Saturday, July 10, 2010

Update. Design contest: Top Ten targeted attack emails of 2009-2010. (Now Top Twenty)

Thanks to F-Secure mention of some of the targeted attack emails from our collection, there was an increased interest to the content and appearance of the messages. We usually pay more attention to  malware and forget about the message part, which is supposed to look impressive and lure recipients into opening malicious attachments. Today we present the Top Ten particularly well crafted messages of 2009-2010. They blend in with the rest of the mail filling our mailboxes and most are designed to look like another newsletter or publication. Some of the messages below were posted here earlier in 2010 or 2009. Some are spoofed while others are from free email accounts. PDF attachments are most common but MS Office documents get sent often too - especially during the days of unpatched vulnerabilities.

Update July 10, 2010 - Here are 10 more messages to add to the list of winners

This recent message from Russia reminded me about this targeted emails design contest we had in March 2010  and I decided to add more candidates. Shall we choose one winner in the end of the year?
I would say there is a subtle evolution in the design and sophistication of the attacks - comparing to the Top Ten winners posted in March 2010(scroll down to see)

Virustotal links show the malicious payload as it would be detected at the time of the receipt

 1. Jun 20 CVE-2010-1297 PDF Adobe 0-Day Meeting agenda from alexis.mo88@gmail.com

Virustotal 5/41  Zero Day

http://3.bp.blogspot.com/_xQabPlo6k5s/TCBHyzjR-tI/AAAAAAAABac/Ds9PJ6S0fIk/s1600/msg.jpg

2. Apr 10 CVE-2010-0188 PDF Research Paper on Nuclear Posture Review 2010 and the upcoming Nuclear Security Summit

Virustotal 5/39


3 May 5 CVE-2010-0188 PDF 2010-05-06 Asian Pacific Security stuff from samuelberger19@yahoo.com

Virustotal 6/41

http://4.bp.blogspot.com/_xQabPlo6k5s/S-Mofp6AlbI/AAAAAAAABMY/ATZYR7wSBRw/s1600/msg2+-+Copy.jpg
4. May 9 CVE-2010-0188 PDF Concept Paper.pdf from global.faruk@gmail.com

Virustotal 6/41 
 The forwarded conversation (it might be real or fake) together with a malicious attachment are quite convincing.


http://2.bp.blogspot.com/_xQabPlo6k5s/S-fvo6bNMqI/AAAAAAAABNI/IIP6zuiLj-s/s1600/msg.jpg

5. Mar 30 CVE-2009-4324 PDF China and Foreign Military Modernization from americansina@gmail.com

Virustotal 8/42

http://1.bp.blogspot.com/_xQabPlo6k5s/S7Iq1jTGQrI/AAAAAAAAA8w/JzzkbgqYH9I/s1600/msgch.JPG




Virustotal 14/41

http://3.bp.blogspot.com/_xQabPlo6k5s/TDRpWovWO0I/AAAAAAAABeM/_hoaEWLr0GA/s1600/msg.jpg


7. Mar 24 CVE-2010-0188 PDF rumours in N Korea2010march from coljoint@aol.com 

Virustotal 4/42

http://3.bp.blogspot.com/_xQabPlo6k5s/S7HjfVuKatI/AAAAAAAAA8Q/bmvrOg9zhcc/s1600/msg.JPG


8. Mar 23 CVE-2009-4324 PDF Talking Points on Chinese Currency from eaisecs@nus.edu.sg

Virustotal 7/42

http://3.bp.blogspot.com/_xQabPlo6k5s/S6rpkF_2ykI/AAAAAAAAA5Y/ZiJg9MFDKLc/s1600/msg.JPG

9. Mar 14 CVE-2010-0188 PDF 2010 Trade Policy Agenda from irc@state.gov

Virustotal 14/42

[tradepolic.jpg]

10.  Mar 18 CVE-2009-4324 PDF Report on 2010 NPC Mar 18, 2010 8:53 AM
Virustotal 10/42 

[msg1.jpg]


ORIGINAL TOP TEN LIST (March 2010)

Virustotal links show the malicious payload as it would be detected these days. Most of them had much lower antivirus detection rate at the time of the receipt  - compare it to the AV detection rate of one of the recent messages (CVE-2010-0188).


Click on the pictures to enlarge
1 US-Taiwan Exchange Program Enhancement
Virustotal scan


2 2009 DoD ATC Procedures
Virustotal scan



3 Wolf Letter to Secretary Clinton Regarding China Human Right
Virustotal scan
 
4 Asking for an interview from NBC Journalist
Virustotal scan 





5 Peer Review - Assessing Chinese Military Transparency
Virustotal scan
6 Terrorism in Asia
Virustotal scan 
7 Top risks of 2010
Virustotal scan


8 RSIS Commentary 54/2009 Ending the LTTE
Virustotal scan 

9 The Chinese Navy's Budding Overseas Presence

10 Road Map for Asian-Pacific Security
Virustotal scan


 

1 comment:

  1. Such a very good and informative post. thanks for sharing with us....

    ReplyDelete