Tilon, son of Silon, or… SpyEye2 evolution of SpyEye? The malware family commonly known as Tilon has been around for several years now. While several public analysis reports have described the malware; no one has thus far linked it with the well-known SpyEye malware family. In light of the recent news of the guilty plea … Continue reading Tilon/SpyEye2 intelligence report
Malicious advertisements served via Yahoo
Detection of the infection Fox-IT operates the shared Security Operations Center service ProtACT. This service monitors the networks of our clients for malicious activity. On January 3 we detected and investigated the infection of clients after they visited yahoo.com. Infection Clients visiting yahoo.com received advertisements served by ads.yahoo.com. Some of the advertisements are malicious. Those … Continue reading Malicious advertisements served via Yahoo
Not quite the average exploit kit: Zuponcic
A couple of weeks ago at the FOX-IT SOC, we noticed Zuponcic attempting to infect one of our clients protected networks. The incident was caused by a person visiting the website of Suriname's Ministry of Finance, minfin.sr. This post connects three recent developments in the realm of malware infections: .htaccess server compromise, the Zuponcic exploit … Continue reading Not quite the average exploit kit: Zuponcic
Large botnet cause of recent Tor network overload
Recently, Roger Dingledine described a sudden increase in Tor users on the Tor Talk mailinglist. To date there has been a large amount of speculation as to why this may have happened. A large number of articles seem to suggest this to be the result of the recent global espionage events, the evasion of the … Continue reading Large botnet cause of recent Tor network overload
DNS takeover redirects thousands of websites to malware
Starting on Mon, 5 august 2013, 06:57:30 Fox-IT's monitoring service detected a redirect occurring initially on conrad.nl but later on many other websites. The way the site was compromised means thousands of websites are redirecting, in total 3 web hosters seem to have been affected by the DNS server compromise: Digitalus VDX Webstekker All sites … Continue reading DNS takeover redirects thousands of websites to malware
Analysis of malicious advertisements on telegraaf.nl
Starting on Wed, 31 July 2013, 18:54:50 Fox-IT's monitoring system detected a redirect occurring on telegraaf.nl. It was another case of advertisement provider abuse. One of the advertisement providers loaded ads from an outside resource which returned an exploit kit named "FlimKit" exploit kit. After first being removed from telegraaf.nl a second exploit kit redirect … Continue reading Analysis of malicious advertisements on telegraaf.nl
Analysis of the KINS malware
The malware family KINS, thought to be new by researchers, has been used in private since at least December 2011 to attack financial institutions in Europe, specifically Germany and The Netherlands. It is fully based on the leaked ZeuS source code, with some minor additions. While the technical additions are interesting, they are far from … Continue reading Analysis of the KINS malware
Geïnfecteerde advertenties op nu.nl
Fox-IT houdt voor haar klanten de netwerkbeveiliging in de gaten. Hierbij zijn op 5 juni tussen 10:42 en 15:34 besmettingen geconstateerd van klanten die nu.nl bezochten. Er zijn waarschijnlijk meer Nederlanders besmet na een bezoek aan nu.nl. De infectie werd verspreid via advertenties. De oorzaak is een advertentieserver die op nu.nl adverteerde. De software om … Continue reading Geïnfecteerde advertenties op nu.nl
Security advisory: Unencrypted storage of confidential information in Keeper® Password & Data Vault v5.3 for iOS
Summary Paul Pols of Fox-IT's penetration testing team discovered a critical vulnerability in version 5.3 of the "Keeper® Password & Data Vault" app for iPhones, iPods touch and iPads. An update was released today that is said to resolve the issues that we identified. We urge all users of this application to install this update … Continue reading Security advisory: Unencrypted storage of confidential information in Keeper® Password & Data Vault v5.3 for iOS
Seen in the wild: Updated Exploit Kits
In early March, after one of our network sensors flagged an incident at one of our customers, we noticed some traffic going to a rather suspicious .biz domain. When looking into the details of this domain, we found it to be registered to a guy named "Lukas Vask". When doing a reverse whois on just the … Continue reading Seen in the wild: Updated Exploit Kits