'StrongPity' Malware Infects Users Through Legitimate WinRAR and TrueCrypt Installers (neowin.net)
Kaspersky Labs has revealed a new strain of malware -- named 'StrongPity' which targets users looking for two popular applications - WinRaR and TrueCrypt. The malware contains components that not only has the ability to give attackers complete control on the victim's computer, but also steal disk contents and download other software that the cybercriminals need. From a Neowin report: To be able to gather victims, the attackers have built special fake websites that supposedly host the two programs. One instance that was discovered by the researchers is that the criminals transposed two letters in a domain name, in order to fool the potential victim into thinking that the program was a legitimate WinRAR installer website.
"through legitimate WinRAR and TrueCrypt installers"? By what logic are those installers legitimate?
If it's malware infected, it's not legitimate.
... no. How could the malware being served qualify as a legitimate installer?
It isn't. Slashdot editors stink.
someone just downloaded an .exe off a website and ran it.
If I can get someone to do that, you don't need winrar as part of the equation anymore.
Nothing like an ad-infested news page with referral program links to the original source. Here is the actual article, with a sanitized URL:
http://usa.kaspersky.com/about-us/press-center/press-releases/2016/Kaspersky_Lab_Reveals_Advanced_Persistent_Threat_StrongPity
Fake installers have malware
Headline is wrong, and contradicted by the summary
News at 11
Who actively look to install WinRAR in this day and age, other than maybe some old person who has no clue what the hell they are doing and just getting whatever crap they were using 15 years ago...
Why are people still using something that the authors of same apparently think is compromised?
HBI's Law: Frequency of calling others Nazis is directly correlated with the likelihood of the accuser being Communist.
Words have meaning, but only if you subscribe to the theory that meaning has meaning.
Hasn't this been done 1000 times before? What's new here? Why is this newsworthy?
I saw this on Neowin earlier today. The headline should have read illegitimate. I'm surprised that they never fixed it as it's wrong the way it's worded. I'm more surprised that Slashdot passed on the error without thinking how stupid it sounded.
"The malware contains components that not only has the ability to give attackers complete control on the victim's computer"
Msmash forgot to mention that this malware is only effective on Microsoft Windows. Go here for an alternative to the Microsoft industry standard.
See subject: Add the bogus domains it uses as blocked to hosts, e.g.:
0.0.0.0 gezginler.net
0.0.0.0 tamindir.com
0.0.0.0 www.true-crypt.com
0.0.0.0 true-crypt.com
* ... & "voila", there ya go - SOURCE = https://securelist.com/blog/research/76147/on-the-strongpity-waterhole-attacks-targeting-italian-and-belgian-encryption-users/
(You CANNOT be infected/infested by WHAT YOU CANNOT ACCESS/TOUCH in the 1st place)
APK
P.S.=> It's THAT simple to stall either getting this bogus machination from its hosting sources (or even having it "talk back to mama" should it do that by adding those servers as well)... apk
0.0.0.0 ralrab.com
0.0.0.0 www.winrar.it
0.0.0.0 winrar.it
* Along w/ the others from my original post https://tech.slashdot.org/comments.pl?sid=9759361&cid=53057377/ that SHOULD do it...
APK
P.S.=> You couldn't PAY me enough to WANT to be president - why? What I'd do would get me SHOT (by those profiting by the shenanigans going on politically & in the corporate world, the TRUE masters of puppets pulling the strings in gov't.) but, I guarantee it'd fix the messes we have - I'd have posted all this information sooner, but the JACKASS that now runs this site puts all kinds of effete wannabe blocks on me (so talk to him on it)... apk
'StrongPity' Malware Infects Users Through Legitimate WinRAR and TrueCrypt Installers
in order to fool the potential victim into thinking that the program was a legitimate WinRAR installer website.
It certainly fooled whoever submitted the story.
Now, will someone at Slashdot bother to fix it?
systemd is Roko's Basilisk.
But surely if the site was WinARR.com you'd be suspecting pirates.
They found the links for it on DotSlash.
Stop with the spamming already! Somebody get this guy outta here!
Use ZIPmagic instead. It's faster than WinRAR and also does disk compression, which no other tool does. A nice way to payback for the clickbait too!
Why do people even download WinRAR? For the odd occasion I need to extract a WinRAR archive, the free and open source 7-zip works fine. It also handles a number of other formats, and is fast. (For example, it is MUCH faster at extracting ZIP archives than Windows Explorer).
This is supposedly a tech news site.
There is no way that editing can accidentally be that shit. Malware in "Legitimate installer" - wow that is news. Click through to standard bullshit.
Things like this are a good way to drive away the readership. Only reason I still visit is that the community is still large enough to have interesting discussions around the articles (although the trolling etc is getting worse as time goes on)
(Just wish a few other alternatives would get more active communities)
First of all, the headline is misleading. For it to be true, you'd have to get infected somehow by installing genuine WinRAR and TrueCrypt software you downloaded from trusted (and trustworthy), genuine sources. Now THAT definitely WOULD be a story!
But what do we have instead? Malware writers using typosquatting techniques to get people to install genuine looking software. Now, it's been a while that I've left the malware analysis business, but even back then, well over a decade ago, this would not have made the news anymore. Or is it news because that technique is SO ancient that nobody remembers it anymore?
Damn millennials and their goldfish-dimension long term memory!
No, but seriously, what the hell is the news here? That malware authors get nostalgic when it comes to distribution? So Retro isn't just for music and games anymore? Are we going to get file infectors again, too? And hand crafted, self-morphing viruses? That would at least be interesting to analyze again.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
See subject: Note I said "effete wannabe blocks"? It's true - after all, you see me post as much as I like!
* All he had to ever do was ASK ME POLITELY & I'd have left but "no" he never did & tried to "play smart" instead, vainly as you can plainly see.
APK
P.S.=> Nothing stops the truth & nothing stops me (I'm on topic + being helpful w/ a working solution here, not you & "yours" (useless "ne'er-do-well" TROLL losers))... apk
See subject: 2nd - Offer a working solution vs. this threat as I did - lastly, do a better program for it too (again, as I have).
* You CAN'T on any ground noted & that makes YOU a "ne'er-do-well" troll, nothing more...
APK
P.S.=> You're pitiful & useless... apk
See subject: Eventually they'll be 'sinkholed' by ICANN/IANA etc. (the "internet powers that be", whoever that is nowadays).
APK
P.S.=> Until then, "sinkhole" them yourself & nothing does it better vs. modern online threats (since they mostly use host-domain names) than "yours truly"'s APK Hosts File Engine 9.0++ SR-4 32/64-bit https://www.google.com/search?hl=en&source=hp&biw=&bih=&q=%22APK+Hosts+File+Engine%22+and+%22start64%22&btnG=Google+Search&gbv=1/
... apk
See subject: & as far as our source article goes (which I used as reference), it's fine for now - they do more? I block more - yes, it's THAT simple.
* As far as ranum? Ok - Ask THEM, directly, IF I block sources of these types of machinations (or systems they talk back to as in C&C servers) IF the malware as it presently is architected would work OR be able to be obtained in the 1st place!
I guarantee they say NO & that I am correct (per the information given by said source article I used).
APK
P.S.=> LASTLY & ABOVE ALL ELSE - you "great critics" behind FAKE NAMES online (like you)? Make me laugh - do better than I have regarding programs for security, ala:
APK Hosts File Engine 9.0++ SR-4 32/64-bit https://www.google.com/search?hl=en&source=hp&biw=&bih=&q=%22APK+Hosts+File+Engine%22+and+%22start64%22&btnG=Google+Search&gbv=1/APK Hosts File Engine 9.0++ SR-4 32/64-bit
See subject: Learn to read - I can't BE blocked by ANY means, fool!
* Drink it in & digest it - it's reality, "phantasyland-boy" troll "ne'er-do-well" that you are... lol!
(What's it LIKE being MY FOOL? Reduced to using your unjustifiable PUNY "downmods" I can get around easily getting you to RUN DRY of those modpoints? Hohohoho!)
APK
P.S.=> Yes, I am LAUGHING @ you & so is anyone reading this seeing me blow you AWAY @ every turn easily... apk
Guys what kind of editors you have ?
Even the title is wrong.
Original article linked in your own green title bar is stating "ILLEGITIMATE" is a big difference compare to your "LEGITIMATE" title.
This way I consider it as a click-bite.
What is going on there . Not enough money ?
Beside bashing Clinton, Trumpie, RNC, DNC (see I am all inclusive ),the "technical" articles are also garbage ?
When you click thru to the story the real page correctly identifies the installers as ILLegitimate, /. needs to update their title!
/.'ers speak 4 it & thus, me:
his hosts program is actually pretty good by xenotransplant
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg
I've never tried to belittle (APK's) work, I've flat out said it's good by BronsCon
take a look at the APK hosts file engine by SuperKendall
APK is kinda right. I've tried his hosts file generating software. It works by bmo
APK is totally right on this count. Adblock Plus on Firefox mobile is a dog on older, or lower end, phones. A hostfile based adblocker makes for a much better experience by chihowa
I like your host file system by Karmashock
I find your hosts file admirable by vel-ex-tech
* My code's recommended & hosted by Malwarebytes' hpHosts - Argue w/ #'s (you're outnumbered/outthought etc.)
APK
P.S.=> Want more? In the interim "Achilles last stand" Led Zeppelin 'Presence' album https://www.youtube.com/watch?... ... apk
Dont't be mean.
"we are all atheists about most of the gods that societies have ever believed in. Some of us just go one god further."
See subject & this link where /. registered peers say QUITE otherwise shutting you down 10++:1 https://tech.slashdot.org/comments.pl?sid=9759361&cid=53064255/
* :)
APK
P.S.=> I notice you didn't take up my offer of putting out even MORE users here that like my ware, lol - why's that? Oh, WE know... apk
You got your ass kicked by your /. peers (only a partial list) + myself using facts, in a ratio of 10++:1 https://tech.slashdot.org/comments.pl?sid=9759361&cid=53064255/
* Face facts - you WISH you were ME...
APK
P.S.=> Instead of the no-talent do-nothing "ne'er-do-well" trolling loser you are... apk
You're still spamming! Why do you do it? What kind of weirdo are you?
See subject: We know what kind of weirdo you are getting your ass kicked by /. peers https://tech.slashdot.org/comments.pl?sid=9759361&cid=53064255/ regarding myself, hahahaha.
* You can't handle the fact that you got destroyed by your own do-nothing stupidity vs. ME getting the job done so it works via hosts...
APK
P.S.=> "Your kind" in "ne'er-do-well" unskilled MENIAL trolls never can OR will - & you know it (proof's in that link above + my 1st https://tech.slashdot.org/comments.pl?sid=9759361&cid=53057377/ & 2nd https://tech.slashdot.org/comments.pl?sid=9759361&cid=53057495/ posts showing how to use hosts to nullify this threat easily)... apk
The only things your links prove is that you're a fucking spammer! Go. the. fuck. away! And take all your spammy friends with you!
See subject - YOU did THIS to yourself & you LOSE (badly) https://tech.slashdot.org/comments.pl?sid=9759361&cid=53064255/ lol...
* :)
(I love making fools like you show your true color - of FAIL!)
APK
P.S.=> Thanks for making ME look GOOD & yourself, by way of comparison vs. your peers opinions from ONLY a PARTIAL LIST of what I could put out, well - lol, "not so good" (stupid more like it on YOUR part)... apk
See subject & your massive SELF-defeat vs.myself + /. peers opinions vs. you https://tech.slashdot.org/comments.pl?sid=9759361&cid=53064255/
* I don't NEED anymore than that to put "your kind" away... you do it to yourselves every single time - it's pricelessly hilarious!
APK
P.S.=> That's obviously WHY you troll me by unidentifiable ac posts - I've obviously done you in before, having you do YOURSELF in for me (lol) so you use this "tactic" (loser one)... apk
See subject: Continually defeating yourself (w/ help from /.'ers & myself) https://tech.slashdot.org/comments.pl?sid=9759361&cid=53064255/
* You did THAT to yourself!
APK
P.S.=> Why not be creative & industrious instead like I have been (with a working solution vs. this online threat via hosts too no less) creating something useful as I did in my hosts file generating engine? Oh - that's right: That's BEYOND unskilled unidentifiable ac trolls like yourself... apk
See subject: You repetitiously destroy yourself as always, e.g. as you did here vs. me, yet again-> https://tech.slashdot.org/comments.pl?sid=9759361&cid=53064255/
* LOL!
APK
P.S.=> It's ALWAYS the same w/ you unidentifiable off-topic ac trolls - you trash yourselves EVERY single time vs. me, lmao... apk
Keep on spammin' babe. It's what you know. It's what you do best. Simple, fact free repetition is all you got.
AC trolls
That's almost funny coming from you... You project more that Trump. Are you him?
See subject & this https://tech.slashdot.org/comments.pl?sid=9759361&cid=53064255/ it says it all!
* :)
(Always a pleasure letting others do the talking for me regarding my work...)
APK
P.S.=> It's GOT to absolutely suck to be you (which is the WHY of why you post as an unidentifiable ac - you KNOW you're less than nothing)... apk
Yeah! It says you are a dorky spammer. That is what you are. That is all you are. Accept it and embrace it Only then will you find true religion.
It's GOT to absolutely suck to be you
Ah, but it doesn't. Life is very good, and you're just jealous.
you post as an unidentifiable ac
Exactly like you. See? We're exactly alike, except I'm not a spammer who has been restricted. I still have a working account. Yours has been blocked, quite rightfully. Why? Because you are a spammer and a moronic troll. How simple can it be?
See subject: I know why - you've defeated yourself before like this vs. me (& you know it) MANY times https://tech.slashdot.org/comments.pl?sid=9759361&cid=53064255/ ... so you 'hide' behind unidentifiable ac posts!
It's SO obvious (makes me laugh).
* We're NOTHING alike - I come up with a working solution vs. threats like these along with a program others here (& elsewhere by the 100's of 1,000's) use & like (saying so in that link above as a small sampling thereof). A program that does FAR more for FAR less, natively (vs. illogically & stupidly "Bolting on 'MoAr'" that does less yet consumes more).
APK
P.S.=> You, by way of comparison = a do-nothing "ne'er-do-well" unskilled MENIAL who trolls me by unidentifiable ac posts (+ projecting YOUR JEALOUSY @ folks like myself who get the job done right) & nothing more - lol, yes I am absolutely correct that it's GOT to SUCK to be "someone like you" (lol)... apk
You do nothing but spam Slashdot with your useless crap. As an AC, of course. Put up or shut up... But you can't, because you are nothing but a spammer. I fart in your general direction, and my farts are more intelligent than you can ever hope to be. They are Shakespeare to your trolliness.
See subject: Answer that. You brag about having one, why not use it? You don't since I defeated you like here https://tech.slashdot.org/comm... many times before & you KNOW I'd toss those many self-defeats of yours RIGHT BACK @ YOU AGAIN, & laugh as I do it (everyone else would also)... lol!
* ... That's why you stalk me by unidentifiable ac posts, completely off-topic & offering NOTHING of value on your part...
APK
P.S.=> Being a slinking weasel's no way to spend a life boy - grow up, get on topic, & do something useful w/ your time as I have... apk
Oh yeah... Because you have been banned for spamming. You are a lousy filthy dirty nasty spammer, nothing else. Well, maybe you're a tranny too. You seem the type, a real fruitcake. You have "defeated" no one and have done nothing useful. You are deluding only yourself. You are the mentally handicapped anencephalic clown that is fun to watch, so you're most likely ugly as sin also. Please don't stop trolling and spamming me now. There's nothing to watch on the TV at this moment. Toodles...