Feed View | F-Secure Antivirus Research Weblog

F-Secure Antivirus Research Weblog

Weblog of F-Secure Antivirus Research Team

Subscribe | Retrun to feeds | Users subscribed: 0 | Last Updated: Sep 07 2008, 15:21:02

Black Hat and DEF CON

07 Sep 2008 14:21:02
Greetings from Las Vegas, it's again that time of the year.

black hat 2008

Black Hat 2008 is in full swing and DEF CON will start tomorrow.

On the first day of Black Hat the most popular presentation was, as could be expected, Dan Kaminsky's DNS talk. The room was totally packed while Dan went through in detail what exactly was the story behind the biggest vulnerability announcment of the year.

People attending Dan Kaminsky

Dan actually spent most of his talk coming up with creative ways on how to exploit this DNS problem and combine it with other vulnerabilities - quite creative. Bottom line; if DNS doesn't work, pretty much nothing will work.

We have a presentation of our own coming on Sunday at noon in DEF CON, when Teo and Hirosh from our labs will talk about how to fight new types of phishing.

def con

Signing off,
Mikko

On 07/08/08 At 04:15 PM


SQL Injection Attacks Targeting Chinese-oriented Sites

07 Sep 2008 14:21:02
With all the attention on China these days, especially in conjunction with the Beijing 2008 Olympics Games, and with ‘China’ being one of the more popular search engine keywords at the moment, it makes sense for malware writers to focus their attention on the Chinese web – and we’ve been seeing some interesting examples of SQL injection attacks specifically targeting website designed for a Chinese audience, whether from the mainland or overseas.

Like most SQL injection attacks, these attacks begin with a compromising script being injected into a legitimate site, compromising it and redirecting its users to a malicious website. This website then takes advantage of the vulnerabilities available on the user’s computer to download and execute malicious programs.

obfuscatedscript

In one of the samples we received, a close look at the obfuscated URL showed that users of the compromised website were being redirected to ‘hxxp://vc??.cn’. Though this malicious website was first reported in April 2008, it is still live and infectious today. Additional mirror sites include pdh0??.cn, iihao??.cn, qqhao??.cn, yyhao??.cn, zzhao??.cn and more, but they all redirect users to two sites hosting the most invasive programs: jzm0??.cn and hby0??.cn.

The ‘vc??.cn’ website basically functions like a transit station, deciding which website the user gets shunted to next, depending on what browser they are using. Whichever route they take, they are finally infected with a password stealer trojan, which we detect as Trojan-GameThief.Win32.OnLineGames.snsq.

infected_results

The interesting thing about this particular SQL injection attack is that a number of vulnerabilities the malware writers exploit are most likely to be used by Chinese websites, and by extension are targeted specifically towards Chinese (or Chinese-language literate) visitors. For example, the Baidu Soba Remote Code Execute Vulnerability is more or less exclusive to the Chinese web, as is the Sina DLoader Class ActiveX Control 'DonwloadAndInstall' Method Arbitrary File Download Vulnerability.

That's not to say that non-Chinese visitors won't be affected by this attack, as a specially crafted Flash file exploiting Adobe Flash Player Integer overflow (CVE-2007-0071) is also served. When the webpage is loaded, it forcefully floods the user’s computer memory beyond its capacity, then takes advantage of the computer’s attempts to correct the problem to execute its own hidden code. If the user hasn’t updated their Flash Player to newer versions than those targeted, their computer is vulnerable.

For such users then, the best advice would be to run the F-Secure Health Check to determine if your computer has all the latest updates and most importantly, don't click on any suspicious links related to the Olympics!


Response Team post by — Lordian & Alia

On 08/08/08 At 07:17 AM


About the Java vulnerability on S40 phones

07 Sep 2008 14:21:02
s40 phone There's been some media coverage on a recent vulnerability announcment. This is related to Java vulnerabilities affecting at least the Nokia S40 phone platform, and possibly other phone platforms based on a similar Java reference platform.

The vulnerability details have not been released, but if it works as advertised, this vulnerability could affect more than a hundred million mobile phones. This vulnerability is reported to enable attacker to be able to execute arbitrary code on target phones.

The S40 platform has never been targeted by a mobile phone virus or other malware. We're not expecting to see real-world attacks using this vulnerability in the near future either.

We're monitoring the situation.

On 12/08/08 At 12:09 PM


Teh skool

07 Sep 2008 14:21:02
lukkari Summer is almost over and schools are restarting for our student readers.

Download a *free* school schedule and other mad props from our ABC pages. There's also a cool virus-themed game.

Take a deep breath. Next summer is coming soon.

 

On 12/08/08 At 01:47 PM


MSNBC / CNN malware run

07 Sep 2008 14:21:02
For some days we've been spam runs with titles like 'CNN Alerts: My Custom Alert' or 'CNN Alerts: Breaking news'. These are fake news articles that point to a fake news page that will try to download malware to your machine.

Apparently people stopped clicking on fake CNN links as today the attackers switched the mails to look like they are now coming from MSNBC.

Some examples:

msnbc

Example email:

  • From: MSNBC Breaking News
    Subject: msnbc.com - BREAKING NEWS: Elvis Presley daughter gives birth to twins
    Precedence: list

    msnbc.com: BREAKING NEWS: Elvis Presley daughter gives birth to twins
    Find out more at http://breakingnews.msnbc.com
    ======================================================
    See the top news of the day at MSNBC.com, and the latest from Today Show and NBC Nightly News.
    =========================================
    This e-mail is never sent unsolicited. You have received this MSNBC Breaking News Newsletter
    newsletter because you subscribed to it or, someone forwarded it to you.
    To remove yourself from the list (or to add yourself to the list if this
    message was forwarded to you) simply go to
    http://www.msnbc.msn.com/id/11611202, select unsubscribe, enter the
    email address receiving this message, and click the Go button.
    Microsoft Corporation - One Microsoft Way - Redmond, WA 98052
    MSN PRIVACY STATEMENT
    http://privacy.msn.com (http://privacy.msn.com/)


And the links point to a web page looking like this (notice the sudden change from MSNBC to CNN):

cnn

The site tries to prompt you to download ADOBE_FLASH.EXE, which we detect as Trojan-Downloader.Win32.Exchanger.mn.

On 13/08/08 At 03:03 PM


Drops, Dumps, CVVS, WMZ, WU, et cetera...

07 Sep 2008 14:21:02
Underground forums are always full of chatter around various activities related to online crime.

You keep reading about things like dumps (stolen credit card information), carding (using those cards), WU (Western Union), WMZ (Webmoney), CVVs (card verification value) and drops.

So what's a drop?

A drop is a remailing location. Many online shops refuse to send expensive items (think laptops, video cameras and so on) to faraway countries. So criminals use stolen credit cards to purchase items and have them mailed to a local drop, where someone else picks up the gear and forwards it to the final destination. Alternatively the dropkeeper will simply sell the goods in online auctions and then credits the carder with part of the profits.

Here's an example from an underground forum where an individual is advertising his website, providing such services. He offers 25% of the profits of the carder items to the carder — keeping 75% to himself.

Drops

And here's his website. Nice one.

Drops

On 18/08/08 At 11:41 AM


An Unexpected Demonstration of Mobile Security

07 Sep 2008 14:21:02
Encountering a mobile phone worm 'in the wild' has never been a common event. But even less common must be encountering one in the wild while you're giving a presentation on mobile phone security.

Erkki Mustonen (Eki) is a Technical Service Manager here at F-Secure. He's very knowledgeable and frequently handles requests for comment from Finnish journalists regarding AV technologies.

Earlier this week Eki was visiting a customer's premises and was giving a presentation to approximately twenty people. As he was discussing the topic of mobile malware, a quite unexpected demonstration took place. Some of the phones within the room started to flicker simultaneously. Very soon it was determined that connection attempts were being made from a phone located somewhere nearby (but not in the room itself).

What was the source of the commotion? It was Commwarrior.B sending a copy of itself to open Bluetooth connections. Three years old and the worm is still kicking around.

The customer's phones were all Symbian S60 3rd Edition phones with F-Secure Mobile Security installed. So there were no infections and no problems. Commwarrior.B will not install on a S60 3rd Edition phone. Regardless, it wasn't even given the chance.

And the nearby S60 2nd Edition phone with the Commwarrior.B infection? Eki thinks that the phone's owner really should consider installing a security solution…

Here are some screenshots from Eki's Nokia E61i:

E61i

E61i

E61i

On 22/08/08 At 07:36 PM


Somebody Doesn't Like Us in Denmark

07 Sep 2008 14:21:02
This morning we saw several spam runs in the country of Denmark. The messages are in Danish and they are sent to Danish e-mail addresses.

The e-mail claims to be from us. It's not.

Here's what the e-mail looks like:

  
   From: supportupdate@f-secure.com
   Date: 26. August 2008 08:31
   Subject: Data er tillagt og sendt med denne meddelelse.
  
   Käre kunder!
  
   Regning
  
   Data er tillagt og sendt med denne meddelelse.
  
   Jeg bruger gratis F-secure antispamversion, som allerede har fjernet 338 spambreve.
  
   Antispam er helt gratis for private brugere.
  
   Attachment: f-secure.rar

  

The attachment contains a file called update26.08.2008.exe, which, when run, drops a file called dcbcg.exe (Unker related trojan) that connects to a server in Ukraine.

We detect this trojan as Trojan:W32/Agent.FVO. More information in the virus description.

The spam run must have been fairly large, as we've received more than 13,000 bounces to supportupdate@f-secure.com from non-existent e-mail addresses alone.

Watch out and pass the word.

Update: Agent.FVO is a downloader.

Yesterday, its C&C server was quiet so there were no additional components for download. Today, the C&C server is pushing out a BZub variant which has been detected as Trojan-Spy.Win32.Bzub.fbm since our 2008-08-25_07 database update.

BZub is a trojan-spy interested in banking details.

On 26/08/08 At 09:44 AM


Space Based Malware

07 Sep 2008 14:21:02
An online games password-stealer has reportedly made its way onto the International Space Station.

Fortunately for the space station, there's no direct Internet connection, and so therefore no online games to steal from (one hopes). The malware most likely made its way onto the infected ISS laptop via an infected USB drive.

Autorun.inf worms is another way of categorizing such malware. Worm.Win32.AutoRun.bhx is our detection name for their particular variant. Read more about it from the AutoRun.BHX description page.

BBC News has additional details.

On 27/08/08 At 02:58 PM


Western Union MTCN #2989115571

07 Sep 2008 14:21:02
Fake airplane tickets, greetings cards and credit card receipts…

There's plenty of ZIPped trojans being spammed around. The one that's being seeded right now claims to be a bounced Western Union money transfer.

Attention! The wire sent to Maksim Zverev, Moscow, Russia has been blocked by our security service. Your credit card issuing bank has halted the transaction by the demand of the Federal Criminal Investigation Service (case No. 44571 since the recipient has been undergoing the international retrieval by the InterPol. Please contact the closest Western Union office and make sure you have your ID card, the credit card that was used for making the payment, and the invoice file with you.

And the malware inside the ZIP is a ZBot banking trojan variant.

Attention! The wire sent to Maksim Zverev, Moscow, Russia has been blocked by our security service. Your credit card issuing bank has halted the transaction by the demand of the Federal Criminal Investigation Service (case No. 44571 since the recipient has been undergoing the international retrieval by the InterPol. Please contact the closest Western Union office and make sure you have your ID card, the credit card that was used for making the payment, and the invoice file with you.

On 28/08/08 At 11:10 AM


Video - E:VOLUTION

07 Sep 2008 14:21:02
The Lab's YouTube channel has been updated:

E:VOLUTION
www.youtube.com/fslabs E:volution

This 'white' video is a sequel to last year's 'black'.

RE:SOLUTION
www.f-secure.com/fslabs Re:solution

Enjoy.

On 01/09/08 At 10:26 AM


Google Chrome and Security

07 Sep 2008 14:21:02
So Google's Chrome web browser has been released.

For a change it's nice to see a browser that does not eat all of your memory.

Chrome is going to become popular. That means it will also become an interesting target for malware authors.

Google knows this.

Snippet from the Chrome Cartoon by the great Scott McCloud

Chrome features sandboxing of each tab, built-in web reputation service, special privacy mode and so on.

For example, here's what it looks like when you try access a known malicious site with Chrome:

ssl2.su phishing site

However, one security vulnerability has already been found, based on the WebKit engine used inside Chrome.

There will be more issues, especially related to plugins.

We expect Chrome to quickly gather a sizable market share, mostly from existing Firefox users.

On 03/09/08 At 06:54 AM


It's Time for 2009

07 Sep 2008 14:21:02
Today is the official launch day for our 2009 consumer lineup. Lots of work has gone into the launch, and plenty more has gone into the development. We'll have some details on the technology for you later.

In meantime, check out our Online Wellbeing campaign.

F-Secure Anti-Virus 2009

On 03/09/08 At 03:51 PM


abuse@human-rights.org

07 Sep 2008 14:21:02
Digital security is something that human rights activists are concerned about, and they should be

Here in the lab, we see many examples of targeted malware attacks focused on human rights organizations. Here's one example from September 3rd that ironically uses 'digital security training' as the hook.

The spoofed message is very well done; the content uses real names, organizations, e-mail addresses, phone numbers, et cetera.

It looks very legitimate at first glance.

Targeted Message

The message was sent to a human rights activist based in USA. There was a Word document attached.

It too uses real names, locations, and so on.

Training Application Form

Fortunately, the recipient of this message was knowledgeable enough to avoid opening the attachment. Instead of opening it, he forwarded it to the lab for analysis.

Yep. It was a trap. The Word document had an exploit.

The only thing about this case that seems to indicate 'hackers' rather than 'spies' is the document's author.

Training Application Form Properties

…perhaps the spies are paying the hackers?

Front Line Defenders, mentioned in the e-mail message actually has some very good security advice on their site.

They should perhaps add one more topic — targeted malware attacks.

You can read more on the topic from Wired.com.

P.S. Front Line's Software Installation guide suggests uninstalling ALL unused Windows applications. Great idea.

Human Rights Organizations really concerned with digital security might also consider going one step further by giving something such as Ubuntu a try. It's free, has all of the needed applications, and none of the current exploits being used against activists.

On 05/09/08 At 08:26 PM




Subscribe | Retrun to feeds | Users subscribed: 0 | Last Updated: Sep 07 2008, 15:21:02To top



 



Sign in to NewsAlloy
E-mail 
Password 
  Remember me 



News Alloy © Copyright 2005 - 2008 Mobispine AB. All Rights Reserved.