[00:00.000 --> 00:00.580] This talk. [00:00.960 --> 00:09.600] And first of all, I really want to thank HOPE conference for allowing us an opportunity to discuss about our research and share our views. [00:09.900 --> 00:14.480] So here I'm going to talk about advancement in botnet attacks and the malware distribution strategies. [00:15.600 --> 00:21.360] So a bit of background of first, like this research has been collaborated, done with my advisor and one of my friends. [00:21.700 --> 00:24.160] And we run like secondary security labs. [00:24.520 --> 00:29.600] And apart from that, it's like our open work and open research that we do. [00:30.700 --> 00:36.400] And I used to work for, like, at the back end or as a contractor for security companies. [00:36.520 --> 00:38.240] As present, I'm working for ISAC Partners. [00:39.060 --> 00:44.160] And so this is just a little background of me and that gives you an idea of what I do and what our team does. [00:44.360 --> 00:47.560] So I'm also a PhD candidate at Michigan State University. [00:49.080 --> 00:51.160] So what are we going to talk about today? [00:51.840 --> 00:53.800] It's like malware paradigm. [00:54.380 --> 00:59.980] We're going to look at the browser malware taxonomy because understanding a taxonomy is really required. [01:00.000 --> 01:02.660] to look at the malware from different perspective. [01:03.020 --> 01:17.200] For example, if we want to dissolve and if we want to design some robust security or protection mechanisms against malware, we need to access of malware that actually provides us with a better opportunity to understand what lies at the core or the crux of the malware. [01:18.120 --> 01:21.800] So we're going to talk about the present-day malware propagation tactics. [01:22.600 --> 01:24.460] And I'm going to run some demos. [01:25.000 --> 01:28.500] And at last, we're going to talk about information-stealing tactics. [01:28.880 --> 01:32.680] Or maybe data exfiltration strategies used by the botnets nowadays. [01:33.000 --> 01:34.020] And a bit of conclusion. [01:35.200 --> 01:45.120] So before starting the concepts that I'm going to discuss in this talk, I want to say, like, there are a plethora of things that a botmaster or the botnets or the bots or the different kind of malware uses. [01:45.120 --> 01:50.560] And it's really hard to, you know, put that all that in a 60-minute talk. [01:50.900 --> 01:56.420] But I've tried my best to pick up the best things that are running pretty good nowadays. [01:56.680 --> 02:02.460] And that's how the botnets actually exploiting the user systems and the network capabilities. [02:03.460 --> 02:04.480] Let's get started. [02:04.900 --> 02:07.680] So before starting the things, I want to raise the bar here. [02:07.680 --> 02:13.600] Like, everything that works in the malware field relates to these three characteristics. [02:13.960 --> 02:15.700] Like, fear, uncertainty, and doubt. [02:16.280 --> 02:26.940] And if you look at it from perspective of psychology and, like, the psychology of botmaster or any attacker, you will find that they try to exploit one or the other things. [02:27.600 --> 02:30.280] If you consider an example of social engineering, right? [02:30.720 --> 02:35.840] And then you get an idea how this works, like, users are having a fear. [02:36.580 --> 02:36.980] Paranoid. [02:37.140 --> 02:38.340] I don't want to open that website. [02:38.560 --> 02:39.620] I don't want to click that link. [02:40.260 --> 02:41.580] And then it comes, like, uncertainty. [02:41.720 --> 02:42.340] What will happen? [02:42.560 --> 02:49.120] I mean, if I click that link, if I go to website, if I use this software, if I run this applet, sort of things like that. [02:49.260 --> 02:49.760] And the doubt. [02:50.420 --> 02:50.820] Yeah. [02:51.060 --> 02:53.460] You don't know what is going to happen in your system. [02:53.700 --> 02:58.780] So all these things, which you used to call a FUD, it works pretty well from malware perspective. [03:00.340 --> 03:03.580] And the paradigm is the devil is in the details. [03:03.940 --> 03:06.640] I mean, for example, why do we analyze malware? [03:06.900 --> 03:12.900] Why do the antivirus companies spend a lot of money in research analyzing malware to build products, building new signatures? [03:13.200 --> 03:14.540] Because that's where the devil lies. [03:14.640 --> 03:21.400] I mean, if they want to work with their antivirus products, then they have to get the details to build signatures, to build memory-driven productions. [03:21.840 --> 03:23.100] And that's how it works. [03:23.300 --> 03:30.220] And so even for exploit-driven scenarios, if you want to exploit a vulnerability, you need to get into the details of that vulnerability. [03:31.280 --> 03:41.060] So, from perspective of analyzing botnet attacks, we have to simulate those attacks, or we have to run that in emulators to see how it works, to get a better understanding of the scenario. [03:42.020 --> 03:45.040] But that's the truth, and that's how it works in every field. [03:46.380 --> 03:49.460] Now, that's what I used to call a reality of the Internet. [03:49.460 --> 04:04.420] I mean, talking about the attackers' bot masters' perspective, and you look at the other scenarios, and when the people try to exploit network infrastructures, and they're sort of like, for example, they want to run botnets in collaboration with browser exploit packs, [04:05.100 --> 04:10.240] and try to exploit the user-driven mechanisms on the client side, and sort of things like that. [04:10.720 --> 04:11.880] I mean, they're anonymous. [04:12.540 --> 04:13.380] They are hidden. [04:13.380 --> 04:17.920] You don't know what is happening at the back end, and what you see is like, it's a sort of gift. [04:18.440 --> 04:20.480] Typical example of social engineering attack. [04:21.400 --> 04:29.040] For another example, you can take like, you're talking to your friend on Facebook, and you suddenly see that there is a message pop-up, hey, you want to go here? [04:29.240 --> 04:30.120] There is a link. [04:30.600 --> 04:32.300] You don't know what it comes from, right? [04:32.680 --> 04:35.520] Maybe the system is infected, or some things like that. [04:35.960 --> 04:37.360] That's what we're going to see later on. [04:37.540 --> 04:40.840] But that is the truth, and that is the reality of Internet nowadays. [04:42.360 --> 04:45.420] Now, let's jump back onto the concepts here. [04:45.880 --> 04:52.480] Like, before talking and providing some of the malware distribution strategies, I want to spend like five to seven minutes on this. [04:53.000 --> 04:58.440] The browser malware taxonomy, actually, we wrote that paper for Wires Bulletin last year. [04:58.860 --> 05:02.400] And that actually gives you an idea how the browser-based malware works. [05:02.860 --> 05:09.420] So, considering the Class A specification, this is the kind of malware that actually installs in the browser itself. [05:09.420 --> 05:14.860] For example, malicious extensions that are being driven to perform like man-in-the-middle. [05:16.480 --> 05:19.180] Replica of attack, which you used to call the man-in-the-browser. [05:20.260 --> 05:21.700] But it works pretty fine. [05:21.840 --> 05:23.800] I mean, it resides in the browser process. [05:23.980 --> 05:30.660] So, it's in the private address space of the browser, and it can harness all the properties of the browser process. [05:31.080 --> 05:35.120] And, of course, it is going to communicate well with the different browser components. [05:35.120 --> 05:38.260] And that's what we have seen recently. [05:38.420 --> 05:40.560] That's where the concept from browser rootkits came. [05:40.960 --> 05:44.260] And that actually belongs to the Class A browser malware. [05:45.500 --> 05:48.660] Talking about the Class B, I mean, so what it actually works. [05:48.880 --> 05:54.640] For example, browser provides an inherited functionality of different kind of things here. [05:54.800 --> 05:57.860] For example, collaborating with other set of software. [05:57.860 --> 05:59.320] For example, plug-in frameworks. [05:59.600 --> 06:02.160] Adobe Flash, Silverlight, Java. [06:02.700 --> 06:07.960] In order to, you know, harness the power of browser, they really need to get into this architecture. [06:09.060 --> 06:13.620] And Class B browser malware specifically exploits the plug-in architecture. [06:13.820 --> 06:15.720] For example, vulnerability in Adobe plug-in. [06:16.300 --> 06:17.440] Vulnerability in Flash. [06:18.140 --> 06:21.640] Google Chrome got compromised in a can-seq respond to on competition. [06:22.200 --> 06:23.740] And so that's what is... [06:24.320 --> 06:27.600] But if you ask me, like, plug-in runs in a separate address space. [06:27.820 --> 06:29.000] It's in a separate process. [06:29.480 --> 06:30.040] And they... [06:30.040 --> 06:32.260] But they're running inside in a sandbox environment. [06:32.540 --> 06:33.160] But that's fine. [06:33.300 --> 06:34.000] I mean, because that... [06:34.000 --> 06:39.440] The complexity is an outcome of the interdependency among various components here. [06:39.860 --> 06:42.940] Like, for example, running of an Adobe in the browser. [06:42.940 --> 06:47.900] It has to be interdependent with the browser communication flow, which we used to call interprocess communication. [06:48.660 --> 06:50.180] And that's how it actually works. [06:50.180 --> 06:55.320] So, any vulnerability in a plug-in frameworks is very well exploited. [06:55.520 --> 06:57.920] And that's how it results in compromise of the browser. [06:59.420 --> 07:00.200] Okay, sorry. [07:00.660 --> 07:02.880] Now, it gets back onto the Class C browser malware. [07:03.160 --> 07:09.060] So, in this particular scenario, this class of malware, I typically use to say, like, a user land rootkits. [07:09.480 --> 07:20.800] And it has a relation within a Class B browser malware because attackers try to exploit a vulnerability in plug-ins and then downloads a specific set of malware onto your system. [07:21.220 --> 07:22.380] And that's how it works. [07:22.500 --> 07:31.460] So, if you look at the diamond box for the malware that we have presented there, like, it has an interrelation or there is an interface between the browser process and the operating system kernel. [07:31.980 --> 07:36.980] So, the user land rootkits are typically used for man in the browser attacks. [07:36.980 --> 07:38.900] And that's how it compromises. [07:39.160 --> 07:47.140] And if you look at and understand the scenario, how hooking works in an operating system, that's how it actually implements in the context of browser. [07:47.500 --> 07:51.560] Being a user land rootkit and the browser runs and then a user application space. [07:52.120 --> 07:56.100] And that's how it's gonna hook different functions in the browser and how it manipulates it. [07:56.420 --> 07:58.080] That's how the man in the browser works. [07:59.320 --> 08:01.700] So, let's talk about the malware lifecycle. [08:02.920 --> 08:09.520] And all the cases that I am going to discuss in this talk is, like, taken from the various case studies that we have done. [08:09.740 --> 08:13.940] And this is another case study that we analyzed for the black hole exploit pack. [08:14.640 --> 08:22.560] Though, I mean, it was one of the most ferocious, I would say, like, the most robust exploit pack which is being used nowadays. [08:22.840 --> 08:30.800] Though there were, like, Phoenix exploit pack, other kind of exploit packs released earlier, and nowadays, nuclear exploit pack is running pretty fine. [08:32.260 --> 08:41.960] So, considering this scenario, it's like any attacker, or if you were an attacker of anybody like a bot master, they try to exploit a vulnerability in high traffic website. [08:42.220 --> 08:43.920] It's pretty general, as we all know. [08:44.480 --> 08:46.480] The idea is to, like, to get the traffic. [08:46.700 --> 08:50.080] I mean, because it's a lot of broad-based attacks, which we used to call as an... [08:50.080 --> 08:54.220] It's not a targeted attack in this scenario from botnet perspective. [08:55.020 --> 08:57.600] So, they exploit a vulnerability in high traffic website. [08:57.860 --> 08:58.780] It works pretty fine. [08:59.180 --> 09:05.360] Now, they want to serve malware, because the user that is coming onto that website clicks some links and get the information. [09:07.180 --> 09:09.780] Next step is to just inject a malicious iframe. [09:10.020 --> 09:14.620] If you want a more stealthy kind of things, you can obfuscate it pretty fine. [09:15.140 --> 09:15.880] And that's the other thing. [09:16.100 --> 09:23.260] So, the snapshots that I provided here is, like, from the analyst perspective, some of the scripts that we have designed customly. [09:23.260 --> 09:27.680] Okay, so this script is actually extracting the scripts, because I don't want to execute that code in my browser. [09:27.960 --> 09:29.880] I don't want to open that web page in my browser. [09:30.100 --> 09:33.340] So, I simply issue a command, okay, extract the scripts in that page for me. [09:33.780 --> 09:38.940] So, it extracted, and I saw that when I was doing the analysis for this one. [09:39.440 --> 09:43.300] Like, there is a code came up, and there was a malicious script inside it. [09:43.720 --> 09:53.640] Then you can do, like, you can also use inbuilt Linux libraries called curl, or wget to get the full source page downloaded onto your analysis machine. [09:54.900 --> 10:02.260] Now, what happens when you see that and deobfuscate the scripts doing a lot of other things, you'll get an idea that a malicious Java applet is there. [10:02.960 --> 10:04.460] And that works pretty fine. [10:04.600 --> 10:08.020] So, if you want to look at the analysis, the slides will be released later on. [10:08.080 --> 10:10.820] You can look at the wireless total plugin and see how that works. [10:11.420 --> 10:15.700] But if you get that idea, you say, like, there is applet.jar, so you need to decompile it. [10:15.820 --> 10:20.320] Just decompile it with any Java decompiler and unchar the files. [10:20.460 --> 10:22.220] And you get an idea that there is... [10:22.220 --> 10:24.580] And it's also downloading the lsauce.exe. [10:25.300 --> 10:35.440] So, I'm not saying it's an irregular executable, but you can say it's a malicious executable that is actually using a file name of the Windows login process. [10:35.600 --> 10:36.960] There's lsauce we used to call. [10:37.160 --> 10:50.480] And if you remember in earlier days, like, when there's, like, Windows Hacking Expose was released, so they have in a fake Jina.dll, which actually hooks into this lsauce process to, you know, key log all your Windows login credentials. [10:52.000 --> 10:53.480] But that's how they use it. [10:53.600 --> 10:59.860] I mean, because they want to use the legitimate processes of process names of various Windows binders and Windows processes. [11:00.680 --> 11:00.820] Okay. [11:01.940 --> 11:08.280] Now, when we decompile the Java applet, we get an idea, like, the Java applet is actually using a VBScript code in it. [11:08.280 --> 11:18.460] And, you know, that VBScript is always being in our first preference for the attackers or the bot monsters to exploit the Windows client-side mechanisms. [11:18.720 --> 11:20.280] And that's how it actually works. [11:21.300 --> 11:33.540] So, it actually, again, that file is there, and it actually downloads, execute the codes, and the user can simply call the shell functions to VBScript, and it works, and your system is infected. [11:34.680 --> 11:48.360] But that's how, actually, why, actually, I pointed this malware lifecycle scenario from Java exploit, because if you're doing analysis nowadays, you see, like, most of the systems that got compromised are because of the Java exploits. [11:48.680 --> 11:52.760] I mean, the latest one is the Java array exploit, and it works pretty fine. [11:54.420 --> 11:58.880] The loading of that malicious bots onto the victim machine is pretty high. [11:59.780 --> 12:08.680] And now, we're going to talk about the strategies, like how to implant malware, we used to call a bots, and the present-day propagation tactics. [12:08.960 --> 12:16.360] Because I'm not going to talk about, like, phishing attacks, which include, like, spear phishing, exploiting some open SMTP relay service and sort of things like that. [12:16.600 --> 12:18.440] Things have changed from that perspective. [12:19.020 --> 12:26.980] And if you talk about phishing attacks, they still exist, and they will till the end of the Internet, because that's where this actually exploits the default design of that. [12:27.840 --> 12:35.760] But with the passage of time, things have changed a bit with the outcome of new proxy-based software and virtual hosting kind of scenarios. [12:36.200 --> 12:37.120] Things have changed a lot. [12:38.380 --> 12:40.560] Let's talk about, like, exploiting web hosting. [12:40.800 --> 12:51.780] Like, we did a study, and we refined that attackers not only want to exploit the high-traffic volume of websites, but they typically want to exploit the servers, which are doing, like, virtual hosting. [12:52.120 --> 12:54.500] Because consider a scenario, I mean, you're... [12:54.500 --> 12:58.460] one particular server is hosting 500 websites. [12:58.460 --> 13:01.400] And one website has a kind of vulnerability. [13:01.900 --> 13:07.320] For example, you can load a malicious file uploading functionality is there, which is not restricted. [13:07.840 --> 13:15.300] Or there's some sort of credentials which were leaked, and the attacker were able to compromise that particular account on the server machine. [13:16.320 --> 13:22.260] But the idea behind virtual machine is that if one website is compromised, you can build the scripts like that. [13:22.420 --> 13:24.800] For example, automated iframe injector. [13:24.920 --> 13:37.080] And if you run that iframe injector in the context or the host name, or typically called as a host providing, or the typical, what you used to call a website, which is hosting on a server. [13:37.500 --> 13:46.260] And that iframe injector actually injects different kind of iframes in all the hosting websites on that particular system. [13:46.400 --> 13:49.400] So, for example, one website is compromised, it's fine. [13:49.580 --> 13:51.060] I mean, but what's with the others? [13:51.180 --> 13:53.120] The other securities also got compromised. [13:54.320 --> 13:59.680] and then we used to study some of the IP providers, really like servers. [13:59.920 --> 14:09.220] They provide like hosting panels, and things like that, some other sphere vulnerabilities like cookie replay attacks with MD5 hashes, and things like that came to exist. [14:09.620 --> 14:15.800] And with the replay attacks, we get access to the hosting panel, and things like that works pretty good. [14:15.800 --> 14:25.580] And, of course, if you get an access to the hosting panel, there are a lot of emails and emailing lists going on where the people used to discuss about their username and passwords. [14:26.040 --> 14:29.160] And from that perspective, you also get to compromise the server. [14:29.400 --> 14:30.960] So these are different scenarios. [14:31.280 --> 14:39.280] But the one is like with compromise of the one website, you can compromise the whole server and then, in fact, the things in a distributed manner. [14:40.600 --> 14:44.960] And that is a snippet of script that we found that one of the attackers was using. [14:45.260 --> 14:49.020] And that is actually a bash script written, and I think so, yeah. [14:49.340 --> 14:58.240] So it actually triggers the automated iframe injection in every website that is being hosted on that server, basically index.html page, things like that. [14:59.560 --> 15:01.240] And this works pretty fine. [15:01.380 --> 15:02.000] Things have changed. [15:02.160 --> 15:03.660] Everything is getting automated. [15:05.880 --> 15:17.320] And, again, we find, like, this is all we know that they used to upload different kind of C99 shells, which actually automates the process of administrating the compromised server. [15:17.600 --> 15:29.060] And this actually gives you an idea that once you upload, like, this, like, C99 shell or other sort of, like, remote web administration shells on the compromised server, you can do much more things. [15:29.740 --> 15:35.760] And because it's all centralized, you access the PHP web page, and you get all the information about the server. [15:35.900 --> 15:37.760] You can execute commands and things like that. [15:38.260 --> 15:44.700] So it, again, comes from the infection scenario of, which we discussed earlier, like exploiting web hosting. [15:46.500 --> 15:48.340] With the use of proxies. [15:48.820 --> 16:00.880] I mean, for example, in certain organizations where you find that you don't have access to Facebook or other sort of domains because they have an app blacklist implemented on the client side or maybe on the server side. [16:01.100 --> 16:05.360] And they don't want, the gateway don't allow, does not allow you to do those things. [16:05.980 --> 16:07.600] That's where the users actually do. [16:07.760 --> 16:11.400] They try to open up a Glyproxy web page somewhere on the Internet. [16:13.560 --> 16:20.100] And I think, like, when we're doing this study, there are, like, some of the other researchers have done, like, studies on Glyproxies. [16:20.100 --> 16:23.280] Like, one of the done in, like, paper release in SANS, actually. [16:23.860 --> 16:27.360] Which actually shows that how insecure the Glyproxies are. [16:27.500 --> 16:33.140] Because people just simply host it and then advertise the main way you can advertise your Glyproxy. [16:33.440 --> 16:38.820] And then the people or the users go there and find that, okay, I want to use this Glyproxy. [16:39.120 --> 16:41.320] And they open it and then start doing the thing. [16:41.860 --> 16:46.600] But when we analyze these things, we try to tune the Glyproxy into attack. [16:47.200 --> 16:51.840] You know, weaponize, basically try to weaponize this Glyproxy from that perspective. [16:52.600 --> 17:00.140] And what we did, like, we did tune that Glyproxy and got an idea, like, it's still possible to inject malicious things. [17:00.440 --> 17:03.660] Typically, malicious scripts on all the proxy-fied web pages. [17:03.880 --> 17:05.080] What that actually means. [17:05.120 --> 17:11.180] A user opens a page and the proxy is going to rewrite all the URLs and everything based on that. [17:11.320 --> 17:18.480] And when you return, when the Glyproxy actually returns a web page, it will inject some malicious script in it. [17:19.060 --> 17:32.260] And that is, like, very disastrous because a simple link to the black hole exploit pad can do the things and the user still feels that, okay, I'm using a Glyproxy, I'm anonymously surfing the things, and other stuff, but they still got infected. [17:33.100 --> 17:40.740] One other thing is that they can also inject a script that actually exfiltrate data that I'm going to demonstrate on Rona video just after that. [17:40.740 --> 17:42.880] And you will see that, how it works. [17:43.460 --> 17:54.700] Because in proxies, what you can do, you can turn off, like, hot linking, things like that, and you configure in such a way that you won't get a, like, status bars when you are accessing the web page of Glyproxy. [17:55.240 --> 17:57.640] And then actually makes the things a bit more anonymous. [17:58.060 --> 17:59.260] And let's take a look at it. [18:04.860 --> 18:16.040] So this demo that gives you an idea how it works, the study that I was discussing about the SENSE one, they also released a lot of information that how insecure these Glyproxies are. [18:16.200 --> 18:25.000] And if you go on Internet and try to do some Google darking and do some brute forcing, you will easily get access to Glyproxies that are available on the Internet. [18:25.600 --> 18:34.160] And another fact is that they used to run a log monitoring mechanism at the backend. [18:34.400 --> 18:37.400] So whatever you send is going to get logged at the proxy. [18:38.140 --> 18:46.680] And again, from attacker perspective, they again get a lot of things like surfing habits and the privacy of the users, how they are actually going on the Internet and exploiting the things. [18:46.920 --> 18:53.980] So what we are doing here is that we actually compromised one of the Glyproxy and conducted a small test. [18:54.700 --> 19:09.480] So if you look at this scenario, what the skip, this parameter is going to do that, it actually going to inject a jQuery, a small plugin that we wrote like five, four or five, six lines, it actually going to inject that jQuery plugin in all the Proxified web pages. [19:13.700 --> 19:17.280] So let's say when a user is actually accessing the page, it looks like this. [19:18.300 --> 19:22.440] And okay, and whatever, it's like Facebook, they want to go through. [19:25.340 --> 19:29.420] Typically, this Glyproxy actually has an inbuilt plugin so you can surf Facebook. [19:29.980 --> 19:34.740] And that have been used by the users a lot in the previous times. [19:35.380 --> 19:38.720] So if you look at this scenario, the user has no idea. [19:38.960 --> 19:43.240] I mean, it's just like I'm surfing anonymous and my organization not knowing about it. [19:45.060 --> 19:46.300] And it works. [19:46.540 --> 19:50.380] So what we did actually, we are not providing any legitimate username or password here. [19:50.540 --> 19:54.340] We're just trying that when we submit a login button, the post request goes up. [19:56.420 --> 19:58.200] And let's look at the source code. [19:59.720 --> 20:06.780] So if you go down, you see that all these links are rewritten by the URL rewriting module of the Glyproxies. [20:07.240 --> 20:13.860] And at the end, you will see that the script is actually get inserted in every web page. [20:14.860 --> 20:25.900] So what that script was doing like, so when you're submitting anything, it is actually picking that post request and sending it to another command and control server, or maybe the server that is hosting the Glyproxy. [20:26.180 --> 20:28.100] And let's look at the log file. [20:29.740 --> 20:38.300] And so this is the code which we used to just redirect all incoming information onto the file. [20:38.540 --> 20:40.320] So this is the file we actually got. [20:41.180 --> 20:45.240] And you can see that we have the email, password, and things like that. [20:47.480 --> 20:48.640] So this is very easy. [20:49.940 --> 20:55.720] Typically when you're accessing any Glyproxy on the public available Internet, how you're going to build a trust. [20:56.040 --> 20:59.400] Because this is somewhat like an exploration of trust boundary. [21:00.620 --> 21:04.520] But in this fast world, people or users don't realize that. [21:04.600 --> 21:08.540] They simply access the things and they don't have any idea what is happening at the backend. [21:09.260 --> 21:13.340] But that's the thing is, so that's what we have in a one demo here. [21:13.520 --> 21:17.020] That actually shows how the Glyproxies can be manipulated. [21:19.520 --> 21:24.760] Now, I put this screenshot because I want to give you an idea like how the obfuscated iframes are used. [21:24.980 --> 21:27.720] This screenshot, I took it from like malware domain list. [21:27.900 --> 21:29.320] And this actually gives you an idea. [21:30.040 --> 21:32.020] Like attackers are simply using a lot of obfuscation. [21:33.600 --> 21:36.110] And it's not that hard to reverse that obfuscation. [21:36.740 --> 21:37.200] It's easy. [21:37.360 --> 21:41.280] And if you know the like hot shots and how to do it, it's very easy. [21:41.280 --> 21:45.140] If you understand the browser-based secure DOM model and all that things. [21:45.400 --> 21:51.560] But this actually gives you an idea that obfuscated iframes are being used at a pretty high scale. [21:52.780 --> 21:56.320] And that's what I want to talk about like is like browser exploit packs. [21:57.560 --> 21:59.580] Typically bundled within exploits. [22:00.860 --> 22:06.560] And these browser exploits like is the kind of sort of like we used to call a PHP-based application. [22:07.480 --> 22:09.340] It's running in MySQL at the backend. [22:09.960 --> 22:14.880] And have all sorts of browser exploits bundled together at one place. [22:14.880 --> 22:19.020] Simple scenario is like, user is going to send a request. [22:19.540 --> 22:19.880] Right? [22:20.160 --> 22:22.460] And it actually comes with the user-agent string. [22:22.700 --> 22:27.700] Which actually gives some attacker in a view of what kind of environment the user is running. [22:28.220 --> 22:38.020] After doing that, they actually fingerprinted according to running up a plugin.js file which actually fingerprint the kind of plugins you were running. [22:38.440 --> 22:44.300] And then, based on that part, they actually get information about the environment and the kind of versions. [22:44.940 --> 22:47.720] Sort of different plug-ins running on the client side. [22:48.400 --> 22:52.660] And if you... I analyzed one of the product or the web-based service released by the colleagues. [22:52.960 --> 22:55.700] They actually used to call like a browser plug-in detector. [22:55.940 --> 22:57.440] It actually verifies it. [22:57.700 --> 23:07.220] It actually uses the same concept and checks the various version of browser plug-ins the user is running and then gives up a notification based on that. [23:07.960 --> 23:09.480] So that actually gives you an idea. [23:09.640 --> 23:17.980] So this screenshot was taken from one of the compromised domain, which actually gives you an idea that browser exploit pack is used in collaboration with the botnets. [23:18.620 --> 23:25.940] So it's on the same server, they are running a browser exploit pack and when the vulnerability in browser is successfully compromised, they deliver the bot. [23:26.420 --> 23:28.600] And that's how this works. [23:28.920 --> 23:30.880] So it's used like different things. [23:31.420 --> 23:40.140] To avoid analysis, they actually fingerprint also your IP address and serves you the exploit only once a time. [23:40.140 --> 23:44.480] So they don't want to serve like different set of exploits to the same IP address more than one time. [23:44.880 --> 23:45.980] But you can do that. [23:46.140 --> 23:47.320] I mean, you can use an... [23:47.320 --> 23:53.400] For example, you can anonymize your IP address on the client side and then you can get the malware again and again. [23:55.380 --> 24:04.180] This screenshot gives you an idea about how the kind of obfuscation is being done or the encoding is being done on the server side. [24:04.180 --> 24:07.980] So this is a web page being encoded using an INCube encoder. [24:08.420 --> 24:13.420] So they are actually proactive in their approach like the attackers or the bot masters. [24:13.640 --> 24:18.420] So when they are hosting this browser exploit packs, they use the PHP INCube encoder. [24:18.780 --> 24:20.460] And that encode all the files. [24:21.060 --> 24:22.580] And it's really hard. [24:22.760 --> 24:23.580] I'm not saying it's impossible. [24:23.740 --> 24:29.500] It's really hard to de-obfuscate this code and get the real things out of it. [24:29.620 --> 24:34.040] That's why we have to emulate it and do the behavioral-based testing on it. [24:35.200 --> 24:44.760] But if you get an idea and see while performing analysis, you will see that the compromised server and you will notice these kind of files on the server side. [24:46.420 --> 24:57.940] And which I've analyzed like last year, looking at the browser Blackhole Exploit Pack and I did a detailed talk on Blackhole Exploit Pack back at Whitehole Splitting Conference last year. [24:58.600 --> 25:03.160] And I analyzed like Java exploits are the typical ones. [25:03.500 --> 25:07.960] And in last year, it was like a Java SMB vulnerability which was exploited the most. [25:08.900 --> 25:11.760] And at present times, it's the Java array exploit. [25:12.120 --> 25:20.020] So if you look at these files, I mean, so we access, perform de-obfuscation of five frames, and then try to access the code. [25:20.180 --> 25:23.920] And we get the idea like it's actually downloading our VLC player file. [25:25.200 --> 25:26.200] Okay, it's fine. [25:26.320 --> 25:36.100] But we need to execute it to see what is happening, how it is manipulating the file system entries, registry entries, network-based infrastructures, and sort of things like that. [25:36.500 --> 25:39.240] But it gives you an error that it's not like that. [25:39.580 --> 25:44.240] And a very simple thing in what we do in the malware analysis is to just tweak the extensions. [25:45.080 --> 25:50.760] So what I did, like, we tweak the extension there and we change it from AVA file to the JAR file. [25:51.000 --> 25:52.120] And then we decompile it. [25:52.280 --> 25:53.480] And that's how we get the exploit. [25:53.780 --> 25:55.340] And it was like Java SMB exploit. [25:56.320 --> 26:00.060] So the idea of discussing about this all facts is like some of the... [26:00.720 --> 26:05.080] I mean, I was used to call it nuts and bolts that one can use while doing analysis. [26:05.340 --> 26:13.120] Because I have seen, like, some of my friends left the analysis because they don't get an idea like, it's an AVA file, it's not working, it's useless. [26:13.120 --> 26:14.900] But no, you're gonna tweak it. [26:15.340 --> 26:17.420] And then get the idea of what is happening at the back end. [26:18.980 --> 26:24.480] And again, came across, like, last six months, this is being used and on JDB. [26:24.740 --> 26:26.420] It's like a drive-by frameworks. [26:26.560 --> 26:31.220] It automatically generates the Java-based exploits and solves you with the malicious applets. [26:31.580 --> 26:38.420] And while you run it, it exploits the Java, install on your client side, and then, you know, your browser and system is compromised. [26:39.060 --> 26:40.580] And that's how it actually works. [26:40.580 --> 26:45.800] So, the idea behind showing this snapshot is, like, everything is getting automated. [26:46.060 --> 26:50.040] Even the attackers, bot masters, they don't have enough time to do everything manually. [26:50.700 --> 26:53.700] Yeah, they do invest a lot of time in designing these frameworks. [26:54.060 --> 26:59.800] But in the underground community, most of the source code you can find or you can take it from the previous version. [26:59.940 --> 27:15.980] For example, in Zeus botnet, SpyEye took the concept of webinjects from there and now the latest one which we're analyzing is NGR bot and then there's an Andromeda and then there's Smoke and then there's a U-Pass botnet. [27:16.080 --> 27:21.000] And some of them are also, you know, taking the source code from that perspective. [27:22.020 --> 27:25.580] A little bit optimizing it, tweaking it according to their own design. [27:25.760 --> 27:26.780] But yeah, it works. [27:27.520 --> 27:33.240] And that actually gives you an idea, and this screenshot actually gives you an idea that how many infections occur through that. [27:34.380 --> 27:35.280] But it works. [27:35.480 --> 27:40.660] The automated infection frameworks are the key things nowadays. [27:42.040 --> 27:44.280] And let's take a look at this demo. [27:46.100 --> 27:54.480] That actually gives you an idea about the fact that why drive-by-downloads are so stealthy and the user is not able to get in. [27:55.860 --> 27:59.180] And that actually gives you an idea how it works. [28:03.800 --> 28:13.360] So I actually designed this video from overall scenario, like you log in into your email account, you get a very tempting email because it has a sort of phished email. [28:13.820 --> 28:15.520] And you click that email. [28:18.300 --> 28:19.540] Let's see how it works. [28:20.600 --> 28:22.700] And of course, URL shorteners. [28:22.800 --> 28:25.380] This is another good thing for optimizing the URLs. [28:26.140 --> 28:29.400] But attackers and the bot masters are also using it. [28:30.460 --> 28:33.460] Specifically, if you remember, the Nigerian fishers. [28:34.440 --> 28:35.380] They do a lot. [28:36.800 --> 28:37.980] So I did like... [28:37.980 --> 28:44.600] I just ran the traffic monitoring code on the client side, which actually gives you what kind of URLs are being accessed. [28:47.320 --> 28:49.400] So I logged into my Facebook account. [28:49.540 --> 28:50.960] It's just a malicious web page. [28:51.780 --> 29:01.120] And if you go down, you will see that this is done kind of very sophisticatedly, I would say like, in a sophisticated manner, it de-obviscate the code. [29:01.920 --> 29:03.520] Really compressed and optimized. [29:04.540 --> 29:07.460] I mean, it's so no easy to, you know, de-obviscate it. [29:07.640 --> 29:16.260] But yeah, if you know, you can tweak the URL with alert and windows.document parameters to just render it without execution. [29:16.980 --> 29:19.580] Yeah, so this page has a this malicious iframe. [29:29.210 --> 29:31.370] Now take a look at the traffic. [29:32.430 --> 29:38.030] I mean, the request, the HTTP request, the get and the post that actually got issued from the victim machine. [29:41.030 --> 29:45.170] And you will analyze that there are two or three different hops are there. [29:45.830 --> 29:56.750] But these all subsequent requests, which actually being issued by the iframe, because it fetches the content from the malicious domain that actually hops from one domain to the another domain. [29:56.750 --> 30:00.130] And then actually downloading the malware onto your system. [30:00.310 --> 30:05.970] But till this point of time, it's really hard to notice whether your system is infected or not. [30:08.290 --> 30:12.110] But this traffic actually gives you an idea that something is there. [30:16.670 --> 30:28.190] So this was done on an infected machine and we ran the malware antibodies, tried to see if it fetches the infection, because that malicious iframe was actually downloading a zspot. [30:28.190 --> 30:30.950] And there are many signatures of zspot. [30:31.090 --> 30:33.650] And the malware antibodies typically picks up. [30:33.830 --> 30:37.370] Because it's a userland rootkit, it's not doing any memory based hooking. [30:37.690 --> 30:39.730] So it's really hard to get the signature. [30:40.510 --> 30:44.630] So you can see that there is another hop out there, which is from the third-party domain. [30:44.970 --> 30:46.870] The URL is downloading the content. [30:54.850 --> 30:59.730] And since we know that we were performing the analysis, this was like a... [30:59.730 --> 31:05.510] It conducted back to this particular domain and you get an idea there isn't a black hole exploit pack running over it. [31:05.770 --> 31:07.790] Gives you any stats and how it works. [31:09.950 --> 31:12.270] And then gives you, like, there isn't a java exploits. [31:15.050 --> 31:15.830] It is fine. [31:16.150 --> 31:28.890] So if you say there is a one notification being raised by the malware antibodies, and if you go back and look at the signature, it gives you an idea that this is a z-bar, and which is actually a zspot. [31:29.630 --> 31:30.890] So that's why... [31:30.890 --> 31:36.750] I mean, it's not a new attack, but it's been an old-school attack, but it's been executed in a different manner. [31:37.290 --> 31:40.210] And it still works very fine. [31:41.350 --> 31:44.510] And that's the culprit code which is actually doing the things. [31:44.690 --> 31:53.750] Because if you consider a scenario, how many users look at the source code even I don't do when I'm doing and processing, and I have, like, some gigs to do, and I don't care for that. [31:54.590 --> 31:59.670] But this actually gives you an idea, the overall scenario, how the drive-by-download attack works. [32:01.970 --> 32:04.350] Now I want to talk about, like, malware on the cloud. [32:04.750 --> 32:16.250] We analyzed this case study when we were doing some research on malware and came across with the fact that Amazon, AWS Cloud, which we used to call, and they actually provide bins to different set of users. [32:16.490 --> 32:20.890] And that bins are used like storage repository, or maybe you can host a website over it. [32:21.750 --> 32:22.930] I got an access. [32:23.270 --> 32:28.710] And the attacker actually hosted this kind of malware onto the Amazon AWS instance. [32:30.150 --> 32:38.450] And, you know, it's not that easy to actually scan all the bins until unless you use the Amazon AWS APIs and then build up a product according to that. [32:38.590 --> 32:42.330] They don't allow you to do the third-party scanning, or a cloud-based scanning. [32:43.010 --> 32:50.970] So, but this actually, the link is actually picked from some of the malware we are analyzing because it was downloading from that link, and it came up to us, and it was very interesting. [32:51.650 --> 32:53.670] So, when you download the malware, it was packed. [32:54.110 --> 32:57.010] And when we did the unpacking, it's things like that. [32:57.670 --> 33:07.590] And then you, when we unpack it, and we got like, it was like a package which is actually downloading like 11 or 12 different set of files. [33:08.350 --> 33:13.030] And every single file is still, again, unpacked with the, like, UPX Packer. [33:14.730 --> 33:22.890] And from this part, you can realize the fact that there's like 10 different kind of malicious files that are being bundled together, and it's getting onto your system. [33:23.270 --> 33:24.050] I mean, come on. [33:24.170 --> 33:25.030] It's not gonna... [33:25.030 --> 33:28.350] So, no production mechanism can support this. [33:28.430 --> 33:31.990] I mean, if it's got installed in your system, you have to reinstall your system. [33:32.830 --> 33:38.670] But until in time, you do that, your system, your information is not yours. [33:40.450 --> 33:43.930] And afterwards, we found that that's how it is. [33:44.370 --> 33:53.530] And, again, scanning with the malware, just wanna give a quick check and every single file raised an alert about that is suspicious. [33:54.090 --> 33:56.010] And it is actually spreading infections. [33:56.330 --> 33:58.350] So, I did a tweet to the Amazon. [33:58.570 --> 33:59.270] They removed it. [34:00.110 --> 34:03.250] And after that, we haven't got any instances serving malware. [34:03.410 --> 34:10.330] But this actually gives you an idea, even the cloud technology or the cloud infrastructure is not untouched by this kind of malware. [34:12.650 --> 34:15.530] And, let's talk about malvertisements. [34:16.010 --> 34:20.150] This is a name that is actually being harnessed from malicious advertisements. [34:21.130 --> 34:33.750] And I've seen that this thing is being used because I've been offered sometimes to do that for some third-party business provider where they want to hijack the advertisements from some other companies. [34:34.030 --> 34:37.450] But that was like an unauthentic kind of thing, and that is not legitimate. [34:38.950 --> 34:43.490] But I'm saying, I'm just discussing this part because the business... [34:45.530 --> 34:50.130] Typically, like I say, different side of businesses are doing it because they want a hits on their products. [34:50.250 --> 34:51.510] They want a hits on their websites. [34:51.810 --> 35:00.790] So they have designed some sort of malicious plugins that install in your browser and hijack Google Ads and replace it with that company website. [35:01.570 --> 35:01.770] Ads. [35:01.990 --> 35:03.470] And that is working. [35:04.710 --> 35:05.110] And... [35:05.730 --> 35:06.130] But... [35:06.130 --> 35:06.710] Consider this scenario. [35:06.870 --> 35:08.830] This was picked up from like Armwri's blog. [35:08.990 --> 35:11.410] They have like a very good graphic for this one. [35:11.570 --> 35:16.430] But if you want to read the Malvertisement paper, it's being available on the slide share that we wrote earlier. [35:16.870 --> 35:18.430] And that actually gives you an idea. [35:18.810 --> 35:24.430] So if you count the hops, one, two, three, four, five, six, it's like seven different hops. [35:25.910 --> 35:32.450] The request has to the advertiser and then there is an ad network, redirector, exploit server, and things like that. [35:33.410 --> 35:34.230] But this... [35:34.230 --> 35:40.790] These kind of things like malicious advertisements are becoming the popular source for downloading malware, typically the bots. [35:41.110 --> 35:43.130] And it's easy because it tempts you a lot. [35:43.290 --> 35:49.050] I mean, you want to get this gift, click on it, and that codes, you know, take your browser to somewhere else which you don't know. [35:49.970 --> 35:51.510] But this works pretty fine. [35:53.570 --> 35:55.530] Yeah, of course, how can I... [35:56.510 --> 36:00.470] You know, This talk will not be complete if I won't talk about like social network exploitation. [36:01.390 --> 36:11.650] So our ongoing research is going over it and it will be completed within the next couple of months where we show exactly the complete model how the social networks are being exploited. [36:11.650 --> 36:23.110] It's not about typically, you know, putting up a URL, things like that, but how the userland root gets actually hooked into the web chat panels of Twitter, Facebook, and then inject messages in that. [36:23.890 --> 36:37.230] But it came us to surprise when we analyze some of the cases like one of the cases that analyzed is using the click-jacking and the light-jacking at the same time and then injecting malicious links on your Facebook profiles. [36:37.670 --> 36:39.930] It works very well and it's very... [36:39.930 --> 36:42.690] I would say like it's very dangerous, this attack. [36:48.710 --> 36:54.050] The only thing that you require is if you remember like cross-site request forging, you have to be in a session. [36:54.250 --> 36:57.030] Typically, it means like you have to login into the Facebook account. [36:57.850 --> 37:01.170] And let's say this is a profile and... [37:03.750 --> 37:08.210] of the user who is actually visiting his profile, trying to send messages to some other users. [37:08.490 --> 37:10.130] And this is a malicious web page. [37:10.250 --> 37:14.750] Like I open another web page and I want to surf that web page and it's malicious. [37:15.390 --> 37:20.290] So if you remember, if you look at the mouse cursor there, you will see that there's a like button. [37:21.110 --> 37:22.450] And you can make it transparent. [37:23.170 --> 37:30.910] And I actually tweak a bit of code which I actually extracted from one of the malicious domain which is actually using this kind of technique. [37:31.350 --> 37:33.670] And I retested it and it was pretty good. [37:33.890 --> 37:38.330] So this is a code they are actually using sending HTTP request in query. [37:39.990 --> 37:46.470] And it means if you consider the whole screen width and the length, you click anywhere. [37:47.550 --> 37:48.750] Let's say I clicked it. [37:51.150 --> 37:56.730] So if you see there is a post request that is being issued onto the Facebook content delivery network. [37:57.610 --> 37:58.970] And it starts with 200. [37:59.170 --> 38:00.350] Okay, it means it is accepted. [38:03.400 --> 38:08.900] And I go back and then I refresh my page and it gives you that like link. [38:10.300 --> 38:10.780] Right? [38:11.620 --> 38:12.760] It should be malicious. [38:13.060 --> 38:14.040] It has to be malicious. [38:14.640 --> 38:21.640] And when you click on that link you will be redirected somewhere on this like what a beautiful song by this singer. [38:23.420 --> 38:24.980] So what the attacker did like. [38:25.160 --> 38:29.320] So this was like a POC I posted for showing that how it can redirect to malicious domain. [38:29.580 --> 38:34.980] So this Windows Media Player file has a back door in it which actually downloads the malware for you. [38:35.280 --> 38:45.320] I mean, so even if you look at the source code until unless you want to disassemble this WMV file, you won't be able to get the malware until unless you do the behavioral analysis. [38:46.520 --> 38:49.500] So that is the concept behind social network exploitation. [38:49.500 --> 38:54.120] A small POC that gives you an idea that how it is still getting exploited. [38:55.080 --> 38:59.380] And I think it is a pretty good attack in spreading malware. [39:01.360 --> 39:14.580] So I want to talk about now the present day botnets and one of the most appropriate technique they are using and how they have came across with different set of techniques and they stick to that technique. [39:15.660 --> 39:16.260] Let's see. [39:17.000 --> 39:18.700] It comes with the man in the browser. [39:19.360 --> 39:32.820] I mean, so if you remember we are all talking about like man in the middle which actually like compromising the two endpoints, having an accession going on and then, you know, acting a third party between that and then compromising that network channel between two endpoints. [39:33.120 --> 39:34.920] But what happened with man in the browser? [39:35.320 --> 39:41.460] It's like, okay, I want to compromise your communication channel in the browser. [39:42.020 --> 39:45.500] That would actually the MITB agent does. [39:47.340 --> 39:50.640] Typically an example of userland rootkit it resides in your system. [39:51.600 --> 39:55.080] But as you know in userland you can hook, right? [39:55.660 --> 39:56.240] There is that... [39:56.680 --> 39:58.640] I think there are many techniques you can do that. [39:58.700 --> 40:00.760] It starts with like, for example, hooking. [40:00.940 --> 40:02.980] You can do it with like imported rest table hooking. [40:03.360 --> 40:11.500] You can do it with like inline hooking which I always feel like one of the most sophisticated attack techniques where you implement a deter and the trampoline functions. [40:12.160 --> 40:14.160] And do the jump in the first five bytes. [40:14.340 --> 40:14.820] It's a simple thing. [40:15.060 --> 40:16.700] Then there is a DLL injection base. [40:16.880 --> 40:20.100] You can typically inject a DLL in the registry entry. [40:20.220 --> 40:22.420] There is a name called app in a DLL. [40:22.800 --> 40:24.980] You can do the set windows, hook EX. [40:25.180 --> 40:26.640] You can do the create remote thread. [40:27.420 --> 40:32.140] If I remember, one more is like APC based which zero access malware did. [40:33.560 --> 40:35.180] Many ways to perform hooking. [40:36.900 --> 40:38.560] You know, some you get it. [40:38.680 --> 40:41.280] So you can detect some of the hooking techniques very easily. [40:41.600 --> 40:44.960] But like for like memory base, like inline hooking, it's really hard to detect. [40:45.840 --> 40:52.760] So two-factor SSL authentication, things like that, SSL implementation is not going to protect you against from these kind of attacks. [40:52.960 --> 40:54.340] Because it's inside your system. [40:54.580 --> 40:57.240] And they can, they are going to do something really nefarious. [40:58.820 --> 41:04.380] Typically came to exist with the existence of third generation botnets. [41:04.580 --> 41:10.300] Why I used to call a third generation because they exploit, harness the power of HTTP communication channel. [41:10.560 --> 41:16.440] Like HTTP protocols and get post requests, get the idea, and get the information, then act according to it. [41:16.740 --> 41:19.400] First generation botnets use IRC based protocol. [41:19.620 --> 41:21.500] Second generation, I think used P2B. [41:22.020 --> 41:24.780] And they, of course, they are a hybrid which can use anything. [41:25.380 --> 41:28.260] All of these three, but really good. [41:28.400 --> 41:30.320] This attack is really, really good. [41:32.320 --> 41:37.820] So what they did, I mean, so they, so they extracted this technique, which we used to call a webinjects. [41:39.380 --> 41:50.600] It's similar to like a cross-site scripting, but in a cross-site scripting, you are not on a, on a user machine, you are on a third party domain, send up a URL, you know, trigger script, which actually downloads something from the third party domain. [41:51.060 --> 41:56.060] But in this particular case, the malware is in your system, the bot is inside your system. [41:56.980 --> 42:01.560] So whatever you send a request to facebook.com, and your HTTP response is coming back. [42:02.120 --> 42:12.400] In that case, they have built a scenario, there is a typically file call as like webinjects.txt, which has in our patterns, which has in our rules defined in it. [42:12.820 --> 42:28.380] So it says like, if there is in a facebook.com is being, you know, a request is being sent to facebook.com by the user, whenever the response is coming back, inject a particular input box, or inject a particular javascript before this tag, or before that tag. [42:29.160 --> 42:34.920] Which actually is a very, very, I think, artistic technique, based on static rule sets. [42:35.200 --> 42:38.500] And this actually gives you an idea here, that how it is done. [42:38.640 --> 42:49.120] So this is, this is one of the webinjects rule, that we extracted from a malicious, which used to call infected machine, and they have in a webinjects.txt file. [42:50.180 --> 42:55.600] And that bot is actually reading this, this kind of code, and injecting into the HTTP responses. [42:57.820 --> 43:13.120] And another set of rules that, so if you remember, I've seen like some of the protections that are implemented by the Citibank, last year, has been subverted through webinjects, because they got like, they, some of the webinjects that we analyze, they actually build up their own cookie, [43:14.060 --> 43:18.680] and then do the things, to you know, really compromise the session. [43:19.300 --> 43:20.980] But this works pretty fine. [43:21.480 --> 43:33.660] And if you want to read more about, there's in a blog entry that we posted, but our research, the upcoming research is, going to build some defense mechanism, like defensive mechanism, to protect against webinjects. [43:33.960 --> 43:37.960] And this screenshot gives you an idea, that how it works. [43:38.440 --> 43:44.120] It's a simple example, you get like an inject, so there's like three different tags, set URI. [43:44.120 --> 43:46.400] You want to set the URL against the domain name. [43:47.020 --> 43:50.960] There is a GP, which actually gives you an idea, it's in a get request, and a post request. [43:51.740 --> 43:55.400] Data before, data after, and data end. [43:55.520 --> 44:06.040] That actually gives you an idea, in which part of the web page, you want to inject your script, to look at it as an inline, so that, it won't impact the CSS layout of the web page. [44:06.040 --> 44:07.600] And that's how it works on the site. [44:07.700 --> 44:11.820] So if you look in on the right side, in the title bar, the inject is here. [44:12.700 --> 44:14.860] Because it injects in the title bar. [44:15.360 --> 44:16.720] And you can do many things. [44:16.860 --> 44:20.920] You can inject JavaScript, do the automated transfers. [44:21.360 --> 44:26.760] But that is really complex, because the attacker has to come up with the solid rules, to do that. [44:27.440 --> 44:34.980] And it is very specific to domains, because it might be possible, that Chase Bank is not using the same production, as the Citibank. [44:35.200 --> 44:36.860] So it has to be a website specific. [44:38.760 --> 44:41.120] Another one I want to talk about, is the web fakes. [44:41.560 --> 44:45.280] And I don't want to go deeper, into the DNS changer malware. [44:46.140 --> 44:50.700] But this is a web fakes, a similar technique based on the hooking. [44:52.500 --> 44:54.580] And it came from the SpyEye. [44:55.220 --> 45:00.760] And in SpyEye, they have a plugin architecture, a plugin kind of framework, which actually implement this thing. [45:00.960 --> 45:06.960] So if you want to open a facebook.com, it's going to open you a different kind of domain. [45:07.800 --> 45:11.720] And different parameters are defined in this way, because these are the static parameters. [45:12.020 --> 45:17.900] The attacker define it, the bot read those parameters, and then perform the fakes. [45:18.120 --> 45:19.360] And how it looks like, let's see. [45:20.540 --> 45:25.180] So these are the callback functions that SpyEye uses, to perform the web fakes. [45:27.160 --> 45:33.920] And, yeah, you get an HTTP response, and maybe the user is trying to send up a request, to the third party domain. [45:34.060 --> 45:35.240] I want to open this URL. [45:35.620 --> 45:37.080] It says, okay, don't worry. [45:37.440 --> 45:39.780] So, you're going to call up these callback handlers. [45:40.080 --> 45:44.100] And when these handlers are executed, you will see something like this. [45:45.640 --> 45:47.100] And it's in the Bank of America. [45:47.100 --> 45:52.860] your browser shows it's legitimate, and it's an SSL, I think, notification, for, like, a proper certificate and stuff. [45:53.340 --> 45:56.180] And that's how you get an ID on the Internet Explorer. [45:56.360 --> 46:01.580] It might not having, like, SSL one or something like that, but it's a different page that gets displayed. [46:02.480 --> 46:13.420] And in web fakes, it actually manipulates the DNS entries, to some extent, but also manipulates the CSS layout of the web page, and then putting something else over it. [46:14.120 --> 46:15.660] But it's a real-time example. [46:16.960 --> 46:25.820] And the last thing that I want to talk about is, like, form-grabbing, which I have just shown you a bit of earlier in Glyproxies, but I'll be showing a demonstration on the Chase Bank. [46:27.180 --> 46:38.880] And if you go nowadays and open up the cheesebank.com, on the left-hand side, below the username and a password box, you will see that check for the virus alerts and things like that. [46:39.040 --> 46:49.460] And if you go into their fraud column and they say, they talk about don't put your information in a malicious pop-up, which is being generated on the infected machine. [46:50.020 --> 46:53.880] And that pop-up is because of web injects that we have discussed earlier. [46:54.060 --> 46:56.180] And that's how it actually exploits it. [46:56.680 --> 47:01.540] It generates a malicious pop-up and asks you for, like, give me your SSN number, account, and sort of things like that. [47:02.500 --> 47:05.700] But do go and check on chase.com, and it's still there. [47:06.720 --> 47:08.040] And this technique... [47:08.040 --> 47:12.720] This technique is, I say, like an advancement, like key logging technique. [47:13.840 --> 47:15.120] What happened in key logging? [47:15.300 --> 47:25.860] Like simply, okay, just implement a callback handler whenever the window sends up in a WM underscore key star messages, hook it, and then put that in log file and do it. [47:26.580 --> 47:33.800] But what the attackers realize is that they're actually getting a lot of garbage data, which they don't want. [47:33.800 --> 47:38.820] They only want a specific post request, the data which is being in the input forms. [47:39.120 --> 47:46.700] Because if you go and search for some underground forums and things like that, you will see that it depends upon how sophisticated your logs are. [47:47.140 --> 47:48.400] And then how you get... [47:48.400 --> 47:51.060] And then the buyer will pay according to that. [47:51.340 --> 47:53.420] And that's the thing is, and it's been a... [47:53.420 --> 47:56.440] I've seen like many advertisements on the underground forums. [47:57.320 --> 48:06.240] But this concept from grabbing, like initially implementing virtual keyboards, and you fill those things on a virtual keyboard and the request actually being... [48:06.240 --> 48:14.500] So in this particular case, when you submit it, the virtual keyboard and the mechanism they have implemented simply sends the form request. [48:14.840 --> 48:21.960] And in those cases, you won't get a key log data because you have not pressed anything on your keyboard and the window sends up like Windows messages. [48:22.840 --> 48:23.960] Yeah, it's not like that. [48:24.120 --> 48:24.880] It's a web-based. [48:25.260 --> 48:28.500] So the attacker came across, okay, why not to explore this technique? [48:29.920 --> 48:31.360] So how they do like... [48:31.360 --> 48:33.440] They still implemented like a browser-based hooking. [48:33.740 --> 48:36.740] And in this particular thing, if say like... [48:36.740 --> 48:46.580] In previous times, the samples that we analyzed were doing DLL injection, but now at the times, they are doing it on inline hooking, which makes this really good. [48:47.060 --> 48:59.740] And if you say like, it's inject DLL or it performs inline hooking and it hooks PR underscore write function in the Mozilla NSPR4 dot DLL library and secure 32 message in Internet Explorer. [49:00.160 --> 49:03.000] I think yes, secure 32 DLL library for encrypt message. [49:03.660 --> 49:11.260] Another thing is like, they can also hook into WinInet DLL, which sends up like all the HTTP Win APIs requests to the remote domain. [49:12.320 --> 49:13.100] So that's the thing. [49:13.180 --> 49:13.840] That's how it works. [49:14.060 --> 49:31.140] So the idea is like, whenever you try to fill something in the forms, login forms, anything, and you submit it, bot gonna come up, it hooks it, sends it to the command and control server, and your request still relate back to the, like legitimate, to me. [49:31.360 --> 49:33.060] And let's see how this works. [49:36.290 --> 49:39.990] So this, this demonstration show you how the iSpot works. [49:40.270 --> 49:41.710] And this is a real-time demo. [49:42.090 --> 49:45.310] We analyze and reverse the binary, get the idea how it works. [49:45.870 --> 49:53.190] And if you get here, so what I'm doing like, I have an assemble, I'm executing it on my emulator here. [49:56.030 --> 49:58.770] Typically a virtual machine that we use to perform analysis. [49:59.190 --> 50:02.270] And that actually gives you an idea that is in a simple executable. [50:03.890 --> 50:05.510] So when I execute it, [50:08.900 --> 50:10.220] it waits for a bit. [50:13.250 --> 50:16.970] And when I refreshes it, it melts away. [50:17.450 --> 50:28.070] So because most of these bots have like a self-destructible code, like they can simply inject an MLE, we should say like simply inject a batch file in it. [50:28.270 --> 50:31.050] Okay, delete the dropper, when you install the bot. [50:32.710 --> 50:36.470] And now I'm logging into the command and control server of the iSpot. [50:40.330 --> 50:41.650] So you see that, [50:44.700 --> 50:47.100] I get all the lists of the bots that were infected. [50:48.640 --> 50:51.920] And while I'm doing this, like just try to show that our system is infected. [50:52.200 --> 50:54.540] When I get an open, like my IP address is this. [50:56.100 --> 51:00.820] And when I go back, so you see that, that IP address is there. [51:01.160 --> 51:04.280] And it means that our system is infected with that bot. [51:06.840 --> 51:09.100] So we are confirmed, it's infected here. [51:09.880 --> 51:11.800] Now let's open a Chase Bank website. [51:16.950 --> 51:21.950] Yeah, so if you go and now look at the Chase Bank, so below that box, you will see the alert notification. [51:22.350 --> 51:24.430] So I'm not giving a legitimate credentials. [51:24.550 --> 51:27.070] Of course, I'm not supposed to do that. [51:27.290 --> 51:29.090] But I'm sending the request here. [51:29.810 --> 51:32.210] I'm also opening a legitimate Facebook here. [51:38.910 --> 51:46.330] Just try to show that it works across every website you open in your browser on the infected machine. [51:47.690 --> 51:50.590] So I didn't send the legitimate, you know, credentials. [51:51.010 --> 51:52.250] But the request is sent. [51:52.410 --> 51:53.570] That's why you get in this idea. [51:53.570 --> 51:57.650] The response back from the server that it got it. [51:58.350 --> 52:00.690] Now let's get back to the command and control server. [52:01.030 --> 52:06.170] So if you see at the bottom, you get that request. [52:06.450 --> 52:07.850] And that's how it looks like. [52:08.570 --> 52:12.990] The bot ID is this, botnet is ice9, what kind of version is being there, everything. [52:13.450 --> 52:15.270] And that's your post request. [52:18.400 --> 52:20.540] So your account is here, right? [52:21.780 --> 52:25.380] And typically, if you look at the user input field, this is like a key log data. [52:25.540 --> 52:28.820] But that key log is only restricted to the input forms here. [52:29.020 --> 52:31.620] It's not to the whole system data. [52:32.080 --> 52:33.620] And this log is optimized. [52:34.200 --> 52:35.900] It's a sophisticated log. [52:35.900 --> 52:41.240] And it's gonna get a more value in the underground community when the bot master is going to sell it. [52:47.130 --> 52:49.690] Yeah, so typically with the Facebook, we go back. [52:53.100 --> 52:57.360] And when we refresh it, our command and control panel, we get the Facebook too. [53:04.620 --> 53:07.480] Yeah, so we get the post request and all the data that we want. [53:07.480 --> 53:17.060] So considering this bot, I don't want to infect and do some like different kind of attacks if I can simply infect your system with this kind of malware. [53:19.980 --> 53:21.020] And that's... [53:21.020 --> 53:23.500] it's in our latest size spot, which is an... [53:23.500 --> 53:26.640] I would say like advancement in some of those use code. [53:28.560 --> 53:37.660] And there's another information stealing tactics like credit card grabbers, certificate grabbers, socks, packnacks, webcam hijacker, infecting messengers, and things like that. [53:37.840 --> 53:42.340] But there's a lot of study on that too, which I cannot put in this talk. [53:42.720 --> 53:47.300] But the overall concepts that I have discussed in that are being used heavily. [53:47.720 --> 53:53.660] And if you look at these kind of characteristics are being provided by all different bots nowadays. [53:54.160 --> 53:56.000] And we are open to questions. [53:56.480 --> 53:56.580] Yep. [54:05.010 --> 54:10.870] How effective are drive-by install of these bots on Macintosh and Linux systems? [54:12.790 --> 54:15.370] Yeah, so if you remember, like... [54:15.370 --> 54:17.870] I'm not sure, but there's like... [54:17.870 --> 54:24.550] like four months back, there was a case study on Veiland Yutani bot, which is actually impacted the Mac OS X. [54:24.790 --> 54:35.030] It actually exploits the Flash vulnerability, though I'm not saying it's exploiting the vulnerability in Safari itself, but it exploited the vulnerability in Flash plugin of some Safari components. [54:35.030 --> 54:44.550] And I did follow the same attack pattern to install the form grabber, the bot that actually does the perform grabber on the Safari, on the Mac machines. [54:45.150 --> 54:46.770] And it worked pretty fine. [54:46.970 --> 54:48.230] Though there is a... [54:48.230 --> 54:49.030] the factors... [54:49.570 --> 54:52.870] the numbers are pretty less, for considering the Mac-based malware. [54:53.490 --> 54:57.910] But, yeah, we have seen that, but maybe in the later time we'll see much more. [54:59.850 --> 55:01.210] I hardly find it. [55:01.870 --> 55:05.930] Maybe back doors are there, but that's why we love Windows. [55:06.830 --> 55:07.230] Yeah. [55:07.990 --> 55:08.170] Yep. [55:11.200 --> 55:12.040] I didn't get you. [55:20.660 --> 55:31.880] See, considering on a big traffic, like most of like, if I remember, like there's a firm's call, like I'm just talking about from a business perspective, there's a Dembala firm, which actually monitors all your DNS-based traffic. [55:32.860 --> 55:34.460] And try to find... [55:34.460 --> 55:38.920] implement the blacklisting techniques, and how to interpret the DNS fluxing at the backend. [55:39.160 --> 55:46.960] And that actually gives them the idea that rather they want to flag that domain, because if you do that, you won't be getting another set of malware. [55:47.100 --> 55:49.620] For example, reverse honeypots do that. [55:49.800 --> 56:00.560] I mean, they implement a blacklist technique, a blacklist, and it's like whatever the request that is coming out, or any command and control server present outside the domain, if communicating back to your system, they won't allow that. [56:01.160 --> 56:08.360] But that's a simple thing, but it's like more of like, I think like a user-specific, like they exploit the user's ignorance, and things like that. [56:09.160 --> 56:10.540] But it's a... [56:10.540 --> 56:11.940] I say it's a law of asymmetry. [56:12.220 --> 56:19.680] I mean, it's a never-ending game, but whoever wins, if we can delay execution of botnet to eight months, we can still save a lot of money. [56:19.680 --> 56:22.220] And that's what the art is all about. [56:25.600 --> 56:26.200] Yep. [56:26.600 --> 56:26.860] Thanks. [56:26.860 --> 56:26.880] You're welcome. [56:27.140 --> 56:27.280] Thank you.