Zerosecurity
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Data Breaches
  • Crypto
  • Privacy
  • Downloads
    • Malwarebytes
    • Exploits
    • Paper Downloads
    • Software & Service Reviews
No Result
View All Result
SUBSCRIBE
Zerosecurity
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Data Breaches
  • Crypto
  • Privacy
  • Downloads
    • Malwarebytes
    • Exploits
    • Paper Downloads
    • Software & Service Reviews
No Result
View All Result
Zerosecurity
No Result
View All Result
Home Malware

Malware Protection Whitepaper [VeriSign]

Paul Anderson by Paul Anderson
February 25, 2012
in Malware, Public, Whitepapers
1
virus web malware shield internet
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

This white paper was provided by VeriSign. VeriSign is the trusted provider of Internet infrastructure
services for the digital world and contents are copyright by VeriSign Inc. www.VeriSign.com

You might also like

Emotet now utilizing Onenote for its spam campaigns

Netwire RAT seized by FBI and other worldwide police agencies

The Emotet botnet returns and is sending a slew of malicious emails

malware

 

Malware is crawling onto web sites everywhere :-


This white paper will help you understand the threat from malware and how it can impact your online business. You’ll learn about criminals’ motivations for distributing malware through the web and how they infect web servers to make distribution possible. This paper also highlights techniques administrators can use to detect when and how attackers have compromised their web server.

What is malware ?

Malware is a general term for malicious software, and it is a growing problem on the Internet. Hackers install malware by exploiting security weaknesses on your web server to gain access to your web site. Malware includes everything from adware, which displays unwanted pop-up advertisements, to
Trojan horses, which can help criminals steal confidential information, like online banking credentials.
Malware is increasingly distributed through web browsers. This tactic has become more common in recent years,

The anatomy of malware attacks :-

To infect a computer through a web browser, an attacker must accomplish two tasks. First, they must find a way to connect with the victim. Next, the attacker must install malware on the victim’s computer. Both of these steps can occur quickly and without the victim’s knowledge, depending on the attacker’s tactics.

One way for an attacker to make a victim’s browser execute their malicious code is to simply ask the victim to visit a web site that is infected with malware. Of course, most victims will not visit a site if told it is infected, so the attacker must mask the nefarious intent of the web site. Sophisticated attackers use the latest delivery mechanisms, and often send malware-infected messages over social networks, such as
Facebook, or through instant messaging systems. While these methods have proved successful to a degree, they still rely on tempting a user to visit a particular web site. Other attackers choose to target web sites that potential victims will visit on their own. To do this, an attacker compromises the targeted web site and inserts a small piece of HTML code that links back to their server. This code can be loaded from any location, including a completely different web site. Each time a user visits a web site compromised in this manner, the attacker’s code has the chance to infect their system with malware.

Malware code is not easily detectable and may infect consumers’ computers when they simply browse your web site. This is known as “drive-by” malware, and users are largely (or completely) unaware that their systems have become compromised with this type of attack—making it a particularly insidious problem. Hackers use drive-by malware to spread viruses, hijack computers, or steal sensitive data, such as credit card numbers or other personal information.
How drive-by malware works, and are small web sites at risk?

Drive-by malware downloads itself onto a user’s system without their consent. Cybercriminals exploit browser and/or plug—in vulnerabilities to deliver the malware by hiding it within a web page as an invisible element (e.g., an iframe or obfuscated javascript) or by embedding it in an image (e.g., a flash or PDF file) that can be unknowingly delivered from the web site to the visitor’s system. Any web site is at risk. Small sites can be more vulnerable because they are less likely to have the resources and expertise needed to detect and rapidly respond to attacks. Malware may infect your customers’ computers when
they simply browse your site. Targeting web sites with low traffic allows hackers to avoid detection longer and cause more damage.
malwareattackandroidphone
Common types of malware delivery mechanisms :-
• Software updates: Malware posts invitations inside social media sites, inviting users to view a video.
The link tries to trick users into believing they need to update their current software to view the video.
The software offered is malicious.
• Banner ads: Sometimes called “malvertising,” unsuspecting users click on a banner ad that then
attempts to install malicious code on the user’s computer. Alternatively, the ad directs users to a web site that instructs them to download a PDF with heavily-obscured malicious code, or they are instructed
to divulge payment details to download a PDF properly.
• Downloadable documents: Users are enticed into opening a recognizable program, such as Microsoft
Word or Excel, that contains a preinstalled Trojan horse.
• Man-in-the-middle: Users may think they are communicating with a web site they trust. In reality,
a cybercriminal is collecting the data users share with the site, such as login and password. Or, a criminal can hijack a session, and keep it open after users think it has been closed. The criminal can then conduct their malicious transactions. If the user was banking, the criminal can transfer funds. If the user was shopping, a criminal can access and steal the credit card number used in the transaction.
• Keyloggers: Users are tricked into downloading keylogger software using any of the techniques mentioned above. The keylogger then monitors specific actions, such as mouse operations or keyboard
strokes, and takes screenshots in order to capture personal banking or credit card information.
The malware business model :-

 

How do attackers use malware to turn a profit? They can use infected computers to generate income in many ways. One of the simplest is through advertising. Just as many of the websites generate income by displaying ads, malware can display ads that result in payments to the cybercriminal.
Alternatively, extortion is used. A large network of infected computers can be very powerful, and some attackers use this threat to extract payments from web site owners. A group of computers controlled by one attacker, known as a “botnet,” can send a large amount of network traffic to a single web
site, which can result in a denial of service (DoS) attack.
The criminals then contact the web site owner and demand a payment to stop the attack. Criminals also frequently use infected computers to gather valuable user information, such as credentials for online
banking. This type of malware, known as an infostealer or banking Trojan, is one of the most sophisticated and stealthy forms of malware. The criminals can then use the private information for their own malicious schemes or sell it to a third-party who then uses it to make a profit.
What is blacklisting, and why is it important to avoid?
Because of the potential damage caused by malware, Google, Yahoo, Bing and other search engines place any web site found with malware on a blocked list, or “blacklist.” Once blacklisted, the search engine issues a warning to potential visitors that the site is unsafe or excludes it from search results altogether. No matter how much search engine optimization you do, if your web site is blacklisted the impact to your business could be devastating. This blacklisting can occur without warning, is often done without your knowledge, and is very difficult to reverse. Taking the proper measures to prevent search engine blacklisting is critical to the long-term success of any web site.
Tags: malwareMalware Analysisupdatewhitepaper
Share30Tweet19
Paul Anderson

Paul Anderson

Editor and chief at ZeroSecurity. Expertise includes programming, malware analysis, and penetration testing. If you would like to write for ZeroSecurity, please click "Contact us" at the top of the page.

Recommended For You

Emotet now utilizing Onenote for its spam campaigns

by Kyle
March 26, 2023
0
Emotet now utilizing Onenote for its spam campaigns

The infamous Emotet malware has adopted a new tactic to spread its infection. Cybercriminals are now distributing the malware via email attachments in Microsoft OneNote format. The move...

Read more

Netwire RAT seized by FBI and other worldwide police agencies

by Christi Rogalski
March 16, 2023
0
Netwire RAT seized by FBI and other worldwide police agencies

The FBI, in partnership with several police agencies worldwide, has carried out an international law enforcement operation resulting in the arrest of a suspected administrator of the NetWire...

Read more

The Emotet botnet returns and is sending a slew of malicious emails

by Kyle
March 14, 2023
0
The Emotet botnet returns and is sending a slew of malicious emails

The notorious Emotet botnet, considered one of the biggest threats to internet security, has resurfaced after a prolonged hiatus, armed with new tactics. The botnet's trademark strategy of...

Read more

Update-resistant malware infects SonicWall security appliances

by Paul Anderson
March 12, 2023
0
Update-resistant malware infects SonicWall security appliances

Researchers have discovered that threat actors linked to the Chinese government are using malware to infect SonicWall's Secure Mobile Access 100, a popular security appliance, which remains active...

Read more

Fake ChatGPT websites are popping up and spreading malware

by Paul Anderson
March 1, 2023 - Updated on March 2, 2023
0
ChatGPT is found spreading malware created in Python

It was only a matter of time before hackers would start using the growing popularity of ChatGPT to spread malware and steal sensitive personal information. Recently, multiple security...

Read more
Next Post
100+ Sites hacked by Orionshunter

100+ Sites hacked by Orionshunter

Related News

NSA intercepting U.S. Routers

NSA intercepting U.S. Routers

June 6, 2014 - Updated on March 17, 2023
Netwire RAT seized by FBI and other worldwide police agencies

Netwire RAT seized by FBI and other worldwide police agencies

March 16, 2023
The Emotet botnet returns and is sending a slew of malicious emails

The Emotet botnet returns and is sending a slew of malicious emails

March 14, 2023
Zerosecurity

We cover the latest in Information Security & Blockchain news, as well as threat trends targeting both sectors.

Categories

  • Crypto
  • Data Breaches
  • DotNet Framework
  • Downloads
  • Exploits
  • Exploits
  • Information
  • Legal
  • Malware
  • Malware Analysis
  • Mobile Security
  • Paper Downloads
  • Piracy
  • Privacy
  • Programming
  • Public
  • Security
  • Security
  • Software & Service Reviews
  • Technology News
  • Tools
  • Tutorials
  • Video Tutorials
  • Whitepapers
  • Zero Security
  • Contact Us
  • List of our Writers

© 2022 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Tools
  • Contact Us
  • Privacy Policy

© 2022 ZeroSecurity, All Rights Reserved.