Symantec Connect
  • Login
  • Register
  • Security
    • All of Connect
    • Backup and Archiving
    • Clustering and Replication
    • Endpoint Management & Virtualization
    • Storage Management
    • Security
    • Inside Symantec
    • Vision User Conference
    • Partners
    • Developers
    •  
  • Overview
  • Forums
  • Articles
  • Blogs
  • Downloads
  • Events
  • Videos
  • Groups
  • Ideas
Login to participate
Security ResponseRSS

Twitter + Pastebin = Malware Update

Patrick Fitzgerald
August 17th, 2009
Tags: Endpoint Protection (AntiVirus), Emerging Threats, Emerging Threats, Malicious Code, Malicious Code, Security, Security Response
Facebook Twitter

A few days ago we wrote about how Downloader.Sninfs is using Twitter as part of its command and control infrastructure. How the threat uses this is quite interesting. Here’s an example of a Twitter account used by this threat:

imagebrowser image

This is a pretty standard Twitter page, but the message is unusual. It turns out that this message is a base64-encoded string that contains two URLs. These URLs are:

http://bit.ly/17a3tS
http://bit.ly/3CHn

These URLs are using the bit.ly URL-shortening service. These URLs redirect to:

http://rifers.org/paste/content/paste/9509/body?ke...
http://paste.debian.net/44079/download/44079

Debian.net and Rifers.org are both legitimate sites and it was a little surprising to see them both in this context. A closer look shows that both of these URLs seem to be using the pastebin feature of the Debian and Rifers sites. Pastebins give Web users the ability to upload arbitrary text in order to share information. Pastebins exist on many sites across the Internet and any one of these sites could have been selected by the attackers in order to host their malicious payloads. It’s likely the Debian and Rifers sites were selected because of the trust associated with their brand. There is little these sites can do to mitigate this type of misuse of a legitimate service provided by their sites.

Pastebin items are typically short-lived and deleted automatically after a period of time. The data at both of these URLs seems to have expired and is not available at the above URLs; however, one of the pages was still accessible in Google’s cache:

imagebrowser image

This pastebin item contained a large base64 encoded string. When this is decoded it is shown to be a zip archive containing two files: gbpm.dll and gbpm.exe. These files are both detected as Downloader.Sninfs. This attack highlights the fact that in the wrong hands, any useful technology can be used for malicious purposes. In this case micro-blogging and pastebin have been used by attackers to host their malware.

Symantec customers can ensure that they are fully protected by keeping their product definitions up to date.

0 votes
  • Patrick Fitzgerald's blog
  • Comments RSS Feed

About Security Response Blog

Our security research centers around the world provide unparalleled analysis of and protection from malware, security risks, vulnerabilities, and spam.
Filter by:

Recent Blog Posts

  • Microsoft Patch Tuesday - February 2010
    Robert Keith - February 09, 2010
  • Sale! This Offer is Valid EVERY Week
    Mayur Kulkarni - February 05, 2010
  • SpyEye Bot versus Zeus Bot
    Peter Coogan - February 04, 2010
  • 利用双重漏洞发动攻击的木马Trojan.Hydraq
    Livian Ge - February 03, 2010
  • Phishing Using Pornographic Content as Bait
    Mathew Maniyara - February 03, 2010

Blog Tags

10.x 11.x 9.x and Earlier Brightmail Gateway Emerging Threats Endpoint Encryption Endpoint Protection (AntiVirus) Evolution of Security General Symantec How to IT Risk Management Internet Security Threat Report Malicious Code Mobile & Wireless Online Fraud Platforms & Hardware Restore Security Security Security Risks Spam Vulnerabilities & Exploits Windows
© 2010
  • Symantec Corporation
  • Contact Us
  • Get RSS
  • Newsletter
  • Privacy Policy
  • Symantec.com