Skip to main content
QUICK REVIEW

[论文解读] Privacy and Security Risks of "Not-a-Virus" Bundled Adware: The Wajam Case

Xavier de Carné de Carnavalet, Mohammad Mannan|arXiv (Cornell University)|May 13, 2019
Advanced Malware Detection Techniques参考文献 22被引用 4
一句话总结

本文研究了 Wajam,一个长期存在的广告软件平台,其已演变为一种复杂且严重威胁隐私与安全的恶意威胁。通过逆向工程与对 52 个样本(2013–2018 年)的分析,作者揭示了其先进的反分析与杀毒软件规避技术,包括通过 ProtocolFilters 实现的流量拦截、浏览器历史记录外泄、任意 HTTPS 内容注入以及远程代码执行——表明广告软件可能带来与传统恶意软件相当的风险。

ABSTRACT

Comprehensive case studies on malicious code mostly focus on botnets and worms (recently revived with IoT devices), prominent pieces of malware or Advanced Persistent Threats, exploit kits, and ransomware. However, adware seldom receives such attention. Previous studies on "unwanted" Windows applications, including adware, favored breadth of analysis, uncovering ties between different actors and distribution methods. In this paper, we demonstrate the capabilities, privacy and security risks, and prevalence of a particularly successful and active adware business: Wajam, by tracking its evolution over nearly six years. We first study its multi-layer antivirus evasion capabilities, a combination of known and newly adapted techniques, that ensure low detection rates of its daily variants, along with prominent features, e.g., traffic interception and browser process injection. Then, we look at the privacy and security implications for infected users, including plaintext leaks of browser histories and keyword searches on highly popular websites, along with arbitrary content injection on HTTPS webpages and remote code execution vulnerabilities. Finally, we study Wajam's prevalence through the popularity of its domains. Once considered as seriously as spyware, adware is now merely called "not-a-virus", "optional" or "unwanted" although its negative impact is growing. We emphasize that the adware problem has been overlooked for too long, which can reach (or even surplus) the complexity and impact of regular malware, and pose both privacy and security risks to users, more so than many well-known and thoroughly-analyzed malware families.

研究动机与目标

  • 调查 Wajam 这一存在七年的广告软件平台的技术演变及其持续威胁,该平台从一个社交搜索引擎演变为高风险间谍软件。
  • 分析 Wajam 所采用的反分析与杀毒软件规避机制,包括多态更新、隐写术以及注册表混淆技术。
  • 评估 Wajam 所带来的真实世界隐私与安全风险,例如浏览器历史记录明文泄露及任意 HTTPS 内容注入。
  • 通过域名追踪与数据库泄露分析,评估 Wajam 及其变种的传播范围与影响程度。
  • 鉴于广告软件与 PUP(潜在有害程序)日益复杂且威胁面扩大,呼吁在网络安全研究中给予其更多关注。

提出的方法

  • 收集并逆向分析了 2013–2018 年间共 52 个 Wajam 样本,以追踪其技术演变过程。
  • 分析了 ProtocolFilters 的使用,以拦截并修改 HTTPS 流量,从而实现中间人(MITM)攻击。
  • 识别并验证了通过隐写术将次级安装程序嵌入媒体文件中,以规避检测的技术。
  • 追踪域名基础设施与每日变种分发情况,以评估其传播与持久化机制。
  • 发现并报告了一个 Wajam 变种(OtherSearch)的公开暴露的 MySQL 数据库,其中包含超过一亿条 Google 搜索记录。
  • 对注册表修改、进程注入及证书操作进行了行为分析,以检测其长期持久性。

实验结果

研究问题

  • RQ1现代广告软件平台(如 Wajam)在多大程度上采用了先进的反分析与杀毒软件规避技术?
  • RQ2Wajam 运行过程中所关联的真实隐私与安全风险是什么,特别是涉及 HTTPS 流量与浏览器数据时?
  • RQ3基于域名使用情况与网络基础设施,Wajam 及其变种的传播范围与普遍程度如何?
  • RQ4当广告软件使用合法 SDK(如 ProtocolFilters)在未经用户同意的情况下实现中间人攻击时,其影响是什么?
  • RQ5尽管广告软件威胁(尤其是 PUP 形式)的复杂性与影响日益增加,为何其长期未受到充分研究?

主要发现

  • Wajam 采用多层规避策略,包括多态更新、隐写安装包分发以及注册表键随机化,导致杀毒引擎检测率极低。
  • 该广告软件利用 ProtocolFilters 对 HTTPS 流量实施中间人攻击,注入任意内容,使用户面临会话劫持与凭据窃取风险。
  • Wajam 从高流量网站(包括 Google)外泄明文浏览器历史记录与关键词搜索,大规模损害用户隐私。
  • 一个 Wajam 变种(OtherSearch)因数据库未受保护,导致超过一亿条 Google 搜索查询与点击结果泄露,涉及 654 万个唯一用户 ID。
  • 研究发现,共使用了 332 个域名分发 Wajam 变种,且来自多个来源的每日更新,表明其具备高度弹性与可扩展的基础设施。
  • 尽管其运营时间长、攻击面广,但 Wajam 长期未被安全厂商检测与处理,凸显了威胁分析中的关键疏漏。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。