顯示具有 Malware 標籤的文章。 顯示所有文章
顯示具有 Malware 標籤的文章。 顯示所有文章

2013年8月16日 星期五

HITCON 2013 Session Summary : Advance Malware Evasion And Hiding Techniques

This session is origin in HITCON 2013, proposed by Chong Rong Hwa from FireEye

Attack Vector

In this session, first three type of infection vectors are discussed
  1. Physical, like USB
  2. Email
    Compress, Encryption, Password protected compression
  3. Web
    Water Hole Attack, which attacker compromise legitimate website to host malicious page.
    ex. May 1 2013, attacker compromise US Department of Labour to host PoisonIvy Backdoor

APT Advanced Malware

Those malware not use advance technique but disguise itself as normal program or user.

Hacker may use old vulnerabilities, but slightly change the exploit code to harden the analysis.
    Add invalid characters in rtf file to confuse parser
    Replace part of shellcode to semantic-equivalent instructions

Save non-malicious code in disk, construct malicious payload in the memory
    Trojan.APT.BaneChant

Employ common used encryption(signature) algorithms with slightly change(ex. DES,AES)
Use public and legitimate service for malicious behaviors, such as : google drive, amazon aws
    Trojan.APT.Seinup
Anti-VM
   Detect human behaviors

APT Attack Source

Not from single source and the control servers are distributed over the world.
      Asia and East Europe are two most source region for APT attack. 
      Most of APT tool made in China, ex. Gh0stRAT

2013年8月15日 星期四

HITCON 2013 Overview


Cyber War

  1. People's Republic of Cyber Warfare: Comparing China Iran & Russia Militarization of Cyberspace(駭客人民共和國: 中國伊朗跟俄羅斯網軍的分析與比較)
  2. Global Cyber Espionage and Chinese Hacker Threats, Internet Survillance and PRISM(全球間諜:互聯網監控全球趨勢 棱鏡門與中國駭客威脅論)
  3. APT1: Technical Backstage(APT1: 反攻網軍後台)
  4. How South Korea Makes White-hat Hackers(南韓如何培養白帽駭客?)
  5. How does Japan dea with Targeted Attack and SCADA Security(目標鎖定攻擊與工控系統安全:日本如何應對兩大趨勢)
Cyber War is the main topic of HITCON 2013. Hence many session about global cyber activity are included.
In first two presentation talk about national power of cyber war, include China, Iran and Russia. And also mention about chineese hacker and  Internet survillance of U.S.
Second, Paul Rascagneres from malware.lu share their experience to track APT1 hacker,which probable come from china.
Then, national strategy of Japan and Korean, which are two countries near TW, is mentioned. 

APT

  1. APT defense from the view of security architecture(從系統設計建置面談 APT 防禦)
  2. Visual Data Analytics - Graphing your Indicators(APT 特徵的視覺資料分析法)
  3. Digital Eagle Eye System: Use Cyber Intelligence against APT Attacks(數位鷹眼系統: 以網路數位情資對抗 APT 攻擊)
  4. APT Cyber Shuttle: From Automated Analysis to TTP Observation(APT網際飛梭:從自動化分析到拆解 APT 後台駭客活動)
  5. Light & Shadow about Banking $ecurity @Japan(光與影 日本銀行業的資訊安全)
In HITCON 2013, APT is still one of hottest topic. In those session, management and strategy against APT is discussed. And some forensics technique are also proposed to face APT attack.
Notice that, the session "APT Cyber Shuttle: From Automated Analysis to TTP Observation" proposed by Xecure-Lab & Academia Sinica will give a session in Black Hat US 2013.

Malware

  1. Building new weapons for malware analysts(建立惡意軟體分析的新武器)
  2. Advance Malware Evasion and Hiding Techniques(惡意軟體的進階免殺技巧)
  3. Static Analysis and Dynamic Instrumentation for Intelligent Exploit Analysis(靜態與動態智慧型漏洞文件分析系統)
Malware analysis is a old discussion problem. In this year, some session about malware are also included.

Mobile


  1. Escaping Android Dynamic Analysis; Chinese New Year Train Ticket Ordering Day(逃離安卓動態檢測 & 訂票助手一日談)
  2. Dex Education 201: Anti-Emulators(深入Dalvik Dex教學:反制模擬器)
  3. Android Hooking Attack
  4. Review of Security Vulnerabilities on the Android Platform(Android平臺安全性漏洞回顧)
  5. GSM Security Research using Open Soruce Tools(以開源軟體進行GSM安全研究)

With exponent usage of mobile device, sessions about mobile are also increasing. The first two sessions mention about how malware evade security analysis mechanism. Then the following two sessions is about technique employed by malware. Especially, "Review of Security Vulnerabilities on the Android Platform" ,proposed by 肖梓航 Claud, which overview the android vulnerabilities in current year is worthy to read.

Exploit & Vulnerability


  1. Life of Coder: The adventure through the landscape of bugs(程序員的蟲洞漂流)
  2. Analysis on the EPATHOBJ Exploit(請謹慎編碼,哪怕它只是一句錯誤處理— 來自 win32k!EPATHOBJ::pprFlattenRec 漏洞的啟示)
  3. Killing AV in x64(戳戳防毒軟體死穴)
  4. 0-Day Easy Talk - Happy Fuzzing Internet Explorer(0-Day 輕鬆談 - Happy Fuzzing Internet Explorer)
  5. How can i have 100 0day for just 1day(超級祕訣 - 一天擁有 100 個 0day!)
  6. Exploiting JRE (JRE安全机制与漏洞挖掘研究)
Exploit and Vulnerability is an interesting topic this year. An 0 day sharing activity is also include in this year's HITCON.
In first three sessions, the authors analysis some known exploit and  share their implementation. The fourth session, the author demonstrate the 0-day he found and share his experience.
The fifth talk present an idea to fuzz numerous of application at once. The last one session conclude java vulnerabilities in current day and the direction to fuzz java platform.

Others


  1. The undisclosed files of incidents by the data scientist(資料科學家未曾公開之資安研究事件簿)
  2. OS X Rootkits Stuff(那些洞,我們一起追的 OS X Rootkits)
  3. Spears and shields on online game(線上遊戲矛盾大對決)
  4. Breaking image CAPTCHA for fun(CAPTCHA 好好玩)
  5. Protocol and physical analysis of EMV POS devices.(EMV晶片卡POS裝置的實體與溝通協定分析)
  6. Browser and Local Zone(瀏覽器和本地域)
The session "The undisclosed files of incidents by the data scientist" talk about some research topic of professor 陳昇瑋. Social network and malicious phone call are both special and interesting topic.
Also web security are widely discussed in Black Hat 2013, there are less topic about web security in this year's HITCON.  

2013年8月8日 星期四

PoisonIvy Remote Administration Tool

In this article, I will talk about PoisonIvy and demo it's usage.
PoisonIvy is a remote administration tool, which is widely used by hackers as the backdoor.
There are some news about PoisonIvy:

Usage Demostration

In PoisonIvy Server Profile, we can config the server.

In this tab, address and password can be set. Proxy attribute can also be set in this tab.
The next tab, install, is used to config how the backdoor startup. Such as autostart and executable name is included.

Some advantage attribute like process injection, persistent and key logger are contained.
After generation, a backdoor will be generated. Then we create correspond client and  execute the backdoor in another machine.
After a success infection, a message will showed. And we can get some basic information about victim.

 Then we can retrieve some system information about victim's machine.


Next step, we can create a remote shell to victim.

Moreover, we can also get the remote desktop of victim.



2013年6月23日 星期日

Android Malware Zitmo Analysis

Zitmo

Zitmo is an android bot which aim to stole user's bank authentication tokens. It is interest that Zitmo's feature to beat two factor authentication. 

In order to prevent traditional banking trojan, online banking service employ transaction authentication numbers (TAN), which is a two factor authentication mechanism, to authorize user.  

Zitmo is the mobile version of Zeus bot, which give Zeus a chance to defeat two-factor authentication.

In two factor authentication, online bank will first request user's mobile number. After user first authentication with tradition password mechanism, the message contains secondary password will send to user's mobile. Only user with this two password can successful authentication and complete transaction.

Following figure describe how Zitmo work:
First, Zeus will infect user's computer. Once user connects to online back after infection, the connection will be hijacked. All the user's input will be sent to bot server including the phone number used to authenticate. Then the bot server will send a forge message to user's mobile to install an app, which is indeed Zitmo bot. Once user install this app, all the message will be hijacked too. Hence the secondary password will sent to bot server, thus attacker has ability to do some bank transaction.

Take a briefly look into Zitmo.
In manifest, we can observe following sections.
Zitmo requests permission to reseive and send message.


Zitmo also register a receiver triggered once mobile boot/reboot.

We can observe Zitmo register a receiver to intercept message with high priority(MAX INTEGER), so it can hijack user's incoming messages. 


The core part of Zitmo is in following figure. After massage coming, function onReceive() will called and snedSmsIfEnabled() will called to send Sms to attacker. 




Reference

2013年5月27日 星期一

Anti-Reverse Technique Used in Malware

It is endless arm between security experts and hackers. Hacker discover new exploits or new attack vectors, in the same time security experts try to identify and block those attacks. In order to prevent detection or analysis, attackers employ some technique to avoid reverse engineering and detection.Following pic show that nearly 90% malware will employ some Anti-Re technique.

In Black Hat US 2012, Rodrigo Rubira Branco et al. classified anti-reverse technique into four type, Anti-Disassembly, Anti-Debugger, Obfucation and Anti-VM. In this article, I will summary anti-reverse technique based on this paper, and discussion each technique in other article . The distribution of Anti-Re is shown below.
This paper also summary the packer used in their observation. As this table show, most packer employed in malware is UPX. 


List below is famous packer used by malware with their function to anti-reverse engineering.

UPX
  1. UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser
    Anti-VM (SLDT)
    Anti-VM (IN)
    Push Pop Math
    Instruction Counting
    PEB NtGlobalFlag
    PEB's BeingDebugged (Stealth IsDebuggerPresent)
  2. UPXv20MarkusLaszloReiser
    Anti-VM (SLDT)
    Anti-VM (IN)
    Push Pop Math
    Instruction Counting
    PEB's BeingDebugged (Stealth IsDebuggerPresent)
    SS register
  3. UPX290LZMAMarkusOberhumerLaszloMolnarJohnReiser
    Anti-VM (IN)
    Push Pop Math
    Instruction Counting
    PEB's BeingDebugged (Stealth IsDebuggerPresent)
    SS register
  4. UPX20030XMarkusOberhumerLaszloMolnarJohnReiser
    Anti-VM (IN)
    Push Pop Math
    Instruction Counting
    PEB's BeingDebugged (Stealth IsDebuggerPresent)
  5. UPX293300LZMAMarkusOberhumerLaszloMolnarJohnReiser
    Anti-VM (IN)
    Instruction Counting
    PEB NtGlobalFlag
    PEB's BeingDebugged (Stealth IsDebuggerPresent)
  6. UPXProtectorv10x2
    Nothing

Armadillo
  1. Armadillov171
    Instruction Counting
    Instruction Substitution (push – ret)
  2. Armadillov1xxv2xx
    Nothing
PECompact
    Anti-VM (STR)
    Anti-VM (SLDT)
    Anti-VM (IN)
    Push Pop Math
    PEB NtGlobalFlag
    PEB's BeingDebugged (Stealth
    IsDebuggerPresent)
    SoftICE – Interrupt 1
    Software Breakpoint Detection
    SS register
BobSoftMiniDelphiBoBBobSoft
    Anti-VM (STR)
    Anti-VM (SLDT)
    Anti-VM (IN)
    Push Pop Math
    PEB's BeingDebugged (Stealth IsDebuggerPresent)
    SoftICE – Interrupt 1
    SS register
ASPack
  1. ASPackv212AlexeySolodovnikov
  2. ASProtectV2XDLLAlexeySolodo
    Anti-VM (IN)
    PEB's BeingDebugged (Stealth IsDebuggerPresent)
    SS register
  3. ASPackv10803AlexeySolodovnikov
    Anti-VM (IN)
    PEB's BeingDebugged (Stealth IsDebuggerPresent)
  4. ASPackv21AlexeySolodovnikov
    PEB's BeingDebugged (Stealth IsDebuggerPresent)
    SS register
ProtectSharewareV11eCompservCMS
    Anti-VM (SLDT)
    Anti-VM (IN)
    Instruction Counting
    PEB's BeingDebugged (Stealth IsDebuggerPresent)
    Instruction Substitution (push – ret)
ASProtect13321RegisteredAlexeySolodovni kov ASProtectv12
    Anti-VM (STR)
    Anti-VM (SLDT)
    Anti-VM (IN)
    Push Pop Math
    PEB's BeingDebugged (Stealth IsDebuggerPresent)
    SoftICE – Interrupt 1
    Software Breakpoint Detection
    SS register
WiseInstallerStub
    Nothing
MaskPEV20yzkzero
    Anti-VM (SLDT)
    Anti-VM (IN)
    Push Pop Math
    PEB's BeingDebugged (Stealth IsDebuggerPresent)
    SS register

Reference

[1]  Rodrigo Rubira Branco, Gabriel Negreira Barbosa, Pedro Drimel Neto "Scientific but Not Academical Overview of Malware Anti-Debugging, Anti-Disassembly and Anti-VM Technologies", Black Hat US 2012

2012年8月28日 星期二

A New Attack Vector : Attack from VMM

With growth of cloud service , virtual machine become widely deployed. Nowadays, security issue was most   concern when employ cloud service. Recently, Symantec has announced malware analysis report about Crisis. The most interesting thing is that Crisis can propagate though VMware, and this can be a good example of security issue of cloud service.

The only function demo by Crisis is copy it self into VM by VMware player tool. However with power of VMI technique proposed by many academic work, Mlaware can do almost everything from stealing information, killing Anti-Virus to invoking new process outside the VM. Due to this "out-of-box" character, system inside VM has no direct way to detect this kind of attack.

To raise this kind of attack, hacker should first get control of VMM. This can be done by misconfiguration of    VM server, by insider attack, or some vulnerability of VM system(like vulnerability in Xen driver). Although attack to VM server is not an easy job, it still introduce a new attack vector that worthy to research in the future.       

[1]  Symantec Crisis Analysis Report

2012年8月6日 星期一

Malware Analysis : Trojan:AutoIt/Ransom.F

This malware has free sample and analysis report in malware.lu. So I try to analysis this sample as practice.
When I am analyzing this  sample , it had detection rate 14/40 at VirusTotal
This malware come with icon as following image , which give us hint that this malware is compiled by AutoIt :
After this sample execution , it will connect to 95.163.104.88 which website was already removed.And this network activity can be cached by our tool. So we can observe that it connect to 95.163.104.88/spielberg/start.php.
Sometimes there is an pop-up windows during execution :

 We can also observe it change some file in following image:
This malware are packed by UPX.  We can easily unpacked it and get origin executable.
Then we use exe2aut to decompile the sample , and retrieve AutoIt scipt.
The most interesting part is at end of script , it install some registry to trigger itself after booting.But this behavior is not detect by our tool. Then it check if explore.exe and taskmgr.exe existed to ensure it's GUI in top of windows.

This sample can not run by both anubis and cwsanbox.