Clues That Identify Where Malware Originates

We’re used to the idea that web traffic can be tracked to its location, but malicious code developers often take extra steps to try and conceal their identity. However, there are often tell-tale clues even when that happens — everything from the font used on phishing mails to the file structures evident in malware code.

A report from security software developer FireEye identifies seven “calling cards” that can point to the origin of a particular malicious attack. In the example above, while the text is written in Russian, two fonts commonly used in Korea (Batang and KPCheongPong) are also visible. “Those font choices reconfirmed existing evidence from other sources that pointed to North Korea, including the author’s name and the CnC servers used in the attack,” the report notes.

Others on the list include repeated language mistakes (which can sometimes be reverse-engineered to suggest the language of origin) and common patterns of DNS registration across multiple attack sites.

These clues aren’t easily analysed by the casual observer, though bad expression remains one of the most obvious indicators of phishing emails. Hit the link for the full report.

Digital Bread Crumbs [FireEye]


The Cheapest NBN 50 Plans

Here are the cheapest plans available for Australia’s most popular NBN speed tier.

At Lifehacker, we independently select and write about stuff we love and think you'll like too. We have affiliate and advertising partnerships, which means we may collect a share of sales or other compensation from the links on this page. BTW – prices are accurate and items in stock at the time of posting.

Comments


One response to “Clues That Identify Where Malware Originates”