Attackers Use Microsoft Office To Push BlackEnergy Malware (csoonline.com)
itwbennett writes: Researchers at SentinelOne reverse engineered the latest variant of the BlackEnergy 3 rootkit (the same malware used in recent attacks against Ukraine's critical infrastructure) and found indicators that suggest it is being used by insiders and that it is the byproduct of a nation-sponsored campaign. 'BlackEnergy 3 exploits an Office 2013 vulnerability that was patched some time ago, so it only works if the target machine isn't patched or an employee (either deliberately or after being tricked into it) executes the malicious Excel document,' writes CSO's Steve Ragan.
... Who turn off Windows update. All I can say is told you so.
http://saveie6.com/
wow, how leet. Now try it with libreoffice, noobs.
This raises some very interesting questions.
1) If I don't want systemd installed on my Linux computer, does that make systemd a form of malware if it is installed? (I think it does, because in that case it would be unwanted software.)
2) If systemd prevents a Linux installation from booting properly, does that make systemd a form of malware? (I think it does, because in that case it prevents the correct operation of the computer.)
3) If systemd comes with a Linux distribution, and the distribution's installer does not include a menu for easily choosing an init system other than systemd, is that Linux distribution considered to be infected with malware? (I think it is, because in that case the distro would come bundled with unwanted software that can potentially have a very negative impact on the operation of the computer.)
Now that BizX, Inc has purchased Slashdot, I would like to welcome our new overlords. If you would like to welcome them, you can by contacting the CEO at: Roger Abbott CEO 858.454.5900 ext. 10501 And the President at: Roger Sheppard President 858.454.5900 ext. 20501 As an added bonus, the new overlords are a SEO company.
HELLO Ukraine, don't run your critical infrastructure on a malicious Excel document. Microsoft, the company that made typing dangerous.
From the marketwired.com article:
"I am excited to be leading future strategy for two of the most iconic technology sites on the web. With a combined monthly average of over 30 million unique visitors and 150 million downloads, SourceForge.net and Slashdot.org are leaders in their fields," explains Logan Abbott, President of SourceForge Media, LLC. "We will improve and accelerate development of useful open source software developer tools on SourceForge in addition to rekindling the original spirit of open source that made SourceForge great. We plan to keep Slashdot positioned as the best technology-centric news and discussion site on the web."
TRANSLATION: "Suck it, n00bs. We'll rape slashdot, suck it dry, and then dump it as fast as we can to an even shadier company."
And you thought Dice was bad....you ain't seen nothin' yet.
So yeah, it's high time for an alternative to slashdot to emerge, and leave this empty husk behind.
Just cruising through this digital world at 33 1/3 rpm...
If any nation is using an imported, outdated consumer OS for its critical infrastructure something is strange.
Open networks that face the internet, commercial OS's and older applications should be replaced with more robust solutions.
Re "... deployed in NATO countries, and more broadly across the European Union" Would an older vulnerability that might not exist or be updated even be of interest to an advanced nation-sponsored effort?
The penetration products offered to nations are new, fancy and work on the most modern OS without been found or noticed. AV fails to detect them during their useful operation.
Other products have been crafted to only go after very bespoke systems and evade traditional logs, tracking, AV or firewalls eg Equation Group.
The software used by nations is modern and always works ie not hoping to guess that all systems are not updated and access will be lucky.
What nation would risk all on old code that is of no use and will quickly be discovered hoping for an application or OS version will align with their access?
Nations can afford to win using the best code that is mission ready that no other party has seen as it is bespoke no matter what new upgrades or commercial security products are in place.
The "constantly changing attack vectors" is not new. An old consumer OS left open the internet is not a national energy policy.
Having industrial networks facing the internet is not a great idea.
Domestic spying is now "Benign Information Gathering"
may disturb other 1t's going, up my 7oys. I'm AND MICHAEL SMITH
So spam in the Ukraine is SlashDot frontpage material?
I hope the new management fires you all... maybe we could stop seeing the overhyped, bidaily CSO crap
... I no longer feel shocked by reading "microsoft" and "malware/virus" in the same sentence. When you read some news about OS X, or some FUD about Linux, and malware there is room for some banter. But with microsoft it is kind of expected. Isn't it sad that the name of a company is that linked to malware?
'BlackEnergy 3 exploits an Office 2013 vulnerability that was patched some time ago, so it only works if the target machine isn't patched or an employee (either deliberately or after being tricked into it) executes the malicious Excel document,' writes CSO's Steve Ragan.
A vulnerability that is still present if user behavior allows triggering the payload is NOT PATCHED. It's a workaround, at best.
BlackEnergy malware pushes Microsoft Office!
0.0.0.0 mail1.auditoriavanzada.info
0.0.0.0 auditoriavanzada.info
0.0.0.0 lasvegas-nv-datacenter.com
(Insert those entries into hosts as they are shown with blocking addresses in front of them 'blackholed' & I obtained them via reverse dns methods...)
* Which resolves out to 5.149.254.114 on the 1st two listed above (inserted as a firewall rule as well) & 162.246.22.74 (which oddly also points to the 1st two domains also) + 64.235.52.31 for the last one in the list of blocked host-domain names for hosts above!
(Data obtained from the source article research/disassembly material + tracings PDF file provided & done by the researchers (they're some of the best guys in the world, all of their kind imo, in giving us all this information to protect ourselves...)).
APK
P.S.=> My next post? I bet you'll NEVER guess what that'll be about as an "addendum" to this one folks, lol... apk
See subject & for the best custom hosts file http://start64.com/index.php?o...
-
FREE, not 'souled-out' to advertisers + adds speed, security & reliability.
Does far more w/ far less more efficiently vs. browser addons (clarityray blockable, redundant + RAM/CPU wasteful & 'souled-out' crippled by default) & local DNS servers @ home.
It fixes DNS' security issues & stops tracking @ webpage + DNS levels via 1 file you NATIVELY have!
(Firewalls do the rest on far less used IP address trackers/threats vs. host-domain names).
-
Obtains data vs. threats & adblocking via 10 reputable security community sites - easily edited by you.
-
SPEEDS YOU UP 2 ways:
Adblocking ALL ads + local RAM cached favorite sites @ TOP of hosts for faster resolution vs. remote DNS (aids reliability) vs. other "so-called security 'solutions'" SLOWING YOU!
-
All via what you already have vs. illogically "bolting on browser addons 'MOAR'" (clarityray detected/blockable + usermode slow & increased messagepassing, cpu + ram overheads)
-
MalwareBytes' hpHosts Admin (MalwareBytes employee verified it's source as safe http://forum.hosts-file.net/vi... ) hosts & recommends it -> http://hosts-file.net/?s=Downl...
&
MalwareBytes = BEST antivirus per a VERY recent testing of them all http://www.av-test.org/en/news...
&
It's safe proven by 57 antivirus programs in BOTH its 64-bit model https://www.virustotal.com/en/...
+
32-bit model https://www.virustotal.com/en/...
&
Installer-> http://f.virscan.org/APKHostsF...
-
* "The premise is quite simple: Take something designed by nature & reprogram it to make it work for the body rather than against it..." - Dr. Alice Krippen: "I am legend".
APK
P.S.=> By "yours truly" - "The Lord of Hosts" so-to-speak:
"The image this title brings to mind is a mighty military commander who can at a mere word summon rank upon rank of protective power" -> https://answers.yahoo.com/ques... & THE WORD = hosts!
(Accept NO substitutes!)
...apk
How can you put malware... on malware... that is also spyware and adware already?
dicks.