Wednesday, September 18, 2013

, , ,

VirusTotal += CMC

We welcome CMC as a new engine working at VirusTotal. In the words of the antivirus company:

"CMC featured in house developed engine called Odin with static, dynamic unpackers, an x86 virtual machine to provide advanced de-obfuscation and in-memory engine to detect malware called Sonar. There is also a reputation based system named CMCRadar to accelerate response time, early warnings and global white listing."

Tuesday, September 17, 2013

, , , ,

VirusTotal += Bkav

We welcome Bkav as a new engine working at VirusTotal. This scanner includes both signature based and cloud technologies. This vietnamese company, established in 1995, is also a smartphone manufacturer.

Wednesday, September 04, 2013

, ,

VirusTotal += Zemana AntiLogger metadata

Zemana is a security solutions provider that produces, among other software, a popular antilogger, in their own words:
In a nutshell, the AntiLogger is a lightweight app that keeps track of who is doing what on your computer. Instead of identifying malware based on its signature fingerprint, like all malware products with scan functionality, the AntiLogger catches malware at the moment it attacks your computer. It will then prompt you if an illegal program is trying to record your keystrokes, capture your screen, gain access to your clipboard, microphone and webcam, or inject itself into your computer’s sensitive areas.The AntiLogger features our unique SSL Intrusion Protection technology that guards you against advanced forms of Financial Malware. The AntiLogger is one of the very few products on the market today able to detect these dangerous and complex threats. Zemana AntiLogger is not designed to replace your installed antivirus software -- it's made to detect serious threats that are outside of their scope. It adds an extra layer of essential protection to whatever anti-malware or anti-virus software you're currently using.
As part of the work that Zemana carries out with respect to these forms of malware, they come across many malicious files and are able to characterize their behaviour according to the information theft activities they carry out. Zemana has been kind enough to share some of its behavioural notions with VirusTotal and now for many of the files in our dataset you will see Zemana behavioural tags such as:


  • keylogger
  • screen-capture
  • webcam-capture
  • microphone-access
  • clipboard-monitor
  • dll-injection
  • driver-installation
  • startup-registration
  • bho-installation
  • ssl-hook-installation


Please refer to the additional information tab of the following report in order to see how this data is rendered publicly:
https://www.virustotal.com/en/file/7a8a5298f0a5e8222f3746b429a18dbdaeb8bbc7a4070ef4490824ffda0b2c66/analysis/

This information is particularly interesting as it characterizes behaviour in end-user physical machines, i.e. real-world scenarios, so it can overcome common problems with behavioural sandboxes such as virtual machine detection. But the metadata shared does not limit to this, as they are also providing interesting data such as the in the wild file names for certain malware, which can sometimes be a hint regarding the dissemination and propagation strategies used by attackers.

Additionally, since Zemana is not designed to replace installed antivirus software but rather as a complementary security layer, they are very often able to detect zero-day malware with low detection rates, samples that they are actively sharing with VirusTotal in order to improve detection rates world-wide and help make the Internet a safer place.

Thank you Zemana team! Keep up the good work!

Tuesday, September 03, 2013

, ,

VirusTotal += Baidu-International

We welcome Baidu International as a new engine working at VirusTotal. In the words of the antivirus company:

“Baidu international antivirus engine innovated original ultrafast cloud security technology. We established a huge Black-White sample list system. By aligning the client software on the user's computer with servers in Baidu cloud security data center, Baidu Antivirus utilizes cloud computing technology and its massive file database to quickly and accurately eradicate the latest trojans, unknown trojans, and other malicious programs. This solves the problems faced by traditional antivirus software such as the lag behind the latest trojans and viruses and the huge consumption of computer resources.”

Monday, June 03, 2013

, , , ,

Social engineering attacks using DRM protected ASF files

Some of you may have already noticed that we have started to show new information for ASF files in the File details tab, example:

https://www.virustotal.com/en/file/b44378bc5f32700edd97d3f66479d9665194cfef95a2252c70a4237263bdfafd/analysis/

This information includes the content encryption object, the extended content encryption object and script command objects, if any at all.

The Advanced Systems Format (ASF) is Microsoft’s proprietary audio/video container format, this specification defines the structure of the audio/video stream and provides a framework for digital rights management (DRM) of the contained streams. Files using such a format are commonly seen with wmv, wma or mp3 extensions.

The Windows Media Rights Manager allows protection of the media content in such a way that once the user tries to play a file for which there is no valid license, Windows Media Player will display a URL defined by the content provider.

This scheme allows attackers to create evil media files forcing visits to malicious URLs when the crafted file is opened. In the following screenshot we can observe how a wmv file (https://www.virustotal.com/en/file/9c3d364fb2f6e43a8c1d149bfb929bc5fc1ec2a9ae6ca424d87295e65b61e3c4/analysis/) forces the user to visit xvidprox.com, this site deceives the visitor making him think he has to download and install a “required” plugin in order to watch the video, a common social engineering trick.



Parsing the file content encryption headers we find:

Content Encryption Header:
Secret Data: '\xcf\xb8\xba\xf2F2\xd3\xf7Sb\xd9D\xbd5\x936\x8c\xd2Tk\x97\xdb\tT'
Protection Type: DRM
Key ID: gAtyRGxTp0uyKC9AAbf3Gg==
License URL: http://www.microsoft.com/isapi/redir.dll?prd=wmdrm&pver=2&os=win&sbp=newclient

Extended Content Encryption Header:
<WRMHEADER version="2.0.0.0">
<DATA>
 <RID>1</RID>
 <CID>500</CID>
 <LAINFO>http://xvidprox.com/index.html?id=&amp;dlgx=1000&amp;dlgy=600&amp;adv=0</LAINFO>
 <KID>gAtyRGxTp0uyKC9AAbf3Gg==</KID>
 <CHECKSUM>ErLnEFXO!A==</CHECKSUM>
</DATA>
<SIGNATURE>
 <HASHALGORITHM type="SHA"></HASHALGORITHM>
 <SIGNALGORITHM type="MSDRM"></SIGNALGORITHM>
 <VALUE>Trh0AiQYQRBmw3qKi1i4Ox1Lv2FTC!4VFKZoCAJdGwnkPNC8z*bfDA==</VALUE>
</SIGNATURE>
</WRMHEADER>



Needless to say, you will not be able to reproduce the video file (commonly they are small encrypted videos no bigger than 300k and padded with useless data to look like the latest 800MB movie release).

Downloaded file analysis:
https://www.virustotal.com/en/file/5e0b93dfa2aca2463aa022141f079b9bb455d5823f0ab2c9fca8254834bcd47b/analysis/

Let us look at another example of a malicious video sample:
https://www.virustotal.com/en/file/2b75d7be851514dbaf1fa1649f5eee29efc9669ca774bae98944b72356fef4d3/analysis/


Again the ASF headers contain:

Content Encryption Header:
Secret Data: '\xfe\xf0\xfc\x0f\x8c\xf6^\xb9\x8eav\x9f\xfb\x92)\x9d'
Protection Type: DRM
Key ID: ldkokwerodkkkkkk
License URL: http://free-media-player.info/play.cgi?DlgX=800&DlgY=600

Extended Content Encryption Header:
<WRMHEADER version="2.0.0.0">
<DATA>
 <CHECKSUM>KeBODgJtVQ==</CHECKSUM>
 <KID>ldkokwerodkkkkkk</KID>
 <LAINFO>http://free-media-player.info/play.cgi?DlgX=800&DlgY=600</LAINFO>
</DATA>
<SIGNATURE>
 <HASHALGORITHM type="SHA"></HASHALGORITHM>
 <SIGNALGORITHM type="MSDRM"></SIGNALGORITHM>
 <VALUE>2tV2YzlYaZH1LFpq3CEUF+XrNT6+gh++dF3hNEWPONoVWUClPHXGKg==</VALUE>
</SIGNATURE>
</WRMHEADER>

The downloaded file is, once again, clearly malicious:
https://www.virustotal.com/en/file/38eb4c07d967862bbee40010671d111ca76d5e14c3ad23962bc0755ffeaf6fec/analysis/

We successfully tried these videos on Windows Media Player 11 and 12, no user iteration was needed to show the malicious websites, this leads to even more interesting automated exploitation through browser vulnerabilities.

We can find a deeper analysis of this matter in a 2010 post at http://habrahabr.ru/post/89676/ (Russian).

We believe displaying these new file details will further help malware researchers in their fight against the bad guys. Additionally, this attack trend leaves room for new interesting features to be implemented in VirusTotal with regards to the relationships between files. Was this file downloaded from a given site? And if so, was this site used in a media content DRM social engineering attack? Which video file was the initial trigger for the whole infection process? Interesting questions that we will soon be addressing.

Friday, May 03, 2013

, , , ,

VirusTotal += CyberCrime botnet panels tracker

Xylitol has been extremely kind in letting us enrich VirusTotal's URL scanner with his CyberCrime tracker. CyberCrime is a C&C panel tracker, in other words, it lists the administration interfaces of certain in-the-wild botnets. As such, its URL database is inherently smaller than other datasets integrated in VirusTotal.

Nonetheless, one should not neglect the usefulness of this tracker, very often other malware-related infrastructure will be located in the same host as the botnet administration panel, hence, it can prove itself very useful in finding evil.

https://www.virustotal.com/en/url/ba1cee3c6a157232ac8a61b17ff07694acc970e1bae9ced5c9ef2bfc56ae6ea1/analysis/1367596300/

Thank you Xylitol! Keep up the good work!
, , , , ,

VirusTotal += Virus Tracker

Just after Kaspersky joining VirusTotal's aggregate URL scanner, we are excited to announce that Virus Tracker is also becoming part of our family:

https://www.virustotal.com/en/url/82ddbb7eea25e7ce2ca13aed44cac009d9ff6c463e763d22b8b2043f20bd8a52/analysis/1367576071/

Virus Tracker is a service whose mission:
is to provide detailed infection statistics, C&C information and an automatically updated domain blocklist of various botnets to the security community.
The site is non-profit and focuses on banking trojans and financial malware, some of the botnets they track are: multibanker, sinowal, tinybanker, urlzone, zeus, ramnit, etc. This is fantastic news for the average end-user, since they will have a better view of the most perilous threats directly targeting their money.

Yet another URL scanner, one more and we will be in the forties, thank you Virus Tracker team!