Overclock.net - Overclocking.net
     
 
Home Gallery Reviews Blogs Register Today's Posts Mark Forums Read Members List


Go Back   Overclock.net - Overclocking.net > Industry News > Software News

Reply
 
LinkBack Thread Tools
Old 06-29-09   #1 (permalink)
Overclocker
 
1337guy's Avatar
 
intel nvidia

Join Date: Aug 2007
Location: *Cape Town* FTW!
Posts: 1,746

Rep: 143 1337guy is acknowledged by many1337guy is acknowledged by many
Unique Rep: 110
Trader Rating: 0
Default [SP]Web Malware Employs New Obfuscation Technique

Quote:

Security researchers from antivirus vendor Trend Micro announce that a newly discovered web malware sample uses a code obfuscation technique that generates a different encryption key for every infected page. Decrypting the code without knowing the original URL is impossible.

Trend Micro detects this malware as JS_VIRTOOL and warns that it "uses certain Javascript techniques so that encrypted code may not be decrypted and analyzed by a malware analyst." The reason for this statement is that security researchers receive samples through various different channels and analyze them offline inside controlled environments.


With JS_VIRTOOL, this would be impossible to do without knowing the URL from where a particular sample was extracted. The malware retrieves the URL where it is located and adds it to its own function. It then proceeds to calculating a CRC of this entire string and uses it to encrypt the function.

"In this case, the encrypted code which is the real routine of the malware will not execute if the function is tampered and/or the URL is not correct," Jonathan San Jose, threat analyst at Trend, explains. "Currently, we have multiple samples that all use this particular technique, but have different encrypted contents. We suspect that they have the same decrypted data, the only difference being the URL location which will decrypt each sample," he notes.

Web malware has been a particularly prevalent type of threat in recent times. Several mass injection attacks that affected hundreds of thousands of websites have been reported this year alone. Such was the case of Gumblar, Beladen, or Nine-Ball, which made use of compromised FTP accounts, instead of web vulnerabilities like cross-site scripting or SQL injection.

Development of new obfuscation techniques such as this one, which potentially make investigating complex attacks and tracking their origin a lot harder, are worrying for security researchers. Prevx, a UK-based antivirus vendor, has just recently discovered a dump site containing stolen FTP credentials for more than 68,000 websites, including some very high-profile ones.
http://news.softpedia.com/news/Web-M...e-115349.shtml
__________________

Don't listen to crap! Listen to real music. Listen to TRANCE!!
I WANT TO FOLD FOR OCN BUT MY CELERY JUST AINT CUTTING IT!
Best OCN flame pics!
Best game ever!
...┌∩┐(◣_◢)┌∩┐...

System: T3H FA1LB0X 1S FA1L!! :'(
CPU
prescott celery D @ 3.20ghz
Memory
1GB-DDR400
Graphics Card
6600GT stock @ 500/900
Hard Drive
80GB hitachi deskstar || 1TB 7200.12
Sound Card
onboard
Power Supply
CM Silent Power Pro 600w Modular || 40amps single 12v
CPU cooling
Stock
GPU cooling
Stock
OS
XP Pro SP3 32bit
Monitor
17' crt 1280x1024
1337guy is offline 1337guy's Gallery   Reply With Quote
Old 06-29-09   #2 (permalink)
Luck : 10pts
 
Licht's Avatar
 
amd ati

Join Date: Mar 2007
Location: Fl, US
Posts: 12,820
Blog Entries: 3

Rep: 363 Licht is a proven memberLicht is a proven memberLicht is a proven memberLicht is a proven member
Unique Rep: 240
Trader Rating: 0
Default

Interesting plot twist.

System: Uzicht #4.5
CPU
Phenom II X4 920
Motherboard
Gigabyte 790X AM2+
Memory
6GB Kingston DDR2 667MHZ
Graphics Card
HD4850 + HD3870
Hard Drive
4x WD1600AAJS RAID0
Sound Card
X-Fi Extreme Gamer Professional
Power Supply
OCZ Game-X-Stream 700w
Case
NZXT Black Steel
CPU cooling
Xigmatec Rifle
GPU cooling
Stock Saphire 3870 Cooling
OS
Windows 7 Ultimate x86-x64
Monitor
Samsung SyncMaster 19"Wide
Licht is offline Overclocked Account Licht's Gallery   Reply With Quote
Old 06-29-09   #3 (permalink)
between projects
 
CattleRustler's Avatar
 
intel nvidia

Join Date: Apr 2008
Location: NYC (Queens)
Posts: 7,181

Rep: 658 CattleRustler is becoming famousCattleRustler is becoming famousCattleRustler is becoming famousCattleRustler is becoming famousCattleRustler is becoming famousCattleRustler is becoming famous
Unique Rep: 375
Trader Rating: 0
Default

thats actually pretty awesome from a technical and programmatic standpoint, but it sucks otherwise. Obfuscation has been evolving over time to try and protect legit software from crackers, but now the baddies are making use of it to protect their mal-intent code. damn.
__________________
YO DAWG I HERD YOU LIKE CASE MODDING SO WE PUT A CASE IN YO CASE SO YOU CAN MOD WHILE U MOD

[Current Project] PolymorphiX v2 (alu & steel alu hybrids)
[Pending finish] Butcher's Hook (Slipknot tribute bench in steel)
[mod2hardware] All Modding Projects by CattleRustler
[mod2software] WorklogCreator 1.0.1.6
visually build postable worklogs, quickly & easily with drag and drop

MOTM's: 6/08 2nd Place 12/08 1st Place 2/09 1st Place 8/09 1st Place

System: Chuckle2Tits
CPU
Core i7 920 2.66 45nm D0
Motherboard
Foxconn BloodRage x58
Memory
6 GB Corsair Dom. DDR3 1600
Graphics Card
EVGA GTX 285
Hard Drive
1x500 GB WD Caviar SATAII
Sound Card
Creative X-Fi Xtreme Gamer
Power Supply
Silverstone Decathalon 850
Case
PolymorphiX Prototype v1
CPU cooling
CM Gemini II s (Megahalem pending)
GPU cooling
stock nvidia
OS
Win 7 RC 64
Monitor
Viewsonic VX2255 22" LCD
Overclock.net Mod of the Month
CattleRustler is online now Overclocked Account   Reply With Quote
Old 06-29-09   #4 (permalink)
Programmer
 
lordikon's Avatar
 
intel nvidia

Join Date: Feb 2008
Location: Denver, CO
Posts: 3,900

Rep: 189 lordikon is acknowledged by manylordikon is acknowledged by many
Unique Rep: 151
Folding Team Rank: 104
Trader Rating: 0
Default

I guess it'd be too much to ask people to make an honest living and quit trying to ruin the lives of others through the internet.
__________________
Current Modern Warfare 2 petition count: http://sebastien.me/mw2/petition.png
Currently folding with:
2 8800GTS g92s -- 1 GTX 275 -- 1 8600GTS -- 1 e8400 -- 1 i7 950 (50%) -- 1 e6600

System: Max Pwnage
CPU
e8400 E0, 3.81Ghz, 1.324v
Motherboard
Asus P5N-D 750i
Memory
4GB (2x2gb) A-Data DDR2-800
Graphics Card
2x 8800GTS 512(G92) SLI
Hard Drive
150 WD Raptor, 640 WD Ext.
Power Supply
750W PC P&C Silencer
Case
CoolerMaster 690
CPU cooling
$7USD Copper HS
GPU cooling
Stock
OS
Vista Home Premium
Monitor
22" Asus AL2223W
1 Million+ Folding at Home points
lordikon is offline I fold for Overclock.net   Reply With Quote
Old 07-01-09   #5 (permalink)
PC Gamer
 
amd ati

Join Date: Sep 2008
Location: your front door ;)
Posts: 756

Rep: 43 0m3g4 is acknowledged by some
Unique Rep: 38
Trader Rating: 15
Default

wow, pretty ingenious of them.
looks like they took it and crafted it better than the pro's?
__________________
Quote:
Originally Posted by Shane1244 View Post
Maybe I can come over to your house and we can play some SuperPi? Then later on we can set up a LAN and play 3D Mark Vantage?

System: My System
CPU
x3 710 unlocked @ 3.7
Motherboard
ma790xt-ud4p
Memory
4g ocz plat 1600mhz
Graphics Card
sapphire 5850
Power Supply
corsair tx750
Case
nzxt guardian
CPU cooling
fuzion v1
OS
vista 64
Monitor
asus 24"
0m3g4 is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools



All times are GMT -5. The time now is 09:14 AM.


Overclock.net is a Carbon Neutral Site Creative Commons License

Terms of Service / Forum Rules | Privacy Policy | DMCA Info | Advertising | Become an Official Vendor
Copyright © 2009 Shogun Interactive Development. Most rights reserved.
Page generated in 0.12679 seconds with 8 queries