Počet zobrazení stránky

Zobrazují se příspěvky se štítkemSpam Blog. Zobrazit všechny příspěvky
Zobrazují se příspěvky se štítkemSpam Blog. Zobrazit všechny příspěvky

čtvrtek 26. dubna 2012

New Spam campaign on Twitter Leads to Rogue AV


Early today, Kaspersky Lab discovered a new ongoing spam campaign on Twitter. hundreds of compromised accounts are currently spamming malicious links, hosted on .TK and .tw1.su domains, leading to Rogue Anti Virus softwares.
Here is an analysis of the infection at a given time. Keep in mind that it is just a snapshot of the infection, and that the numbers are actually lower than reality.
The compromised accounts spammed up to 8 messages per second, with links redirecting users to the infamous BlackHole exploit kit.

Upon following such a link, users received an alert about malicious activities on their computer and the need to do a fast scan of their system files

Here is the above mentioned fast system scan:

At the end of the "scan", they are invited to install a fake Anti Malware solutions. During our tests, several variants were pushed to the infected machines, which were the same threat using different names. Here is one of them:


Campaign Monitoring


Kaspersky Lab is still monitoring the campaign and here are a few statistics we would like to share.
We started monitoring the campaign for a little less than two hours where a total number of 453 compromised Twitter account where being used to spam malicious links. The campaign was divided in two. Links to .TK domains and links to .tw1.su.

The .TK TLD

153 unique users were actively sending links to .TK domains, with a count of 20 unique domains used. We recorded 656 messages sent.

The .TW1.SU TLD

300 unique users were actively sending links to .tw1.su domains, with a count of 21 unique domains used. We recorded 758 messages sent.
At this point, the domains weren't resolving anymore and the spamming slowed down until it stopped. The top domains was used in 95 Tweets.

Campaign Monitoring: Part 2

The campaign quickly restarted with only 3 unique .TK domains this time in a much more agressive way and is still ongoing.

The top domain from the first part of the campaign was present in 95 tweets only. Here is the number of Tweets we recorded for the new ones:

WI[redacted]K.TK       884
VI[redacted]DA.TK      890
RE[redacted]LOS.TK     929 
This time, we recorded a number of 317 unique users actively spamming the new domains. 87 users were new and not used in the first part of the campaign.(230 overlapping from the first part of the campaign).

Conclusion

Our analysis is just a snapshot at a given time, and is lower than reality. The campaign is still ongoingas we publish our analysis. From our small monitoring, we can say that:
The total number of unique Twitter account that were recorded is: 540
The total number of unique domains used: 44
The total number of recorded Tweets is: 4148
The malicious samples we gathered were already detected by Kaspersky Lab and our customers were protected since the start of the campaign. Threats detected as: Trojan-FakeAV.Win32.Agent.dqs andTrojan-FakeAV.Win32.Romeo.dv
Many thanks to my colleague Vicente Diaz for helping monitoring the Malicious Campaign.

středa 4. dubna 2012

Another airline scam! This time from US Airways


Be careful with the links showed in this diary because they might still be live and could infect your computer if not handled properly
More and more scams are seen each day. I discussed in a previous diary a phishing attack sent to users so attackers can own their computers. I will show you today another attack using the same technique and the same malicious code.
I received today the following message:
US Airways SCAM
The online reservation details link pointed to the linkhttp://somostigreros.com.ve/s3JgEpEu/index.html. The document has a javacript pointing to four different URL:
Javascript from infected page
The javascript downloaded is the same in all the four cases and points to another link:
Link to malicious code
We arrive to an obfuscated javascript. Let's see a snip of it:
Obfuscated Javascript
After decoding the script, I got the same javascript analyzed in my previous diary, which performs the following:
  • Identification of the navigator being run.
  • Identification of Adobe Flash and Adobe Reader version.
  • Shellcode execution to download malware but this time it is downloaded from http://207.210.101.44/q.php?f=4203d&e=1.
  • Malware is the same DLL discussed in my previous diary, but at this time virustotal shows 30/42 detection ratio. Mcafee detects it as Generic.bfr!em, Symantec detects it as Suspicious.Cloud and TrendMicro detects it as TROJ_SPNR.11C912.
Additional to the measures previously discussed to mitigated this kind of threats, You can be a propagation vector for malware like the one being shown if you publish to the internet vulnerable servers. Many attackers no longer want to shutdown your server but to publish malware in not-visible locations inside your webserver or web application. Please keep in mind the following:
  • Install all available patches  to your operating system and base software. If you cannot do this because your application will stop working, you definitely need to put in place additional controls like Host Intrusion Prevention System (HIDS) and Network Intrusion Prevention System (NIPS) .
  • Test your web applications for vulnerabilities before publishing them on the Internet. If you don't do this, the attackers will be happy to do it for you.
  • If you are unsure if your web server or web application have vulnerabilities, use a Web Application Firewall (WAF). I have found useful ModSecurity to place that kind of protection.
Have you received this kind of threat inside your network? Let us know using our contact form.
Manuel Humberto Santander Peláez
SANS Internet Storm Center - Handler
Twitter: @manuelsantander
Web:http://manuel.santander.name
e-mail:msantand at isc dot sans dot org

středa 14. března 2012

Dropbox Abused by Spammers


Recently we noticed spammers abusing Dropbox, a popular cloud-based, file-hosting and synchronization tool, to spread spam.
Dropbox accounts have a public folder where files can be placed and made publicly available. This function is useful to spammers, as it effectively turns Dropbox into a free hosting site. Spammers have abused URL shortening and free hosting sites for some time. Dropbox also provides a URL shortening service, which spammers have also abused.
Spammers have created several Dropbox accounts, uploading an image and a simple .html file and then using the image to link to a pharmaceutical site.
Following this link takes you to a fairly standard "Canadian Health & Care Mall" site:
We saw over 1,200 unique Dropbox URLs being used in spam over a 48-hour period. We have informed Dropbox, providing them with the full list of URLs.
Since Dropbox is a widely-used service (with smartphone applications) people might view Dropbox URLs as more trustworthy, and therefore more likely to open them.
In fact, Dropbox is being abused by malware authors, as well as spammers. We recently saw a Brazilian Portuguese malware message claiming to contain photos and asking if they can be put onto a popular social networking site. The links in the email point to a Trojan hosted on Dropbox. The link text is crafted to look like image file names similar to what many digital cameras would use:
This abuse is a good reminder that any site which makes user-supplied content publicly available must continue to be vigilant about dealing with abuse. Although Dropbox is a high-profile site, spammers target all sorts of sites, big and small. There are many things that sites do to deal with such abuse, but in some cases this crucial work is often seen as low priority, despite the damage that such abuse can cause. Dropbox however assured us "they care about their user's security and experience above all else."
Symantec.cloud customers are protected from these threats based on advanced link-handling technology.

Webmail Security and Associated Best Practices


Webmail is popular for its many advantages over regular desktop email. One of its salient benefits is ubiquitous availability, which is a double-edged sword. The price paid for universal access is a greatly increased attack surface area. Below we will identify existing threats, the implications of being targeted, and best practices to effectively mitigate threats associated with the use of webmail.
Business employees often require access to work resources from outside of the office. As a result, web-based email has become one of the most widely used corporate communications resources. Email is the communication backbone that supports the smooth and successful operation of any company. Therefore, because of its high value and sensitive nature, email resources are often targeted by malicious attackers. Compromised email infrastructure can result in several problems, such as:
  • Intellectual property loss: This includes stolen company secrets, customer and partner information, internal memos, etc. These can be used for blackmail, or can even be sold on the internet to the highest bidder.
  • Email contact loss: Stolen address books can cause lost business opportunities while company contacts may be exposed to future spam and malware attacks.
  • Also, depending on local legislation, data breaches might have to be publicly disclosed and companies can be given significant fines.
Attackers have a multitude of options available at their disposal. Some malicious individuals may run a simple Web search to obtain your webmail URL. Once they have this information, they can employ bots (automated programs) to guess a correct username and password. The most common attack we see is targeted phishing emails spoofing the company’s IT helpdesk. These messages employ various social engineering tactics to trick users into giving up their password. Once the attackers have the passwords, they can login to the relevant webmail server and perform additional malicious activities.
Below are two samples of targeted phishing emails. In the first sample, the attacker directs the victim to a URL where they can capture the victim’s username and password. In this example they are using Google Docs, which is being used to host a simple form into which the attacker hopes the victim will input their details. The second sample is a simpler phishing email where the attacker just asks the victim to fill out details and reply with their username and password to a webmail account.
Effective security policies should be implemented to prevent phishing attempts and the following approaches can help mitigate these threats. When used together, you can appear less enticing to attackers and avoid becoming a victim.
Policy solutions
  • Implement a two-factor authentication process with a hardware or software token. This will require a user to provide a second set of authentication credentials (in addition to username and password) to log into webmail.
  • Consider allowing only specific users access to webmail. This will reduce the attack surface area, which in turn reduces the probability of being targeted. In many companies, not all employees truly need webmail access outside of office hours.
  • Hide your webmail URL from search engine crawlers by setting up a robots.txt in the root of your webmail server.
  • Avoid generic or easily guessable webmail URLs (such as webmail.domain.com or mail.domain.com).
  • Enforce an effective password policy (such as requiring complex passwords) and force regular password changes.
  • Limit the total number of messages per user. This can be based on a per-day or per-hour limit.
User education
  • Ask your IT department to publish monthly advisories and hold regular brief meetings and training modules regarding security best practices.
  • Login pages can have friendly security reminders which change depending on the season. For example, during holidays or festive seasons be aware of suspicious themed attachments.
  • Educate users on how to recognize phishing attempts. For example, showing users a sample email would help them better recognize phishing attempts.
  • Discourage use of webmail on public or shared computers which might have key loggers or other malware installed.
Pro-active measures
  • Ensure server and webmail software are patched with the latest updates to prevent vulnerabilities from being exploited.
  • Frequently monitor authentication and access logs for suspicious events, such as sudden spikes in user activity. Administrators can be alerted to disable compromised accounts.
Of all of the above approaches, our experience has shown that the most effective way to mitigate becoming a target is to implement a two-factor authentication process. If an attacker cannot gain access to your webmail server because you utilize such technology, they will simply move on to the next target which doesn’t.

Survey Scammers Moving to Pinterest


Survey scammers like to place enticing links in places such as forums, article comments, and social networks. These enticing links lead to surveys that promise items such as gift cards or free electronics, as long as you fill out multiple marketing surveys. Rarely is someone able to complete an entire set of surveys and the promise of a free item is rarely fulfilled, as we’ve discussed in the past with survey scammers spamming social networks.
A new social networking website called Pinterest garnered attention from the media after buzz at an interactive entertainment conference this month. Pinterest allows users to create virtual corkboards, pin content from other external Web pages onto these boards, and then share their boards with others. The new-found attention has not only brought new users, but scammers as well. Recent news articles have discussed how scammers are posting enticing images and links to supposed free offers onto Pinterest boards.
 
Figure 1. Example scam pins on Pinterest pointing to supposed free gift cards
 
If an unsuspecting Pinterest user clicks on the link for one of the scam images, he or she is taken to an external website. The website states that in order to take advantage of the offer, they must re-pin the offer onto their own Pinterest board. This helps propagate the scam, as it now gains further credibility by being posted by a trusted source. Some of the trusted source’s followers subsequently fall for the same scam, then their followers as well, and so on.
 
Figure 2. A user is asked to pin something to his or her board
 
After re-pinning the scam, the user is asked to click the second link on the landing page. This link redirects the user to a survey scam page.
 
Figure 3. The user is redirected to a scam survey or offer page
 
Most scam pages ask the user to fill in surveys, sign-up for subscription services, reveal personal information, or even install unwanted executables. These types of scams are already popular on other social networking websites and Pinterest is only the latest site scammers are leveraging for their attacks.
Some of the Pinterest scams we analyzed led to a cost-per-action (CPA) based network.. For each successful conversion the scammer is expected to make between one and 64 US dollars. We speculate that a scammer might be earning a few hundred dollars each day from these scams.
We are able to determine that, while this is new to Pinterest, the scammers are not new to this game and are behind similar, previously successful scams on other social networks. Furthermore, they are not expert Web programmers, as they required multiple iterations to get their code to work.
For example, the scammers wanted to enforce a check that ensured that the user re-pinned the scam before sending them to the free offer surveys. However, in the first iteration of the scam, the code does not redirect the user to any external scam survey site. If someone clicked the survey link, it would just prompt the user to remind them to re-pin the content.
 
Figure 4. The first iteration of the scam
 
In the second iteration we can see that the scammer has added a link to a scam survey site; however, there is no check to ensure that the user has finished the first step of re-pinning the content.
 
Figure 5. The second iteration of the scam
 
Soon after, we discovered a post on a popular programming forum asking the programming community for help implementing this check.
 
Figure 6. A post on a programming forum asking for help
 
In fact the same code was used in the third iteration of the scam, as shown below.
 
Figure 7. The third iteration of the scam
 
The final iteration has some additional changes, including code to dynamically choose the landing page, the marketing message, and the image to be used in the Pinterest pin.
 
Figure 8. The scammers use randomly selected marketing messages, image, and landing pages
 
In light of these scams on popular social networking websites, we encourage users to avoid offers that appear too good to be true and not re-pin such content. We also encourage them to review their Pinterest boards and remove pins related to such scam surveys. In addition, Symantec SafeWeb and IPS technologies, available in Symantec antivirus products, will block users from seeing such scam surveys.