system. IT experts are making their best to come up with an ultimate recovery solution. The encryption is strong enough, though. Any decoding attempts of the white hat hackers have not yielded a satisfactory result – so far. While the users still reasonably place their hopes on the release of decryption method, there are some smart techniques enabling quite efficient data recovery that often meets user’s needs.

Let us gain some insight into how the infection works and what it actually is. That would facilitate the use of anti-ransomware methods referred to above.

The IT industry tends to classify the infection as a piece of ransomware. The Locky virus holds your data out of your access as a hostage. To restore the access, a victim is prompted to pay the amount specified by the invader. The sum is payable in bitcoins and via dedicated TOR channel.

More: https://pc-protect.weebly.com/blog/locky-virus-targets-all-of-us

ARTICLE ABOUT FRAUDULENT ATTACKS ASSOCIATED WITH ITUNES GIFT CARDS



Currently, cybercriminals often resort to a strategy of making telephone calls with the requirement to transfer funds for paying taxes, medical bills, utility bills, etc. Fraud attacks are carried out in many ways, often using gift cards. Since some attackers use iTunes gift cards, we feel it necessary to warn Apple customers about the likelihood of encountering such an attack.
All fraudulent attacks (regardless of the purpose of payment) are conducted according to a certain formula: the attacker calls the victim in order to sow panic and convince him of the need to urgently pay something using the iTunes gift card, which can be purchased at the nearest retail store. After purchasing the card, the victim is asked to make a payment by dictating a 16-digit code on the back of the card by phone.
Remember that iTunes gift cards can only be used to purchase products and services from the iTunes Store, the App Store and the iBooks Store, or to pay for a subscription to Apple Music. If you are required to use a card to make a payment that is not associated with the iTunes Store, App Store, iBooks Store or Apple Music, you are likely to have become the target of a fraudulent attack. Immediately report this to the local law enforcement agencies (police department, trade commission, etc.).

Article on how to stay safe while using public Wi-Fi

Free Wi-Fi at the airport, at the mall or in coffee shops help us when we are running a little low on our data pack but they come with threats to your security. Public Wi-Fi even those offered by hotels do not come with necessary security, using them could put your data at risk. These servers are easy to hack into, without your knowing all your browsing activity and other personal information could be accessed by a third party. Read more here:
https://antivirusspace.wordpress.com/2019/08/14/how-to-stay-safe-while-using-public-wi-fi/

Tuesday, December 18, 2018

Information security

Information security is the state of preservation of information and the protection of the legal rights of an individual and society in digital space.

Information security is the process of ensuring the confidentiality, integrity and availability of information.

Privacy and Confidentiality: Providing access to information only to authorized users.

Integrity: Ensuring the reliability and completeness of information and methods for its processing.

Accessibility: Providing access to information and related assets of authorized users as needed.

Information security - all aspects related to determining, achieving and maintaining confidentiality, integrity, availability, non-repudiation, accountability, authenticity and reliability of information or means of its processing.

Information security - the state of data security, which ensures their confidentiality, availability and integrity.

Information security is determined by the absence of unacceptable risk associated with the leakage of information through technical channels, unauthorized and unintended effects on data and (or) on other resources of the automated information system used in an automated system.


Here are several interesting security articles:

http://scalar.usc.edu/works/new-daily-article/how-to-check-the-macbook-virus


https://privacy-security.shorthandstories.com/globeimposter/index.html


http://antonlucanus.web.ugm.ac.id/2018/10/30/the-pros-and-cons-of-the-cyber-reality-in-our-lives-technology-its-differing-aspects-and-demanding-impositions/


http://www.imfaceplate.com/infosec/strange-cryptocurrency-industry-jobs


https://cybersmith.exposure.co/similar-photo-cleaner/


https://dailygram.com/index.php/blog/492275/mining-crypto-at-work/


https://busy.org/@davesure/how-apple-s-self-proclaimed-employees-cheat-on-mac-users


http://sharingknowledge.world.edu/are-there-viruses-for-mac-computers/



Tuesday, October 25, 2016

Locky ransomware has been updated again: now uses .thor file extension



Seems like Locky creators have returned from vacation, after several weeks of slow distribution of their earlier version called Odin, they released two more variants this week. First one adds .shit extension and the second one adds .thor extension. Two variants differ in a way that one may work offline without contacting Command and Control servers. Seems like cyber criminals want to launch two variants simultaneously and see which one goes better in terms of rogue ROI.

Like with many previous versions, new .thor file virus usually arrives with malicious email attachments or hyper links within the body of the email message or instant message. Do not click on such links and do not open attachment sent by unfamiliar users. 

If your files got encrypted with .thor version of the virus, try restoring Windows from previous restore point or utilize backups. For more tips read here.

To be protected, make regular backups and keep you security software up-to-date.

Tuesday, April 5, 2016

Locky Ransomware Virus Is on the Rise




The easy availability of Locky malware attracts a number of distributors. Those propagators are unrelated to each other. They make use of any possible method of introduction. Naturally, some of them have already been caught at spreading the malware. The point is, they are not much closer to the arch villain than anyone.
The ransoming virus installation details vary from case to case. The prevailing infection vector is known. Most of the infiltration cases are due to opening spam mail attachments.
The introduction is to be followed by installation of the Locky ranowmare. The latter requires an affected system to reboot. One can prevent the encryption already at that stage. If a sudden reboot is happening, it is worth switching your computer to Safe Mode: the malware is not able to complete its installation.
If it succeeds in its encrypting attempts, the victims are presented with a relevant ransom note. The note is available at each folder with affected files. Several formats convey the same notification to ensure the users would read it.
The removal of Locky encryption shall include the ransomware elimination and data recovery. Whenever possible, the victims shall abstain from purchasing the key as prompted by the scammers. Relevant instructions on how to handle and prevent Locky invasion follow: http://myspybot.com/decrypt-locky-files/

Friday, December 11, 2015

An update of TeslaCrypt came out this week




It incorporates minimal adjustments to the previous version of TeslaCrypt. In particular, the file name of the ransom note is now called Howto_RESTORE_FILES.txt, it can be also .html and .bmp. With the exception of the change of the name, the wording of the ransom note is similar to the previous version.

Another change is a different name for autorun entry.

Finally, a modest modification of the way ransomware cleans the Shadow Volume Copies. In terms of removing Shadow Volume Copies, new version of TeslaCrypt is now executing vssadmin.exe until the ransomware identifies that the user of the infected machine did not terminate the request to run vssadmin.exe.

More details about TeslaCrypt ransomware as well as removal instructions can be found here: http://soft2secure.com/knowledgebase/teslacrypt

Sunday, March 22, 2015

Searchult virus causes web browsing frenzy

When it comes to surfing the web, some things are inviolable. 


The Superfish adware has a promotion to dream of

The app called Superfish Visual Discovery has gotten into a scandal due to the story about Lenovo laptops being shipped with the doubtfully safe bundle.

Tuesday, December 9, 2014

BrowserSafeguard with RocketTab features a malicious combination

Ad-supported software inherently implies a certain degree of risk to the end users because of the marketing model its authors selected. 

Wednesday, September 10, 2014

Mac computers attacked by Conduit Search virus

Conduit Search, also known as Search Protect by Conduit, is one of the few adware programs capable of infecting both Windows and Mac OS machines.



Tuesday, July 8, 2014

Profile and the fix for Audio Ads virus

Ethical merits of some computer world’s actors end where big money comes in, moreover that’s where technical sophistication grows exponentially. Whereas browser hijacking and similar adware-related activities has been prevailing as cybercriminals’ methods of delivering advertisements to users on the Internet, a fairly new yet more annoying tactic has emerged, impersonated by the so-called Audio Ads virus.

Sunday, July 6, 2014

Speedial Search virus violating the Internet FairPlay

Badly meddling with the web browsing facet of one’s computing is what the app called Speedial Search is designed to do. In contradistinction to legitimate software, this browser helper object does not comply with the setup regulations, permissions acquisition on the target computer, and the critical authorization guidelines for making changes to the system it finds itself on.

Thursday, July 3, 2014

ArabyOnline imposes content indiscernible to many

It’s not a far-sighted online strategy to deliver content irrespectively of the language and location of the target users. Obviously, for some reason that’s not an issue to the creators of ArabyOnline, a web portal in Arabic that allows for no lingual choice. But even as odd as it is, this drawback is far from being the worst part about the entity under consideration.

Wednesday, January 8, 2014

How to control your privacy on Facebook

Facebook’s privacy settings are huge and can be difficult to use. Here’s a guideline to some of the most important Facebook’s privacy controls.