Home Discord Chat
Go Back   ChiefsPlanet > Nzoner's Game Room > Media Center
Register FAQDonate Members List Calendar

Reply
 
Thread Tools Display Modes
Old 09-22-2017, 09:46 AM  
Fish Fish is offline
Ain't no relax!
 
Fish's Avatar
 
Join Date: Sep 2005
Casino cash: $2308919
CCleaner app found to be distributing malware

Attention. If you are using the cleanup app CCleaner, I would recommend uninstalling it immediately. I've warned about this shady app before. Turns out it is knowingly distributing malware in its code.

It was initially reported that malware was found, but it didn't appear that it had actually infected any computers. But a recent update to the story shows that it was much worse than that...

CCleaner malware outbreak is much worse than it first appeared

Microsoft, Cisco, and VMWare among those targeted with additional mystery payload.

The recent CCleaner malware outbreak is much worse than it initially appeared, according to newly unearthed evidence. That evidence shows that the CCleaner malware infected at least 20 computers from a carefully selected list of high-profile technology companies with a mysterious payload.

Previously, researchers found no evidence that any of the computers infected by the booby-trapped version of the widely used CCleaner utility had received a second-stage payload the backdoor was capable of delivering. The new evidence—culled from data left on a command-and-control server during the last four days attackers operated it—shows otherwise. Of 700,000 infected PCs, 20 of them, belonging to highly targeted companies, received the second stage, according to an analysis published Wednesday by Cisco Systems' Talos Group.
Because the CCleaner backdoor was active for 31 days, the total number of infected computers is "likely at least in the order of hundreds," researchers from Avast, the antivirus company that acquired CCleaner in July, said in their own analysis published Thursday.


From September 12 to September 16, the highly advanced second stage was reserved for computers inside 20 companies or Web properties, including Cisco, Microsoft, Gmail, VMware, Akamai, Sony, and Samsung. The 20 computers that installed the payload were from eight of those targeted organizations, Avast said, without identifying which ones. Again, because the data covers only a small fraction of the time the backdoor was active, both Avast and Talos believe the true number of targets and victims was much bigger.

More fileless malware

The second stage appears to use a completely different control network. The complex code is heavily obfuscated and uses anti-debugging and anti-emulation tricks to conceal its inner workings. Craig Williams, a senior technology leader and global outreach manager at Talos, said the code contains a "fileless" third stage that's injected into computer memory without ever being written to disk, a feature that further makes analysis difficult. Researchers are in the process of reverse engineering the payload to understand precisely what it does on infected networks.

"When you look at this software package, it's very well developed," Williams told Ars. "This is someone who spent a lot of money with a lot of developers perfecting it. It's clear that whoever made this has used it before and is likely going to use it again."

Stage one of the malware collected a wide assortment of information from infected computers, including a list of all installed programs, all running processes, the operating-system version, hardware information, whether the user had administrative rights, and the hostname and domain name associated with the system. Combined, the information would allow attackers not only to further infect computers belonging to a small set of targeted organizations, but it would also ensure the later-stage payload is stable and undetectable.

Now that it's known the CCleaner backdoor actively installed a payload that went undetected for more than a month, Williams renewed his advice that people who installed the 32-bit version of CCleaner 5.33.6162 or CCleaner Cloud 1.07.3191 reformat their hard drives. He said simply removing the stage-one infection is insufficient given the proof now available that the second stage can survive and remain stealthy.

The group behind the attack remains unknown. Talos was able to confirm an observation, first made by AV provider Kaspersky Lab, that some of the code in the CCleaner backdoor overlaps with a backdoor used by a hacking group known both as APT 17 and Group 72. Researchers have tied this group to people in China. Talos also noticed that the command server set the time zone to one in the People's Republic of China. Williams warned, however, that attackers may have deliberately left the evidence behind as a "false flag" intended to mislead investigators about the true origin of the attack.

[...]
Posts: 47,478
Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.
    Reply With Quote
Old 09-22-2017, 09:53 AM   #2
SuperChief SuperChief is offline
Damn it feels good.
 
SuperChief's Avatar
 

Join Date: Mar 2011
Casino cash: $7547978
Thanks for the heads up, Fish.
__________________
Posts: 3,305
SuperChief is blessed with 50/50 Hindsight.SuperChief is blessed with 50/50 Hindsight.SuperChief is blessed with 50/50 Hindsight.SuperChief is blessed with 50/50 Hindsight.SuperChief is blessed with 50/50 Hindsight.SuperChief is blessed with 50/50 Hindsight.SuperChief is blessed with 50/50 Hindsight.SuperChief is blessed with 50/50 Hindsight.SuperChief is blessed with 50/50 Hindsight.SuperChief is blessed with 50/50 Hindsight.SuperChief is blessed with 50/50 Hindsight.
    Reply With Quote
Old 09-22-2017, 10:00 AM   #3
Bowser Bowser is offline
sorta mod-ish
 
Bowser's Avatar
 

Join Date: Jan 2004
Location: KC North
Casino cash: $3471616
Thanks.

I had it on my old phone that crapped out. It was in my app library on my replacement phone, but not installed. Removed it anyway.
Posts: 100,581
Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.
    Reply With Quote
Old 09-22-2017, 10:03 AM   #4
Bowser Bowser is offline
sorta mod-ish
 
Bowser's Avatar
 

Join Date: Jan 2004
Location: KC North
Casino cash: $3471616
In light of the Equifax debacle and now this, it would appear hackers are progressing around two or three times the speed as those that try to stop them.
Posts: 100,581
Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.Bowser is obviously part of the inner Circle.
    Reply With Quote
Old 09-22-2017, 10:14 AM   #5
InChiefsHeaven InChiefsHeaven is offline
Rockin' yer FACE OFF!
 
InChiefsHeaven's Avatar
 

Join Date: Feb 2003
Location: Omaha, Nebraska
Casino cash: $3904937
Damn, thanks for that. I use it on my home PC. I'll be taking that off when I get home.
__________________

We have a million reasons for failure, but not one excuse...
Die Donks, DIE!!
Holy Crap fellas!!! We did it!!! THREE TIMES!!!
Posts: 25,717
InChiefsHeaven is obviously part of the inner Circle.InChiefsHeaven is obviously part of the inner Circle.InChiefsHeaven is obviously part of the inner Circle.InChiefsHeaven is obviously part of the inner Circle.InChiefsHeaven is obviously part of the inner Circle.InChiefsHeaven is obviously part of the inner Circle.InChiefsHeaven is obviously part of the inner Circle.InChiefsHeaven is obviously part of the inner Circle.InChiefsHeaven is obviously part of the inner Circle.InChiefsHeaven is obviously part of the inner Circle.InChiefsHeaven is obviously part of the inner Circle.
    Reply With Quote
Old 09-22-2017, 12:40 PM   #6
kcxiv kcxiv is offline
In Search of a Life
 

Join Date: Mar 2005
Location: Central Valley, Cali
Casino cash: $8807996
The activity was discovered on September 12, and while Piriform says it's already patched CCleaner Cloud, users running CCleaner will need to upgrade immediately.

its already been patched.
Posts: 29,110
kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.
    Reply With Quote
Old 09-23-2017, 12:32 AM   #7
Demonpenz Demonpenz is offline
I got Rice cookin in the micro
 
Demonpenz's Avatar
 

Join Date: Nov 2003
Location: Apartment "G UNIT!"
Casino cash: $3152136
Damn I downloaded that shi to every folder, oh well I didn't pay shit for it.
__________________
Posts: 54,267
Demonpenz is obviously part of the inner Circle.Demonpenz is obviously part of the inner Circle.Demonpenz is obviously part of the inner Circle.Demonpenz is obviously part of the inner Circle.Demonpenz is obviously part of the inner Circle.Demonpenz is obviously part of the inner Circle.Demonpenz is obviously part of the inner Circle.Demonpenz is obviously part of the inner Circle.Demonpenz is obviously part of the inner Circle.Demonpenz is obviously part of the inner Circle.Demonpenz is obviously part of the inner Circle.
    Reply With Quote
Old 09-25-2017, 03:54 PM   #8
Boon Boon is offline
a.k.a. Lenny
 
Boon's Avatar
 

Join Date: Oct 2004
Location: Smack dab in the middle
Casino cash: $9637069
Thanks for the information. Haven't used it but have heard of it.
Posts: 1,919
Boon must have mowed badgirl's lawn.Boon must have mowed badgirl's lawn.Boon must have mowed badgirl's lawn.Boon must have mowed badgirl's lawn.Boon must have mowed badgirl's lawn.Boon must have mowed badgirl's lawn.Boon must have mowed badgirl's lawn.Boon must have mowed badgirl's lawn.Boon must have mowed badgirl's lawn.Boon must have mowed badgirl's lawn.Boon must have mowed badgirl's lawn.
    Reply With Quote
Old 09-25-2017, 06:09 PM   #9
kcxiv kcxiv is offline
In Search of a Life
 

Join Date: Mar 2005
Location: Central Valley, Cali
Casino cash: $8807996
again, its gotten patched like right after they found out someone got passed their backdoor. There is no malware in it if you have the current version of it.
Posts: 29,110
kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.kcxiv is too fat/Omaha.
    Reply With Quote
Old 09-25-2017, 07:51 PM   #10
Fish Fish is offline
Ain't no relax!
 
Fish's Avatar
 

Join Date: Sep 2005
Casino cash: $2308919
It's a shit app, and always has been. I do not recommend using it, regardless of whether they say it's been patched.
__________________
Posts: 47,478
Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.
    Reply With Quote
Old 09-26-2017, 08:55 PM   #11
Simply Red Simply Red is offline
You Sweetie!
 
Simply Red's Avatar
 

Join Date: Sep 2005
Casino cash: $2021206219
VARSITY
Quote:
Originally Posted by Fish View Post
It's a shit app, and always has been. I do not recommend using it, regardless of whether they say it's been patched.
will this interfere with porn?
Posts: 71,691
Simply Red is obviously part of the inner Circle.Simply Red is obviously part of the inner Circle.Simply Red is obviously part of the inner Circle.Simply Red is obviously part of the inner Circle.Simply Red is obviously part of the inner Circle.Simply Red is obviously part of the inner Circle.Simply Red is obviously part of the inner Circle.Simply Red is obviously part of the inner Circle.Simply Red is obviously part of the inner Circle.Simply Red is obviously part of the inner Circle.Simply Red is obviously part of the inner Circle.
    Reply With Quote
Old 09-26-2017, 09:19 PM   #12
Fish Fish is offline
Ain't no relax!
 
Fish's Avatar
 

Join Date: Sep 2005
Casino cash: $2308919
Quote:
Originally Posted by Simply Red View Post
will this interfere with porn?
Fear not, this will not affect your goat bestiality porn search settings in any way.
__________________
Posts: 47,478
Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.Fish is obviously part of the inner Circle.
    Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump




All times are GMT -6. The time now is 06:02 AM.


This is a test for a client's site.
Fort Worth Texas Process Servers
Covering Arlington, Fort Worth, Grand Prairie and surrounding communities.
Tarrant County, Texas and Johnson County, Texas.
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2024, vBulletin Solutions, Inc.