Dismiss this notice
Master PDF Editor Easter 2019 Giveaway - https://www.geeks.fyi/showthread.php?tid=6240

Dismiss this notice
Avast Premier Easter 2019 Giveaway - https://www.geeks.fyi/showthread.php?tid=6095

Dismiss this notice
Ashampoo Snap 10 Easter 2019 Giveaway - https://www.geeks.fyi/showthread.php?tid=6241

Dismiss this notice
Backup4all Professional Easter 2019 Giveaway - https://www.geeks.fyi/showthread.php?tid=6464


Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
GandCrab Ransomware Discovered To Be Embedded in Super Mario Image
#1
Quote:A newly discovered malware campaign uses steganography to hide GandCrab in a seemingly innocent Mario image.
 
In the Mario Brothers universe, Mario is a hero, but that "good guy" status doesn't extend to the real world — at least not for victims of a malware campaign that wraps the GandCrab ransomware in a Mario graphic package.
Matthew Rowan, a researcher at Bromium, discovered the campaign in a malware sample he was analyzing. In his blog post detailing the discovery, he shows how threat actors hide their true intentions, why it's a very bad idea to disable software protection mechanisms, and why old encryption techniques like steganography are still useful in the modern era.
The steganography comes into play with heavily obfuscated Microsoft PowerShell commands hidden within the color channels of a picture of Mario in a particularly cool pose. Rowan notes that hiding commands in the image makes it very difficult for a firewall to pick up the threat and apply a standard filter against the malware.
The new campaign is a threat to computer users in Italy, though, like most such campaigns, it could easily be modified by a different criminal to target users in any (or every) geography. 
Source
[-] The following 2 users Like Toligo's post:
  • harlan4096, silversurfer
Reply
#2
Quote:Researchers spotted the ransomware GandCrab embedded into a downloadable Mario image from Super Mario Bros.

Matthew Rowan, a researcher at Bromium discovered the malware and identified the trends and patterns to be of an older method, steganography. This form of malware tends to use obfuscated Microsoft PowerShell commands. Similarly, the hacker uses a PowerShell command in this campaign. The targeted emails are sent to individuals in Italy, with an excel document attached. Labelled, “F.DOC.2019 A 259 SPA.xls” it also contains a Macro. The document prompts users to click ‘enable content,’ effectively deploying the malware. The malware firstly checks the region, usually, relying on the administrative language of the operating system. Here the coding used to determine this consisted of using IF statement with country 39, which was Italy. If the device is not based in Italy, then it will not deploy.

[Image: mario-1558068__340.jpg]
Source

Image courtesy of  : latesthackingnews.com
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Latest Threads
Try Out the Reader Mode in Microsoft’s N...
Last Post: silversurfer
Today 14:13
» Replies: 0
» Views: 27
Microsoft Brings a Key Security Feature ...
Last Post: silversurfer
Today 14:13
» Replies: 0
» Views: 26
PC Game Giveaway:Assassins Creed Unity
Last Post: sinanogz
Today 10:57
» Replies: 0
» Views: 24
LibreOffice 6.1.2
Last Post: JM Safe
Today 09:53
» Replies: 5
» Views: 197
WhatsApp Will Allow Users to Block Conve...
Last Post: JM Safe
Today 09:51
» Replies: 1
» Views: 30
Avast Blog_Security News: Facebook wants...
Last Post: harlan4096
Today 07:51
» Replies: 0
» Views: 25
Avast Blog_Tips & Advices: Are budget-tr...
Last Post: harlan4096
Today 07:49
» Replies: 0
» Views: 20
Emsisoft Anti-Malware named one of AVLab...
Last Post: harlan4096
Today 07:41
» Replies: 0
» Views: 47
Next generation antivirus: the future of...
Last Post: harlan4096
Today 07:38
» Replies: 0
» Views: 34
10 Chrome Extensions to Boost Your Onlin...
Last Post: harlan4096
Today 07:31
» Replies: 0
» Views: 22
Microsoft Announces Surface Hub 2S: 50-I...
Last Post: harlan4096
Today 07:26
» Replies: 0
» Views: 18
AMD 50th Anniversary Ryzen CPUs Listed A...
Last Post: harlan4096
Today 07:24
» Replies: 0
» Views: 15
The Huawei P30 & P30 Pro Reviews: Photog...
Last Post: harlan4096
Today 07:22
» Replies: 0
» Views: 25
Samsung Completes Development of 5nm EUV...
Last Post: harlan4096
Today 07:20
» Replies: 0
» Views: 24
TSMC Reveals 6 nm Process Technology: 7 ...
Last Post: harlan4096
Today 07:16
» Replies: 0
» Views: 21
8 ways in which Microsoft Edge (Chromium...
Last Post: harlan4096
Today 07:11
» Replies: 0
» Views: 24
Google to present browser and search cho...
Last Post: harlan4096
Today 07:09
» Replies: 0
» Views: 19
Ubuntu 19.04 is out
Last Post: harlan4096
Today 07:07
» Replies: 0
» Views: 17
Start Menu gets its own process and a pe...
Last Post: harlan4096
Today 07:04
» Replies: 0
» Views: 21
Microsoft explains how Dynamic Updates w...
Last Post: harlan4096
Today 07:02
» Replies: 0
» Views: 23

[-]
Staffs Online
There are no staff members currently online.