fyodor yarochkin - dissecting unlawful internet activities

69
Dissecting unlawful Internet Activities Fyodor Yarochkin @fygrave Armorize Technologies

Upload: defconrussia

Post on 18-Jan-2015

620 views

Category:

Technology


1 download

DESCRIPTION

International Security Conference "ZeroNights 2011" - http://www.zeronights.org/

TRANSCRIPT

Page 1: Fyodor Yarochkin - Dissecting unlawful Internet activities

Dissecting unlawful Internet Activities

Fyodor Yarochkin

@fygraveArmorize Technologies

Page 2: Fyodor Yarochkin - Dissecting unlawful Internet activities

АГЕНДА

Observations

Case studies

Sampling goods and services

Q & A

(c) 2011 Armorize Technologies

Page 3: Fyodor Yarochkin - Dissecting unlawful Internet activities

MEET THE AUTHORS

(c) 2011 Armorize Technologies

Page 4: Fyodor Yarochkin - Dissecting unlawful Internet activities

Our environment

Honeypots (http, ftp, ssh, smtp, ...)

Sandboxes + proactive internet “browsing”

End points around the globe

Public discussion groups of interest: scrapping and indexing

(c) 2011 Armorize Technologies

Page 5: Fyodor Yarochkin - Dissecting unlawful Internet activities

Overview

(c) 2011 Armorize Technologies

Page 6: Fyodor Yarochkin - Dissecting unlawful Internet activities

What makes the news..

MALWAREBlack SEO

Fake AVMass Injections

CC abuse

(c) 2011 Armorize Technologies

Page 7: Fyodor Yarochkin - Dissecting unlawful Internet activities

MAIN ACTORS

KiddiesProfit Oriented

Crime APT

(c) 2011 Armorize Technologies

Page 8: Fyodor Yarochkin - Dissecting unlawful Internet activities

Range of players!

(c) 2011 Armorize Technologies

Page 9: Fyodor Yarochkin - Dissecting unlawful Internet activities

Kiddies: hit our honeypots daily :)

(c) 2011 Armorize Technologies

Page 10: Fyodor Yarochkin - Dissecting unlawful Internet activities

Still live in IRCBOT age

(c) 2011 Armorize Technologies

Page 11: Fyodor Yarochkin - Dissecting unlawful Internet activities

APT

• Kiddies are not very interesting. Following the APT guys is a bit more fun

APT – advanced persistent threat (made lots of noise after Aurora attacksBut, .. how advanced that is.. really :-))

(c) 2011 Armorize Technologies

Page 12: Fyodor Yarochkin - Dissecting unlawful Internet activities

APT: attack vectors – often plain silly

(c) 2011 Armorize Technologies

Page 13: Fyodor Yarochkin - Dissecting unlawful Internet activities

APT: in taiwan

• Targets: academics, post, rail, ..

(c) 2011 Armorize Technologies

Page 14: Fyodor Yarochkin - Dissecting unlawful Internet activities

APT: main characteristics

• Attacks are planned and methodological

• In many instances – the primary aim of an action is information gathering (i.e. javascript that collects and posts the user environment information)

• Malicious content is well-prepared (digitally signed w/ valid certificates etc etc)

(c) 2011 Armorize Technologies

Page 15: Fyodor Yarochkin - Dissecting unlawful Internet activities

APT Research from xecure-lab guys

(c) 2011 Armorize Technologies

Page 16: Fyodor Yarochkin - Dissecting unlawful Internet activities

Aptdeezer: apt analysis platform from xecure-lab

(c) 2011 Armorize Technologies

Page 17: Fyodor Yarochkin - Dissecting unlawful Internet activities

Businessmen are fun to study:)

Online goods

services

Traffic

(c) 2011 Armorize Technologies

Page 18: Fyodor Yarochkin - Dissecting unlawful Internet activities

How to steal a million?

(c) 2011 Armorize Technologies

Page 19: Fyodor Yarochkin - Dissecting unlawful Internet activities

Effectiveness

• Old school: steal it from a bank. Make a lot of noise and either get caught (or run to South America)

• New school: steal a dollar from a million people. It is still a million (and no noise).

(c) 2011 Armorize Technologies

Page 20: Fyodor Yarochkin - Dissecting unlawful Internet activities

So, where is the money?

CC cashing

Banking credentialsAds (PPC)

Mobile scam

Pharm

Pr0n

DIRECT SOURCES:

Extortions“Software”

INDIRECT SOURCES:

TRAFF Credentials Online goods& services

(c) 2011 Armorize Technologies

Page 21: Fyodor Yarochkin - Dissecting unlawful Internet activities

TRAFFIC..

• You need users to start visiting your “milking resource” to start with..

(c) 2011 Armorize Technologies

Page 22: Fyodor Yarochkin - Dissecting unlawful Internet activities

TRAF. COST

• AU - 300-550$

• UK - 220-300$

• IT - 200-350$

• NZ - 200-250$

• ES,DE,FR - 170-250$

• US - 100-150$

• RU, UA, KZ, KG .. 10-40$(c) 2011 Armorize Technologies

Page 23: Fyodor Yarochkin - Dissecting unlawful Internet activities

Case studies~

(c) 2011 Armorize Technologies

Page 24: Fyodor Yarochkin - Dissecting unlawful Internet activities

Infrastructure compromise: case study

(c) 2011 Armorize Technologies

Page 25: Fyodor Yarochkin - Dissecting unlawful Internet activities

UNDER THE HOOD

(c) 2011 Armorize Technologies

Page 26: Fyodor Yarochkin - Dissecting unlawful Internet activities

Looking into Packet fields

(c) 2011 Armorize Technologies

Page 27: Fyodor Yarochkin - Dissecting unlawful Internet activities

TRACKING THE GHOST

(c) 2011 Armorize Technologies

Page 28: Fyodor Yarochkin - Dissecting unlawful Internet activities

HYPO: ATTACK SCENARIO

(c) 2011 Armorize Technologies

Page 29: Fyodor Yarochkin - Dissecting unlawful Internet activities

RESULTED IN...

http://tools.cisco.com/security/center/viewAlert.x?alertId=17778

(c) 2011 Armorize Technologies

Page 30: Fyodor Yarochkin - Dissecting unlawful Internet activities

Compromised CAs

• How about combining this and compromised CA?

(c) 2011 Armorize Technologies

Page 31: Fyodor Yarochkin - Dissecting unlawful Internet activities

WHAT HAD HAPPENED..

Your taffic is mirrored!!

tunnel source <interface>

tunnel destination <badIP>

(c) 2011 Armorize Technologies

Page 32: Fyodor Yarochkin - Dissecting unlawful Internet activities

How were they 0wn3d?

(c) 2011 Armorize Technologies

Page 33: Fyodor Yarochkin - Dissecting unlawful Internet activities

AND MORE..

(c) 2011 Armorize Technologies

Page 34: Fyodor Yarochkin - Dissecting unlawful Internet activities

LESSON LEARNT

• The whole city compromised

• Users infected on the fly. Visiting legimate web sites

• Tricky to investigate

• Affected parties - complete denial

(c) 2011 Armorize Technologies

Page 35: Fyodor Yarochkin - Dissecting unlawful Internet activities

Other varieties ;-)

(c) 2011 Armorize Technologies

Page 36: Fyodor Yarochkin - Dissecting unlawful Internet activities

Ad ABUSE: “MALVERTISEMENT”

(c) 2011 Armorize Technologies

Page 37: Fyodor Yarochkin - Dissecting unlawful Internet activities

Introducing ad. Space hell :)

Source: razorfishmedia.com

(c) 2011 Armorize Technologies

Page 38: Fyodor Yarochkin - Dissecting unlawful Internet activities

Ad network dynamic bidding

• Ad network dynamic bidding system is asking for abuse :-)

• Decentralized, small players feed data to bigger guys (doubleclick), verification is mostly manual, real-time content tampering is easy, automated target selection, number of mechanisms that prevent click fraud (and makes automated analysis hard!!!)

(c) 2011 Armorize Technologies

Page 39: Fyodor Yarochkin - Dissecting unlawful Internet activities

MALVERT. Mechanics

iframe

redirect

iframe

redirect

iframe

Iframe to TDS(c) 2011 Armorize Technologies

Page 40: Fyodor Yarochkin - Dissecting unlawful Internet activities

Malvertisement (cont)

(c) 2011 Armorize Technologies

Page 41: Fyodor Yarochkin - Dissecting unlawful Internet activities

Malvert: agencies get 0wned

• Pulpomedia incident:

(c) 2011 Armorize Technologies

Page 42: Fyodor Yarochkin - Dissecting unlawful Internet activities

Extortions going international

(c) 2011 Armorize Technologies

Page 43: Fyodor Yarochkin - Dissecting unlawful Internet activities

Also spanish version

Credit: http://xylibox.blogspot.com/

(c) 2011 Armorize Technologies

Page 44: Fyodor Yarochkin - Dissecting unlawful Internet activities

Common characteristics

• Hosting and domain registration

Registration Service Provided By: Bizcn.comWebsite: http://www.cnobin.comWhois Server: whois.bizcn.com

Domain name: bundespol.net

Registrant Contact: Whois Privacy Protection Service Whois Agent [email protected] +86.05922577888 fax: +86.05922577111 No. 61 Wanghai Road, Xiamen Software Park xiamen fujian 361008 cn

person: Ionut Triparemarks: SC GoldenIdeas SRL

address: Str. Drumul Sarii, nr. 57Caddress: Sector 6, Bucuresti

phone: +0744885334abuse-mailbox: [email protected]

nic-hdl: IT1737-RIPEsource: RIPE # Filtered

mnt-by: GOLDENIDEAS-MNT

person: Ionut Triparemarks: SC GoldenIdeas SRL

address: Str. Drumul Sarii, nr. 57Caddress: Sector 6, Bucuresti

phone: +0744885334abuse-mailbox: [email protected]

nic-hdl: IT1737-RIPEsource: RIPE # Filtered

mnt-by: GOLDENIDEAS-MNT

(c) 2011 Armorize Technologies

Page 45: Fyodor Yarochkin - Dissecting unlawful Internet activities

WAS ON THE NEWS

(c) 2011 Armorize Technologies

Page 46: Fyodor Yarochkin - Dissecting unlawful Internet activities

COMMON PATTERNS

Exploits Social tricks

(c) 2011 Armorize Technologies

Page 47: Fyodor Yarochkin - Dissecting unlawful Internet activities

“Social engineering”

(c) 2011 Armorize Technologies

Page 48: Fyodor Yarochkin - Dissecting unlawful Internet activities

Well-operated :)

• Spreads through advertisements (social engineering and exploits)

• Reboots machine until license is purchased (80USD)

• Provides support hotline (hosted in India)• Uses legimate payment gateways (possible

to do refunds)(c) 2011 Armorize Technologies

Page 49: Fyodor Yarochkin - Dissecting unlawful Internet activities

Another attack: infrastructure

(c) 2011 Armorize Technologies

Page 50: Fyodor Yarochkin - Dissecting unlawful Internet activities

Infrastructure

Speedtest.net

Ads.ookla.com

http://35ksegugsfkfue.cx.cc(c) 2011 Armorize Technologies

Page 51: Fyodor Yarochkin - Dissecting unlawful Internet activities

TDS systems: TRAFF marketplace

(c) 2011 Armorize Technologies

Page 52: Fyodor Yarochkin - Dissecting unlawful Internet activities

COMMON TDS

(c) 2011 Armorize Technologies

Page 53: Fyodor Yarochkin - Dissecting unlawful Internet activities

TDS + verification srv

(c) 2011 Armorize Technologies

Page 54: Fyodor Yarochkin - Dissecting unlawful Internet activities

SEO:Another option

• Black SEO:

(c) 2011 Armorize Technologies

Page 55: Fyodor Yarochkin - Dissecting unlawful Internet activities

SEO USE and abuse :)

<*bad* word (rus)

(c) 2011 Armorize Technologies

Page 56: Fyodor Yarochkin - Dissecting unlawful Internet activities

SEO SERVICES

(c) 2011 Armorize Technologies

Page 57: Fyodor Yarochkin - Dissecting unlawful Internet activities

Goods and services :Sampling :)

(c) 2011 Armorize Technologies

Page 58: Fyodor Yarochkin - Dissecting unlawful Internet activities

Digital currencies

• Modern day hawalla

(c) 2011 Armorize Technologies

Page 59: Fyodor Yarochkin - Dissecting unlawful Internet activities

Amusing portals

(c) 2011 Armorize Technologies

Page 60: Fyodor Yarochkin - Dissecting unlawful Internet activities

PASSPORT COPIES

(c) 2011 Armorize Technologies

Page 61: Fyodor Yarochkin - Dissecting unlawful Internet activities

.. OR A SET

For money of any state of dirtinessPack includes1. Online bank account access2.ATM card (1000/6000USD per month withdrawal limit)3. online access passwords4. Passport copy of “poor john”5. SIM card

(c) 2011 Armorize Technologies

Page 62: Fyodor Yarochkin - Dissecting unlawful Internet activities

MALWARE Q/A AND HOSTING

(c) 2011 Armorize Technologies

Page 63: Fyodor Yarochkin - Dissecting unlawful Internet activities

Abuse-resistant hosting

(c) 2011 Armorize Technologies

Page 64: Fyodor Yarochkin - Dissecting unlawful Internet activities

CLOUD-cracking

(c) 2011 Armorize Technologies

Page 65: Fyodor Yarochkin - Dissecting unlawful Internet activities

AND CAPTCHA

(c) 2011 Armorize Technologies

Page 66: Fyodor Yarochkin - Dissecting unlawful Internet activities

MOBILESo far - easy to spot with

static analysis tools (android, j2me)

(c) 2011 Armorize Technologies

Page 67: Fyodor Yarochkin - Dissecting unlawful Internet activities

Press the button “stop” as soon as Press the button “stop” as soon as possible!possible!

(c) 2011 Armorize Technologies

Page 68: Fyodor Yarochkin - Dissecting unlawful Internet activities

LEARNING POSSIBILITIES :)

(c) 2011 Armorize Technologies

Page 69: Fyodor Yarochkin - Dissecting unlawful Internet activities

Questions

l

(c) 2011 Armorize Technologies