Learn about Zero Trust Architecture
Impenetrable cybersecurity without sacrificing usability
Gain detailed visibility into all your endpoints activities
Harden applications and hardware environments
Immediate and continuous response to incidents
Close the window of time your data could be exposed
Get your Comodo solutions setup, deployed or optimized
Control access to malicious websites
Defend from any internet based threats
Stop email threats before it enters your inbox
Preserve and protect your sensitive data
Keep your website running fast and malware free
Add encryption to your websites
Automated certificate mgmt. platform
Secure private intranet environments
Digital signature solutions for cloud apps
Encrypt emails for senders and recipients
Stay compliant with PCI DSS
Trusted authentication for IoT devices
Francisco Partners a leading technology-focused private equity fund, has acquired a majority stake in Comodo’s certificate authority business. Newly renamed from Comodo CA Limited to Sectigo Limited. Privacy Policies, Trademarks, Patents and Terms & Conditions are available on Sectigo Limited’s web site.
Meet the people behind the direction for Comodo
Get the latest news about Comodo
People are the key to achievement and prosperity
Stay up to date with our on-demand webinars
Worldwide: Sales, Support and General Inquiries
Schedule a live demonstration of our solutions
Need immediate help? Call 1-888-551-1531
Instantly removes viruses to keep your PC virus free
Experience true mobile security on your mobile apple devices
Secure Internet Browser based on Chrome
Chrome browser internet security extension
Submit a ticket to our support team
Share any product bugs or security flaws
Collaborate with research experts on data sets
Valkyrie Threat Intelligence Plugins
Valkyrie Threat Intelligence APIs
Cybercriminals’ big hunt for users’ credentials is gaining momentum rapidly. Their strategy usually stays the same: get attention of the victim, use social engineering techniques to make her run a malicious file, and then steal logins and passwords. But the tactic and the malware hackers use constantly changes. Let’s consider in detail the freshest example of such attack with a new variant of a password stealer recently intercepted by Comodo antimalware tools.
The disguise
As you can see, it contents a few social engineering tricks to manipulate the victims. Let’s have a closer look at them.
First, it’s the subject of the message. A rare human being would miss an information relating to her money. Thus, the perpetrators gain the victims’ attention. They can be sure that most receivers will read the message.
Next, the cybercriminals named the file “PAYMENT- PDF” for adding more credibility (in fact, it’s a .ZIP archive, but many non-techy people might not notice that). Then, to imitate authenticity, they add the photo of the “bank telex copy”. A picture is worth a thousand word, so it also raises the chances a victim will open the file.
Now let’s see what is hidden inside the “PAYMENT- PDF” in reality?
The malware
As Comodo analysts revealed, “PAYMENT- PDF” is an .html file containing an obfuscated VBScript. If the user runs it, the script downloads and executes a Portable Executable file from hdoc.duckdns.org:1133/PAYMENT.exe
And the malware becomes act covertly on the infected machine. First, it ferrets out information about the applications installed on the PC. It chooses the browsers as the first target and tries to extract logins, passwords, and other private data from them.
Notably, the malware attacks a big bunch of various browsers: Mozilla Firefox, IceDragon, Safari, K-Meleon, SeaMonkey, Flock, BlackHawk, Chrome, Nichrome, RockMeIt, Spark, Chromium, Titan Browser, Torch, Yandex, Epic, Vivaldi, Chromodo, Superbird, Coowon, Mustang, 360Browser, Citrio, Orbitum, Iridium, Opera, QupZilla and more.
After that, it reads each application’s data files to find all FTP and SSH accounts saved in the system. To be precise, it targets applications MyFTP, FTPBox, sherrodFTP, FTP Now, Xftp, EasyFTP, SftpNetDrive, AbleFTP, JaSFtp, FTPInfo, LinasFTP, Filezilla, Staff-FTP, ALFTP, WinSCP, FTPGetter, SmartFTP and some more.
Finally, the malware searches for various email clients — FoxMail, Thunderbird, PocoMail, IncrediMail, Outlook, etc. – to extract the accounts information from them.
After collecting all the data, the password stealer sends it to the cybercriminals’ server hta.duckdns.org/excel/fre.php.
And that’s the sad final. Now all the victim’s credentials are in the hands of the attackers, and she doesn’t have even a guess about it. Unfortunately, when she’ll have realized what’s happened it could be already too late to take rescue actions…
The heat map and details of the attack
As you can see, the cybercriminals conducted the attack from Italy-based IP 80.211.7.236 using email “hnym.hnyemei@gmail.com”. The attack started on April 18, 2018 at 14:28 UTC and ended on April 20, 2018 at 07:23 UTC.
“In the Comodo Q1 2018 report we pointed out the surge in password stealers, and the case confirms this trend continues growing. This kind of malware is not too sophisticated in its design, but very dangerous in its consequences” comments Fatih Orhan, the Head of Comodo Threat Research Labs. ”Its sneaky behavior let the attackers provide their malevolent activity covertly, so the victims often stay unaware of being hacked until the perpetrators use the stolen credentials.
It’s better to care about the protection in advance to prevent your network or PC from the malware break-in than sorry for not doing it later. The one, who prepares better, wins the battle. That’s just the case. Comodo technologies protected our clients from the attack and made the cybercriminals go away with empty pockets”.
Live secure with Comodo!
Tags: Comodo Cybersecurity,Email Security,Password stealer,phishing email,Phishing Scams
Reading Time: 4 minutes Increased dependency on computers and access to data makes an organization more vulnerable to cybersecurity threats. With the increase in cyber-criminals and cyber-attacks, many companies today are looking for greater protection of their decentralized computing work environments from their Managed Service Providers (MSPs). As a result, MSPs need to deliver firewall solutions that are designed…
Reading Time: 3 minutes Rapid technological growth and increasing digitalization in all aspects of life around the world have increased the value of ensuring cyber-security at all levels. This is increasingly true for EU member states and the organizations that are based in or operate from these countries. The number of cyber-attacks targeting EU member states has risen. The…
Reading Time: 4 minutes There should be no doubt in anyone’s mind that the coronavirus pandemic will reshape our education systems. It has already altered how students around the world learn and share knowledge with their peers in just a matter of months. Those changes can give insight into how education will progress in the long run, for better…
Sign up to our cyber security newsletter
Comodo Cybersecurity would like to keep in touch with you about cybersecurity issues, as well as products and services available. Please sign up to receive occasional communications. As a cybersecurity company, we take your privacy and security very seriously and have strong safeguards in place to protect your information.
agreecheck
See how your organization scores against cybersecurity threats
Advanced Endpoint Protection, Endpoint Detection and Response Built On Zero Trust Architecture available on our SaaS EPP