Shedding Light on the Targeted Victim Profiles of Malicious Downloaders

Shedding Light on the Targeted Victim Profiles of Malicious Downloaders
复制标题

DOI:
10.1145/3538969.3544435
复制
发表时间:
2022-08
期刊:
Proceedings of the 17th International Conference on Availability, Reliability and Security
影响因子:
--
通讯作者:
François Labrèche;Enrico Mariconti;G. Stringhini
François Labrèche;Enrico Mariconti;G. Stringhini
中科院分区:
其他
文献类型:
--
作者:
François Labrèche;Enrico Mariconti;G. Stringhini

文献摘要

相似文献

恶意软件影响全球数百万用户,影响许多人和企业的日常生活。恶意软件感染的复杂性正在增加,并在多个阶段展开。恶意下载程序通常充当起点,因为它会对受害者的计算机进行指纹识别,并下载一个或多个额外的恶意软件有效负载。虽然以前对这些恶意下载器及其按安装付费网络进行了研究,但有限的工作调查了受害者机器的配置文件(例如,其特征和软件配置)如何影响网络犯罪分子的目标选择。在本文中,我们通过在12个月的时间里执行151,189次恶意软件下载程序,对机器配置文件与下载程序的有效负载之间的关系进行了大规模的调查。我们构建了一个完全自动化的框架,该框架使用沙箱中的虚拟机(VM)来构建自定义用户和机器配置文件,以测试我们的恶意样本。然后,我们使用变点分析来模拟不同下载者家族的行为,并对每个配置文件的感染率执行方差分析(ANOVA)。有了这一点,我们就可以识别网络犯罪分子在不同时间点针对的机器配置文件。我们的结果表明,根据机器的许多功能,许多下载器呈现出不同的行为。值得注意的是,当使用不同的浏览器配置文件、键盘布局和操作系统时,观察到特定恶意软件家族的感染数量更多,而一个键盘布局获得特定恶意软件家族的感染较少。我们的发现揭示了运行恶意下载器软件的机器功能的重要性,特别是对于恶意软件研究。
Malware affects millions of users worldwide, impacting the daily lives of many people as well as businesses. Malware infections are increasing in complexity and unfold over a number of stages. A malicious downloader often acts as the starting point as it fingerprints the victim’s machine and downloads one or more additional malware payloads. Although previous research was conducted on these malicious downloaders and their Pay-Per-Install networks, limited work has investigated how the profile of the victim machine, e.g., its characteristics and software configuration, affect the targeting choice of cybercriminals. In this paper, we operate a large-scale investigation of the relation between the machine profile and the payload downloaded by droppers, through 151,189 executions of malware downloaders over a period of 12 months. We build a fully automated framework which uses Virtual Machines (VMs) in sandboxes to build custom user and machine profiles to test our malicious samples. We then use changepoint analysis to model the behavior of different downloader families, and perform analyses of variance (ANOVA) on the ratio of infections per profile. With this, we identify which machine profile is targeted by cybercriminals at different points in time. Our results show that a number of downloaders present different behaviors depending on a number of features of a machine. Notably, a higher number of infections for specific malware families were observed when using different browser profiles, keyboard layouts and operating systems, while one keyboard layout obtained fewer infections of a specific malware family. Our findings bring light to the importance of the features of a machine running malicious downloader software, particularly for malware research.