Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 20th, 2011, 11:23 PM
Malcontent's Avatar
Malcontent Malcontent is offline
Frequent Poster
 
Join Date: Dec 2005
Location: Cleveland, Ohio USA
Posts: 423
Default Chinese Trojan blocks cloud-based security defences

http://www.theregister.co.uk/2011/01...usting_trojan/
Quote:
Miscreants have released a Trojan specially designed to disable cloud-based anti-virus security defences.

The Bohu blocks connections from infected Windows devices and cloud anti-virus services in place to protect them. Malware writers have long included routines to disable components of desktop anti-virus software packages or block access to anti-virus websites from infected machines.

Bohu - which was spotted by anti-virus researchers working for Microsoft in China - is hardwired to block access to cloud-based net services from Kingsoft, Qihoo, and Rising. All three firms are based in China.
__________________
Avast + WinPatrol Plus + Router/SPI
  #2  
Old January 20th, 2011, 11:26 PM
funkydude's Avatar
funkydude funkydude is offline
Incredibly Massive Poster
 
Join Date: Apr 2004
Posts: 6,000
Default Re: Chinese Trojan blocks cloud-based security defences

More detail: https://blogs.technet.com/b/mmpc/arc...the-cloud.aspx
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #3  
Old January 21st, 2011, 12:20 AM
Kernelwars's Avatar
Kernelwars Kernelwars is offline
Very Frequent Poster
 
Join Date: Aug 2010
Location: TX
Posts: 2,155
Default Re: Chinese Trojan blocks cloud-based security defences

ah thanks for posting this.. I dont like to rely on antivirus for protection..I do have em but thats it..I believe that if you have a clean image to fall back you are good to go no matter what IMO
__________________
Sandboxie | WinPatrol | CCE | MBAM | OpenDns with DnsCrypt
  #4  
Old January 21st, 2011, 12:51 AM
drhu22 drhu22 is offline
Frequent Poster
 
Join Date: Aug 2010
Posts: 268
Default Re: Chinese Trojan blocks cloud-based security defences

Read this thread from #6 onwards

http://www.wilderssecurity.com/showt...ighlight=panda
  #5  
Old January 21st, 2011, 01:40 PM
carat
 
Posts: n/a
Default Re: Chinese Trojan blocks cloud-based security defences

https://www.infosecisland.com/blogvi...Antivirus.html

Quote:
"Technique 1: Evade hash-based detection using file modifications. Bohu writes random junk data into the end of its key payload components to avoid hash-based detection commonly used by cloud-based antivirus technologies."

  #6  
Old January 21st, 2011, 02:03 PM
Sm3K3R's Avatar
Sm3K3R Sm3K3R is offline
Frequent Poster
 
Join Date: Feb 2008
Posts: 310
Default Re: Chinese Trojan blocks cloud-based security defences

So the cloud based detection has been nailed ?!
__________________
Over & Out!
  #7  
Old January 21st, 2011, 04:48 PM
carat
 
Posts: n/a
Default Re: Chinese Trojan blocks cloud-based security defences

Of course!
  #8  
Old January 21st, 2011, 06:47 PM
drhu22 drhu22 is offline
Frequent Poster
 
Join Date: Aug 2010
Posts: 268
Default Re: Chinese Trojan blocks cloud-based security defences

Can anyone test this with immunet?
  #9  
Old January 22nd, 2011, 09:44 AM
dr pan k's Avatar
dr pan k dr pan k is offline
Frequent Poster
 
Join Date: Nov 2007
Posts: 202
Default Re: Chinese Trojan blocks cloud-based security defences

not that i have tested it but for now it only "blocks" chinese vendors (rising,qihoo and kingsoft). the technology used by bohu can be easily implemented on other known malware pieces and trust me on this one, it will be within days or so.

actually lots of people were waiting for something like this to pop up for quite some time now

ps: on second read it probably interacts with norton and kaspersky too, at some extencion
  #10  
Old January 22nd, 2011, 11:48 AM
Ibrad's Avatar
Ibrad Ibrad is offline
Very Frequent Poster
 
Join Date: Dec 2009
Posts: 1,887
Default Re: Chinese Trojan blocks cloud-based security defences

Interesting, everyone knew that malware like this would eventually come. However the cloud vendors will most likely push out a client side update that allows the engine to detect the threat without being on the cloud. The back and forth game continues.
__________________
Panda Security TRUSTED MOD


Panda Cloud Antivirus + Rising PC Doctor + Common Sense

My Security Blog: http://igl-security.blogspot.com/
  #11  
Old January 23rd, 2011, 05:04 AM
carat
 
Posts: n/a
Default Re: Chinese Trojan blocks cloud-based security defences

Quote:
Originally Posted by Ibrad
However the cloud vendors will most likely push out a client side update that allows the engine to detect the threat without being on the cloud. The back and forth game continues.

... and Bohu 2 will kill the cloud again and so on ...
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:34 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums