Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 9th, 2010, 01:07 PM
Rmus Rmus is offline
Exploit Analyst
 
Join Date: Mar 2005
Posts: 3,624
Default Vodafone distributes Mariposa botnet

http://research.pandasecurity.com/vo...utes-mariposa/
Quote:
Today one of our colleagues received a brand new Vodafone HTC Magic with Google's Android OS.
The interesting thing is that when she plugged the phone to her PC via USB her Panda Cloud Antivirus went off, detecting both an autorun.inf and autorun.exe as malicious. A quick look into the phone quickly revealed it was infected and spreading the infection to any and all PCs that the phone would be plugged into.
Be sure and read all of the comments.

As with the infected digital photo frames from several years ago, it's not always easy to determine at what point in the manufacturing/distribution chain the infection occurred.

It became clear at that time that since more USB devices are being marketed, that protection against USB exploits must be a part of one's security set up.

In addition, reported here:

Vodafone Android Phone: Complete with Mariposa Malware
http://isc.sans.org/diary.html?storyid=8389

Also read the comments.

----
rich
  #2  
Old March 9th, 2010, 01:14 PM
funkydude's Avatar
funkydude funkydude is offline
Massive Poster
 
Join Date: Apr 2004
Posts: 5,997
Default Re: Vodafone distributes Mariposa botnet

Turn autorun off! Thankfully Windows 7 doesn't autorun USB devices.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #3  
Old March 9th, 2010, 04:20 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,848
Default Re: Vodafone distributes Mariposa botnet

They just keep on coming, look at the other devices also infected on here http://www.broadbandreports.com/foru...h-malware-incl

Bet it's not the last we see of these types of methods.
  #4  
Old March 11th, 2010, 12:10 PM
Daveski17's Avatar
Daveski17 Daveski17 is offline
Massive Poster
 
Join Date: Nov 2008
Location: Lloegyr
Posts: 5,320
Default Re: Vodafone distributes Mariposa botnet

I found this as well from eSecurity Planet. I must admit I was a bit gobsmacked to find Mariposa & Conficker were involved!


Link to Conficker Eye chart for anyone interested in checking to see if they have Conficker.
__________________
Quis custodiet ipsos custodes?
  #5  
Old March 11th, 2010, 12:17 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,848
Question Re: Vodafone distributes Mariposa botnet

Looks like i'm infected

Click image for larger version

Name:	conf.gif
Views:	5
Size:	234.5 KB
ID:	216105

According to that test anyway, what can it mean ?
  #6  
Old March 11th, 2010, 06:14 PM
Daveski17's Avatar
Daveski17 Daveski17 is offline
Massive Poster
 
Join Date: Nov 2008
Location: Lloegyr
Posts: 5,320
Default Re: Vodafone distributes Mariposa botnet

Quote:
Originally Posted by CloneRanger
Looks like i'm infected

Attachment 216105

According to that test anyway, what can it mean ?

Oh dear!

(It's a good job I'm on Orange & not Vodafone that's all I can say)
__________________
Quis custodiet ipsos custodes?
  #7  
Old March 11th, 2010, 11:40 PM
siljaline's Avatar
siljaline siljaline is offline
Security Expert
 
Join Date: Jun 2003
Location: Montréal, Canada
Posts: 4,133
Post Re: Vodafone distributes Mariposa botnet

Recent mariposa events, a worthwhile read.
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:23 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums