200-fold increase in HTML-attachment spam

Posted by   Virus Bulletin on   Feb 16, 2012

Cutwail botnet likely behind campaign that sends users to Phoenix exploit kit.

Researchers at M86 have reported a significant increase in the amount of spam sent with malicious HTML attachments, the volume of which on some days was 200 times that on the first day of the year.

HTML, the mark-up language used to create web pages, is commonly used in email to display various fonts and colours and to embed images. All modern email clients are capable of displaying HTML emails, though it is good practice for these to contain a text-part as well. A slight modification to the emails means the HTML-part is seen as an attachment that can be viewed in a web browser, rather than shown within the email client. It is this that is being used in a large spam campaign, of which M86 believes the Cutwail botnet is the perpetrator.

These particular emails - which either have the subject 'End of August statement' or come with a 'Xerox scan' attached - contain an HTML attachment in which, through obfuscated JavaScript, an iframe is embedded. The Phoenix exploit kit is loaded in the iframe, which attempts to infect the user through exploits in various browsers and plug-ins.

The tactic of infecting users via iframes and obfuscated JavaScript is commonly used for drive-by downloads, mostly in compromised legitimate websites. By using an HTML attachment rather than a website, this kind of attack is less likely to be picked up by web filters, while spam filters may not attempt to de-obfuscate the JavaScript, thus making it less likely for URL blacklists to block the emails.

HTML-attachment spam made the news last month when it was said that users could be infected without opening the attachments. While it is not impossible for an email client to open the attachment and render the JavaScript, either through a bug or through bad design, it seems unlikely for this to happen. We have not found evidence of an email client with that property.

More at M86 here. The original story on the emails allegedly infecting users without the need to open an attachment is at eleven here, with comments from Sophos's Naked Security blog here.

Posted on 16 February 2012 by Virus Bulletin

twitter.png
fb.png
linkedin.png
googleplus.png
reddit.png

 

Latest posts:

Security products and HTTPS: let's do it better

A recent paper showed that many HTTPS-intercepting security solutions have implemented TLS rather poorly. Does that mean we should avoid such solutions altogether?

The SHA-1 hashing algorithm has been 'shattered'

Researchers from Google and CWI Amsterdam have created the first known collision of the SHA-1 hashing algorithm, making a very strong case to ditch it.

Throwback Thursday: Once a researcher...

VB was saddened to learn this week of the passing of one of the pioneers of the AV industry, Ross Greenberg. This Throwback Thursday we look back at an interview with Ross in November 1995.

VB2017: What is happening in the threat landscape and what are we doing against it? Submit a proposal in the VB2017 CFP!

Have you analysed a new online threat? Do you know a new way to defend against such threats? Then submit an abstract in the CFP for VB2017!

VB2016 paper: APT reports and OPSEC evolution, or: these are not the APT reports you are looking for

APT reports are great for gaining an understanding of how advanced attack groups operate - however, they can also provide free QA for the threat actors. Today, we publish a VB2016 paper by Gadi Evron (Cymmetria) and Inbar Raz (Perimeter X), who…