The goal of this project is to make virtual world a safer and better place without child pornography, major computer crime and RIAA.
Login As
You can log in if you are registered at one of these services:
Security Bulletins
Latest Malware Updates

Infostealer.Posteal

02/26/2015

Downloader.Busadom

02/26/2015

Trojan.Ladocosm

02/26/2015

SONAR.SuspDocRun

02/25/2015

SONAR.SuspHelpRun

02/25/2015
02/05/2015

Trojan.Cryptolocker.M

Type:  Trojan
Discovered:  05.02.2015
Updated:  05.02.2015
Affected systems:  Windows 7, Windows Vista, Windows XP
AV Vendor:  Symantec

Description:

When the Trojan is executed, it creates the following files:
  • %Temp%\w8i9eHkHOwWwQlX.exe
  • %Temp%\ocegiklmnabcefgj.bmp

The Trojan creates the following registry entries:
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Alcmeter="%Temp%\w8i9eHkHOwWwQlX.exe"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.CryptoTorLocker2015!\@="PRPASCBHJSZLMOM"
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PRPASCBHJSZLMOM\shell\open\command\@="%Temp%\ocegiklmnabcefgj.bmp"

The Trojan encrypts files with the following extensions:
  • .zip
  • .rar
  • .7z
  • .tar
  • .gzip
  • .jpg
  • .jpeg
  • .psd
  • .cdr
  • .dwg
  • .max
  • .bmp
  • .gif
  • .png
  • .doc
  • .docx
  • .xls
  • .xlsx
  • .ppt
  • .pptx
  • .txt
  • .pdf
  • .djvu
  • .mdb
  • .cer
  • .p12
  • .pfx
  • .1cd
  • .md
  • .mdf
  • .dbf
  • .odt
  • .vob
  • .ifo
  • .lnk
  • .torrent
  • .mov
  • .m2v
  • .3gp
  • .mpeg
  • .mpg
  • .flv
  • .avi
  • .mp4
  • .wmv
  • .divx
  • .mkv
  • .mp3
  • .wav
  • .flac
  • .ape
  • .wma
  • .ac3
  • .sql
  • .wallet
  • .dat

The Trojan appends the following string to the file name of the encrypted files:
  • CryptoTorLocker2015!

The Trojan drops the following file in every affected folder:
  • HOW TO DECRYPT FILES.txt


The Trojan then displays the following message box:


The Trojan changes the wallpaper to the following image:

Security Advisories Database

Remote Code Execution Vulnerability in Microsoft OpenType Font Driver

A remote attacker can execute arbitrary code on the target system.

07/21/2015

SQL Injection Vulnerability in Piwigo

SQL inection vulnerability has been discovered in Piwigo.

02/05/2015

Cross-site Scripting Vulnerability in DotNetNuke

A cross-site scripting (XSS) vulnerability has been discovered in DotNetNuke.

02/05/2015

Cross-site Scripting Vulnerability in Hitachi Command Suite

A cross-site scripting vulnerability was found in Hitachi Command Suite.

02/02/2015

Denial of service vulnerability in FreeBSD SCTP RE_CONFIG Chunk Handling

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in Apache Traffic Server HTTP TRACE Max-Forwards

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in MalwareBytes Anti-Exploit "mbae.sys"

An attacker can perform a denial of service attack.

01/30/2015

Denial of service vulnerability in Linux Kernel splice

An attacker can perform a denial of service attack.

01/29/2015

Denial of service vulnerability in Python Pillow Module PNG Text Chunks Decompression

An attacker can perform a denial of service attack.

01/20/2015