2011年4月15日星期五

Operation b107 - Rustock Botnet Takedown

Just over one year ago, Microsoft- with industry and academic partners- utilized a novel combination of legal and technical actions to take control of the Win32/Waledac botnet as the first action in Project MARS (Microsoft Active Response for Security).  Today, a similar action has had its legal seal opened allowing us to talk more openly about recent activities against the Win32/Rustock botnet.

Comparatively, Waledac was a much simpler- and smaller- botnet than Rustock.  It is, however, because of legal and technical lessons learned in that set of actions that we were able to take on the much larger challenge of Rustock- a botnet with an estimated infection count above one million computers and capable of sending billions of spam messages per day. Some statistics suggest that, at peaks, it represented as much as 80% of spam traffic and in excess of 2000 spam messages per second.

 

Our efforts here represent a partnership between Microsoft?s Digital Crimes Unit, the Microsoft Malware Protection Center and Trustworthy Computing. This was a multi-month effort which had its denouement yesterday with a coordinated seizure of command and control servers under court order from the U.S. District Court for the Western District of Washington carried out by the U.S. Marshals Service as well as authorities in the Netherlands.  Investigators are now inspecting the evidence captured in these seizures from five hosting centers in seven locations in order to, potentially, learn more about those responsible and their activities.

 

Efforts like this are not possible without collaboration with others.  For this effort, we worked with Pfizer?whose brands were infringed by fake-pharma spam coming from Rustock. We also worked with our colleagues at FireEye and the University of Washington.  All three provided valuable declarations to the court on the behaviors of Rustock and the specific dangers posed by this threat- dangers to public health in addition to those affecting the Internet. 

 

We are continuing our work with both CERTs and ISPs around the world to reach out to those whose computers are infected and help clean them of viruses. If you believe a computer under your care or that of a family member, friend or colleague may be infected, please make a concerted effort to clean it and get protected with a full antivirus product from a trusted provider.  More support information is available at http://support.microsoft.com/botnets. The announcement from Microsoft?s Digital Crimes Unit can be found on the Official Microsoft Blog and the Microsoft on the Issues blog.

 

 --Jeff Williams

fix registry errors free fix windows error fix error free

Japan Quake Spam leads to Malware

Kaspersky Lab has detected a malicious spam campaign using the recent earthquake in Japan to infect users. These emails contain malicious URLs:

fix errors free free fix computer errors fix errors on my computer

2011年4月14日星期四

Japan Quake Spam (II)

As was predicted by many, email scams soliciting donations for Japan are appearing in user’s inboxes. We took a closer look at one of these messages and identified the following details:

free fix error fix script errors fix runtime error free

The Fake Defragmenter Invasion

Since the beginning of its popularity in the end of October 2010; a rogue defragmenter still continues to haunt the users, which in the end of 2010 has reached 20 variants, and may still continue to rise. The author has never stopped producing new variants. As is typical of the rogue application, this rogue defragmenter [...]

fixing errors find and fix errors how to fix error

Trojan downloader Chepvil on the UPSwing

A new spam campaign using UPS (United Parcel Service) as a social-engineering draw was initiated this week.  The spammed message contains an attachment, detected as TrojanDownloader:Win32/Chepvil.I. The spam campaign actually started around March 16th 2011. The threat was originally detected as Backdoor:Win32/Hostil.gen!A (was Backdoor:Win32/Hostil.F). More specific signatures (TrojanDownloader:Win32/Chepvil.I and TrojanDownloader:Win32/Chepvil.J) were added on March 22nd 2011.

Win32/Chepvil is a trojan that downloads other malware such as Rogue:Win32/Winwebsec, Rogue:Win32/FakeRean, Backdoor:Win32/Cycbot.B and VirTool:Win32/Injector.gen!BG. The retrieved malware is saved to the %TEMP% folder and then executed. Microsoft Malware Protection Center has noticed that detections over the past few days have gone from a handful to around 400k per day.

The majority of these detections are coming from the antimalware technology protecting our Hotmail customers, clearly indicating the vector – spam. At the time of this blog writing, we received a few reports of other online email service account holders receiving this trojan via spam email as well.

Below is a chart indicating observed telemetry of this trojan over a short period of time:

Image 1 – Chepvil telemetry

Image 1 – Chepvil telemetry

 

Nearly all of the attached files are named “United Parcel Service document.zip”.

The most prevalent SHA1s for the .ZIP attachment are:
0610CE22DF47B3D9C69DC63387705FD666C7205A
151755454A9D443A8A60996F3F1DC4E0C68A9B5D
2C25B6B2764E4DA5EC0A7D57017DFA5FF2A10873

The most prevalent SHA1s for the .EXE trojan within the .ZIP archive are:
0FB63DFF83DB643C9EE42EFE617BDD539A5FFB8F
142E8b00AA24954f9A4AA2271B8A49C445B87587
DA65B7B277540B88918076949A28E8307AD7E41A

Our geographical data from our endpoint protection products show a heavy focus on the United States:

Image 2 – Chepvil telemetry by geography

Image 2 – Chepvil telemetry by geography

 

Below is one example of a spammed message containing the Chepvil trojan.

 

Image 3 – Sample of Chepvil trojan attachment

Image 3 – Sample of Chepvil trojan attachment

 

MMPC customers have detection for this issue through the signature TrojanDownloader:Win32/Chepvil.I.

 

- Holly Stewart, Joe Faulhaber, Jaime Wong & Patrick Nolan

fix system errors fix errors free free fix computer errors

Fake MSE updated. Did your real MSE updates too?

Recently, AVG caught a new variant of Fake MSE, which was more sophisticated and confusing. As usually, it will pop up to warn you that you have been infected. If you apply ?recommened? actions, the UI announces that the malware...

how to fix registry errors fixing errors find and fix errors

Be aware of rogue security software

We have noticed rogue antivirus software that pretends to be the AVG Anti-Virus 2011. AVG detects this malware usually as part of the Trojan horse FakeAV family and we are also actively tracking sources of this scam. Please make sure...

free pc repair pc fixer pc problems