Title
Prometheus: Analyzing WebInject-based information stealers.
Abstract
Nowadays Information stealers are reaching high levels of sophistication. The number of families and variants observed increased exponentially in the last years. Furthermore, these trojans are sold on underground markets along with automatic frameworks that include web-based administration panels, builders and customization procedures. From a technical point of view such malware is equipped with a functionality, called WebInject, that exploits API hooking techniques to intercept all sensitive data in a browser context and modify web pages on infected hosts. In this paper we propose Prometheus, an automatic system that is able to analyze trojans that base their attack technique on DOM modifications. Prometheus is able to identify the injection operations performed by malware, and generate signatures based on the injection behavior. Furthermore, it is able to extract the WebInject targets by using memory forensic techniques. We evaluated Prometheus against real-world, online websites and a dataset of distinct variants of financial trojans. In our experiments we show that our approach correctly recognizes known variants of WebInject-based malware and successfully extracts the WebInject targets.
Year
DOI
Venue
2017
10.3233/JCS-15773
JOURNAL OF COMPUTER SECURITY
Keywords
Field
DocType
WebInject,banking trojan,info-stealer
Data science,Computer science,Theoretical computer science
Journal
Volume
Issue
ISSN
25
2
0926-227X
Citations 
PageRank 
References 
3
0.41
11
Authors
6
Name
Order
Citations
PageRank
Andrea Continella1598.18
michele carminati2214.16
Mario Polino31126.94
Andrea Lanzi484540.99
Stefano Zanero573653.78
Federico Maggi652437.68