The inline frames play a crucial part in sharing and delivering third party content through them. But this is also a hardened fact that Iframes are used effectively by malware writers to spread infection across domains in a hidden manner. But the question is , Do browsers play significant role in this?
The URL obfuscation is a big stringency in the online world. Actually, it tests the browser efficiency to dissect the behavior of crafted URL. That has to be done. The browsers have shown a rogue behavior in determining the source and destination of URL's when it is obfuscated or fused with meta characters. This is dangerous from a user perspective because a victim can go to undesired destination. Well, lot of changes have been noticed in browser development with respect to that but in certain conditions , browsers still fail to find the authentic nature of URL's being rendered in the browser. A Google Chrome URL Obfuscation Vulnerability can be seen HERE
Further, a recent bug has been posed to BugZilla ID - 570658 regarding the behavior of IFrames and Frames handling the URL obfuscation. Firefox implements a notification alert to user when a obfuscated URL is used in the address bar as follows
On performing analysis of various malware, a bug has been noticed in all version of Firefox which fails to generate an alert when obfuscated URL is being placed in Iframes. In certain cases, it can be used effectively in spreading malware and stealing sensitive information. While discussions on BugZilla, it is noticed that Firefox behavior is completely different in these two scenarios which should not happen. The bug is in open state now. The major improvements can be seen in the following trunk
A generic POC can be considered as [iframe src="http://www.example.com@malware.com" width="600" height="600" /];
May be it is considered as a fact that frames are not shown directly but this is a bug by behavior. We can expect some changes in coming time regarding this falsified behavior.
Read more (rest of article)...
It was actually a report that we wrote for this customer, to assure them that although other detection mechanisms aren't flagging, that we are rightfully flagging these pages as malicious.
Soon after publishing the blog, we realized that it was the same widget that got the boingboing.com parked domain infected, which we blogged about back in May.
Yesterday I had some time to sit down and study this widget further, and discovered something critical--it's a part of the standard domain parking page of Network Solutions.
And so, just how many domains (not pages) are currently affected and serving malware?
More than 500,000 domains, according to Google: According to Yahoo, add a zero to that, at least 5,000,000 domains: I didn't have time to click on every single one of them, but I clicked on enough to conclude that, all of them are indeed infected, via the same widget we blogged about a few days ago. Also, neither Google or Yahoo actually shows all results. Google shows the first 45 pages only, and Yahoo shows the first 100 only. So we couldn't really go through all the domains one by one...and 5 million is too large a number for manual verification anyways.
Deciding to look a bit deeper to see if there are other infections, I realized that there is. The behavior is quite the same as our boingboing.com alert back in May.
One infection, in addition to the widget, is this:
Analyzing this and comparing traffic logs of the boingboing.com post back in May, we concluded the the attacker uses the following free traffic analysis services, which are the two most popular choice among attackers in greater China--cnzz and 51.la. Specifically, the following accounts are used:
Since both accounts were registered with handle "skbanner," we assume it's not multiple infections by different attackers but the same attacker using two counters. The 51.la account can be accessed: First, the account was registered on Feb 5th. A day later, on Feb 6th, Tata Consulting Services, who uses Network Solutions as domain registrar, had their DNS records manipulated, according to TechCrunch and other media. This all happened shortly after Jan 19th, when Network Solutions publicly addressed that some of their sites have been hacked and they are addressing the problem.
The 51.la "skbanner" counter recorded 2,683,120 accumulative page views--that's a lot of victims out there.
The highest page view was seen on April 3rd, 2010. This time frame is close to the largest incident in this series--on April 7th, WordPress admins started to post on the WordPress Forum complaining that their WordPress on Network Solutions has been compromised and were serving malware. That thread had 151 posts total.
Network Solutions acknowledged the problem on April 9th with a blog post Alert: WordPress Blog & Network Solutions. If these events were associated, then sometime in early April the attacker group must have decided to leverage the control they had of Network Solutions, and massively injected malicious content not into the default parked domain page, but rather, into the hosted WordPress blogs and / or websites.
It's concerning that this series of compromises happened starting Jan of this year, and today we are still seeing more than 500,000 Network Solutions domains actively serving malware as we write.
We also just registered a domain, armorizetest.com, with Network Solutions, and verified that it indeed actively serves malware the moment that it's up. Here's what we did:
First we paid for our domain: Then we set it to park using the "standard construction page": It's done. We connect to our newly purchased and parked domain, and as you can see, the fake (and malicious) QQ messagebox pops up, and the compromised (and malicious) Network Solutions SMCI widget is there, too. From the traffic, yes, it's serving malicious content, which is the same as described in our last blog post. One of the dropped malware executable is: C:\Documents and Settings\Administrator\Application Data\SystemProc\lsass.exe The hidden directory SystemProc is created by a javascript exploit.
Follow-up: We have managed to get in touch with Network Solutions, and within less than three hours, they have acted and taken down the widget. Actually, they have commented the code out, so you can still see it if you "view source."
At the same time, while trying to figure out the exact number of affected domains, we realized that Yahoo is probably more correct on this--it was more than five million domains! Here's a video:
Finally, as to the dropped malware lsass.exe itself, here's what it does (credits to Chris Hsiao): When run, itcreates the following components: ======================================================== %ProgramFiles%\Mozilla Firefox\extensions\{9ce11043-9a15-4207-a565-0c94c42d590d}\install.rdf %ProgramFiles%\Mozilla Firefox\extensions\{9ce11043-9a15-4207-a565-0c94c42d590d}\chrome.manifest %ProgramFiles%\Mozilla Firefox\extensions\{9ce11043-9a15-4207-a565-0c94c42d590d}\chrome\content\timer.xul %USERPROFILE%\Application Data\SystemProc\lsass.exe
The following registry key is added in order to auto start itself after reboot: ========================================================= [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "RTHDBPL" = "%appdata%\SystemProc\lsass.exe"
It monitors the following Web browsers: ========================================================= Explorer Opera Chrome Firefox
User searches using the following search engines are redirected to another Web site: =========================================================== Google Ask Yahoo! AOL Bing
It monitors the following search terms and pops up advertisement accordingly: ============================================================ cialis pharma casino finance mortgage insurance gambling health hotel travel antivirus antivir pocker poker video baby bany porn golf diet vocations design graphic football footbal estate baseball shop books gifts money spyware credit loans loan dating ebay myspace virus film ipod verizon amazon iphone software movie mobile bank music cars craigslist game sport medical school wallpaper military weather twitter fashion spybot trading tramadol yobt flower cigarettes doctor flights airlines comcast
It searches for the following directories: ====================================================== C:\program files\winmx\shared\ C:\program files\tesla\files\ C:\program files\limewire\shared\ C:\program files\morpheus\my shared folder\ C:\program files\emule\incoming\ C:\program files\edonkey2000\incoming\ C:\program files\bearshare\shared\ C:\program files\grokster\my grokster\ C:\program files\icq\shared folder\ C:\program files\kazaa lite k++\my shared folder\ C:\program files\kazaa lite\my shared folder\ C:\program files\kazaa\my shared folder\
If any of the above directories are found, it duplicates itself (lsass.exe) into the directories. It renames itself into the following names: =========================================================== YouTubeGet 5.6.exe Youtube Music Downloader 1.3.exe WinRAR v3.x keygen [by HiXem].exe Windows2008 keygen and activator.exe [+ MrKey +] Windows XP PRO Corp SP3 valid-key generator.exe Windows Password Cracker + Elar3 key.exe [Eni0j0 team] Windows 7 Ultimate keygen.exe Windows 2008 Enterprise Server VMWare Virtual Machine.exe Winamp.Pro.v7.xx.PowerPack.Portable+installer.exe Website Hacker.exe [Eni0j0 team] Vmvare keygen.exe VmWare 7.x keygen.exe UT 2003 KeyGen.exe Twitter FriendAdder 2.3.9.exe Tuneup Ultilities 2010.exe [antihack tool] Trojan Killer v2.9.4173.exe Total Commander7 license+keygen.exe Super Utilities Pro 2009 11.0.exe Sub7 2.5.1 Private.exe Sophos antivirus updater bypass.exe sdbot with NetBIOS Spread.exe [fixed]RapidShare Killer AIO 2010.exe Rapidshare Auto Downloader 3.8.6.exe Power ISO v4.4 + keygen milon.exe [patched, serial not needed] PDF Unlocker v2.0.5.exePDF-XChange Pro.exe [patched, serial not needed] PDF to Word Converter 3.4.exe PDF password remover (works with all acrobat reader).exe Password Cracker.exe Norton Internet Security 2010 crack.exe Norton Anti-Virus 2010 Enterprise Crack.exe Norton Anti-Virus 2005 Enterprise Crack.exe NetBIOS Hacker.exe NetBIOS Cracker.exe [patched, serial not need] Nero 9.x keygen.exe Myspace theme collection.exe MSN Password Cracker.exe Mp3 Splitter and Joiner Pro v3.48.exe Motorola, nokia, ericsson mobil phone tools.exe Microsoft.Windows 7 ULTIMATE FINAL activator+keygen x86.exe Microsoft Visual Studio KeyGen.exe Microsoft Visual C++ KeyGen.exe Microsoft Visual Basic KeyGen.exe McAfee Total Protection 2010 [serial patch by AnalGin].exe Magic Video Converter 8.exe LimeWire Pro v4.18.3 [Cracked by AnalGin].exe L0pht 4.0 Windows Password Cracker.exe K-Lite Mega Codec v5.2 Portable.exe K-Lite Mega Codec v5.2.exe Keylogger unique builder.exe Kaspersky Internet Security 2010 keygen.exe Kaspersky AntiVirus 2010 crack.exe IP Nuker.exe Internet Download Manager V5.exe Image Size Reducer Pro v1.0.1.exe ICQ Hacker Trial version [brute].exe Hotmail Hacker [Brute method].exe Hotmail Cracker [Brute method].exe Half-Life 2 Downloader.exe Grand Theft Auto IV [Offline Activation + mouse patch].exe Google SketchUp 7.1 Pro.exe G-Force Platinum v3.7.6.exe FTP Cracker.exe DVD Tools Nero 10.x.x.x.exe Download Boost 2.0.exe Download Accelerator Plus v9.2.exe Divx Pro 7.x version Keymaker.exe DivX 5.x Pro KeyGen generator.exe DCOM Exploit archive.exe Daemon Tools Pro 4.8.exe Counter-Strike Serial key generator [Miona patch].exe CleanMyPC Registry Cleaner v6.02.exe Brutus FTP Cracker.exe Blaze DVD Player Pro v6.52.exe BitDefender AntiVirus 2010 Keygen.exe Avast 5.x Professional.exe Avast 4.x Professional.exe Ashampoo Snap 3.xx [Skarleot Group].exe AOL Password Cracker.exe AOL Instant Messenger (AIM) Hacker.exe AnyDVD HD v.6.3.1.8 Beta incl crack.exe Anti-Porn v13.x.x.x.exe Alcohol 120 v1.9.x.exe Adobe Photoshop CS4 crack by M0N5KI Hack Group.exe Adobe Illustrator CS4 crack.exe Adobe Acrobat Reader keygen.exe Ad-aware 2010.exe [patched, serial not needed] Absolute Video Converter 6.2-7.exe
It retrieves the following URLs to fetch commands and download more malware (link currently not working): ====================================================== http://updrandomhottys.com/update.php?sd=2010-03-23&aid=blackout http://updrandomhottys.com/inst.php?aid=blackout
The beginning of this year saw mass Web hosting compromises across numerous hosting providers; thousands of websites were compromised via vulnerabilities in shared hosting providers and as a result, were serving malware. We thought eventually everything would be cleaned up and everyone's operations would be back to normal--but it seems that didn't happen... yet.
Recently a lot of our HackAlert customers are still flagged (by HackAlert) to be serving malware. We noticed a particular group of them today--those that have installed the "Small Business Success Index" widget by Network Solutions. There are two ways one can install the widget into one's website or blog--via the one-click installation script offered by Widgetbox (as seen in Screenshot 1 above), or by directly visiting Network Solution's growsmartbusiness.com (Screenshot 2 below).
Screenshot 2
We quickly registered a Google Blogger account and verified that whoever installed this widget, will be serving malware as of now. Although Widgetbox is only one website providing an installation script for this widget, this site alone has recorded 5,371 installations (yes that "1" is us) already (see Screenshot 1 above). This means more than five thousand sites may be affected.
Here are the steps we went through in our verification process. We first went to Widgetbox and clicked on the "Install Widget" button as seen in Screenshot 1. A popup showed us the javascript to embed, as well as one-click-install buttons for Facebook, Blogger, Twitter, iGoogle, WordPress, LinkedIn, my Yearbook, etc. Yikes:
Screenshot 3
We clicked on "Blogger" and it worked--our armorizetest blog now has the widget installed:
Screenshot 4
Clicking on "Edit" shows the widget's javascript code--it's loading the javascript from cnd.widgetserver.com:
Screenshot 5
Visiting our test blog now shows the widget:
Screenshot 6
And now, our blog is officially serving malware. Scanning this test blog with HackAlert shows that our blog is indeed serving malware now. Here's the traceback:
Conclusion: what a quick way to make your blog, website, facebook, linkedin, all serving malware.
Googling a bit, we verified that the domain growsmallbusiness.com was definitely compromised and injected with a r57shell (webshell), which allowed the attacker easy manipulation of the site. Check this link.
In part 2, we'll detail the actual malware behavior.
Note: We received some questions so we'll answer here. If you are trying to analyze this malware, note that it's quite mean and implements the following behavior: 1. Serves to each IP only once 2. Blocks well-known drive-by download analysis services such as Wepawet and jsunpack. These won't be able to help you in this case--see Wepawet results and jsunpack results.
Read more (rest of article)...
A big thanks to everyone who came to our talk, and to the black hat and DEF CON staff! We've had a lot of fun this year, the conferences rocked! Love it.
Our talks at black hat and DEF CON 2010 are here:
Drivesploit: Circumventing Both Automated AND Manual Drive-By-Download Detection (blackhat and DEF CON)
We presented at Texas Regional Information Security Conference (TRISC) Grapevine, Texas. The conference in itself was highly structured. We discussed about malware infections in web 2.0 environment discussing about various facets of malware infections and the way client machines are actually get compromised. The presentation is rooted below.
We will be presenting our talk at Hacker Halted 2010. Recently, we have been officially interviewed by the Hacker Halted crew about the nostalgia and reality of web application security game. The prime aim is to discuss the artifacts of ongoing realm of security in web application and browsers exploitation.
"Attackers are not exploiting the apps' vulnerabilities. They are exploiting our human vulnerability in allowing our apps to run our lives. Platform of choice? Our browsers. According to a poll by Harris Interactive, we, the adult internet users, spend an average of 13 hours online each week. This writer is online at minimum 16 hours a day. The internet is never more than a meter away from the writer at any time of the day or any place in the world (that has a connection!). Making him very vulnerable."
Armorize Technologies provides next-generation Web application security solutions traversing the System Development Life Cycle (SDLC).
As part of the Armorize Appsec Suite™, SmartWAF™ integrates with both the CodeSecure™ Source Code Analysis platform and the Hackalert™ Malware Monitoring service to provide end-to-end security for Web applications.
Headquartered in Santa Clara, CA, with its R&D center in the Nan Kang Software Park in Taipei, Taiwan, Armorize has a global customer base with clients among finance, telecom, government and technology sector leaders. For more information visit www.armorize.com