Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / News / Fileless Powershell malware uses DNS as covert communication channel

Fileless Powershell malware uses DNS as covert communication channel

Latest Govt. Jobs 22:40:00 News Edit
DNSMessenger uses DNS TXT records to steal data.

Targeted attacks are moving away from traditional malware to stealthier techniques that involve abusing standard system tools and protocols, some of which are not always monitored.
The latest example is an attack dubbed DNSMessenger, which was analyzed by researchers from Cisco Systems' Talos team. The attack starts with a malicious Microsoft Word document distributed through an email phishing campaign.
When opened, the file masquerades as a "protected document" secured by McAfee, an antivirus brand now owned by Intel Security. The user is asked to click on the enable content button in order to view the document's content, but doing so will actually execute malicious scripting embedded within.
[ Further reading: How the new age of antivirus software will protect your PC ]
The script is written in Powershell, a powerful scripting language built into Windows that allows for the automation of system administration tasks. What's interesting is that until this point, everything is done in memory, without writing any malicious files to disk.
The second stage is also done in Powershell and involves checking for several parameters of the envrionment, like the privileges of the logged-in user and the version of Powershell installed on the system. This information is used to determine how to proceed to the next step and how to achieve persistence.
Depending on the result of the stage-two checks, yet another Powershell script will either be stored in an Alternate Data Stream (ADS) in the NTFS file system or directly inside the registry. The third stage Powershell script contains an additional obfuscated script that establishes a fairly sophisticated two-way communications channel over the Domain Name System (DNS).
DNS is normally used to look up the Internet Protocol addresses associated with domain names, but it has support for different types of records. The TXT record in particular allows a DNS server to attach unformatted text to a response.
"All C2 [command-and-control] communications associated with this malware are performed using DNS TXT queries and responses," the Cisco Talos researchers said in a blog post.
This covert communication channel allows attackers to send commands to be executed on the system and to receive the output of those commands.
Organizations typically go to great lengths to filter HTTP and HTTPS traffic that goes in and out of their networks, but not many of them monitor DNS. Attackers know this and are encapsulating other protocols inside DNS to remain undetected.
The use of system tools like Powershell and code that's executed directly in memory are also increasingly common techniques that makes the detection of compromises much harder.
"This malware sample is a great example of the length attackers are willing to go to stay undetected while operating within the environments that they are targeting," the Cisco Talos researchers said. "It also illustrates the importance that in addition to inspecting and filtering network protocols such as HTTP/HTTPS, SMTP/POP3, etc. DNS traffic within corporate networks should also be considered a channel that an attacker can use to implement a fully functional, bidirectional C2 infrastructure."
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


Oppo F7 India launch confirmed

Alcatel 1x with Android Oreo (Go ed...

Huawei P20, P20 Pro, P20 Lite price
Fileless Powershell malware uses DNS as covert communication channel Fileless Powershell malware uses DNS as covert communication channel Reviewed by Latest Govt. Jobs on 22:40:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • Taotronics TT-BH22 Headphones Review
    We make it a addiction to now not look up pricing of a product sooner than reviewing and if ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on Monday strongly condemned North Korea’s latest missile test, adding that the ...
  • Fitbit Zip 2017 review
    Fitbit PROS: Clever, accurate tracking Expandable online service Integration with 3rd ...
  • Bank wallets growing faster than e-wallets
    In the  bank  versus  e-wallets  sweepstakes,  lenders  have now gained lost ground. As of ...

Random Posts

  • 15 Effective Beauty Tips for Fair Skin
    15 Effective Beauty Tips for Fair Skin
    26.03.2016 - 0 Comments
    “Beauty lies in the eyes of beholder.”- PlatoBeauty—this word itself brings smiles on faces of many people.…
  • How To Remove Hair Color With Baking Soda?
    How To Remove Hair Color With Baking Soda?
    13.05.2016 - 0 Comments
    Have you ever colored your hair only to realize how disastrous it was? You are not alone. When something like…
  • Xiaomi Mi5 Review: Great Design. Amazing Specs. INSANE Price
    Xiaomi Mi5 Review: Great Design. Amazing Specs. INSANE Price
    11.02.2017 - 0 Comments
    Xiaomi has always been successful at combining cutting-edge mobile tech with eye-catching design and…
  • AT&T Mobile Insurance and Protection Plan Prices Increasing in April
    AT&T Mobile Insurance and Protection Plan Prices Increasing in April
    07.02.2017 - 0 Comments
    According to a reliable source, AT&T is preparing to increase prices of their device…
  • The best top 10 next-gen smartphone innovations you need to know about
    The best top 10 next-gen smartphone innovations you need to know about
    04.03.2017 - 0 Comments
    Mobile World Congress is a largely corporate show. The big telecoms companies jostle with each other…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • Taotronics TT-BH22 Headphones Review
    We make it a ...
  • Bank wallets growing faster than e-wallets
    In the  bank ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on ...
  • Fitbit Zip 2017 review
    Fitbit PROS ...

Random Posts

  • Nintendo’s Q3 net profit jumps on Pokémon sales
    Nintendo’s Q3 net profit jumps on Pokémon sales
    05.02.2017 - 0 Comments
    Japanese video game maker Nintendo’s third-quarter profit more than doubled from a year earlier on…
  • Your last guide To Organizing long WordPress content material And weblog Posts
    Your last guide To Organizing long WordPress content material And weblog Posts
    01.04.2017 - 0 Comments
    When you build a website or blog, populating it with content is just one step of the process. For some,…
  • Here is How to make Storage Space in a Amazon Fire Tablet
    Here is How to make Storage Space in a Amazon Fire Tablet
    26.01.2018 - 0 Comments
    Amazon Fire tablets ship with 8GB to 16GB of internal storage. It’s not much. You’re…
  • APPLE IPAD AIR 2 WIFI CELLULAR 32GB
    APPLE IPAD AIR 2 WIFI CELLULAR 32GB
    17.11.2016 - 0 Comments
    SUMMARY To many a tablet is an entertainment device and…
  • Facebook loses Belgian privacy case
    Facebook loses Belgian privacy case
    17.02.2018 - 0 Comments
    BRUSSELS: A Belgian court threatened Facebook with a fine of up to 100 million euros ($125 million) if it…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!