由买买提看人间百态

boards

本页内容为未名空间相应帖子的节选和存档,一周内的贴子最多显示50字,超过一周显示500字 访问原贴
USANews版 - New Financial Virus Targets Iran
相关主题
粗大事了!开火了!有谁知道川普宣布任命朱利亚尼为
我比较支持Scott Walker明州Castile的CCW permit letter
我鳖要完蛋了This is hilarious
local news, a threat targeting black.FBI files reveal missing email 'boxes' in Clinton case, allegations of evidence tampering
target这么快就耸了FBI: evidence tampering in Clinton email case
Bush是个C等学生PA judge dismiss Jill's recount petitions
Planned parenthood 偷拍录像制作人被起诉了奥巴马出面:没有任何证据证明美国选举被人Tampered
厉害:有人在trump记者会上把cnn, msnbc信号给掐了米疣攻击床铺的教育部长是完全没有道理的
相关话题的讨论汇总
话题: threat话题: malware话题: targets话题: virus话题: databases
进入USANews版参与讨论
1 (共1页)
l****z
发帖数: 29846
1
Now this is interesting. From Symantec, makers of the Norton Ant-Virus
family of products:
n the last couple of years, we have seen highly sophisticated malware
used to sabotage the business activities of chosen targets. We have seen
malware such as W32.Stuxnet designed to tamper with industrial automation
systems and other destructive examples such as W32.Disstrack and W32.Flamer,
which can both wiped out data and files from hard disks. All of these
threats can badly disrupt the activities of those affected.
Following along that theme, we recently came across an interesting
threat that has another method of causing chaos, this time, by targeting and
modifying corporate databases. We detect this threat as W32.Narilam.
Based on the detections observed, W32.Narilam is active predominantly in
the Middle East. (See heat map above)
Just like many other worms that we have seen in the past, the threat
copies itself to the infected machine, adds registry keys, and spreads
through removable drives and network shares. It is even written using Delphi
, which is a language that is used to create a lot of other malware threats.
All these aspects of this threat are normal enough, what is unusual about
this threat is the fact that it has the functionality to update a Microsoft
SQL database if it is accessible by OLEDB. The worm specifically targets SQL
databases with three distinct names: alim, maliran, and shahd.
The malware does not have any functionality to steal information from
the infected system and appears to be programmed specifically to damage the
data held within the targeted database. Given the types of objects that the
threat searches for, the targeted databases seem to be related to ordering,
accounting, or customer management systems belonging to corporations.
The problem is that the U.S. is not invulnerable from this type of worm
either, though this worm specifically attacks Persian names and tables.
1 (共1页)
进入USANews版参与讨论
相关主题
米疣攻击床铺的教育部长是完全没有道理的target这么快就耸了
川普禁令下的首批祭品 被撕裂的美国人Bush是个C等学生
巴尔的摩这老黑被杀,女儿给关车里Planned parenthood 偷拍录像制作人被起诉了
作弊的偶像在真穆斯林眼里就是这货色厉害:有人在trump记者会上把cnn, msnbc信号给掐了
粗大事了!开火了!有谁知道川普宣布任命朱利亚尼为
我比较支持Scott Walker明州Castile的CCW permit letter
我鳖要完蛋了This is hilarious
local news, a threat targeting black.FBI files reveal missing email 'boxes' in Clinton case, allegations of evidence tampering
相关话题的讨论汇总
话题: threat话题: malware话题: targets话题: virus话题: databases