Pages

Showing posts with label f-secure. Show all posts
Showing posts with label f-secure. Show all posts

Wednesday, October 19, 2011

German Federal Trojan Supports 64-bit Windows Systems, Analysis Suggests

About two weeks ago word got out that the Chaos Computer Club got their hands on what they identified as a German state-sponsored trojan. The initial analysis assumed that the trojan would only run on 32-bit Windows systems. We reviewed a software that would detect the trojan on the system.

Two weeks later things have changed considerable. Several German states acknowledged that the backdoor was used by German police forces to spy on communication software installed on computers. According to the news spyware programs were in use since 2009.

The initial analysis of the contents was far from complete. Security experts at F-Secure and Kaspersky posted the results of their analysis recently which offer a more detailed view of the malware’s capabilities.

Kaspersky discovered that the trojan installer supports both 32-bit and 64-bit Windows operating systems. Experts previously assumed that only 32-bit systems could be targeted by it.

The second finding is a list of applications that the trojan has been designed to monitor. This list is larger than the initial list that the Chaos Computer Club published. A total of 15 applications are listed, including Firefox, Explorer, Opera, Skype, Microsoft Messenger, ICQ and Yahoo Messenger.

The trojan injects code into those processes:

Code injection into target processes is carried out by the dropper, two user-mode components and also a 32 bit kernel driver with extended functionality compared to the version previously analyzed, which only provided an interface for registry and file system modifications. This new driver starts an additional thread that constantly loops over the current list of running processes and injects a DLL into each whose image name matches an entry from the following list:

The 64-bit Kernel driver is limited in its functionality compared to the 32-bit component.

Contrary to the 32 bit version, the 64 bit driver does not contain any process infection functionality but only provides a rudimentary privilege escalation interface through file system and registry access. Similar to its brother, it creates a device and implements a basic protocol for communicating with user-mode applications.

Kaspersky identified the a 1024 bit RSA certificate issued by Goose Cert on April 11, 2010.

The F-Secure blog has more information on how the backdoor was installed on target systems.

In one case, the trojan was installed on a suspect’s laptop while he was passing through customs & immigration at the Munich International airport.

The existence of a 64-bit component, the monitoring of additional processes and information on how the trojan was installed on systems confirms that there has been more to that state sponsored trojan than initially assumed. The majority of security software available should detect the backdoor by now.


© Martin Brinkmann for gHacks Technology News | Latest Tech News, Software And Tutorials, 2011. | Permalink |
Add to del.icio.us, digg, facebook, reddit, twitter
Post tags: , , , ,



Monday, October 10, 2011

F-Secure Online Scanner Scans System For Malware

Sometimes you do not want to or cannot install another security software on your computer system to scan for malware. Maybe you do not have the rights to install software on the computer or you have a program installed and do not want to risk incompatibilities.

The alternative is an application like F-Secure’s Online Scanner which can be started from a web browser. This particular application is a Java app which means that the latest Java Runtime Environment (JRE) needs to be installed on the system.

Users can visit the official website to start a scan of their computer system right away. The online application uses up to date virus and threat definitions that F-Secure maintains for all of their products.

f-secure online scanner

When you start the online app you are asked to select a scan mode. Available for selection are quick scan, which only scans the most important files and folders of the system, a full scan or a custom scan. Custom scan can be configured on an extra screen in the program interface.

f-secure custom scan

Here it is then possible to scan all or only selected folders and file types. The program itself will scan for malware, spyware, rootkits using a database of known virus signatures and heuristics to identify unknown threats.

The program then downloads files from the Internet which may take some time depending on the Internet connection. The scan time depends largely on the selected mode and the speed of the system.

virus scan

The application displays a summary after the scan highlighting potentially malicious files. These files can be deleted from the system and send to F-Secure as a sample (handy if heuristics identified an unknown threat that F-Secure has no information about).

The program is easy to use and comes with enough customizations for advanced uses. I would not recommend relying solely on online scanners for security though, but would recommend them for additional security scans on a regular basis. You can check out our overview of online virus scanners here.


© Martin Brinkmann for gHacks Technology News | Latest Tech News, Software And Tutorials, 2011. | Permalink |
Add to del.icio.us, digg, facebook, reddit, twitter
Post tags: , , , ,