{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T11:00:16Z","timestamp":1777806016796,"version":"3.51.4"},"reference-count":29,"publisher":"SAGE Publications","issue":"2","license":[{"start":{"date-parts":[[2017,2,15]],"date-time":"2017-02-15T00:00:00Z","timestamp":1487116800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2017,5,2]]},"abstract":"<jats:p>Nowadays Information stealers are reaching high levels of sophistication. The number of families and variants observed increased exponentially in the last years. Furthermore, these trojans are sold on underground markets along with automatic frameworks that include web-based administration panels, builders and customization procedures. From a technical point of view such malware is equipped with a functionality, called WebInject, that exploits API hooking techniques to intercept all sensitive data in a browser context and modify web pages on infected hosts.<\/jats:p>\n                  <jats:p>In this paper we propose Prometheus, an automatic system that is able to analyze trojans that base their attack technique on DOM modifications. Prometheus is able to identify the injection operations performed by malware, and generate signatures based on the injection behavior. Furthermore, it is able to extract the WebInject targets by using memory forensic techniques.<\/jats:p>\n                  <jats:p>We evaluated Prometheus against real-world, online websites and a dataset of distinct variants of financial trojans. In our experiments we show that our approach correctly recognizes known variants of WebInject-based malware and successfully extracts the WebInject targets.<\/jats:p>","DOI":"10.3233\/jcs-15773","type":"journal-article","created":{"date-parts":[[2017,2,17]],"date-time":"2017-02-17T10:37:13Z","timestamp":1487327833000},"page":"117-137","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":9,"title":["Prometheus: Analyzing WebInject-based information stealers"],"prefix":"10.1177","volume":"25","author":[{"given":"Andrea","family":"Continella","sequence":"first","affiliation":[{"name":"Politecnico di Milano, Italy. E-mails:\u00a0,\u00a0,\u00a0,\u00a0,\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michele","family":"Carminati","sequence":"additional","affiliation":[{"name":"Politecnico di Milano, Italy. E-mails:\u00a0,\u00a0,\u00a0,\u00a0,\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mario","family":"Polino","sequence":"additional","affiliation":[{"name":"Politecnico di Milano, Italy. E-mails:\u00a0,\u00a0,\u00a0,\u00a0,\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrea","family":"Lanzi","sequence":"additional","affiliation":[{"name":"Universit\u00e0 degli Studi di Milano, Italy. E-mail:\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stefano","family":"Zanero","sequence":"additional","affiliation":[{"name":"Politecnico di Milano, Italy. E-mails:\u00a0,\u00a0,\u00a0,\u00a0,\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Federico","family":"Maggi","sequence":"additional","affiliation":[{"name":"Politecnico di Milano, Italy. E-mails:\u00a0,\u00a0,\u00a0,\u00a0,\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2017,2,15]]},"reference":[{"key":"ref001","doi-asserted-by":"crossref","unstructured":"H.\u00a0Binsalleeh, T.\u00a0Ormerod, A.\u00a0Boukhtouta, P.\u00a0Sinha, A.\u00a0Youssef, M.\u00a0Debbabi and L.\u00a0Wang, On the analysis of the Zeus botnet crimeware toolkit, in: Proceedings of the Annual International Conference on Privacy, Security and Trust (PST), 2010.","DOI":"10.1109\/PST.2010.5593240"},{"key":"ref002","unstructured":"Blueliv, Chasing cybercrime: network insights of Dyre and Dridex Trojan bankers, Cyber Threat Intelligence Report, 2015."},{"key":"ref003","unstructured":"J.I.\u00a0Boutin, The evolution of webinjects, ESET, 2014, https:\/\/www.virusbtn.com\/pdf\/conference\/vb2014\/VB2014-Boutin.pdf."},{"key":"ref004","unstructured":"Z.\u00a0Bu, P.\u00a0Bueno, R.\u00a0Kashyap and A.\u00a0Wosotowsky, The new era of botnets, McAfee Labs, 2013."},{"key":"ref005","doi-asserted-by":"crossref","unstructured":"A.\u00a0Buescher, F.\u00a0Leder and T.\u00a0Siebert, Banksafe information stealer detection inside the web browser, in: Proceedings of the International Workshop on Recent Advances in Intrusion Detection (RAID), 2011.","DOI":"10.1007\/978-3-642-23644-0_14"},{"key":"ref006","doi-asserted-by":"crossref","unstructured":"C.\u00a0Criscione, F.\u00a0Bosatelli, S.\u00a0Zanero and F.\u00a0Maggi, Zarathustra: Extracting WebInject signatures from banking trojans, in: Proceedings of the Annual International Conference on Privacy, Security and Trust (PST), 2014.","DOI":"10.1109\/PST.2014.6890933"},{"key":"ref007","unstructured":"S.\u00a0Doherty, P.\u00a0Krysiuk and C.\u00a0Wueest, The State of Financial Trojans 2013, Luettavissa: http:\/\/www.symantec.com\/content\/en\/us\/enterprise\/media\/security_response\/whitepapers\/the_state_of_financial_trojans_2013.pdf, 2013."},{"key":"ref008","unstructured":"S.\u00a0Dyre, Emerging threat on financial fraud landscape, 2015."},{"key":"ref009","unstructured":"N.\u00a0Falliere and E.\u00a0Chien, Zeus: King of the bots, Symantec Security Response, 2009."},{"key":"ref010","doi-asserted-by":"crossref","unstructured":"A.\u00a0Fattori, A.\u00a0Lanzi, D.\u00a0Balzarotti and E.\u00a0Kirda, Hypervisor-based malware protection with AccessMiner, Computers & Security (2015).","DOI":"10.1016\/j.cose.2015.03.007"},{"key":"ref011","unstructured":"M.\u00a0Goncharov, Russian underground 101, Trend Micro Incorporated Research Paper, 2012."},{"key":"ref012","doi-asserted-by":"crossref","unstructured":"C.\u00a0Grier, L.\u00a0Ballard, J.\u00a0Caballero, N.\u00a0Chachra, C.J.\u00a0Dietrich, K.\u00a0Levchenko, P.\u00a0Mavrommatis, D.\u00a0McCoy, A.\u00a0Nappa, A.\u00a0Pitsillidis et al., Manufacturing compromise: The emergence of exploit-as-a-service, in: Proceedings of the ACM Conference on Computer and Communications Security (CCS), 2012.","DOI":"10.1145\/2382196.2382283"},{"key":"ref013","doi-asserted-by":"crossref","unstructured":"M.\u00a0Heiderich, T.\u00a0Frosch and T.\u00a0Holz, Iceshield: Detection and mitigation of malicious websitewith a frozen dom, in: Proceedings of the International Workshop on Recent Advances in Intrusion Detection (RAID), 2011.","DOI":"10.1007\/978-3-642-23644-0_15"},{"key":"ref014","unstructured":"Kaspersky Lab, Financial Cyberattacks Grow by Almost 16% in Q2 2016 as Malware Creators Join Forces, 2016, http:\/\/usa.kaspersky.com\/about-us\/press-center\/press-releases\/2016\/Financialz_Cyberattacks_Grow_by_Almost_16_percent_in_Q2_2016_as_Malware_Creators_Join_Forces."},{"key":"ref015","unstructured":"L.\u00a0Kharouni, Automating Online Banking Fraud, Trend Micro Incorporated, 2012."},{"key":"ref016","doi-asserted-by":"crossref","unstructured":"D.\u00a0Kirat, G.\u00a0Vigna and C.\u00a0Kruegel, BareBox: Efficient malware analysis on bare-metal, in: Proceedings of the Annual Computer Security Applications Conference (ACSAC), 2011.","DOI":"10.1145\/2076732.2076790"},{"key":"ref017","doi-asserted-by":"crossref","unstructured":"A.\u00a0Lanzi, D.\u00a0Balzarotti, C.\u00a0Kruegel, M.\u00a0Christodorescu and E.\u00a0Kirda, Accessminer: Using system-centric models for malware protection, in: Proceedings of the ACM Conference on Computer and Communications Security (CCS), 2010.","DOI":"10.1145\/1866307.1866353"},{"key":"ref018","doi-asserted-by":"crossref","unstructured":"M.\u00a0Lindorfer, A.\u00a0Di Federico, P.\u00a0Milani Comparetti, F.\u00a0Maggi and S.\u00a0Zanero, Lines of malicious code: Insights into the malicious software industry, in: Proceedings of the Annual Computer Security Applications Conference (ACSAC), 2012.","DOI":"10.1145\/2420950.2421001"},{"key":"ref019","unstructured":"McAfee Labs, Threats Report, Technical report, 2016, http:\/\/www.mcafee.com\/us\/resources\/reports\/rp-quarterly-threats-mar-2016.pdf."},{"key":"ref020","unstructured":"T.\u00a0Ormerod, An Analysis of a Botnet Toolkit and a Framework for a Defamation Attack, 2012."},{"key":"ref021","doi-asserted-by":"crossref","unstructured":"A.\u00a0Rahimian, R.\u00a0Ziarati, S.\u00a0Preda and M.\u00a0Debbabi, On the reverse engineering of the citadel botnet, in: Foundations and Practice of Security, 2014.","DOI":"10.1007\/978-3-319-05302-8_25"},{"key":"ref022","doi-asserted-by":"crossref","unstructured":"M.\u00a0Riccardi, R.\u00a0Di Pietro and J.\u00a0Aguila Vila, Taming Zeus by leveraging its own crypto internals, in: eCrime Researchers Summit (eCrime), 2011.","DOI":"10.1109\/eCrime.2011.6151981"},{"key":"ref023","doi-asserted-by":"crossref","unstructured":"M.I.\u00a0Sharif, W.\u00a0Lee, W.\u00a0Cui and A.\u00a0Lanzi, Secure in-vm monitoring using hardware virtualization, in: Proceedings of the ACM Conference on Computer and Communications Security (CCS), 2009.","DOI":"10.1145\/1653662.1653720"},{"key":"ref024","doi-asserted-by":"crossref","unstructured":"A.K.\u00a0Sood, R.J.\u00a0Enbody and R.\u00a0Bansal, Dissecting SpyEye \u2013 Understanding the design of third generation botnets, Computer Networks (2012).","DOI":"10.1016\/j.comnet.2012.06.021"},{"key":"ref025","doi-asserted-by":"crossref","unstructured":"A.\u00a0Srivastava, A.\u00a0Lanzi, J.\u00a0Giffin and D.\u00a0Balzarotti, Operating system interface obfuscation and the revealing of hidden operations, in: Proceedings of the International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA), 2011.","DOI":"10.1007\/978-3-642-22424-9_13"},{"key":"ref026","unstructured":"C.\u00a0Wueest, The State of Financial Trojans 2014, Symantec, 2014."},{"key":"ref027","unstructured":"C.\u00a0Wueest, Financial Threats 2015, Symantec, 2015, http:\/\/www.symantec.com\/content\/en\/us\/enterprise\/media\/security_response\/whitepapers\/financial-threats-2015.pdf."},{"key":"ref028","unstructured":"J.\u00a0Wyke, Vawtrak \u2013 International Crimeware-as-a-Service, Sophos, 2014."},{"key":"ref029","unstructured":"J.\u00a0Wyke, Breaking the bank(er): automated configuration data extraction for banking malware, Sophos, 2015, https:\/\/www.sophos.com\/en-us\/medialibrary\/PDFs\/technical%20papers\/sophos-wyke-breaking-the-bank-VB2015.pdf."}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-15773","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/JCS-15773","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-15773","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:45:02Z","timestamp":1777495502000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JCS-15773"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,2,15]]},"references-count":29,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2017,5,2]]}},"alternative-id":["10.3233\/JCS-15773"],"URL":"https:\/\/doi.org\/10.3233\/jcs-15773","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,2,15]]}}}