The goal of this project is to make virtual world a safer and better place without child pornography, major computer crime and RIAA.
Login As
You can log in if you are registered at one of these services:
Security Bulletins
Latest Malware Updates

Infostealer.Posteal

02/26/2015

Downloader.Busadom

02/26/2015

Trojan.Ladocosm

02/26/2015

SONAR.SuspDocRun

02/25/2015

SONAR.SuspHelpRun

02/25/2015
02/09/2015

Infostealer.Steamfishi

Type:  Trojan
Discovered:  09.02.2015
Updated:  09.02.2015
Affected systems:  Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP
AV Vendor:  Symantec

Description:

The Trojan may be downloaded from the following remote location:
  • steamccommynity.com

When the Trojan is executed, it ends the following process:
  • Steam.exe

The Trojan then searches for the following files and folders in the directory that stores the application for the gaming service Steam:
  • [PATH TO STEAM FOLDER]\ssfn*
  • [PATH TO STEAM FOLDER]\config\loginusers.vdf
  • [PATH TO STEAM FOLDER]\config\SteamAppData.vdf
  • [PATH TO STEAM FOLDER]\config\config.vdf

Next, the Trojan uploads these files to the following remote location:
  • [http://]files.sellexpo.net/upload[REMOVED]

The Trojan then downloads a file from the following remote location:
  • [http://]sft.xquad.info/core/crosCssRandm898kljlUIDG8[REMOVED]

Next, the Trojan deletes the legitimate Steam launcher and replaces it with the downloaded file under the following file name:
  • [PATH TO STEAM FOLDER]\Steam.exe

When executed, the downloaded Steam.exe displays a fake Steam login web page.


If the user inputs a user name and password and logs in, the Trojan uploads these credentials to the following remote location:
  • [http://]files.sellexpo.net/upload[REMOVED]

The Trojan then displays a fake error dialog displaying the following message:
  • Steam Error

Security Advisories Database

Remote Code Execution Vulnerability in Microsoft OpenType Font Driver

A remote attacker can execute arbitrary code on the target system.

07/21/2015

SQL Injection Vulnerability in Piwigo

SQL inection vulnerability has been discovered in Piwigo.

02/05/2015

Cross-site Scripting Vulnerability in DotNetNuke

A cross-site scripting (XSS) vulnerability has been discovered in DotNetNuke.

02/05/2015

Cross-site Scripting Vulnerability in Hitachi Command Suite

A cross-site scripting vulnerability was found in Hitachi Command Suite.

02/02/2015

Denial of service vulnerability in FreeBSD SCTP RE_CONFIG Chunk Handling

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in Apache Traffic Server HTTP TRACE Max-Forwards

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in MalwareBytes Anti-Exploit "mbae.sys"

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in Linux Kernel splice

An attacker can perform a denial of service attack.

01/29/2015

Denial of service vulnerability in Python Pillow Module PNG Text Chunks Decompression

An attacker can perform a denial of service attack.

01/20/2015