Flame Worm

How prepared is Avast for this kind of threat that is in the news today about this ‘Flame’ worm program?

what do you mean by prepared?

the news around say it was tested against 43 scanners (guessing that is all at Virustotal) and none detected it
Sophos say they are about to release signature for it

Hi Pondus.

It only runs when the controllers want it to run. It is 20 times :smiley: more complicated than stuxnet was. Skywiper/Flame has been already 5 year’s into development ??? before Kaspersky came with detection for the data stealing part of the malware.
If they were able to build this cyber-weapon five years ago, what are they out to be building right now? ;D

polonus

Good technical analysis on latest variant here: http://www.symantec.com/connect/blogs/flamer-highly-sophisticated-and-discreet-threat-targets-middle-east.

Is financial malware side-kick of Stuxnet. Primarily designed to go after government or large corp. servers. Doubt it will even waste it’s time with us "small fry. ::slight_smile:

@ DonZ63,

Figure 2. Distribution of the threat

Based on the number of compromised computers, the primary targets of this threat are located in the Palestinian West Bank, Hungary, Iran, and Lebanon. However, we have additional reports in Austria, Russia, Hong Kong, and the United Arab Emirates. These additional reports may represent a targeted computer that was temporarily taken to another region–for example, a laptop. Interestingly, in addition to particular organizations being targeted, many of the compromised computers appear to be personal computers being used from home Internet connections.

Quote from article DonZ63 referenced above. My italics added.

ATM usage is somewhat speculative. However, even in the right hands, potentially a very dangerous tool.

“Flame has been “in the wild” for more than two years, since March 2010, Kaspersky said. It gave no clues over which party could have been behind the attack.”

If individual PCs are being targeted, I suspect it would be as a bot. More likely to throw off authorities trying to track Flame’s original source. If it’s been in the wild for two years, odds are thousands of PCs are already infected. In the wild for two years … talk about being “flamed!” ;D

I stand corrected. Per a current Huffingtonpost.com article:http://www.huffingtonpost.com/2012/05/29/flame-malware-middle-east_n_1552981.html?ref=technology

The malware can also hide inside seemingly harmless programs and can create “backdoors” that enable hackers to re-enter the infected computer network at any time, Gostev said. So far, the spread of the Flame malware has been relatively small – less than 400 infections have been reported, about half of them coming from Iran, according to Kaspersky Lab.

There is also a link in the Huffingtonpost article to the Iranian CERT web site with a manual fix. Article is in English but rest of web page is in Arabic.

detections are in avast database

 Win32:Skywiper-E [Trj], Win32:Skywiper-F [Trj]

see : http://www.avast.com/virus-update-history

29.5.2012 - 120529-1

Last lines :wink:

something interesting here too:
http://securitywatch.pcmag.com/security-spyware/298405-flame-malware-cybergeddon-or-old-news

P.S. I was able to discover some of the binary codes of flame malware which i forwarded to avast lab via E-mail yesterday

normal users should not worry too much :wink:
http://nakedsecurity.sophos.com/2012/05/29/flame-malware-the-biggest-the-baddest-a-little-perspective/

Bitdefender has prepared for Flame

http://labs.bitdefender.com/2012/05/cyber-espionage-reaches-new-levels-with-flamer/

Steve Gibson is talking about Flame in the latest Security Now:

http://twit.tv/show/security-now/355

Hi,

Here is more info on Flame Virus from Aleks, Kaspersky Lab Expert and at the end of the article he provides a method for a quick “manual” check of your systems for the presence of a Flame infection.

http://www.securelist.com/en/blog/208193538/Flame_Bunny_Frog_Munch_and_BeetleJuice

Cheers,
Janice

Hi,

Here is more info on Flame.

http://www.securelist.com/en/blog/208193540/The_Roof_Is_on_Fire_Tackling_Flames_C_C_Servers

Thanks Dim@rik…!! Very interesting read. :slight_smile:

Hi All,

After so long i never comment or read AVAST Forum anymore, there is a lot of precious information and update regarding to malware attacks.

About FLAME i got update from one of Indonesia Dr.Web Scanner Distributor, and i am still curious how strength this malware compared than Virut or Conficker or Virut?

Cheers,

Hi All,

More on Flame Virus now reportedly dead!

See: http://rt.com/usa/news/flame-virus-suicide-stuxnet-743/ and

http://www.washingtonpost.com/blogs/blogpost/post/flame-faq-all-you-need-to-know-about-the-virus/2012/06/20/gJQAAlrTqV_blog.html

Cheers,
Janice