Saturday, June 30, 2007

More greeting card spam

The greeting card spam wave continues. Subject lines vary somewhat; here's a sampling from today:
  • You've received a greeting card from a class-mate!
  • You've received a greeting card from a colleague!
  • You've received a greeting card from a family member!
  • You've received a greeting card from a friend!
  • You've received a greeting card from a neighbor!
  • You've received a greeting card from a school mate!
  • You've received a greeting ecard from a class-mate!
  • You've received a greeting ecard from a colleague!
  • You've received a greeting ecard from a family member!
  • You've received a greeting ecard from a friend!
  • You've received a greeting ecard from a neighbour!
  • You've received a greeting ecard from a partner!
  • You've received a greeting ecard from a worshipper!
  • You've received a greeting postcard from a colleague!
  • You've received a greeting postcard from a family member!
  • You've received a greeting postcard from a friend!
  • You've received a postcard from a class-mate!
  • You've received a postcard from a colleague!
  • You've received a postcard from a family member!
  • You've received a postcard from a partner!
  • You've received an ecard from a partner!
  • You've received an ecard from a worshipper!
They are now linking to IP addresses (as opposed to .hk sites in the early stages).

The Internet Storm Center has an excellent analysis.

Here's a sample 'index.html' file:


The hex code goes on for awhile:


The file is obfuscated with XORed hexadecimal. The key in this case is '227' (it changes with each copy, for a simple form of polymorphism). This perl snippet will decode the XORed hex:

perl -e 'while(<>){
s/\\x([a-f0-9]{2})/chr(227)^pack(C,hex($1))/eg;print;}'


If you are analyzing your own code, change the '227' in the perl code to match the key in the index.html file.

The de-obfuscated code looks like this:


Among other nastiness, it retrieves the file http://XX.252.250.104/file.php, which is really a Windows executable that BitDefender identifies as: "Generic.Malware.dld!!.2526793B"

Tuesday, June 26, 2007

HK greeting card malware

Beginning this morning we received a torrent of 'greeting card' malware, linking to domains in Hong Kong.

The excellent Chinese Internet Security Response Team has a blog entry on this attack.

Sites today include 'menot', 'notme,' and 'catcher,' all in the .HK tld.

The attack appears highly widespread. Avira detects EXP/iFrame.D.1 in the drive-by javascript included in the site's 'index.html' file, and TR/Small.DBY.DH in ecard.exe (helpfully offered if the drive-by exploit fails, with the text "the We are currently testing a new browser feature. If you are not able to view this ecard, please click here to view in its original format.)

The spams look like this:

---------------------------------------------------------------------
From: "*****.hk"
To:
Subject: You've received a postcard from a family member!
Date: Tue, 26 Jun 2007 19:19:33 -0500

Good day.

Your family member has sent you an ecard from ******.hk.

Send free ecards from ******.hk with your choice of colors, words and music.

Your ecard will be available with us for the next 30 days. If you wish to keep the ecard longer, you may save it on your computer or take a print.

To view your ecard, choose from any of the following options:

--------
OPTION 1
--------

Click on the following Internet address or
copy & paste it into your browser's address box.

http://******.hk/?XXXXXXXXXXXXXXXXXXXXXXX

--------
OPTION 2
--------

Copy & paste the ecard number in the "View Your Card" box at
http://*******.hk/

Your ecard number is
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

Best wishes,
Postmaster,
*****.hk

*If you would like to send someone an ecard, you can do so at
http://*********.hk/

Thursday, June 21, 2007

'BBB.org' spearphishing attack

I've seen a number of fake 'BBB.org' emails, spammed to senior positions.

The Better Business Bureau's official site describes the attack.

I attached a cleaned-up copy below, with headers.

The emails contain an attachment, in these cases called 'Document_for_Case.doc'. It's an RTF (Rich Text Format) document that contains a malicious embedded object; here's the beginning of that file:

{\rtf1\ansi\ansicpg1252\deff0\deflang1033{\fonttbl{\f0\fswiss\fcharset0 Arial;}}
{\*\generator Msftedit 5.41.15.1507;}\viewkind4\uc1\pard\f0\fs20 This document contains an embedded object. To open it double-click the icon.\par
\par
{\object\objemb{\*\objclass Package}\objw2325\objh765{\*\objdata
01050000
02000000
08000000
5061636b61676500
00000000
00000000
882e0000
0200446f63756d656e74735f666f725f436173652e70646600433a5c41444f4245527e312e4558


That document scans 'clean' by most virus scanners. On 6/21/2007 Virustotal.com reported that only 9 of their 30 scanners spot it.


This attack may be fairly damaging, given that weak antivirus coverage, the fact that it's a legitimate '.doc' file (typically allowed through internet mail relays, unlike exe's which are sometimes blocked), and due to the fact that it's targeted at a small number of senior users.

Here's the email, somewhat cleaned up. The original was in html format:

Received: from smtp.tele.fi (smtp.tele.fi [192.89.123.25])
by *****.*****.org (Postfix) with ESMTP id 0AAC85F13D4
for <*****@*****.org>; Thu, 21 Jun 2007 09:05:37 -0400 (EDT)
Received: from mailgw.benefon.fi (unknown [194.197.24.10])
by smtp.tele.fi (Postfix) with ESMTP id 38E97AE182
for <*****@****.org>; Thu, 21 Jun 2007 16:05:03 +0300 (EEST)
Received: from localhost.localdomain ([192.83.5.2])
by mailgw.benefon.fi (Lotus Domino Release 5.0.9)
with SMTP id 2007062116045807:59067 ;
Thu, 21 Jun 2007 16:04:58 +0300
From: Better Business Bureaus
Subject: Complaint Case Number 450596111
MIME-Version: 1.0
Date: Thu, 21 Jun 2007 16:04:58 +0300
Message-ID:
Content-Type: multipart/mixed; boundary=38ACD4BC0E5E9B20090A53C405940998
To: undisclosed-recipients:;

Dear Mr./Mrs. ***** *****

You have received a complaint in regards to your business services. The
complaint was filled by Mr. ***** ***** on 6/19/2007

Complaint Case Number: XXXXXXXXXX

Complaint Made by Consumer Mr. ***** *****

Complaint Registered Against: Company ********************

Date: 6/19/2007

Instructions on how to resolve this complaint as well as a copy of the original complaint are attached to this email.

Disputes involving consumer products and/or services may be arbitrated.
Unless they directly relate to the contract that is the basis of this dispute
the following claims will be considered for arbitration only if all parties
agree in writing that the arbitrator may consider them:

- Claims based on product liability;
- Claims for personal injuries;
- Claims that have been resolved by a previous court action, arbitration, or written agreement between the parties.

The decision as to whether your dispute or any part of it can be arbitrated rests solely with the BBB.

The BBB offers its members a binding arbitration service for disputes involving marketplace transactions.

Arbitration is a convenient, civilized way to settle disputes quickly and fairly, without the costs associated with other legal options.

© 2003 Council of Better Business Bureaus, Inc. All Rights Reserved.

Tuesday, June 05, 2007

Upcoming conferences and SANS Monterey

I will teach SANS Management 414: SANS® +S™ Training Program for the CISSP® Certification Exam in St. Louis, beginning this Monday:

http://www.sans.org/stlouis07_cs/


Community SANS Portland Maine 2007 was just announced, beginning August 20th. It's Hacker Techniques (Security 504), in 'bootcamp' style. It's SAN's first conference in Maine.

http://www.sans.org/portland07_cs/

I just got back from beautiful Monterey, CA, where I taught Security Hacker Techniques (SEC 504):

http://www.sans.org/monterey07/event.php

I've been to other parts of California; Monterey is my favorite so far.

Thursday, April 26, 2007

Mix and Match

An additional point worth mentioning regarding IP Address Obfuscation is that the techniques can be mixed and matched within the same IP address.
All/most of these formats should work in all browsers. Additionally, in dotted format, each octet can be of the different bases. For example, 207.0x8E.0203.235 is a valid (though unconventional) equivalent to the above addresses. (Wikipedia article on IPv4)
Spammers are actively using this technique; this URL arrived today in a Pump and Dump stock spam:

http://0x00000000000d8.00000000000323.0x000000000000000000000009e.124/

The link in the email refers to MoneyCentral.MSN.com, but actually redirects to a random .BIZ site.

The format of this URL is:
  1. 'Dotted Hex with leading zeroes' .
  2. 'Dotted Octal with leading zeroes' .
  3. 'Dotted Hex with leading zeroes' .
  4. 'Dotted Decimal'.
The address translates to 216.211.158.124 in dotted quad (decimal) format.

Tuesday, April 24, 2007

URL Obfuscation for fun and profit

We've all grown accustomed to the 'dotted quad' format of IP addresses. Localhost is 127.0.0.1, for example.

'127.0.0.01' is simply a convenient shorthand for a 32-bit number, in this case listed as four 8-bit numbers. There are numerous other ways to represent that 32-bit number. The simplest is to represent it as a decimal. '127.0.0.01' is decimal 2,130,706,433.

An easy way to make that conversion is to open up a calculator; Windows calculator in Scientific mode works fine (go to Options-> Scientific). Then choose binary mode ('Bin'), and enter '01111111' (127) . '00000000' (0). '00000000' (0).'00000001' (1). Then hit decimal ('Dec').

Your answer should be 2130706433. To verify you are correct, open a command prompt and type 'ping 2130706433'. What IP address answered?

There are other legitimate ways to represent an IP address; many are summarized in this Wikipedia article. Other forms include dotted hex, dotted octal, and others.

This topic is normally an arcane source of trivia for die-hard IP geeks. I mention it today because spammers and phishers abuse these forms of URL obfuscation in an attempt to bypass IP address blocking schemes.

Here are some live examples harvested from today's mail spool:

Bank phishing attempt using dotted hex IP address:
  • Subject: Arizona Federal - Account Suspended.
  • Embedded URL: http://0xcb.0xe9.0xc7.0x92/(deleted)/www.azfcu.org/
Ebay phishing attempt using a decimal IP
  • Subject: Question about payment for item: #2070651641
  • Embedded URL: http://1478700420:82/(deleted)&co/reg.php
Paypal phishing attempt using a dotted octal URL:
  • Subject: Update your PayPal records
  • Embedded URL: http://0112.0000.0067.0012/(deleted)/index.htm
MSN phishing scam in dotted hex, with leading '0's:
  • Subject: Fwd: MoneyCentral.MSN.com 721362
  • Embedded URL: href="http://0x000000000000000D8.0x0D3.0x000000000000000009E.0x00000(deleted)">MoneyCentral.MSN.com
As the last example illustrates, these obfuscation techniques may be further confused by adding leading zeroes.

The good news is these phishing attempts are trivially easy to block via email, assuming your MTA can block email based on regular expression matches in the body of the email.
Postfix is one such mailer, with its excellent support of Perl-Compatible Regular Expressions.

Here are the pcre maps I use to block these URL obfuscation attacks:
  • /http:\/\/(0x0*[0-9A-F]{2}\.){3}0x0*[0-9A-F]{2}/ REJECT URL Obfuscation
  • /http:\/\/0*[0-9]{8,10}/ REJECT URL Obfuscation
  • /http:\/\/0x0*[0-9A-F]{8}/ REJECT URL Obfuscation
  • /http:\/\/(0+[0-7]{3}\.){3}0+[0-7]{3}/ REJECT URL Obfuscation
These will block dotted hexadecimal, decimal, hexadecimal, and dotted octal URLs, respectively. You may enable these using the Postfix MTA by saving them to a file (in this case, /usr/local/etc/postfix/bodyfilt.pcre), and entering the following line in main.cf:

body_checks = pcre:/usr/local/etc/postfix/bodyfilt.pcre

Postfix PCRE's are case insensitive by default. If your MTA is not, use '[A-Za-z0-9]' for a hex digit (for example).

Tuesday, April 17, 2007

SANS CISSP @Home

I just finished up teaching SANS@Home Management 414: SANS® +S™ Training Program for the CISSP® Certification Exam with Dr. Eric Cole, which began on Monday, February 26, 2007, and ran through Thursday, April 12, 2007.

http://www.sans.org/athome/details.php?nid=1982


The next SANS CISSP @Home begins on July 16th.

http://www.sans.org/athome/details.php?nid=5066

It will be 13 sessions, Mondays and Wednesday nights. The last class was a blast; I'm looking forward to this one.

Wednesday, March 21, 2007

s/sprinkles/jimmies/g

I taught Stay Sharp: Using Regular Expressions in Boston on May 3rd:

http://www.sans.org/staysharp/details.php?id=3126

Thursday, March 15, 2007

Community SANS Maine 2007

SANS just tentatively announced Community SANS Portland Maine 2007, beginning August 20th.

http://www.sans.org/training/bylocation/index_us_canada.php


No details yet on hotel, etc. I plan to teach one track there.

Monday, March 05, 2007

Hacker Techniques at SANS Monterey

I will teach Security 504: Hacker Techniques, Exploits & Incident Handling at SANS Monterey in May.

http://www.sans.org/monterey07/event.php

Friday, February 09, 2007

Papers

Five of my papers on Cryptography have been posted as part of the 'GIAC Research in the Common Body of Knowledge.' They include papers on AES, DES, Kerberos, and others.

My papers on Artificial Intelligence and Intrusion Detection will be posted shortly.

http://www.giac.org/resources/whitepaper/cryptography/

Older stuff

I recently taught SANS Security 504 (Hacker Techniques, Exploits and Incident Handling), Security 452: Mastering Packet Analysis, and Security 450: Defeating Rogue Access Points at Community SANS Portsmouth:

http://www.sans.org/portsmouth06/

I lead SANS Stay Sharp "Mastering Packet Analysis" course on July 20th 2006: http://www.sans.org/staysharp/details.php?id=1547

I led the Community SANS Boston 2006 CISSP conference http://www.sans.org/boston2006/faculty.php#iid189

I am a contributing author to SANS HIPAA Security Implementation https://store.sans.org/store_item.php?item=117