Jump to content

FireEye Malware

Intelligence Lab

Threat research, analysis, and mitigation

« August 2012 | Main | October 2012 »

6 posts from September 2012

Top 20 Words Used in Spear Phishing Emails

TWSP-report-graphicDespite the many security defenses aimed at protecting email communications, email continues to be a critical vulnerability for enterprises.

Between Q1 2012 and Q2 2012 alone, FireEye reported a 56% increase in the amount of malicious emails—and this wasn’t simply an increase in the total number of emails distributed; it was an increase in the number of emails that were able to bypass signature- and reputation-based security defenses, like next-generation firewalls, intrusion prevention systems (IPS), anti-virus (AV), and secure gateways. This means that, while more and more malicious emails are outsmarting traditional security technology, more and more are making their way to your inbox.

Continue reading "Top 20 Words Used in Spear Phishing Emails" »

Grum—New segement came and gone

Back in July, with the help of Spamhaus and CERT-GIB, FireEye took down Grum, one of the world's largest spam botnets. The whole shutdown operation was like a roller coaster ride and is explained in my previous blog posts here and here. Apart from an unsuccessful recovery attempt made by the bot herders a few days after the takedown, we never noticed any movement from the opposite side. Apparently the Grum guys had given up their botnet.

Continue reading "Grum—New segement came and gone" »

Possible Update to the Blackhole Exploit Toolkit

Pretty much everyone is aware of the BlackHole toolkit. We previously wrote a blog that compared the prevalence of various toolkits.

At FireEye, we trigger on thousands of BlackHole events every day across our customer base. We have recently seen reports that the toolkit has been updated. The following website gives you good details about what features have been included in the new toolkit: http://malware.dontneedcoffee.com/2012/09/blackhole2.0.html.

We immediately started looking through the FireEye Malware Protection Cloud (MPC) to see if the FireEye Virtual Execution engine in our appliances had seen instances of this new toolkit. (The FireEye Virtual Execution engine is our proprietary virtual machine technology that enables us to detect threats that have never before been seen.) Websense reported finding URLs in their blog, and we found a bunch of URLs—the earliest of which was detected on September 3, 2012.

Continue reading "Possible Update to the Blackhole Exploit Toolkit" »

Analysis of Malware Page

Target and Delivery Method

Malware Page employs the vulnerability in PDFs and has been seen to be delivered via email. Agenda_Web_(8-24-12).pdf is one of the names this malicious sample uses. Per our logs this sample has been seen to target the aviation defense industry, making this malware a critical limited edition threat. When the malicious PDF file is opened, it infects the victim’s machine and a decoy document is generated. When the decoy PDF file is opened in Acrobat Reader, as shown in Figure 1, the victim finds an invitation to an actual defense industry event.

Image2.jpg

Figure 1. Contents of the decoy PDF file

The purpose of this blog is to share the technical details about this critical limited edition malware.

Continue reading "Analysis of Malware Page" »

Getting Tricky With Shellcode

For those who read my previous blog regarding a very interesting shellcode exploit running inside a PDF, I got a little curious during my spare time and, upon further research, I realized that there is yet another way to insert shellcode inside a Windows program.

The assumption here is that the reader knows about the Windows executable format (hence PE headers) and has some knowledge of DEP, ASLR, and some exploit techniques such as ROP chains.

Continue reading "Getting Tricky With Shellcode" »

The Story Behind Backdoor.LV

From May of this year, we have seen a sudden uptick in the number of samples of an interesting malware we call Backdoor.LV. We have seen this malware primarily using websites hosting .exes to propagate. The HTTP header below shows one such example from which the malware was downloaded. A quick look up on the location of the IP in the HTTP header "94.129.29.233" shows that the IP is located in Kuwait.

Continue reading "The Story Behind Backdoor.LV" »