BlackHole exploit kit casts a wide net

Analysis
Oct 4, 20123 mins

Solutionary's SERT Quarterly Report Highlights Mass Distribution Malware Threat

Despite high-profile takedowns of several large botnets, there is still lots of malware being pushed on us by mass distribution phishing attacks, according to the latest quarterly research report by Solutionary’s Security Engineering Research Team (SERT). Based on the sheer and overwhelming number of samples that came from the BlackHole exploit kit the team dedicated almost all of the report on this widely used kit.

The BlackHole exploit kit is used as a front end for a wide range of Trojans, mostly around banking. According to the report:

The BlackHole Exploit Kit is the most notable and predominant kit observed based on recent analysis, representing 67% of all exploit kit use. BlackHole is a web application that allows an attacker to take advantage of the most known vulnerabilities in popular applications such as Adobe Reader, Adobe Flash and Java. It has been the most popular exploit kit among cybercriminals since 2011 and shows no sign of slowing down. Its first version, v.1.0.0, was released in 2010 and the most recent version, v.1.2.3, was released on March 25, 2012. 

The kit is usually delivered via a phishing email. According to Solutionary’s report, most of the phishing email was of the mass-distribution variety (92%) versus targeted phishing. This may be due to the fact that casting a wider net means you have to send out more email than required for specific targeted attacks. A more relevant metric maybe the percentage of successful attacks per emails sent. It is akin to shooting with a shotgun versus a sniper rifle.

In any event, according to Don Gray, chief security strategist at Solutionary, over 60% of the phishing attempts and associated malware were not detected by most AV programs. This is an oft-cited problem in the security industry. The fact is even the biggest and best AV programs just don’t seem to keep up with rather run-of-the-mill malware, such as Black Hole.

In speaking with Gray, he said that most of the BlackHole attempts would then try to install a banking Trojan on the client’s computer. The Trojan of choice was of the Cridex variety, but Zeus and some others were also observed. Again, only 54% of these were detected by common AV programs.

Another disturbing characteristic of the phishing emails is that they purport to be from legitimate hosts. Some of the most popular are:

• UPS delivery confirmation

• Scanned documents

• Flight tickets

• Credit card issues

• Better Business Bureau (BBB) complaints

• ACH (Automated Clearing House) wire transfer problems

I have seen so many of these myself and they can be quite realistic looking. It can be really difficult to tell phishing from real emails. Also, Don mentioned that some of these emails are displayed as HTML in the web client. Sometimes that is all that is required to install the malware. You don’t even have to go visit a website. That makes it really hard to stop and is why you should not display email as HTML by default.

Solutionary’s SERT is always researching across their wide customer base and feeding the information back into their ActiveGuard Platform. They will have a 4th quarter and year end report out in the coming months as well. It will be interesting to see what they turn up.