Showing posts with label Flame. Show all posts
Showing posts with label Flame. Show all posts

Flame Computer virus

20 komentar



Flame is the most advanced type of computer virus ever found. Kaspersky Lab announces the discovery of a highly sophisticated malware, named Flame, which is actively used as a weapon that targets cyber entities in several countries. Flame was found by the experts at Kaspersky Lab conducted research that was carried by the International Telecommunication Union (ITU). Results of analysis showed that the Flame is an attack the largest and most complex toolkit available today
Kaspersky Lab analysis results also showed that this program be used as a means of cyber spying and infect computers to steal sensitive data and information. Stolen data is then sent to one server command & control (C & C) Flame



.In cooperation with GoDaddy and OpenDNS, Kaspersky Lab succeeded in largely sinkholing domain used by C & C infrastructure & Flame. Below is a detailed summary of the results of analysis carried out:


  • Infrastructure C & C Flame, which has been operating for many years, direct offline as soon as Kaspersky Lab announces the discovery of its existence last week.
  • Currently there are more than 80 domain known as the Flame is used by C & C server and it and other related domains, which registered between 2008 and 2012.
  • In the last 4 years, the hosting infrastructure server C & C & Flame moved to various locations including Hong Kong, Turkey, Germany, Poland, Malaysia, Latvia, England and Switzerland.
  • C & C Flame Domain was registered with a false identity and various peregister impressive, with the time of registration from 2008.
  • Based on the sinkhole Kaspersky Lab, an infected computer is registered in the various regions including the Middle East, Europe, North America and Asia Pacific.
  • Flame Spreader seem to have a high interest towards the use of Autocad, in addition to PDF and text files.
  • Data are uploaded to the C & C Flame encrypted using a relatively simple algorithm. The stolen documents being compressed using the open source zlib and modification of PPDM.

  • After sending the code to remove traces of suicide, allegedly Flame virus has similarities with the Stuxnet virus first emerged.Stuxnet is a virus that was recently rumored to be made by the joint United States and Israel in order to cripple Iran's nuclear facilities, and how the virus Flame? virus is not known who is behind this flameFlame spread that some time ago in the Middle East region is as yet known who the author and what the motive of this sophisticated virus makers?Researchers from security firm Kaspersky Lab found that there were parts of the Flame malware that has similarities to a virus that attacks Stuxnet computer users in 2010.One of which is owned in common and Stuxnet Flame is disappearing without a trace and this is only realized researcher Kaspersky Labs.In addition, the constituent codes Flame and Stuxnet virus are considered to have some similarities, so there is speculation among two security researchers who estimate the Flame maker and Stuxnet is the same team or two teams that work together to create a second virus.this is reinforced by the findings of researchers in the module "207" used to infect a USB storage device by Stuxnet, and is also found in the virus Flame.Kaspersky researchers Flame and Stuxnet menyimpilkan that relate to each other and are made by the same team and with a slightly different purpose.Roel Schowenberg also explain the difference between Flame and Stuxnet. Stuxnet virus leads to more acts of sabotage and Flame is more directed to espionage to collect data.Researchers will continue to work hard to find information related to the mystery of the relationship between virus Flame with Stuxnet virus that has many similarities.
Read More …