b374k
v10
today : | at : | safemode : ON
> / home / facebook / twitter / exit /
name author perms com modified label

Hijacked websites serve Fake AV and PRISM-themed Ransomware Asylum rwxr-xr-x 0 6:39 PM

Filename Hijacked websites serve Fake AV and PRISM-themed Ransomware
Permission rw-r--r--
Author Asylum
Date and Time 6:39 PM
Label
Action
Now a days when in every walk of life there is danger, one cannot expect anything good in cyber world.



Some attackers are reported to use PRISM to scare unsophisticated users into installing ransomware. Zscaler researchers report to identify 20 affected websites that are used to spread fakeAV.



Zscaler reports-'These websites seem to have been hijacked. They are all hosting the malicious content over port 972 and use similar URL patterns. Here are a couple examples:




  • kringpad.websiteanddomainauctions.com:972/lesser-assess_away-van.txt?e=20

  • miesurheilijaaantidiabetic.conferencesiq.com:972/realism_relinquish-umbrella-gasp.txt?e=21

  • squamipi.worldcupbasketball.net:972/duty_therefore.txt?e=21'




Not only this but they reported that the files seem to be changing from FakeAV to fake PRISM warning. But the common thing is that in both the cases it is used to frighten the target and ask them for money to 'fix' the computer. Thus making a lot of money.



Fake AV were mostly used to lock the desktop of the user and asked for money to unlock it or it used to run a fake computer scan in the browser and the victim had to pay to remove the threats.



Well PRISM was used to fool the user and said that the victim's computer has been blocked because it contained some illegal pornographic content. The victim has to pay $300 through MoneyPak, a prepaid card service.



It has been reported that:-"Both malware connect to the same couple of IP addresses over ports 80 and 443 that include:



37.139.53.199



64.120.167.162



64.191.122.10"



The attackers are clever and shrewd and can use any trick to fool you for their benefit, so beware the next time.





via E Hacking News [ EHN ] - Latest IT Security News | Hacker News Hijacked websites serve Fake AV and PRISM-themed Ransomware http://www.ehackingnews.com/2013/09/hijacked-websites-serve-fake-av-and.html

0 comments:

Post a Comment

 

Jayalah Indonesiaku © 2010 Hacker News
VB (Vio b374k) Template design by p4r46hcyb3rn3t