Breaking RSA Conference News: Damballa Discovers Advanced Evasion Techniques Being Used by Six Crimeware Families to …
ATLANTA--(BUSINESS WIRE)--
Damballa Inc., the company transforming the fight against cyber threats, today released results of its discovery of advanced stealth techniques used by six crimeware families to carry out global cyber attacks. The crimeware families are a new Zeus variant, Bamital, BankPatch, Bonnana, Expiro.Z and Shiz. The crimeware has been evading detection because cyber criminals are rapidly adopting domain generation algorithms (DGAs). This technique is being used to completely evade detection by blacklists, signature filters, and static reputation systems and to hide command-and-control (C&C) infrastructure. DGAs are also referred to as a form of Domain Fluxing.
An eight-page Damballa Research Report describes, for the first time, how six known malware families have been using DGAs to evade detection and grow sizable criminal networks. The oldest, BankPatch, has been using DGAs to evade detection for approximately two years. Without having to reverse engineer malware or 'decode' the DGA algorithm, Damballa Labs can now automatically detect and model DGA behavior by using patent-pending machine learning technology. The report is titled DGAs in the Hands of Cyber-Criminals - Examining the State of the Art in Malware Evasion Techniques.
The company also released a detailed analysis of a recent variant of the Zeus version 3 malware, and for the first time, provided details on its use of DGAs as a secondary connection technique when the primary connection attempt is blocked or fails (the primary connection technique being peer-to-peer). The case study is titled DGAs and Cyber-Criminals – A Case Study.
“While DGAs are not new, the rate at which they are being adopted and their ability to elude the scrutiny of some of the most advanced malware analysis professionals should be of great concern to incident response professionals,” stated Gunter Ollmann, vice president of research for Damballa. “We have found that the security community as a whole has insufficiently or only partially analyzed the network behaviors of DGA-capable malware. For one, some advanced malware is using DGA as a secondary connection technique when the primary technique, let’s say peer-to-peer, has failed. Those charged with protecting the enterprise that have detected or blocked the obvious primary connection technique have failed to counter the back-up technique, and the malware can then successfully locate the C&C using DGAs.”
DGAs first made major news with the outbreak of Conficker. Since that time, the DGA techniques have significantly advanced and are now being adopted by some of the more stealthy threats and by criminals desperately seeking to avoid attribution.
The concept of DGAs is simple enough, but incredibly stealthy. Malware that has infected an endpoint device is programmed with an algorithm that uses a ‘seed’ value, like the current date, to generate potentially hundreds of seemingly random domain names that all attempt to resolve to an IP address. Nearly all of the domain names will result in a ‘non-existent’ domain message (NXDomain). Only one or a few will actually resolve to an IP address. The criminal operator, knowing the nature of the algorithm and the seed that will be used that day, will register only one (or a few) of the domains and have them resolve to his C&C infrastructure. The next day the cycle repeats. The domains used for the previous day’s connection are discarded, meaning the domain names are ‘thrown away,’ and even if detected, would be meaningless in stopping the threat or discovering the criminal C&C.
“With the leak of the Zeus source code and expanding investment by criminal operators to hide and protect their C&C infrastructure, we should expect to see more DGA-based malware being used to deliver ever-increasingly stealthy attacks,” said Ollmann. “At Damballa Labs we have been studying this trend and have two patent-pending machine learning technologies specifically designed to identify DGA-based threats by clustering NXDomains from big data that we maintain from years of monitoring global DNS traffic. We can identify these threats without prior interception or knowledge of malware samples, and as described in the case study, map this DGA-based behavior back to the C&C infrastructure and ultimately to the malware family. DGA ‘classifiers’ are then used on the Damballa Failsafe sensors to automatically and rapidly identify DGA-based malware infected devices in customer networks – attributing the behavior to a specific malware family without having to see the malware or the infection occur. Damballa is the only company with this capability today. I am very proud of what the research team at Damballa Labs has been able to accomplish.”
About Damballa
Damballa is a pioneer in the fight against cybercrime. Damballa provides the only network security solution that detects the remote control communication that criminals use to breach networks to steal corporate data and intellectual property, and conduct espionage or other fraudulent transactions. Patent-pending solutions from Damballa protect networks with any type of server or endpoint device including PCs, Macs, Unix, smartphones, mobile and embedded systems. Damballa customers include mid-size and large enterprises that represent every major market, telecommunications and Internet service providers, universities, and government agencies. Privately held, Damballa is headquartered in Atlanta. http://www.damballa.com
- Donuts Launches Domain Namespace Expansion with 307 gTLD Applications, More Than $100 Million in Funding - June 5th, 2012 [June 5th, 2012]
- Google Bids on New gTLDs .google, .youtube., .lol & More - June 3rd, 2012 [June 3rd, 2012]
- SAIC to Webcast Presentation at Stephens Spring Investment Conference - May 31st, 2012 [May 31st, 2012]
- 3gnewsroom.com - May 31st, 2012 [May 31st, 2012]
- Olma Investment Group Fails to Put Forward an Alternative Offer - Instead makes Unrealistic Demands which First ... - May 29th, 2012 [May 29th, 2012]
- suntimes.co.za - May 29th, 2012 [May 29th, 2012]
- itv-boxing.com - May 29th, 2012 [May 29th, 2012]
- Today last chance to visit Suez Domain’s roadshow - May 27th, 2012 [May 27th, 2012]
- Movie visual effects company Digital Domain to set up studio and media school in UAE capital - May 23rd, 2012 [May 23rd, 2012]
- Top Domain RaiseCapital.com for Sale - May 23rd, 2012 [May 23rd, 2012]
- Digital Domain to open animation and visual effects studio in Abu Dhabi - May 23rd, 2012 [May 23rd, 2012]
- Digital Domain Announces Abu Dhabi Expansion, Receives $100M Grant for Animation Studio and Educational Institute - May 23rd, 2012 [May 23rd, 2012]
- Fidelity Growth Partners Europe Leads a £10m Investment in Online Marketplace notonthehighstreet.com - May 20th, 2012 [May 20th, 2012]
- Suez Domain offers KL Gateway office towers to Sarawak market - May 20th, 2012 [May 20th, 2012]
- DDMG Beats Revenue and Earnings Estimates, Reporting 1st Quarter Revenues of $31.1 Million and EPS Loss of $0.37 per ... - May 17th, 2012 [May 17th, 2012]
- Fitch Affirms Solar Investment Grade CBO I, Ltd. - May 12th, 2012 [May 12th, 2012]
- Capital Payments, LLC Welcomes Camden Partners as Growth Financing Partner - May 9th, 2012 [May 9th, 2012]
- Straban Township moves closer to eminent domain - May 9th, 2012 [May 9th, 2012]
- Digital Domain Media Group Closes $35 Million Financing - May 9th, 2012 [May 9th, 2012]
- Tucows First Quarter Investment Community Conference Call is Tuesday, May 8, 2012 AT 5:00 P.M. (ET) - May 2nd, 2012 [May 2nd, 2012]
- David Lu Appointed Head of Asia Investment Banking - April 23rd, 2012 [April 23rd, 2012]
- Eric Greenhut Joins Ramius as Head of Quantitative Trading Group - April 19th, 2012 [April 19th, 2012]
- Netflix Snaps Up DVD.com Domain - March 31st, 2012 [March 31st, 2012]
- Fitch Affirms CRA/LA, A Designated Local Authority's Investment Portfolio at 'AAA/V1' - March 29th, 2012 [March 29th, 2012]
- Pingtan project 'just for business' - March 29th, 2012 [March 29th, 2012]
- China opens economic zone to Taiwan - March 29th, 2012 [March 29th, 2012]
- Domain Developers Fund Announces 16.37% annual net performance results for 2011 - March 29th, 2012 [March 29th, 2012]
- BNY Mellon Takes Top Honours Amongst Peers in 2012 R&M Global Custody Survey - March 26th, 2012 [March 26th, 2012]
- Local company playing key role in adding Internet domains - March 24th, 2012 [March 24th, 2012]
- Schwab, E*Trade et al outpacing traditional brokers - March 23rd, 2012 [March 23rd, 2012]
- Manhattan Hotel Market Report 2012 - NYC Hotel Investments - Developments & Acquisitions by Domain Properties - March 23rd, 2012 [March 23rd, 2012]
- Top Level Domain Hdg - TLDH to apply for dot music - March 23rd, 2012 [March 23rd, 2012]
- Research and Markets: Venture Capital Investment Trends in the United States Automotive Industry - March 23rd, 2012 [March 23rd, 2012]
- Equipos and HCL Forge Award-Winning Global Client Reporting Partnership - March 21st, 2012 [March 21st, 2012]
- ICANN prez calls out own board over conflicts of interest - March 20th, 2012 [March 20th, 2012]
- GTCR Announces Investment in Zayo Group to Finance Zayo’s Pending Acquisition of AboveNet - March 20th, 2012 [March 20th, 2012]
- Princeton venture capital firm and Russians collaborate on life sciences - March 20th, 2012 [March 20th, 2012]
- All Quiet on the Virtual Front: Why Domain Investors' Fear of the Feds is Irrational - March 16th, 2012 [March 16th, 2012]
- BOKU Secures $35 Million Strategic Investment From NEA, Telefónica and Other Investors - March 15th, 2012 [March 15th, 2012]
- US Airways grabs merger-related Internet names - March 15th, 2012 [March 15th, 2012]
- Zacks #1 Ranked Energy Mutual Funds - March 14th, 2012 [March 14th, 2012]
- Briefly: Hoping to merge, airline collects domain names - March 14th, 2012 [March 14th, 2012]
- Web Hosting and Domain Name Leader Easyspace Chosen as goMobi's UK Partner for the Google GetMo Programme - March 14th, 2012 [March 14th, 2012]
- Hoping to merge, airline collects domain names - March 14th, 2012 [March 14th, 2012]
- Equinox Expands Product Range with Launch of Single CTA Program Mutual Funds - March 14th, 2012 [March 14th, 2012]
- Small caps round-up: FFastFill, Nasstar, SocialGo... - March 14th, 2012 [March 14th, 2012]
- 7 Outstanding Female Investors - Finance News - March 14th, 2012 [March 14th, 2012]
- Domain Properties Sells the Avalon Hotel NYC - Another Hotel Represented by Domain Properties - March 14th, 2012 [March 14th, 2012]
- Domain Properties Sells The Avalon Hotel NYC - March 12th, 2012 [March 12th, 2012]
- 4 Questions to Ask Before Venturing Into a Self-Directed IRA - March 12th, 2012 [March 12th, 2012]
- This Fascinating Study Of 15,208 Pairs Of Swedish Twins Sheds New Light On Investor Behavior - March 12th, 2012 [March 12th, 2012]
- Fitch Affirms Preferred Share Ratings of 2 Pioneer Municipal Closed End Funds at 'AAA' - March 10th, 2012 [March 10th, 2012]
- Fitch Affirms Preferred Share Ratings of 2 Pioneer Corporate Fixed-Income Closed End Funds at 'AAA' - March 9th, 2012 [March 9th, 2012]
- Officials seek change in EEZ statute - March 9th, 2012 [March 9th, 2012]
- New investment projects worth $46bn identified - March 8th, 2012 [March 8th, 2012]
- Highly Coveted CO.com Domain Name for Sale via DomainAdvisors - March 8th, 2012 [March 8th, 2012]
- Protecting Customerand CompanyData - Security - News & Reviews - Baseline.com - March 7th, 2012 [March 7th, 2012]
- Amdocs Leads in Global Billing Market Share, Analyst Firm Reports - March 7th, 2012 [March 7th, 2012]
- Cloud Sherpas and GlobalOne Merge, Raise $20M to Create Global Cloud Service Provider Powerhouse - March 7th, 2012 [March 7th, 2012]
- Jalak Jobanputra Named Managing Director at RTP Ventures in New York City - March 5th, 2012 [March 5th, 2012]
- The issues surrounding the Sappi site are not so clear cut, Muskegon chamber chief says - March 2nd, 2012 [March 2nd, 2012]
- Fitch Affirms Preferred Share Ratings of 4 PIMCO Closed End Funds at 'AAA' - March 2nd, 2012 [March 2nd, 2012]
- Signal Hill Announces Launch of India Initiative - March 2nd, 2012 [March 2nd, 2012]
- Proskauer Expands Litigation Practice, Private Investment Funds Capabilities with Addition of Partner Timothy Mungovan ... - March 2nd, 2012 [March 2nd, 2012]
- YOGA.com Domain Name Exclusively for Sale with DomainAdvisors - March 2nd, 2012 [March 2nd, 2012]
- Rule Financial Ramps up Global Operations to Support International Growth - February 28th, 2012 [February 28th, 2012]
- Social Entertainment Leader Milyoni Secures $11 Million in Funding - February 25th, 2012 [February 25th, 2012]
- Lake Havasu Todays News Herald - February 25th, 2012 [February 25th, 2012]
- B5M Lands $7.1M. Series A Led by Oak Investment Partners and Giosis Holdings - February 24th, 2012 [February 24th, 2012]
- Chinese Social Shopping Search Engine B5M Secures $7.1 Million Series A Financing Round Led by Oak Investment Partners ... - February 24th, 2012 [February 24th, 2012]
- Prominent White-Collar Criminal Defense Litigator Daniel Rubinstein, and Intellectual Property Authority, Paul McGrady ... - February 23rd, 2012 [February 23rd, 2012]
- Neustar Announces Partnership with the National Small Business Association - February 23rd, 2012 [February 23rd, 2012]
- 5 Simple Hedge Strategies for Volatile Times - February 23rd, 2012 [February 23rd, 2012]
- Halfpenny Technologies Secures $2.25 Million in Capital Investment - February 23rd, 2012 [February 23rd, 2012]
- Updated: Melbourne IT profit down 16 per cent - February 21st, 2012 [February 21st, 2012]
- Melbourne IT FY profit down 16% - February 21st, 2012 [February 21st, 2012]
- Domaining Power Course Lesson #3 - Domain Name Appraisals - Video - February 21st, 2012 [February 21st, 2012]
- Health Care Turning To IT Info Systems - February 17th, 2012 [February 17th, 2012]
- AFL applies for new domain - February 17th, 2012 [February 17th, 2012]
- AFL applies for new domain name - February 17th, 2012 [February 17th, 2012]