#RSAC: Domain generation algorithm tricks used by 6 crimeware families to carry out attacks
Six crimeware families are using some new algorithm tricks to escape detection as they carry out global attacks, according to findings from security company Damballa Inc.
The crimeware families are a new Zeus variant, Bamital, BankPatch, Bonnana, Expiro.Z and Shiz. The crimeware has been evading detection because cyber criminals are rapidly adopting domain generation algorithms (DGAs). This technique is being used to completely evade detection by blacklists, signature filters, and static reputation systems and to hide command-and-control (C&C) infrastructure. DGAs are also referred to as a form of Domain Fluxing, Damballa says.
The eight-page Damballa research report describes, among other things, how BankPatch used DGAs to evade detection for approximately two years. Without having to reverse engineer malware or decode the DGA algorithm, Damballa Labs says it figured out how to automatically detect and model DGA behavior using patent-pending machine-learning technology.
The company also released a detailed analysis of a recent variant of the Zeus version 3 malware, and, for the first time, provided details on its use of DGAs as a secondary connection technique when the primary connection attempt is blocked or fails (the primary connection technique being peer-to-peer).
DGAs first made major news with the outbreak of Conficker. Since that time, the DGA techniques have significantly advanced and are now being adopted by some of the more stealthy threats and by criminals desperately seeking to avoid attribution.
According to the Damballa report, "
Reduce Email Archives up to 60%
Are you considering implementing a proactive archiving and eDiscovery solutions? This paper summarizes 15 separate soft cost savings when implementing Symantec Enterprise Vault and the Clearwell eDiscovery Platform.
Aberdeen Report: To Patch, or Not to Patch? (Not If, But How)
The report explores the correlation between the current use of patch management and the level of endpoint-related risk that companies are effectively accepting.
Recent Comments
- The CISO's Survival Guide to Securing Data
- Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- FireEye Advanced Threat Protection KnowledgeVault
- Five Tips to Consider in a Data Security Strategy for Smartphones and Tablets
- Moving Your Email to the Trusted Cloud
- Comprehensive Server Protection

