Search This Blog

Showing posts with label Arbor Networks. Show all posts
Showing posts with label Arbor Networks. Show all posts

Wednesday, September 20, 2017

The Formidable FormBook Form Grabber

More and more we’ve been seeing references to a malware family known as FormBook. Per its advertisements it is an infostealer that steals form data from various web browsers and other applications. It is also a keylogger and can take screenshots. The malware code is complicated, busy, and fairly obfuscated–there are no Windows API calls or obvious strings. This post will start to explore some of these obfuscations to get a better understanding of how FormBook works.

https://www.arbornetworks.com/blog/asert/formidable-formbook-form-grabber/

Saturday, May 13, 2017

WannaCry

Information regarding the WannaCry ransomware is spreading as quickly as the malware itself and is expected to do so throughout the weekend. This blog provides some information from our malware processing system that may, or may not be, available elsewhere.



WannaCry

Monday, May 1, 2017

Greenbug’s DNS-isms – Arbor Networks Threat Intelligence

Over the past few months there has been a lot of research and press coverage on the Shamoon campaigns. These have been the attacks on Saudi Arabian companies where a destructive malware known as Disttrack was deployed. The malware, using stolen credentials, spreads throughout the targeted networks and then at a set date and time wipes the disks attached to the victim computers.



Greenbug’s DNS-isms – Arbor Networks Threat Intelligence

Wednesday, April 26, 2017

Observed Spike in DDoS Attacks Targeting Hong Kong – Arbor Networks Threat Intelligence

Each week ASERT produces a weekly threat intelligence bulletin for Arbor customers. In addition to providing insights into the week’s security news and reviewing ASERT’s threat research activities, we also summarize the weeks DDoS attack data as reported by over 330 global Internet Service Providers that share anonymized traffic statistics and DDoS event data.



Observed Spike in <span class="ddos">DDoS</span> Attacks Targeting Hong Kong – Arbor Networks Threat Intelligence

Tuesday, January 31, 2017

Flokibot Invades PoS: Trouble in Brazil

Threat actors salivate at the thought of an increased volume of credit and debit card transactions flowing through endpoints they have compromised with card-stealing malware. While there are many distinct malware families that scrape unencrypted process memory to obtain cards, some of these malware capabilities overlap with generic information stealing trojans such as Flokibot that obtain and exfiltrate HTTPS GET and POST data and other materials from compromised machines.



Flokibot Invades PoS: Trouble in Brazil

Thursday, October 27, 2016

TrickBot Banker Insights

A new banking trojan, TrickBot, has seemingly risen from the ashes left behind by the November 2015 takedown of Dyreza/Dyre infrastructure and the arrests of threat actors identified by Russian authorities. Dyreza was used to target customers of over 1000 U.S. and U.K. banks and other companies during the peak of operations. Researchers at Threat Geek and MalwareBytes have already extensively covered general TrickBot functionality.



TrickBot Banker Insights

Sunday, October 23, 2016

On DNS and DDoS

The global DNS infrastructure provides the critical function of mapping seeming random sets of numbers in IP addresses (like 1.1.1.1) to a name that an Internet consumer may recognize (like www.myfavoritestore.com).   To scale to a global level, the DNS system was designed as a multi-level reference network that would allow any user on the Internet to query a set of servers that will iteratively find where a specific domain is owned and get the name to IP address mapping from that location.  To accomplish this, it is made up of root servers controlling top level domains such as .com, .gov, and .org, Global Top Level Domains (TLDs) controlling regional domains such as .br, .fr and .uk, authoritative servers controlling specific domains such as myfavoritestore.com and a very large group of recursive resolvers that end user systems connect to.  A query from a user for a domain name would be sent to a recursive resolver and that resolver would work with the root, GTLD and varying levels of authoritative servers to track down the DNS authoritative server responsible for the domain from which it would receive a DNS reply.  This is a very high level and simplified representation of the most common way that DNS is used.



On DNS and DDoS

Tuesday, October 18, 2016

The Great DGA of Sphinx

This post takes a quick look at Sphinx’s domain generation algorithm (DGA). Sphinx,another Zeus-based banking trojan variant, has been around circa August 2015. The DGA domains are used as a backup mechanism for when the primary hardcoded command and control (C2) servers go down. It is currently unknown to us as to what version added the DGA functionality.
This sample was used for analysis and it is version 1.7.1.0.


The Great DGA of Sphinx

Tuesday, October 4, 2016

Panda Banker’s Future DGA

Since we last visited the Panda Bankers at the malware zoo, two new versions have emerged: 2.2.6 and 2.2.7. While sifting through the encrypted strings of the latest version, two interesting ones stood out:



Panda Banker’s Future DGA