Уровень 0 · материалов: 4
В кластер включаются документы, описывающие атаки, основанные на принудительном изменении локального файла hosts для перенаправления пользователя на вредоносные серверы.
Общие признаки: подмена DNS, перенаправление трафика, изменение файла hosts, кража данных, социальная инженерия
Группа выше: Распространение вредоносного ПО обманом
Смысл: The text warns users about a pharming campaign spreading through social networks where attackers trick victims into running a batch file that redirects major websites to a malicious server via the system hosts file.
An analysis of a social engineering attack that uses a malicious .bat file to redirect popular websites to a fraudulent IP via the system hosts file.
Смысл: The text is a security analysis of a social engineering attack that combines credential theft (phishing), ransom-based website redirection (DNS hijacking via hosts file), and automated spamming to spread itself through a social network.
A technical analysis of the VKGuests.exe malware that steals VKontakte credentials, hijacks the hosts file for ransom, and sends spam to the victim's contacts.
Смысл: The main idea is to warn users about a DNS redirection attack via hosts file modification used to steal banking credentials and funds, emphasizing that antivirus software alone is not a guarantee of security.
Attackers used hosts file modification to redirect VTB24 and Alfa-Bank users to fake websites to steal login credentials and funds.
Смысл: The author describes finding malicious redirects in their local hosts file and proposes that web browsers should implement a notification system to warn users when a domain is being resolved locally via the hosts file.
After discovering banking redirects in their hosts file, the author suggests that browsers should warn users when a site is resolved locally.