Website Lenovo distributed malicious code
Hackers have attacked vebsite to support downloading drivers from leading Chinese computer manufacturers, Lenovo and inserting malicious code into the website. Many users searching for computer drivers on this website have been removed from the system by Bredolab trojan.
According to Bkis, many customers access the Lenovo website on June 22 and 23 to download drivers that have received a warning from the security program announcing malicious code on the site.
ESET NOD32 Antivirus security program identifies files
pdf file with embedded malicious code is a trojan type (Photo: Internet)
The malicious code exploit code is stored in volgo-marun (.) Cn. After performing a number of checks to identify software that is carrying security flaws installed on the visitor's system, the exploit code will focus on the old Internet Explorer browser security vulnerabilities. Adobe Reader or Adobe Flash Player.
"These exploit codes will download the volgo-marun.cn/pek/exe.exe file (identified as a virus) into the victim computer. Virus is a variant of Bredolab Botnet After successful penetration , the virus will clone to% Programs% Startupmonskc32.exe and receive commands from the server with the domain name sicha-linna8.com ", according to the Bkis blog.
The new variant of malicious code is only recognized by 10/41 antivirus programs, tested by VirusTotal. The download.lenovo.com subdomain is marked " black " by Google's Safe Browsing service. Accordingly, users using two browsers FireFox and Chrome will receive malicious code alerts when opening the resources on this site.
The section to prevent access and warning of malicious code of Google Safe Browsing
(dark red frame in the middle of the page) - (Photo: Internet)
Currently, users are advised to temporarily not access the download.lenovo.com website until the cleanup department " clean " the malicious code and patch the vulnerability to prevent hackers from breaking in again.
You should read it
- ESET launched NOD32 Antivirus 5 and Smart Security 5
- 7 best antivirus programs for Ubuntu
- Trojan inserts ads into OS X browser
- Offer free monthly ESET antivirus software license for PC and Android
- Use SEO to bring Google search results to bank trojans
- ESET Cybersecurity security software for Mac
- Appeared trojan trojan antivirus tool for mobile
- Fileless malware - Achilles heel of traditional antivirus software
May be interested
- 2 Dangerous Trojans are being distributed heavily through fake VPN websinternational cybersecurity researchers recently discovered a fake website that hides a vpn service, but is actually used to spread and install two malicious password-stealing trojans, vidar and cryptbot, into the network. victim's system.
- 10 million Android devices are preinstalled with malicious code from the factorybad guys have compromised with the manufacturer to install malicious code on the device.
- Detects malicious code showing porn ads in children's games on Google Playcheck point security company has discovered malicious code called adultswine that appears in children's games on google play.
- GIBON extortion code spread through spama new ransomware called gibon, once again malspam (malware spread via email) attaches a malicious file and contains the download macro, installs the malicious code to blackmail the victim's computer.
- Malware sneaks into iOS through Apple's official distribution channelstaking advantage of distribution channels of unapproved applications for testing purposes, malicious code has quietly sneaked into ios users' devices.
- Appearing dangerous Android malicious code specializing in stealing chat content on Facebook Messenger, Skype ...a type of malware that has a package name is com.android.boxa that can steal users' private chat data on current messaging applications such as facebook messenger, skype, etc., by experts from the company. network security trustlook detected on android operating system.
- Discover a new kind of malicious code that can record the phone call to extort moneyreddrop is one of the most sophisticated android malware that researchers have ever seen spread widely.
- Discovered a new line of malicious Android code that steals user data on the electronic application marketrecently a security expert at trend micro discovered a new line of malicious code first written in kotlin, a kind of static language for android programmers.
- Defeat China's largest hacker training furnacechinese police have closed the website to recruit thousands of members and provide training on cyber attacks and malicious code.
- Android apps contain malicious code that uses motion sensors to avoid detectionthe sad fact is that after many efforts by google to isolate the play store from malware, malicious applications somehow find new ways to deceive measures. malware prevention ...