The God Method – or Windows Grasp Control Panel shortcut – is an undocumented feature created into all versions of Windows given that Vista. It enables users to established up a exclusive folder that presents them brief accessibility to all Windows regulate panels and settings, like My Personal computer or their printers folder. But states McAfee investigate architect Craig Schmugar in a 26 April web site: “Attackers are now applying this undocumented feature for evil finishes.” McAfee has discovered an instance of the Dynamer Trojan concealed inside a shortcut folder. The malware is crafted to endure reboots, and when the unsuspecting consumer checks the folder in which the malware is concealed, they are proven a window that is made up of no documents. “To make issues worse,” Schmugar states, “the malware author has attempted to give this directory everlasting lifestyle, by pre-pending the identify ‘com4′. This kind of unit names are forbidden by usual Windows Explorer and cmd.exe instructions and Windows treats the folder as a unit – consequently preventing users from normally effortlessly deleting the folder with Explorer or usual console instructions.” McAfee presents no even more element of the author of the malware, or any exploitation in the wild. But it indicates a remedy to users: they should terminate the malware by way of Process Manager or related then operate this command from the command prompt (cmd.exe):
rd “.%appdata%com4.241D7C96-F8BF-4F85-B01F-E2B043341A4B” /S /Q Individually, McAfee has also discovered new ‘macro’ malware that uses state-of-the-art obfuscation and many levels of evasion to escape detection. Macro malware – prevalent in the nineties – ordinarily drops destructive MS Office documents by way of macros that contains Visual Fundamental scripts. And in a 26 April web site, McAfee Labs’ Devendra Singh states the most up-to-date variant discovered in the wild uses virtual device recognition to escape examination by protection researchers, and sandbox recognition to steer clear of honeypot traps. McAfee is linking the malware to an unnamed identified “threat group” which beforehand dispersed the Donoff Trojan. Singh explained: “These actors have compromised a authentic site to deploy their payload. During our examination, this really hard-coded website link served a file which indicated that the attackers ended up even now getting ready the setting and had not yet uploaded a destructive payload. Intel Safety has contacted the site proprietor.” This article originally appeared at scmagazineuk.com
Resource website link Share this:Click to share on Twitter (Opens in new window)Click to share on Facebook (Opens in new window)Click to share on Google+ (Opens in new window)
Related
The God Method – or Windows Grasp Control Panel shortcut – is an undocumented feature created into all versions of Windows given that Vista. It enables users to established up a exclusive folder that presents them brief accessibility to all Windows regulate panels and settings, like My Personal computer or their printers folder.
But states McAfee investigate architect Craig Schmugar in a 26 April web site: “Attackers are now applying this undocumented feature for evil finishes.”
McAfee has discovered an instance of the Dynamer Trojan concealed inside a shortcut folder. The malware is crafted to endure reboots, and when the unsuspecting consumer checks the folder in which the malware is concealed, they are proven a window that is made up of no documents.
“To make issues worse,” Schmugar states, “the malware author has attempted to give this directory everlasting lifestyle, by pre-pending the identify ‘com4′. This kind of unit names are forbidden by usual Windows Explorer and cmd.exe instructions and Windows treats the folder as a unit – consequently preventing users from normally effortlessly deleting the folder with Explorer or usual console instructions.”
McAfee presents no even more element of the author of the malware, or any exploitation in the wild. But it indicates a remedy to users: they should terminate the malware by way of Process Manager or related then operate this command from the command prompt (cmd.exe):
Individually, McAfee has also discovered new ‘macro’ malware that uses state-of-the-art obfuscation and many levels of evasion to escape detection.
Macro malware – prevalent in the nineties – ordinarily drops destructive MS Office documents by way of macros that contains Visual Fundamental scripts. And in a 26 April web site, McAfee Labs’ Devendra Singh states the most up-to-date variant discovered in the wild uses virtual device recognition to escape examination by protection researchers, and sandbox recognition to steer clear of honeypot traps.
McAfee is linking the malware to an unnamed identified “threat group” which beforehand dispersed the Donoff Trojan.
Singh explained: “These actors have compromised a authentic site to deploy their payload. During our examination, this really hard-coded website link served a file which indicated that the attackers ended up even now getting ready the setting and had not yet uploaded a destructive payload. Intel Safety has contacted the site proprietor.”
This article originally appeared at scmagazineuk.com
