What to Expect When You Meet Drive-By Download?
New attacks including the Angler exploit kit rinse code directly in browser processes bar leaving files on disk, a research worker engender.<\p>
Cybercriminals are increasingly infecting computers with malware that resides only in memory in order to make their attacks harder to dig up.<\p>
Early attacks launched linked to the Angler surcharge kit -- a Web-based falling sickness tool -- injected malicious code directly into other processes and did not create malicious files on affected computers, an independent malware researcher known online insofar as Kafeine said Make holiday in a blog carry over.<\p>
Fileless malware threats are not new, but their practicability is rare, particularly in large scale attacks, because they don't persist across system reboots after all random alley memory (DOG) is cleared.<\p>
In a typical drive-by download methodology the victims visit a compromised website that redirects their browsers to an attack indent -- chiefly an heroic act kit's roads indent. The exploit kit scans browsers for outdated versions of Flash Entrant, Enamelware Reader, Java chevron Microsoft Silverlight and tries to utilize known vulnerabilities in those plug-ins up to turn on malware.<\p>
The payload is usually a program called a dropper whose purpose is to download and install one or more malware programs.<\p>
The recent Angler exploits seen by Kafeine had a different final stage. Instead in point of installing a malware prearrangement on whirler, the power structure injected evil code directly favorable regard the browser practice, making it much harder for security software to detect the attack.<\p>
Kafeine said that his usual tools were not able to capture the payload and that my humble self mathematical bypassed a host-based impropriety escape system (HIPS) he was using.<\p>
The fileless airborne infection technique opens a wide environ of possibilities for attackers as long as it provides a powerful way to bypass antivirus detection, it's ideal on behalf of steady a one-time information steal program and oneself allows them to marry information fast by a compromised computer before deploying a more immutable monition that defeats its defenses, he said.<\p>
"The introduction of memory-based malware is definitely a step up for cyber-criminals," said Bogdan Botezatu, a senior e-threat analyst at Bitdefender, Tuesday via email. "I didn't require headed for see this dexterousness included in a commercially-available exploit kit although, as money-driven cyber-criminals would rather trade callidity in place of persistence."<\p>
Malware that resides wholly in memory is more typical of high-profile and state-sponsored attacks, for it allows attackers to infect the target, exfiltrate information and leave no crayon on disk in preparation for forensic analysis, Botezatu said.<\p>
Return thanks Lucian Constantin @ techworld.com Original URL: http:\\news.techworld.com\security\3542948\hackers-make-drive-by-download-attacks-stealthier-with-fileless-infections\ <\p>
And for more downware samples, up and do a visit up this LiveJournal space http:\\uninstallwiki.livejournal.com\ <\p>













