The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

New Brazilian banking Trojans recycle old URL obfuscation tricks

Kaspersky Lab Expert
Posted March 19, 21:17  GMT
Tags: Internet Banking, Obfuscation

Fabio, our researcher in Brazil, has noticed malware authors using an old trick to mask URLs. The trick involves specifying an IP address such as say, (the IP address of google.com, borrowed from my colleague, Costin) in a numerical base other than base 10. The supported bases are octal (8) and hexadecimal (16), and even a single 32bit number work, thus the following are all valid, and each will take you to google.com:

Now, by itself, this isn’t terribly interesting from a technical perspective; this ‘feature’ of IP specification has been around for quite a while.

However…what is interesting though is that due to the relative obscurity of using such methods to denote an IP or URL, it is quite feasible that existing security products do not correctly identify the URLs as valid or flag them as malicious when they point to existing known bad websites.

In my testing, Firefox on Windows supports all of the above addresses, under Linux however, Marco from our German office says some are unsupported. Based on poor browser support for such features, it’s possible to imagine URL filtering tools having the same lack of support.

In addition to potential weak tool support for such URLs, it is likely that unsuspecting users may be more easily convinced that a particular URL is legitimate, which I think is the obvious goal of using such URL obfuscation techniques.



2013 Feb 07, 14:19

Defcon talk by Josh Phillips

Privacy PC guys have made a detailed transcription of the Defcon talk by Josh Phillips and Mike Donnelly on Hacking Online Games: http://privacy-pc.com/news/hacking-online-games-josh-phillips-and-michael-donnelly.html

If you would like to comment on this article you must first

Bookmark and Share