0% found this document useful (0 votes)
24 views3 pages

CoolWebSearch Spyware Overview

The document outlines a task performance assignment on malware, where the author, Justin Lacap, selects five types of malware and provides examples and descriptions for each. It also includes a section on a cybersecurity attack, specifically detailing an article about a LockBit ransomware attack on Accenture, including its title, author, publication date, and the company's response to the incident. The assignment emphasizes the importance of cybersecurity measures and the impact of malware attacks.

Uploaded by

ezjustin99
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
24 views3 pages

CoolWebSearch Spyware Overview

The document outlines a task performance assignment on malware, where the author, Justin Lacap, selects five types of malware and provides examples and descriptions for each. It also includes a section on a cybersecurity attack, specifically detailing an article about a LockBit ransomware attack on Accenture, including its title, author, publication date, and the company's response to the incident. The assignment emphasizes the importance of cybersecurity measures and the impact of malware attacks.

Uploaded by

ezjustin99
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

06 Task Performance 1

Name: justin lacap Subject: “ Information Assurance & Security”


Section: A604

Part I 1. Select five (5) malware from the following: Spyware, Adware, Rootkit, Ransomeware,
Worm, Trojan Horse, or Backdoor

2. Search two (2) examples for each of the five malware you have selected. Add a short
description for each. Cite your reference. (5 points per example)

[Link]

a. Fireball – Developed by a Chinese digital marketing agency called Rafotech. This adware
hijacks a computer browser by changing the search engine, which is fake, and put a noticeable
ads on any website you visit, and prevent you from changing your setting on your browsers

b. DeskAd – This adware put misleading ads on your browser. This adware is so hidden at first
and gradually became a problem and take control over your browser. It spread normally thru
email attachments.

2. Spyware –

a. TIBS Dialer – This Spyware disconnected the victim's PC from their local phone connection
and connected them to a toll number for visiting pornographic websites.

b. CoolWebSearch – This spyware is exploiting security flaws in Internet Explorer to take control
of the browser, change its settings, and send browsing information to the creator of the spyware

[Link] Horse

a. BankingTrojan – The purpose and goal of this malware is to steal your online banking,
epayment, and credit or debit card account information.

[Link] Trojan – This Trojan carries out Attacks, which are meant to bring a network to a stop
by overwhelming it with data traffic.

4. Rootkits

a. Firmware Rootkit – This kind of rootkit can potentially infect your computer's hard drive,
router, or BIOS. They allow hackers to not only watch your internet activities but also to log your
keystrokes since they affect the hardware.
b. Memory Rootkit – This root kits is commonly hide in your computers RAM, it eat your
memory resources and run in the background and doing harm on your computer.

5. Worm

Email worm – The worm uses the email inbox as a medium. The message contains an infected
link or attachment that, when clicked or opened, automatically installs the worm. This worm
finds the infected system's email contacts and sends links to those e-mail, causing them to be
destroyed as well.

Instant messages and chat room worm – These worms function like email worms, stealing
contacts from chat rooms and sending messages to them. The system is infected once the
receiver opens the message or link

Part II:

1. Search for an article regarding a cybersecurity attack using malware. The article should be
published within the last 5 years by a credible source.

2. Answer the following items based on the article you found.

a. What is the title of the article? (3 points)

b. Who wrote the article? (3 points)

c. When was the article published? (2 points) d. Give the link where you found the article. (2
points)

e. Is it possible to prevent this kind of attack? How? (Essay: 15 points)

f. How extensive was the impact of the attack to the environment where it happened? (Essay:
15 points)

g. How did the person/company, who was attacked, cope with the consequences and effects of
the incident? (Essay: 15 points)

Answers: a. Accenture Confirms LockBit Ransomware Attack

b. Lisa Vaas

c. August 11, 2021

d. Accenture Confirms LockBit Ransomware Attack | Threatpost


e. Yes, this kind of attack can be possibly prevented by bolstering their security by upgrading
and employing trusted cyber security firm, but hackers is getting smarter every day without us
knowing, unbeknownst to us they could be attacking us right now without us knowing. It is hard
to prevent this kind of attack without the help of experts.

f. The impact is quite small because they notice the malware early. And they act very quickly

g. They said that they were okay because, they notice the irregularities in the servers and
isolated the infected server, by doing so they stop the attack on its early stages.

Common questions

Powered by AI

Ransomware targets critical data, encrypting it and demanding a ransom for access, with monetary gain directly tied to user compliance with payment demands . In contrast, adware like Fireball aims to generate revenue through advertisement impressions, taking control over browsers without demanding payments, focusing on prolonged control for ongoing earnings rather than immediate payouts .

Browser vulnerabilities are particularly attractive to spyware like CoolWebSearch due to the central role browsers play in day-to-day internet use. These weaknesses can be exploited to alter browser settings, monitor user activities, and collect sensitive data without user consent, leveraging ubiquitous features in browsers that interface with diverse web content .

Adware primarily aims to generate revenue by displaying advertisements, such as Fireball and DeskAd, which hijack web browsers to show ads and alter settings without user consent . In contrast, Spyware, like TIBS Dialer and CoolWebSearch, is designed to covertly gather user information and monitor internet activities, often for malicious intent or financial gain .

Organizations face challenges like keeping up with evolving spyware tactics and ensuring user awareness. Effective strategies include implementing comprehensive endpoint security solutions, conducting regular security training sessions to reduce susceptibility to phishing-like tactics, and maintaining updated security protocols to mitigate vulnerabilities targeted by spyware .

Rootkits like Firmware Rootkit and Memory Rootkit embed themselves deeply into a system's hardware or RAM, allowing them to evade traditional detection mechanisms that focus on the software layer. Firmware Rootkit, by impacting the BIOS or hardware, can remain undetected during routine software scans, while Memory Rootkit consumes system resources subtly within RAM, eluding process-based detection .

Worms targeting email and instant messaging platforms exploit the tendency for users to trust and open messages from known contacts. They hijack email and instant message contact lists, sending infected links or attachments that users are likely to open, thereby facilitating their spread to additional systems .

Key preventive measures include maintaining robust security infrastructures, such as employing trusted cybersecurity firms and monitoring for irregularities which can facilitate early detection. Accenture's success in quickly isolating the affected server demonstrates the importance of rapid response and containment strategies to mitigate further impact .

Accenture’s response highlights the importance of vigilant system monitoring, rapid incident response, and the ability to isolate affected systems. Their swift identification and containment of the ransomware attack prevented widespread damage, emphasizing the need for preparedness and proactive cybersecurity measures in minimizing business disruptions .

Both email and instant messaging worms use social engineering techniques to spread, but email worms typically exploit attachments or malicious links, often reaching a broad audience due to email blast capabilities. Instant messaging worms capitalize on real-time interactions, spreading quickly among active chat users. Cybersecurity strategies must address both asynchronous and synchronous communication modes, emphasizing the importance of user education, advanced filtering, and protection systems .

BankingTrojan targets users' financial information, aiming to steal online banking credentials and credit card details, causing financial loss to the victims . Conversely, DDoS Trojan focuses on overwhelming networks with excessive traffic to disrupt services, impacting the availability of network resources rather than directly stealing information or money .

You might also like