Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

December 29th, 2010, 18:18 GMT · By

New Phoenix Exploit Kit Version Employs Anti-Analysis Techniques

SHARE:

Adjust text size:


Phoenix exploit kit authors ramp up anti-analysis protection
Enlarge picture
New versions of the Phoenix drive-by download kit employ special obfuscation and name randomization techniques in order to protect its installations from analysis by security researchers.

Along Eleonore, Phoenix is one of the most popular exploit kits used by cyber criminals to sillently infect users with malware over the Web.

These attacks, known as drive-by downloads, are usually launched from legit websites that have been compromised and injected with rogue code.

The code's purpose is to load the exploit pack landing page from a remote server. This contains scripts which determine the visitor's operating system and browser, as well as the installed version of popular applications like Adobe Reader, Flash Player or Java.

These checks are needed in order to select and serve the exploit that has most chances of success against the user's particular configuration.

"Like many exploit kits, this one is PHP-based but unlike most kits, the installer is actually obfuscated," writes Chris Astacio, a security analyst at Websense.

"This is probably an attempt by the developers to make it harder for security researchers to understand how to install the kits, especially if there is no 'readme.txt' file included," he adds.

However, in addition to the obfuscated installer, which is by no means impossible to reverse-engineer, the new Phoenix versions randomize the names of the generated pages.

These are the files uploaded by attackers on their servers and used for the toolkit's multiple functions, including displaying attack statistics.

Generating unique file names certainly makes it harder to researchers to try and hack into new Phoenix instances, especially if all they have is the original install script.

"We can see that the developers of Phoenix Exploit's Kit are working on not only protecting their exploit code from being recognized, but also their installations," Mr. Astacio concludes.

TELL US WHAT YOU THINK:

2,454 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


New Drive-By Download Attack Exploits Recently Patched IE Flaw

Siberia Exploits Kit Features AV Scanner Module

Exploit Toolkit Infects One in Ten Users via Outdated Java

Drive-By Kit Generates Fake Twitter Home Pages

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM