Sunday, January 1, 2012

Hopefully a revival!

Sorry we have been gone for so long. I have been way to busy at my day job. Just changed from that so I hope to get back on the wagon here soon. Stay tuned!

Thursday, August 18, 2011

Two files with the same name!

Question: Can you create two files with the same name in a Windows directory?


Answer:

http://blogs.technet.com/b/mmpc/archive/2011/08/10/can-we-believe-our-eyes.aspx

Not sure how many of you remember the right to left override trick that was found a few months back. Here is another play on that type of bypass. Very interesting.








Tuesday, August 16, 2011

To APT or not?

McAfee recently discovered a widespread series of exploits that they are calling Operation Shady Rat (http://blogs.mcafee.com/mcafee-labs/revealed-operation-shady-rat). This exploit compromised 72 companies around the world and seemed to lead back to China. McAfee concluded that this attack was an Advanced Persistant Threat or APT, other security Vendors such as Sophos claimed that this attack was not an APT becuase the malware was not sophisticated. As a result, I wanted to take the time to discuss this type of attack and get away from some of the marketing terms.

What is an APT? APT is the term used to describe an attack carried out over a fairly significant time, that is meant to gain a foothold deep into an organization's systems, staying in the network for a long period of time undetected, usually with the goal of collecting intelligence information such as troop movements in the case of an attack carried out against the government or intellectual property in the case of an atack carried out against a corporation. The main difference between an attacker that is considered an APT is that they are persistent and have resources such as a government or major corporation backing them.

Second, an APT is not a piece of malware, even though some seurity vendors would have you believe that for the sake of selling a product. For example FireEye claims they can stop APT's (http://www.fireeye.com/products-and-solutions/), really? Don't ge me wrong, I love the FireEye malware analysis product and I am not just picking on them as there are several others that advertise the same, but really do you expect me to believe you can shutdown hackers backed by a large government or the Russian Mafia on all attack vectors? Now, yes you maybe able to find the malware that is being planted, but that is only one part of the attack and even if you stop that piece of malware, the attackers will be back, they are persistent after all.

Ultimately what I want get across here is that, an APT is the attack as a whole, including; the attackers, the attackers' motives, and the methods used to compromise the network (it could be malware, or maybe a misconfigured server, etc.). An APT attack could be carried out by a group of attackers using something as old as Back Orifice, or by using no malware at all. To protect against APT's you, will need mroe than a product that claims to protect against APT's, you will need multiple products and you will also need people analyizing logs and network behavior for things that your tools missed.


NoVAH Hackers Talk

I would like to thank everyone at NoVAH hackers for having me tonight. I had a great time and learned some good things.

For those who couldn't make it, or those that were there and want the slides, I am adding them here. If you have any questions, don't hesitate to ask. I have some good links coming this week as well. Stay tuned.

Also guys, don't forget, if you want us to analyze a sample and post the steps, send it on! We generally try to find samples that are good learning samples. I have one that I'm sitting on now, but that's for another talk. I will release it then :)

Get the talk here: Curt NoVAH Talk 8-15-2011


Thursday, August 11, 2011

SANS Malware Analysis Challenge

I am working on a talk to present at NoVA Hackers August meeting. I will be posting the slides and a link to the video on the blog once the talk is complete. The subject is on how to utilize Indicators of Compromise (IOCs) found during malware analysis to find and fix infected machines and to protect others. If you are in the NoVA area stop by and check it out. The details can be found here:

http://novahackers.blogspot.com/

In the mean time, to keep your malware analysis learning going, check out the latest SANS Malware Analysis Challenge.

http://computer-forensics.sans.org/blog/2011/08/10/malware-analysis-challenge-to-strengthen-your-skills








Saturday, July 2, 2011

Changing the Blog format

We have found, as many probably have that venture into blogging, that it can be hard to keep up with new posts. With that in mind, we have decided to change the way we are doing things. We will still be submitting step by step examples of malware analysis when possible. To keep posting moving in our busy schedules, we are also going to add posts about new malware trends, how to for tools that are either existing or new, how to protect or detect malware in the enterprise etc.

We are also looking for some volunteers. If you are interested in helping out with the blog, or if there is anything you would like to see us write about, please send an email to inetopenurla[at}gmail(dot)com.

The static portion of the latest sample should be coming any day. Stay tuned. And thanks for viewing!

Saturday, May 21, 2011

Analysis of facebookmessenger malware

In this latest analysis, I will be analyzing a recent piece of malware called the facebook messenger. This piece of malware has received some recent press, which to me makes it even more interesting to evaluate.

I started the analysis of this sample in my XP analysis VM. I began once again by taking a snapshot of the VM and a baseline using Regshot. I then started up Process Hacker and Capture Bat. Process Hacker is similar to Process Explorer but includes a few more advanced features, such as the ability to suspend a process and the ability to look into the memory of the process to see DLL's in use, what file handles are open, and basic network information very similar to TCP View. I will not cover how to run capture bat or take a snapshot as we have covered these items before.

Right away one of the interesting things here is that facebook messenger is less than 100k, yet after being run, it uses well over 20 Mb of RAM. Very Interesting!

Add Image


What this interesting behavior tells us is that Facebook Messenger is relying on mostly built in Windows functions and DLL's for its capabilities. This a tactic used to make the malware more difficult to detect, as it is using legitimate libraries.

Next I went to the network tab and noticed facebook messenger opening a connection to smtp.mail.ru. At first this would seem to be a standard SMTP communication except that it is connecting to TCP port 8080 which is a standard web proxy or web server port. Using this port is most likely done to allow the malware to bypass firewalls that would normally block non-standard ports. Process hacker also indicated that facebook messenger was sending a TCP SYN, meaning it is expecting a live connection and response. Since the sample could not connect to it's server, the process went into a wait state using a UDP port.




Since I wanted to find out more, I moved on to my Regshot and Capture Bat Analysis. The Capture bat analysis didn't show much of interest, it seems that the activity of this specimen primarily takes place in memory. During this process I tried to terminate the process several times, with task manager which did not work. It's a good thing I have Process Hacker. Process Hacker has an arsenal of ways to terminate processes in Windows, chances are that if you run into process termination protection, that Process Hacker can bypass it.

Interestingly, Facebook Messenger made very few registry changes, this is most likely due to the fact that it is really jsut calling other windows libraries. The changes it made were designed to set facebookmessenger to autrun on bootup.

Next I went back to process hacker and looked at the strings in memory. I found a few interesting things such as what appears to be non-random obfuscated text.

Since this line of questioning was not getting as far as I wanted, I decided to load up REMNux and the HoneyD honeypot to see if I could complete the connection and see what the facebook messenger is sending to smtp.mail.ru.

To get the sample to redirct its traffic to my honeypot, I edited the hosts file (c:\windows\system32\drivers\etc\hosts) to redirect smtp.mail.ru to 192.168.40.120.

The screenshot below shows what I captured with Wireshark.










Next I started Remnux and edited honeyd.conf to set Honeyd to listen to port 8080.
You can edit the honeyd.conf file using your favorite Nix text editor. After editing the .conf file, start honeyd using the command honeyd start



HoneyD doesn't provide services of it's own, just a redirect to another service. As a result, I setup netcat using the command 'nc -l -p 8080' to have netcat listen to port 8080. At this point the conenction completed and the facebook messenger sent out a sting of text. The text appears to be obfuscated and encrypted (shown in the above screenshot). After the connection completed, facebook messener turned itself into a listener and began to listen on a UDP port. Even though I was unable to understand what was being sent, it is fairly easy to determine that this malware is sending system information to a command and control and then setting up to wait for commands to come back.

In this case I am really interested in what this malware is doing, so I will move on to some Brain Surgery/Static Analysis to determine what this malware is doing. Look for my next post in the next couple of weeks (Hopefully!)