uncovering the secrets of malvertising · uncovering the secrets of malvertising jérôme segura,...

29
Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware Intelligence Analyst

Upload: others

Post on 20-Sep-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

UncoveringTheSecretsofMalvertisingJérômeSegura,@jeromesegura,LeadMalwareIntelligenceAnalyst

ChrisBoyd,@paperghost,LeadMalwareIntelligenceAnalyst

Page 2: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Agenda

•Legacyandrealitybehindadvertising

•Malvertising101andsocialengineering

•Evasiontechniquesthatkeepresearchersatbay

•Malvertisingbeyondmalware(scams,fraud)

Page 3: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

10yearsago...

Page 4: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Earlydaysofadblocking•Adoverlaysanger

pornwebmasters

•They'drathersacrifice

trafficalongsidethe

saleslostfrompop-

overredirects

Page 5: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Onlineadsin2016:Onewebsite,mixedmessages

Page 6: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Malvertising (n)Maliciousadvertising istheuseofonlineadvertisingtodistributemalwareorscamswithlittleornouserinteractionrequired.

Page 7: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Malvertisinginthenews…

Page 8: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Theimpact•Millionsofusers

exposed

•Payloadsrange

fromransomware

tobankingTrojans

Page 9: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Malvertising101

Page 10: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

MalvertisingandExploitKits

Maliciousad Redir./Gate ExploitKit Malware

https://blog.malwarebytes.com/threat-analysis/2016/01/msn-home-page-drops-more-malware-via-malvertising/

Page 11: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

AdTechbasics•Publisher:Websitethatdisplaysads

•Creative:Shortfor‘adcreative’,meaninganadvert

•Impression:Referstoanadbeingviewedoncebyavisitor

•Adcall:Thebrowserrequestthattriggersanimpression

•RTB:ARealTimeBiddingauctionforeachimpression

•CPM:Costper1Kimpressions

Page 12: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Whythreatactorsgetontopopularwebsites

Inoneparticularcampaign,withjust$5,threatactorswereabletoexposeoversixthousandpeopletomalware!!!

https://blog.malwarebytes.com/threat-analysis/2015/02/hanjuan-ek-fires-third-flash-player-0day/

• Hugetrafficvolumes• PayPerImpression

becomes‘PayPerInfection’

Page 13: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Howthreatactorsgetontopopularwebsites•Inconsistentguidelinesweakentheadindustry

•Profitvssecurity(i.e.‘arbitrage’)

•3rd partytagscanbehijackedonthefly

•Neweradformats(videoads)

•Exploiting‘Trustedpartners’

•Socialengineeringtobypassadscanners

Page 14: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Fakeadvertisers•Threatactorscreate

fakeprofiles

•Socialengineeringis

usedtodupead

agencies/networks

•It’salongtermgame

Page 15: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Domainshadowing:Stolenidentities•Abuseslegitimate

businesses

•Adbannersarecreated

andhosted‘silently’

•Difficulttofindthe

‘smokinggun’

Page 16: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Domainshadowing:FunwithPhotoshop

Page 17: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Evasiontechniques

Page 18: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

AdsmovingtoHTTPS• The‘adcall’URLinplainHTTPversusHTTPS

Usefulmetadata

Nothingtosee,muchtohide

Page 19: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Anti-researchers,honeypots(fingerprinting)• Identifynongenuinetargetsvia

informationdisclosurebugs

• Readlocalfilenamesviathebrowser

(XMLDOM)

• CheckforMIMEtype(.pcap,.saz)

• Ifvmware,virtualbox,wireshark,etc

arefound,showthe‘cleanad’

Page 20: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Fingerprinting:XMLDOMvuln.

Page 21: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Fingerprinting:XMLDOMandMimeType inaGIF

Page 22: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Malvertisingbeyondmalware

Page 23: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Hidingblockersfrom...blockerblockers?

“Pleasedisableyouradblocker!”“Yes,but…”

Page 24: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Malvertising&scamsWithaVPN WithoutaVPN

Page 25: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Directtobillpaymentsdoneright•Directtobillpayments

– payforserviceswith

nocreditcard

•Merchants

(webmasters)can

subvertpayment

process

SMS- Clicklinkto

confirmacceptance

ofbilling for

product

www.exampleurl.com

555-555-5555

Page 26: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Directtobillpaymentsdonewrong•Advertonforumauto

redirectstoinstant

payment

•Forrefunds...contact

thescammer!

Page 27: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Digitalbecomesrealitybecomes...digi-reality?•Vehicletrackingservespersonalizedads

•Tracking/pricingviabatterystatus

•Augmentedreality

Page 28: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Let’sTakeYourQuestions

LearnMore:malwarebytes.com/business

LatestNews:blog.malwarebytes.com

RequestaTrial:malwarebytes.com/business/licensing

Page 29: Uncovering The Secrets of Malvertising · Uncovering The Secrets of Malvertising Jérôme Segura, @jeromesegura, Lead Malware Intelligence Analyst Chris Boyd, @paperghost, Lead Malware

Thank You!