Select Menu

Ads

Random Posts

Images de thèmes de Dizzo. Fourni par Blogger.

Blog Archive

Translate

Subscribe Via Email

Subscribe to our newsletter to get the latest updates to your inbox. ;-)

Your email address is safe with us!

Smartphone

best news

biography

‹
›

android

Apple

tutorial

social media


Skype worms are not exactly new anymore (unfortunately).
Scenario is simply: someone on your friends list got infected and is now sending you a link to a ‘funny image’ or pictures of you. In this case, you are being baited by a video of you. Let’s just hope it’s nothing embarrassing ;)
skype worm
Lol! Seems like there’s a cool new video of you going around.
When visiting the (totally not malicious looking) link, you get a video, but apparently you need to download a plugin first:
malicious link
When you click on Install plugin… a new file called ‘setup.exe’ gets downloaded. It’s actually simply a self-extracting archive which contains a file named: ‘setup_BorderlineRunner_142342569355180.exe’
When running the setup.exe file:
skypefall setup
It almost seems like we’re installing legitimate software, SkypeFall version 1.0. Almost.
Clicking Next, Next, Next in the setup wizard, nothing much seems to be happening, but in the background there’s quite a lot going on:
skype setup wizard
A new file called ‘SkypeFall’ is dropped and a new DLL is being registered. Afterwards, two new processes are now active in memory: SkypeFall.exe and rundll32.exe, in which the latter is actually running the DLL BorderlineRunner.dll.
Files are being created in both respectively %programfiles%\BorderlineRunner and %appdata%\SkypeFall. A new service is also registered:
HKLM\System\CurrentControlSet\Services\6b57ae94
Afterwards you’ll spam all your friends with the same message as well, following the pattern:
skype scam

We detect this malware as:
W32/Skyper.A.worm
IOCs
Domains:
hxxp://24onlineskyvideo.info
hxxp://24videotur.in.ua
hxxp://deepskype.net
hxxp://factorygood.net
hxxp://ironskype.net
hxxp://letitskype.info
hxxp://letskype.net
hxxp://popskypevideo.net
hxxp://popvideoskype.com
hxxp://popvideoskype.info
hxxp://popvideoskype.net
hxxp://skypepopvideo.net
hxxp://skypepopvideo.net
hxxp://skyvideo24.in.ua
hxxp://skyvideo24online.in.ua
hxxp://skyvideo24online.ru
hxxp://skyvideotape.in.ua
hxxp://skyvideotape.ru
hxxp://someskype.com
hxxp://someskype.net
hxxp://techine.info
hxxp://techine.net
hxxp://videosk.in.ua
hxxp://videosk.info
hxxp://videoskype.ru
hxxp://videoskype24.ru
hxxp://videoss.in.ua
Hashes (SHA1):
b6f690849e9ed71b3f956078934da5ed88887aa3
42c685ac60555beaacd5e07d5234a6600845e208
dfb9bfb274e9df857bb0fae02ba711e62a2a9eb6
726db7f1c956db8c5e94d21558cbbe650b949b7e

How to avoid the malware W32/Skyper.A.worm

  • Never click on unknown links, especially when a friend sends you a generic text saying there are pictures or videos of you going around. If you’re really curious, ask them first what’s it about. Better be safe than sorry.
  • Don’t be fooled by known icons or “legit” file descriptions, this can easily be altered.
  • Even if you clicked the link and you’re not suspicious, you should be when a file is downloaded and no pictures are shown, but just an EXE file.

You may have woken up this morning to find a Twitter notice asking you to re-enter your Twitter account details. Has your password been stolen? Was this a case of identity theft?
Relax! Just follow a few simple steps and your Twitter account will remain perfectly safe.
The popular micro-blogging network suffered a worldwide outage last night that prevented many users from accessing the service normally for a few hours.
According to Twitter’s information service, Twitter Status, the problem started early morning (CET) and although it is now resolved, some users may still have problems accessing their accounts.
Accounts that appear to have been closed, old messages appearing as recent on timelines… these are some of the effects of thebug that hit the social network.
Have you been affected by this incident?

Videos, videos, and more videos! The millions of YouTube users are probably unaware of the dangers when surfing the platform looking for the next viral hit. However, this Google service is in the eye-line of many cybercriminals.
Through phishing attacks, they try to obtain passwords to access information such as bank data associated with your YouTube channel. The problem may be even greater if the account you use is owned by the company for which you work.
So, in the event that you have a YouTube channel which you use frequently, take note. Carelessness can end up being very expensive taking some precautions will serve you in the long run.

5 tips to protect your YouTube account

1. Be careful with shortened links
To begin with, be wary of any shortened link that reaches you, no matter where it comes from. While most are safe, some hide nasty surprises, like a malware that is automatically downloaded to your computer to steal information. Before clicking, make sure you know where the link will lead you to.
password
2. Use secure passwords
A key aspect in preventing a phishing attack is to have a strong password. It should include a mix of uppercase, lowercase, numbers, symbols and the maximum number of possible. In addition, it is recommended to change your password every three months if you can. This way you’ll be able to ensure that the cybercriminals are stopped in their tracks.
3. Change your  password frequently
As if it needs to be repeated, but be cautious with your password – do not use the same one you use on other platforms and don’t have it written down. We must tread warily in the digital world, but the physical world can be just as dangerous.
4. Don’t give your information away via email
You shouldn’t trust emails that you receive that request the password with which you access your YouTube account. In fact, if it comes from Google itself, be extra wary – an attack uncovered a few months ago shows that a malicious URL, in the guise of a company link, could make users enter their information without realizing it.
5. Fill out the recovery form on Google
It is important that you fill out the recovery form on your Google account. Although you may not like the idea of ​​giving your phone number to the company, it is a good way to avoid bigger issues if you discover that someone tries to enter your account – you’re the only one who has access to the recovery code on your phone.
In short, common sense and some thoughtfulness when creating your password can save you some massive headaches later. Just check carefully where you enter your personal details and this will stop cybercriminals from getting their hands on it.

Have you ever wondered why the advertisements that appear on your Facebook feed offer you the exact product and service that you are supposedly interested in? Have you also stopped to think about what information Candy Crush holds on you, or do you just click play anyway?
Facebook offers you information on your privacy, although it’s like that few users have ever reviewed it. Hardly surprising when you consider that it would take it 76 days to read all of the terms and conditions of the services that we use over the course of a year, according to a study carried out by the Carnegie Mellon University.
It’s likely that lots of workers include information relating to their role in the company on their Facebook profile, so both you and they could benefit from a better level of privacy control on the social media site. Here are a few tips to make it harder for companies to follow your tracks online.

Stop giving away personal information to applications

Every time that you install an application from Facebook it tells you what information you will share with it. In that moment, you can edit the information you wish to share. Seeing as you’ve probably ignored this or have logged into Facebook from the external website, we’ll explain to you how to restrict the details that you give away to the apps.
  • The first thing you have to do is click on the lock in the top right part of the Facebook page. Click on “see more” form the expandable menu and access “settings and privacy tools”.
facebook privacy settings
  • Then, search the left column for the button marked “applications” and click on “see all”. We bet you never expected to see so many websites associated with your Facebook page! Now, it’s time to organize it all.
  • You can click beside each application to delete it from your account, or you can click on the pencil icon to edit the information that each app keeps on you. Keep in mind that there may be some details that are obligatory and you can’t keep them hidden.
facebook remove
  • When you’ve finished this process, go to the bottom of the page where you’ll find two very interesting options. The first of these is the option to activate “always play anonymously” and the second is to edit the information on Facebook that others can see in the apps that you use by clicking on “applications used by others”.
facebook apps

Repel the advertising

If you want to stop Facebook from using your personal information to show you predetermined advertisements, then there are a few ways you can go about it.
  • The first is click on the arrow at the top of the page, beside the lock icon, and access the part for “settings”. In the left column you’ll see “adverts”. From there you can deny Facebook the right to use your actions (for example, things you indicate you like) tooffers ads to your friends and that you don’t receive ads based on their preferences either.
To do this, you need to click on the “edit” option for both “other websites” as well as “adverts and friends” in order to change the default setting from “only friends” to “nobody”.
facebook adverts
You can also use other tools to avoid this personalized advertising such as Facebook Disconnect or Adblock Plus. So, if you want to improve your privacy on Facebook and control what businesses can analyze from your information, you know what to do. It is also recommended that you read the policy of the company so as you know what you’re getting yourself into.


Fake Flash Player updates fool Facebook users.

facebook-fake-flash-small
Facebook users get malware from clicking on fake Flash Player updates.
Facebook users have fallen victim to a recycled scam, and we want to make sure that all of our readers are fore-warned. Cybercrooks use social engineering tactics to fool people into clicking, and when the bait comes from a trusted friend on Facebook, it works very well.
Here’s how the scam works – your friend sends you an interesting video clip; in the latest iteration you are tagged and lots of other friends are also tagged – this makes it seem more trustworthy. The video stops a few seconds in and when you click on it, a message that your Flash Player needs to be updated for it to continue comes up. Since you have probably seen messages from Adobe to update your Flash Player, this does not raise any red flags. Being conscientious about updating your software, as well as curious about what happens next in the video, you click the link. That’s when the fun really begins.
The fake Flash Player is actually the downloader of a Trojan that infects your account. Security researcher Mohammad Faghani, told The Guardian, …” once it infects someone’s account, it re-shares the clip while tagging up to 20 of their friends – a tactic that helps it spread faster than previous Facebook-targeted malware that relied on one-to-one messaging on Facebook.”

How to protect yourself from Facebook video scams

Don’t fall for it. Videos that are supposedly sensational or shocking are also suspect. Be very cautious when clicking.
Does your friend really watch this stuff? If it seems out of character for your friend to share something like that with you, beware. Their account may have been infected by malware, and it’s possible they don’t even know this is being shared. Do them a favor and tell them about it.
Be careful of shortened links. The BBB says that scammers use link-shortening services to disguise malicious links. Don’t fall for it. If you don’t recognize the link destination, don’t click.
Use up-to-date antivirus software like Avast Free Antivirus with full real-time protection.
Social networks have become an integrated part of our lives. Facebook is not just a simple communication channel anymore but an important source of daily news, information about brands, as well as a selling platform. Thanks to mobile apps, we access it everywhere and anytime we want. As active consumers we should take even better care of our security while using the service.

How to set up a secure login for your Facebook account

1. Set up double verification, or so called Login Approvals to achieve your desired security level during the login process. Every time you  login into your account, Facebook will send you a newly generated code via SMS to enter to finish login process. Login approval will allow you to better control who can access your account.  Detailed instructions how to set it up can be found here.
2. Select so-called  trusted contacts. This should be three or four people, who can be contacted by Facebook, in case access to your account is blocked. The selected person will be given an access code, which should be passed to you, so you can restore your account credentials. Therefore choose trusted contacts carefully, so you can easily get in touch in case it’s needed. In order to choose trusted contacts go to Settings -> Security and select friends. If you want to learn more about this setting go here.
3. Set up Login alerts, to be notified in case Facebook spots a suspicious login attempt to your account; for example from an unknown computer or smartphone. A login alert will be delivered to you as a text message, email, or Facebook notification. You decide which format is the most suitable for you. In case you suspect that someone tried to break into your account, Facebook will help you to reset your password and set up a new one. Just as other safety settings you will find login alerts in the Security section. Detailed instructions can be found here.
Facebook login alerts

4. Protect yourself from Phishing and Spam. Cybercrooks try to take over your personal data and login, by creating URLs which look just like Facebook. Please bear in mind that the social network will never send you an email, requesting your credentials or any other personal or financial data. In case you receive such an email, redirecting you to a webpage deceptively resembling Facebook, never ever submit your data. Learn more about Phishing on Facebook here.
On the other hand, if your friends spam you with suspicious messages, or simply bother you with invitations to the “farm games”, it’s possible that they became victims of a malicious app. It can post on their behalf without their knowledge and spread malware further. You can report it to the social network by clicking on the arrow symbol in the right top corner next to the message. Read more in Spams on Facebook section.
5. Last but not least, secure your Facebook mobile app. If, like other millions of Facebook users, you access the social network on mobile, you should consider installing an application that will block the access to Facebook. This is handy in case your mobile is lost or for simply preventing your friends from joking around and posting something on your behalf, while you leave your smartphone unattended.
Avast Mobile Security protects your Facebook and other social networks or banking apps with a security code for free. Download it for free from Google Store
Stay tuned for more social media security and privacy tips!