WINDOWS CALCULATOR UNDER ATTACK || A LOOK AT HOW HACKERS INFECT OUR PC WITH MALWARE THROUGH APPS. ||

in Steem Ghana2 years ago (edited)


virus-4811655__480.jpg

Source

In every seconds, every hour, every day and every year PCs are getting advanced with the appropriate tools, privacy measures and security features that helps them to prevent malwares from attacking the machine.

Just as the producers of this machine are doing their very best to prevent malwares from attacking the machine, hackers are also doing their very best in other to attack the machine with those malware. As a result hackers have found new way of attacking PC through the windows calculator.

The malware group of companies called the Qakbot have been able to discover a way through which it distribute it malicious codes to the system it is to infect. Research by the bleeping computers have come out that the hackers are using the windows calculator as a means to side load the malicious codes into the system it wants to affect. One of the supporting system helping it to take effect is the DLL side loading which is among the common side loaders.


computer-1446109__480.jpg

Source


A look at how the malware attack the PC


As I made mention of, the DLL side loading system made a very good use of the dynamic Link Libraries which is also one of the handling process in windows system. What actually happens is that the attackers all around made use of this method exactly by mimicking the actual DLL, which will automatically move to a folder and at this point the OS load is then authorized to DLL.

It was initially known as the banking trojan but has for the few years develop into what is called malware actively used by the ransomware gang in and around the world according to the Qakbot company. Research has proven that most of the times, attackers use the known calculator app on windows 7
to perform the side loading which is very crucial.

It is has also been reported that the since July 11th of the last month, the malware has been causing damages to people's PC most importantly their documents that are been lost. It has also be confirmed that it has been used in malicious spam campaign.

Another reports also suggested that the malware were been spread through emails. It comes with an HTML file attached with an encrypted Zip achieve and because of the encryption of the ZIP file, it is very difficult for antivirus to be able to identify that it is a malware to rise the alarm. This same ZIP contain an ISO file containing a link copy of calculator.exe' which is the executable file for the windows calculator. In this same ZIP file is the dll file window codesc.dlland 7533.dll which is the malicious play load popularly called the dynamic Link Libraries.

Immediately an individual receives this executable file and mount it, there is an immediate shortcut that gets executed link by taking over the windows calculator app. This is when the Qbot will come in to infiltrate the window calculator using the command prompt. While it is hidden inside this calculator app, it then execute it functionalities in the manner making it difficult to be detected by antiviruses even though antivirus might be installed.

Individuals should be aware that this malware is ineffective in the current window 10 and 11 systems. They have tried several times but can not use the Dll side loading technique on the the present version of both windows 10 and 11. However individuals using any other version of windows should be very much aware that they are probe to these malwares and can cause great harm.


computer-1446111__480.jpg

Source


Conclusion


This is one of the major reasons reason why it is advisable to update to the newer version of windows or any other applications you are using. Older versions of applications and windows or other operating systems are easily bothered by malwares and viruses. Let's Check and ensure we are safe.

Sort:  
 2 years ago 

I've learned what you taught me on how to download a video from Facebook. In fact it did some good. Thank you for sharing with us. I encourage you to keep writing in the community. Steem on friend.

😄🇬🇭🎉🎉

 2 years ago 

I am glad you could apply it. Thanks for passing by.

Technology is something which has come out to help all of us. At times the apps we think have been made to help us are the ones that are easily accessible by bad people who are looking to access our information. This is a useful information.

CriteriaRemark
Club statusClub 100
Steemexclusive
Free of plagiarism
Bot free

Thank you for posting in the steem Ghana community.

 2 years ago 

I am glad you liked it

Amigo no debes usar 2 etiquetas como #learnwithsteem y #fintech, te invito a que quites una de las dos. Pienso que debes dejar #fintech porque el tema esta relacionado con esta etiqueta.

Saludos

@pelon53

 2 years ago 

Thanks

Keep sharing with us. We do encourage that you Continuously power up always and share you diary games with us. Steem on!

😄🇬🇭🎉🎉

 2 years ago 

👍❤️👍

Your post has been successfully curated by our team via @pelon53 at 30%. Thank you for your committed efforts, we invite you to do more and keep posting high quality posts for a chance to win valuable upvotes from our team of curators and why not be selected for an additional upvote later this week in the Top Seven.


Note : You must enter the tag #fintech for your post to be reviewed.

Coin Marketplace

STEEM 0.18
TRX 0.15
JST 0.028
BTC 62928.79
ETH 2465.26
USDT 1.00
SBD 2.55