Showing posts with label phish. Show all posts
Showing posts with label phish. Show all posts

Wednesday, October 15, 2008

Phishing with Malware

I've been pretty busy lately with work and the malware challenge (only 11 days left!) but I figured I'd post something which came across my inbox today. Wachovia has been getting alot of phishing attempts against it which lead to a page trying to get you to install a security update, which is actually malware. I guess the bad guys decided that Wachovia had enough and decided to turn their sites on Key Bank.

I received the following email supposedly from Key Bank asking that I update my system now.



Clicking on the link took me to the following page, which is NOT located on Key Bank's website.



If you wait long enough it will refresh itself to the executable, but by clicking on the link the page will attempt to download and run (with user acceptance) the malware and will open up another browser window to the actual Key Bank login page. This page IS on Key Bank's website, but note that Key Bank is NOT compromised.



What has happened is when the user installs the "update" the initial malware loaded downloads another one which installs itself as a service on the system. This new service then watches for any credentials sent. What happens when it gets one?



This isn't a new method for doing things - its been around for a while. However, this is the first time I've seen this specific attack (from this group) directed at Key Bank. Trend Micro has a posting about the same attack against a German bank.

Thursday, April 24, 2008

Tracking malware

I've been following the certificate phish I posted about the other night for the last couple days. There have been a few more iterations of it using the same certificate scam, only for different banks. The interesting thing is while the domain names keep changing, the IP address of one of the name servers has been staying the same. This is a fast flux network, but I have to wonder if this name server is at some bullet proof hosting provider. If I find out more I'll post.

This got me thinking - how can we track the site which malware uses? The big AV/MA companies have databases and huge repositories of information from their customer base which allows them to track the websites and groups which are sending out malware. However, I don't work for a huge AV/MA company and neither to my MA buddies. We don't have access to the resources these big companies do, but is our research any less important?

I came to the conclusion that I'm going to start my own tracking database. I've only begun to formulate the idea on how to set it up in my head. I'm curious if anyone knows of anything like this, that is publicly accessible, which already exists? I know the ISC has their DShield database but this is more of any attacks and not specific to malware.

Tuesday, April 22, 2008

Certificate Phish

I received an interesting phish email the other day. The email contained a notice, supposedly from a bank, which said my "personal certificate" was about to expire and in order to renew it, and keep the security of account up to date, I needed to click on the link, install the update and then log into my account. Of course, the link led to some malware.

What I find interesting about this is that it throws enough security jargon out to the recipient to make it sound believable. While most people don't know what a certificate is or what its used for, they have probably heard about it at some point and know it has to do with security.

The email also takes a different approach than most phishes - instead of telling the victim there is something wrong with their account and they need to sign in immediately to fix it, it tells them they have to update to keep secure. I think this is going to be a shift in phishing tactics - phishers will start new methods to entice users to click on their links and inadvertently reveal their credentials. Of course, this may already be happening - I am in no way a phishing expert.

In any case, it just means we need to keep vigilant and stay aware as always.