Showing posts with label カスペルスキー. Show all posts
Showing posts with label カスペルスキー. Show all posts

Saturday, February 16, 2013

操作 "レッドオクトーバー" - 世界中から政府を攻撃

操作 "レッドオクトーバー" - 世界中から政府を攻撃

対象とする主に東欧、旧ソ連·中央アジア諸国の国であったが、被害者は、西ヨーロッパと北米を含む世界中に散らばっていた。攻撃の第一の目標は、情報地政学資格パーソナルモバイル機器やネットワーク機器から、機密のシステムやデータへのアクセスが含まれていた機密書類の被害者団体を収集することであった。 2012年10月では、カスペルスキーの専門家チームは、ゴール国際機関の外交的サービスだったコンピュータネットワーク上での一連の攻撃に応答して、調査を開始した。調査中に発見され、大規模な包括的ネットワークを分析した。操作の分析報告書 "Rocra"と呼ばれる "レッド·オクトーバー"(レッドオクトーバーと呼ばれる)によると、積極的に追求され続けており、その起源は2007年にさかのぼる。 攻撃者はしばしば密かに追加したシステムへのアクセスを得るために感染したネットワークから得られた情報を使用していました。たとえば、盗まれた資格情報がリストにコンパイルされており、攻撃者が追加のシステムへのアクセスを得るために、パスワードまたはフレーズを知っている必要があります状況で使用。 感染したコンピュータのネットワークを制御するために、攻撃者は主にドイツやロシアでは、さまざまな国で60のドメイン名とサーバーホスティング複数のサイトで作成しました。制御基盤のカスペルスキーの分析によって行わするサーバのチェーンは、実際には、サーバーの場所最も重要なコントロールセンターです "母船"を、隠して、プロキシとして動作することを示しています。 感染したシステムから盗まれた情報は、拡張子TXT、CSV、EML、DOC、VSD、SXW、ODT、DOCX、RTF、PDF、mdbファイル、xlsファイル、WAB、RST、XPS、IAU、CIF、キー、CRT、セリウム、HSEを使って文書を含む、PGPやGPG、夏、秀、XIS、XIO、XIG、acidcsa、acidsca、aciddsk、acidpvr、acidpprとacidssa。これは、拡張子 "*酸"北大西洋条約機構(NATO)、欧州連合のいくつかの組織によって使用される独自のソフトウェア "Cryptofiler酸"を指しているようだ。

Sunday, September 23, 2012

Half of us do not recognize the attack


The standard method of data theft is social engineering - the potential victim is lured to a malicious website or fraudulently induced to open a file attached to an e-mail. As shown in a study conducted in May 2012 by the O + K Research commissioned by Kaspersky Lab, a recognition of the message is not always easy. 50 percent. respondents admitted that they can not recognize a phishing email or crafted web page.
The vast majority of phishing emails are delivered via e-mail or social networking sites. The reason is simple: currently the most popular means of communication. The same study shows that 86 percent. PC users regularly check their e-mail, and 73 percent. communicating via social networking sites. 54 percent. users regularly talking on the internet with their smartphones. Cyber ​​criminals who use phishing as a tool for data theft are mainly interested in gaining unauthorized access to accounts on social networking sites, accounts, online banking systems and payment systems, as well as online stores. According to Kaspersky Lab in June to 68 percent. phishing emails associated with these sites were stealing data. The results provide direct evidence that the method uses mass mailings brings results: about half of the respondents to the survey O + K Research acknowledged that the suspect has already hit communications on social networking sites and e-mail. 47 percent. PC users received a message from the suspect a link or attachment, and 29 per cent. respondents got a message sent on behalf of the bank, or any other social networking site looking for a reliable website.
In addition, 26 percent. users reported that their computers have been infected as a result of the opening of the Annex to the news, and 13 percent. respondents cited personal and financial data on suspicious sites.
Quite a high percentage of users fell victim to phishing attacks on your mobile device. 24 percent. Tablet users and 18 percent. smartphone owners received correspondence containing suspicious links and attachments. 14 and 11 percent. respondents got messages sent on behalf of the bank or social network. It can be assumed that as more and more mobile devices have access to the Internet, the number of phishing emails for mobile platforms will continue to grow.


データの盗難の標準的な方法は、ソーシャルエンジニアリングである - 潜在的な被害者が悪意のあるWebサイトにおびき寄せ、または不正に電子メールに添付ファイルを開くように誘導される。カスペルスキーの委嘱O + K Researchが2012年5月に実施した調査で示すように、メッセージの認識が必ずしも容易ではありません。 50パーセント。回答者がフィッシング詐欺メールまたは作成されたWebページを認識することができないことを認めた。
フィッシングメールの大半は電子メールやソーシャルネットワーキングサイトを介して配信されます。理由は単純です:現在のコミュニケーションの最も人気のある手段。同じ調査によると、86パーセントを示しています。 PCユーザーは、定期的に自分の電子メールをチェックして、73パーセント。ソーシャルネットワーキングサイトを介して通信。 54パーセント。ユーザーは定期的に彼らのスマートフォンで、インターネット上で話している。データの盗難のためのツールと​​して使うフィッシングサイバー犯罪者は、主にソーシャル·ネットワーキング·サイト、アカウント、オンラインバンキングシステムや決済システムと同様に、オンラインストアのアカウントへの不正アクセスを得ることに興味を持っています。カスペルスキーによると、6月の68%に。これらのサイトに関連付けられているフィッシングメールは、データを盗んでいた。 O + Kリサーチは、容疑者がすでにソーシャル·ネットワーキング·サイトや電子メールでの通信をヒットしていることを認めて調査に回答者の約半数:結果は、メソッドが結果をもたらす大量のメールを使用している直接の証拠を提供しています。 47パーセント。 PCユーザーは、疑わしいリンクや添付ファイル、および29%からメッセージを受信しました。回答者は、信頼性の高いウェブサイトを探し銀行に代わって送信されたメッセージ、または任意の他のソーシャルネットワーキングサイトを得た。
加えて、26パーセント。ユーザーは自分のコンピュータがニュースに附属のオープニング、そして13パーセントの結果として感染していることを報告した。回答者は、疑わしいサイト上の個人情報や財務データを引用した。
ユーザーのかなりの割合が高い場合は、お使いの携帯デバイス上でのフィッシング攻撃の犠牲になった。 24パーセント。タブレットのユーザーと18パーセント。スマートフォンの所有者は、疑わしいリンクや添付ファイルを含む対応を受けた。 14と11パーセント。回答者は、銀行やソーシャルネットワークを代表して送られたメッセージを得た。それは、ますます多くのモバイル機器がインターネットへのアクセスを持っていると仮定することができる、モバイルプラットフォーム向けにフィッシングメールの数は増加していきます。


数据被窃取的标准方法是社会工程 - 潜在的受害者被引诱到一个恶意网站或打开一个文件附加到电子邮件欺诈诱导。 O + K委托卡巴斯基实验室的研究,在2012年5月进行的一项研究显示,并不总是很容易确认的消息。 50%。受访者承认,他们无法识别网络钓鱼电子邮件或制作的网页。
绝大多数都通过电子邮件或社交网站的网络钓鱼邮件。原因很简单:目前最流行的交流方式。同样的研究显示,86%。 PC用户定期检查他们的电子邮件,而73%。通过社交网站。 54%。用户在互联网上经常说自己的智能手机。网络犯罪分子使用网络钓鱼作为一种工具,数据盗窃的主要兴趣是获得未经授权的访问社交网站账户,网上银行系统和支付系统,以及网上商店帐户。根据卡巴斯基实验室在6月的68%。与这些网站的钓鱼邮件窃取数据。结果,该方法使用群发邮件带来的结果:大约一半的受访者的调查,O + K的研究确认,犯罪嫌疑人已经打在社交网站和e-mail的通信提供了直接证据。 47%。 PC用户收到一条消息,从犯罪嫌疑人的链接或附件,和29%。受访者得到了代表的银行,或任何其他的社交网站寻找一个可靠的网站上发送的消息。
此外,26%。用户报告说,他们的计算机已经被感染的附件开幕的消息,13%的结果。受访者认为个人和财务数据,对可疑的网站。
相当高比例的用户在移动设备上的网络钓鱼攻击的受害者。 24%。平板电脑用户和18%。智能手机用户收到的信件含有可疑链接和附件。 14%和11%。受访者有代表的银行或社会网络上发送的消息。可以设想,随着越来越多的移动设备接入互联网,移动平台的钓鱼邮件数量将继续增长。


Стандартный способ кражи данных социальной инженерии - потенциальная жертва заманили на вредоносный веб-сайт или обманным путем индуцированного, чтобы открыть файл, прикрепленный к электронной почте. Как показали исследования, проведенного в мае 2012 года O + K исследований по заказу Kaspersky Lab, признания сообщения не всегда легко. 50 процентов. респондентов признались, что они не могут признать, фишинг электронной почты или созданные веб-страницы.
Подавляющее большинство фишинговых писем доставляются через электронную почту или социальные сети. Причина проста: в настоящее время самым популярным средством связи. То же исследование показало, что 86 процентов. Пользователей ПК регулярно проверять свою электронную почту, и 73 процентов. общения через сайты социальных сетей. 54 процентов. Пользователям регулярно разговаривает по интернету с их смартфонов. Кибер-преступники, которые используют фишинг как инструмент для кражи данных в основном заинтересованы в получении несанкционированного доступа к учетным записям на сайтах социальных сетей, счетов, системы онлайн-банкинга и платежных систем, а также интернет-магазинов. По данным Лаборатории Касперского в июне до 68 процентов. фишинговых писем, связанных с этих сайтов были кражи данных. Результаты дают прямые свидетельства того, что метод использует массовых рассылок приносит результаты: около половины респондентов опроса O + K исследований признали, что подозреваемый уже попал связи на сайтах социальных сетей и электронной почты. 47 процентов. Пользователи ПК получили сообщение от подозреваемого ссылки или вложения, и 29 процентов. респондентов получили сообщение, отправленное от имени банка или любой другой социальной сети ищет надежного сайта.
Кроме того, 26 процентов. Пользователи сообщили, что их компьютеры были инфицированы в результате открытия приложении к новостям и 13 процентов. респондентов назвали личные и финансовые данные на подозрительных сайтах.
Довольно высокий процент пользователей стали жертвой фишинговых атак на мобильные устройства. 24 процентов. Планшетный пользователей и 18 процентов. владельцев смартфонов полученной корреспонденции, содержащих подозрительные ссылки и вложения. 14 и 11 процентов. респондентов получили сообщения, отправленные от имени сети банка или социальной. Можно предположить, что все больше и больше мобильных устройств имеют доступ к Интернету, количество фишинговых писем для мобильных платформ будет продолжать расти.



Die Standard-Methode von Datendiebstahl ist Social Engineering - das potentielle Opfer auf eine bösartige Website gelockt oder in betrügerischer Absicht veranlaßt, eine Datei an eine E-Mail zu öffnen. Wie in einer Studie Mai 2012 durch die O + K Forschung von Kaspersky Lab in Auftrag durchgeführt gezeigt, ist eine Anerkennung der Nachricht nicht immer einfach. 50 Prozent. Befragten zugaben, dass sie nicht erkennen kann, eine Phishing-E-Mail oder gestaltete Web-Seite.
Die überwiegende Mehrheit der Phishing-E-Mails werden per E-Mail oder Social-Networking-Sites geliefert. Der Grund ist einfach: die derzeit populärste Mittel der Kommunikation. Die gleiche Studie zeigt, dass 86 Prozent. PC-Nutzer regelmäßig ihre E-Mails und 73 Prozent. Kommunikation über Social-Networking-Sites. 54 Prozent. Nutzer regelmäßig im Gespräch über das Internet mit ihren Smartphones. Cyber-Kriminelle, die Phishing als Werkzeug für Datendiebstahl sind vor allem in den unbefugten Zugriff auf Konten auf Social Networking Sites, Konten, Online-Banking-Systemen und Zahlungssystemen sowie Online-Shops interessiert. Laut Kaspersky Lab im Juni auf 68 Prozent. Phishing-E-Mails mit diesen Seiten verbunden waren Daten zu stehlen. Die Ergebnisse ermöglichen den direkten Beweis dafür, dass das Verfahren die Massen-Mailings verwendet bringt Ergebnisse: Etwa die Hälfte der Befragten an der Umfrage O + K Research bestätigt, dass der Verdächtige bereits Kommunikation auf Social-Networking-Sites und E-Mail getroffen. 47 Prozent. PC-Benutzer eine Nachricht von dem Verdächtigen einen Link oder Anhang und 29 Prozent. Befragten habe eine Nachricht im Namen der Bank oder einem anderen Social-Networking-Website, die eine zuverlässige Website gesendet.
Zusätzlich 26 Prozent. Nutzer berichteten, dass ihre Computer als Folge der Öffnung des Anhangs zu den Nachrichten, und 13 Prozent infiziert wurden. Befragten persönlichen und finanziellen Daten auf verdächtige Websites.
Ein ziemlich hoher Prozentsatz der Nutzer zum Opfer fielen Phishing-Angriffe auf Ihrem mobilen Gerät. 24 Prozent. Tablet-Nutzer und 18 Prozent. Smartphone-Besitzer erhalten Korrespondenz mit verdächtigen Links und Anhänge. 14 und 11 Prozent. Befragten bekamen Nachrichten im Namen der Bank oder sozialen Netzwerk gesendet. Es kann angenommen werden, dass mehr und mehr mobile Geräte Zugriff auf das Internet haben, die Zahl der Phishing-E-Mails für mobile Plattformen wird weiter wachsen werden.



El método estándar para el robo de datos es la ingeniería social - la víctima potencial es atraído a una página web maliciosa o fraudulentamente inducido a abrir un archivo adjunto a un e-mail. Como se muestra en un estudio realizado en mayo de 2012 por la O + K Investigación encargada por Kaspersky Lab, un reconocimiento de que el mensaje no siempre es fácil. 50 por ciento. los encuestados admitió que no puede reconocer un correo electrónico de phishing o página web diseñada.
La gran mayoría de los correos electrónicos de phishing se entregan a través del correo electrónico o los sitios de redes sociales. La razón es simple: en la actualidad los medios de comunicación más populares. El mismo estudio muestra que el 86 por ciento. Los usuarios de PC regularmente revisar su correo electrónico, y el 73 por ciento. comunicación a través de sitios de redes sociales. 54 por ciento. los usuarios regularmente hablando por Internet con sus teléfonos inteligentes. Los delincuentes cibernéticos que utilizan phishing como una herramienta para el robo de datos están principalmente interesados ​​en obtener acceso no autorizado a las cuentas en las redes sociales, cuentas, sistemas de banca online y sistemas de pago, así como las tiendas en línea. Según Kaspersky Lab en junio a 68 por ciento. correos electrónicos de phishing asociados con estos sitios estaban robando datos. Los resultados proporcionan evidencia directa de que el método utiliza correos masivos trae resultados: cerca de la mitad de los que respondieron a la encuesta O + K Investigación reconoció que el sospechoso ya ha afectado a las comunicaciones en las redes sociales y el correo electrónico. 47 por ciento. Los usuarios de PC recibió un mensaje del sospechoso en un enlace o archivo adjunto, y el 29 por ciento. los encuestados recibió un mensaje enviado en nombre del banco, o cualquier otro sitio de redes sociales en busca de un sitio confiable.
Además, el 26 por ciento. usuarios reportaron que su ordenador ha sido infectado como consecuencia de la apertura del Anexo de la noticia, y 13 por ciento. encuestados citaron los datos personales y financieros sobre sitios sospechosos.
Un porcentaje alto de usuarios fueron víctimas de ataques de phishing en su dispositivo móvil. 24 por ciento. Los usuarios de Tablet y el 18 por ciento. propietarios de teléfonos inteligentes recibido correspondencia que contenga enlaces sospechosos y archivos adjuntos. 14 y 11 por ciento. encuestados dieron mensajes enviados en nombre de la red bancaria o social. Se puede suponer que como dispositivos más y más móvil tiene acceso a la Internet, el número de correos electrónicos de phishing para plataformas móviles continuará creciendo.



Kaspersky Lab presents its 2013 product line


Kaspersky Lab announced the availability of the latest versions of its flagship consumer products Kaspersky Internet Security 2013 and Kaspersky Anti-Virus 2013. The new versions use technologies to provide maximum protection against all types of threats with a focus on safe shopping and banking online.W response to ever-changing threat landscape in the new Kaspersky Lab products used technology "automatically prevent exploits" that cares about the safety of the applications that are potentially vulnerable. In addition, easy-to-use function "Safe Money" will provide users with a new version of Kaspersky Internet Security complete protection when shopping and banking online. Both products are fully compatible with the operating system Windows 8 and its touch interface.

The main advantages of the new products
• A new antivirus engine provides better detection rates of all types of cyber threats.
• Unique technology "automatically prevent exploits" protects against the most sophisticated threats that use vulnerabilities in popular software.
• Simplified interface allows for easier installation, activation and daily use of the product.
• Better performance in key scenarios of use and much longer battery life in laptops.

What's new in Kaspersky Internet Security
• The unique technology of "Safe Money" effectively protects your money when shopping and banking online.
• New module effectively blocks unwanted spam e-mail, saving users time and nerves.

New technologies used in Kaspersky Lab products line 2013
Kaspersky Internet Security 2013 offers a number of completely new technologies designed to combat the most common and advanced threats that target personal information and your bank accounts. The most important of these technologies is "Automatically prevent exploits" and "Safe Money".

Protection against zero-day exploits
Technology "automatically prevent exploits" was created in order to combat the most sophisticated threats that use vulnerabilities in popular software. Exploits have long been the preferred weapon cyber criminals used the online attacks, known as "drive-by download" - when a user gets infected as a result of the visit a specific website.
"Automatically prevent exploits" to protect users from these threats, including those that use the so-called zero-day vulnerabilities. The latter are among the most dangerous, infecting the system through unknown or unpatched vulnerabilities in popular software. Technology "Automatic exploits to prevent" unauthorized activity can recognize exploits without blocking the normal operation of a program that potentially contain vulnerabilities, such as a web browser, an application for viewing documents, etc.

Secure shopping and banking online
Technology "Safe Money" includes a set of different methods of online money transactions. Such activities may include making purchases online, the use of electronic payment systems such as PayPal, or access to your bank account from your computer. A new feature, available in Kaspersky Internet Security 2013, provides enhanced protection for banking operations. Technology works in several steps:
• Automatically switches to a special mode "Safe Browser" when the user visits a banking sites, the mode of payment operations isolates from other online activities, making it impossible to monitor the user transaction.
• Automatic activation of the safe when you visit the most popular payment services, with the ability to easily add sites of banks or online stores to the list.
• Checking the authenticity of the payment page, so you can be sure that it is not hacked or falsified by cybercriminals.
• Evaluation of the security of your computer and the warning of the serious threats that should be removed before performing the operation of payment.
• Use the virtual keyboard to safely enter passwords or credit card numbers.

New and improved security features
Kaspersky Internet Security 2013 and Kaspersky Anti-Virus 2013 are equipped with a new anti-virus engine, which offers improved detection of all types of malicious programs, including those with the most complex. In particular, it introduces special methods to ensure a better control of complex and targeted threats by neutralizing malicious code attempts to suture the basic processes in the system. At the same time, by moving the database to the cloud Kaspersky Security Network, new products update much faster internet access and charged to a lesser extent.
Virtual keyboard, designed to protect the most sensitive data from keyloggers while you use the "Safe Money", was supported technology called "Safe enter information", which uses a special driver for the keyboard connected to the computer, prevent logging malware entering characters. In order to provide more effective protection against phishing sites both new products have now updated phishing module that provides automatic updates and improved heuristics websites by which criminals attempt to steal passwords and other sensitive data. Kaspersky Internet Security 2013 also includes a new anti-spam engine, providing an effective detection of unwanted messages in e-mail.

Fully compatible with Windows 8
Kaspersky Internet Security 2013 and Kaspersky Anti-Virus 2013 are fully compatible with the new Microsoft operating system - Windows 8 Kaspersky Lab offers complete protection for users of Windows 8, providing increased safety applications and a new adapted interface for touchscreens, as well as support for all the new security features of the operating system. The new tool allows users of Kaspersky Now Windows 8 a quick check of the security of your computer and run the key features of Kaspersky Anti-Virus and Kaspersky Internet Security directly from the new Windows 8 interface This tool is available for free in the Windows Store store with the official release of Windows 8


Kaspersky Labは、同社の主力コンシューマ製品カスペルスキーインターネットセキュリティ2013とKaspersky Anti-Virus 2013の最新バージョンを発表しました。新しいバージョンは、潜在的なアプリケーションの安全性について心配 "自動的に攻撃を防ぐ"安全なショッピングや技術を使用する新しいカスペルスキー製品で常に変化する脅威のする銀行のonline.Wの応答に焦点を当てつつ、あらゆるタイプの脅威から最大限の保護を提供するための技術を使用脆弱性が存在します。また、使いやすい機能 "セーフマネー"カスペルスキーインターネットセキュリティを完全に保護の新しいバージョンショッピングやバンキング、オンラインでユーザーに提供します。両方の製品は、オペレーティングシステムのWindows 8とそのタッチインターフェイスと完全に互換性があります。

新製品の主な利点
•新しいアンチウイルスエンジンは、サイバー脅威のすべてのタイプの良い検知率を提供しています。
•独自の技術 "自動的に攻撃を防ぐためには、"人気のあるソフトウェアの脆弱性を使用するほとんどの巧妙な脅威から保護します。
•簡素化インタフェースは、製品の簡単なインストール、アクティベーションおよび毎日の使用が可能になります。
ノートパソコンで使用すると、はるかに長いバッテリ寿命の重要なシナリオで•パフォーマンスの向上。

カスペルスキーインターネットセキュリティの新機能
ときにオンラインショッピングやバンキング• "セーフマネー"のユニークな技術が効果的にあなたのお金を保護します。
•新しいモジュールは、効果的にユーザーの時間と神経を保存し、不要な迷惑メールをブロックします。

カスペルスキー製品ライン2013で使用される新しい技術
カスペルスキーインターネットセキュリティ2013は、個人情報や銀行口座をターゲットに、最も一般的で先進的な脅威に対抗するように設計され、完全に新しい技術の数を提供しています。これらの技術の中で最も重要なのはと "セーフマネー" "自動的に攻撃を防ぐ"です。

ゼロデイ攻撃からの保護
技術 "自動的に攻撃を防ぐには"人気のあるソフトウェアの脆弱性を使用し、最も洗練された脅威に対処するために作成されました。ユーザーが特定のWebサイト訪問の結果として、感染したときに - エクスプロイトは長い武器優先サイバー犯罪者は、 "ドライブバイダウンロード"として知られているオンライン攻撃を、使用されている。
いわゆるゼロデイ脆弱性を利用したものも含め、これらの脅威からユーザーを保護するために "自動的に攻撃を防ぐ"。後者は、人気のあるソフトウェアにパッチを適用していないか、または未知の脆弱性を介してシステムに感染する、最も危険なの一つです。 Webブラウザなどの不正行為は、潜在的な脆弱性が含まれているプログラムの正常な動作をブロックせずに攻撃を認識することができる技術 "を防ぐために自動攻撃"、ドキュメントを表示するためのアプリケーションなど

安全なオンラインショッピングやバンキング
技術 "セーフマネー"オンラインマネー取引の様々なメソッドのセットが含まれています。このような活動は、購入がオンラインでPayPalのような電子決済システムの利用、またはお使いのコンピュータからあなたの銀行口座へのアクセスを行うことを含むことができる。カスペルスキーインターネットセキュリティ2013で使用可能な新機能は、銀行業務のための強化された保護を提供します。この技術にはいくつかのステップで機能します:
ユーザーが銀行サイトを訪問したとき•自動的に特殊モード "安全なブラウザ"に切り替わり、支払い操作のモードは、それが不可能なユーザのトランザクションを監視すること、他のオンライン活動から分離します。
安全の•自動アクティベーションを簡単にリストに銀行やオンラインショップのサイトを追加する能力を持つ、最も人気のある決済サービスをご覧ください。
•支払いページの真正性を確認するので、あなたはそれがサイバー犯罪者によってハッキングや改ざんされていないことを確認することができます。
•コンピュータと支払いの操作を実行する前に除去しなければならない重大な脅威の警告のセキュリティの評価。
•安全にパスワードやクレジットカード番号を入力するように仮想キーボードを使用してください。

新しく改良されたセキュリティ機能
カスペルスキーインターネットセキュリティ2013とKaspersky Anti-Virus 2013が最も複雑有するものを含む悪意あるプログラムのすべてのタイプの改良された検出を提供する新しいアンチウイルスエンジンが搭載されています。特に、それは、システムの基本的なプロセスを縫合糸に悪意のあるコードの試みを中和することにより、複雑かつターゲットを絞った脅威のよりよい制御を確実にするために、特別な方法を紹介します。同時に、クラウドカスペルスキーセキュリティネットワークにデータベースを移動することにより、新製品は、はるかに高速インターネット回線を更新し、より少ない程度に充電されます。
あなたは "セーフマネー"を使用しながら、キーロガーから最も機密データを保護するために設計された仮想キーボードは、サポートされていた技術では、ロギングマルウェア文字を入力するのを防ぐ、コンピュータに接続されたキーボードのために特別なドライバを使用して "セーフ入力した情報"と呼ばれる。両方の新製品は今や犯罪者がパスワードやその他の機密データを盗むために試みることによって、自動更新と改良されたヒューリスティックのウェブサイトを提供するフィッシング対策モジュールが更新されているフィッシングサイトに対してより効果的な保護を提供するために。カスペルスキーインターネットセキュリティ2013は、電子メール内の不要なメッセージの効果的な検出を提供する、新しいアンチスパムエンジンを搭載しています。

Windowsの8と完全な互換性
カスペルスキーインターネットセキュリティ2013とKaspersky Anti-Virus 2013の新しいMicrosoftオペレーティングシステムと完全に互換性があります - Windowsの8 Kaspersky Labは、安全増アプリケーションおよびタッチスクリーンのための新しい適応インタフェースだけでなく、オペレーティング·システムのすべての新しいセキュリティ機能のサポートを提供する、Windows 8のユーザーのための完全な保護を提供しています。新しいツールは、Kaspersky今すぐWindows 8コンピュータのセキュリティのクイックチェックのユーザーを可能にし、新しいWindows 8のインタフェースから直接カスペルスキーアンチウイルスとカスペルスキーインターネットセキュリティの主要な機能を実行します。このツールは、Windows 8の正式リリースでWindowsストアストアで無料で入手可能です


卡巴斯基实验室宣布推出的消费旗舰产品卡巴斯基互联网安全套装2013和卡巴斯基反病毒软件2013年最新版本的。新版本使用的技术,以提供最大程度的保护对所有类型的威胁与安全的购物和银行online.W响应不断变化的威胁景观的新的卡巴斯基实验室产品使用技术“的焦点自动阻止的攻击”,关心对有潜在的应用程序的安全性脆弱的。此外,易于使用的功能“安全理财”为用户提供了一个新版本的卡巴斯基互联网安全完整的保护时,在线购物和网上银行。这两款产品是完全兼容的操作系统Windows 8和它的触摸界面。

新产品的主要优点
•一个全新的反病毒引擎的所有类型的网络威胁提供了更好的检出率。
•独特的技术“自动防止遭到攻击”防止最复杂的安全威胁,使用流行的软件中的漏洞。
•简化的界面,可以更容易安装,激活和日常使用的产品。
•更好的表现在关键场景,在笔记本电脑的使用和更长的电池寿命。

有什么新的卡巴斯基互联网安全套装
•“安全理财”的独特技术,有效地保护了你的钱购物和网上银行在线。
•新的模块有效地阻止不需要的垃圾邮件,从而节省了用户的时间和神经。

卡巴斯基实验室的产品线2013中使用的新技术
卡巴斯基互联网安全2013提供了一些完全新技术,旨在打击最常见的和最先进的针对个人信息和银行账户的威胁。这些技术中,最重要的是“自动防止遭到攻击”和“安全货币”。

防止零日攻击安全漏洞
技术“自动阻止的攻击”,以打击最复杂的安全威胁,使用流行的软件中的漏洞。侵入的首选武器早已被网络犯罪分子使用的网络攻击,被称为“驱动下载” - 当被感染用户访问特定的网站的结果。
“自动防止遭到攻击”,以保护用户免受这些威胁,包括那些使用所谓的零日漏洞。后者是最危险的,流行的软件中的未知和未修补的漏洞,通过感染系统。技术“自动的攻击,以防止未经授权的活动可以识别的攻击,而不会阻止可能包含漏洞,如Web浏览器,用于查看文档的应用程序,等程序的正常运行

安全购物和网上银行在线
科技“安全货币”包含了一组不同的方法网上赚钱的交易。这些活动可能包括进行网上购物,使用电子支付系统如PayPal,或者从您的计算机访问您的银行帐户。卡巴斯基互联网安全2013,一个新的功能,可以为银行业务提供增强的保护。科技工作在以下几个步骤:
•自动切换到一个特殊的模式“安全浏览器”的用户访问银行网站时,隔离从其他网上活动,使得它不可能监视用户的交易支付业务模式。
•自动激活的安全,当您访问最流行的支付服务,能够方便地添加到列表中的银行或网上商店的网站。
•检查的真实性付款页面,所以你可以肯定,它不是攻击或伪造网络犯罪分子。
•您的计算机和警告的严重威胁,应删除,然后再执行付款操作的安全性评价。
•使用虚拟键盘来安全地输入密码或信用卡号码。

新的和改进的安全功能
卡巴斯基互联网安全套装2013和卡巴斯基反病毒软件2013都配备了一个新的反病毒引擎,它提供了完善的检测所有类型的恶意程序,包括那些最复杂的。特别是,它引入了特殊的方法,通过中缝合的基本进程在系统中的恶意代码试图以确保更好地控制复杂的和有针对性的威胁。同时,将数据库移动到云的卡巴斯基安全网络,新产品更新速度远快的互联网访问,并在较小程度上扣除。
支持虚拟键盘,键盘记录器,当您使用“安全理财”,以保护最敏感的数据,技术所谓的“安全输入信息”,它采用了特殊的驱动程序连接到计算机的键盘,防止记录输入字符的恶意软件。为了提供对钓鱼网站的两个新产品,现在已经更新罪犯企图窃取密码和其它敏感数据的自动更新和改进的启发式网站的网络钓鱼模块,提供更有效的保护。卡巴斯基互联网安全2013还包括一个新的反垃圾邮件引擎,提供了有效的检测不需要的邮件在电子邮件中。

完全兼容与Windows 8
卡巴斯基互联网安全套装2013和卡巴斯基反病毒软件2013是完全兼容的新的微软操作系统 - Windows 8的卡巴斯基实验室的Windows 8的用户提供了完整的保护,提高安全性的应用程序和一个新的适应触摸屏界面,以及支持新的安全功能的操作系统。新的工具允许用户的卡巴斯基现在,Windows 8的快速检查您的计算机的安全性和运行新的Windows 8界面直接从卡巴斯基反病毒软件,卡巴斯基互联网安全的主要特点这个工具是免费提供的Windows 8正式发布的Windows店铺


Saturday, September 22, 2012

Wiper sabotaged oil extraction


In April of this year. appeared in a series of reports of malicious malware, codenamed Wiper, who attacked the computer systems associated with many oil installations in Western Asia.
In May 2012, a team of experts from Kaspersky Lab led the search initiated by the International Telecommunication Unit (ITU) to investigate the incident and determine the potential threat posed by this new pest, because it had an impact on global sustainable development and security. Kaspersky Lab has released a study analyzing the effect of constituting the hard drives obtained from the machines affected by the wiper. The analysis revealed information about an extremely effective method used by the wiper to the destruction of computer systems, including a unique pattern of data cleaning and destructive behavior. While searching for unintentionally resulted in the detection of wiper cyber espionage campaign, Flame, Wiper he was not found and remains unidentified. However, the wiper is used effectively destroying the machines can encourage followers to create a malicious malware such as Shamoon, which appeared in August 2012,

Summary results of the analysis
• Kaspersky Lab confirms that the wiper was responsible for the attacks carried out on computer systems in Western Asia held on 21 - 30 April 2012
• Analysis of the damaged hard drive wiper cleaning regimen revealed specific data together with the name of a specific component malware that begins with the characters "~ D". These findings are reminiscent of Duqu and Stuxnet pests that also apply file names beginning with "~ D" and have been developed on the same platform attacks, known as "Tilded".
• Experts from Kaspersky Lab began to look for other files with names beginning with "~ D" with the KSN (Kaspersky Security Network) and tried to find additional files from wiper connection Tilded platform.
• The search identified a large number of files in Western Asia, called "~ DEB93D.tmp". Further analysis showed that the file was in fact part of another type of malicious software: Flame. Thus, Kaspersky Lab has detected Flame'a.
• Although the flame is detected during the search for wiper, a team of experts from Kaspersky Lab believes that the Wiper and Flame are two separate and independent malware.
• Despite signs of infection Wiper analysis carried out by Kaspersky Lab malware is still unknown, as there were no further incidents of data cleaning on the same schedule, and proactive protection Kaspersky Lab does not detect this pest.
• Wiper was extremely effective and can inspire others to create new "imitative" copies of malicious malware such as Shamoon.

Analysis of the computers cleaned by the "wiper"
Carried out by Kaspersky Lab analysis of hard drives damaged by Wiper showed that this pest has cleared all the data that could be used to identify it. The file system modified by the wiper prevented successful execution of computers. Therefore, on any machine tested was not hardly anything on the wiper activation, it was also possible to restore or recover any data. owever survey conducted by Kaspersky Lab has revealed some valuable information, including the cleaning regimen used by the pest and the names of specific malware components and, in some cases, registry keys, indicating the name of the previous files that have been deleted from the hard drive. All these registry keys to point to the file names beginning with ~ D.

The unique pattern of data cleaning wiper
The analysis revealed a pattern consistent cleaning method to be used on any machine on which the wiper is activated. Wiper algorithm was designed to quickly and effectively destroy as many files - many gigabytes at a time. Completely erase the data took place at roughly three out of four attacked machine, the operation focused on the destruction of the first half of the disk, and then systematically clean the rest of the files, which allow the proper operation of the disk, ultimately leading to the collapse of the system. Furthermore, the identified attacks Wiper, whose aim was to NF files. These attacks would be useless, if not related to the removal of additional malware components. This was an interesting finding, since Duqu and Stuxnet stored their main code is in the files PNF.

How Wiper search led to the discovery Flame'a
Temporary files (TMP) with names starting with "~ D" were also used by Duqu, which has been developed on the same platform as the Stuxnet attacks: platform "Tilded". Following this path, the team of experts began to look for other potentially unknown file names associated with Wiper, based on the platform of "Tilded" using KSN - a cloud-based infrastructure used by Kaspersky Lab products to detect the latest threats. During this process, a team of experts found that the number of computers in Western Asia contains a file named "~ DEF983D.tmp". In this way, the Kaspersky Lab discovered Flame'a. Unfortunately, Wiper not found using this method and remains unidentified.

Alexander Gostev, chief security expert at Kaspersky Lab, said: "Analysis of the patterns left by the wiper on the hard-drive images examined, it is clear that this pest has existed and has been used to attack computer systems in West Asia in April 2012, and probably even earlier - in December 2011 While the search for Wiper Flame'a discovered, we believe that the wiper was not flame, but independent and other types of malware. destructive behavior Wiper, together with the names of the files that remain on the cleaned system , like a program that used the platform Tilded. Flame'a modular architecture was completely different and is designed to perform continuous and precise campaign of cyber espionage. Flame'a The analysis also have not identified any disruptive behavior that was characteristic of the wiper. "


今年の4月に。西アジアの多くの石油のインストールに関連するコンピュータシステムを攻撃した悪意のあるマルウェアのレポート、コードネームワイパーのシリーズで登場しました。
それは世界の持続可能な開発と安全保障への影響を持っていたので、2012年5月では、カスペルスキーの専門家のチームが、事件を調査し、この新たな害虫がもたらす潜在的な脅威を決定するために、国際電気通信ユニット(ITU)によって開始された検索を主導した。 Kaspersky Labは、ワイパーの影響を受けたマシンから取得したハードドライブを構成しているの効果を分析する研究結果を発表しました。分析では、データのクリーニングおよび破壊的行動のユニークなパターンを含むコンピュータシステムの破壊にワイパーが使用する非常に効果的な方法についての情報を明らかにした。無意識にワイパーサイバースパイキャンペーン、炎、ワイパーの検出の結果を探している間に彼が発見され、身元不明のままでいませんでした。しかし、ワイパーが機械を破壊する効果的に使用されるのは、信者がそのような2012年8月に登場しShamoon、などの悪質なマルウェアを作成することをお勧めすることができ

分析結果のサマリー
•Kaspersky Labは、ワイパーが西アジアでのコンピュータシステム上で行われた攻撃を担当したことが確認され21日に開催 - 2012年4月30
損傷したハード·ドライブのワイパー洗浄レジメンの•分析は文字 "A〜D"で始まる特定のコンポーネントのマルウェアの名前と一緒に特定のデータを明らかにした。これらの知見は、 "A〜D"で始まるファイル名を適用し、 "Tilded"として知られているのと同じプラットフォームの攻撃、上に開発されてきたDuquとStuxnetの害虫を連想させる。
カスペルスキーから•専門家は、KSN(カスペルスキーセキュリティネットワーク)と "A〜D"で始まる名前を持つ他のファイルを探し始めたとワイパー接続Tildedプラットフォームから追加のファイルを見つけることを試みた。
•検索は "〜DEB93D.tmp"と呼ばれる西アジアに多数のファイルを同定した。炎:さらなる分析は、ファイルが実際に悪意のあるソフトウェアの別の型の一部であることを示した。したがって、Kaspersky LabはFlame'aを検出しました。
炎がワイパーの検索時に検出された•が、カスペルスキーの専門家チームは、ワイパーと炎が2つ別々の独立したマルウェアであると信じている。
•カスペルスキーのマルウェアによって行わ感染ワイパー分析の兆しにもかかわらず、同じスケジュールでデータクリーニングのさらなる事件がなかったとして、まだ不明であり、積極的な保護Kaspersky Labは、この害虫を検出しません。
•ワイパーは非常に有効であり、そのようなShamoonなどの悪意のあるマルウェアの新しい "模倣"コピーを作成するために他人を刺激することができます。

"ワイパー"で駆除されたコンピューターの分析
ワイパーによって損傷ハードディスクドライブのカスペルスキー分析により行っこの害虫がそれを識別するために使用することができるすべてのデータをクリアしていることが明らかになった。ワイパーによって変更されたファイル·システムは、コンピュータの実行が成功したことを防いだ。したがって、試験したいずれのマシンではほとんどワイパーの活性化には何もしませんでした、それは、任意のデータを復元したり、回収することも可能であった。 owever Kaspersky Labが行った調査では、害虫やハードディスクドライブから削除されている以前のファイルの名前を示す特定のマルウェアのコンポーネントと、いくつかのケースでは、レジストリキーの名前で使用される洗浄レジメンを含むいくつかの貴重な情報を、明らかにした。すべてのこれらのレジストリキーは、〜Dで始まるファイル名を指すように

ワイパーを清掃するデータの一意のパターン
分析は、ワイパーが作動されているすべてのマシンで使用するパターンの一貫洗浄方法を明らかにした。一度に多くのギガバイト - ワイパーアルゴリズムは、迅速かつ効果的に多くのファイルを破壊するために設計されました。完全データは、大まかに3つのうち4つ襲わマシンの時にディスクの最初の半分の破壊に焦点を当てて操作を行われ、その後、最終的に体系的にシステムの崩壊につながる、ディスクの適切な操作を可能にするファイルの残りの部分をきれいに消去します。また、その目的は特定された攻撃のワイパーは、NFのファイルにあった。追加のマルウェア成分の除去に関連していない場合、これらの攻撃は、役に立たないでしょう。 DuquとStuxnetのが彼らのメインのコードはファイルのPNFにあるストアドので、これは面白い発見でした。

どのようにワイパー検索Flame'a発見につながった
で始まる名前の一時ファイル(TMP) "A〜D"もStuxnetの攻撃と同じプラットフォーム上で開発されたDuquによって使用された:このプラットフォームは "Tilded"。最新の脅威を検出するために、カスペルスキー製品で使用されるクラウドベースのインフラストラクチャ - このパスに続いて、専門家チームがKSNを使って "Tilded"のプラットフォームに基づいて、ワイパー、関連付けられている他の潜在的に未知のファイル名を探し始めた。この過程で、専門家のチームは、西アジアでのコンピュータの数が "〜DEF983D.tmp"という名前のファイルが含まれていることを発見した。この方法では、Kaspersky LabはFlame'aを発見しました。残念なことに、ワイパーは、このメソッドを使用していて、正体不明のまま見つかりません。

アレクサンダーゴステフ、カスペルスキーチーフセキュリティ専門家は、言った: "調べハードドライブイメージでワイパーが残したパターンの分析は、それはおそらく、この害虫が存在しており、2012年4月に西アジアでコンピュータシステムを攻撃するために使用されていることは明らかである、と以前にも - は、ワイパーFlame'aを検索し、検出されたものの、2011年12月にクリーンシステムに残っているファイルの名前と一緒に、私たちは、ワイパーが炎ではなかったと信じているが、マルウェアの独立した他の種類の破壊的な行動ワイパー。 、Tildedプラットフォームを使用するプログラムのような。Flame'aモジュラアーキテクチャは完全に異なっていたとサイバースパイ活動の継続的かつ正確なキャンペーンを実行するように設計されています。Flame'a分析もワイパーの特徴であったいかなる破壊的な行動を識別していません。 "


在今年4月。出现在一系列报告的恶意程序,代号为雨刮器,攻击计算机系统与西亚的石油设施。
2012年5月,一队来自卡巴斯基实验室的专家带领的搜索发起的国际电信组(ITU)对事件进行调查,并确定这个新的有害生物的潜在威胁,因为它有一个全球的可持续发展和安全的影响。卡巴斯基实验室公布的一项研究,分析构成的雨刮器受影响的机器的硬盘驱动器的效果。分析结果显示信息的一个非常有效的方法,使用雨刮器,以破坏计算机系统,包括数据清理和破坏性行为的独特模式。在寻找无意地导致雨刮器网络间谍活动,火焰,雨刮器的检测,他没有被发现,仍然身份不明。然而,雨刮器使用,有效地破坏了机器可以鼓励信徒创建一个恶意程序,如Shamoon,2012年8月,

分析结果摘要
•卡巴斯基实验室证实,雨刮器是负责对计算机系统进行攻击,在西亚,2012年4月21 - 30日举行
•损坏的硬盘驱动器清洁刷清洁方案的分析透露具体的数据,连同一个特定的组件的恶意软件开始字符“D”的名称。这些研究结果Duqu和Stuxnet的害虫,也适用于“D”开头的文件名,并已在同一平台上的攻击,已知为“Tilded”的影子。
•卡巴斯基实验室的专家们开始寻找其他文件KSN(卡巴斯基安全网络)与“D”开头的名字,并试图找到更多的文件从雨刮器连接Tilded平台。
•搜索发现了大量的文件在西亚,“DEB93D.tmp”。进一步的分析表明,该文件是在事实上恶意软件的一部分,另一种类型的:火焰。因此,卡巴斯基实验室已经检测到Flame'a。
虽然火焰检测雨刮在搜索过程中,一队来自卡巴斯基实验室的专家认为,雨刮器和火焰是两个独立的不同的恶意软件。
尽管有迹象显示进行了卡巴斯基实验室的恶意软件感染雨刮分析仍然是未知的,有没有再发生相同的时间表上的数据清洗,并积极主动的保护卡巴斯基实验室没有检测到这种害虫。
•雨刷是非常有效的,能够激励他人创造新的“模仿”副本的恶意程序,如Shamoon。

分析的电脑清洗“抽头”
开展由卡巴斯基实验室的硬盘驱动器损坏雨刮的分析表明,这种害虫已经清除了所有可以使用的数据,以确定它。刮水器改性阻止成功执行的计算机的文件系统。因此,在任何机器上测试,几乎没有什么是不上雨刷激活,它也可以还原或恢复任何数据。然而调查由卡巴斯基实验室已经发现了一些有价值的信息,包括的害虫所使用的清洗方案和具体的恶意软件组件的名称和,在某些情况下,注册表项,说明在以前的文件,已被删除从硬盘驱动器的名称。所有这些注册表项〜D.开头的文件名

独特的模式,数据清洗雨刮器
分析揭示的图案一致的清洗方法,该雨刮器被激活的任何机器上使用。雨刮器算法的目的是要迅速和有效地摧毁尽可能多的文件 - 许多GB的一次。完全擦除的数据了地方大致有三种出的4攻击机,集中销毁的磁盘上半年的操作,然后系统清理其余的文件,它允许在适当的操作的磁盘,最终导致系统崩溃。此外,识别的攻击雨刮器,其目的是NF文件。这些攻击是无用的,如果不涉及到去除额外的恶意软件组件。这是一个有趣的发现,因为Duqu和Stuxnet存储他们的主要代码文件中的PNF。

,雨刮搜索发现Flame'a
临时文件(TMP)的名字开始与“〜D”也使用Duqu,已在同一平台上开发的Stuxnet攻击平台“Tilded”。这条道路,专家团队开始寻找其他潜在的未知文件名与雨刮上的使用KSN“Tilded”的平台 - 一个基于云的基础设施所使用的卡巴斯基实验室产品检测最新的威胁。在这个过程中,一个专家小组发现,在西亚的计算机数量包含名为“〜DEF983D.tmp”的文件。在这种方式中,卡巴斯基实验室发现Flame'a,。不幸的是,雨刮器没有发现使用这种方法,仍然身份不明。

亚历山大·高斯特夫,首席安全专家卡巴斯基实验室,说:“留下的雨刮器上的硬盘驱动器影像检查的模式分析,它是明确的,此虫已存在的和已经被使用到攻击计算机系统中西亚在2012年4月,并可能甚至更早 - 2011年12月虽然发现雨刷Flame'a搜索,我们相信,雨刮器没有火焰,但独立和其他类型的恶意软件。破坏性的行为雨刷,一起保持在清洁系统的文件的名字,像一个程序使用的平台Tilded。Flame'a模块化的架构是完全不同的,是设计用来执行连续和精确的网络间谍活动。Flame'a的分析也没有发现任何破坏性行为为特征的雨刮器。“


Tuesday, August 28, 2012

The most dangerous viruses in the world


The list, published on Thursday, the 15 most significant in the history of the virus, Kaspersky Lab lists include viruses attacking Iran's nuclear facilities. Cyberwarfare is not a screenplay, and the reality - says the analyst of the Polish branch of the company.
The most significant so far in 2012 the authors of the virus recognized statement of Flame (also known as Flamer, sKyWIper and Skywiper) - a malicious program that is actively used as cyberbroń in attacks on objects in different countries, especially the Arab world. Once infected machine can record audio Flame (eg, instant messaging conversations), take screenshots and record keystrokes on the keyboard.
In contrast to the famous Stuxnetu (used among others to attack Iran's nuclear facilities - destroy centrifuges used to enrich uranium, misleading supervisor working speed devices) - Flame by experts, was created primarily for the purpose of espionage, as well as an outdoor year Duqu virus earlier.
- If I had to choose three "worst" of the threat presented by our list, it would be the three most recent. All showed the whole world that it is no longer Cyberwarfare Hollywood production scenario and the reality - said Maciej Ziarek, malware analyst at Kaspersky Lab Poland. - Despite the fact that these three are not exploited by malicious programs infecting innovative technology, it was ground-breaking in terms of the objectives that have chosen cybercriminals. They were strictly selected organizations or strategic objects, and the complexity indicates that the creation of programs involved many experts and a lot of money. We had to deal with cyberbronią aimed at specific targets.
The top fifteen most important by the company in the history of computer threats was also Brain - one of the first computer viruses infecting diagnosed IBM PC computers. Discovered in 1986 and writes its code in the boot sector of floppy virus within a few months of the uprising has spread around the world. The program itself is not destroyed a data disk only the name has changed. Considered virus writers, programmers Pakistani Basit Farooq Alvi and Amjad explained later that with the help of Brain wanted to measure the level of software piracy in the country.

Another important program that Kaspersky Lab analysts earned a place in the top fifteen is Conficker, also known as Downup, Downadup or Kido. Exploiting vulnerabilities in Windows, it was infecting computers private and corporate, where protective systems shut down, install additional malware and steal personal information. Its characteristic feature is that it automatically downloads its new, updated by cybercriminals copies. In 2009, Microsoft has set 250 thousand. U.S. dollar prize to anyone who will contribute significantly to the recognition of Conficker creator. Unfortunately, to this day do not know who was behind the creation of this program.
However, the greatest threat to individual users and businesses recognize Maciej Ziarek Trojan horses, programs that pretend useful tools perform malicious acts. - Nowadays, information is more valuable than ever before, so the cyber criminals use Trojans to steal any data that can later be sold on the black market or used to blackmail users or companies. There are also banking Trojans that "specialize" in the theft of information related to online banking - added Ziarek.
Kaspersky Lab has released a list of the occasion of the 15th anniversary of its founding.
Top 15 most important virus in chronological order:
- 1986 - Brain appears, the first computer virus. Brain spread by writing your code in the boot sector of floppy disks.
- 1988 - Morris worm infects about 10% of computers connected to the Internet (about 6 000 machines).
- 1992 - Michelangelo appears - the first virus that causes widespread media interest.
- 1995 - appears Concept - the first macro virus that infects Microsoft Word documents.
- 1999 - Melissa begins the era of mass mailing malware responsible for the massive global epidemics.
- 2003 - appears Slammer worm bezplikowy responsible for massive worldwide epidemic.
- 2004 - Cabir appears: the first worm a "Proof-of-Concept" for Symbian, Cabir infects mobile phones through Bluetooth.
- 2006 - Leap appears, the first virus for Mac OS X.
- 2007 - Storm worm (also known as Zhelatin) initiates the use of distributed servers through which the cybercriminals controlling malicious programs.
- 2008 - there is Koobface, the first malicious program that attacks Facebook.
- 2008 - appears Conficker, the worm that caused one of the biggest epidemics in history, attacking corporate networks, consumers and governments in more than 200 countries.
- 2010 - appears FakePlayer, pink SMS Trojan for Android.
- 2010 - there is Stuxnet, which is used to carry out targeted attacks on SCADA systems (Supervisory Control and Data Acquisition), signaling the arrival of cyberwars.
- 2011 - appears Duqu, a sophisticated Trojan that collects information about its carefully selected targets.
- 2012 - Flame appears highly sophisticated malicious software that is actively used as cyberbroń in attacks on objects in different countries.


カスペルスキーのリストが含まれて木曜日に発行されるリストは、ウイルスの歴史の中で最も重要な15日イランの核施設を攻撃するウイルス。サイバー戦争は、脚本、そして現実ではない - 会社のポーランド支店のアナリストは述べています。
特に積極的に様々な国、アラブ世界内のオブジェクトへの攻撃にcyberbrońとして使用された悪意のあるプログラム - 最も重要なのは、これまでのところ、2012年にはウイルスの作者は、炎の文(もFLAMER、sKyWIperとSkywiperとしても知られる)を認識した。一度感染するとマシンは、(例えば、インスタントメッセージングの会話)オーディオ炎を記録するキーボード上のスクリーンショットと、レコードのキーストロークを取ることができます。
有名Stuxnetu( - 高速デバイスをワーキングウラン、誤解を招くようなスーパーバイザーを豊かにするために使用される遠心分離機を破壊するイランの核施設を攻撃するためにとりわけ使用される) - とは対照的に、専門家による炎、主にスパイの目的だけでなく、屋外の年間のために作成されました以前Duquウイルス。
- 私は私たちのリストが提示した脅威の3 "最悪"を選択しなければならないとしたら、それは最新の3つであろう。すべては、それがもはやサイバー戦争ハリウッド製作のシナリオと現実でないことを全世界に示した - マチェイZiarek、カスペルスキーでマルウェアのアナリストは述べています。 - これらの3つの革新的な技術を感染させる悪意のあるプログラムによって悪用されていないという事実にもかかわらず、それはサイバー犯罪者を選択した目標の観点から画期的だった。彼らは、厳選された組織や戦略的なオブジェクトであった、と複雑さは、プログラムの作成は、多くの専門家や多くのお金が関与していることを示します。我々は、具体的な目標に向けたcyberbroniąに対処しなければならなかった。
診断されたIBM PCのコンピュータを感染させる最初のコンピュータウイルスの1 - コンピュータの脅威の歴史の中で会社でトップ15で最も重要なのは、脳であった。 1986年に発見され、反乱の数ヶ月以内にフロッピーウイルスのブートセクタに自身のコードを書き込むには、世界中に広がっています。プログラム自体は名前だけが変更されたデータディスクが破壊されていません。ウイルス作成者と見なされ、プログラマーパキスタンBasitファルークAlviと民放は、脳の助けを借りて国にソフトウェア著作権侵害のレベルを測定したいと思ったことを後で説明した。

Kaspersky Labのアナリストは、トップ15内に地位を獲得したもう1つの重要なプログラムはまたDownup、Downadupや木戸として知られているConfickerのです。 Windowsの脆弱性を悪用し、それは、保護システムがシャットダウンする個人や企業のコンピュータを感染させる追加のマルウェアをインストールし、個人情報を盗みました。その特徴は、それが自動的にその新しい、サイバー犯罪のコピーによって更新がダウンロードされていることです。 2009年、マイクロソフトは250万人を設定しています。 Confickerワーム作成者の認識に大きく貢献します誰にも米国ドルの賞金。残念なことに、この日にこのプログラムの作成の背後にいたのか分からない。
ただし、個々のユーザーや企業への最大の脅威はマチェイZiarekトロイの木馬、便利なツールが悪質な行為を行うふりをするプログラムを認識しています。 - 今日では、情報がかつてないほど貴重なものですので、サイバー犯罪者は、後で闇市場で売られたり、ユーザーや企業を脅迫するために使用できる任意のデータを盗むトロイの木馬を使用しています。 Ziarekを追加しました - それはオンラインバンキングに関連する情報の窃盗に "特化"銀行のトロイの木馬もあります。
Kaspersky Labは、創立15周年の機会のリストを公表した。
年代順にトップ15最も重要なウイルス:
- 1986 - 脳は、最初のコンピュータウイルスが表示されます。脳はフロッピーディスクのブートセクターにあなたのコードを記述することによって広がる。
- 1988 - モリスワームは、インターネット(約6 000機)に接続されたコンピュータの約10%に感染します。
- 1992年 - ミケランジェロが表示されます - 広範囲のメディアの関心を引き起こした最初のウイルスを。
- 1995 - Microsoft Word文書に感染する最初のマクロウイルス - コンセプトが表示されます。
- 1999 - メリッサは、大規模な世界的流行を担うマスメーリングマルウェアの時代が始まります。
- 2003 - 大規模な世界的流行にbezplikowy責任Slammerワームが表示されます。
- 2004 - Cabirはが表示されます:最初のワームSymbian向けの "プルーフ·オブ·コンセプト"、CabirはBluetooth経由で携帯電話に感染する。
- 2006 - リープが表示され、Mac OS X用の最初のウイルス
- 2007 - Stormワーム(またZhelatinとして知られている)、サイバー犯罪者は、悪意のあるプログラムを制御しているを通じて配布サーバの使用を開始します。
- 2008 - Koobfaceは、Facebookを利用して攻撃する第一の悪意のあるプログラムがある。
- 2008 - Confickerを、200カ国以上で企業ネットワーク、消費者、政府を攻撃し、史上最大の流行の一つの原因となったワームが表示されます。
- 2010 - FakePlayer、Android用のピンクのSMSトロイの木馬が表示されます。
- 2010 - cyberwarsの到着を合図に、SCADAシステム(監視制御およびデータ収集)に標的型攻撃を実行するために使用されるStuxnetは、があります。
- 2011 - Duqu、その厳選されたターゲットに関する情報を収集し、洗練されたトロイの木馬が表示されます。
- 2012 - 炎は積極的に様々な国のオブジェクトへの攻撃にcyberbrońとして使用され、高度に洗練された悪意のあるソフトウェアが表示されます。


周四公布的名单,15个最重要的在历史上的病毒,卡巴斯基实验室列表病毒攻击伊朗的核设施。网络战是不是一个电影剧本,而现实 - 波兰的分支公司的分析师说。
最重要的,到目前为止,在2012年确认的病毒作者声明火焰(也称为火焰喷射器,sKyWIper和Skywiper的) - 是一种恶意程序,积极作为cyberbroń的攻击对象在不同的​​国家,特别是阿拉伯世界。一旦感染的机器可以录制音频火焰(如即时消息对话),键盘上的截图,记录键击。
相反的,著名Stuxnetu(以及其他攻击伊朗的核设施 - 摧毁离心机进行铀浓缩活动,误导性导师工作的测速设备使用) - 火焰由专家,间谍活动的目的,主要是为创建,以及一个室外的一年Duqu病毒。
- 如果我不得不选择三个“最差”的威胁,提出了我们的名单,这将是最近三个。都表现出了整个世界,它不再是网络战的好莱坞生产场景和现实 - 马切伊Ziarek说,波兰卡巴斯基实验室的恶意软件分析师。 - 尽管这三者都无法利用恶意程序感染的创新技术,突破性的选择了网络罪犯的目标。他们是经过严格挑选的组织或战略的对象,并创建程序的复杂性表明,涉及许多专家和大量的资金。我们要处理的具体目标,旨在与cyberbronią。
前15个最重要的公司在历史上对计算机的威胁也是脑 - 感染诊断的IBM PC计算机的计算机病毒之一。 1986年发现的,其代码病毒的软盘的引导扇区写入的起义在短短几个月内已传播到世界各地。这个程序本身不被破坏的数据磁盘的名称发生了变化。考虑病毒作家,程序员巴基斯坦的巴西特法鲁克ALVI和Amjad解释的帮助下,脑想的盗版软件在国内的高低来衡量。

另一项重要的程序,卡巴斯基实验室的分析师顶部15赢得了一个地方是Conficker的,也称为Downup的,Downadup或Kido。利用Windows的漏洞,它被感染计算机的私人和企业,保护系统关闭,安装额外的恶意软件,窃取个人信息。它的特征是,它会自动下载新的,更新的网络犯罪分子的副本。在2009年,微软已经设置为250000。美元奖金,任何人都将有助于显着的Conficker创造者的认可。不幸的是,这一天不知道谁是背后的创造这一计划。
然而,最大的威胁为个人用户和企业认识到的马切伊Ziarek特洛伊木马,伪装成有用的工具,执行恶意行为的程序。 - 现在比以往任何时候都更有价值,因此网络罪犯使用的木马程序窃取,以后可以在黑市上销售或使用要挟用户或公司的任何数据。也有银行木马“专门”的盗窃网上银行的相关信息 - Ziarek。
卡巴斯基实验室已经发布了其成立15周年之际列表。
15个最重要的病毒按时间顺序排列:
- 1986 - 大脑出现的第一个计算机病毒。脑软盘的引导扇区写代码的传播。
- 1988年 - 莫里斯蠕虫感染的电脑连接到互联网(约000台)的10%左右。
- 1992年 - 米开朗基罗出现了 - 第一个病毒,引起了媒体的广泛关注。
- 1995 - 出现的概念 - 第一个宏病毒感染Microsoft Word文档。
- 1999 - 梅丽莎开始群发邮件恶意软件负责大规模的全球流行病的时代。
- 2003 - 出现Slammer蠕虫病毒bezplikowy负责的为大规模的全球性流行病。
- 2004 - Cabir蠕虫病毒出现:“证明概念”为Symbian的首个蠕虫病毒,Cabir蠕虫病毒感染的手机通过蓝牙。
- 2006 - 飞跃出现​​的第一个病毒的Mac OS X
- 2007 - 风暴蠕虫病毒(也称为Zhelatin)发起使用分布式服务器通过网络罪犯控制的恶意程序。
- 2008 - Koobface的恶意程序,第一攻击Facebook的。
- 2008 - 出现Conficker蠕虫,该蠕虫造成攻击企业网络,在超过200个国家和地区的消费者和政府在历史上,最大的流行病之一。
- 2010 - 出现FakePlayer的,粉红色的Andr​​oid短信木马。
- 2010 - Stuxnet的,它是用来进行有针对性的攻击SCADA系统(监控和数据采集系统),信号cyberwars的到来。
- 2011 - 出现Duqu,一个复杂的木马程序,收集信息,其精心挑选的目标。
- 2012 - 火焰高度复杂的恶意软件积极作为cyberbroń的攻击对象在不同的​​国家出现。