<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Fortinet Security Blog &#187; conficker</title>
	<atom:link href="http://blog.fortinet.com/tag/conficker/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.fortinet.com</link>
	<description>Real Time Network Protection</description>
	<lastBuildDate>Fri, 27 Jan 2012 11:59:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
	<!-- podcast_generator="podPress/8.8" -->
		<copyright>&#xA9;Fortinet Product Marketing </copyright>
		<managingEditor>rpopko@fortinet.com (Fortinet Product Marketing)</managingEditor>
		<webMaster>rpopko@fortinet.com(Fortinet Product Marketing)</webMaster>
		<category>Fortinet Product Information</category>
		<ttl>1440</ttl>
		<itunes:keywords>forti-gate, anti-spam, anti-virus, fortigate</itunes:keywords>
		<itunes:subtitle>The latest news and information about Fortinet products and services for Real Time Network Protection.</itunes:subtitle>
		<itunes:summary>Fortinet is a leading provider of Unified Threat Management (UTM) network security solutions for enterprise and service provider environments. The Fortinet FortiCast delivers news, information, and tutorials about products, services, and industry trends. Fortinet's FortiGate product line and FortiGuard security subscription services provide an array of integrated network security functions including antivirus, firewall, virtual private networking, intrusion prevention (IPS), web filtering, antispam and traffic optimization. </itunes:summary>
		<itunes:author>Fortinet Product Marketing</itunes:author>
		<itunes:category text="Technology"/>
<itunes:category text="Technology">
  <itunes:category text="Tech News"/>
</itunes:category>
		<itunes:owner>
			<itunes:name>Fortinet Product Marketing</itunes:name>
			<itunes:email>rpopko@fortinet.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-300x300.jpg" />
		<image>
			<url>http://blog.fortinet.com/wp-content/uploads/2009/01/forticast-144x144.jpg</url>
			<title>Fortinet Security Blog</title>
			<link>http://blog.fortinet.com</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>March Threat Landscape Report: Virut, Conficker and social engineering</title>
		<link>http://blog.fortinet.com/march-threatscape-report-virut-conficker-and-social-engineering/</link>
		<comments>http://blog.fortinet.com/march-threatscape-report-virut-conficker-and-social-engineering/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 21:19:28 +0000</pubDate>
		<dc:creator>DManky</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Threat Landscape]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[virut]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=243</guid>
		<description><![CDATA[Our March 2009 Threat Landscape Report is now available, recapping a month of threat activity from exploits and malware, to spam. Here are some key movements from the report along with comments: After a year long battle, W32/Virut.A finally lands in top spot &#8211; surpassing Netsky. This parasitic file infector proves to be quite virulent, [...]]]></description>
			<content:encoded><![CDATA[<p>Our March 2009 Threat Landscape Report is <a href="http://www.fortiguardcenter.com/report/roundup_mar_2009.html">now available</a>, recapping a month of threat activity from exploits and malware, to spam. Here are some key movements from the report along with comments:</p>
<p><strong>After a year long battle</strong>, <a href="http://www.fortiguardcenter.com/VirusEncyclopedia/search/encyclopediaSearch.do?method=viewVirusDetailsInfo&amp;fid=252377">W32/Virut.A</a> finally lands in top spot &#8211; surpassing Netsky. This parasitic file infector proves to be quite virulent, and has generated enough activity to land in our malware top 10 for twelve solid months. On top of infecting multiple local files on a PC, the virus can spread through file shares and/or removable media such as USB thumb drives. Additionally, it has a rather unique capability to propagate through other worms in a hybrid form &#8211; <a href="http://blog.fortinet.com/virut-infecting-worms-hitching-a-ride/">read here for more info</a>.</p>
<p><strong>Conficker, conficker, conficker. </strong>The notorious worm which has made headlines across the world continues to evolve with a new variant, Conficker.C. While it remained in fourth position in our Top 10 Exploitation list, exploit activity of MS08-067 (detected by FortiGuard IPS as &#8216;<a href="http://www.fortiguardcenter.com/ids/VID18947">MS.DCERPC.NETAPI32.Buffer.Overflow</a>&#8216;) actually decreased since we recorded a peak of activity on February 12th, 2009. Even with slightly deflated exploit levels, the worm has certainly established a strong global foothold and with the development of Conficker.C, the authors intend for it to stick around for a while. Conficker.C is quite simply more robust and effective &#8211; it boasts a new domain generation algorithm, and uses an enhanced cryptographic hash function (MD6) to validate the authenticity of its own malicious code. Most notably, after April 1st, 2009 it will attempt to communicate with a larger set of rendezvous points than previous variants used.</p>
<p>It is yet to be seen what happens after April 1st, though it should be pointed out that this code simply becomes active on that date and will remain active afterwards. Given the amount of attention <a href="http://blog.fortinet.com/the-art-of-unpacking-conficker-worm/">Conficker has received</a>, it is likely the authors will attempt any sort of strike at a later date when it is less anticipated &#8211; and more Conficker.C variants are spread. That said, always be aware and keep your protection up to date. Conficker is best blocked through layered defense, such as intrusion prevention, web content filtering, and antivirus. We continue to monitor this threat in the lab.</p>
<p><strong>There were 30 new vulnerabilities </strong>rated as &#8216;Critical&#8217;, up from last period&#8217;s count of 25. So far, active exploitation of these has been low. However, as we have seen before, critical vulnerabilities are highly sought in the digital underground and typically have long lifespans; it may take some time before successful exploits rise. This should be seen as a good opportunity to keep up to date with the latest patches before the vulnerabilities become larger issues.</p>
<p><strong>Social engineering attacks continue </strong>to become more sophisticated. A form of Location Based Services (LBS), spam and attacks custom tailored towards a recipient&#8217;s geographical location have become more mainstream. Two examples from this edition include a spam campaign from Waledac, providing links to fake news sites serving up malicious variants of the Waledac family. The fake news sites (posing to be Reuters) had dynamic headlines which cited explosions in regions that were close to the geographic location (geoIP) of the victim who would follow these links. The other example comes from the Canadian Pharmacy gang: spam driving traffic to the vast network of fraudulent domains owned by this group is shown this edition, localized in Japanese. Canadian Pharmacy employs LBS, offering different content based on the geographic location of the would-be customer.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/march-threatscape-report-virut-conficker-and-social-engineering/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The art of unpacking Conficker worm</title>
		<link>http://blog.fortinet.com/the-art-of-unpacking-conficker-worm/</link>
		<comments>http://blog.fortinet.com/the-art-of-unpacking-conficker-worm/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 23:12:06 +0000</pubDate>
		<dc:creator>RPlantado</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=216</guid>
		<description><![CDATA[Over the past two years, rarely did a worm get as much attention that Conficker (aka Downadup) is getting now. Its last variant, the infamous W32/Conficker.C, which surfaced in early March and is set to time-bomb on April 1, is literally all over the media. Of course, its features are well known and documented and [...]]]></description>
			<content:encoded><![CDATA[<p>Over the past two years, rarely did a worm get as much attention that Conficker (aka Downadup) is getting now. Its last variant, the infamous <span style="text-decoration: underline;"><a href="http://www.fortiguardcenter.com/virusency/W32/Conficker.C%21worm" target="_blank">W32/Conficker.C</a></span>, which surfaced in early March and is set to time-bomb on April 1, is literally all over the media. Of course, its features are well known and documented and some papers (such as  <span style="text-decoration: underline;"><a href="http://mtc.sri.com/Conficker/">SRI</a></span>&#8216;s excellent analysis and a blog post from <span style="text-decoration: underline;"><a href="http://vrt-sourcefire.blogspot.com/2009/02/making-conficker-cough-up-goods.html">Sourcefire</a></span>) even give interesting insights on the reverse engineering process. Indeed, while understanding the behavior of the malware is important to most people, learning <em>how</em> to understand it is even more important to some. Does the fable of the fisherman who gives the hungry man a fishing rod rather than a fish sound familiar?</p>
<p>That is the purpose of this post. While not delving into the depths of reverse engineering Conficker, it aims at providing a few tips to whomever may want to participate in the community efforts, for a better understanding of the infamous worm variants. And the best part is that part of these tips apply to other malware pieces.</p>
<p><strong>1. Equipment</strong></p>
<p>The first thing to note is that Conficker is encrypted/compressed by a custom &#8220;run-time packer&#8221;, which is a very common strategy to prevent static analysis. Indeed, should you load a copy of the worm in a disassembler, all you&#8217;ll see is the assembly code of the said run-time packer, and a bunch of compressed data.</p>
<p>The first thing to do, therefore, is to unpack it, to reveal the actual assembly code of the worm.</p>
<p>The following gives some insights that may be useful to achieve this, using OllyDbg and IDAPro.</p>
<p><em>Note: It is assumed that doing this in an isolated and safe lab machine is required to avoid possible infection of internal networks. </em></p>
<p><strong>2. Loading the malware into the debugger</strong>.</p>
<p>The Conficker worm is in fact a DLL file, sometimes obfuscated by a first layer of UPX run-time encryption/compression. Thus it&#8217;s a good idea to give it a first pass of unpacking with the appropriate <span style="text-decoration: underline;"><a href="http://upx.sourceforge.net/">UPX</a></span> version, before loading it into the debugger.</p>
<p>We all have our own methods for debugging DLLs, and my personal choice is to modify the DLL bit flag to turn it into an EXE to the eyes of the debugger. Among other PE editors, CFF Explorer from <span style="text-decoration: underline;"><a href="http://www.ntcore.com/">ntcore</a></span> is a tool that allows to do that.</p>
<p><img class="alignnone size-full wp-image-222" title="conficker1" src="http://blog.fortinet.com/wp-content/uploads/2009/03/conficker1.png" alt="conficker1" width="489" height="277" /></p>
<p>Now open the file in OllyDbg and &#8216;Step into&#8217; the <em>DllMain()</em> function.</p>
<p><strong>3. Choosing the unpacking method</strong></p>
<p>Run time packers are commonly hard to trace due to many anti-debugging tricks being employed by the malware authors. Yet all of them will certainly undergo some stages before jumping to the actual malicious code.  We can roughly divide the unpacking process flow into the following simplified flowchart:</p>
<p><img class="alignnone size-full wp-image-223" title="conficker2" src="http://blog.fortinet.com/wp-content/uploads/2009/03/conficker2.png" alt="conficker2" width="458" height="29" /></p>
<p>Conficker follows roughly this sequence, decrypting byte by byte and saving the data in non-contiguous location, before reconstructing it again to copy somewhere in memory. That said, there are really two methods to unpack the actual malicious code:</p>
<ul>
<li>Either you reverse-engineer the unpacking algorithm, re-implement it in a scripting language, and run the script on the packed file (long and tedious)</li>
<li>Or you let the run-time packer do the unpacking job for you, and catch a break right before the execution flow is passed to the actual malicious code</li>
</ul>
<p>The latter method is the one we&#8217;ll explore here; while it is quicker, it has a drawback: it implies defeating the anti-debugging tricks scattered over the unpacking code, which are precisely meant to prevent the code to run inside a debugger.</p>
<p><span id="more-216"></span><strong></strong></p>
<p><strong>4. The Good, the bad and the branch</strong></p>
<p>Surprisingly, defeating the anti-debugging tricks in Conficker&#8217;s run-time packer code is not that difficult, once you&#8217;ve noticed something: Throughout the code, &#8220;decision-making&#8221; code blocks are frequently present at the end of its <span style="text-decoration: underline;"><a href="http://en.wikipedia.org/wiki/Basic_block">basic blocks</a></span>. A &#8220;decision-making&#8221; code bit looks like this:</p>
<p style="padding-left: 30px;">call    sub_100014A0    ; Unknown function<br />
test    eax, eax<br />
jz      loc_1000128E    ; branch 1<br />
jmp     @loc_10001698   ; branch 2</p>
<p>This is very easy to formulate in English: If the &#8220;unknown function&#8221; returns 0, then go to branch 1, otherwise go to branch 2. The question therefore is: what does the &#8220;unknown function&#8221; do? Examples of such functions called in &#8220;decision-making&#8221; code bits can be seen below:</p>
<p><img class="alignnone size-full wp-image-224" title="conficker3" src="http://blog.fortinet.com/wp-content/uploads/2009/03/conficker3.bmp" alt="conficker3" width="479" height="285" /></p>
<p>A specialist eye would quickly spot the RDTSC instructions and the nuisance API calls, very typical of debugger detection strategies implemented by malware authors. Consequently, the &#8220;unknown functions&#8221; mentioned above really are debugger detectors, returning 0 if the code runs in a debugger. We can thus label the &#8220;decision-making&#8221; code blocks as such:</p>
<p style="padding-left: 30px;">call    sub_100014A0    ; debugger detector function<br />
test    eax, eax<br />
jz      loc_1000128E    ; bad branch<br />
jmp     @loc_10001698   ; good branch</p>
<p>Where &#8220;good branch&#8221; leads to the following of the unpacking process (until the next decision-making code block), and &#8220;bad branch&#8221; leads to the exit door (after more or less deceptive circumvolutions).</p>
<p>Therefore, all we need to do to get the unpacking code to run properly is to set breakpoints over each decision-making code block, and force the good branch (either by manually setting the EIP right to it, or by mingling with the registers), hopping over the bad branches in rhythm.</p>
<p>Tracing this malware thus reminds me about <span style="text-decoration: underline;"><a href="http://en.wikipedia.org/wiki/Tinikling">Tinikling</a></span> (an indigenous Filipino dance), where dancers need a coordinated jumping to avoid being hit by the bamboo poles by two other people tapping and sliding the bamboos.</p>
<p><strong>5. Dump!</strong></p>
<p>Now we know how to fence over the anti-debugging traps, the last remaining question is: when do I know I am done with the unpacking process? Again, there are various methods for that; the one we will use here consists in identifying when the code flow reaches the &#8220;Resolve APIs&#8221; phase in the unpacking sequence.</p>
<p>As a matter of fact, to access the services provided by the Operating System, modern compiled code typically resorts to <em>function pointer tables </em>(aka IAT in the Windows executable format): the addresses of imported API functions are stored in a table with a static location, and API calls in the code are done via an indirection through this table. It makes the <em>relocation </em>process easier: when a dll exporting API functions is dynamically loaded in the process memory space, the Windows loader only needs to update the function pointer table with the imported functions addresses, rather than fixing all the calls to the said API functions throughout the code.</p>
<p>As a matter of fact, once unpacking is complete and the actual malicious code reconstructed, a run-time packer will play the role of the Windows loader, and engage in a relocation process on the Malware&#8217;s function pointer table. In other (simple) words: it loads the needed dynamic libraries, and writes the addresses of the API functions used by the Malware in its function table. To obtain such addresses, the run-time packer will typically call the Windows API function <em>GetProcAddress().</em></p>
<p>You have probably already inferred that a breakpoint astutely set on this function will be reached in the &#8220;Resolve APIs&#8221; phase&#8230; At this point, the malware code is fully reconstructed and stands, bare, in memory. Save it, like shown below:</p>
<p><img class="alignnone size-full wp-image-225" title="conficker4" src="http://blog.fortinet.com/wp-content/uploads/2009/03/conficker4.png" alt="conficker4" width="478" height="570" /></p>
<p>Although not necessary for further analysis in IDA, at this point, it is a good idea to turn this data file into a working Win32 executable file, by reconstructing the proper PE headers, for a &#8220;clean&#8221; result. Various tools may help in that (eg: <a id="kfyz" title="ShellCode2Exe" href="http://labs.idefense.com/software/malcode.php#more_malcode+analysis+pack">ShellCode2Exe</a> )</p>
<p>Once this is done, you&#8217;re set to load your brand new, unpacked worm copy into IDA and engage in a new battle: understanding the malware actual features. This is left as an&#8230; exercise for the reader.</p>
<p><em><a href="http://blog.fortinet.com/facebook-url/">Guillaume Lovet</a> contributed to this report</em></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/the-art-of-unpacking-conficker-worm/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>February Threat Landscape &#8211; Exploits, Conficker, Waledac and Sexy View</title>
		<link>http://blog.fortinet.com/february-threatscape-exploits-conficker-waledac-and-sexy-view/</link>
		<comments>http://blog.fortinet.com/february-threatscape-exploits-conficker-waledac-and-sexy-view/#comments</comments>
		<pubDate>Fri, 27 Feb 2009 18:18:24 +0000</pubDate>
		<dc:creator>DManky</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[adobe reader]]></category>
		<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[mobile threat]]></category>
		<category><![CDATA[ms excel]]></category>
		<category><![CDATA[pdf]]></category>
		<category><![CDATA[sexy view]]></category>
		<category><![CDATA[symbianos]]></category>
		<category><![CDATA[waledac]]></category>

		<guid isPermaLink="false">http://blog.fortinet.com/?p=117</guid>
		<description><![CDATA[With February&#8217;s Threat Landscape Report out, it&#8217;s time to highlight some of the most interesting movement happening from late January 2009 to now: New vulnerabilities (NVC) were up nearly three fold, with 117 posted in comparison to 43 from January&#8217;s edition; 25.6% of these new vulnerabilities were detected to be actively exploited. Two new high-profile [...]]]></description>
			<content:encoded><![CDATA[<p>With <a href="http://www.fortiguardcenter.com/report/roundup_feb_2009.html">February&#8217;s Threat Landscape Report</a> out, it&#8217;s time to highlight some of the most interesting movement happening from late January 2009 to now:</p>
<p><strong>New vulnerabilities (NVC) were up</strong> nearly three fold, with 117 posted in comparison to 43 from January&#8217;s edition; 25.6% of these new vulnerabilities were detected to be actively exploited. Two new high-profile zero-day exploits (CVE-2009-0238 and CVE-2009-0658) affecting MS Excel (XLS) and Adobe Reader (PDF) have since been disclosed. Given these facts, and Conficker&#8217;s success, there is no better time than now to underscore patch management and effective security to battle these threats.</p>
<p><strong>Conficker is still running strong</strong>. Our systems showed exploitation of the well known MS08-067 vulnerability displayed the highest recorded activity to date on February 14th, 2009. As of writing, volume levels are still quite high; a new variant has been discovered in the wild that allows malicious payload transfers through a backdoor port opened on an infected machine &#8211; without relying on the domain generation algorithm. Since the algorithm that generates the list of domains Conficker contacts to download code has been reversed/put in the spotlight, this latest functionality can be seen as a counter move by Conficker&#8217;s authors.</p>
<p><strong>Waledac, a relatively new botnet in town</strong>, went on a long run using a Valentine&#8217;s Day campaign to dupe users into downloading a malicious executable which was, to no surprise, a copy of the Waledac trojan. The campaign used a variety of domain/sub domain names, safe-haven registrars, and fast flux. As a result, the domains are still resolving to malicious servers hosting the sites and executables. Sadly, this proves how durable and effective such campaigns can still be using not-so-new methodologies such as fast flux. As of writing, the campaign is still alive but is using a different theme dubbed as the &#8216;Couponizer&#8217;. This social engineering hook offers online &#8220;coupons&#8221; to the victim. One thing we noticed with Waledac is that, aside from coming in the usual shifting variants (server side polymorphic), the served malicious executable&#8217;s filename shifted frequently as well. Names such as &#8216;reader.exe&#8217;, &#8216;start.exe&#8217;, and &#8216;lovekit.exe&#8217; were used.</p>
<p><strong>Movement on the mobile front</strong>: After new variants of Flocker surfaced in January, targeting accounts with Indonesian operators, we reported on Yxes.A in February &#8212; the latest and greatest SymbianOS threat &#8212; aka &#8220;Sexy View&#8221;. While mobile threats are certainly low profile in terms of prevalence (compared to non-mobile threats), this is an area to keep a close eye on. The biggest threat posed by SymbOS/Yxes.A is its ground-breaking propagation function; with the capability to spread through SMS by providing malicious URLs, a bridge is created from mobile telecommunications to the the Internet as we know it. In turn, this opens up a range of possibilities, effectively allowing the authors more control over their creation. With more control and functionality added, Yxes.A proved that we may not be far away from a mobile botnet.</p>
<p><strong>Spam levels remained consistent</strong> after crawling back from a sharp decrease late 2008 thanks, largely in part, to the McColo take-down in November 2008.  Phishing and scam emails are popular as ever in play with the economic crisis, as our spam traps harvested loan and job scams showing up in localized languages to various regions.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.fortinet.com/february-threatscape-exploits-conficker-waledac-and-sexy-view/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

