Jump to content

Content Filtering Issues With Microsoft Outlook


Guest CalamityJane
 Share

Recommended Posts

Guest CalamityJane

Advisory from Message Labs

Date: 1/29/03 12:47:49 PM Eastern Standard Time

From: [email protected]

With the advances being made in content filtering techniques, virus authors and trojan writers are now resorting to exploiting the veiled quirkiness of our email software to further consolidate their social engineering tactics.

Malware authors are exploiting an Outlook quirk to give their malware a better chance of evading any content filters, and then persuading an email recipient that an attachment is safe to open when in fact it contains some malicious program.

Over the weekend (25th – 26th January 2003), MessageLabs stopped over 3,000 copies of a trojan called W32/Sadhound, which had been distributed using just this trick.  However, this is not the first time MessageLabs have stopped emails of this nature; there are now many tools freely available to malware authors that can be used to assist them in this task. 

See Advisory on W32/Sadhound.A following

The Exploit

The malware relies on especially crafted email headers, creating an attachment with three file-extensions.  Standard email packages will not generate these headers; these emails must either be created by hand, or using hacker tools (this exploit has been known of for a long time in the hacker community).

Content Filters

If the filename used for the malware attachment ends with a “safe” extension, for example .JPG or .HTM, the email is unlikely to be stopped by the most common content filters that would otherwise block potentially harmful file programs.  Many content filtering mechanisms in place may also look for double extensions, in addition to the usual problematical ones.  However, these need to be carefully checked as well.  Often the order in which the double extensions appear determines whether the file is blocked or not.  For example, blocking .JPG. EXE may not be sufficient; you may additionally need to block .EXE. JPG.

Further details may be found on the MessageLabs website at:

http://www.messagelabs.com/viruseye/report.asp?id=130

.......................................................

Subj: New Virus Warning: W32/Sadhound.A

Date: 1/26/03 7:14:42 PM Eastern Standard Time

The details of the new virus are as follows:

    Virus name: W32/Sadhound.A

    Number of copies seen so far: 2,704

    Date first Captured: 25th Jan 2003

    Origin of first intercepted copy: Netherlands

    Number of countries seen active: 1

    Most active countries: Netherlands

Technical Details

On 25th January 2003, MessageLabs intercepted the first copies of a new virus called W32/Sadhound.A.  To date, all of the copies that we have thus far stopped all originated from the same IP address in the Netherlands.  Therefore, at this time, we are unsure as to whether this is a seeding of a trojan, broken malware, or a mass-mailer.

Initial analysis suggests this is a dropper-program, depositing a mass-mailer with a backdoor and a mIRC component; however, this has yet to be confirmed.

From the copies that MessageLabs have intercepted, the email may be composed as follows:

Subject:

    I Miss You

The email body contains the following text:

    I Miss You…

Attachment file names include:

    Bloods.jpg (11,507) – a picture of a sad-looking bloodhound,

    hence the name

    bgg.jpg (2,680) – a background image

    Missingyou.htm .pf.htm – or Missingyou.pif (11,296) since the name

    and filename are different in the MIME header.

Detection

Skeptic™ detected W32/Sadhound.A heuristically.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy