« Rogue Trail
Setting up a web trap… »

File infector reveals some lessons to be learned

May 28th, 2009

I have a webpage to monitor some of our stats and I use some GIF files to make it user friendly.

Yesterday I noticed that the pics were’nt displaying properly… Oddly enough, all the files also had the same size now…

vt0

I still had the originals, so I compared two of them. The new (infected) GIF contains PE Sections and PE Headers!

v2

I renamed the GIF file to EXE and ran it:

v3

Talk about a payload…

It replicates itself as “picture files” that really are executables, and disables the file extensions display.

v4

Upon analysis with our tools, you can see the registry key in question that hides all the .EXE extension.

v5

The file is well detected on VirusTotal:

v1

You may wonder how the GIF files got infected in the first place…

The files are stored on a SAMBA network share… This being a Worm, it’s no big surprise that it tried to propagate through everything it could find.

This allowed us to realize there was a security hole in our virtual machines systems that opened up the network in some rare cirmcustances, but not rare enough to happen every once in a while.

We also tightened up the file permissions to prevent such a thing from happening again:

red

What does that teach me?

- Never take for granted what malware can and can’t do

- Access control is crucial

- System designs must be built with potential weak spots in mind

Jerome

    This entry was posted on Thursday, May 28th, 2009 at 10:02 am and is filed under Malware Trends. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (33)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (15)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (110)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.