Hi there everyone.
I trust this update finds you all well and you are looking forward to a great weekend.
My I offer a piece of advice for this weekend?
AVOID "LNK" FILES LIKE THE PLAGUE!
I was drafting the previous post regarding the fact that a USB key no longer requires an autorun file to perform an infection, but it seems that is now only one small part of the over all issue.
One of our newer staffers here at Trend in Sydney has many security qualification, and certifications, including many industry regulatory compliance advisory certifications as a result of his time with Visa Europe. As a result of all this knowledge he was able to craft some impromptu internal demonstrations for us to show us the extent and possibilities that this particular vulnerability presents.
Needless to say the outcome is concerning.
Without even so much as a double click, he had complete control of a demo-lab machine remotely, executing commands without hindrance.
As a result of a wonderful flaw in Microsoft a number of articles need to be viewed.
Microsoft Security Advisory - Temporary "Fix It For Me" tool This will be superseded by the patch that Microsoft eventually releases.
Microsoft Security Response Center
Information about the vulnerability
Trend Updates as a result of related Malware
Guys, just be aware - a LNK file can be propagated via any number of vectors. A web site, an email a USB, and as a result of the way this vulnerability works the user does not need to interact with the LNK file at all. As a result of Windows rendering the LNK file icon, the contents are executed to perform the exploit. And as you know an LNK file can point to ANYTHING and in this case, ANY type of exploit!
Be careful, and keep a keen eye out for the impending Microsoft fix since this is going to be the most effective way to protect your customers.
Have a great weekend!
Welcome
**Please note: This is an INFORMAL blog, and I will attempt to add information to it on a reasonably regular basis**
Please maintain your current support paths for any post-sale technical queries:
Partner Support Hotline - 1800 094 155
Support Email - support@trendmicro.com.au
Friday, July 23, 2010
No AUTORUN.INF needed for USB infection!!
New Malware Distribution Technique For USB via MS Vulnerability
Please be aware that there is a new vulnerability in the way Microsoft handles shortcut (.LNK) files in external drives. This is currently being exploited by malicious code for new propagation techniques related to external devices such as USB keys.
By having a shortcut (.LNK) file on the removable drive, this simply needs to be viewed (not executed) to automatically execute malicious code. In other words, just by plugging in a USB key and opening the root folder would trigger the infection.
References:
MS Security Advisory:
http://www.microsoft.com/technet/security/advisory/2286198.mspx
http://www.securecomputing.net.au/News/220266,microsoft-looks-into-malware-spreading-via-usb.aspx
Trend Micro Malware Blogs and Virus Information:
http://blog.trendmicro.com/usb-worm-exploits-windows-shortcut-vulnerability/
http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_STUXNET.A&Vsect=T
There are actually a number of components to the malware which we detect as:
WORM_STUXNET.A – The malicious files themselves
LNK_STUXNET.A – The malicious .LNK file to execute the files.
RTKT_STUXNET.A – Rootkit component.
How can Trend Micro protect against this?
We already have a virus signature file available to detect the initial malware.
Please be aware that there is a new vulnerability in the way Microsoft handles shortcut (.LNK) files in external drives. This is currently being exploited by malicious code for new propagation techniques related to external devices such as USB keys.
By having a shortcut (.LNK) file on the removable drive, this simply needs to be viewed (not executed) to automatically execute malicious code. In other words, just by plugging in a USB key and opening the root folder would trigger the infection.
References:
MS Security Advisory:
http://www.microsoft.com/technet/security/advisory/2286198.mspx
http://www.securecomputing.net.au/News/220266,microsoft-looks-into-malware-spreading-via-usb.aspx
Trend Micro Malware Blogs and Virus Information:
http://blog.trendmicro.com/usb-worm-exploits-windows-shortcut-vulnerability/
http://threatinfo.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_STUXNET.A&Vsect=T
There are actually a number of components to the malware which we detect as:
WORM_STUXNET.A – The malicious files themselves
LNK_STUXNET.A – The malicious .LNK file to execute the files.
RTKT_STUXNET.A – Rootkit component.
How can Trend Micro protect against this?
We already have a virus signature file available to detect the initial malware.
Thursday, July 15, 2010
Whoops, we did it again!
hmmm lame title... sorry about that! :)
I trust everyone is enjoying their week so far. Down hill run from here on the week and the month!
We topped the NSS labs report again!
Now, those of you who have seen me speak, you will be very aware of my opinion's of other lab-tests, and comparisons. Even when Trend comes out on top of these.
NSS has always been a bit of a shining beacon in this arena though. They are the equivalent of Choice magazine - taking completely unbiased, unsponsored view points to provide their subscribers with the best possible and most untainted information available. See below a screen shot of their website.
Here is a portion of the outcomes this report showed.
This table is anonymised at the request of NSS - but the results are pretty obvious. Trend are the fastest to respond with a time of 4.62 hours - the next quickest are our British friends lagging by a full 12 hours, and it only gets worse from there. Our 2 major competitors scored around the 30 and 45 hour marks - I'll leave the rest to you to interpret.
And there are three words which are the reason for this success. Smart Protection Network.
I wonder if you are noticing a theme here so far with my blogs??
You can find out some more information on this report here.
Signing off... Kieran
I trust everyone is enjoying their week so far. Down hill run from here on the week and the month!
We topped the NSS labs report again!
Now, those of you who have seen me speak, you will be very aware of my opinion's of other lab-tests, and comparisons. Even when Trend comes out on top of these.
NSS has always been a bit of a shining beacon in this arena though. They are the equivalent of Choice magazine - taking completely unbiased, unsponsored view points to provide their subscribers with the best possible and most untainted information available. See below a screen shot of their website.
Here is a portion of the outcomes this report showed.
This table shows blocking mechanisms at download and at execution on the system.
This is the total time in hours to block a previously undetected Malicious URL.
And there are three words which are the reason for this success. Smart Protection Network.
I wonder if you are noticing a theme here so far with my blogs??
You can find out some more information on this report here.
Signing off... Kieran
Monday, July 12, 2010
Another Gem from the keyboard of Wayne Small
Are you planning on installing WFBS v6?
Do you have field engineers who like pictures?
Do you generally install WFBS without changing anything from defaults?
Wayne has just released his lastest publication to make your reselling life easier!
WFBS 6.0 Visual Guide
This is a great step-by-step field guide which will be well worth forking over a few bucks for.
Have a great week everyone!
Do you have field engineers who like pictures?
Do you generally install WFBS without changing anything from defaults?
Wayne has just released his lastest publication to make your reselling life easier!
WFBS 6.0 Visual Guide
This is a great step-by-step field guide which will be well worth forking over a few bucks for.
Have a great week everyone!
Tuesday, July 6, 2010
Latest information to combat Fake AV
Fake AV has been one of the most challenging malware families I have encountered in a long time.
A friend of mine recently had an encounter with a FakeAV variant. Her son had been using the computer, and her updated free-AVG had no idea the malware had infiltrated or was present. Even though there were many pop-ups appearing asking her to pay for the "Security Software" which had detected Trojans on her machine (classic indicator of a FakeAV "RansomWare").
Eventually it was a simple matter of removing a single registry run key in safe-mode and submitting the related file to our labs for further analysis (which we were able to identify immediately).
We were actually a little disappointed that this variant seemed so easy to remove. We thought it was all over... we were wrong!!
The pop-ups had ceased. It was like looking at a still pond. Smooth surface, but plenty of activity happening underneath!
I installed Trend Micro Titanium on her Netbook, which immediately started detecting Web Threats! Granted, we were not detecting a local file-based infection at that stage - BUT it was blocking the malware's connection home. This malware will try to connect home to either get an updated malware components, or send sensitive information back "home". Our Virus Research labs filled in the gaps with the file-based infection response.
< soap_box >
(I hope this doesn't sound like Marketing fluff.) This really highlights the true power of what the Smart Protection Network means in real-life scenarios. It's not only for the major enterprises - its also for the "average-Joe" home user, who effectively is the most vulnerable user of all! Plus the information provided from this ultra-vulnerable source also contributes to protecting our large corporate customers, and visa-versa.
PLEASE enable Web Threat Protection (Web Reputation) in all your Trend Micro installs. PLEASE enable Email Reputation and Smart Scanning (File Reputation) were applicable too.
Another thing that is highlighted is that you certainly get what you pay for when installing a "Free" Anti-Malware product, and unfortunately this was installed by a person from one of the franchise computer services companies who should really have known better!
< /soap_box >
Anyway. I trust you will enjoy having a read through this whitepaper which aims to educate users on how FakeAV gets onto their machines, and best to protect themselves from it happening in the first place!
Have a great rest of the week everyone!
Regs
Kieran
A friend of mine recently had an encounter with a FakeAV variant. Her son had been using the computer, and her updated free-AVG had no idea the malware had infiltrated or was present. Even though there were many pop-ups appearing asking her to pay for the "Security Software" which had detected Trojans on her machine (classic indicator of a FakeAV "RansomWare").
Eventually it was a simple matter of removing a single registry run key in safe-mode and submitting the related file to our labs for further analysis (which we were able to identify immediately).
We were actually a little disappointed that this variant seemed so easy to remove. We thought it was all over... we were wrong!!
The pop-ups had ceased. It was like looking at a still pond. Smooth surface, but plenty of activity happening underneath!
I installed Trend Micro Titanium on her Netbook, which immediately started detecting Web Threats! Granted, we were not detecting a local file-based infection at that stage - BUT it was blocking the malware's connection home. This malware will try to connect home to either get an updated malware components, or send sensitive information back "home". Our Virus Research labs filled in the gaps with the file-based infection response.
< soap_box >
(I hope this doesn't sound like Marketing fluff.) This really highlights the true power of what the Smart Protection Network means in real-life scenarios. It's not only for the major enterprises - its also for the "average-Joe" home user, who effectively is the most vulnerable user of all! Plus the information provided from this ultra-vulnerable source also contributes to protecting our large corporate customers, and visa-versa.
PLEASE enable Web Threat Protection (Web Reputation) in all your Trend Micro installs. PLEASE enable Email Reputation and Smart Scanning (File Reputation) were applicable too.
Another thing that is highlighted is that you certainly get what you pay for when installing a "Free" Anti-Malware product, and unfortunately this was installed by a person from one of the franchise computer services companies who should really have known better!
< /soap_box >
Anyway. I trust you will enjoy having a read through this whitepaper which aims to educate users on how FakeAV gets onto their machines, and best to protect themselves from it happening in the first place!
Have a great rest of the week everyone!
Regs
Kieran
Thursday, July 1, 2010
Beware of Tab-Jacking or Tabnapping!!
I just came across an interesting article detailing a new phishing threat mechanism.
http://uk.biz.yahoo.com/07062010/389/tab-napping-new-online-scam.html
The general message appears to be that now we need to check that the URL we typed in originally is still there if we utilise a number of tabs and come back to a previously opened tab.
As per usual - this is something that Web Threat Protection in our Smart Protection Network will serve to protect Trend Micro users from.
http://uk.biz.yahoo.com/07062010/389/tab-napping-new-online-scam.html
The general message appears to be that now we need to check that the URL we typed in originally is still there if we utilise a number of tabs and come back to a previously opened tab.
As per usual - this is something that Web Threat Protection in our Smart Protection Network will serve to protect Trend Micro users from.
Subscribe to:
Posts (Atom)


