Malvertising: The Dawn of a New Attack Era

In September 2014, two news sites in Israel fell victim to a malvertising campaign that affected thousands of viewers. One month later, Yahoo! and AOL became victims of a similar campaign. Malvertising concerns me more than the average attack method for a several reasons:

  1. It utilizes ad space on any web page that hosts third party ads… so basically most of the Internet.

Have you counted how many ads are on each web page as you casually browse news articles, or look up that film with what’s-her-name and so-and-so? This article states that the average user saw over 1,000 ads per month in 2012, and one can only assume that this number has increased since then. There’s no easy escape. Malvertising grants attackers access to hundreds of millions of users. Makes you want to install some ad blocking software, doesn’t it?

  1. Malvertisements are indistinguishable from legitimate ads.

You’d be pretty hard-pressed to pick out a malicious ad at first glance even if you have “cyber intuition.”

A strict “no-click” policy for web ads isn’t enough to protect you because some malvertisements, like pop-up ads, don’t even require users to click— malware is installed when the ad loads on the page, and the malware could be anything from bots (think zombie computer) to ransomware.

  1. Repercussions are basically nonexistent because the hosting web site has no control over the ads placed, and the attacker is several times removed from the ad network.

Attackers take advantage of the way an advertising network functions, with its low prices, automatic bidding process, potential for very large audiences via “trusted” sources, and almost nonexistent means for tracking them down.

This is how it works: The attacker, along with legitimate ad buyers, submits advertisement code and the highest price they’re willing to pay to an ad publisher who then uses an ad network to bid on ad space on third-party web sites. The ad network sells each space to the highest bidder on behalf of the web site — this is an automatic selling process that takes milliseconds, and prices are typically less than a dollar. An attacker’s “ad” code is then placed on the web site.

Attackers will typically build a solid reputation for themselves by placing ads with clean code for a few months before injecting them with attack code. Once this happens, the attack has a widespread reach and the potential to inject hundreds of thousands of users and generate hundreds of thousands of dollars for an initial cost was a mere fraction of that. The malvertisement only needs to be posted for a few days or a few hours before the attacker has the victims he needs, so he’ll then remove the ad altogether.

Creating an industry safeguard against malvertising requires the coordinated effort of ad networks and publishers, as well as pressure from ad hosting web sites. Such cooperation between many parties is difficult to orchestrate unless the problem greatly affects profits. But because ad networks are still being paid for ad space sold to attackers, the impact on the bottom line is revealed much more slowly. Attackers use this process because it’s easy and it works.

  1. Malvertising as a consumer-based attack method is a shift from the sketchiness seen in spear phishing and packet sniffing to one that’s almost legitimate because it leverages a real business process to do all the hard work normally involved in delivering malware.

Gone are the days when malware only hung out on the bad side of the internet. Cyber threats are out in the open, hiding on real web pages that we trust and frequently visit, using methods honest people intentionally created to improve business, and we must continue to adapt in order to protect our cyber valuables. Attackers are upping their game and focusing their guile on identifying loopholes in commonplace business processes.

Luckily, there are things we at Palo Alto Networks already do to thwart malvertising threats:

  • Drive-by download protection alerts users that a download is attempting to take place and requires the user to either allow or deny the download. If a malvertisement tries to auto-download malware, this mechanism gives the user an opportunity to nix it before it happens
  • File-blocking profiles restrict the types of files that can be downloaded to only the files that are needed and expected by the user
  • WildFire creates new anti-virus protections for unknown malware immediately after it’s seen. Malvertisements attempting to deliver known or unknown malware are detected and blocked
  • URL Filtering stops traffic to known malicious web sites and uncategorized web sites. If a malvertisment is clicked, resulting web page is blocked
  • Even if malware succeeds in downloading onto your machine, Traps prevents it from installing itself

Security isn’t something that stops with network architecture and coding practices. Business-to-business processes need it, too. Anything that uses the internet, or an intranet, in the slightest way must be included on the list of potential threat vectors, poked at with a cyber-stick by someone wearing their “if-I-were-a-hacker” hat, and secured accordingly.

For more information on what can happen as a result of a successful malvertisement, check out Dan Kaminsky’s interview with USA Today staff writer, Elizabeth Weise.

[Palo Alto Networks Blog]

Moving Beyond Proxies: A Better Approach to Web Security

Once upon a time, proxies fulfilled a need traditional firewalls could not meet: visibility into web traffic starting with the categorization of HTTP, and later HTTPS, traffic. However, little to no emphasis was put on the vast number of applications utilizing other avenues of accessing corporate networks.

Proxy deployments today have outlived their usefulness and practicality. They have joined a long list of legacy security products that provide limited security capability against today’s advanced threats.

Download this whitepaper to find out more on the shortcomings of proxies, and how a next-generation security platform can provide faster, simpler and more comprehensive security.

[Palo Alto Networks Blog]

Dridex Banking Trojan Begins 2015 with a Bang

In October, we called out a series of attacks installing the Dridex Trojan using macros in Microsoft Word documents. Those attacks continued over the last few months and in first two weeks of the new calendar year we’ve seen another new campaign.

To refresh your memory, Dridex is the latest version of the Bugat/Feodo/Cridex banking Trojan. Its core functionality is to steal credentials of online banking websites and allow a criminal to use those credentials to initiate transfers and steal funds. Dridex is currently being distributed through an e-mail campaign that carries a Word Document attachment, which uses built-in macro code to download and execute a copy of the Trojan.

While Dridex targets banks from all over the world, in October the majority of the e-mails we tracked were destined for the United States, with the United Kingdom coming in at a distant second place. This time around the UK comes out on top, with over one third of all attacks observed there.

This change in targeting is also clear in the themes used in each of the attacks. Many of the most-common attachment names refer to the BACS, or Bankers’ Automated Clearing Services, which is used for bank transfers in the UK. Another group of e-mails claimed to be an invoice from the Les Mills UK, a fitness organization. This campaign is likely preying on individuals who have made New Year’s resolutions to get fit in the UK.

In October we had identified just six URLs used by the Word documents to download the Dridex Trojan. In the past two weeks we’ve detected files using 43 different download locations.

  • 108.59.252.116/mops/pops.php
  • 111.125.170.132/doc/8.exe
  • 159.253.19.113/ord/1.exe
  • 178.77.79.224/mops/pops.php
  • 188.241.116.63/mops/pops.php
  • 192.157.233.28/ord/1.exe
  • 192.227.167.32/mops/pops.php
  • 193.136.19.160/mans/pops.php
  • 194.28.139.100/mans/pops.php
  • 206.72.192.15/mans/pops.php
  • 213.174.162.126/mans/pops.php
  • 213.9.95.58/mans/pops.php
  • 87.106.165.232/mans/pops.php
  • aircraftpolish.com/js/bin.exe
  • betterinnovation.net/modules/mod_arateiclws/cr_7_2711_2.exe
  • cerovski1.net.amis.hr/js/bin.exe
  • curie-hennebont.fr/js/bin.exe
  • dollarbrasil.com.br/444
  • ecovoyage.hi2.ro/js/bin.exe
  • elsy.pwp.blueyonder.co.uk/444
  • fachonet.com/js/bin.exe
  • gofoto.dk/js/bin.exe
  • gv-roth.de/js/bin.exe
  • interativaonline.com/444
  • jasoncurtis.co.uk/js/bin.exe
  • lapiden.com/wp-content/themes/twentytwelve/mss20.exe
  • lapiden.com/wp-content/themes/twentytwelve/mss22.exe
  • lichtblick-tiere.de/js/bin.exe
  • media.mystudio.net/js/bin.exe
  • microinvent.com/js/bin.exe
  • nestorausqui.com/444
  • ngrbook.com/cp/images/digits/blushdw/cr_7_2711_2.exe
  • nubsjackbox.oboroduki.com/js/bin.exe
  • obuwiehurt.com.pl/js/bin.exe
  • paulmartinseo.com/wp-content/themes/twentyten/cr_7_2711_13.exe
  • phaluzan.net.amis.hr/js/bin.exe
  • riccis.homepage.t-online.de/Testseite/js/bin.exe
  • sardiniarealestate.info/js/bin.exe
  • ticklestootsies.com/js/bin.exe
  • walkdesign.com/wp-content/themes/willow/cr7_2711_1.exe
  • weme-systems.de/modules/mod_arateiclws/mss3.exe
  • http://www.isolectra.com.sg/tmp/rk2n1.exe
  • zusso.jp/444

Many of these URLs are hosted on compromised websites, but there is no clear pattern to indicate how they are taking control of the websites. However, there are clear groupings of patterns for the download URLs. One group relies on the path “/js/bin.exe” while another uses “mops/pops.php”. These URLs are encoded within the macros included in each file. If you are interested in extracting them, Rodel Mendrez from SpiderLabs wrote a short guide using Python. If you want to take the simpler route, Didier Steven’s OLE Dump tool has a plug-in that will automatically decode and extract these URLs, as shown below.

Palo Alto Networks WildFire detects all of these macro-based attacks using our sandbox technology. Others can protect themselves by disabling macros in Microsoft Word. Macro-based malware has been around for over well over a decade. Most organizations should disable them by default, enabling macros only for trusted files.

[Palo Alto Networks Blog]

CNBC Talks to Cyber Threat Alliance About Taking the Fight to Cyberattackers

Today at Palo Alto Networks HQ we hosted the four co-founders of the Cyber Threat Alliance, which includes our own Mark McLaughlin, for a live discussion on CNBC’s Squawk Alley that was squarely focused on how collaboration between security companies is helping customers in the ongoing battle against cyberattackers. Mark and his fellow co-founders also touched on the latest cybersecurity legislation to come out of Washington.

Watch the full interview here, learn more about the Cyber Threat Alliance here and check out a few shots of the behind-the-scenes action at HQ this morning.

 [Palo Alto Networks Blog]

 

English
Exit mobile version