Showing posts with label Banking Trojan. Show all posts
Showing posts with label Banking Trojan. Show all posts

Tuesday, October 27, 2015

Dridex activity continues

Dridex, a banking malware which attempts to steal the victim's banking credentials and system information, continues to remain active in the wild after the recent takedown attempt. Dridex activity went down significantly in September after the takedown operation but we started seeing an uptick in the number of samples in our sandboxes starting early October 2015.

Dridex is distributed via e-mail with a Microsoft Office attachment that leads to the download and installation of the Dridex Trojan executable. The e-mail attachments in these campaigns varied from regular Microsoft Office document files to MHTML files as seen in Figure 1.

Figure 1: Malicious document sent in MHTML format
MHTML, also known as MIME HTML, is a web page archive format used to combine in a single document the HTML code and its companion resources that are otherwise represented by external links (such as images, Flash animations, Java applets, and audio files). The malware authors are known to send the documents containing malicious macro in MHTML format to evade antivirus detection.

The content of the embedded macro was both obfuscated and protected using a basic password that is intended to prevent modification of the macros.  We were able to bypass the password protection and extract the various document components by standard means.

Figure 2 shows an example embedded malicious macro that downloads the Dridex executable from a predetermined server:

Figure 2: Embedded malicious macro to download Dridex
The samples we are seeing in these new campaigns are a mix of unsigned as well as some digitally signed using valid certificates. The format of the URLs hosting the signed Dridex samples changed to 195.37.231[.]2:8080/uniq/load[.]php instead of previously seen URL format 94.250.252[.]13/bt/bt/stata[.]php

The Dridex executable downloaded by above macro (Figure 2) appears to be packaged using a custom packer. This instance of the Dridex Trojan is signed using a certificate with the common name of “Favorite-III” which appears specific to the Dridex malware and which is currently also present in Comodo’s Certificate Revocation List.


Figure 3: Dridex Certificate issued with CN Favorite-III

We also saw following additional certificates used to sign the newer Dridex executables:
  • INTEX
  • KASHTAN OOO
  • Promtorg
  • KONSALTING PLUS OOO
  • Brand IT 
  • AVTOZVIT Scientific Production Private Company
  • Afet
  • 3 AM CHP
  • PJSC "BIZNES AVTOMATYKA"
  • Favorite-III
  • Private Person Parobii Yuri Romanovich
  • SWIFT Weather
  • PJSC "BIZNES AVTOMATYKA
  • AVTOZVIT Scientific Production Private Company
  • Private Person Parobii Yuri Romanovich
  • Favorite-III [NEW - seen in October 2015]
  • promtorg  [NEW - seen in October 2015]
The following are some recent URLs from which Dridex executables were downloaded:
  • 93.170.104.168:443/uniq/load[.]php
  • 178.62.7.183:443/uniq/load[.]php
  • 195.37.231.2:443/uniq/load[.]php
  • 5.2.199.30:8080/uniq/load[.]php
  • 113.30.152.165:8080/uniq/load[.]php
  • 168.243.33.195:8080/uniq/load[.]php
  • 199.175.55.116:8080/uniq/load[.]php
The following are some MD5 sums of signed and unsigned Dridex executables that we have encountered in past month:

Signed

82BB00DCAC6411669CE6AE5A60CBB3B3
9D4225ECDCDA7FE9A5EAE48601919114
2485C741AF50DE986079B6AD9B6C948A
290CD720AECF28773960C8E41172513C
1C21AEB3DC0E30E05630A3F61AAE83F9
0DA24BD7B49A955D8E4624371CCB8E9F
AFADE4E50D147A1FE18ACA8942E3E679

Unsigned

1DE3889FDE95E695ADF6EADCB4829C6D
D7A31449E5F808FDBA0F6D3CF0D6E91C
7519F0D9D5C3B8D072FFCA7DDF213DDA
F2D6DEC39DAEF7ED90AAABB725590B02

Following are the statistics of Dridex executable downloads that we have seen in past six weeks:

Figure 4: Dridex executable downloads in past six weeks

Figure 5: Dridex executable hosting servers

Conclusion

Dridex infections went down considerably after the global takedown operation but we are starting to see a steady increase in the infections this month, which indicates the malware gang's attempt at resurrecting this highly lucrative Botnet. The authors continue to use the tactic of digitally signed malware executable to evade detection with legitimate certificates created specifically for this purpose.

Zscaler ThreatLabZ is actively monitoring this Botnet and ensuring that Zscaler customers are protected.

Research by Tarun Dewan and Nirmal Singh

Monday, August 24, 2015

Signed Dridex Campaign

Introduction

Malware authors use various means to make their malware look similar to legitimate software. One such approach involves signing a malware sample with a digital certificate. Recently we saw Dridex malware authors using this technique while reviewing the samples in our Cloud Sandbox. Dridex is a banking Trojan which typically arrives to a system via malicious spam email with a Microsoft Office file as an attachment. These files will have embedded macros that lead to the download and installation of the Dridex Trojan. Dridex then attempts to steal the victim's banking credentials and system information.

Signed Dridex campaign

Here we came across one malicious attachment with an encrypted macro that downloads signed Dridex samples from 81.17.28.101/bt/bt/sti[.]php. This Dridex sample is packed using a custom packer, which is is compiled with .NET. The current Dridex is signed with a certificate that is issued to Private Person Parobii Yuri Romanovich. This certificate as been specially created for spreading the Dridex malware.


Certificate
We also saw the following signer information in the certificates used for signing the Dridex executables:
  • PJSC "BIZNES AVTOMATYKA
  • AVTOZVIT Scientific Production Private Company
  • Private Person Parobii Yuri Romanovich
The certificates were all issued by COMODO and we observed the following URLs serving the signed Dridex malware:
  • 185.14.29.214/bt/bt/sdp [.] php
  • 81.17.28.101/bt/bt/sti [.] php
  • 5.196.241.204/bt/bt/ched [.] php
  •  217.12.203.171/bt/bt/freda [.] php
  • 94.250.252.13/bt/bt/stata [.] php
  • 149.202.146.176/bt/bt/chdid [.] php
  • 93.170.105.60/bt/bt/grtes [.] php
Below are the Dridex samples served from the aformentioned URLs. All tof he samples are packed with the same .NET packer mentioned above:
  • 5CA1DBA1C72AC999E221DE98BBC584C4
  • 9E73E0C4B92253C5F8B6648F29B28B5B
  • CD243B30B9BBD682C082CFEFDBF79ACD
  • E578618F2D38FC251D52D1366144404F
  • 5F907702CE229937955B4DCE92EC4575
  • DC443FBB5FB6125EBEEEBEC2E4BAA372
  • 0BBC8CD08E9958ACDE0519A2B2840CD7
  • 9D1D0632329F04D8B1EC21AFF4CE6493
  • 32230D747829DCF77841F594AA54915A
  • 8F1A9A9830FF02C5C2BA4C17DFE8B09D
  • 00DCA835BB93708797A053A3B540DB16
  • 393E2145F4C3E9B5697A2AAEB25AA8D3
  • 1992170FDC642D4A99A7BC82BA82FA31
  • 9261B8EAF1DA3D9CFF522875A7198667
  • FB67C85F3F42D3E48B9E7B7637D30858
  • E578618F2D38FC251D52D1366144404F
Dridex Packer:
The Dridex sample is embedded in the resource section of the packer. After unpacking, it drops a Borland Delphi executable file. The following is the snapshot of encrypted resource section:

Encrypted Resource Section
Dridex Activity:
The current Dridex sample tries to connect to different IPs included in the config file. The config file for the sample is embedded in the sample itself. In the config file we observed a botnet ID and list of  C&C servers. Below is a snapshot of config file:

Configuration file
Dridex collects and sends the following system information to one of the C&C mentioned in the config file:
  • Computer Name
  • User Name
  • Windows Version
  • Botnet ID
Information sent to the server
Below is the complete list of C&Cs it tries to connect.
  • 80.247.233.18
  • 91.121.82.113
  • 69.164.213.85
  • 79.143.191.147
  • 199.241.30.233
  • 162.243.12.14
  • 188.93.73.90
  •  195.154.184.240

Conclusion

The use of a legitimate certificate in signing malware executables to evade security detection is not new but is still very effective. The malware author aims to exploit the Code-Signing Certificate based whitelisting approach by signing their samples. Zscaler ThreatlabZ is actively monitoring these signed malware campaigns and ensuring coverage for our customers.

Analysis by Tarun Dewan and Nirmal Singh

Sunday, July 5, 2015

A look at recent Tinba Banking Trojan variant

Introduction 

Tinba is information stealing Trojan. The main purpose of the malware is to steal information that could be browsing data, login credentials, or even banking information. This is achieved through code injection into system process (Winver.exe and Explorer.exe) and installing hooks into various browsers like IExplorer, Chrome, Firefox and Opera.

Tinba has been known to arrive via spammed e-mail attachments and drive-by downloads.  Recently, Angler Exploit Kit instances were also found to be serving Tinba banking Trojan as seen here.

Detailed Analysis of Tinba

Tinba is packed with a custom packer and uses well known anti-debugging technique using the WinAPI function “IsDebuggerPresent” to hinder reverse engineering of the binary image. The execution flow of the infection cycle for Tinba is shown below.
Execution flow of Tinba

The image below shows the custom packer code being used by the Tinba sample we were looking at.


Tinba unpacking Routine
The unpacked binary image is shown below which upon execution will perform code injection into system processes like Winver.exe and Explorer.exe.


Unpacked Binary
It generates Mutex name using root volume information of the victim’s machine as shown below.

Mutex name generation
Remote Thread in System Process
 
A remote thread is created inside Explorer process that is responsible for creating a copy of Tinba Binary in %APPDATA% & auto start registry entry in Registry hive.


Explorer remote thread
The Tinba binary is stored in a hidden folder which is created under %APPDATA% directory:


 C:\Documents and setting \username \Application Data\mutexname\bin.exe
It also creates an auto-run registry entry to execute Tinba binary during every windows start-up as shown below:


Auto start registry entry

Another thread is also created in Explorer process which is responsible for generating DGA (Domain Generation Algorithm) domains and injecting code into browsers like IExplorer, Chrome, Firefox and Opera.

Explorer local thread
Domain Generation Algorithm

The following is the Domain Generation Algorithm (DGA) used by Tinba variant where every sample uses a hardcoded domain and seed to generate the DGA domains.

DGA routine

Hardcoded Domain and seed
These DGA domains are fast flux domains where single domain is frequently switched to different IPs by registering it as part of the DNS A record list for a single domain.


targetHost
targetIP
eudvwwwrmyqi.in
89.111.166.60
eudvwwwrmyqi.in
95.163.121.94
jrhijuuwgopx.com
176.31.62.78
jrhijuuwgopx.com
176.31.62.77
norubjjpsvfg.ru
210.1.226.15
norubjjpsvfg.ru
104.223.122.20
norubjjpsvfg.ru
104.223.15.16
scpxsbsjjqje.ru
5.178.64.90
scpxsbsjjqje.ru
192.198.90.228
scpxsbsjjqje.ru
5.178.64.90
wgwnmffclqvu.ru
192.198.90.228
wgwnmffclqvu.ru
192.3.95.140


Remote Thread in browsers

The Explorer thread searches for browser process either by checking path of the browser executable or by loaded application specific DLL (e.g. NSS3.dll for firefox.exe). If the targeted browser process is found, then the secondary thread is created in the process.

Browser thread
This thread is responsible to get updated Bot configuration details like Target URL list and strings (BOTUID ) from a remote C&C server. If there is no updated list of target URLs from C&C server, then it uses default targeted list of URLs which is stored in the injected code. The list of default target URLs after decryption is shown below.

Default Targeted URL list
The collected information form webmail, social media and the banking sites are stored in "log.dat" file.

Log file path
C&C communication & Cryptography:
 
The POST request to C&C server contains encrypted system information like system volume & version information.  The cryptography routine is a simple byte 'XOR' with an 8 bit 'ROR' of the key after each write. 

Send Data Encryption

A sample Tinba POST request to DGA domains with 157 bytes of encrypted data is shown below.


C&C POST Request
Geo distribution of C&C call back attempts that we blocked in past one month:

Geo Location
We have seen following C&C server IP addresses:
Conclusion:
     Tinba also known as small banking Trojan continues to be prevalent in the wild.  The arrival method varies from e-mail spam, drive-by downloads and most recently Exploit Kit infection cycle. Zscaler ThreatlabZ is actively monitoring this malware family and ensuring coverage for our customers.

Monday, February 2, 2015

Android Banking Trojan and SMS stealer floating in the wild

We recently came across an Android Banking Trojan with a very low antivirus detection rate that is targeting Chinese mobile users. This Android malware is capable of stealing banking information by intercepting SMS messages looking for certain keywords. It also steals all the contact information from the user's mobile device and relays it to a remote Command & Control (C2) server.

Malicious Android package details
  • Name : 888.apk.
  • MD5 :  ff081c1400a948f2bcc4952fed2c818b.
  • VT : 7/56 (at the time of analysis)
  • Source: http://wap{.}jhgxc{.}com/888.apk

Functionality
  •  Intercept and capture all incoming and outgoing SMS messages
  •  Intercept incoming calls and the ability to end calls
  •  Receive C2 commands via SMS
  •  Sends stolen data via SMS, e-mail, and possibly web requests to the C2 server
Let's take a look at some of the above mentioned malware features and how they have been implemented:

Email sent SMS

In the screenshot above, you can see that it is e-mailing the captured outbound SMS messages using a hardcoded 163.com email address. It e-mails the stolen data to itself with the subject "Send SMS".

Email and SMS all sniffed data

Here you can see that it is e-mailing the captured inbound SMS messages using the same parameters that it used for outbound SMS messages. Additionally, it is also relaying the same information via SMS to a hardcoded Chinese phone number "15996581524".

Intercepting call

The above screenshot shows the ability to intercept incoming calls and send the caller's number via e-mail with subject "Intercept incoming call once the call!". It also has the ability to end the call.

Receives SMS as commands.

It's also capable of receiving C2 commands via SMS from the malware author to act further.

Commands to act

As seen in the screenshot above, the attacker can start the data capturing activity by sending the SMS command "intercept#" and can also stop the capturing activity by sending SMS command "interceptstop#".

Banking strings

In the screenshot above, you can see that there are string checks in place which are related to online banking transactions. It checks for strings like "Pay","Check","Bank","Balance","Validation"  which clearly shows the intent of the malware author to sniff banking related information.

Setting high priorities

The malware sets the SMS receiver and outgoing call services to high priority. This will ensure that the malicious application will get a higher preference for these events compared to other applications.

Web request for sending stolen contacts

We also saw some code that can allow the malware to send stolen contact information & SMS data through web requests. However, it appears to be non-functional in this version and the malware author might still be testing out this feature, as seen by the usage of the private IP address:

 "http://192.168.1.102/input/input_data_get_contact.asp?user=XXX&pwd=XXXX&addr="

Web request for sending stolen SMS data

"http://192.168.1.102/input/input_data_get_sms.asp?user=XXX&pwd=XXX&addr=XXX&id=XXX"

The following are screenshots showing a sample of stolen information that the malware author has been able to capture through these malicious APK infections till now:

Sent email section
E-mailed stolen SMS message
Intercepted incoming call notification

SMS matching online banking strings

Stolen contact information


Infected mobile users.
Intercepted online banking SMS
Intercepted online banking SMS

Here you can see some serious financial information sniffed by this malware illustrating the impact of such banking sniffers.

-Viral.