Friday, April 3, 2009

ConfickerC Update

OK just a quick update regarding ConfickerC numbers. 

I have seen published numbers that are all over the place *cough IBM/ISS cough*. 

Over the last 30 hours or so we recorded 9,795,101 raw (not unique IP) http connections to the sinkhole.

 As unique IPs go we recorded a total of 1,071,132 unique IPs from with in that 9+M. Now keep in mind, we have to think about DHCP churn, NAT (Firewalls, gateways, proxies, etc) So the number is obviously not a 100% true representation.  

Here is what the PER HOUR numbers look like from the sinkhole:





Tuesday, March 10, 2009

PIFTS


Something is rotten in the state of security.

Users of Symantec's Norton AV have been reporting instances of a file named PIFTS.exe trying to connect out to the Norton updates.

This wouldn't be news in and of itself, but it seems that Symantec doesn't want to discuss the issue. All questions regarding PIFTS are removed from the message board within minutes of being posted. Some users have been banned after attempting to repost.

Since they can't turn to Symantec for answers, many users have turned to the communal knowledge of the web. Unfortunately, the bad guys have also noticed the influx of searches for PIFTS.exe and some of the top results in Google are actually malicious, attempting to infect any visitors with rogue anti-virus Malware. DO NOT DOWNLOAD ANYTHING from those sites.

ThreatExpert has a breakdown of PIFTS and its attempt to phone home here

VirusTotal shows no hits

Brian Krebs @ The Washington Post is trying to get some answers.

SANS Internet Storm Center writes that they've been contacted by a Symantec employee who claimed ownership of the file and tried to make clear that it isn't intended to do any harm.

Nice of them to respond...

But won't they let people talk about it on the msg boards?

Why the secrecy Symantec?

**Update** (courtesy of Brian Krebs @ The Washington Post)

"David Cole, senior director of product management at Symantec, said the PIFTS file was part of a 'diagnostics patch' shipped to Norton customers on Monday evening. The purpose of the update, Cole said, was to help determine how many customers would need to be migrated to newer versions of its software as more Windows users upgrade to Windows 7."

As to why Symantec was deleting forums posts and banning users for mentioning PIFTS, Cole says, "hundreds of new users began registering on the forum, leaving inane and sometimes abusive comments."

This is a lame excuse. Though the forums do seem to have been hit by the 4chan crowd, the first people to ask questions were very polite and straightforward. They asked simple questions, like 'hey, how come part of your software wants to access the Internet?'

Not exactly ban-worthy behaviour.

A forum moderator could have simply (easily!) answered the question and closed the thread. Wouldn't that have saved everyone a lot of trouble?


Tuesday, March 3, 2009

Coin Toss



http://tinyurl.com/akvagb

Go. Read the article.

Anti-virus software vendors like to proclaim that their products achieve success rates in the 90%+ range. This is false and misleading.

It is inconceivable that end users (and many corporate entities) still believe that AV software is the catch all for security.

A 50% success rate is unacceptable. It is a coin toss - 50/50 chance - that your network is secure.

"The average delay in detection and remediation was 54 days."

54 days?! Two months?!

The bottom line here is that Malware created for non-commercial purposes simply does not exist anymore. It hasn't in over two years.

Modern Malware is specifically designed to operate quietly and unobtrusively for as long as possible. The bad guys are after our social insurance numbers, credit card numbers, bank account details, credit equity, customer lists, a jump on the quarterly earnings, our emails, online payment accounts, access to our social network of friends, ANYTHING they can get their hands on.

Think about it: the average delay in detection is 54 days. For almost two months the bad guys have access to your system.

This isn't like having your house robbed.

It's like having your house broken into and the robbers moving in and hiding in your closet for two months.

From home users to large corporate networks, we must - MUST - move beyond our tired notions of network security. The bad guys are always evolving, adapting their Malware to evade detection and improve levels of compromise. Why haven't the good guys evolved?

The numbers speak for themselves:

"About 3 to 5 percent of all systems in an enterprise are infected with bot-related malware -- even within organizations running up-to-date antimalware tools."

"Antivirus software immediately discovered only 53 percent of malware samples."

"Another 32 percent were found later on, and 15 percent were not detected at all."

Now you may be thinking that 15% doesn't sound like a lot, that maybe that's an acceptable level of risk. Consider this:

Security researchers around the world analyze anywhere from 20-30,000 pieces of Malware every day. Every day!

The Shadowserver Foundation has analyzed over 19 million Malware samples in the past 12 months alone.

15% of 19 million is a big number.

You really want to take that chance?


Friday, February 20, 2009

Building a Botnet

Friday, January 30, 2009

Is your computer watching you?


SecureWorks has a posting up discussing the Ozdok/Mega-D trojan and its ability to capture screenshots on the systems it's infected. We've been talking about this for months! Ozdok is certainly not the only trojan with this ability, and the researchers are specifically talking about screenshots, but what about systems with webcams?

Think the bad guys know how to turn those on?

Check out the video posted in our Facebook group and find out!


Wednesday, January 28, 2009

24/7



We're opening the office doors:

Defintel's on Twitter. Check it out, drop us a line.

Facebook too. Join the Defintel group for botnet building videos, photos, and a chance to ask us questions about computers, security, videos games, comics, and just about anything else.

From the whole Definel team:

Welcome!


Wednesday, December 17, 2008

Explorer Exiled

There is a 0day exploit currently exploiting a critical flaw in Microsoft's Internet Explorer.

If this is the first you're hearing of this flaw, check out the link below to hear Defintel's CEO, Chris Davis explain the situation:

CTV News - Exploiting Explorer

Researchers estimate that more than 10,000 sites are compromised. While in-the-wild exploits are currently targeting IE 7 on Windows XP SP2 and SP3, Windows Server 2003 SP1 and SP2, Windows Vista (including SP1) and Windows Server 2008, it's important to remember that all versions of Internet Explorer, from IE5 all the way to IE8 Beta 2, are affected.


If a user visits a compromised site, malicious JavaScript code is injected into the browser, and Malware is downloaded onto the user's computer. The Malware that gets installed on the user's computer will likely remain nearly invisible to the average user. The goal of the attacker is not to disrupt a user's online experience, but rather to remain inconspicuous for as long as possible. The Malware allows the attacker complete access to user's computer and allows him to track everything you type into your keyboard.

Visit your legitimate online banking site and enter your user information? Now he's got it.
Visit your favourite social networking site and chat with some friends? Now he's got that too.

Microsoft intends to release a critical patch today, the second patch coming on Exploit Wednesday instead of Patch Tuesday in as many months. Back in October, Microsoft was forced to release an out-of-band patch to mitigate the extremely critical flaw in several Windows OS'.

In the meantime, users should use other browsers - FireFox, Chrome, Safari - whatever you like! Just not IE.

The general public is completely ill-equipped to deal with security events. Who knows how long it will be before the AV companies have signatures developed for this new exploit. And Microsoft surely isn't losing any market share over yet another security debacle.

Why do we still treat online security as though the Internet only encompasses six guys at Berkeley? Everyone is online, from 5 year old girls to 95 year old men - they can't all be expected to keep up to date with these vulnerabilities and exploits.

So, how do we help them?