Latest news
Take, for example, digital certificates which have been in the spotlight after Stuxnet used some or after Adobe’s servers were breached to sign malware. The purpose of a digital signature is to guarantee the authenticity of a file from a particular vendor and is provided by one of a few certificate authorities.
We spotted a new malware sample (Brazilian banking/password stealer) which happens to be signed with a real and valid digital certificate issued by DigiCert:


This certificate is issued to a company called “Buster Paper Comercial Ltda”, a Brazilian company that actually does not exist and was registered with bogus data.
The file – disguised as a PDF document (an invoice) – actually opens up as such to really fool the victim:


But what is really going on here? Let’s have a look, here are the new processes created:

and HTTP traffic:

Let’s pause for a moment on where the malware connects to: som.egnyte.com

This is a sub-domain for a cloud storage company focusing on file sharing for the enterprise. In our case it’s file storage for the criminals. The fake PDF document downloads additional payload stored on this server:
hxxps://som.egnyte.com/h-s-internal/{redacted}/f3487f359b38436f
hxxps://som.egnyte.com/h-s-internal/{redacted}/d3669545621045d9
These files are banking Trojans that are very large (over 10 MB unzipped). No pun intended, but size matters as many antivirus scanners have trouble with detecting larger files.
Digging a little deeper, this is not a new case at all. In fact, last November the same kind of digitally signed Trojan was also distributed. Its certificate has, since then, been revoked.
What we have here is a total abuse of hosting services, digital certificates and repeated offenses from the same people. Clearly, if digital certificates can be abused so easily, we have a big problem on our hands.
Digital certificate theft can be used in targeted attacks as a spear phishing attack for example. As we know, one of the weakest link in the security chain is the end-user (and this is especially true in the Enterprise world). An attacker can easily find out or guess what antivirus a company is running and craft a piece of malware that will not be detected by it. Because such attacks are very narrow, the sample will not be disseminated around the world, making its discovery less likely.

Author: Jerome Segura, Malwarebytes.


Spotlight

Is it time to professionalize information security?
Posted on 23 May 2013. | The issue of whether or not information security professionals should be licensed to practice has already been the topic of many a passionate debate.

Review: Logging and Log Management
Posted on 22 May 2013. | Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.

Experts highlight top data breach vulnerabilities
Posted on 22 May 2013. | Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





