Fake Antivirus- Journey from Trojan to a Persistent Threat
DeepSec 2011
Jagadeesh Chandraiah
to a Persistent Threat Jagadeesh Chandraiah DeepSec 2011 Agenda - - PowerPoint PPT Presentation
Fake Antivirus- Journey from Trojan to a Persistent Threat Jagadeesh Chandraiah DeepSec 2011 Agenda FakeAV Trends Infection Vectors Packer Evolution How do they work ? DeepSec 2011 Introduction Fake AntiVirus (FakeAV) is a
DeepSec 2011
Jagadeesh Chandraiah
DeepSec 2011
DeepSec 2011
Fake AntiVirus (FakeAV) is a malware which displays fake warnings to the users to trick them to buy illegitimate software.
DeepSec 2011
DeepSec 2011 Analyse the major events over the last three and half years.
DeepSec 2011
DeepSec 2011
FakeAV.
method.
2010 continued to see the spike in FakeAV detections.
DeepSec 2011
2011.
Significant events in 2011.
DeepSec 2011
Aug 2011.
Significant events in 2011.
DeepSec 2011
DeepSec 2011 Sophos Top Five FakeAV Detection rate between Mar-Oct 2011.
FakeAV is down, but still active
DeepSec 2011 FakeAV infection between 1st Quarter of 2010 and 2nd Quarter of 2011, according to Microsoft Security Intelligence Report.
DeepSec 2011 We will analyse popular Infection methods and how they work.
DeepSec 2011 Poisoning search engine optimization.
Pictorial Representation of Black Hat SEO attack DeepSec 2011
DeepSec 2011
website.
website.
DeepSec 2011 Serving FakeAV through Advertising networks.
JavaScript used in New York Times newspaper website. DeepSec 2011
DeepSec 2011 Fake tech support centre’s are used to scam users.
DeepSec 2011 FakeAV served through email attachments and drive by download links.
DeepSec 2011
DeepSec 2011
Users are social engineered to download FakeAV as Codecs.
DeepSec 2011 Use Blackhole Exploit kit as an example to see how exploit kit works.
Black Hole Exploit Kit panel showing Infections by country and vulnerabilities.
Blacklisting mechanism used by Black Hole. DeepSec 2011
Infection mechanism using Exploit kit. DeepSec 2011
Obfuscated Black Hole Exploit Script DeepSec 2011
Decrypted Exploit script checking version and creating Iframe element. DeepSec 2011
DeepSec 2011
FakeAV without packed layer DeepSec 2011
DeepSec 2011
system.
processor.
DeepSec 2011
DeepSec 2011
DeepSec 2011 Process Environment Block
DeepSec 2011 Thread Information Block
and decryption strings.
DeepSec 2011
Understand Packing using a Polymorphic Cryptor. DeepSec 2011
Click icon to add table
Cryptors available in underground forums. DeepSec 2011
Crum Polymorphic Cryptor DeepSec 2011
Crum Polymorphic Cryptor with different icons. DeepSec 2011
DeepSec 2011 Testing Crum Polymorphic Cryptor
DeepSec 2011 Testing Crum Polymorphic Cryptor
DeepSec 2011 Anti Emulation stuff inserted by Crum Polymorphic Cryptor
DeepSec 2011
DeepSec 2011
DeepSec 2011
DeepSec 2011
FakeAV.
binaries.
Landing Pages and FakeAV purchases.
earned more than 130 million dollars.
DeepSec 2011
DeepSec 2011
DeepSec 2011
DeepSec 2011