Off late, malware economy is proving to be a lucrative deal for cyber outlaws and there is no nook which has been left unscathed from this usher of despondency. Anytime, anywhere malware can reach at you and that too at times when you are least cagey. But then, the prudent way is to turn every stone to trace out the pugmarks of devilry before they could land up through the doorway of your very own duck diamond. Getting cyber looted and ending with spoofed credentials is just not affordable in the times when most of your financial tomes are lying on the cyber racks.

‘Push-Pull’ affairs

Clearly pigeonholed into two distinct branches, web threats can be Pushbased or Pullbased. Putting forth techniques such as phishing, spam or DNS poisoning (pharming), the main schema of Pushbased threats is to entice a user to malicious (often spoofed) web sites, which then serve the pivotal function of gathering information or infusing malware. Often monikered as “drive-by” threats, “Pull-based threats” have been known to ensnare any naïve visitor despite of safety measures. The core line of action involves infecting legitimate web sites, which then unwittingly transmits malware to visitors or alter search results to take users to malicious sites.

The Deadly Five

Count on the variety of ways malware can arrive at you to ransack your cyber integrity:

• Banner ads

It’s time to give a bid adieu to genuine advertising as “malvertising” is sooner going to outpace everything in coming future. Especially, if you’re a tech novice, probabilities run too high that you might stumble upon an authentic-prototype malicious banner ad by chance and once you click on it, you end up finding yourself in a bigger conundrum. This ad page may direct you towards a website where you are being told to download a .pdf file, heavily infested with malicious coding or you are being asked to unveil your financial details in order to wind up the downloading task properly.

• Downloadable documents

Downloadable docs in form of MS Word or Excel formats can prove a fitting medium to dispense malicious code far and wide. In this line of action, users are lured to open a Word or Excel file which already contains a preinstalled Trojan horse.

• Keyloggers

Innocent users are coaxed and cajoled in myriad of ways to download keyloggers, which then keep a strictly keen eyes on every of your digital movements. The screen shots of your credit card and other vital information are then taken before being packed and send across to muggers.

• Man-in-the-middle

In this modus operandi, users are made to believe that they are reaching out to an authentic website but on the other side of the picture, cybercriminals are collecting the crucial login ids and passwords or in some cases may commandeer the whole login session, where malicious financial transactions are conducted stealthily.

 

What to do in case you fall a victim to identity theft?
Wednesday, March 28th, 2012 | Author:

It goes without saying that jitteratis are no sooner getting any respite from growing cyber melancholies. Whether its virus attack, hacking, phishing or more recent-identity theft, cyber freebooters have decided not to give a sigh of relief to internet denizens in coming future. Identity thefts have come to lie as a recent hobby horse of bandits and statistics also hold the truthiness of this very fact. Around 4% to 6% percent of U.S. population have reported to be an unwary victim of one or other kind of identity theft. So what to do if you also come to lie as a hapless muggee of identity theft? Read on to know more on how to escape the lurid identity theft experience if you happen to stumble upon by chance.

Know first the tell-tale signs of disaster

A bad credit report stating missing payments or receiving unfamiliar IRS filings at your name, these are sure shot signs that freebooters have ran over your hard earned deposits. Then, while on shopping, if your credit cards get rejected because of a recent deciphered fraud or you happen to receive unpaid traffic tickets at your name, or there is a windfall of court action notices, the signs are very clear that it’s time to run for an immediate action as you have come to lie as an apple of hacker’s eye.

Get into action mode for your stolen identity

  • Set a “fraud alert” on your account

When you place a fraud alert with credit bureaus, it will discourage the marauders from further creating sham accounts under your name. Soon after you can get a free copy of your credit report, which you can review in thorough to spot from where the first signs of forgery have initiated.

  • Notify creditors to keep them aware

The next very step to ensure that no stone remains unturned is to reach out to your credit card provider, telephone and internet service vendors to keep them well noted of the fact that you have been beleaguered.

  • Do away with tampered accounts

Have a closer eye on accounts, which you think might have been messed about and it’s always advisable to close these accounts before they get into troublemaker mode.

  • Reach out to local law enforcement agencies

It’s always best to place your complaint with the police of your area, which will assist you to make your creditors believe of the fraud.

  • Keep a tight watch on your financial records

A monthly review of your bank and credit card statement can help you to trace out any loopholes and manage the situation accordingly.

Along with all these you can also file a claim with your insurance provider and Federal Trade Commission as a stitch on time can always save nine.

 

Ounce of prevention is better than pounds of cure

And as always, it’s prudent to look for preventive measures rather than going for cure. Therefore, a wise man approach is to be at an arm’s length from hackers menace and this you can ensure by sealing the key vulnerabilities in your cyber security.  This can be done easily by not going for unsolicited emails and by keeping your password least guessable. Also, you should ensure to log off properly while you’re over with your net banking operations. Not clicking on pop-ups can be really beneficial. Also, to undo the danger set in by malware most commonly used by hackers these days, it’s advisable to look out for genuine antivirus and antispyware programs. Going for effective tech support can prove its fittingness as a redeemer to keep hackers and their missionaries i.e. viruses, malware and botnets at bay always.

 

 

 

It seems that there is no end of woes for online freaks as, of late, cyber world is giving words to worst of human nightmare- the day when you stop being you. Identity theft has come to lie in the core of every second cyber felony. And why not, if payoffs are large and effort is minimal, online freebooters are not able to hold themselves back from concocting new-fangled approaches to steal you from yourself. It’s surely more than nerve racking, if someday you wake up finding that your social security number has been vitiated or there is a foul play with your credit card detailing. Clearly, it means no social security, no mortgage for new home, no student loan, no more shopping and final verdict is that you end up hanging in a lurch.

The stakes run high

There is lot more on wager than expected when you go for cyber navigation. Your credit card details serves as all-time favourite booty but then it doesn’t end here as freebooters are also tracking your social security number and insurance coverage to cash on the instant benefits. Tech connoisseurs have labelled five different categories of identity thefts which can mess up with your digital personality.

  • Social Security Number Identity Theft

Brigands are lurking to snatch the sense of security from you. Those who have the habit of escaping the tax regime have every reason to go for SSN pilferage so that they can easily file taxes and get refund under your good name.

  • Financial Identity Theft

If you try finding out the number of those victimized due to online financial fraud, you may end up with the fact that every second person has its own story to tell. Financial Identity theft, for very obvious reason, topples all charts to lie as the most prominent of all identity thefts. So large is the hysteria that even some businesses and consumers end up counting the identity theft resulting in financial fraud in their business cost.

  • Criminal Identity Theft

If you find earlier ones awful then this one is truly horrendous. How about landing up in a jail for a crime not committed by you? Criminal Identity theft is the potent way deciphered by charlatans to commit wrong by masking themselves under your identity, making law enforcement agencies believe that it’s actually you who has played the instrumental role in the criminal act.

  • Driver’s License Identity Theft

If you have received unpaid traffic tickets or DUI’s at your name for no apparent reason, it’s a clear cut indicator that you have fallen a prey to Driver’s License Identity Theft, where someone else has used your name to get driving license.

  • Medical Identity Theft

This is a new kid on the bloc that takes you by surprise. But then sleuths take advantage of your name, insurance coverage or Social Security Number to feast on a major chunk of your medical benefits, rendering a permanent dint on your current benefits along with corrupted medical records. Medical Identity thefts are also making to the news in the recent times as they are the most intricate ones to be fixed. The very fact behind is that victims have limited rights and recourses to excise.

 

If you are a florist or owner of an internet café, it’s time for you all to ponder upon the security needs of your business credentials to escape being victimized by the malware mania. No matter, your business is driven with single PC or sustains on multiple systems, being an SME doesn’t gives you that added advantage, making you the lucky one to escape from being a luscious confection for cyber goons. In a hacked era, the out-of-proportion malware problem has profoundly raked in through all business domains, whether big or small. For small businesses, it’s even more imperative as a single accost with the malware and their system- the lifeline of their entire business operations, meets a crashing end.

Skinning the Security Onion

What is best suited for my business security needs? To answer, it’s always advised to dig deep down into the very anatomy of your business and cotton on the security needs according to its dimension. Then there too many questions to look for- What are those things that need to be prioritized on top and which ones are to be placed on the second berth? The layers of security which needs to blanket the organisation structure can be best understood with the example of onion layers. Like onions have many layers engulfing the central part, similarly an organisation central data repository also needs to be mantled with multiple security layers to prevent infringements.

Looking out for practical solutions

In every business establishment, any significant decision cannot be taken by circumventing its budgetary effect. This fact holds even more relevance when we talk about SME’s, as any decision which has to be made is to lie strictly within the limited budget ambits. Here are some handy things that you can grasp to escape cyber infringes:

  • Work on your technical tools

Technical tools such as firewalls, antispyware and antivirus programs are all part and parcel of the anti-malware crusade. Therefore, it’s highly essential to keep them updated and buy them from trusted vendors.

  • Ensure end-users should not be left-out

The very crux of all security measures fail if end-users are not kept updated on technological advancements and lingering malware threats. So, keeping them up-to-date will help reaching the desired goal.

  • Lay down the procedural policy

Laying down administrative policies such as Acceptable Use Policy (a document that explains what rights employees enjoy with regard to the usage of computer systems) and Remote Access Policy (provides set of rules and standards for methods and times for usage of computer systems by employees through remote locations) will assist you to counteract the issues arising due to usage of computers by employees.

  • Go and grab a reliable Online Technical Support

In the end, never to leave out solution is to go for Online Technical Support to safeguard your single or multiple systems from the mongering malware threats.

Category: Uncategorized  | 3 Comments
Ransomware: Get Ready for Cyber-age extortion!
Tuesday, December 27th, 2011 | Author:

What if somebody comes and put your computer on gunpoint and ask you for extortion money? You must say, it’s totally insane, or how it can be possible? But, yes it’s true as hackers have stumbled upon this idea and given their bewildering ideas a chance to turn into reality. They are now up with their novelistic gimmick- Ransomware. Alike to its name, Ransomware is more an iniquitous-to-the-core contraption, which has been formulated to siphon out your money by evoking your internal fear.

What all it takes to be a ransomware?

The formulation of new marketing tactics by cyber thugs is on as usual, but now in a very different avatar. In professional lingo, Ransomware is a malicious code that has born with a sole instinct to lock down your valuable files into an encrypted archive and then asking for money in lieu of restoring these files. A fast picking trend, ransomware deals with data, files, and end-user manipulation.

Getting to extortion business

Let’s anatomize the very core of this extortion affair. It all starts when you visit any compromised site and get dirtied by this malware through drive-by-download attack. Once installed, this lout encrypts the crucial of your documents in an archive and then impels you to pay ransom money through services such as Paysafecard or Ukash, in order to swab its dabs of deviltry. Once the ruffian gets the whiff of your money, then only it releases the password to disengage the files. More advanced ransomware scenarios now influence multiple forms of end-user manipulation and extortion.

Some ransomware attacks engage mortification and panic as their cog to run over their victims. In such a scenario, victims are shown a falsified vision by making claims that ransomware has get onto their systems by visiting inappropriate websites and also due to storage of porn materials. In recent, a Trojan detected in the wild display phony messages from law enforcement agencies in Europe and asks the users to pay fictitious fines within 24 hours otherwise data will be erased from their hard drives. Moving a step ahead, some ransomware even cause the code to self destruct by employing stealth tactics, after encrypting user’s files, making the process of unlocking files a herculean challenge.

Finally, let’s end the discussion on a good note. The good news is that there is no need to trigger your panic button on hearing about ransomware. All you have to do is to keep your PC high on security rules such as using reliable firewalls, antivirus and antispyware and keeping them up-to-date with latest patches. That’s all very enough to stop you from paying ransom money for your PC.

Watch Out!!! A felon is adumbrating there
Monday, December 19th, 2011 | Author:

A flawless and secured PC experience, isn’t it appears what you have dreamt of? But wait a minute. It’s a dangerous world out there. Click on www. and hey, welcome to the hacker’s Shangri-La. A moment spent on internet and that’s enough to get your PC packed like sardines. The only difference is that here sardines are viruses, spyware, adware, rootkits and many such odds and ends. Rootkits especially are proving to be the effective scimitars for hackers to gouge out a hole into your PC’s fortification and then sabotage your personal and financial data in a hush-hush way.

A Rooty Affair

With its etymology lying in word “root”, a name of UNIX administrator, rootkit is a very potent tool in hacker’s kitty that assists the same to take the driver’s seat of your PC. The hacker installs a rootkit on your PC the moment it gets its access by exploiting user-level access or administrator-level access. This can be done either by taking advantage of the known remote vulnerabilities or by using local exploit or cracking administrator password. Once this schemer (rootkit) is in, a slew of cascading effects just get kick started. Equipped with an armada of wicked programs, a rootkit assures that its looting spree can be carried out in an infallible manner. The most infamous among these programs is backdoor, which assists the hacker in gaining unauthorized access of an entire system. The next in the line is the Packet Sniffer, which monitors the data travelling over a network, TCP/IP or other network protocol. Finally, not to forget the log-wiping utilities that masks the lists of actions that have occurred, which assists the mugger to swab down the traces of its devilry.

What’s in the name?

Many versions but with a sole endeavour to ransack the confidential data, that’s what forms the part and parcel of the rootkit contraption. LRK, tOrn, Adore, NTROOT, NTKap, Nullsys and many, many more, the list of these iniquitous charms go on inexhaustible. But techheads pigeonhole the rootkits in two separate categories. The one labelled as conventional is termed as Application rootkit which replaces the useful application with the trojaned file for opening the entry doors for the hackers. As these conventional rootkits can be ensnared by security software, the caballers have come up with second generation of reprobates known as Kernel rootkits. These rootkits establish themselves in the most reliable kernel layer of the operating system to escape from detention. As these can circumvent conventional system integrity checker at application layer, kernel rootkits have came to be the toughest one to confiscate.

Rooting out!

Few simple steps and you will remain at a safe distance from the rootkit assault. Here are some of them:

  • Firewall all the networks.
  • Grant admittance to the concerned users that are needed to perform their jobs to avoid any kind of unauthorized access.
  • After a system is installed, take inventory of what is running.
  • Enable secure communications such as VPNs and Secure Shell.
  • Periodically monitor all log-files.
  • Install host and network based intrusion detection systems.

Malware landscape in today’s time, cease to know any form of boundaries. This boisterous trend is lately catching up as modern malware can now land up through multiple vectors ranging from unsolicited emails to compromised websites and never to forget the ever-favourite social networking sites. Pacing towards the zenith, blended threats have had incredible success at causing infection due to the systematic approach by professional Internet hackers in what has become a highly lucrative industry. The same has been confirmed by Microsoft that has estimated in 2009 that blended threats has been responsible for distributing malware infection among 30% of home PCs and 4% of corporate computers.

A Salver of Choices

Blended threats have become coveted conduit for malware writers to gratify their iffy intents as now they have multiplicity of choices. These range from envenoming search engine results that use popular search terms leading to malicious websites or to social networking sites that enables hackers to promulgate the malicious URL links to contacts by compromising accounts that are legitimate. But it’s still the email that holds high regards among the virus writers. Now no more malicious email attachments, as inserting a seemingly legitimate URL link directing to a malicious website will do all wonders for hackers without any risk of being caught.

The line of attack

It all starts with hacking of a legitimate website by a hacker using automated tools for placing the malware- a radical shift from the conventional approach where the site is developed by the hacker for launching a systemic attack. Next in the line comes the dissemination task where the unsolicited emails (spams) containing the URL of these compromised websites are sent to the end-users through botnets, often in low levels to escape from getting revealed. This circumvents the traditional Email antivirus gateways which do not identify them as impending threats and they pass on unnoticed to the user. Once the user receives the mail and clicks on the rooted link, a Pandora box of systematic multi-level attacks gets unplugged and the malware gets installed onto the user’s PC by “drive-by download” attack. Bit by bit an appalling drama unfolds as the user’s PC becomes a cog of botnet which is further being deployed to spread spam and blended threats.

A multi-million dollar alcove for cyber criminals, that’s what perfectly defines the internet in today’s time. This evolution is now paced with the ingression of fake security software which has outsized the cybercrime industry into a profitable deal and thus luring more and more newbie to join the bandwagon. The new tactics is to create hysteria among the netizens by generating fake scans and then enticing them to buy the product for restoring their systems. The result- birth of a new malware called “Scareware” that let your nerves run amok by making you feel that your system has been compromised but in actual it’s a fabricated melodrama to further drive you towards a gaping ensnare.

Typology of Scareware

Each passing day the number of scareware released is skyrocketing, giving wakeful nights to the netheads and techheads to deal with this unrelenting challenge. According to an estimate, the number of scareware programs released till 2010 has exceeded 500,000. Cloud Protection, Cloud AV 2012, Security Guard 2012, System Security 2011, Advanced PC Shield 2012, Internet Security 2011, 2004 Adware/Spyware Remover & Blocker, Ad-Eliminator, and the list stretches to 100,000 of these rogues. Out of these, Internet Security 2011 rogue antispyware is one of the most difficult to remove among all rogue programs, as it has been commissioned to get bundled with a rootkit that terminates and then denies future access to any program that scans a particular process.

To give it a real outlook, some fake AV applications even assume the appearance of legitimate products such as Microsoft Windows Defender to further assist in the trickery that the program is legitimate and useful. Taking this a step further, some rogue programs such as WiniGuard operated under multiple of names (more than 30 names) to keep itself charged up for alluring new victims.

The Big Game

The key charade of the scareware is to create a deceptive perception among the PC users that their PC has been infested to prompt them for a castigatory action. It all starts by producing the fake scans and exaggerated results showing abundance of malware and viruses in the system. All these appear to be very legitimate to the users. Furthermore, some scareware even show the legitimate Windows Registry keys as the malware. Once the user gets inveigled, he is then compelled towards purchasing the fake program. In the core of all this lies the veiled axiom, that is to sell as many copies of the rogue software as possible to mint easy money.

Take the scare out of Scareware

Here are few of the do’s and don’ts so that scareware doesn’t make the fool out of you:

  • Keep your firewall updated and in action all the times.
  • Check the installation settings for patches and updates to your operating system, office software, and web browsers to automate the process as much as possible.
  • Install software to filter hits for search engines within your browser and always go for updated browser versions.
  • Always bank upon the genuine antivirus and antispyware software.
  • Prevent JavaScript from running in your browser, and activate it only in case the site is trustable.
  • Install all the Windows Critical Updates to prevent spyware and adware from sneaking into your PC from your back.
Shhhhhhhhhh!!! Someone is eyeing your PC
Friday, December 02nd, 2011 | Author:

Espionage has got a new phizog. Cannier than Mata Hari and Belle Boyd, the stage is now set for the latter-day firebrands. Here, it is not anyway correlated to the cosmos as these moles are more akin to the virtual cyber world. In apposite terms, we classify them as “Spyware” or the cyber sleuths, bespoken to siphon out the dearest of your data.

The genealogy of spyware

An incongruity on what can be classified as spyware and what not has rendered a similar ambiguity on what it means to protect against them. A stroll through technical jargons and you are met with a caboodle of convoluted definitions. Data gathering programs that are installed with the user having the prior knowledge of it, doesn’t qualifies as a spyware, if the user fully understands what data is being collected and with whom it is being shared. Then, what all it takes to be a spyware?

  • Adware

With advertisements built into software, adware can serve as effective spying tool. Once this con finds out that you are sitting online, it channelizes a surge of popups and popunder ads towards the PC. More to this, it tracks and stores the information of your viewing habits which is further sold on to marketing companies, which draw on this information to inundate your inbox with junk emails.

  • Cookies

Sweet name but not as sugary as it’s monikered! Cookies can also serve as effectual spyware tool as they are employed by the advertisers to track sales and clicks to better understand how best to spend their marketing budget.

  • Hostile Scripts and Dialers

These scripts and programmes are tailored to get hold of the local computer files for drawing together information about the user. Alternatively, they can force a modem to dial expensive toll calls or can capture every keystroke you make, creating jeopardy for your confidential information ranging from passwords to credit-card numbers.

  • Browser Redirector/Hijacker

More than just creating nuisance, these hijackers can play havoc with your homepage and search engine settings. Every time you are on the web browser you land up onto the page stifled with porn and ads. Incidentally, most browser hijackers are also data miners which can redirect your web browsing habits to a central database where it can be exploited by companies for minting extra dollars.

  • Keyloggers

Keylogger is a potent tool to scoop out the credit card details and other money related information from your PC covertly by keeping a record of your keystrokes. Email attachments and file download are among their preferred havens.

  • Trojans, Backdoors and Downloaders

And finally, not to forget the evil trinity of Trojans, backdoors and downloaders that form a safe conduit for flushing information valuables from your PC, clandestinely.

So, watch out before your privacy would become a far-flung trance forever!!!

 

 

 

Sort Out Your Antivirus Package Prudently
Wednesday, November 23rd, 2011 | Author:

Individuals and organizations always end up facing complicated buying decisions when it comes to buying anti-virus solutions. Often confused between brands such as Norton and Mcafee, Vipre and Avast,Kaspersky or Panda; not being able to make up their mind on how and which antivirus protection suite would best end up standing tall on their stringent requirements.

Why to go for antivirus software?


The negative impact from malware is perceived so threatening authorities such as HIPAA and PCI-DSS have laid out many regulations and standards to enlighten organizations about their potency. Giving way to a scenario where antivirus software is considered as quintessential in many organizations to prevent any malicious attacks on networks and systems.

Software application at the end of the day coming in good towards minimizing any potential damage resulting from Worms, Trojans, Keystroke Loggers and Root Kits. But then as it is the case even though antivirus software installs are straightforwardly non-negotiable, the choices facing corporate anti-malware buyers are almost considered to be labyrinthine in their complexity.

Which antivirus solution to opt for?


Although it is possible to purchase single purpose antivirus solutions, a good majority of organizations find it easier to combine a number of functions into a single agent. For at the end of the day, benefits of any single agent include a smaller installation footprint and a single point of control for policy management.

However, names for a good deal of combined-function agents end up comprising of security suites, endpoint security and total protection. A bare minimum of what’s in a standard antivirus suite; inclusive of scanning for viruses as well as a personal firewall. And yes what’s more with such security suites considered to be mature in their overall orientation they have been offered by major players in a majority of antivirus industries over a number of years.

PCCare247 takes antivirus support to the next level


Taking multifunction antivirus support to the next level, companies such as PCCare247 have teamed up with names such as Avast to offer additional security controls comprising of full NAC integration (with quarantine and patching support), DLP (data loss prevention) functionality, file encryption Web2.0 (e. g. cross-site request forgery and cross-site scripting attacks) and browser protection, and messaging hygiene with anti-spam and instant messaging filtering. Controls one would end up considering as pivotal for safeguarding computers from a range of unscrupulous elements residing on the World Wide Web.

PCCare247 and Avast a force to reckon with in the antivirus industry have joined hands to offer computer users unique solutions for their fight against viruses, malwares and Trojans found in the cyber world. In fact, as it goes every solution offered guarantees PC users are bound to win their freedom against viruses.