Newsletter
July 5, 2009
Search 
JUST IN
cxo_content_drill
Home
CXOtoday Storage
CXOtoday Plus
News
Industry Verticals
Tech Insight
Market Scan
Interview
CXO Lifestyle
CXO Views
Case Studies
White Papers
Editorial
Downloads
Specials
SMB Zone
TECH INSIGHT
SaaS: Opportunities and Challenges in India
Despite challenges, SaaS model is here to stay. Anita N, corporate communications, Calsoft talks about what these challenges are and how enterprises can overcome them to leverage SaaS benefits.
More...
MARKET SCAN
Broadband Internet Investment Beat Recession Blues
The urge to avoid commuting and green concerns have ensured investments in broadband Internet globally remain robust and are not pared down, finds a study.
More...
 Home > News > Security
Email Print View Comments   
MBR Rootkit, A New Breed of Malware
By CXOtoday Staff
Mumbai, Mar 04, 2008 1436 hrs IST

The MBR is the first physical sector of the hard drive and contains the first code loaded and executed from the drive during the boot process. In the competition between rootkits and rootkit detectors, the first to execute has the upper hand. And you can't execute earlier than from the MBR. MBR viruses used to be very common in the DOS days, 15 years ago or so. This new Windows MBR rootkit launches itself very early during the Windows startup process without requiring any registry or file modifications. In fact, it is quite surprising that it's possible to write to the MBR from within Windows to begin with. The MBR rootkit - known as "Mebroot" - is highly advanced and according to security solutions provider, F-secure, probably the stealthiest malware seen so far. It keeps the amount of system modifications to a minimum and is very challenging to detect from within the infected system. Some details about the MBR rootkit's stealth features: * The 'ntoskrnl.exe' module hook that executes the kernel-mode downloader payload is set to the 'nt!Phase1Initialization' function which resides in the INIT section. This means that after the system has initialized the section is wiped out from memory and no sign of the hook is any longer present. * The rootkit stores data that's required to survive reboots in physical sectors instead of files. This means that the data, including the real payload, is not visible or in any way accessible to normal applications. Therefore the rootkit does not have to hook the normal set of interfaces to keep them hidden. * The MBR is the rootkit's launch point. Therefore it doesn't need to make any registry changes or to modify any existing startup executables in order to launch itself. This means that the only hooks it needs to make are used to hide and protect the modified MBR. Essentially this means that the rootkit hooks only two DWORDs from the disk.sys driver object. * Another interesting feature of the MBR rootkit that has not received very much public discussion is its networking layer and firewall bypassing capabilities. One reason for this might be that this part of Mebroot's code is heavily obfuscated and time consuming to analyze. It is known that the rootkit's main purpose is to act as an ultimate downloader. To be stealthy and effective it is essential that the rootkit does not trigger nor is blocked by personal firewalls. It is able to achieve this by operating in the lowest parts of the NDIS layer just above the physical hardware. Only a single DWORD is hooked at all times from the NDIS internal structures. To send packets the rootkit uses the SendPacketsHandler function implemented by the actual hardware specific driver. The rootkit uses its own unmodified versions of NDIS API functions it needs to operate. This has been done before by some malware, such as Rustock and Srizbi. However, what has not been seen before is the fact that the MBR rootkit uses a "code pullout" technique to only load the relevant code from the ndis.sys driver instead of loading the whole 'ndis.sys' driver as its private module into memory. This means that the memory fingerprint of the malware is smaller and there are no additional modules loaded into the system address space, which might trigger some forensic tools. This malware is very professionally written and produced. Initial samples from December 2007 and January 2008 were at beta stage. Now it appears that the malware is fully ready and more active distribution has begun. During the weekend F-Secure Security Labs started to receive information about multiple drive-by exploit sites spreading the latest version. The actual site hosting the exploit code utilizes the following exploits: * Microsoft Data Access Components (MDAC) Function vulnerability (MS06-014) * AOL SuperBuddy ActiveX Control Code Execution vulnerability (CVE-2006-5820) * Online Media Technologies NCTsoft NCTAudioFile2 ActiveX Buffer Overflow (CVE-2007-0018) * GOM Player "GomWeb3" ActiveX Control Buffer Overflow (CVE-2007-5779) * Microsoft Internet Explorer WebViewFolderIcon setSlice (CVE-2006-3730) * Yahoo! JukeBox datagrid.dll AddButton() Buffer Overflow * DirectAnimation.PathControl KeyFrame vulnerability (CVE-2006-4777) * Microsoft DirectSpeechSynthesis Module Remote Buffer Overflow Proof of concept code for two of the exploits was publicly disclosed just less than a month ago. The downloaded payloads seem to clearly target online banking and other financial systems. Related Links: AMD: Advanced Malware Detection Panda Says Malware on the Rise
  Tags: MBR Rootkit   A New Breed of Malware  
  Share and Connect   Myweb MyWeb  Newsvine.comNewsvine.com 
  You may also be interested to read latest news under :
  Business| Hardware| Software| People| Technology|
  Recent news in Security
 
Symantec's New Approach to Security with Quorum
Hyderabad Police Gets Tough with Cyber Crime
PwC to Research Tech Approaches for PCI (SSC)
HDFC Strengthens Security of Online Customers
Security Revenues Up, Appliance-based Products In
 
 
Comment :

Name :
Company :
City :
E-mail :
Word verification : Type the characters you see in the picture below.
 
Characters are not case-sensitive
   


Disclaimer
ITNation (India) Pvt. Limited and its sites: www.channeltimes.com, www.techtree.com and www.cxotoday.com provide Comments and discussion boards as a professional medium for the various businesses of the IT industry to discuss business problems. Gossip, personal attacks and unsubstantiated charges are prohibited. Messages posted on this Web site as discussion threads or Comments (Content) are solely the opinions of their creators and do not necessarily reflect the opinions of ITNation (India) Pvt. Limited or its sites www.channeltimes.com, www.techtree.com and www.cxotoday.com.
All individuals who post material to this web site are solely responsible for all Content that they upload, post or otherwise transmit via the Web Site.
ITNation cannot vouch for the authenticity of the user or company names or e-mail addresses associated with posted messages. Under no circumstances will ITNation India Pvt.Ltd. or Cxotoday.com be liable in any way for any Content, including, but not limited to, for any errors or omissions in any Content, or for any loss or damage of any kind incurred as a result of the use of any Content posted or otherwise transmitted via the Bulletin Boards.
ITNation reserves the exclusive right to edit or remove messages containing inappropriate language or other material that could be construed as libelous, potentially libelous, or otherwise offensive or inappropriate. Discussion forums, bulletin boards and chat facilities are provided by ITNation solely for the convenience of those who make use of the service. ITNation does not endorse the products and services or other offerings mentioned in messages.
TODAY'S HEADLINES
Budget 2009
ESOPs should be made
Symantec's Quorum
BI to Manage Unstructure
Barrett Gives Intel-Noki
CXO VIEWS
Lean Six Sigma Makes Biz Customer Responsive
Lean Six Sigma (LSS) is a management concept that focuses on customer needs like no other process does, says Balaji Rajagopalan, executive director-Operations and LSS, Xerox. Rajagopalan dwells extensively on the LSS concept in an interview with Tabrez Khan
More...
LATEST COMMENTS
want training in finance mgt pls contact ..
If India can't take advantage of the global ..
HELLO SIR i have got the information that ..
I WANT TO BE A AUTHORISED ALL TYPES OF TICKET ..
dear sir, i have a 2000 sq ft. space available ..
MOST POPULAR STORIES
Nandan Nilekani to Quit (2)
Budget Expectations (2)
Roshni Nadar HCL CEO (1)
Healthcare, Energy (1)
Satyam Computers is MS (1)
Copyright (C) 2009 ITNation India Pvt. Ltd. All Rights Reserved.