Endpoint Protection

 View Only
Expand all | Collapse all

W32.Flamer Information

Migration User

Migration UserJun 01, 2012 05:34 AM

Srikanth_Subra

Srikanth_SubraJun 05, 2012 06:04 AM

Migration User

Migration UserJun 22, 2012 11:04 PM

Migration User

Migration UserJun 27, 2012 02:27 PM

  • 1.  W32.Flamer Information

    Posted May 31, 2012 12:15 PM

    W32.Flamer is a worm that spreads through removable drives. It also opens a back door and may steal information from the compromised computer. Highly sophisticated and discreet, the Flamer threat contains code that is on par with Stuxnet and Duqu in complexity. It appears to be the work of a well-funded group targeting Eastern Europe and the Middle East.

    Keep up with the latest information on this new threat by subscribing to this thread.

    W32.Flamer 
    http://www.symantec.com/security_response/writeup.jsp?docid=2012-052811-0308-99
    W32.Flamer!gen
    www.symantec.com/security_response/writeup.jsp?docid=2012-053007-0702-99
    Security Response Blog 1
    http://www.symantec.com/connect/blogs/flamer-highly-sophisticated-and-discreet-threat-targets-middle-east
    Security Response Blog 2
    http://www.symantec.com/connect/blogs/painting-picture-w32flamer
    Outbreak Page
    http://www.symantec.com/outbreak/?id=flamer

    Latest Blogs

    W32.Flamer: Enormous Data Collection 6/4/12

    W32.Flamer: Microsoft Windows Update Man-in-the-Middle 6/4/12

    Flamer: Urgent Suicide 6/6/12

    Flame Malware exploits Microsoft's digital certificate  6/7/12



     



  • 2.  RE: W32.Flamer Information

    Posted May 31, 2012 01:02 PM

    Fantastic info! Thanks for the post.

     

    Regards,

    Aniket 



  • 3.  RE: W32.Flamer Information

    Broadcom Employee
    Posted May 31, 2012 01:04 PM

    Thumbs up for putting up blogs and article on one page!



  • 4.  RE: W32.Flamer Information

    Posted Jun 01, 2012 05:33 AM

    Are you seeing this spread to other geographies and industries yet? What kind of trends have you observed? Would be interested to know this info



  • 5.  RE: W32.Flamer Information

    Posted Jun 01, 2012 05:34 AM

    Thanks for sharing information yes



  • 6.  RE: W32.Flamer Information

    Broadcom Employee
    Posted Jun 01, 2012 05:35 AM


  • 7.  RE: W32.Flamer Information

    Trusted Advisor
    Posted Jun 01, 2012 08:51 AM

    Hello,

    Here are the Latest BLOG from Symantec Security Response Team

    Flamer: A Recipe for Bluetoothache

    http://bit.ly/JRjm5K

    W32.Flamer: Spreading Mechanism Tricks and Exploits

    http://bit.ly/KxdLiM

    Hope that helps!!



  • 8.  RE: W32.Flamer Information

    Trusted Advisor
    Posted Jun 04, 2012 03:44 AM

    Hello,

    Here is the Latest BLOG from Symantec Security Response Team

    W32.Flamer: Leveraging Microsoft Digital Certificates

    http://bit.ly/K8WXun

    Hope that helps!!



  • 9.  RE: W32.Flamer Information

    Posted Jun 04, 2012 09:28 AM

    Do you know if there is some report about the spread in a corporate environment ? This virus seems to be limited to governative targets.



  • 10.  RE: W32.Flamer Information

    Posted Jun 04, 2012 09:50 AM

    @ riva11, Everything that we can publish publicly is listed in this thread. Keep checking back here for new reports.

    Best,

    Thomas



  • 11.  RE: W32.Flamer Information

    Posted Jun 05, 2012 06:04 AM

    All useful info in one place!!!



  • 12.  RE: W32.Flamer Information

    Posted Jun 06, 2012 01:17 AM

    Hello Microsoft release a patch (in this patch tuesday) KB2718704 for stopping Man-in-the-middle attack from Flamer and others :

    http://answers.microsoft.com/en-us/windows/forum/windows_xp-security/kb2718704-connection-to-flame-malware/ca73ce4b-4718-4926-bb86-b21a1762012a

    This update should be installed asap.



  • 13.  RE: W32.Flamer Information

    Posted Jun 06, 2012 12:00 PM

    I especially want to thank DCourtel for the link to the MS KB (http://support.microsoft.com/kb/2718704) and Mithun Sanghavi for his link to the blogs: good info.

    If anyone is in need of even more reading on flame, OpenDNS also has some interesting comments on this particular bug: http://blog.opendns.com/2012/06/01/unique-insight-into-flame-malware/



  • 14.  RE: W32.Flamer Information

    Posted Jun 06, 2012 03:32 PM

    On Monday, a single windows update was downloaded to my computer.

    How can I tell if this update was from the W32.Flamer?

    At the time I was running Norton Internet Security 2012 in Windows 7.



  • 15.  RE: W32.Flamer Information

    Posted Jun 06, 2012 03:39 PM

    Go to add/remove progams, check the "Show Updates" box, then scroll down to the list looking for KB2718704.

    If it is shown, then your system is updated with the security patch.



  • 16.  RE: W32.Flamer Information

    Posted Jun 06, 2012 06:34 PM

    Thanks, Thomas.

    The patch was applied on Monday, the day I noticed the automatic update.

    Richard



  • 17.  RE: W32.Flamer Information

    Posted Jun 22, 2012 11:04 PM
    Great info


  • 18.  RE: W32.Flamer Information

    Posted Jun 27, 2012 02:27 PM

    perfect



  • 19.  RE: W32.Flamer Information

    Posted Aug 21, 2012 06:45 AM

    Followers of this W32.Flamer thread may also be interested in a related threat, W32.Gauss

    https://www-secure.symantec.com/connect/blogs/complex-cyber-espionage-malware-discovered-meet-w32gauss



  • 20.  RE: W32.Flamer Information

    Posted Sep 18, 2012 04:46 AM

    This new analysis from Symantec Security Response may be of interest to followers of this thread:

    Have I Got Newsforyou: Analysis of Flamer C&C Servers
    https://www-secure.symantec.com/connect/blogs/have-i-got-newsforyou-analysis-flamer-cc-servers



  • 21.  RE: W32.Flamer Information

    Posted Oct 16, 2012 08:25 AM

    Another new finding from Symantec Security Response may be of interest to followers of this thread:

     

    W32.Flamer.B: Additional Module Discovered
    https://www-secure.symantec.com/connect/blogs/w32flamerb-additional-module-discovered



  • 22.  RE: W32.Flamer Information

    Posted Oct 17, 2012 02:31 PM

    Hi Mick,

    Thanks for updating the thread.

     

    Cheers,

    Thomas



  • 23.  RE: W32.Flamer Information

    Posted Oct 17, 2012 03:53 PM

    Threat came out in June, just found it on an old USB drive of mine that was in a storage box.