The Information Warfare Monitor (Citizen Lab, Munk School of Global Affairs, University of Toronto and the SecDev Group, Ottawa) announce the release of Koobface: Inside a Crimeware Network by Nart Villeneuve, with a foreword by Ron Deibert and Rafal Rohozinski.
The full report can be accessed here (local mirror):
Globe and Mail coverage of the report can be accessed here:
Koobface is a notorious botnet that leverages social networking platforms to propagate. Since, people are much more likely to execute a malicious file if it has been sent to them by someone they know and trust, the Koobface operators, known as "Ali Baba and 40 LLC" have developed a system that that uses social networking platforms such as Facebook to send messages containing malicious links. These links redirect users to false YouTube pages that encourage users to download malicious software masquerading as a video codec or a software upgrade.
In late April 2010, I discovered archive files on a well known Koobface servers that provided an inside look at the operations and monetization strategies of the Koobface botnet. The contents of these archives revealed the malware, code, and database used to maintain Koobface. It also revealed information about Koobface’s affiliate programs and monetization strategies. There are three main issues that have stood out for me throughout this investigation.
The first is the level of Koobface's financial success. The operators of Koobface have been able to successfully monetize their operations. Through the use of pay-per-click and pay-per-install affiliate programs, Koobface was able to earn over US$2 million between June 2009 and June 2010 by forcing compromised computers to install malicious software and engage in click fraud. This, of course, does not occur in a vacuuum but within a malware ecosystem that sustains and monetizes botnet operations.
The second concerns the countermeasures taken by Koobface against the security community.Koobface maintains a banlist of IP addresses that are forbidden from accessing Koobface servers. In addition, Koobface operators carefully monitor whether any of their URLs have been flagged as malicious by bit.ly or Facebook and they also monitor their malware links with the Google Safe Browsing API. This is part of a trend where malware authors check their malicious software against a variety of security products to ensure that there is only limited protection.
Finally, botnets such as Koobface present significant, but not impossible, challenges for law enforcement. Botnet operators leverage geography to their advantage, often exploiting Internet users from all countries but their own. While the total amount of criminal activity that the botnet operators engage in may be significant, the distribution of that criminal activity across multiple jurisdictions means that the criminal activity in any one jurisdiction is minimal. In addition, botnet operators leverage Internet infrastructure around the world, making it difficult to interfere with their operations.
However, botnet operators, such as those behind Koobface, do make mistakes. Information sharing and persistent monitoring can uncover the details of botnet operations. Therefore, it is important that the law enforcement and security community continue to share information and work closely together. An understanding of the inner workings of crimeware networks allows law enforcement to pursue leads and the security community to develop better defenses against malware attacks.
This report was made possible thanks to the guidance and encouragement of Ron Deibert and Rafal Rohozinski, the principal investigators of the Information Warfare Monitor. This report is built upon the research of members of the security community and I would like to thank all those who have documented the operations of Koobface over the years, especially Dancho Danchev and Trend Micro’s Threat Research Team. I would like to acknowledge and thank Chris Davis and Jose Nazario for sharing their knowledge and providing advice. In addition, I would like to thank the RCMP, the FBI, the UK Police, and AusCERT for their assistance. Finally, a special thanks is due to Jan Droemer who discovered the same data and shared his analysis and insights.
For more information on Koobface, see:
The Real Face of KOOBFACE: The Largest Web 2.0 Botnet Explained
“The Heart of KOOBFACE: C&C and Social Network Propagation
Show Me the Money! The Monetization of KOOBFACE
Web 2.0 Botnet Evolution: KOOBFACE Revisited
Koobface Gang Responds to the "10 Things You Didn't Know About the Koobface Gang Post"
Koobface – the social network trojan
Friday, November 12, 2010
Nobel Peace Prize, Amnesty HK and Malware
There have been two recent attacks involving human rights and malware. First, on November 7, 2010, contagiodump.blogspot.com posted an analysis of a malware attack that masqueraded as an invitation to attend an event put on by the Oslo Freedom Forum for Nobel Peace Prize winner Liu Xiaobo. The malware exploited a known vulnerability (CVE-2010-2883) in Adobe Reader/Acrobat. The Committee to Protect Journalists was hit by the same attack.
On November 10, 2010 Websense reported that website of Amnesty Hong Kong was compromised and was delivering an Internet Explorer 0day exploit (CVE-2010-3962) to visitors. In addition, Websense reports that the same malicious server was serving three additional exploits: a Flash exploit (CVE-2010-2884), a QuickTime exploit (CVE-2010-1799) and a Shockwave exploit (CVE-2010-3653).
The malicious domain name hosting the exploits mailexp.org (74.82.168.10) has been serving malware since Sept. 2010. The domain mailexp.org was registered in May 2010 to y_yum22@yahoo.com. mailexp.org was formerly hosted on 74.82.172.221 which now hosts the Zhejiang University Alumni Association website.
Both ca80564d93fbe6327ba6b094ae3c0445 and 3a459ff98f070828059e415047e8d58c perform a DNS lookup for ns.dns3-domain.com, which is an alias for centralserver.gicp.net which resolves to 221.218.165.24 (China Unicom Beijing province network).
The domain name "ns.dns3-domain.com" has been associated with a variety of malware going back to May 2010. This domain name, dns3-domain.com is registered to zhanglei@netthief.net, the developer of the NetThief RAT.
Malware attacks leveraging human rights issues are not new. I have been documenting them for some time (see, Human Rights and Malware Attacks, Targeted Malware Attack on Foreign Correspondent’s based in China, "0day": Civil Society and Cyber Security). However, one of the issues that Greg Walton and I raised last year, is a trend toward using the real web sites of human rights organizations compromised and as vehicles to deliver 0day exploits to the visitors of the sites – many of whom may be staff and supporters of the specific organization. Unfortunately, we can expect this to continue.
On November 10, 2010 Websense reported that website of Amnesty Hong Kong was compromised and was delivering an Internet Explorer 0day exploit (CVE-2010-3962) to visitors. In addition, Websense reports that the same malicious server was serving three additional exploits: a Flash exploit (CVE-2010-2884), a QuickTime exploit (CVE-2010-1799) and a Shockwave exploit (CVE-2010-3653).
The malicious domain name hosting the exploits mailexp.org (74.82.168.10) has been serving malware since Sept. 2010. The domain mailexp.org was registered in May 2010 to y_yum22@yahoo.com. mailexp.org was formerly hosted on 74.82.172.221 which now hosts the Zhejiang University Alumni Association website.
The malware dropped from the Internet Explorer exploit (CVE-2010-3962)
scvhost.txt
MD5: ca80564d93fbe6327ba6b094ae3c0445 VT: 2 /43
The malware dropped from the Flash exploit (CVE-2010-2884)
hha.exe
MD5: 0da04df8166e2c492e444e88ab052e9c VT: 2 /43
The malware dropped from the QuickTime exploit (CVE-2010-1799)
qq.exe
MD5: 3e54f1d3d56d3dbbfe6554547a99e97e VT: 16 /43
The malware dropped from the Shockwave exploit (CVE-2010-3653)
pdf.exe
MD5: 3a459ff98f070828059e415047e8d58c VT: 0/43
Both ca80564d93fbe6327ba6b094ae3c0445 and 3a459ff98f070828059e415047e8d58c perform a DNS lookup for ns.dns3-domain.com, which is an alias for centralserver.gicp.net which resolves to 221.218.165.24 (China Unicom Beijing province network).
The domain name "ns.dns3-domain.com" has been associated with a variety of malware going back to May 2010. This domain name, dns3-domain.com is registered to zhanglei@netthief.net, the developer of the NetThief RAT.
Malware attacks leveraging human rights issues are not new. I have been documenting them for some time (see, Human Rights and Malware Attacks, Targeted Malware Attack on Foreign Correspondent’s based in China, "0day": Civil Society and Cyber Security). However, one of the issues that Greg Walton and I raised last year, is a trend toward using the real web sites of human rights organizations compromised and as vehicles to deliver 0day exploits to the visitors of the sites – many of whom may be staff and supporters of the specific organization. Unfortunately, we can expect this to continue.
Friday, November 5, 2010
Clustering Zeus Command and Control Servers Part 2
In Part 1 of "Clustering Zeus Command and Control Servers" I focused on clustering Zeus command and control servers based on three criteria: IP addresses, domain names, and email addresses used to register domain names. Using data drawn from ZeusTracker and MalwareDomainList, I observed that while a wide variety of criminals may set up disparate Zeus operations there may be “core” set of Zeus operations clustered around domain names registered five email addresses: abuseemaildhc@gmail.com, hilarykneber@yahoo.com, steven_lucas_2000@yahoo.com, tahli@yahoo.com and michell.gregory2009@yahoo.com. Beyond the common email addresses and co-hosting on servers with the same IP addresses (which, in general are hosting a wide variety of malware) the exact nature of the relationships remains unclear.
It is clear that there are certain servers that facilitate an abundance of malicious activity. However, caution must be exercised when conclusions are drawn regarding specific (groups of) actors operating discrete segments of botnet command and control servers among a common malicious infrastructure. Malware groups are often the customers of other malware groups or work with affiliates to propagate and monetize malware. Different groups may propagate malicious domain names that belong to other groups, or different groups may propagate common malicious domains that are provided by an affiliate network. In addition, there are malicious networks that provide hosting services to malware distributors and botnet operators. Therefore, links that appear between a variety of actors may not be as solid as the technical data alone would lead one to believe.
In order to examine these relationships further, I'm going to layer some qualitative data and analysis on the Zeus data analyzed in Part 1. Based on information I obtained from some of the command and control servers listed below (this is deliberately vague), combined with common file paths and the presence of the same files on different combinations of these servers, I believe that the following command and control domain names constitute of cluster of malicious activity operated by the same set of operators:
This post will explore the relationships between these domains and other malicious activity, primarily Zeus activity, undertaken by other domain names registered with the same email addresses in order to explore the theory that there is a "core" of Zeus activity. While the malicious activity primarily relates to Zeus there are some significant exceptions. The domain name sosanni.com was used as a command and control server for the Ambler botnet. For the period I observed the Ambler activity, over 5000 IP addresses from compromised computers, 99% of which were from Russia, checked in with the command and control server. In addition, I found that coolparts31.tw was acting as a SpyEye command and control server in addition to a Zeus command and control server.

This screenshot shows the relationship between the command and control domain names, the malicious activity associated with them and the IP address that the domain name resolves to. While there are several instances in which some domain names were co-hosted on the same server, nearly half were not. This makes sense as operators will seek to diversify their hosting in order to avoid a complete shutdown should one of their command and control servers be taken down or blocked. In fact, look at the time span, covering October 2009 to September 2010 we can see how the operators moved their operations from one server to the next.

This operators of this malware cluster tend to host their command and control servers in Eastern Europe and China.

In order to assess this clusters possible linkages within the broader malware ecosystem, the data set was expanded to include a) other domain names registered with the same email addresses and b) the IP addresses of the servers associated with the malicious activity imported from ZeusTracker and MalwareDomainList. This extends the geographic scope of the hosting servers into North America, as well as the previous locations in Eastern Europe (UA, RU, CZ, MD) and South East Asia (CN, TW).
Looking at the relationships between the domains we see that there are two interesting clusters, and arguable a few smaller ones as well. These represent concentrations of servers registered with the same email addresses. The two main clusters are domain names registered to: steven_lucas_2000@yahoo.com and hilarykneber@yahoo.com.

An interesting fact about the "Lucas" cluster becomes apparent when you look at the time line of malicious activity (the date when the domain name was added to ZeusTracker or MalwareDomainList). The Lucas cluster is primarily active January - November 2009 (although there is some subsequent activity) while very few domains registered with other email addresses are active.

This is followed by the introduction of the "Kneber" domains which begin on the tail end of the Lucas cluster's activity. The Kneber domain names begin in November 2009 and continue into October 2010. While the domain names registered with the remaining email addresses do also roughly follow a similar pattern of beginning while the previous one tails off, Kneber remains fairly constant once it begins.
In Part 1, I showed that there are clusters of Zeus activity that around a set of email addresses used to register domain names. Using qualitative data from my investigations, I've found a Zeus cluster that uses domain names registered by some, but not all, of these key email addresses including steven_lucas_2000@yahoo.com and hilarykneber@yahoo.com. This cluster has transitioned through domain names registered by a variety of email addresses over the last year. When the data set is expanded to include all the domain names registered by these email addresses in ZeusTracker and MalwareDomainList we see the same pattern of transition play out. This supports the theory that while Zeus is a toolkit that allows anyone to create a botnet, there is a "core" of Zeus activity.
However, this cluster of 16 domain names is only a small portion of the "core" Zeus activity associated with five key email addresses. According to DomainTools, about 1839 domain names in total:
These email addresses have been used to registered a variety of domain names associated with all manner of malicious activity, not exclusively Zeus activity. While this could be part of a centralized effort to distribute command and control servers to be operated by sub-groups, I am not sure that it is best to attribute all the malicious activity across these domains to the same set of actors. Even if these domain names represent the efforts of the same set of actors, they appear to be distributed to smaller groups of operators. These operators don't necessarily have connections with others managing domain names hosted on the same infrastructure and/or registered with the same email addresses.
However, this simple clustering method does provide us with concentrations of malicious activity that should be investigated further. The introduction of qualitative data provides the ability to probe the operations of specific groups further. In the future I'd like to acquire a list of all 1800 domain names and layer on historical hosting data to see if any further patterns emerge.
It is clear that there are certain servers that facilitate an abundance of malicious activity. However, caution must be exercised when conclusions are drawn regarding specific (groups of) actors operating discrete segments of botnet command and control servers among a common malicious infrastructure. Malware groups are often the customers of other malware groups or work with affiliates to propagate and monetize malware. Different groups may propagate malicious domain names that belong to other groups, or different groups may propagate common malicious domains that are provided by an affiliate network. In addition, there are malicious networks that provide hosting services to malware distributors and botnet operators. Therefore, links that appear between a variety of actors may not be as solid as the technical data alone would lead one to believe.
In order to examine these relationships further, I'm going to layer some qualitative data and analysis on the Zeus data analyzed in Part 1. Based on information I obtained from some of the command and control servers listed below (this is deliberately vague), combined with common file paths and the presence of the same files on different combinations of these servers, I believe that the following command and control domain names constitute of cluster of malicious activity operated by the same set of operators:
freehost21.tw – hilarykneber@yahoo.com - 109.196.143.60
bstservice.biz – accounseller@gmail.com - 195.5.161.73
fivefingers31.org – edgar.marcha@verizon.net - 195.149.88.86
coolparts31.tw – admin@google.name - 121.101.216.205
fhjslk21.com.tw – hilarykneber@yahoo.com - 195.5.161.208
bananajuice21.net – hilarykneber@yahoo.com - 109.196.143.56
cpadm21.cn – Dalas_Illarionov@yahooo.com - 91.212.41.31
gamecp12.cn – GameNet2010TX@yahoo.com - 222.73.37.203
admcp21.cn – Maria_lucas_2000@yahoo.com - 91.212.41.31
subaruservice.cn – hilarykneber@yahoo.com - 59.125.229.79
elektronservice.net – Steven Lucas steven_lucas_2000@yahoo.com - 59.125.229.79
promo-standart.info – MillieDiaz4@aol.com - 121.101.216.205
cpadm21.org – admin@cpadm21.org - 193.104.94.81
decp31.org – hilarykneber@yahoo.com - 119.255.23.209
coolparts31.org – skeletor71@comcast.net - 61.4.82.216
sosanni.com – migray71@yahoo.com - 121.101.216.205
This post will explore the relationships between these domains and other malicious activity, primarily Zeus activity, undertaken by other domain names registered with the same email addresses in order to explore the theory that there is a "core" of Zeus activity. While the malicious activity primarily relates to Zeus there are some significant exceptions. The domain name sosanni.com was used as a command and control server for the Ambler botnet. For the period I observed the Ambler activity, over 5000 IP addresses from compromised computers, 99% of which were from Russia, checked in with the command and control server. In addition, I found that coolparts31.tw was acting as a SpyEye command and control server in addition to a Zeus command and control server.

This screenshot shows the relationship between the command and control domain names, the malicious activity associated with them and the IP address that the domain name resolves to. While there are several instances in which some domain names were co-hosted on the same server, nearly half were not. This makes sense as operators will seek to diversify their hosting in order to avoid a complete shutdown should one of their command and control servers be taken down or blocked. In fact, look at the time span, covering October 2009 to September 2010 we can see how the operators moved their operations from one server to the next.

This operators of this malware cluster tend to host their command and control servers in Eastern Europe and China.

In order to assess this clusters possible linkages within the broader malware ecosystem, the data set was expanded to include a) other domain names registered with the same email addresses and b) the IP addresses of the servers associated with the malicious activity imported from ZeusTracker and MalwareDomainList. This extends the geographic scope of the hosting servers into North America, as well as the previous locations in Eastern Europe (UA, RU, CZ, MD) and South East Asia (CN, TW).
Looking at the relationships between the domains we see that there are two interesting clusters, and arguable a few smaller ones as well. These represent concentrations of servers registered with the same email addresses. The two main clusters are domain names registered to: steven_lucas_2000@yahoo.com and hilarykneber@yahoo.com.

An interesting fact about the "Lucas" cluster becomes apparent when you look at the time line of malicious activity (the date when the domain name was added to ZeusTracker or MalwareDomainList). The Lucas cluster is primarily active January - November 2009 (although there is some subsequent activity) while very few domains registered with other email addresses are active.

This is followed by the introduction of the "Kneber" domains which begin on the tail end of the Lucas cluster's activity. The Kneber domain names begin in November 2009 and continue into October 2010. While the domain names registered with the remaining email addresses do also roughly follow a similar pattern of beginning while the previous one tails off, Kneber remains fairly constant once it begins.
In Part 1, I showed that there are clusters of Zeus activity that around a set of email addresses used to register domain names. Using qualitative data from my investigations, I've found a Zeus cluster that uses domain names registered by some, but not all, of these key email addresses including steven_lucas_2000@yahoo.com and hilarykneber@yahoo.com. This cluster has transitioned through domain names registered by a variety of email addresses over the last year. When the data set is expanded to include all the domain names registered by these email addresses in ZeusTracker and MalwareDomainList we see the same pattern of transition play out. This supports the theory that while Zeus is a toolkit that allows anyone to create a botnet, there is a "core" of Zeus activity.
However, this cluster of 16 domain names is only a small portion of the "core" Zeus activity associated with five key email addresses. According to DomainTools, about 1839 domain names in total:
abuseemaildhcp@gmail.com is associated with about 717 domains
hilarykneber@yahoo.com is associated with about 449 domains
steven_lucas_2000@yahoo.com is associated with about 110 domains
tahli@yahoo.com is associated with about 263 domains
michell.gregory2009@yahoo.com is associated with about 300 domains
These email addresses have been used to registered a variety of domain names associated with all manner of malicious activity, not exclusively Zeus activity. While this could be part of a centralized effort to distribute command and control servers to be operated by sub-groups, I am not sure that it is best to attribute all the malicious activity across these domains to the same set of actors. Even if these domain names represent the efforts of the same set of actors, they appear to be distributed to smaller groups of operators. These operators don't necessarily have connections with others managing domain names hosted on the same infrastructure and/or registered with the same email addresses.
However, this simple clustering method does provide us with concentrations of malicious activity that should be investigated further. The introduction of qualitative data provides the ability to probe the operations of specific groups further. In the future I'd like to acquire a list of all 1800 domain names and layer on historical hosting data to see if any further patterns emerge.
Subscribe to:
Posts (Atom)