Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Friday, March 12, 2010

It's botnet shutdown season

Lately it seems to be botnet-takedown season. For one, Microsoft went the legal route and ask a judge permission to reroute domain name servers related to the Waledac botnet in order to shut it down permanently. Actually, the process is more complicated than that but the domain server procedure was the only non-technical issue that needed external approval.

Then, Panda announced that after a few months of investigation, they provided enough data to the police so they could apprehend three criminals behind a huge botnet managed from Spain. Second takedown of the month and a pretty big one at about 13 million bots involved.

Lately, a few industry researchers followed quite a few Zeus Command and Control servers to a single provider and managed to cut their internet connection, therefore stopping those botnets from working at all. After a few reconnections and counter-attacks by the provider, apparently it's shutting down for good. Third take-down of the month!

These three stories have a single enemy in common: botnets. They have quickly become the biggest enemy of the computer user, but that's not new. What's more recent is the fact that they have become so popular among criminals as a quick way of making money that the criminal underground is steaming with new tools to create and maintain botnets for profit. This "new" software category has become a market that criminals are exploiting to trade with other criminals. Of course there's also fraud in there but who are you going to complain if a fellow criminal scammed you? There are figures like the garant who can verify if the seller is legit. It's some sort of escrow system where some trusted people check the product before the transaction goes through. It's like a real market where malware weapons are being exchanged for money.

Botnet-DIY Kits like Zeus are being sold by thousands of dollars. Piracy is so rampant that the Zeus author has put anti-piracy measures in place. Now, there are some other groups that regularly crack those protections and sell pirated versions of the kit for a lower price. Honor among pirates is a thing of the past and the poor user is the one who will suffer.

The only hope we have is to keep hammering C&C centers, disconnecting them from the internet until they all get the message that letting criminals establish botnets is as bad as being accomplices of the criminal act. This is the only way of getting rid of "bulletproof" hosting providers that ignore abuse complaints and are uncooperative with the police. I hope we keep taking botnets down... it's been a good month.

Thursday, February 25, 2010

Kneber say never

The Zeus malware has been featured in the media lately and I thought I'd talk about it here. The news rage last week started with a security company announcing that they had found a big botnet out there with about 74,000 people infected. These guys dubbed the botnet "kneber" because the domain names involved in this case mentioned a Hillary Kneber. From there, all marketing departments in all security companies went crazy asking "Do we know anything about this new Kneber botnet??".

So digging a bit deeper into the mysterious new botnet that appeared from thin air, it turns out that this is nothing more than our old friend Zeus. This led to a whole new wave of people discussing whether this was important or not and how.

In any case, Zeus is a do-it-yourself malware kit. You can purchase the software, configure your bots and spread them around so you can grow your own botnet with information-stealing capabilities perfectly targeted to your audience (ehm... victims). Obviously the criminals behind the Kneber botnet followed those instructions and managed to get 74,000 people infected. Actually, there's lots of other malware toolkits for sale out there from shady companies that often include tech support and antivirus detection protection among other services.

So this is the world we live in today, one where anybody can make profit in the internet by stealing other people's money. It's as easy as buying a malware kit and building your own botnet. At any moment there are hundreds of different "Zeus" botnets commanded by different criminal groups. Some of them are much bigger than 74,000 PCs and there's really no need to report each one of them as news because they are not. Nevertheless, if this served to raise awareness about Zeus and about how cybercriminals carry out their internet business, maybe something good came out of it.

Saturday, February 13, 2010

You got a Valentine card! click here to open...

Tomorrow will be Valentine's day, the day of love and romance. In the last 10 years it has also been well known for being a favorite theme used by malware writers to lure unsuspecting users to get infected. "Your loved one sent you an e-card. Click here to retrieve it" is already a classic and it doesn't look like it will leave us anytime soon. There is a deeper problem other than people looking for love through the internet though: users are the natural victims of social engineering attacks.

My automated script to parse email messages won't care about love letters sent to him, paypal trying to freeze his account or the big Nigerian fortune recently available to him. Humans, on the other hand, are prone to these and other tricks that exploit naiveness, greed, generosity or any other very human passions that move us. You'd think awareness campaigns have lessened this to some extent but criminals still use the same tricks over and over with a high degree of success.

Just this week I read the story of an ex-scammer from a Nigerian gang telling some of their techniques and the kind of money they're making with the age-old "Give us some money to get a very big payout". People are still falling for the same tricks!!

The IT security industry can make super-sophisticated software that stop zero-day exploits, detect viruses trying to penetrate the computer's defenses, stop bots from making phone-home connections and any other technical attack but what we'll never be able to do is stop the user from clicking on that malicious link because he wants to see the porn video they told him was going to be displayed.

If you think about it, we're trying to save the user from... yes, the user. The problem of creating tight security measures to keep a user safe is that he will try to bypass them because that valentine ecard is more important to him than firewalls, antivirus or any other fancy three-letter-acronym software thrown at them. As somebody in an IT security list I'm subscribed to recently quoted "The problem of making something foolproof is that fools are very ingenious". I suspect we'll keep getting fake valentines that lead to malware for years to come.

Friday, February 5, 2010

The Pushdo DDoS enigma: some theories

Lately there has been unusual reports of a supposed denial of service attack against a variety of well-known web sites. The full list can be found here. This came to me because in the news, they mentioned that a botnet called Pushdo was behind the attack and I reversed this a while ago, so I was quite familiar with the behavior of this particular malcode. This week, I managed to get a sample file related to the Denial of Service attack and found out it's a spambot. This is not part of any botnet, but only the spam-sending component. If you're infected by this, you immediately start sending spam like there's no tomorrow.

So why on earth would a spambot send SSL packets against high-profile web sites? There can be a few theories to choose from:

a) The Denial of Service attack. They could be trying to take those sites down. This is not likely for a few reasons. There are too many sites in that list and that spreads the "attack" too wide. I might give credit to the DDoS theory if the attack was directed to a shorter list of web sites. Also, the list doesn't make a lot of sense. The only thing the sites have in common is their high availability, which probably means they have caching procedures to minimize these kinds of attacks.

b) The internet connection check. These weird SSL connections might be just a way of checking whether the victim is connected to the internet. Just an advanced way of the age-old command "ping". It's a possibility, although it's too convoluted for such a simple use.

c) The DNS check. The connections might be just a way to create DNS queries to check whether the DNS server in the system is properly configured. A stronger possibility than b) but it probably fails for the same reason. Why SSL and not a simple DNS request?

d) The internet performance check. The connections might be measuring how fast the internet connection of the victim is. If this mail agent is anything like other modern spambots like cutwail, there is a field to configure the number of concurrent connections to mail servers. Cutwail, for instance, had this value preset by the bad guys but for some slower systems the number might be too low (so that some outgoing mail connections might not be happening or they happen too slow) and other faster systems would be able to handle more connections (so that the spambot would not be delivering as many spammed emails per second as it could). With a proper internet performance check the spambot would be able to self-configure to the optimal amount of connections in order to make the most out of the victim's internet connection.

I obviously favor the latter theory. I know it's just a theory and I'd probably need to reverse the binary to prove it (or disprove it!) but since I won't have the time anytime soon, I just throw this out there, in case somebody wants to pick it up.

As usual, criticism and new theories are always welcome as well as any other comments...

Friday, January 29, 2010

Printable or not printable?

These last days we're seeing lots of malicious Google search results. In the industry, this is called SEO-poisoned attacks.

For example, my friend Patricia asked me last week about a "very strange" result she got when she googled for "vans rental cork ireland". This is what she got:

 

Digging a bit more into it, I found that the original site had been hacked and replaced by an online pharmacy ad site. The page that replaced the original van rental content also had links to other compromised pages. When Google sees that a highly-positioned page has links to other potentially-interesting sites, it also ranks those sites very highly. This in turns boosts each of them to make them appear very high in their respective search results. Even a week after it was cleanup up, Google still had a copy of the pharmacy page in their cache (that's how I found out all this stuff)

There were some 20+ other hacked pages involved, all ranking quite high in Google. These Google-ranking technique is known as "Search Engine Optimization" or SEO for short.

But this doesn't end there. Either the same group or some other with the ability to compromise a large amount of web sites, started earlier this week to set up redirection pages to legitimate sites. These real websites had a page hidden somewhere within their structure that, when accessed, would point you to a fake antivirus site to scam you. You might be thinking "What is the point of having a hidden web page in a legitimate domain if nobody will be able to find it?". That where their SEO techniques come into play. As in the pharmacy ad case, they riddled the pages with hints and tricks for Google to rank them up quickly and appear high when searching for certain terms. This is a quick list of term that, as of today, still yield malicious results:

road bingo printable cards
rounding how to printables
scary printable pumpkin patterns
shapes sorting printable pocket chart
sleepover party printable invitations
small group bible lessons printable
smith corona na3hh printable instruction manual
spelling word study guides printable
spending track worksheet printable
spirit halloween printable coupons

Now that the attack has lost steam, the bad results start appearing in the lower half of the first result page. I'm guessing there might be many many more search terms but this is just what I found in a quick investigation.

The bottom line of this attack for the average internet user is : Do not trust google results all the time. I know this is a bit shocking but with the amount of bad people out there trying to scam and take advantage of good people, I'm just not surprised very often anymore.

Be careful out there...

Friday, January 22, 2010

Patch or die, an out-of-band story

As I discussed in my last post, the vulnerability in Internet Explorer used against Google and other big companies was a pretty big deal. The reason being that this kind of security hole can be exploited to run malware when a web page is visited. This concept is not new, in fact it's been with us since 2006-2007. When the attacked is performed successfully the victim just visits a web site with the affected browser and becomes infected with malware. In the background, the web page exploits the hole and instructs the flawed browser to download the malicious component and run it.

In the Google case, the hole affected all Internet Explorer versions from 6 to 8. Microsoft announced that the exploit as written would not affect version 7 and 8 if you had enabled a security option called "DEP" (this is on by default though). After the exploit was made public, people modified it to attack effectively all Internet Explorer versions so the DEP suggestion didn't help.

At some point, the French and German governments recommended publicly to not to use Internet Explorer as your browser of choice. With this much pressure coming from all sides, Microsoft today finally released the patch in a special release, something they don't like to do (for some weird unknown reason... if it's necessary, it should be done).

Apparently, Microsoft had known about this flaw in their software since September but it has been sitting in their queue for quite a while until the bad guys discovered it and took advantage. We probably won't ever know the full story, but from the outside it doesn't look very responsible to leave something unsolved for so long waiting for a disaster to happen.

This issue, in my opinion, opens an internal debate in Microsoft about how their patching process should work going forward. It's clear that the current workflow is failing and there should be a way to fix it somehow. This is not the last time we are going to suffer a zero-day exploit attack so the more prepared we are, the better we'll fare when it comes.

Friday, January 15, 2010

Google vs. China, round 1

The biggest news in security this week has been the open war between Google and the China government. The way it's evolving, it looks like there's more to it.

First, Google disclosed that they had an attack coming from China trying to steal information from certain Chinese human rights advocates. They also mentioned that "at least twenty" other big-profile companies were attacked in much the same way. They are so sure that the attacks came from the Chinese government that they threatened with withdrawing their presence from the country. They managed to convince the US government  that this was the case, presumably with really good evidence.

Then, Adobe announced almost instantly that they had detected targeted attacks against them and they were investigating further. Recently, they had been patching lots of newly-discovered vulnerabilities in their Reader product that could be used to run code remotely in machines. People naturally linked these two facts and understood that the mass attack to Google, Adobe and the rest of the companies was performed via a trojanized PDF file sent by email. "Vast espionage campaign" and the likes...

After that, the Chinese government gave an official statement somewhat.... muddled. They said that "China's internet is open and the government encourages development of the internet". That sounds pretty crazy, given the lengths they've gone to censor search engine results. To date, Google China still censors certain results by virtue of the agreement they made with the Chinese government back in 2006.

Just today, news surfaced about a 0-day exploit for Internet Explorer, which seems to be the culprit of the attacks to Google and the others. So it wasn't a PDF hole but an Explorer hole after all. Better yet, it might have been both attacks at the same time. Microsoft hasn't patched the hole yet but they're on it.

Lastly, there is a theory that says that, given that Google's market share is so low in China, Google already wanted out of a market it couldn't compete in. If that is true, they could have used this as an excuse to get out of there, while exposing the government for what they are doing wrong (censoring, hacking, etc.)

My conclusion: While I don't have the clear evidence that apparently Google has, I still believe that the Chinese government has a hand in censoring certain information in the Internet and if that means hacking gmail accounts, they'll make sure it gets done. That is reprehensible and I think that Google should fight the "freedom-of-speech-Internet war with the Chinese government to the last breath and not leave the country. I don't think that's their intention anyway because even if their market share is only 30% in China, 30% of a billion users is still a big market to have. This won't end here though, I'm sure I'll have more chances to comment further on this story.

Thursday, December 31, 2009

End of year recap: Top 5 Security concerns in 2009

This is my own list. There have been many more but I consider these to be the top five:

SEO poisoning has become widespread

Search Engine Optimization techniques have been used by webmasters for quite some time now to promote their sites and appear higher in search engines result lists. During 2009, malicious groups have taken advantage of many of these techniques in order to position bad links very high in search engine results. The scary part is that the bad guys scour the web and study the latest search trends in order to compromise the most likely searches. These have included big events such as the death of Michael Jackson or the latest "Survivor" TV show finalists. They also take advantage of big shopping campaigns such as Christmas, Halloween or Independence Day. Clicking on any link is becoming dangerous and this includes especially Google and other search engine results.

0-day holes in Adobe Reader: PDFs under attack

The interest that some underground groups are showing for pdf reader vulnerabilities are a proof of the popularity of the platform. The fact that most users are blissfully unaware of the dangers of pdf documents is more of a security concern than the ease with which code crackers are succeeding at finding holes. During 2009 there have been many browser plug-in technologies under attack. Not only pdf readers but also flash, winzip and others. This refinement of the browser vulnerability attack is a natural evolution of the classic "click here on this pretty link" infection vector, which nowadays doesn't only utilize html to run malicious code but also pdfs, zips, flash files, etc.

Social Networking sites as infection vectors: Koobface

Seeing how social networking web sites have grown immensely these last 12 months, it's not surprising that the bad guys have decided to attack their users. These sites allow users to create their own profile and add their friends in order to see their updates, pictures and other shared content. Once a real user adds a fake profile with bad intentions, he'll be receiving bad links which may potentially infect him. Once infected, the real user will be posting bad links himself, thereby compromising and infecting his own friends. This makes for a powerful worm which has successfully infected lots of users during 2009 and their creators have added support for quite a few networking sites, such as Facebook, Twitter, Hi5, Bebo and the like.

Make-your-own-botnet kits become popular

The Russian underground, in one of its most recent strokes of genius started offering powerful bots for sale. Anybody can create their own sophisticated botnet with command and control software and custom information-stealing capabilities included. This means that we are finding more mini-custom-botnets and not so many big botnets anymore. Conficker being an exception, most modern botnets are medium to small-sized and very focused to either creating spambots or stealing bank or other credentials. With smaller criminal outfits blossoming, the picture we had of big criminal organizations is becoming fuzzier.

Fake Antivirus schemes bloom

Affiliation programs are as old as the first commercial web sites. This is a method to let others spread word about your site and give them something in return. Traditionally, salesmen have worked on commission and this is no different. Scams such as the fake antivirus software are a few years old but their prevalence during 2009 has grown exponentially thanks to their affiliation programs. For every sucker that pays for a fake antivirus, the intermediary gets a nice commission so all criminal outfits have signed up to become intermediaries. From the Koobface worm gang to all the botnet kits: zeus, bredolab and the rest... all of them have one thing in common: they end up installing a fake antivirus software in their infected victims. Money talks.

This is my summation of 2009 in matters of security. Feel free to share your own or any other opinion...

Thursday, December 17, 2009

Blocking malware with bureaucracy

It's well known that modern malware is primarily web-based. This means that if your computer somehow got infected, chances are you visited an infectious website at some point. Some time ago, bad guys used to use pornographic sites as hooks to infect but nowadays it's either hacked sites or lure sites.

Maybe your regular bookmarked page that you visit every day might have been compromised and is now infectious (this happens more often than you think). Maybe your next Google search is poisoned in a way that it redirects to a site somewhere that infects your computer (this happens mostly with 'popular' search terms but more and more often with all sorts of words you might throw at Google).

The bad guys obviously need to create new domains to host these infectious sites but the good guys take the sites down as soon as possible. We're then in a vicious circle of bad guys creating bad domains very often and good guys looking for them to disconnect them. Curiously enough, the Chinese domains are the most used for malicious purposes (that means that blahblah.cn is more likely to be malicious than blahblah.es, for example).

As a counterattack, the Chinese domain authority revealed earlier this week that they would require new domain registrations to submit paperwork in five days (this is, real physical paper applications in the post). Some others are quickly following suit with rumors that RU domains (that's Russia) will be next in January.

Now, five days is a very long time to have a domain spreading malware. In fact, most malicious domains have done their job by their third or fourth day so it is my belief that this initiative, while a step in the right direction, will not be as useful as they intended it to be. It's a pity that well intentions are not enough in the fight against cyber crime. If it was up to me, I'd raise the real paperwork to two full weeks and wouldn't give them the domain name until then. It's good for their business I'm not in charge.

Thursday, November 26, 2009

Executable text? That doesn't sound right

Today's topic is a bit more esoteric than usual but very interesting nonetheless. Visually, executable code makes all the sense for the computer but it's not human readable. This means that if you open your favorite software (Word, Excel or any other exe) with a word processor, you will see a lot of garbage on the screen which makes no sense to you... apparently.




When you execute it, though, the computer understands it and runs it without a problem. This is called executable code or machine code. Some clever people a few years ago realized that some machine code has normal letter representations so if you create your program by using only those characters you can have a working executable that can be displayed on your screen and not look like garbage.

The first ones to put this concept to use were the guys who created the EICAR antivirus test string. They managed to create a working program that displays a plain-text message on your screen by using only regular "executable text". This week, some team of researchers have taken this concept further and by studying what executable commands look like, they have created a way of expressing them by using plain English. The resulting words don't make a lot of sense but they can throw antivirus researchers off by making them think that some bad code is only a bunch of text.




It's a very interesting concept that can be best applied to short pieces of code, like malicious exploits and the such. This concept of "readable executable text" is tantalizing and scary at the same time. I don't know if the bad guys will ever use this or they are too busy churning out boatloads of regular bad code instead but it's definitely a possibility. For the moment, the paper is being exchanged in underground circles already. Time will tell.

Thursday, November 19, 2009

The future of Fake AV

Fake Antivirus is the latest fashion in malware infections. It's such a simple yet obvious kind of scam that security experts tend to overlook these attacks as non-newsworthy. The truth is that there's more behind the fake antivirus than meets the eye.

In the surface, the supposed antivirus scans the PC for free and it always finds "malware", which it can never clean until the victim buys the upgrade to the "premium" version. In the background, when an infected victim pays the supposed antivirus license to "clean" the detected malware, part of that money goes to whoever helped infect the PC in the first place. The Fake antivirus "companies" give commissions on sales, effectively encouraging criminals to install the fake software in as many PCs as they can.

The first conclusion to this is that fake antivirus software is a tell-tale sign of a deeper infection. So if you or somebody you know has a fake antivirus in their machine, chances are that the computer is infected with something (on top of the fake av!). Nowadays it's commonplace for botnet owners to upload one of these fake antivirus program to each of their nodes.

My second conclusion is that this is not stopping anytime soon. In fact, the same guys who create the fake software have already started creating more varieties that have nothing to do with antivirus, like "Registry Cleaners", "Privacy helpers" and other things. Why end there...? There's a whole lot of possible software to fake that people might be willing to pay for if you use the right incentives.

So what's the future of Fake Antivirus? They have started to do this, albeit timidly, but I forecast that these guys will start using publicly available tools. Instead of faking a scan, why not do a real scan using a free antivirus? (showing a different logo, for good measure) This would make the real antivirus' job that much more difficult, since detecting a competitor's tool is not an option. Sounds like an idea. Antiviruses are not out of options in that case though but that's enough for a forecast. What I'll also say is that fake software for Mac is not that improbable in the coming year.

The real problem is stopping the people who infect (the botnet owners and other miscreants) and the ones who create the fake software. Both are criminals in their own right but with slightly different visions to their respective businesses. That's a tough job we have in front of us.

As for the users, simply put: do not buy licenses for software you did not personally select and install. If somebody else might be installing software for that PC, go ask them first but do not pay straight away. After all, if people stop paying for the scam, the bad guys will move on to something else.