Google Search

Showing posts with label Blackhole. Show all posts
Showing posts with label Blackhole. Show all posts

Monday, January 14, 2013

Technical paper: Journey inside the Blackhole exploit kit

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Plug hole. Image from ShutterstockOne of the most common questions we receive at SophosLabs is "How are users most likely to get infected with malware?".

As regulars readers will be aware, the answer is through the web. More specifically, computers are most likely to be infected through compromised legitimate websites redirecting user traffic to malicious websites that are hosting some exploit kit.

The most active of these exploit kits in recent times is one known as Blackhole.

Properly understanding how the Blackhole exploit kit works and why it has become the most popular of the various exploit kits available is important in order to provide the best protection to our customers.

Previous research focused on early versions of the Blackhole exploit kit, and the tricks used by the attackers in evading detection.

More recently, SophosLabs expert Gabor Szappanos has been delving deeper into the internal workings of the Blackhole exploit kit, to get a more thorough understanding of how it works.

Gabor's technical paper, entitled "Inside a Black hole", is now available, and I would encourage all readers to download it and learn more about the Blackhole exploit kit.

http://twitter.com/SophosLabs

Plug hole image from Shutterstock.


View the original article here

Monday, January 7, 2013

EU domain abuse, courtesy of the Blackhole exploit kit

pyrhox.eu

The domains all resolve to the same IP address, a server located in the Czech Republic.

They are short-lived; the names only resolve to the target server for a brief period before the attackers move on to the next.

This type of tactic is pretty common, used by many threats in their attempts to evade security filtering.

Normally however, it is TLDs other an .eu that are abused.

Digging a little further into the WHOIS information for these registrations reveals some interesting observations. A Finnish connection in fact, based on the registrant details provided.

We can go back a few more months, and see a similar spate of activity, again used for Blackhole hosting, but on .IN domains.

zjmnwv.in
yyssyr.in
wkhmyk.in
hwhjgj.in

As you can see, the domain names follow the same 6-character, seemingly random pattern.

Looking at the WHOIS information for some of these again throws up our Finnish connection!

And guess what? When active, these .IN domain names resolved to the very same IP address as above!

And what of this IP address? It has something of a long history of questionable activity, extending over many months. It currently hosts over 100 domains, whose purpose ranges from porn site gateways (referenced in spam) through to exploit sites.

This episode raises an important question. Is there more that Registrars could or should be doing to prevent the bad guys abusing their services?

Some of the very same techniques that we use to join the dots between data, linking attacks and highlighting malicious activity could be very useful to Registrars attempting to block malicious activity earlier.

History tells us that the European domain name authority, EurID, are no strangers to decisive action when it comes to protecting the reputation of the TLD.

I have reported the current spate of abuse to the appropriate people, so time will tell how effectively they can snub out this activity.

Follow @SophosLabs

.EU domain image from Shutterstock.

Fraser is one of the Principal Virus Researchers in SophosLabs. He has been working for Sophos since 2006, and his main interest is in web related threats.
var OBCTm='1328889400668'; jQuery(document).ready(function($){ Gravatar.profile_cb = function( h, d ) { WPGroHo.syncProfileData( h, d );}; Gravatar.my_hash = WPGroHo.my_hash; Gravatar.init( 'body', '#wp-admin-bar-my-account' ); });

View the original article here

Wednesday, January 2, 2013

Fake Apple invoices lead to Blackhole exploit kit that drains your bank account

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Filed Under: Adobe, Adobe Flash, Apple, Data loss, Featured, Java, Malware, Oracle, PDF, Spam, Vulnerability

Online criminals targeting exploits is nothing new, but they are now taking a multi-pronged approach to compromising your security.

They are not just exploiting unpatched flaws in your applications; when that fails they convince you to infect yourself.

Take, for example, this email I received today pretending to be an invoice from Apple for a $699.99 postcard.

Apple spam invoice for $700 postcard

The social engineering isn't exactly perfect. I haven't been known by the Windows variable %email% in at least 10 years. Whoever is behind this has paid a lot of attention to detail, though.

The link "View/Download" ends in download.jpg.exe, while the "Cancel" and "Not your order" URLs end in check.php.

The smart social engineering bit is that, whether you are simply curious what this is about or furious about this unauthorized charge, you are still likely to click one of the links.

If you click any of the links, you are taken to an unrelated page proclaiming to be the IRS and saying you are not using a supported browser.

Black hole webpage

Once this page is displayed, in the typical fashion of the Blackhole exploit kit, it attempts to deliver exploits against Oracle Java, Adobe Flash Player and Adobe Reader. If any of these are successful, it infects your computer with the Zeus/ZBot Trojan.

Sophos ZBot detectionWorse yet, if none of these works, the image has links to download an "up to date" version of these browsers that simply downloads a file called update.exe.

If the recipient is exploited or downloads and executes the file they are infected with the Zeus/ZBot Trojan, which is designed to log your keystrokes and compromise your bank accounts.

It is always a bad idea to click links that appear in our inboxes, but we may be more likely to do so when we think we are being charged for an illegitimate transaction.

Don't do it. Like anything else, always be suspicious of things that come to you and use a trusted external method of verification.

Go to the website of the company in question, call the number on the back of your card or billing statement, etc.

This is especially important advice at this time of year, as we typically see increased criminal activity during the Christmas season. Be on your guard.

Sophos Anti-Virus on all platforms detects and blocks the various components of this malware as follows:

* Mal/ExpJS-AV: Blackhole exploit JavaScript.
* Troj/Pdfex-HM: Malicious PDF file.
* Troj/SWFExp-AI: Malicious Adobe Flash file.
* Mal/Zbot-JG: Banking Trojan payload.

Follow @chetwisniewski

View the original article here

Monday, December 31, 2012

Blackhole exploit kit confusion. Custom builds or copycats?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Black hole. Image from ShutterstockThe past couple of weeks have been interesting times for anyone following the malicious Blackhole exploit kit that continues to dominate the charts.

Don't get me wrong, we expect changes and updates - the individuals behind the kit work tirelessly to try and evade security products. However, some of the recent changes are a little confusing to say the least!

One of the key aspects of the Blackhole exploit kit that we identified in previous research was the organised and coordinated nature of the kit. For example, as soon as a new obfuscation method was added, we would quickly see it in use, across the majority of exploit sites being tracked.

The release, in September 2012, of Blackhole exploit kit version 2 introduced several changes, but the coordinated 'rollout' of minor tweaks and modifications continued.

And so to recent developments that we have been observing. Firstly, let's start off with a quick recap of what we are seeing:

So what is going on? Why this sudden burst of diversity from Blackhole?

Or is this a new kit? Are some of these recent Blackhole changes actually not Blackhole at all, but some other kit?

As I have been putting together this post, I see that our colleagues at F-Secure are asking a similar question.

Several factors point to this being Blackhole (or at least very closely related - same codebase, potentially same authors).

obvious similarities in the function names, filenames, structure etc of the exploit siteincoming user traffic is using the same malicious script injections (Mal/Iframe-W redirects injected into legitimate web sites)URL structure used in the kit is consistent with Blackhole v2

Personally I suspect these new 'flavours' of Blackhole are from the same group. However, there is one nagging doubt I have:

some of the new features could be considered retrograde steps for Blackhole. Why would they revert to using predictable content within the URLs?

Whatever the case, we will continue to monitor these attacks closely, ensuring our reputation filtering and content detection technologies protect customers, regardless of the group behind them!

Landing page detections: Mal/ExpJS-N, Mal/ExpJS-AN, Mal/ExpJS-AVFlash content detections: Troj/SWFExp-AI, Troj/SWFExp-BEPDF detections: Troj/PDFJS-AAS, Troj/PDFEx-GXJava detections: Mal/JavaGen-A, Mal/JavaGen-C, Mal/JavaGen-EFollow @SophosLabs

Thanks to Gabor and Ferenc in Sophos's Budapest lab for their assistance in putting together the content for this article.

Black hole image from Shutterstock.


View the original article here

Tuesday, December 11, 2012

Blackhole malware attack spread via 'Your photos' email

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Blackhole photo. Image from ShutterstockA malware attack has been spammed out widely via email to internet users, posing as a message about photos.

In the attack, cybercriminals attempt to trick unsuspecting users into opening an attached file in their browser, redirecting them to a webpage hosted on a Russian website that takes advantage of the Blackhole exploit kit.

The notorious Blackhole exploit kit then attempts to infect visiting computers through a wide number of vulnerabilities.

Here's a typical message that has been spammed out - in this case, pretending to come from a LinkedIn user:

Malicious email

Subject: Your Photos

Message body:
Hi,
I have attached your photos to the mail (Open with Internet Explorer)

The attached file has a name of Image_DIG[random number].htm. If you make the mistake of opening the file attachment in your web browser you will see a "please wait" message:

Please wait a moment. You will be forwarded..

Internet Explorer or Mozilla Firefox compatible only

Webpage

Sophos detects this HTML file proactively as Mal/JSRedir-M. What isn't obvious to most computer users is that behind-the-scenes obfuscated JavaScript code is redirecting the user's browser to a Blackhole exploit site.

Obfuscated JavaScript code

More and more of the attacks that the folks at SophosLabs are intercepting involve the Blackhole exploit kit, underlining the importance of keeping your computer's anti-virus software and software patches up-to-date as well as learning to exercise caution about opening unsolicited attachments or clicking on unknown links.

Learn more: Exploring the Blackhole exploit kit

http://twitter.com/gcluley

Black hole illustration image from Shutterstock.


View the original article here

Monday, October 8, 2012

SSCC 98 - RSA keys, Blackhole exploits, Nitol botnets and Apache takes potshots at Microsoft

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Sophos Security Chet Chat logoThis week Paul Ducklin is in the guest seat as he and Chester look at the latest security news.

This week's topics include: Patch Tuesday, weak RSA certificates, how you might manage to lose $250,000 worth of Bitcoins, a new version of the Blackhole exploit kit, and the takedown of the Nitol botnet.

To finish off, Chet and Duck take a look at Apache's recent spat with Microsoft.

That's where Microsoft tried to do what it thought was the right thing about Do Not Track in its new browser, only to suffer a smackdown by the Apache open-source web server crew.

Neither Chet nor Duck mince their words in this segment, so make sure you listen to the end!

(17 Sep 2012, duration 14'48", size 10.7MBytes)

Follow @duckblog
-

Tags: Apache, bitcoin, bitfloor, BlackHole, botnet, buffoonery, chet chat, Cryptography, digital certificate, DNT, Do Not Track, Exploit, Exploit Kit, IE, Microsoft, nitol, Patch Tuesday, RSA, takedown, update, zombie


View the original article here

Tuesday, August 21, 2012

Insecure WordPress blogs unwittingly host Blackhole malware attack

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

SophosLabs has intercepted a major malware campaign, spread via spam email and compromised self-hosted WordPress blogs, which attempts to infect computers using the notorious Blackhole exploit kit.

Be on your guard if you have received an email entitled "Verify your order", as links contained within the email could take you to a poisoned webpage, designed to install malware onto your PC.

Here's what a typical email looks like:

Malicious email

Subject: Verify your order

Message body:
Dear [name],

please verify your order #[random number] at [LINK]

We hope to see you again soon!

WordPressThe websites that are being linked to aren't ones that have been created by the malicious hackers.

They are legitimate websites that are running a self-hosted installation of the popular WordPress blogging platform. (Note, this does not include the many millions of bloggers who use the WordPress.com service - the vulnerable sites are those where people have installed their own WordPress software).

Unfortunately, some people haven't properly secured their sites - which has allowed malicious hackers to plant malicious code from the Blackhole exploit kit, and means that malware is now downloading onto innocent users' computers.

Sophos products detect the malware as Troj/PDFEx-GD, Troj/SWFExp-AI, Mal/ExpJS-N and Troj/Agent-XDM.

More and more of the attacks that we are intercepting involve the Blackhole exploit kit - recent examples include emails posing as traffic tickets from NYC, rejected wire transfer notifications and fake Facebook photo tag notifications.

Remember to not just keep your anti-virus software up-to-date, but also to ensure that any software you run on your web server is also properly secured, and kept patched and current (that includes blogging software like WordPress and any plugins that it might use).

Follow @gcluley

View the original article here

Tuesday, July 24, 2012

Pseudorandom domain name generation and the Blackhole exploit kit

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Blackhole. Image from ShutterstockIn this post I want to highlight one of the script injections we have been tracking for the past month or so, which is being used to redirect web traffic to exploit sites (running the Blackhole exploit kit). Two factors make this particular script injection worthy of discussion, namely:

large scale attacks. Many legitimate sites have been hit in these attacks.JavaScript generates a random string which is used within the target domain name.

We first this redirect script at the start of June. Sophos products block infected pages as Mal/Iframe-AF, and since early June, the prevalence of this threat has risen to the top of our web threat stats (accounting for 30-50% of all web threat detections).

The injected script is obfuscated as we expect nowadays, and will typically be seen appended to legitimate JavaScript libaries within sites. An excellent write-up here suggests that a vulnerability in Plesk (server admin software) was used to gain access to sites, and add the malicious code.

Deobfuscating the malicious JavaScript is trivial and lets us see the true payload, an iframe redirect. However, this attack is made slightly more interesting by the use of a simple date-based algorthim to generate a random string that is used in the target domain name.

The script generates a random string based on the current date, changing the string every 12 hours. It is a pretty simplistic approach.

This is not the first time we have seen this tactic in malicious JavaScript redirects - Sinowal did something similar back in 2009. Of course, once they have their hands on the code, it is easy for the good guys to generate all the possible domain names and get them blacklisted. Sinowal responded to this by including unpredictable data in its algorithm - using content pulled from a live Twitter feed.

No such elegance here I am afraid. The best we have seen are some later variants of the code which prepend a string for a "random" colour.

The iframe that the script adds to the page is intended to point the browser to a TDS server the attackers control. One of the strings used in some of the iframe URLs is responsible for the 'Runforestrun' nickname that has been attached to this attack. *

Latter variants of the script use different strings, and they have started to use dynamic DNS services for the referenced target sites (a favourite trick we have seen Blackhole use aggressively).

The traffic will be bounced (via a HTTP 302) from the TDS to the exploit site (normally via a second TDS). To date the exploit site has typically been running Blackhole, where the usual array of Java, Flash and PDF exploits are used in order to infect the user.

The final payload users are infected with varies - we have seen these payloads ranging from backdoor Trojans and Zbot to ransomware.

Aside from the Mal/Iframe-AF detection of the initial script redirect, Sophos products block the rest of the components involved in the driveby download chain as follows:

blacklisting of the TDS serversblacklisting of the exploit sitesdetection of the landing page and PDF, Java and Flash components used by Blackhole

The final word on this should probably some advice for site admins whose sites have been hit by this attack. As noted in the excellent blog I linked above, it is believed that a Plesk vulnerability was used to gain access to sites. So admins should ensure they update Plesk, and change ALL associated passwords.

* This is a reference to the "Run Forrest, Run!" line from the film Forrest Gump (spelling has never been the focus of malware authors).

Follow @SophosLabs

Black hole in space image, courtesy of Shutterstock.


View the original article here

Friday, July 6, 2012

Zero-day XML Core Services vulnerability included in Blackhole exploit kit

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

A couple of weeks ago (12 June 2012) we published an advisory for a vulnerability in Microsoft XML Core Services, also known as CVE-2012-1889.

The vulnerability is a true zero-day, being exploited in the wild, with no patch yet available from Microsoft.

The main concern in such situations is the speed with which we see exploit kits updating to target new vulnerabilities.

This is hardly surprising: web drive-by download attacks are responsible for the majority of user infections nowadays, and it is exploit kits that are used to construct these attacks.

As soon as we see exploit kits targeting new vulnerabilities we can expect to see a lot more users getting infected - especially if the vulnerabilities are zero-days.

Unfortunately, as noted in the ISC Diary, only a few days after the initial advisory was posted, a metasploit module was created and published.

Expectations were duly set for rapid uptake by the popular exploit kits.

Sure enough, within a week, CVE-2012-1889 exploiting code very similar to that published to Metasploit was seen within the landing page of a Blackhole exploit kit site.

(Thanks and hat-tip to the eagle-eyed researcher who first spotted this - ChrisW, who works at a UK University.)

The code is bundled alongside the various other exploits that Blackhole currently targets. The landing page itself is obfuscated in the usual manner we expect for Blackhole, using the latest anti-emulation tricks in an attempt to thwart detection. (Sophos products detect and block this as Mal/ExpJS-N.)

When the code is deobfuscated, the usual functions used to target the vulnerabilities we associate with Blackhole are evident. However, within this particular page was a new function (spl7), that targeted CVE-2012-1889. The function used well-described heapspray techniques to deliver the shellcode, prior to exploiting the vulnerability in order that execution passes to that shellcode.

The shellcode is pretty straightforward, attempting to download the payload (a dll) from a remote server, writing it to the temp folder.

So, let's take a quick review of the timeline of these events:

30 May 2012: Vulnerability reported to Microsoft12 June 2012: Microsoft publishes advisory12 June 2012: Sophos publishes advisory14 June 2012: Sophos publishes Exp/20121889-A16 June 2012: Metasploit module published18 June 2012: Sophos raises threat level to critical21 June 2012: Updated Blackhole exploit kit spotted27 June 2012: Sophos lowers threat level to high

Curiously enough, at the time of writing, I have not seen other Blackhole sites targeting the vulnerability.

To be honest, after seeing that first site, I was expecting a significant proportion, if not all, of the Blackhole sites to be using it within a few days.

We can only speculate as to why this new exploit isn't widespread. Is the exploit code unreliable? Is it being reserved for specific, new (expensive!) variants of the kit?

For now, it is a case of watch this space...

Follow @SophosLabs

View the original article here

Thursday, April 5, 2012

Technical paper: Learn about the Blackhole exploit kit

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Blackhole, courtesy of ShutterstockThe Blackhole exploit kit first reared its head in late 2010. Since then it's grown to be one of the most notorious exploit kits ever seen.

In this technical paper, "Exploring the Blackhole Exploit Kit", SophosLabs' Fraser Howard lifts the lid on Blackhole.

He describes in detail how it works and the various files used to exploit machines and infect them with malware.

Fraser discusses how the kit has become so successful by uncovering and explaining the tricks used by Blackhole.

From how a user's web traffic is controlled to how the attackers attempt to evade detection, the paper offers a great insight into how Blackhole works.

Blackhole image, courtesy of Shutterstock


View the original article here