Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Thursday, July 29, 2010

Adobe CS7 Searches Saturated With Dangerous Results

Looking to save a few bucks on software will almost always lead users down a dangerous path.  Users either end up at “OEM Software” sites offering unlicensed and illegal software, or to downloading cracks or keygens laced with malware. 

One of the big issues here is that these sites are quite easy to find. Google searches for “cheap” or “discount” software reveal it’s very easy to come across these sites.  Searches for all kinds of popular software from MS Office, to Adobe CS will bring up dangerous results.

Even searches like ‘Microsoft Windows 7’ which should be filled with Microsoft related sites and articles instead include fraudulent OEM sites in the top results.  Today, the eSoft Threat Prevention Team is warning users to be especially wary of unreleased software.  A major target of these scams is Adobe, who recently released their Creative Suite 5 (CS5) software.  However, searches for CS7, a product not yet announced and two versions premature, result in a solid wall of bogus search results leading to scams and malware.





Aside from poisoning search results, the criminal enterprises behind these scams are increasingly using Spam to increase their reach.  The criminal rings associated with these sites also control infected machines capable of sending millions of Spam messages per day, making it very easy to draw users to these sites.  Spam messages are sent offering “instant” downloads and huge savings, only leading the user to a full blown fraud operation.




Rightly suspicious users who are wary of entering their personal information on these sites, or don’t want to pay for the software at all (aka stealing), may try to find cracks or keygens to allow them to activate trial versions of the software.

Take the example of the site below, keygenguru.com.  The keygen download on this page is malware that attempts to call home and download more malicious software.  The other links on this page lead the user right back to the same OEM software scams. 


Each week eSoft finds hundreds of sites and domains related to these OEM Scams.  It’s important for users to realize that these sites are fraudulent and could potentially be very dangerous.  If you are purchasing new software, make sure it is from the vendor itself or a reputable distributor.

Monday, July 19, 2010

Widespread Compromise Impacts Thousands of Legitimate Websites

The eSoft Threat Prevention Team has detected a new widespread compromise, with tens of thousands of domains infected.  Cybercriminals have used stolen credentials, placing specially crafted pages into legitimate websites that lead visitors to malicious payloads.

The cybercriminals involved in this campaign are primarily targeting pornographic search terms.  Poisoned searches involve celebrities and porn stars nude, nudism, sex parties and searches that are much more lewd and inappropriate.  Obfuscated javascript is used to redirect a visitor to Rogue Anti-Virus and other malicious payloads.

At the time of writing most infected pages lead to the rogue anti-virus scam “Antivirus Plus” as shown below.



Cybercriminals are increasingly infecting legitimate sites rather than creating their own websites.  Otherwise honest sites that have been compromised have a much longer lifetime with which to infect visitors and have a better chance of passing undetected through web filtering technologies, infecting a greater number of users.  Sites created specifically for malware distribution or malicious intentions can be shut down by the domain registrar or ISP much more quickly than a legitimate site that’s been compromised.  With granular URL classifications, eSoft SiteFilter technology is able to detect and block these sites before a user is infected.

Based on the number of different platforms and web server software that are infected in this specific attack (recognized by the recurring malicious code it uses), it’s most likely the sites were compromised using stolen FTP credentials. For webmasters out there, be sure to keep your FTP passwords secure, and don’t save them in popular FTP programs where they can easily be harvested by attackers. If possible, use SFTP and key based authentication instead of the less secure FTP protocol.  Also avoid passwords that are found in the dictionary or are common place or person names (even adding a number to the end will not protect you from a determined brute force attack).

Further details are available for security researchers interested in the specific attack and related code.  Right now, eSoft estimates that the attack affects 3,200 websites.

Tuesday, June 29, 2010

Red Button SEO Poisoning and Malware Campaign

eSoft researchers have been tracking a new campaign by cybercrooks, compromising and creating websites for use in SEO poisoning and malware distribution. Thousands of these sites have been detected which use elaborate techniques to trick search engines and are ready to serve malware in an instant.

At the forefront of this attack is the use of a website referrer, or user-agent, which enables the cybercriminals to effectively increase their search engine ranking while keeping their malicious intentions hidden. Google and other search engine bots will be served up SEO tailored content to manipulate search results and drive traffic. This content cleverly uses a mashup of text and images scraped from various sites.

Danger lurks for users that visit these pages using Google search or other search engines. In the course of monitoring, eSoft has seen these pages deliver Rogue AV, redirect to fraudulent pharmacies, fake search pages and more.


At the time of writing, most of the sites involved in the campaign are currently hosting a Red Button flash file, as shown below.  This file indicates a compromise, but clicking the red button currently does nothing malicious, but these pages serve as a placeholder for the attackers.  These pages change their character depending on how they are referenced and at any time these pages could be infect the user with malware.



The Threat Prevention Team is keeping a close watch on these sites as they continue to multiply.  There is a strong chance that these sites are currently establishing good reputations with security companies that will make future attacks through these sites more effective.  eSoft is classifying these sites as Compromised to protect SiteFilter users from any future malicious payloads.

Wednesday, June 23, 2010

Introduction to Rogue Anti-Virus

If you follow the Threat Center Blog, you’ve heard us talk about “Rogue AV,” but may not fully understand what we’re referencing.  This post is for those users who are not already familiar with this widespread and common threat.

In short, when we and other security researchers reference Rogue AV, we’re referring to an Internet scam where an official-looking web page pops up telling the user that a virus has been detected on their computer.  The web page often appears to be scanning the local computer and often reports multiple found infections.  The web page, the report, and everything about this scam is a fraud.

Millions of users have been duped into installing malicious software, also known as malware onto their systems allowing cybercriminals to steal money and other personal details. Here’s how the attack works:

Step One: Get the user to the malicious website

First, the group or groups behind these attacks first post large numbers of links to some new domain by spamming community forums, blog comments, and by putting the links inside hidden elements on compromised websites in a technique known as Blackhat SEO (Search Engine Optimization).  In this way, they are able to get the target website high up in search results for common or recently trending search terms.  Right now, for example, search results on Wimbledon and the World Cup are actively being poisoned in this manner.

The above technique is usually seen in conjunction with one or more of the following:
  • Redirects from compromised websites that are otherwise legitimate
  • Spam emails that are often sent via other compromised computers
  • Malvertisements where attackers pay for an ad in a legitimate ad network, but use the ad to send people to the malicious website.  In the past year, reputable sites like the New York Times, White Pages, Tech Crunch and others have been caught hosting such malvertizements.
Step Two: The con game

Once on the website, social engineering tricks are invoked to convince a user to fall for this modern Internet con.  Computer users are conditioned with constant reminders to keep their computer free from virus and malware by running anti-virus software and keeping their virus definitions up to date.  These websites use this conditioning against the user, using visual elements to establish authority and trust and then causing a sense of danger and urgency when notifying the user that their computer is infected with viruses and that their data personal computer is under someone else’s control. 

Rogue anti-virus malware comes in many different forms and will take different approaches to fool a user, but at the most basic level, rogue anti-virus scams convince the user that they have a problem and that they need to download some software to fix the problem.

The screenshots below are just a few examples of fake scanners. These specially crafted pages are made with great detail to look exactly like Windows XP, Vista, or Windows 7 system alerts.


Fake scans like these are very believable for uneducated users and lead to a very high success rate for cybercriminals. 

Step Three: Infection

Frequently a box pops up that asks the user if they want to download the software that will fix the purported problem.  In many cases, it doesn’t matter if the user agrees or cancels, the download will begin in either case. Once the downloaded file is opened, the system is infected and the user has been tricked into installing the very thing he or she sought to remove. 

Cybercriminals make it very difficult to click away from the page, so that in some cases, the user relents out of a sense of frustration and not knowing how else to move forward.  In many cases the malicious file is downloaded with no user interaction at all.

The actual file that is downloaded changes often with different names and characteristics.  eSoft rarely sees more than two or three legitimate anti-virus software (of over 40 checked) detecting the file as a virus at the time of the attack.  The perpetrators of this attack spit out new variations on the download at a very high rate in an attempt to stay ahead of signature-based anti-virus software.

Step Four: Asking for payment

Once a user has clicked to open the malicious file and install the software, the problem only gets worse. The cybercriminals do well in masking their malicious intentions throughout the install process. In many cases the installation is a silent install – one which requires no user interaction – or a standard install wizard which raises no red flags to the user. 


Once installed, the rogue anti-virus program will inundate the user with notifications that the system is infected and that they still need to take action. In order to remove the supposed infections (not the real problem) the user is asked to pay a license or subscription fee that typically runs between $50 and $100 USD.



Though the branding changes – these screenshots show the Rogue AV “Alpha AntiVirus” – the checkout pages remain as convincing as the rest of the scam, frequently with badges showing secure payments and other “trust me” icons.  Pricing is comparable to legitimate anti-virus products and comes with a money back guarantee to further convince the user who may be wavering that the risk to giving up their credit card and personal information is low.  In reality, submitting credit card info does not clean their system, but instead sends name, address, and credit card info directly to the perpetrators of the attack.

Users infected with this might just assume this is an annoyance, but the scam goes much deeper than this. These programs have been created by large underground crime rings that now have the users’ personal information and credit card number.  In addition, these programs are often packaged with downloader Trojans which are capable of downloading any type of malware the attacker chooses. Because many of these criminal enterprises are also heavily involved in banking malware this is just one of the many additional types of malware that can be installed.  As a result, an infected computer should have a computer professional remove the virus, which can cost small businesses thousands of dollars per year.

Prevention

Cybercriminals go a long way to making sure they can infect a machine and to get around classic signature-based virus scanning.  If a user gets a web browser window that says their computer is infected with malware, they should immediately attempt to close the window.  If that is not possible, then quitting and restarting the web browser is the next best thing.  This, of course, requires that users are trained in spotting and avoiding this attack, but in practice, training unsavvy users alone is not always fruitful.

Now more than ever, malware is distributed via the web. In fact, over 75% of new malware is delivered through the web. Classic anti-virus is struggling to address these threats effectively.  The most effective way to stop web-based threats is with Secure Web Filtering.  Secure web filtering works by detecting and blocking dangerous sites even before there is any anti-virus protection.  By blocking access to the site, the threat is mitigated. Secure web filtering must have real-time updates in order to block these fast moving websites, but with such a solution, users should be well protected from this pervasive threat.

Wednesday, May 12, 2010

Google Groups Latest Hot Spot for Rogue AV and Malware

eSoft researchers have been tracking a recent campaign abusing Google Groups to spread malicious links in Spam emails.  Users following the link are infected with a Downloader Trojan, silently infecting the machine with various types of malware including Rogue Anti-Virus.

The scam starts with an email asking the user to update their email settings according to the linked instructions.  The URL in the message brings the user to a Google Groups page linking to a malicious download.

Sample Email:





















The link on the Google Groups page is a Downloader Trojan with better than normal virus detection.  58% of virus scanners detected the file as malicious on Virus Total.

The Downloader then does its job, downloading a mixed bag of malware from several locations. eSoft is currently blocking all known distribution points.  Among the malware downloaded is Desktop Security 2010, a Rogue Anti-Virus program.




















A fake system scan is run notifying the user they’ve been infected and prompting the user to purchase a license key to remove the malware.


















For only $89.95 you can get a lifetime license with special support. Users following through on the purchase have handed their credit card and other personal information to cybercriminals on a silver platter.

Access to the Internet through the browser is blocked until you’ve purchased a license, adding a hint of Ransomware to the mix.  Between this tactic and the official looking interface, unsavvy users are unfortunately easy prey.

















Use of community sites like Google Groups, Windows Live, Blogger and others is becoming commonplace for cybercriminals looking to get the upper hand on web and spamfilters.  Secure Web Filtering with a combination of granular classifications and real-time URL lookups is the most effective way to combat these threats.

eSoft is actively identifying and flagging select Google Groups pages as Compromised as they’re discovered.  Other sites involved with this attack are blocked as Malware Distribution Points.


Update: May 12th 10:00 AM

It appears the spammers have switched tactics and are now sending fake ecards claiming to be from 123greetings.com. Users receive an email in the form below with an image link.  The links in the email use the same Google Groups URLs and present the same dangerous malware.  This new round of spam uses an even more effective social engineering trick than in the first campaign, and more unsuspecting users will certainly fall victim.






Thursday, March 4, 2010

Virus Alert! Twitter, Google, Hallmark and Others Subject To Attack

The eSoft Threat Prevention Team is warning customers today of a new email scam circulating very quickly.  These fraudulent emails claim to be from Google Staffing, Hallmark, Twitter as well as other social networks and legitimate businesses.

The email persuades the user to open the attached zip file to find out more information. Users that follow through and open the file infect their own system and become part of the threat.

The very legitimate looking email below is just one example of the scam.  The email uses the actual Google logo downloaded directly from their website and easily hooks you into opening the attached file to find out more.


In this case, the downloader infected the system with a bot which immediately begins spewing thousands more of infected emails including fake e-cards from Hallmark, and invitations from social networks like Twitter and Hi5. 

The Twitter email is also very well crafted to make the user believe they were invited by a friend and is legitimately from Twitter.  The from address is spoofed to invitations@twitter.com with a subject “Your friend invited you to Twitter!”.  The body of the message begs the user to open the attached file - “To join or see who invited you check the attachment”.  Using this clever social engineering tactic the scammers are able to peak interest in finding out who may have sent them the message.  The user is tricked into opening the attachment and infecting their system.

As always, be very cautious opening any attachments and especially cautious when they are unexpected.  When in doubt verify with the sender or do not open them. 

Saturday, February 6, 2010

IRS Tax Avoidance Scam

Today, eSoft is alerting customers to a new targeted email scam.  This newest twist to the common IRS email scam seems to be targeted to organizations, notifying the recipient of a tax evasion complaint being filed against the company.  Opening the file infects the user's machine with dangerous trojans that monitor the infected machine, report back to the attacker and download other malicious payloads.

An example of the fraudulent email is below, which prompts the user to open "balance report" attachment.  Because the attachment appears to be a Word file, most users will readily trust the file and proceed to open the file to find out more.


The file is actually in Rich Text Format (RTF) and contains a hidden executable.  Upon opening the file, an error is reported and the user is asked to double click to restart Word.  Doing so will open the executable as shown below, with most unsuspecting users allowing the malicious file to run.

 

Two processes are started and added to Windows startup to run on subsequent boots, microsoft.exe and wks.exe.  These processes send data back to the attacker using HTTP connections to their call home destination.  eSoft is flagging these sites as Malicious to protect any victims of this attack.

These call home destinations are even disguised as a Google search page to evade detection by web filtering companies and automated systems which may detect the site as a search engine.

 

At the time of writing, Virus Total reports only a 25% detection rate on the most recent samples.

Users should be very cautious with any unsolicited emails, particularly those containing an attachment.  The IRS will never email you if they need to contact you, and any emails appearing to come from them are very likely malicous scams.  As noted on the IRS website, "The IRS does not initiate taxpayer communications through email."

Wednesday, October 21, 2009

Compromised Web Servers Host Koobface Malware Cocktail

The Koobface gang has struck again using compromised web servers to deliver a potent mix of malware. eSoft threat researchers have found hundreds of newly exploited sites hosting malware which includes downloaders, keyloggers and multiple variants of the Koobface worm.

Attackers using compromised sites to deliver their malware stand a better chance of evading web filters since those sites are generally already categorized in a "safe" category. The constant changing of the malware binaries also keeps the Anti-Virus detection rates low.



 eSoft has noted a constant stream of new malware files coming from these sites.

Koobface is a social network worm that spreads using social engineering techniques. Users will typically receive a link to an alleged video. After clicking the link, the user is prompted to update their flash player or download a codec to view the video. Users who haven't been trained to be skeptical of such requests follow the directions, infecting their machine and allowing the worm to spread through available social networks using the local users' accounts and targeting the infected users friends, family and business contacts. This social networking aspect is part of the lure of the social engineering and why its so successful. The video might require a download to view, but it came from a close friend so it is probably fine.

The keyloggers hosted on the compromised sites can be used to steal any kind of sensitive personal information. Koobface will often steal login credentials for social networking sites which it can then use to send more messages and infect more machines.

The compromised sites in this attack are in a format that looks something like this:








eSoft is flagging these sites as 'Compromised'.