This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Targeted attacks escape detection

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.usatoday.com/tech/news/computer…r-attacks_N.htm
March 18, 2008 - "…Targeted attacks often escape detection. But click on the wrong thing, and "You could be opening up a door that allows the hacker to do some really bad damage," says Alan Paller, research director at The SANS Institute, a tech security think tank. One indicator this trend is on the rise: Microsoft last week issued security patches for a dozen critical vulnerabilities in its Office suite of programs. Since 2006, more than 260 security holes have been discovered in widely used programs from Microsoft, Adobe, Apple and RealNetworks, according to security firm Secunia. Prior to 2006, there were only a handful. The driver: powerful "fuzzing" tools that continuously try endless strings of computer code, searching for an open path to the computer hard drive. "The bad guys are trying billions of random combinations … and finding new ways to break in," says Gartner tech security analyst John Pescatore. Crooks use flaws uncovered by fuzzing to create tainted files disguised to fool targeted employees. Earlier this year, individuals at several corporations were targeted to receive e-mail carrying an attached Excel file corrupted via a previously unknown flaw. Clicking on the file opened a worksheet with data relevant to the targeted worker; it also gave the attacker a beachhead to probe deeper into the company's network. "The victims never really knew," says VeriSign iDefense researcher Matt Richard, who discovered the attack… "It's not just Microsoft," says Secunia Chief Technical Officer Thomas Kristensen. "Crooks now use many different ways to gain control of computers." Some crime groups target patrons of large organizations, hoping one corrupted computer can take them deeper into rich databases. Last year, three crime rings launched 40 such campaigns targeting, among others, Salesforce.com, the IRS, the Federal Trade Commission and the Better Business Bureau, according to VeriSign iDefense. In one case, crooks using the stolen user name and password of a job recruiter logged onto Monster.com and downloaded résumés for 1.3 million job candidates. Next, the thieves sent out faked Monster.com e-mails enticing the job seekers to click on a free job notification tool that carried a data-stealing program… Computer users should accept all updates from software providers to ensure they have the latest secure version…"

:ph34r:
FYI…

- http://sunbeltblog.blogspot.com/2008/04/20…ted-attack.html
April 18, 2008 - "…There’s an overview of part of the problem in this week’s BusinessWeek*, and some other commentary from our friends at F-Secure**…"

The New E-spionage Threat
* http://www.businessweek.com/magazine/conte…80032218430.htm
April 10, 2008

Espionage Trojans:
** http://www.f-secure.com/weblog/archives/00001424.html
"On Monday SANS Internet Storm Center wrote*** about a targeted attack against CEOs. The e-mail messages were directly sent to senior corporate executives and properly identified them by name. The message claimed their testimony was required in a corporate lawsuit. If they clicked through on the link to read the supposed subpoena they were then asked to install a file. And if they ran the file? Then they were really installing a trojan-spy designed to steal certificates. Here's the description of what we detect as Trojan-Spy:W32/Small.BSL****… We've been watching the evolution of targeted attacks for about two years now. Hopefully this recent press coverage helps to shed some light on a very serious issue. One of our recent posts linked to the Businessweek article "The New E-spionage Threat"*. If you haven't read it yet, take the time to do so this weekend…"

*** http://isc.sans.org/diary.html?storyid=4289
"…UPDATE 4/17 We can share the two checkin/drop sites 124.217.251.118 and 124.94.101.48.
We suggest you watch out for port 80 traffic towards those systems or to block those IP addresses entirely…"

Trojan-Spy:W32/Small.BSL
**** http://www.f-secure.com/v-descs/trojan-spy…small_bsl.shtml

:ph34r: :ph34r:
FYI…

Targeted attacks using malicious PDF files
- http://isc.sans.org/diary.html?storyid=4330
Last Updated: 2008-04-24 18:22:15 UTC - "Dating back to the end of February, we have been tracking test runs of malicious PDF messages to very specific targets. These PDF files exploit the recent vulnerability CVE-2008-0655*. Ever since the end of March, beginning of April, the amount of samples seen in the wild has significantly increased. Interestingly enough, there is almost no "public, widespread" exploitation. All reports are limited to very specific, targeted attacks. However, due to the wide scope of these attacks, and the number of targets we know of, we feel a diary entry was in order. At this point in time, we are receiving more PDF samples from targeted attack victims per day than any other common file type (DOC, CHM, PPT). The threat agents, or attackers, are the same. They are just moving from other file types towards PDF, but are generally using the same control servers and similar backdoor families.
The files contain:
- an embedded trojan installer;
- a clean PDF file.
Once the file is opened in a vulnerable Acrobat Reader version, the backdoor will install, and the clean PDF file is opened in the user's browser. From a user experience, there are two possible methods of detection:
- If the file is opened in a patched Acrobat Reader, an error will be displayed that the file is corrupted;
- If the file is opened in a vulnerable Acrobat Reader, the user will see Acrobat Reader close and immediately reopen the valid PDF document.
Anti virus detection of these samples is usually very low heuristically. The below are detection results from a malicious PDF which had not been reported to an AV vendor yet. Note that these results vary per file. We're not listing MD5 hashes or file names due to the sheer number of samples we've seen so far… Acrobat Reader is proving to be an interesting target because users are not very much inclined to upgrade manually. The file format is relatively stable and users of Acrobat Reader 7 may not always feel a need to upgrade.
As such, we strongly recommend that you:
- Ensure your Acrobat Reader installations have been upgraded to version 8.1.2;
- Disable Javascript parsing through Edit>Preferences>Javascript, by disabling the 'Enable Acrobat JavaScript' option…"

* http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0655

:ph34r:
FYI…

- http://www.f-secure.com/weblog/archives/00001431.html
May 5, 2008 - "We're seeing some new BBB trojan attacks going around. This attack method is well-known and has been occurring for months: A high-level executive inside an organization receives an e-mail that mentions a complaint supposedly made to the Better Business Bureau (USA). The e-mail appears to be credible and links to a site in order to download the complaint. The download claims to require IE and ActiveX in order to succeed. Once ActiveX is enabled, the sites drops a backdoor on the system… The site was running over the weekend, was down today on Monday and then just reappeared — with a modified version of the malware. If the recipient enables ActiveX, the site sends the system a CAB file which gets automatically installed as Acrobat.exe… Nasty stuff…"

(Screenshot available at the URL above.)

:ph34r:
FYI…

DHS PDF
- http://www.f-secure.com/weblog/archives/00001449.html
June 1, 2008 - "…The only information we have on this 130kB sample is that it was named f1be1cdea0bcc5a1574a10771cd4e8e8.pdf (after it's MD5 hash) and that it was submitted on the 23rd of May. 'Looks like a Department of Homeland Security form G-325A.
Look again. What's the filename? It's -not- f1be1cdea0bcc5a1574a10771cd4e8e8.pdf. It's 0521.pdf. This is -not- the document we opened. So what happens here? Apparently this PDF has been used in a targeted attack against an unknown target. When this PDF is opened in Acrobat Reader, it uses a known exploit to to drop files. Specifically, it creates two files in the TEMP folder: D50E.tmp.exe and 0521.pdf. Then it executes the EXE and launches the clean 0521.pdf file to Adobe Reader in order to fool the user that everything is all right. D50E.tmp.exe is a backdoor that creates lots of new files with innocent-sounding filenames, including:
\windows\system32\avifil16.dll
\windows\system32\avifil64.dll
\windows\system32\drivers\pcictrl.sys
\windows\system32\drivers\Nullbak.dat
\windows\system32\drivers\Beepbak.dat
The SYS component is a -rootkit- that tries to hide all this activity on the infected machine. The backdoor tries to connect to port 80 of a host called nbsstt .3322 .org. Anybody operating this machine would have full access to the infected machine. Well, 3322 .org is one of the well-known Chinese DNS-bouncers that we see a lot in targeted attacks. Does nbsstt mean something? Beats me, but Google will find a user with this nickname posting to several Chinese military-related web forums, such as bbs .cjdby .net. Where does nbsstt .3322 .org point to? IP address [removed] is in Zhejiang, China. And it's live right now, answering requests at port 80."

(Screenshots available at the URL above.)

:ph34r: