Showing posts with label Adobe Flash vulnerability. Show all posts
Showing posts with label Adobe Flash vulnerability. Show all posts

Tuesday, November 3, 2015

Chinese Government Website Compromised, Leads to Angler

Introduction

Despite a recent takedown targeting the Angler Exploit Kit (EK), it's back to business as usual for kit operators. On 30-October-2015, ThreatLabZ noticed a compromised Chinese government website that led to the Angler Exploit Kit with an end payload of Cryptowall 3.0. This compromise does not appear targeted and the compromised site was cleaned up within 24 hours. We have noticed some recent changes to Angler, as well as the inclusion of newer Flash exploits. A set of indicators for this compromise is at the end of this post.

Compromised Site

The "Chuxiong Archives" website, www.cxda[.]gov.cn, was compromised with injected code. The site has a similar look and feel to both the Chuxiong Yi Prefecture and Chuxiong City websites and appears somewhat inactive, but surprisingly the site was remediated in less than 24 hours. The full infection cycle from compromised site to encrypted payload is shown in the fiddler session below.

Fig 1. Infection cycle
The injected code was before the opening HTML tag and was heavily obfuscated. The code, shown below, is very similar to other recent compromises we've observed and was present on every page of the site, suggesting a complete site compromise.

Fig 2. Injected script
Consistent with other recent examples, the injected code appears to target Internet Explorer (IE) since Firefox and Chrome consistently throw errors when attempting to execute the code and no redirection occurs. IE has no issues executing the code, however, which unsurprisingly decodes to an iframe leading to an Angler EK landing page:

Fig 3. Decoded injected code
While we did not have access to the server-side code, it likely retrieves landing page URLs from a remote server since we observed iframes leading to multiple different Angler domains within a brief period of time.

Landing Page

The landing page for Angler is immediately recognizable, but with some notable recent changes. For example, instead of using a long block of around seven-character long strings inside divs tag, the newer landing pages use 'li' tags and most of the strings are only about two characters long. Additionally, there's a conspicuous 'triggerApi' function toward the top of the main script block:

Fig 4: Short strings and triggerApi function
Outside of these changes, the functionality of the landing page appears unchanged, and the goal is naturally to serve up a malicious SWF:

Fig 5. Decoded landing page SWF objects

Malicious SWF - CVE-2015-7645

Kafeine already broke the news that Angler is exploiting Flash 19.0.0.207, and we can corroborate that with the samples we've observed.
Fig 6. Flash 19.0.0.207 being exploited
In fact, we compared the sample from his recent post with one obtained from this infection and the structure is identical, with very few changes in the actionscript. The biggest change we saw was in the embedded binary data.

Fig 7. SWF structure, 30-Oct sample on the left, Kafeine's sample on the right

Fig 8. Comparison of binary data, 30-Oct sample on the left, Kafeine's sample on the right
Upon successful exploit cycle, a new CryptoWall 3.0 variant from the crypt13 campaign is downloaded and installed on the target machine. The image below shows a decrypted Command & Control (C&C) communication message from the CryptoWall variant which also contains the total number of files encrypted on the target system:

Fig 9. CryptoWall 3.0 C&C message reporting encrypted file count

Final Thoughts

As stated, this seems to be business as usual for Angler EK operators. While these attacks were not targeted in nature, this is the first instance where we saw EK operators leveraging a government site to target end users. One interesting observation is that we no longer see any Diffie-Helman POST exchange to prevent replaying captured sessions for offline analysis. Additionally, there was a much larger number of C&C servers than we've previously observed, and some of the domain names seem to suggest multi-use hosts (e.g.: spam, bitcoin mining, etc). Note that none of the C&C servers are pseudo-randomly generated domains. ThreatLabZ will continue to track new developments with the Angler Exploit Kit.

Indicators of Compromise


Domain IP Address Description
cxda.gov[.]cn118.123.7.122Chinese government site
erteilend-taendelt.sewnydine[.]com104.129.192.32Angler Domain
repersuasionboldoblique.classactoutlet[.]com104.129.192.32Angler Domain
ayh2m57ruxjtwyd5.stopmigrationss[.]com95.128.181.195Payment Server
ayh2m57ruxjtwyd5.starswarsspecs[.]comfailedPayment Server
ayh2m57ruxjtwyd5.malerstoniska[.]com109.70.26.37,194.85.61.76Payment Server
ayh2m57ruxjtwyd5.blindpayallfor[.]com95.128.181.195Payment Server
flat.splo1t[.]ru188.127.239.164C&C connections
sanliurfapastanesi[.]com95.173.190.210C&C connections
wesalerx[.]xyz46.148.18.100C&C connections
urfakaplanticaret[.]com95.173.190.210C&C connections
taigastyle[.]ru37.140.192.180C&C connections
flickstudio[.]com103.21.59.22C&C connections
mydaycarewebsite[.]com104.24.102.98,104.24.103.98C&C connections
sampiyonvitamin[.]com95.173.190.210C&C connections
xmest.web-zolotareva[.]ru82.146.36.185C&C connections
aandwrentalspm[.]com142.4.6.13C&C connections
orucogluelektronik[.]com95.173.190.210C&C connections
gaja24[.]pl91.234.146.241C&C connections
developmysuccess[.]com50.30.46.201C&C connections
20dollarhomebusiness[.]com50.30.46.201C&C connections
rizvanogluhafriyat[.]com95.173.190.210C&C connections
sanliurfapastanesi[.]com95.173.190.210C&C connections
newatena[.]com95.173.190.210C&C connections
stalkerbanget[.]com68.65.120.182C&C connections
primevisionstudio[.]com192.185.206.97C&C connections
i-tem[.]ru62.173.143.242C&C connections
localuzzweb[.]com143.95.32.179C&C connections
getpostivemind[.]com158.85.170.253C&C connections
zemli72.chaukakau[.]ru62.173.143.242C&C connections
grandmedianetwork[.]com111.118.215.77C&C connections
karakoprudugunsalonu[.]com95.173.190.210C&C connections
sanliurfaparke[.]com95.173.190.210C&C connections
nsdstudio[.]net192.185.206.97C&C connections
meble-simone[.]eu91.234.146.241C&C connections
vsedveri33[.]ru81.177.165.33C&C connections
osk-wojcikiewicz[.]pl91.234.146.241C&C connections
love-deep[.]com111.118.215.77C&C connections
turizmkirov[.]ru82.146.36.185C&C connections
new.turizmkirov[.]ru82.146.36.185C&C connections
avtoreliv[.]com.ua91.234.34.80C&C connections
localwebsitepro[.]com192.185.41.191C&C connections
makrol[.]net91.234.146.241C&C connections
altopics[.]com111.118.215.77C&C connections
burnfatquicky[.]com184.168.221.57C&C connections
mediaopt33[.]ru81.177.165.33C&C connections
otmanad[.]com91.234.146.241C&C connections
markossolomon[.]com104.27.181.171,104.27.180.171C&C connections
kominki-gorlice[.]pl91.234.146.241C&C connections
chaukakau[.]ru62.173.143.242C&C connections
crm.ruhtech[.]com202.160.165.21C&C connections
takas3aya.xsrv[.]jp183.90.232.25C&C connections
famouswhiskybrands[.]com103.21.59.21C&C connections
edwardbrownjr[.]com50.30.46.201C&C connections
avatar77[.]ru62.173.143.242C&C connections
bollywoodupdate[.]net95.173.190.210C&C connections
asiaroyaldeveloper[.]com103.21.59.22C&C connections
asattyres[.]com192.185.206.97C&C connections
records.karika[.]in.ua91.234.34.80C&C connections
ppcprofitz[.]com143.95.32.180C&C connections
ecodeva[.]ru62.173.143.242C&C connections
btcdoubler[.]bizfailedC&C connections
18dollars1time[.]info50.30.46.201C&C connections
urfaeleganceoptik[.]com95.173.190.210C&C connections

Monday, July 13, 2015

Adobe Flash Vulnerability CVE-2015-5119 analysis


With the leak of Hacking Team's data, the security industry came to learn about multiple new 0day vulnerabilities targeting Flash, Internet Explorer, Android, etc. As always, exploit kit authors were quick to incorporate these 0day exploits into their arsenal.

In this blog, we will be looking at the CVE-2015-5119 exploit payload that we have now seen in the wild. The sample has multiple layers of obfuscation and packer routines. The malicious Flash payload is packed, XOR'ed and stored as a binary data inside a parent Flash file that dynamically unpacks a malicious Flash file and writes it to memory at run time.

Here is the structure of the CVE-2015-5119 exploit payload:


Packages, properties and method names are stored in variables for obfuscation:


Here we observe the calling of the unpack routine to decrypt the embedded SWF exploit payload:


An XOR key is used for unpacking and is hardcoded and assigned to the variable vari_10. This is what the unpacked content looks like:



Upon decompilation, it is apparent that majority of the codebase, including variable names and function names are the same as what we saw in the leaked source by the Hacking Team. The public exploit also has checks for:
  • Presence of a debugger
  • Operating System bitness (32-bit or 64-bit)


When the program execution starts, the ActionScript looks for the input parameters and based on it, sets a variable which is then sent to the main exploitation routine as seen below:


The TryExpl() routine allocates sequential pages of memory and begins the exploit cycle:



The vulnerability lies in making use of the valueOf property and corrupting the vector space so that the valueOf  property will overwrite the length field of the vector object, which will be further used to get access to vtables.

Here is explicit definition of valueOf function


prototype.valueOf() is setting up the length of the ByteArray to 4352

Once the memory allocation is done, a MyClass object is created and assigned to _ba[3]. The
valueOf()  function defines the length of ByteArray to 4352, which is greater than the length of the object created, causing reallocation of bytes inside the memory.



If the value of _ba[3] is set to zero after the assignment then it was successful in triggering a Use After Free vulnerability. The exploit code looks for the kernel32.VirtualProtect() (VP) function in the corrupted vector space as seen below:


A call to the VP function is made, which replaces the vtable pointer and sets the PAGE_EXECUTE_READWRITE permission before executing the final payload.



Hashes of  CVE-2015-5119 exploit payloads seen in the wild:




  • 061c086a4da72ecaf5475c862f178f9d
  • 079a440bee0f86d8a59ebc5c4b523a07
  • 16ac6fc55ab027f64d50da928fea49ec
  • 313cf1faaded7bbb406ea732c34217f4
  • 6d14ba5c9719624825fd34fe5c7b4297


  • Conclusion

    It will be a challenge for security vendors to get container file detection in place as majority of the time, the embedded content is highly obfuscated with multiple levels of packing. Adobe has already released a patch to fix this issue. We highly recommend enabling the Adobe's auto update feature to keep the relevant plugins updated.

    References: