affiliate webaffiliate web-based malwarebased malware · affiliate webaffiliate web-based...

13
Affiliate Web based Malware Affiliate Web-based Malware Paul O Baccas ([email protected]) 1 t O b 2008 1 st October, 2008

Upload: others

Post on 01-May-2020

6 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Affiliate WebAffiliate Web-based Malwarebased Malware · Affiliate WebAffiliate Web-based Malwarebased Malware Paul O Baccas (paul.baccas@sophos.com) 1st O b 2008October, 2008. This

Affiliate Web based MalwareAffiliate Web-based Malware

Paul O Baccas ([email protected])

1 t O b 20081st October, 2008

Page 2: Affiliate WebAffiliate Web-based Malwarebased Malware · Affiliate WebAffiliate Web-based Malwarebased Malware Paul O Baccas (paul.baccas@sophos.com) 1st O b 2008October, 2008. This

This talk will coverA definition of the title

A look at examplesp

A look at defences

A look at tricks

Page 3: Affiliate WebAffiliate Web-based Malwarebased Malware · Affiliate WebAffiliate Web-based Malwarebased Malware Paul O Baccas (paul.baccas@sophos.com) 1st O b 2008October, 2008. This

What do we mean by ‘Affiliate Web-based Malware’?

Affiliate websites

Those connected via links for purpose of generating revenue

Web-based Malware

Malware that by design or exploit redirects users to sites that y g p

Install malware on the local machine

Or generate fictitious clicks on ad-sitesOr generate fictitious clicks on ad sites

Page 4: Affiliate WebAffiliate Web-based Malwarebased Malware · Affiliate WebAffiliate Web-based Malwarebased Malware Paul O Baccas (paul.baccas@sophos.com) 1st O b 2008October, 2008. This

Installing malware on local systemsBy making use of drive-by technology

Browser exploits

Social engineering

Page 5: Affiliate WebAffiliate Web-based Malwarebased Malware · Affiliate WebAffiliate Web-based Malwarebased Malware Paul O Baccas (paul.baccas@sophos.com) 1st O b 2008October, 2008. This

Examples – santana First line copy

Second line copy

Third line copy

Fourth line copy

Page 6: Affiliate WebAffiliate Web-based Malwarebased Malware · Affiliate WebAffiliate Web-based Malwarebased Malware Paul O Baccas (paul.baccas@sophos.com) 1st O b 2008October, 2008. This

Example -- clickcashFirst line copy

Second line copy

Third line copy

Fourth line copy

Page 7: Affiliate WebAffiliate Web-based Malwarebased Malware · Affiliate WebAffiliate Web-based Malwarebased Malware Paul O Baccas (paul.baccas@sophos.com) 1st O b 2008October, 2008. This

Example -- meteorxFirst line copy

Second line copy

Third line copy

Fourth line copy

Page 8: Affiliate WebAffiliate Web-based Malwarebased Malware · Affiliate WebAffiliate Web-based Malwarebased Malware Paul O Baccas (paul.baccas@sophos.com) 1st O b 2008October, 2008. This

Example -- ActionScriptFirst line copy

Second line copy

Third line copy

Fourth line copy

Page 9: Affiliate WebAffiliate Web-based Malwarebased Malware · Affiliate WebAffiliate Web-based Malwarebased Malware Paul O Baccas (paul.baccas@sophos.com) 1st O b 2008October, 2008. This

Example -- PoisoningExample -- Poisoning

Subverting adverts gives an instant network

Page 10: Affiliate WebAffiliate Web-based Malwarebased Malware · Affiliate WebAffiliate Web-based Malwarebased Malware Paul O Baccas (paul.baccas@sophos.com) 1st O b 2008October, 2008. This

Example -- ClickbankAffiliated to Gpack

Page 11: Affiliate WebAffiliate Web-based Malwarebased Malware · Affiliate WebAffiliate Web-based Malwarebased Malware Paul O Baccas (paul.baccas@sophos.com) 1st O b 2008October, 2008. This

Example -- bloghttp://www.sophos.com/security/blog/2008/09/1835.html

Page 12: Affiliate WebAffiliate Web-based Malwarebased Malware · Affiliate WebAffiliate Web-based Malwarebased Malware Paul O Baccas (paul.baccas@sophos.com) 1st O b 2008October, 2008. This

SummaryMalware author are using these techniques

To increase coverage

To make it harder to track

And to generate revenue

Anti-malware vendors are providing solutions

Page 13: Affiliate WebAffiliate Web-based Malwarebased Malware · Affiliate WebAffiliate Web-based Malwarebased Malware Paul O Baccas (paul.baccas@sophos.com) 1st O b 2008October, 2008. This

QuestionsThank you