Examining the Creation, Distribution, and Function of Malware On-Line
Total Page:16
File Type:pdf, Size:1020Kb
The author(s) shown below used Federal funds provided by the U.S. Department of Justice and prepared the following final report: Document Title: Examining the Creation, Distribution, and Function of Malware On-Line Author: Bill Chu, Ph.D., Thomas J. Holt, Ph.D., Gail Joon Ahn, Ph.D. Document No.: 230111 Date Received: March 2010 Award Number: 2007-IJ-CX-0018 This report has not been published by the U.S. Department of Justice. To provide better customer service, NCJRS has made this Federally- funded grant final report available electronically in addition to traditional paper copies. Opinions or points of view expressed are those of the author(s) and do not necessarily reflect the official position or policies of the U.S. Department of Justice. This document is a research report submitted to the U.S. Department of Justice. This report has not been published by the Department. Opinions or points of view expressed are those of the author(s) and do not necessarily reflect the official position or policies of the U.S. Department of Justice. Examining the Creation, Distribution, and Function of Malware On-Line Award Number: 2007-IJ-CX-0018 Bill Chu, Ph. D. The University of North Carolina at Charlotte Thomas J. Holt, Ph. D. Michigan State University Gail Joon Ahn, Ph. D. Arizona State University This document is a research report submitted to the U. S. Department of Justice. Opinions or points of view expressed are those of the authors and do not reflect the official position or policies of the U. S. Department of Justice. 1 This document is a research report submitted to the U.S. Department of Justice. This report has not been published by the Department. Opinions or points of view expressed are those of the author(s) and do not necessarily reflect the official position or policies of the U.S. Department of Justice. Abstract The global adoption of the Internet and World Wide Web has engendered the growth of significant threats from computer criminals around the world. Computer crimes are costly, and many appear to be perpetrated by computer hackers in foreign countries, particularly Russia and Eastern Europe. These attackers often use malicious software, or malware, to automate attacks and enable multiple forms of cybercrime. Recently, a great deal of attention has been given to a new form of malware used by computer hackers called bots. This malware essentially takes over an infected computer, allowing it to receive commands remotely. Bots are also bought and sold in virtual markets operating out of Russia. Researchers have, however, only begun to explore the prevalence and origins of this form of malware and its potential as an attack tool. Thus, this study examined the social and technical aspects surrounding the creation, distribution, and use of bots through both a criminological and computer science examination of bots and malware. Specifically, 13 bots were captured in the wild and analyzed using honeynet technologies to determine their utility and function in a simulated computing environment. The findings suggest that these bots had a significant impact on system functionality by changing system protocols, including adding and removing files. The bots also attempted to connect to command and control IRC servers around the world, though the majority appeared to reside in the United States. Five of the bots were able to connect to a command and control channel and received commands to scan other systems online, participate in Denial of Service Attacks, infect another system, and open communication sessions with other computers. The creation and sale of bots and malware in the on-line black market were also examined using a sample of 909 threads collected from 10 publicly accessible web-forums in Eastern Europe and Russia. The findings suggest that a service economy has developed around 2 This document is a research report submitted to the U.S. Department of Justice. This report has not been published by the Department. Opinions or points of view expressed are those of the author(s) and do not necessarily reflect the official position or policies of the U.S. Department of Justice. the spread of bots, including distributed denial of service attack providers, spam distribution, and bulletproof web hosting. Malware is also available through these forums, such as trojan horse programs, encryption tools, and iframe malware uploading and downloading services. Credit card and identity documents were also readily available, along with hijacked ICQ numbers. In order to better understand the social dynamics of this market, the normative orders of this community were explored using grounded theory methodology. The results suggest that three interrelated norms shape the relationships between buyers and sellers: price, customer service, and trust. Price is critical as the cost of goods affect the likelihood that an individual would be able to compete in the market. Customer service reflects the quality of products available, discounts for volume purchases, and real time support to their customers. Finally, trust refers to the lack of regulation within the markets, increasing the risk of engaging in a purchase with a vendor. Individuals who demonstrate that they were trustworthy could gain clients, while those who attempt to cheat other actors were publicly derided. As a whole, this study demonstrates the key role that bots and other malicious software play in the facilitation of cybercrime across the globe. Bots have various utility in the wild, and receive commands from IRC channels around the globe. Though malicious software takes some skill to create, the forums examined demonstrate that bot masters generate a profit from their infrastructure by selling access to attack services that enables hackers of any skill to participate in attacks ranging from Distributed Denial of Service attacks to spam. Thus, there is a significant need to disrupt botnets and the markets that facilitate the distribution of malware and hack tools. 3 This document is a research report submitted to the U.S. Department of Justice. This report has not been published by the Department. Opinions or points of view expressed are those of the author(s) and do not necessarily reflect the official position or policies of the U.S. Department of Justice. Table of Contents Executive Summary p. 5 I. Introduction p. 14 Bot Functionality and Use p. 17 Malicious Software and Stolen Data Markets p. 21 Rationale for Research p. 24 II. Methods p. 25 Bot Analyses p. 25 Qualitative Research p. 30 III. Results p. 35 Bot Analyses p. 35 Qualitative Analyses p. 40 IV. Conclusions p. 124 Discussion of Findings p. 124 Implications for Policy and Practice p. 127 Implications for Further Research p. 135 V. References p. 138 Appendix 1 p. 146 4 This document is a research report submitted to the U.S. Department of Justice. This report has not been published by the Department. Opinions or points of view expressed are those of the author(s) and do not necessarily reflect the official position or policies of the U.S. Department of Justice. Executive Summary The Internet and World Wide Web have dramatically changed the way people communicate and do business around the world. These changes have far reaching consequences, affecting business, banks, government, and home computer users. As a result of the growth and penetration of computer technology, the threat posed by computer criminals has become increasingly significant. Computer crimes are costly, and many appear to be perpetrated by computer hackers in foreign countries, particularly Russia and Eastern Europe. These attackers often use malicious software programs, or malware, that automate a variety of attacks and enable different criminal acts. Recently, a great deal of attention has been given to a new form of malicious code used by computer hackers and attackers called bots. Technical analyses of bots indicate that they operate around the world and can be used to facilitate all manner of computer and cybercrime. Thus, they pose a serious threat to government, businesses, and computer users around the globe. Furthermore, a small body of research suggests that bots and services generated from bots can be purchased in open markets operating on Internet Relay Chat channels in Russia and Eastern Europe. Researchers have, however, only begun to explore the prevalence and origins of this form of malware and its potential as an attack tool. In addition, few studies have considered how web forums may facilitate the sale and trade of bots and other malware. This study examined the social and technical aspects surrounding the creation, distribution, and use of bots through a criminological and computer science examination of multiple data sets. Specifically, 13 bots were collected in the wild using a tool called MWCollect that can capture the binary of the malware. Once obtained, each program was analyzed using honeynet technologies to determine their functionality and activity in a simulated computing environment. 5 This document is a research report submitted to the U.S. Department of Justice. This report has not been published by the Department. Opinions or points of view expressed are those of the author(s) and do not necessarily reflect the official position or policies of the U.S. Department of Justice. The findings suggest that these bots had significant impacts on the system by changing system protocols, including adding and removing files, dlls, and registry information. Two of these bots also attempted to download other executable programs hosted on other websites, including a compromised server hosting a legitimate business website in the United States. All of the bots attempted to connect to Internet Relay Chat (IRC) command and control servers around the world, including Hungary, Malaysia, and China. The majority of command and control servers, however, operated in the United States.