Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Friday, March 12, 2010

Why Stopping Modern Malware Isn't Working - Fighting Torpig, Sinoval, and Mebroot

Those of us who have been in the IT world for a while recall when viruses were transferred by floppy disks, creating infection patterns that could be easily handled by simply cleaning up a lab or a small group of friends who used the same PCs. Over time, we became used network based infections as Code Red and Nimda hit our networks.

Since then, we've seen far fewer heavy hitting worms as our systems and our networks have been armored against such exploits. Over the past few years, we've begun to see a transition to malware that relies on users to spread. This malware such as the broad family of Fake AV products require a user to click, and are usually aimed at the user themselves. Fake AV, for example, typically seeks to get users to provide their credit card number to remove the fake malware it lists.

Nastier malware is out there, however. Mebroot, a particularly nasty specimen, is often the first step in a hard to handle infection. Mebroot is often spread through web based ad networks - so called "drive-by downloads" or "drive-by infections" targeting browser plugin and browser vulnerabilities. Once there, it injects itself into the PC's master boot record. As F-Secure puts it, "In the competition between rootkits and rootkit detectors, the first to execute has the upper hand."

Once Mebroot is on a system, Torpig, a botnet client often follows. Torpig, like Mebroot, comes in many flavors, but most attempt to steal user credentials, credit card information, and bank account details, which they send to central servers. One group of researchers observed 70 GB of stolen data in a 10 day exercise conducted against a Torpig botnet. The same researchers observed 180,000 infections during that time.

The Torpig botnet is well protected - it uses domain flux to keep the controller nodes moving, and when paired with a Mebroot infection, Torpig itself can be both very hard to find, and extremely hard to remove. Thus far, my own work with it has shown that manual capture and analysis of the MBR using tools like Virustotal and Norman Sandbox is somewhat successful, although the quick changes that the malware authors make mean that most mainstream antivirus is useless, and the more targeted tools like GMER can't always keep up.

There's not a silver bullet for these infections yet, other than running an OS that is not targeted by the malware. Thus, MacOS and Linux users remain safe, although that may change over time. If you're stuck in a Windows environment, particularly if you're using Windows XP, you're in much greater danger. Those users running Windows Vista and Windows 7 are likely to have a better chance of avoiding infection thanks to UAC.

For those looking for a solution, sandbox technologies like Sandboxie may be a good option. As always, patching your browser and all of its plugins is still a reasonable best practice, but many plugins have unpatched holes for weeks or months at a time.

In the meantime, show your senior management this New Zealand Herald article - it provides one of the better mainstream media writeups I've seen.

Monday, March 1, 2010

When System Issues Look Like Malware...But Aren't

"My computer is typing to itself" - that's one of those lines that gets the attention of any IT person, and particularly gets a security analyst to sit up and pay attention.

Thus, when I heard those words, I headed down the hall to check out the system in question. It was definitely typing to itself. The sytem - a laptop, would fill in text wherever the cursor sat, and would open a search bar if no application was active. Left to its own devices, rather oracular sounding text like the following was appearing:

"The you know you are using the zone to the net and what it is a young man in a long line of you didn't know as soon the room will send you wish you sell and move the mean no longer be a U.N. own movie and more than one and one was injured when an E. and in an And move is not invite you to UNITA has not been a move that was a year in and was thrown in the sense that certainly room move on and down and was down there that are the men and women in the news and then an And you you and you end up in a bit of the moon and when you move in the middle of the yen is wrong in what"
It looked a bit like every chat session on the network was being dropped in fragmentary fashion into the applications that were open. What it didn't look like was malware. That meant that we could satisfy curiosity rather than pull out the event response process.

The usual tricks - disconnecting the network, disabling network devices, ensuring that no Bluetooth or IR activity was possible, and of course, removing the wireless USB keyboard and mouse had no effect. This was obviously coming from the local system.

The interesting thing is that the text reminded me of a text to speech program, but the user didn't use one - they did note that they had used one years ago, but not since, and that Office had been upgraded in the interim.

Keeping the room silent and saying easily distinguishable words did not result in matching - or even similar text. The result continued to look like this:


Rebooting the system made it stop...for a while. Dogbert may have had a point.

It has been a while since I was a full time desktop support person, so I enlisted the aid of a couple of senior user support folks in case there was something common that I hadn't dealt with before. The answers that came back could be paraphrased as "That's really weird" and "That does look like some sort of text to speech".

Further digging showed that yes, the system's built in microphone was on, and that it used an integrated sound driver. The microphone's gain was so high that it was generating significant amounts of data even in a completely silent room - and our source of oracular typing was found.

We disabled the microphone, and since then, the system has kept its literary attempts to itself. As for your friendly local security guy? Well, I had a good laugh - and I know where to find a good source of random when I need one.

Friday, February 6, 2009

Parking Tickets and Social Engineering


(not the actual ticket - Creative Commons attribution licensed image courtesy singsing_sky)

Lenny Zeltser of the ISC reports that he recently investigated malware that was spread after victims visited a URL that was included on a parking violation flyer on their car. The BBC picked up the story, meaning copycats are far more likely as this hits major news media. Make sure you check out Lenny's article, as his malware analysis is always worth a read.

The bigger question is if we'll see more of this - I suspect yes. We've seen penetration testers use "lost" thumbdrives in parking lots to get into secure networks and the US military has banned thumb drives on some of their networks due to possible threats.. Now we've gone to the next level and rely on users typing in a URL to compromise their own machines. This would be particularly easy on college campuses or other venues during game days or other events, when many people receive parking tickets because they are unfamiliar with the parking rules, or may have parked in the wrong location.

The best technical fix for organizations is likely a combination of border URL filtering (or DNS blackholing), a good centrally managed AV solution, and strong host level anti-malware software. I've seen a lot of good results with Malwarebytes recently, particularly when removing trojans that the major AV companies miss or are unable to properly clean, and that's what I will be recommending to end users.

Monday, April 14, 2008

Panda: Boot Sector Viruses Set For A Comeback?

Ars Technica recently covered Panda's malware report for Q1 2008 - and they note that Panda makes a surprising prediction that boot sector viruses will become more popular again.

Panda's list is interesting - they mention mobile phone and device viruses, a market which has had AV solutions for quite a while, but which hasn't seen a real widespread threat. They also cover the Storm worm, which has been one of the most visible and largest of the recent widespread viruses. Then, surprising to both myself and the Ars Technica writing staff, they spend quite a few pages covering boot sector viruses.

Many newer IT workers likely haven't dealt with boot sector viruses - they haven't been a serious mainstream threat in almost a decade. We're used to seeing worms, and email borne viruses, and even those haven't been a major threat to most organizations since company wide AV, mail server malware filtering, and firewalling became common.

Will we see boot sector viruses make a comeback? My feeling is that it won't make a significant comeback in most organizations. Social networks, browser exploits, and social engineering seem likely to remain our highest threats, as widespread AV use and better network layer protections are making user interaction a more common requirement for the spread of malware. I also expect to see more viruses spread by removable devices and via wireless, both 802.11 and Bluetooth.

Wednesday, April 9, 2008

Server AV? Maybe you do need it...

The Register's report on AUSCert's advisory regarding virus laden thumbdrives sent out by HP for some Proliant servers points out a flaw in a statement I hear quite often. Many system administrators tell me "We don't need AV on our server, because we don't browse the web or do other risky things".

Most of the same administrators would use the provided thumbdrive to install drivers or to transfer files, and while the Fakerecy and SillyFDC viruses aren't a major concern, the habits that lead to one virus making it onto a server could result in something much worse in the future.

Do servers need antivirus software, and is the overhead worth it?

In many cases, server antivirus is simply another layer of protection. Antivirus, particularly AV with centralized reporting can help detect threats that go beyond viruses. Many rootkits include tools that AV detects, meaning that an alert sysadmin can catch a major compromise through a simple AV detection.

The overhead on a server can be relatively significant, particularly if the antivirus software isn't configured to match the server's purpose and usage model. On a heavily utilized server - such as one doing high performance computing with high processor and disk loads, AV may create too much of a resource drain. In those cases, alternate controls may be appropriate.

In the meantime, remember to scan your thumbdrives, LCD photo frames, and any other device you plug into your PC for viruses - you never know what surprises you may find.