Website Lenovo distributed malicious code
Hackers have attacked vebsite to support downloading drivers from leading Chinese computer manufacturers, Lenovo and inserting malicious code into the website. Many users searching for computer drivers on this website have been removed from the system by Bredolab trojan.
According to Bkis, many customers access the Lenovo website on June 22 and 23 to download drivers that have received a warning from the security program announcing malicious code on the site.
ESET NOD32 Antivirus security program identifies files
pdf file with embedded malicious code is a trojan type (Photo: Internet)
The malicious code exploit code is stored in volgo-marun (.) Cn. After performing a number of checks to identify software that is carrying security flaws installed on the visitor's system, the exploit code will focus on the old Internet Explorer browser security vulnerabilities. Adobe Reader or Adobe Flash Player.
"These exploit codes will download the volgo-marun.cn/pek/exe.exe file (identified as a virus) into the victim computer. Virus is a variant of Bredolab Botnet After successful penetration , the virus will clone to% Programs% Startupmonskc32.exe and receive commands from the server with the domain name sicha-linna8.com ", according to the Bkis blog.
The new variant of malicious code is only recognized by 10/41 antivirus programs, tested by VirusTotal. The download.lenovo.com subdomain is marked " black " by Google's Safe Browsing service. Accordingly, users using two browsers FireFox and Chrome will receive malicious code alerts when opening the resources on this site.
The section to prevent access and warning of malicious code of Google Safe Browsing
(dark red frame in the middle of the page) - (Photo: Internet)
Currently, users are advised to temporarily not access the download.lenovo.com website until the cleanup department " clean " the malicious code and patch the vulnerability to prevent hackers from breaking in again.
You should read it
- ESET launched NOD32 Antivirus 5 and Smart Security 5
- 7 best antivirus programs for Ubuntu
- Trojan inserts ads into OS X browser
- Offer free monthly ESET antivirus software license for PC and Android
- Use SEO to bring Google search results to bank trojans
- ESET Cybersecurity security software for Mac
- Appeared trojan trojan antivirus tool for mobile
- Fileless malware - Achilles heel of traditional antivirus software
May be interested
- Watch out for fake viruses Facebook Photoget a link via yahoo messenger or windows live messenger in the form of hxxp: //ow.ly.../http: //www.facebook.com/photo.php, hurriedly click to see that you are 'sticky' virus.
- Appeared malicious software 'clones' famous softwarebitdefender - the leading provider of security solutions in the world has discovered and warned the return of famous brand clone software.
- Kaspersky can forecast malware translationkaspersky lab has just received a patent in the united states on technology that allows to accurately predict the potential scale of malware outbreaks to prevent them from spreading.
- Scanning for viruses before usingto prevent the computer from being infected with malicious code or malware, you should scan the files before using them
- New virus attacks industrial security systemsimens is warning customers about a new, potentially dangerous virus that can attack computers used to manage industrial control systems.
- Stubborn Malware Removal with SuperAntiSpywaresuper anti spyware is another virus scanner that detects, detects and removes malware.