The goal of this project is to make virtual world a safer and better place without child pornography, major computer crime and RIAA.
Login As
You can log in if you are registered at one of these services:
Security Bulletins
Latest Malware Updates

Infostealer.Posteal

02/26/2015

Downloader.Busadom

02/26/2015

Trojan.Ladocosm

02/26/2015

SONAR.SuspDocRun

02/25/2015

SONAR.SuspHelpRun

02/25/2015
01/27/2015

Android.Accstealer

Type:  Trojan
Discovered:  27.01.2015
Updated:  27.01.2015
Affected systems:  Android
AV Vendor:  Symantec

Description:

Android package file
The Trojan may arrive as a package with the following characteristics:

Package name: com.sexywallpapers.wallpaper.sexy
Version: 1.1
Name: SexyWallpapers


Permissions
When the Trojan is being installed, it requests permissions to perform the following actions:
  • Read or write to the system settings
  • Open network connections
  • Access information about networks
  • Start once the device has finished booting
  • Make the phone vibrate
  • Prevent processor from sleeping or screen from dimming
  • Access list of accounts in the Accounts Service
  • Check the phone's current state
  • Access information about the Wi-Fi state
  • Access location information, such as GPS information
  • Write to external storage devices

Installation
Once installed, the application will display a pink icon with a picture of a woman's face and the text "sexy pictures".



Functionality
The Trojan poses as a wallpaper application for Android devices.


When the Trojan is executed, it gathers account details from the following apps:
  • Facebook
  • Twitter
  • Gmail

The Trojan then sends the gathered information to the following remote location:
  • [http://]5.10.71.142/s/s[REMOVED]

Security Advisories Database

Remote Code Execution Vulnerability in Microsoft OpenType Font Driver

A remote attacker can execute arbitrary code on the target system.

07/21/2015

SQL Injection Vulnerability in Piwigo

SQL inection vulnerability has been discovered in Piwigo.

02/05/2015

Cross-site Scripting Vulnerability in DotNetNuke

A cross-site scripting (XSS) vulnerability has been discovered in DotNetNuke.

02/05/2015

Cross-site Scripting Vulnerability in Hitachi Command Suite

A cross-site scripting vulnerability was found in Hitachi Command Suite.

02/02/2015

Denial of service vulnerability in FreeBSD SCTP RE_CONFIG Chunk Handling

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in Apache Traffic Server HTTP TRACE Max-Forwards

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in MalwareBytes Anti-Exploit "mbae.sys"

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in Linux Kernel splice

An attacker can perform a denial of service attack.

01/29/2015

Denial of service vulnerability in Python Pillow Module PNG Text Chunks Decompression

An attacker can perform a denial of service attack.

01/20/2015