Sunday, 10 August 2014

Android Bulletin

executive summary

Security is no longer a “nice to have,” but a must-have. Modern malwares are not only about stealing files anymore, they are about stealth and complexity too. Targeted attacks, one of the most vicious examples of a stealth threat, they precisely target individuals, businesses, governments and their data. These attacks are a sophisticated weapon to carry out targeted missions in cyber space.
The scenario becomes worst when these attacks are on your mobile devices. A scary fact to admit, our mobile have more critical and private data as compared to our computers. Our mobiles are authorized to access our mailboxes, bank accounts, social networks, online backups and whatnot.
In our digital forensics lab, while investigating client’s case we realized how users were compromised using Android based malware. Later on these malwares were sent to our malware analysis team for further in-depth analysis. In our malware analysis lab, we deeply analyzed malware to understand its working and behavior. In this edition we present few exclusive malware that we found lurking inside users Android devices without their knowledge.
With this research based bulletin we intent to create a research collaboration and educate our reader so that internet community can fight against these cyber threats.
         "The only truly secure system is one that is powered off, cast in a block of                         concrete and sealed in a lead-lined room with armed guards."
google services framework

In Android phones, sometimes you can’t stop malware from “serving” you, especially when the “service” is actually a malicious Android class running in the background and controlled by a remote access tool (RAT). This malware pretended to be a “Google Service Framework” and starts killing all anti-virus processed before performing any malicious activities. We found this fake Google Service Framework when we receive a financial fraud case. This fake app was installed in users mobile in which he had installed few banking applications and linked his account with his phone.
In the past, we have seen Android malware that execute privacy leakage, banking credential theft, or remote access separately, but this malware takes Android malware to a new level by combining all of those activities into one app. In addition, we found the hacker has designed a framework to conduct bank    hijacking.
A few seconds after the malicious app was installed, the “Google Services” icon appears on the home screen. When the icon was clicked, the app asked for administrative privilege. Once administration privileges were assigned, the uninstallation option got disabled and a new service named “GS” was started as shown below. The app icon showed “App isn’t installed.” when the user tried to click it again and the icon was removed automatically.

The malware has plenty of malicious actions, which the RAT can command, as shown below:
Within a few minutes, the app started connecting with the CNC server and begins to receive a task list from it. The server IP was 103.228.65.101, and was located in Hong Kong. We cannot conform that it’s the hacker’s IP or a victim IP controlled by the RAT or some pivoting attack.
After performing these activities, it first kills the antivirus process and then start modifying banking applications. After few house  user received a notification “The new version has been released. Please use after reinstallation.” But usually when an update is available, users are asked to download it not to install it. Android performs the installation itself. The malware then downloaded an app named after “update” and the bank’s short name from the CNC server, for example if SBI is the Bank then it will download SBI Update. Also while the fake banking app was downloading, the malware uninstalled the original bank app.
This was first step, in second step when the command to upload SMS is received from the RAT, all the SMS of Android phone started uploading to the CNC server. It’s more of a complex hijacking framework than a simple malware.
After successful execution of all steps planned by hacker, he was able to access his all bank account and was able to transfer  money from his account. Hacker was also capable to access his SMS for OTPs. This is how his all bank accounts connected to his mobile was compromised.
recommendations
It’s better to have a deep research about any app you install in your phone. If you are using banking applications with your phone then install only those apps which you actually use and do not give administrative access to any app.
sms worm
We received these malware when user complained that he received his mobile bill more than 100 times of his normal bill. Mobile bill showed that he has been sending many international SMS every day. This Android phone was brought to our knowledge for further analysis.

After normal analysis, we didn’t found anything malicious happening on his phone. We changed the SIM card and installed one prepaid SIM and balance was nil within minutes. Later on this case was taken up to our malware analysis lab for further analysis and we found an application named “XXshenqi.A”.
This application came up with free games APK downloaded by user from some torrent site. While installing the game, he was asked to download this  application and claimed that this will work as crack of game and without crack your game will not work. After downloading this    application, the game worked perfectly fine, so the user never cared to remove this crack and this malware had a functionality of spreading SMS worm.
Once the installation was complete, it asked user to fill a registration form. The data of this form were send to malware author.

The real behavior started when the form was filled. First it hides app’s icon from menu then startsregistering the phone to receive/send SMS broadcast and broadcast boot. App started a lot background service and hence slowed down the phone’s performance and  started draining phone’s battery. We also found that the incoming SMS were giving commands to infected phone to execute       malicious behavior, including the transmission of e-mail, send text messages, fake messages, sending malicious downloads links  contacts, etc. Also the user information were send to malware author to his email ID a137736513@qq.com as you can see in below source code extracted from malware.


 recommendations
Installing antiviruses and security solutions doesn’t secure your  device completely. Most of the users are compromised by pirated and fake apps. We recommend you to only download and install app from official market place (Google Play) of your device. Do not install or accept any .apk file until and unless you trust the  vendor or understand what you are doing
 se-cure mobile AV
 We received this fake antivirus in one of C-level employee of an MNC. His complaint was that his official and  personal IDs are used for sending spam message without his knowledge. Obviously our first doubt was that his laptop might be infected but he was using    secured official corporate laptop and hence we didn’t found   anything malicious on his laptop. Then we moved to another devices through which he accessed his emails, and we found that he accessed his mails only from company laptop and from his   Android phone. During investigations, he mentioned that while surfing some sites via mobile, he got a pop-up window saying that you are out 10,000th visitor and hence we are giving you 1 year free license of antivirus program, download and follow the  instructions. He was motivated enough to download it and follow the instructions to install it in his Android phone.

This anti-virus program was actually a spam mail sender and the user had already authorized fake antivirus program to access his Gmail ID. Also, his email was used to send invite to his all personal as well as  official contacts and hence this fake antivirus was spread in his entire office and few more colleagues were using it.
User was also using one reputed antivirus and this program wasn’t detected as malicious as this program as it didn’t performed any malicious activities in beginning. When the program was installed, it automatically established connection to                           http://malicious.coproration.hxor.ex/ and downloaded few more supporting files and these files were actually malicious.
recommendations –
We recommend our readers to not to be fooled by these lucrative offers. Sometimes you may receive offers related to your internet searching habits or page you liked in Facebook but most of them are fake. Do not use or download any pirated antiviruses as these are meant to protect your device and alert you for any possible threats. And if you are using pirated antivirus, it will not alert you anymore. It’s like hiring a thief as guard of your home.
installing genuine “flash player”?

You might be aware about fake antiviruses and fake apps but what about genuine famous apps delivering malware to your device? Few famous and widely used apps are customized by hackers to deliver ransomware to your device. Ransomware is a type of   malware which restricts access to the mobile device that it infects, and demands a ransom paid to the creator of the malware in    order for the restriction to be removed.The malware comes in the form of “flash player” and install like normal apps, it also remains undetected by most of the mobile antiviruses as this app will not perform any malicious    activity, instead it will download some malicious code to perform that  malicious activity on your device. Once this app is installed it starts killing on-system processes and a message appears on users screen to deposit 300$ in order to unlock your own device.
After clicking proceed button a message pop up instructing user to pay $300 to GreenDot MoneyPack and retrieve a coupon code thereafter user will enter that particular code in order to    unlock the device. This makes the malware author untraceable. MoneyPak is a portal to send money to where users need it. It works as a ‘cash top-up card’ and once user have purchased it by a participating retailer with cash or online transfer, he is need to purchase a $300 card and enter the code here.
Even after purchasing $300 card, there is no assurance that your device will work properly like it was working before the invasion.

The malware does its best to be as intrusive as possible by blocking the victim’s normal device-use with the app. It uses a   Java TimerTask, which is set to run every 10 milliseconds, the application will kill any other running processes that the user        interacts except the malware itself. The malware also uses an  Android WakeLock to prevent the device from going to sleep.
In some cases, these apps steals your IMEI too and displays it to the user as a scare tactic. Sometimes user receives threatening messages saying – ‘We know who you are’. In some instances the app sends this IMEI back to its command & control server (C&C) to identify the device later to make it work like a bot.
Most of the time users receives messages and notifications that you have been caught by FBI and this is an FBI malware. Even the malware captures user’s photo from front camera to make the threatening more realistic.
recommendations
Unfortunately, these ransomware are not detected by several  major mobile antivirus and security solutions and these are  extremely hard to remove if you had given this malware device administrator privileges. Flashing or hard resetting your device will work in all cases to get back your phone in proper functioning state. Avoid giving device administration access to applications unless you’re really sure of what they do. Only download apps from developers you know and trust. Download apps like Lookout, which can detect these threats before you open them
  


  





Thursday, 10 July 2014

Security Bulletin

executive summary

We at CCFIS believe in research and innovation. We capture malware, decode them and then reverse engineer it to dig more information about it. Every malware we capture, we  deeply analyses it in our state-of-art malware analysis lab. The best part of our malware analysis lab is that instead of relying on commercial tools, we have developed our own sandboxing environment that can simulate almost all operating systems and network infrastructure. We have developed capabilities to      decode and break most of the malware that might be lurking  inside your network.
Our specializations are also in understanding and predicting attack methodologies. In our attack analysis lab, we can simulate different types of attacks being performed by attackers to compromise the systems on various platforms. Once the attack methodologies are identified, we release attack countermeasures to safeguard from these attacks. We are also capable of reverse engineering these malwares and exploits used by attackers to compromise. 
Last but not the least, in our forensics lab, we can gather complete DNA analysis information of any malware or attack. Our  forensics lab have different capabilities to support our research like data recovery, memory forensics, packet analysis and many more.
With all these advanced capabilities and state-of-art labs, we present you our research driven security bulletin which is result of our analysis performed on different malwares, attacks and exploits.
malware size
In this age when we carry GBs of storage space in our pockets and don’t even care about files less than 10 KB or 1 MB. While    analyzing all the malwares we captured from different location via our ATP sensor, we realized that most of the malwares were as small as 10 KB. These programs were actually not malware but were opening gates and downloading malwares from remote    location.
Unfortunately, most of antivirus will not detect it as a virus as it’s not performing any suspicious activity in your computer, it’s just    downloading the file that will perform malicious activity on your computer i.e. the malware.
 Deep inside the code of these programs, we found download IP/URL, username, password and path of malware. Also some of   programs were intelligent enough to detect your operating system and download malware accordingly. For example if you are using Windows 7 and avast antivirus then it will download the malware which can work perfectly fine with combination of Windows 7 & avast antivirus.
In our complete research we found that most of these malicious programs and malwares are not larger than 1 MB. So next time if you are ignoring this files, think twice before ignoring.
recommendations –
· Delete unknown file. If you don’t understand it, or identify it, delete it simply. Stay alert and don’t delete any system file.
· Always monitor your task manager and start up processes and locate the file and if it’s not signed by vendor known to you, simply delete it.
· Most of the time you won’t be able to delete these malware by simply right click and delete. In that case boot your computer in safe mode and try deleting. If malware is smart enough and not allowing you to destroy itself, then install any Linux based live OS in pen drive and then delete these files.

state of malware: encrypted unencrypted

We in information security domain claim that we know all encryption-decryption algorithms, but do we actually know all algorithms? The answer with our research data as evidence is ‘NO’, we don’t know even half of encryption techniques that     exists.
At CCFIS malware analysis lab, we have state of art lab with best malware analysts and almost all tools, equipment and infrastructure. We also developed several in house tools and technologies to analyze malware captured by our ATP sensor. We develop sandboxing technology where we can simulate almost any operating system, network infrastructure and working environment.
After creating this state of art malware analysis lab and best experts & researchers of country we are not even able to decrypt half of these malware to user readable source code format.
Now a days hackers are not using pre-defined algorithms that are publically available internet to encrypt their malware. And if the decryption methodologies are not known to antivirus companies, then how will they detect these malicious programs as malware and release patch for their users.
For analyzing these types of malware we used behavioral analysis and sandboxing technologies both on virtual as well as physical machines and finally we were able to identify these as malwares but still as these malwares were encrypted with methodologies that are not available publically, we were not able to dig into the code.
recommendations –
· Keep an eye over your task manager and see if any unknown process is running in background.
· Additionally you can open Command prompt by typing cmd in Run and then netstat to see list of all IPs your computer is   communicating to. Before doing this, close all browsers and   running applications and see if your system is communication to any unknown IP. If it is communicating then block that particular IP by editing C:\Windows\System32\Drivers\etc\networks in notepad.
 coding language


We at CCFIS malware analysis lab has developed advance  capabilities to open up malwares to user untestable coding language. In our complete analysis to prepare advance threat  report for our customers, we came up with above chart of coding language in which most of the malwares were coded.
In previous issue of our security bulletin, we explained Perl as  favorite language for hackers for creating malwares. In these issue too we found that Perl is the favorite language of hackers for  coding malwares. Remember the phrase – ‘old is gold’? Hacker’s also remember the same phase. As you can see from data above, hackers are still using C & C++ to code most lethal  malwares.
 Python is being used by attacks to code exploit and PoC of most known CVEs. We received several MS Office 2010 based exploit CVE-2014-1761 coded in Python in several ATP sensors that were simulating Windows 7 and MS Office 2010. We also found that most of the shells were coded in PHP to get root access of server hosting the web application. We found several PHP shells in ATP sensors simulated latest wordpress CMS uploaded by attackers in latest version. So if you are a wordpress user, stay alert and keep looking for new files. If you don’t understand it, just Google it or simply delete it.
recommendations
If you don’t use Perl or Python on your Windows machine and install it only out of passion and use very rarely then consider uninstalling it, this will reduce threat of Perl or Python based  remote key-logger. In our research we found that systems without these compilers were not compromised by these malwares but the systems with Perl or Python compiler were compromised easily by these remote key-logger malwares.
file extensions


 A filename extension is a suffix to the name of a computer file   applied to indicate the encoding of its contents or usage. Who says that Windows based malware come in exe format, not       anymore. Above data proves that malware are being packed in different formats to infect users more smarty.
When we are busy in planning business strategies, attackers are busy planning new attack strategies to infect your systems. In first phase, instead of sending you malware in any execution format they are sending these malwares is .doc, .zip, .tar and other        formats and most of the times these files are password protected.  In second phase they simply send a small program that contains password and execution instruction of that particular malware hidden inside these .zip and .tar files. Now these small programs which are actually not malware, opens up these compressed files and execute malware.
 We simulated same techniques and we were able to bypass       almost all updated latest antiviruses. So while simulating if we are able to bypass these antivirus then attacks must be bypassing your all antivirus and security solution. Think about it, if your antivirus or firewall are not detecting any attacks then it does not mean that you are not being attacked, it might be possible that you are    being attacked but your antivirus or firewall are not detecting it.
Attackers are even using file renaming techniques. For example if they want to send you a malware named document.exe then    instead of sending it in document.exe format they are renaming it in document.doc.exe. Also they are changing the icon to make it look like a document or an audible file.
recommendations:
To detect these type of files, just go to folder options and uncheck ‘Hide extensions for known file types’. After doing so, check for files with dual extensions like document.doc.exe. And delete it.
malware type
Backdoors are often installed by attackers who have  compromised a system to ease their subsequent return to the    system. Backdoors in your computer may be accessed by attackers without your knowledge or consent. Backdoors are  considered to be real security threats.
While analyzing malware captured by ATP sensors installed across the globe we found that most of the malware were backdoor. An attacker tries to install a backdoor only when he has already      exploited some vulnerabilities to compromise your system. We also found Trojans, which are generally non-self-replicating type of malware program containing malicious code that, when            executed, carries out malicious actives like, key-logging, spamming, theft of data, and possible system harm.
The most shocking was to see that 26.6% of malicious programs were not detectable by most of antiviruses. We declared these files as malicious file after performing behavioral & code analysis of these malicious files.
Using antivirus and security solutions are best practices but simply relying & trusting your antivirus is not advisable.
recommendations—
We recommend following best practices to safeguard yourself from these identified & unidentified malwares
· Always monitor processes running in your task manager. If you find any suspicious process, kill it immediately.
· Check for msconfig startup options and see what programs are            automatically started when you boot up your system.
· For browsing, we recommend Google Chrome with Ad-block extension. Most of the systems are infecting by foolish activities of users while   browsing like clicking on lucrative and attractive ads. Google Chrome will block sites hosting malicious codes and Ad-block extension will block all annoying ads.
· Perform a netstat in your command and see if your system is trying to communicate with any unknown IP, if yes then block that IP manually from C:\Windows\System32\Drivers\etc\networks.

region wise


  • Alfa – Corporate simulation
  • Delta – Financial institution simulation  
  • Beta – Government simulation

Our ATP sensor can simulate any network infrastructure ranging from complete production environment of banks to corporates. After this analysis, we realized that hackers are targeting mostly on corporate. Targeting money directly is old fashioned, but            targeting data worth money is easier and safer trend opted by hackers now a days. After stealing data from corporates, hackers are selling company sensitive files over underground communities (deep web).
 But still financial institutions are money and this is what that attracts most of attackers. So we created a dummy money bank with our ATP sensor and left it vulnerable to exploits. The result was as expected. Hackers used so complex techniques and 0-day exploits to compromise the network to get the money.
So if you are from corporate or financial institutions, no matter what security solutions you implement, hackers will always try to target you.
recommendations
In this case, we would recommend you to install ATP sensor in your location so that you can deflect attacks form your original network to a fake decoy monitored server. By deflecting most of the attacks you saved your networks from 70% targeted and automated attacks.
Also later on you can scan your network with these attacks, malware and exploit to see if your original network are vulnerable or not.
ATP sensors deployed in metro cities were compromised and attacked more than ATP sensors deployed in other cities. This simplifies that if you or your organization is in metro city then it increases probability of being attack.
 most targeted networks

We developed our ATP sensor to replicate several organizations like research & development, financial, educational, government and critical infrastructure.
It is obvious that research and development organization are  continuous under attack by intelligence agencies to understand capabilities and to gather information about what others are    doing. Same are being attacked by hackers to steal new        technologies, patents and later on make money out of it.
Critical infrastructure (CI) are assets that are essential for the   functioning of a society and economy. Most common sector of CI are chemical sectors, commercial facility sectors,                     communications, critical manufacturing, dams, defense industries, emergency services, energy & power grids, financial, government facilities, healthcare, information technology, nuclear plants, transportation, water, etc. Hackers are trying to hack these       sectors.
 Hacking into these sector can result to creation of weapon of mass          destruction.
If your organization belong from any of above sectors, we would              recommend you to follow the best practices made by National Critical     Information Infrastructure Protection Centre (NCIIPC).
Financial institutions were soft targets for attacks and will be soft targets for attacks. Also now a days attack are trying even to penetrate into educational organizations. There might be many reason behind these but several reason that we predicted are that most of the universities in India are research driven and research conducted by students at their university level are business for others and for themselves after several PoCs. So,   hackers are also interested in these research data that they can steal and can be purchased by some investor. Another prediction is that, now a days every another teenager is either bug bounty hunter or a hacker. So it might also be possible that these students might be trying to hack into their university network to get question papers or hack into university ERP to manipulate their marks & attendance.
One of our major client Amity University captures 500+ targeted malware and 20,00,000 + targeted attacks after deploying ATP sensor. A hacker’s   intensions cannot always be judged by his attack methodologies and hence if you are an educational organization and thinking that who will attack you then example of Amity University proved you wrong.
Also to conclude, if educational organization like Amity University which is not doing any business or any production environment are being attacked to brutally then what about other organizations who are actually doing some business and working on financial sectors.
country wise analysis
IPs of countries detected in attacking India’s network infrastructure. There are no of possibilities
· The country attacking India’s infrastructure might be actually performing attacks and hence responsible to sending malwares.
· IPs of these countries were used as proxies to perform attacks.
 
· It might also be possible that computers of these countries might be compromised and hackers might be pivoting attacks to India from systems of these countries.



attack timelines: hourly


With data collected by all locations of our ATP sensors, we created a central data of 6 months to predict at what time most attacks are happening and attacks are most active.
Most common attacks are happening between 7 PM to 10 PM. This is the most prime time for all Indians to check their social network, online shopping and other personal works that they  cannot perform during official hours of 9 to 6. Most of the             attackers are also active during this time only. Peoples are using their personal computer and laptops which are less secure than their office computers and hence it’s easy for attacker to  break into their system.
Attackers are less active during day. Our ATP captured that India’s infrastructure are facing between attacks after 4 AM to 6 PM. And this is the time when we are sleeping, exercising, walking or     working in offices.
Targeted attacks are not only those in which an attack sends a mail with malware specially crafted to compromise user system only, but these are actual targeted attacks in which attacker know your personal time table and know at what time you will be online over less secure systems and performing personal &            financial transactions.
attack timelines: dates


We monitored logs of 6 months of all locations where we have    installed our ATP sensors. We concluded to a result that attackers were most active on 20th and 28th of every month.
We also summarized that attacks are more active during end and starting of month. In India most of online shopping users make online transactions during this dates only. As most Indians receive their salary during this period only and spend specially in these  period.
Hackers are less active during mid of the month. So it might be possible that attackers might be sniffing or capturing payment  details.
One cannot predict attacker only by his attach methodologies, a behavioral analysts is always required in an organization to predict mindset of an attacker.