<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=Code_Shikara</id>
	<title>Code Shikara - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://en.bharatpedia.org/w/index.php?action=history&amp;feed=atom&amp;title=Code_Shikara"/>
	<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=Code_Shikara&amp;action=history"/>
	<updated>2026-08-05T15:42:17Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.43.6</generator>
	<entry>
		<id>https://en.bharatpedia.org/w/index.php?title=Code_Shikara&amp;diff=430184&amp;oldid=prev</id>
		<title>Ajay Kumar: Created a new article</title>
		<link rel="alternate" type="text/html" href="https://en.bharatpedia.org/w/index.php?title=Code_Shikara&amp;diff=430184&amp;oldid=prev"/>
		<updated>2023-09-25T18:39:28Z</updated>

		<summary type="html">&lt;p&gt;Created a new article&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{short description|Computer worm}}&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Code Shikara&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; is a [[computer worm]], related to the [[Dorkbot (malware)|Dorkbot family]], that attacks through [[Social engineering attack|social engineering]].&lt;br /&gt;
&lt;br /&gt;
== Timeline ==&lt;br /&gt;
In 2011, the Code was first identified by the Danish [[cyber security]] company CSIS. The [[Antivirus software|AV]]-company [[Sophos]] reported in November 2011 that this threat mainly spreads itself through malicious links through the social network [[Facebook]].&amp;lt;ref&amp;gt;{{cite web|url=https://www.csis.dk/|title=CSIS - Exceptional threat intelligence|publisher=}}&amp;lt;/ref&amp;gt;&amp;lt;ref name=autogenerated1&amp;gt;{{cite web|url=https://nakedsecurity.sophos.com/2011/11/29/facebook-worm-two-blonde-women/|title=Facebook worm poses as two blonde women|date=29 November 2011|publisher=}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In 2013, [[Bitdefender Labs]] caught and blocked the worm, which is capable of [[Spyware|spying]] on users&amp;#039; [[Web navigation|browsing activities]], meanwhile stealing their personal online/offline information and/or credentials, commonly known as [[cybercrime]]. The [[Vector (malware)|infection]] was originally flagged by the [[online backup service]] [[MediaFire]], who detected that the worm was being distributed camouflaged as an [[image file]]. Despite the misleading extension, MediaFire successfully identified the malicious image as an [[.exe]]-file. The malicious Shikara Code poses as a [[.jpeg]] image, but is indeed an [[executable file]]. As an [[IRC bot]], the malware is simply integrated by the attackers from a [[control and command server]]. Besides stealing usernames and passwords, the [[bot herder]] may also order additional malware downloads.&lt;br /&gt;
&lt;br /&gt;
MediaFire had then taken steps to address incorrect and misleading file extensions in an [[Patch (computing)|update]], which identified and displayed a short description by identifying specific file types. To help users for this specific threat, the [[file sharing]] service also blocked files with double extensions, such as .jpg.exe, .png.exe, or .bmp.exe. Just like usual malware, the [[Backdoor.IRCBot.Dorkbot]] can update itself once installed on the victim&amp;#039;s computer or other related [[Peripheral|devices]].&amp;lt;ref&amp;gt;{{cite web|url=https://hotforsecurity.bitdefender.com/blog/dorkbot-malware-infects-facebook-users-spies-browser-activities-and-grabs-data-6165.html|title=Dorkbot Malware Infects Facebook Users; Spies Browser Activities...|date=14 May 2013|publisher=}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The biggest risk is that someone&amp;#039;s Facebook contacts may have had their account already compromised (due to sloppy password security, or granting access to a [[rogue application]]) and that the account user has been allured by clicking on a link seemingly posted by one of their friends.&lt;br /&gt;
&lt;br /&gt;
Although the links pretend to point to an image, the truth is that a malicious [[screensaver]] is hidden behind an icon of two blonde women. After the code is launched, it attempts to download further malicious software hosted on a specific compromised Israeli domain. The malware is currently not present on the Israeli website. All that remains is a message, seemingly from the intruders, that says:&lt;br /&gt;
&lt;br /&gt;
:::::::::::::::::::&amp;lt;big&amp;gt;Hacked&amp;amp;nbsp;By&amp;amp;nbsp;ExpLodeMaSTer&amp;amp;nbsp;&amp;amp;&amp;amp;nbsp;By&amp;amp;nbsp;Ufuq&amp;lt;/big&amp;gt;&lt;br /&gt;
&lt;br /&gt;
It is likely that they are using additional or other websites in continuing spreading their cyberattack(s). Some other popular baits tricking users to click on malicious links include [[Rihanna]] or [[Taylor Swift]] [[sex tape]]s.&amp;lt;ref name=autogenerated1 /&amp;gt;&amp;lt;ref&amp;gt;{{cite web|url=https://nakedsecurity.sophos.com/2011/12/05/facebook-chat-worm-continues-spread/|title=Facebook chat worm continues to spread|date=5 December 2011|publisher=}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Statistics ==&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;Niger:&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;  Due to Information from the [[Kaspersky Cybermap]], Shikara Spam Code has been ranking in April 2017 the Top number 1 in the country of [[Niger]] with 77.51%. Place #2 sits as Linguistic Analysis far behind, with 14.7%.&amp;lt;ref name=&amp;quot;kaspersky.com&amp;quot;&amp;gt;{{cite web|url=https://cybermap.kaspersky.com/stats/#country=208&amp;amp;type=kas&amp;amp;period=m|title=Kaspersky Cyberthreat real-time map|publisher=}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* &amp;#039;&amp;#039;&amp;#039;Code Shikara&amp;#039;&amp;#039;&amp;#039; mainly circulates in following Countries (STATISTICS - April 22nd 2017):&lt;br /&gt;
: Afghanistan (81.27%)&lt;br /&gt;
: Romania (78.58%)&lt;br /&gt;
: Algeria (78.56%)&lt;br /&gt;
: India (78.46%)&lt;br /&gt;
: Niger (77.51%)&lt;br /&gt;
: Turkey (75.49%) &amp;lt;ref name=&amp;quot;kaspersky.com&amp;quot;/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
*{{annotated link|Alert (TA15-337A)}}&lt;br /&gt;
*{{annotated link|Computer worm}}&lt;br /&gt;
*{{annotated link|Dorkbot (malware)}}&lt;br /&gt;
*{{annotated link|Malware}}&lt;br /&gt;
&lt;br /&gt;
==References==&lt;br /&gt;
{{reflist}}&lt;br /&gt;
&lt;br /&gt;
== External links ==&lt;br /&gt;
*[https://www.us-cert.gov/ncas/alerts/TA15-337A Alert (TA15-337A) @ United States Computer Emergency Readiness Team] (&amp;#039;&amp;#039;[[US-CERT]]&amp;#039;&amp;#039;)&lt;br /&gt;
*[https://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Win32%2FDorkbot Technical information @ Microsoft]&lt;br /&gt;
*[https://blogs.technet.microsoft.com/mmpc/2015/12/02/microsoft-assists-law-enforcement-to-help-disrupt-dorkbot-botnets/ Microsoft assists law enforcement to help disrupt Dorkbot botnets @ technet.microsoft.com]&lt;br /&gt;
&lt;br /&gt;
{{Malware}}&lt;br /&gt;
{{Software distribution}}&lt;br /&gt;
&lt;br /&gt;
[[Category:2011 in computing]]&lt;br /&gt;
[[Category:Botnets]]&lt;br /&gt;
[[Category:Email worms]]&lt;br /&gt;
[[Category:Exploit-based worms]]&lt;br /&gt;
[[Category:File sharing]]&lt;br /&gt;
[[Category:Hacking in the 2010s]]&lt;br /&gt;
[[Category:Identity theft]]&lt;br /&gt;
[[Category:Instant messaging]]&lt;br /&gt;
[[Category:Internet Relay Chat]]&lt;br /&gt;
[[Category:Internet Relay Chat bots]]&lt;br /&gt;
[[Category:Password authentication]]&lt;br /&gt;
[[Category:Social engineering (computer security)]]&lt;br /&gt;
[[Category:Spamming]]&lt;br /&gt;
[[Category:Spyware]]&lt;br /&gt;
[[Category:Windows malware]]&lt;br /&gt;
[[Category:Cybercrime in India]]&lt;/div&gt;</summary>
		<author><name>Ajay Kumar</name></author>
	</entry>
</feed>