At UAB Computer Forensics, we have been tracking the spam bot, Waledac, since March 19th, by checking every so often (like 4 times a minute) all of the domain names that we now are being used to distribute Waledac. We've been making a list of the infected nodes, with the timestamp that we see them distributing Waledac, and offering that list to various network providers. (If you are a network provider/ISP, send me an email to get a pointer to the list, there are around 4,000 US-based IPs on it so far.)
This morning, Packet Ninja Dan Clemens gave me a call asking if I had seen Trend Micro's claim that Conficker was updating. I hadn't seen that, but I had seen emails on one of my secret squirrel mailing lists that Conficker was updating from "goodnewsdigital.com". That didn't make any sense at all to me! We've seen 2,821 IP addresses serving up "plain ole' Waledac" from GND, so far. (See http://www.cis.uab.edu/forensics/blog/gnd.list.txt)
Just to make sure, I went ahead and fetched the current Waledac binary from one of the GoodNewsDigital.com websites, and sure enough, it was Plain Ole Waledac.
MD5: 20ac8daf84c022ef10bc042128ccace6
Currently detected by only 9 of 40 products at VirusTotal
Here's the VirusTotal Link, but the details are here:
AntiVir - TR/Crypt.ZPACK.Gen
CAT-QuickHeal - DNAScan
F-Secure - Packed:W32/Waledac.gen!I
Fortinet - W32/PackWaledac.C
McAfee-GW-Edition - Trojan.Crypt.ZPACK.Gen
Microsoft - Trojan:Win32/Waledac.gen!A
NOD32 - Variant of Win32/Kryptic.LP
Panda - Suspicious file
Sophos - Mal/WaledPak-A
A sad statement of the current state of anti-virus, that a KNOWN MALWARE DISTRIBUTION POINT that has been serving up viruses since mid-March for a large spam botnet is still entirely undetected by 3/4ths of the AV products!
But it gets worse.
I went and read Trend Micro's assertions on their blog . . .
According to Trend Micro they saw new malware arrive on one of their conficker boxes, being dropped not via a website update, as we've all been expecting, but via a Peer 2 Peer connection from other Conficker machines. The new malware arrived via P2P on their box and began attempting to propagate in worm-like fashion looking for MS08-067 vulnerabilities (the same as previous versions of Conficker), as well as opening a webserver on port 5114, and making connections to Myspace, MSN, eBay, CNN, and AOL. After this, the machine downloaded a file from GoodNewsDigital.com, which is, as I mentioned above, a Waledac distribution point.
The file that it downloads though IS NOT THE PRIMARY WALEDAC MALWARE. We retrieved the same file in our labs at UAB (forgive me, but the file is named "fuck4.exe"), and scanned it with VirusTotal as well. This is NOT the file you receive if you visit the Waledac host, as we decribed above, via a normal spam-referred website visit.
Here's what we got from "fuck4.exe" at VirusTotal:
ZERO products detect this as malware. NONE of the 40 sites thought the 418kb executable file was a virus.
VirusTotal Report
Trend is calling the new variant WORM_DOWNAD.E (DownAdUp is an alias for Conficker).
The Trend article certainly has caused some deep thinking here this morning! Thanks to Ivan Macalintal at Trend, and because he thanks Joseph Cepe and Paul Ferguson, we thank them as well!
Wait, why are we thanking Paul Ferguson? I had to go find out. Its because of his excellent documentation on the Peer2Peer nature of Conficker in the Trend Blog on April 4th. While the entire world began watching on April 1st for Conficker to be updated via new malware that was placed on one of the 50,500 domain names that began to be searched on April 1, the bad guys have snuck in the back door and updated Conficker via P2P instead.
Paul got a head start on his Peer to Peer research from the excellent malware researchers at CERT-LEXI in their Blog at CERT-LEXSI.
We'll be contacting more Conficker researchers as the day goes on and trying to determine if ALL the Conficker nodes have just merged with Waledac, or if something else is occurring here.
Showing posts with label conficker. Show all posts
Showing posts with label conficker. Show all posts
Thursday, 9 April 2009
Tuesday, 7 April 2009
Conficker Fears spread fake AV products
April 1st came with a big round of noise about the Conficker worm as media sources lit up to discuss what users should expect when Conficker "C" went live. Conficker came to international attention back in January, when F-Secure announced that 8.9 million computers were infected. We wrote about their announcement as well, Downadup / Conflicker Worm: 8? 9? 10 Million Infected?, discussing the interesting situation of "Collision domains". At the time, the infected Conficker nodes would each calculate possible places, based on the current date, where the bad guy may have left instructions to tell the Conficker domains what to do next. A "Collision domain" is a website which is randomly calculated by the conficker machines, but actually already belongs to a real company.
Having 500 possible "mutation vectors" each day turned out to be a threat that was controlled by the security community as various White Hats stepped up to register the domains BEFORE the Conficker authors could use them to control.
The newsworthy event of April 1st was that Conficker had changed, and beginning on April 1st, there would be 50,000 domain in addition to the 500. So, each day there were 50,500 possible places that the criminals could place a message, and the infected computers would go find it. Each infected computer would still only look for updates on 500 of the possible infected computers, but it still meant that when the criminal placed an update on even one domain, a very large number of machines would become infected. How many machines would be infected can be solved using something akin to the classic Birthday problem, and that has already been addressed very nicely in another blog by Dan Nicolescu over at Microsoft's Malware Protection Center. The short answer though is that if the criminals successfully registered even 50 domains, they would successfully update 39.5% of all their infected machines. So, if even 50 of the 50,500 possible domains are put into effect by the criminals on any given day, more than 1/3rd of the Conficker bots have the ability to radically alter their behavior.
At UAB we are monitoring the 50,500 domains and making a list of all of those that actually have been registered. Most days its between 12,000 and 20,000, and the vast majority of those have been registered by "the good guys". That still leaves between 100 and 200 that are not registered by the good guys which need to be checked out to determine if the criminals are using them. In almost every case so far, its been easy to prove that the domains are "real" domains that have a history and have been kept in proper control. I'm not aware of any "Conficker update" domains that have been seen so far, although one funny thing is that at least one domain belonging to a DIFFERENT criminal has come under scrutiny because Conficker named it as a possible update domain.
That doesn't mean the criminals aren't capitalizing on Conficker. One way they are doing so is by praying on the fear that has been spread about Conficker. Here's one example of what we are discussing:

In this email, which claims to be from Microsoft the reader is told he that "Microsoft was notified by your Internet company that your network is showing signs of being infected" and than offers "a free computer checkup in order to clean any files infected by the virus."
The link, which claims to go to a "Microsoft System Safety Scan website" actually takes you to a fake AV download site that looks like this. Despite the look and feel, this really is just a website:

Another interesting thing about the copy that I reviewed from the UAB Spam Data Mine is that the email was received from a computer that was part of the "Amazon Web Services Elastic Compute Cloud". IP address 79.125.59.137 - ec2-79-125-59-137.eu-west-1.compute.amazonaws.com. I'll have to dig into that later to see if we are getting other "cloud computer" generated spam.
The domain names used in these spam messages are all sharing a nameserver called "ns1.mojavetech.com" and include:
secureserver1.cc
secureserver2.cc
secureserver3.cc
secureserver5.cc
The WHOIS data for these domains, which were registered at "ruler-domains.com" is:
domainadmin@offshorecdn.com
+1.6192988599
150 W Broadway, Mailbox #3
San Diego, 92123
UNITED STATES OF AMERICA
Mr. OffshoreCDN was unavailable for comment at the time this story was filed. The domains were created on March 22, 2009.
WHOIS for the nameserver domain lists:
Company: Mojave Tech Inc.
Address:
9701 Wilshire Boulevard
Beverly Hills, California 90210
United States
Phone: +13103623150
Email: contact@mojavetech.com
The nameserver boxes themselves, 208.85.178.154 and 218.93.205.141, have some interesting aliases as well:
darksideddl.com
do-stepscan.com
prioridns.com
e-securetechnology.com
and my favorite:
www.deloitteandtouche.net
The exact URL in the spam message shown above was:
http://MScustsupport.microsoft.com.custsupport.microsoft5.client5.secureserver3.cc
If you are running an insecure browser, its pretty easy to cause that to download "setup.exe" which is the actual malware.
The good news is that if you do have anti-virus software loaded, there are plenty of products that are detecting this one. The VirusTotal report shows that this malware has been known at VirusTotal since March 31st, and is currently detected by 30 of the 40 anti-virus products it uses to check.
Curiously AVG, F-Prot, and TrendMicro, are currently NOT detecting this malware.
Here's a link to the VirusTotal Report.
Having 500 possible "mutation vectors" each day turned out to be a threat that was controlled by the security community as various White Hats stepped up to register the domains BEFORE the Conficker authors could use them to control.
The newsworthy event of April 1st was that Conficker had changed, and beginning on April 1st, there would be 50,000 domain in addition to the 500. So, each day there were 50,500 possible places that the criminals could place a message, and the infected computers would go find it. Each infected computer would still only look for updates on 500 of the possible infected computers, but it still meant that when the criminal placed an update on even one domain, a very large number of machines would become infected. How many machines would be infected can be solved using something akin to the classic Birthday problem, and that has already been addressed very nicely in another blog by Dan Nicolescu over at Microsoft's Malware Protection Center. The short answer though is that if the criminals successfully registered even 50 domains, they would successfully update 39.5% of all their infected machines. So, if even 50 of the 50,500 possible domains are put into effect by the criminals on any given day, more than 1/3rd of the Conficker bots have the ability to radically alter their behavior.
At UAB we are monitoring the 50,500 domains and making a list of all of those that actually have been registered. Most days its between 12,000 and 20,000, and the vast majority of those have been registered by "the good guys". That still leaves between 100 and 200 that are not registered by the good guys which need to be checked out to determine if the criminals are using them. In almost every case so far, its been easy to prove that the domains are "real" domains that have a history and have been kept in proper control. I'm not aware of any "Conficker update" domains that have been seen so far, although one funny thing is that at least one domain belonging to a DIFFERENT criminal has come under scrutiny because Conficker named it as a possible update domain.
That doesn't mean the criminals aren't capitalizing on Conficker. One way they are doing so is by praying on the fear that has been spread about Conficker. Here's one example of what we are discussing:
In this email, which claims to be from Microsoft the reader is told he that "Microsoft was notified by your Internet company that your network is showing signs of being infected" and than offers "a free computer checkup in order to clean any files infected by the virus."
The link, which claims to go to a "Microsoft System Safety Scan website" actually takes you to a fake AV download site that looks like this. Despite the look and feel, this really is just a website:
Another interesting thing about the copy that I reviewed from the UAB Spam Data Mine is that the email was received from a computer that was part of the "Amazon Web Services Elastic Compute Cloud". IP address 79.125.59.137 - ec2-79-125-59-137.eu-west-1.compute.amazonaws.com. I'll have to dig into that later to see if we are getting other "cloud computer" generated spam.
The domain names used in these spam messages are all sharing a nameserver called "ns1.mojavetech.com" and include:
secureserver1.cc
secureserver2.cc
secureserver3.cc
secureserver5.cc
The WHOIS data for these domains, which were registered at "ruler-domains.com" is:
domainadmin@offshorecdn.com
+1.6192988599
150 W Broadway, Mailbox #3
San Diego, 92123
UNITED STATES OF AMERICA
Mr. OffshoreCDN was unavailable for comment at the time this story was filed. The domains were created on March 22, 2009.
WHOIS for the nameserver domain lists:
Company: Mojave Tech Inc.
Address:
9701 Wilshire Boulevard
Beverly Hills, California 90210
United States
Phone: +13103623150
Email: contact@mojavetech.com
The nameserver boxes themselves, 208.85.178.154 and 218.93.205.141, have some interesting aliases as well:
darksideddl.com
do-stepscan.com
prioridns.com
e-securetechnology.com
and my favorite:
www.deloitteandtouche.net
The exact URL in the spam message shown above was:
http://MScustsupport.microsoft.com.custsupport.microsoft5.client5.secureserver3.cc
If you are running an insecure browser, its pretty easy to cause that to download "setup.exe" which is the actual malware.
The good news is that if you do have anti-virus software loaded, there are plenty of products that are detecting this one. The VirusTotal report shows that this malware has been known at VirusTotal since March 31st, and is currently detected by 30 of the 40 anti-virus products it uses to check.
Curiously AVG, F-Prot, and TrendMicro, are currently NOT detecting this malware.
Here's a link to the VirusTotal Report.
Subscribe to:
Posts (Atom)