Showing posts with label Angler Exploit Kit. Show all posts
Showing posts with label Angler Exploit Kit. Show all posts

Tuesday, January 19, 2016

Music-themed Malvertising Lead to Angler

Overview

Malvertising, or "malicious advertising," is not a new threat, and just a few weeks into 2016 ThreatLabZ has observed a malvertising campaign injecting iframes into banner advertisements that lead to Angler Exploit Kit. Surprisingly, the Angler operators took some vacation for the New Year, as noted by F-Secure, and have only recently resumed operations, so we were surprised to see a malvertising campaign so soon after their break.

This post will detail aspects of this campaign, and there is a reference list of indicators at the end of this post.

OpenX/OpenAds and Malvertising

OpenAds, now called OpenX or Revive Adserver, is an advertisement platform with a long history and is still quite popular. From a high level, when a user browses to a website using OpenAds for serving advertisements, small code stubs make requests to the OpenAds server, which decides which banner advertisement to run and sends the banner ad plus some tracking code back to the page. The banner advertisements usually rotate on some interval, and a single ad server can serve and control advertisements for multiple domains.

Unfortuantely, the nature of banner advertisements makes them highly lucrative for criminal groups since injecting malicious content into an advertisement can impact hundreds or thousands of sites. This particular campaign impacted multiple OpenAds/OpenX servers which affected hundreds of domains. Intermediary sites were used as an additional hop prior to serving the Angler landing page, and only six second-level intermediary domains were observed, each using dozens of different subdomains and URIs. All six second-level intermediary domains share music-themed names:
  • everyoneismusical.com
  • musik4fingersonthemove.com
  • musik4littlefingers.com
  • youaremusical.com
  • youaremusicalforms.com
  • youaremusik.com
Interestingly, these intermediary domains only use two different IPs for all the subdomains, and the operators appear to have changed hosts suddenly. Figure 1 shows the number of hits we captured for these two IPs.

Fig 1: Hits on Intermediary Domain IPs

iframe Trampolining

The infection cycle starts with a malicious iframe injected in the banner advertisement code that references an intermediary URL. The injected iframe loads transparently, and the intermediary domain server will respond in one of the following three ways:
  • Response code 200 - iframe to Angler Exploit Kit landing page
  • Response code 204 - no content
  • Response code 404 - fake 'not found' page
If the intermediary domain serves an iframe, the Angler landing page is loaded transparently. A more complete overview of the infection cycle is shown below in Figure 2.

Fig 2: Overview of Infection Cycle
We're calling the intermediary domain an "iframe trampoline" since the server may not respond with another iframe and can simply bounce the user out of the infection cycle with benign content.

Infection Cycle

Looking at a full infection cycle in Figure 3, the benign domain 'giftsnideas.com' loads a banner ad with OpenX which contains an injected iframe to the trampoline domain. The trampoline domain's iframe finally sends the user to the Angler landing page. In this instance, the exploit failed, so no further content was loaded.

Fig 3: Relevant URLs for Exploit Cycle
Banner advertisement code on OpenAds/OpenX is very similar between servers. Figure 4 shows the injected iframe, which is simply inserted into the legitimate banner advertisement code.
Fig 4: Advertisement with Injected iframe
All trampoline domains used a very similar URL format of two alphabetic directories followed by an alphabetic JavaScript file (.js). The only content loaded in every successful instance is an iframe to the Angler landing page, as shown in Figure 5.
Fig 5: Trampoline Header and Response
The Angler landing page is exactly what you'd expect and although there have been some recent changes, we won't rehash Angler in this post.
Fig 6: Angler Landing Page

Conclusion

Malvertising continues to be a highly effective means of targeting and compromising a large number of victims, and we expect this trend to continue for 2016. We noted that many of the victim sites we observed in this campaign were radio stations and auto enthusiast forums. Domains in these two groups are owned by Saga Communications and Autoforums.com, so it's likely that each uses a small number of ad servers to power the entire network of sites. ThreatLabZ will continue to monitor this campaign.

Indicators


# HitsSecond Level DomainRegistrarRegistrant
23883youaremusik.comGODADDYMark Lippman
20681musik4fingersonthemove.comGODADDYMark Lippman
16878everyoneismusical.comGODADDYMichael Lippman
16849musik4littlefingers.comGODADDYMark Lippman
5698youaremusical.comGODADDYMichael Lippman
1619youaremusicalforms.comGODADDYMichael Lippman

URL IPs

188.227.72.137 - IT-Grad nets - AS48096
188.227.74.150 - IT-Grad nets - AS48096


List of FQDNs and URLs

Counts and FQDNs - via Pastebin (http://pastebin.com/7vSYi2uz)
URLs - via Pastebin (http://pastebin.com/QN9WqzPn)

Whois Samples

Domain Name: MUSIK4LITTLEFINGERS.COM
Registry Domain ID: 1916653940_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.godaddy.com
Registrar URL: http://www.godaddy.com
Update Date: 2015-04-05T16:22:42Z
Creation Date: 2015-04-05T16:22:42Z
Registrar Registration Expiration Date: 2018-04-05T16:22:42Z
Registrant Name: Mark Lippman
Registrant Organization:
Registrant Street: 4 Cloverbrooke Court
Registrant City: Potomic
Registrant State/Province: Maryland
Registrant Postal Code: 20854
Registrant Country: US
Registrant Phone: +1.2404294083
Registrant Phone Ext:
Registrant Fax: +1.1
Registrant Fax Ext:
Registrant Email: mhlippman@gmail.com
Registry Admin ID:
Admin Name: Mark Lippman
Admin Organization:
Admin Street: 4 Cloverbrooke Court
Admin City: Potomic
Admin State/Province: Maryland
Admin Postal Code: 20854
Admin Country: US
Admin Phone: +1.2404294083
Admin Phone Ext:
Admin Fax: +1.1
Admin Fax Ext:
Admin Email: mhlippman@gmail.com
Registry Tech ID:
Tech Name: Mark Lippman
Tech Organization:
Tech Street: 4 Cloverbrooke Court
Tech City: Potomic
Tech State/Province: Maryland
Tech Postal Code: 20854
Tech Country: US
Tech Phone: +1.2404294083
Tech Phone Ext:
Tech Fax: +1.1
Tech Fax Ext:
Tech Email: mhlippman@gmail.com
Name Server: NS67.DOMAINCONTROL.COM
Name Server: NS68.DOMAINCONTROL.COM

Domain Name: EVERYONEISMUSICAL.COM
Registry Domain ID: 1917710979_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.godaddy.com
Registrar URL: http://www.godaddy.com
Update Date: 2015-06-04T12:18:00Z
Creation Date: 2015-04-08T19:34:50Z
Registrar Registration Expiration Date: 2018-04-05T11:59:59Z
Registrar: GoDaddy.com, LLC
Registrar IANA ID: 146
Registrar Abuse Contact Email: abuse@godaddy.com
Registrar Abuse Contact Phone: +1.4806242505
Domain Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited
Domain Status: clientUpdateProhibited http://www.icann.org/epp#clientUpdateProhibited
Domain Status: clientRenewProhibited http://www.icann.org/epp#clientRenewProhibited
Domain Status: clientDeleteProhibited http://www.icann.org/epp#clientDeleteProhibited
Registry Registrant ID: 
Registrant Name: Michael Lippman
Registrant Organization: 
Registrant Street: 4 Cloverbrooke Court
Registrant City: Potomic
Registrant State/Province: Maryland
Registrant Postal Code: 20854
Registrant Country: US
Registrant Phone: +1.2404298083
Registrant Phone Ext:
Registrant Fax: 
Registrant Fax Ext:
Registrant Email: mhlippman@gmail.com
Registry Admin ID: 
Admin Name: Michael Lippman
Admin Organization: 
Admin Street: 4 Cloverbrooke Court
Admin City: Potomic
Admin State/Province: Maryland
Admin Postal Code: 20854
Admin Country: US
Admin Phone: +1.2404298083
Admin Phone Ext:
Admin Fax: 
Admin Fax Ext:
Admin Email: mhlippman@gmail.com
Registry Tech ID: 
Tech Name: Michael Lippman
Tech Organization: 
Tech Street: 4 Cloverbrooke Court
Tech City: Potomic
Tech State/Province: Maryland
Tech Postal Code: 20854
Tech Country: US
Tech Phone: +1.2404298083
Tech Phone Ext:
Tech Fax: 
Tech Fax Ext:
Tech Email: mhlippman@gmail.com
Name Server: NS37.DOMAINCONTROL.COM
Name Server: NS38.DOMAINCONTROL.COM



Tuesday, November 3, 2015

Chinese Government Website Compromised, Leads to Angler

Introduction

Despite a recent takedown targeting the Angler Exploit Kit (EK), it's back to business as usual for kit operators. On 30-October-2015, ThreatLabZ noticed a compromised Chinese government website that led to the Angler Exploit Kit with an end payload of Cryptowall 3.0. This compromise does not appear targeted and the compromised site was cleaned up within 24 hours. We have noticed some recent changes to Angler, as well as the inclusion of newer Flash exploits. A set of indicators for this compromise is at the end of this post.

Compromised Site

The "Chuxiong Archives" website, www.cxda[.]gov.cn, was compromised with injected code. The site has a similar look and feel to both the Chuxiong Yi Prefecture and Chuxiong City websites and appears somewhat inactive, but surprisingly the site was remediated in less than 24 hours. The full infection cycle from compromised site to encrypted payload is shown in the fiddler session below.

Fig 1. Infection cycle
The injected code was before the opening HTML tag and was heavily obfuscated. The code, shown below, is very similar to other recent compromises we've observed and was present on every page of the site, suggesting a complete site compromise.

Fig 2. Injected script
Consistent with other recent examples, the injected code appears to target Internet Explorer (IE) since Firefox and Chrome consistently throw errors when attempting to execute the code and no redirection occurs. IE has no issues executing the code, however, which unsurprisingly decodes to an iframe leading to an Angler EK landing page:

Fig 3. Decoded injected code
While we did not have access to the server-side code, it likely retrieves landing page URLs from a remote server since we observed iframes leading to multiple different Angler domains within a brief period of time.

Landing Page

The landing page for Angler is immediately recognizable, but with some notable recent changes. For example, instead of using a long block of around seven-character long strings inside divs tag, the newer landing pages use 'li' tags and most of the strings are only about two characters long. Additionally, there's a conspicuous 'triggerApi' function toward the top of the main script block:

Fig 4: Short strings and triggerApi function
Outside of these changes, the functionality of the landing page appears unchanged, and the goal is naturally to serve up a malicious SWF:

Fig 5. Decoded landing page SWF objects

Malicious SWF - CVE-2015-7645

Kafeine already broke the news that Angler is exploiting Flash 19.0.0.207, and we can corroborate that with the samples we've observed.
Fig 6. Flash 19.0.0.207 being exploited
In fact, we compared the sample from his recent post with one obtained from this infection and the structure is identical, with very few changes in the actionscript. The biggest change we saw was in the embedded binary data.

Fig 7. SWF structure, 30-Oct sample on the left, Kafeine's sample on the right

Fig 8. Comparison of binary data, 30-Oct sample on the left, Kafeine's sample on the right
Upon successful exploit cycle, a new CryptoWall 3.0 variant from the crypt13 campaign is downloaded and installed on the target machine. The image below shows a decrypted Command & Control (C&C) communication message from the CryptoWall variant which also contains the total number of files encrypted on the target system:

Fig 9. CryptoWall 3.0 C&C message reporting encrypted file count

Final Thoughts

As stated, this seems to be business as usual for Angler EK operators. While these attacks were not targeted in nature, this is the first instance where we saw EK operators leveraging a government site to target end users. One interesting observation is that we no longer see any Diffie-Helman POST exchange to prevent replaying captured sessions for offline analysis. Additionally, there was a much larger number of C&C servers than we've previously observed, and some of the domain names seem to suggest multi-use hosts (e.g.: spam, bitcoin mining, etc). Note that none of the C&C servers are pseudo-randomly generated domains. ThreatLabZ will continue to track new developments with the Angler Exploit Kit.

Indicators of Compromise


Domain IP Address Description
cxda.gov[.]cn118.123.7.122Chinese government site
erteilend-taendelt.sewnydine[.]com104.129.192.32Angler Domain
repersuasionboldoblique.classactoutlet[.]com104.129.192.32Angler Domain
ayh2m57ruxjtwyd5.stopmigrationss[.]com95.128.181.195Payment Server
ayh2m57ruxjtwyd5.starswarsspecs[.]comfailedPayment Server
ayh2m57ruxjtwyd5.malerstoniska[.]com109.70.26.37,194.85.61.76Payment Server
ayh2m57ruxjtwyd5.blindpayallfor[.]com95.128.181.195Payment Server
flat.splo1t[.]ru188.127.239.164C&C connections
sanliurfapastanesi[.]com95.173.190.210C&C connections
wesalerx[.]xyz46.148.18.100C&C connections
urfakaplanticaret[.]com95.173.190.210C&C connections
taigastyle[.]ru37.140.192.180C&C connections
flickstudio[.]com103.21.59.22C&C connections
mydaycarewebsite[.]com104.24.102.98,104.24.103.98C&C connections
sampiyonvitamin[.]com95.173.190.210C&C connections
xmest.web-zolotareva[.]ru82.146.36.185C&C connections
aandwrentalspm[.]com142.4.6.13C&C connections
orucogluelektronik[.]com95.173.190.210C&C connections
gaja24[.]pl91.234.146.241C&C connections
developmysuccess[.]com50.30.46.201C&C connections
20dollarhomebusiness[.]com50.30.46.201C&C connections
rizvanogluhafriyat[.]com95.173.190.210C&C connections
sanliurfapastanesi[.]com95.173.190.210C&C connections
newatena[.]com95.173.190.210C&C connections
stalkerbanget[.]com68.65.120.182C&C connections
primevisionstudio[.]com192.185.206.97C&C connections
i-tem[.]ru62.173.143.242C&C connections
localuzzweb[.]com143.95.32.179C&C connections
getpostivemind[.]com158.85.170.253C&C connections
zemli72.chaukakau[.]ru62.173.143.242C&C connections
grandmedianetwork[.]com111.118.215.77C&C connections
karakoprudugunsalonu[.]com95.173.190.210C&C connections
sanliurfaparke[.]com95.173.190.210C&C connections
nsdstudio[.]net192.185.206.97C&C connections
meble-simone[.]eu91.234.146.241C&C connections
vsedveri33[.]ru81.177.165.33C&C connections
osk-wojcikiewicz[.]pl91.234.146.241C&C connections
love-deep[.]com111.118.215.77C&C connections
turizmkirov[.]ru82.146.36.185C&C connections
new.turizmkirov[.]ru82.146.36.185C&C connections
avtoreliv[.]com.ua91.234.34.80C&C connections
localwebsitepro[.]com192.185.41.191C&C connections
makrol[.]net91.234.146.241C&C connections
altopics[.]com111.118.215.77C&C connections
burnfatquicky[.]com184.168.221.57C&C connections
mediaopt33[.]ru81.177.165.33C&C connections
otmanad[.]com91.234.146.241C&C connections
markossolomon[.]com104.27.181.171,104.27.180.171C&C connections
kominki-gorlice[.]pl91.234.146.241C&C connections
chaukakau[.]ru62.173.143.242C&C connections
crm.ruhtech[.]com202.160.165.21C&C connections
takas3aya.xsrv[.]jp183.90.232.25C&C connections
famouswhiskybrands[.]com103.21.59.21C&C connections
edwardbrownjr[.]com50.30.46.201C&C connections
avatar77[.]ru62.173.143.242C&C connections
bollywoodupdate[.]net95.173.190.210C&C connections
asiaroyaldeveloper[.]com103.21.59.22C&C connections
asattyres[.]com192.185.206.97C&C connections
records.karika[.]in.ua91.234.34.80C&C connections
ppcprofitz[.]com143.95.32.180C&C connections
ecodeva[.]ru62.173.143.242C&C connections
btcdoubler[.]bizfailedC&C connections
18dollars1time[.]info50.30.46.201C&C connections
urfaeleganceoptik[.]com95.173.190.210C&C connections

Sunday, July 5, 2015

A look at recent Tinba Banking Trojan variant

Introduction 

Tinba is information stealing Trojan. The main purpose of the malware is to steal information that could be browsing data, login credentials, or even banking information. This is achieved through code injection into system process (Winver.exe and Explorer.exe) and installing hooks into various browsers like IExplorer, Chrome, Firefox and Opera.

Tinba has been known to arrive via spammed e-mail attachments and drive-by downloads.  Recently, Angler Exploit Kit instances were also found to be serving Tinba banking Trojan as seen here.

Detailed Analysis of Tinba

Tinba is packed with a custom packer and uses well known anti-debugging technique using the WinAPI function “IsDebuggerPresent” to hinder reverse engineering of the binary image. The execution flow of the infection cycle for Tinba is shown below.
Execution flow of Tinba

The image below shows the custom packer code being used by the Tinba sample we were looking at.


Tinba unpacking Routine
The unpacked binary image is shown below which upon execution will perform code injection into system processes like Winver.exe and Explorer.exe.


Unpacked Binary
It generates Mutex name using root volume information of the victim’s machine as shown below.

Mutex name generation
Remote Thread in System Process
 
A remote thread is created inside Explorer process that is responsible for creating a copy of Tinba Binary in %APPDATA% & auto start registry entry in Registry hive.


Explorer remote thread
The Tinba binary is stored in a hidden folder which is created under %APPDATA% directory:


 C:\Documents and setting \username \Application Data\mutexname\bin.exe
It also creates an auto-run registry entry to execute Tinba binary during every windows start-up as shown below:


Auto start registry entry

Another thread is also created in Explorer process which is responsible for generating DGA (Domain Generation Algorithm) domains and injecting code into browsers like IExplorer, Chrome, Firefox and Opera.

Explorer local thread
Domain Generation Algorithm

The following is the Domain Generation Algorithm (DGA) used by Tinba variant where every sample uses a hardcoded domain and seed to generate the DGA domains.

DGA routine

Hardcoded Domain and seed
These DGA domains are fast flux domains where single domain is frequently switched to different IPs by registering it as part of the DNS A record list for a single domain.


targetHost
targetIP
eudvwwwrmyqi.in
89.111.166.60
eudvwwwrmyqi.in
95.163.121.94
jrhijuuwgopx.com
176.31.62.78
jrhijuuwgopx.com
176.31.62.77
norubjjpsvfg.ru
210.1.226.15
norubjjpsvfg.ru
104.223.122.20
norubjjpsvfg.ru
104.223.15.16
scpxsbsjjqje.ru
5.178.64.90
scpxsbsjjqje.ru
192.198.90.228
scpxsbsjjqje.ru
5.178.64.90
wgwnmffclqvu.ru
192.198.90.228
wgwnmffclqvu.ru
192.3.95.140


Remote Thread in browsers

The Explorer thread searches for browser process either by checking path of the browser executable or by loaded application specific DLL (e.g. NSS3.dll for firefox.exe). If the targeted browser process is found, then the secondary thread is created in the process.

Browser thread
This thread is responsible to get updated Bot configuration details like Target URL list and strings (BOTUID ) from a remote C&C server. If there is no updated list of target URLs from C&C server, then it uses default targeted list of URLs which is stored in the injected code. The list of default target URLs after decryption is shown below.

Default Targeted URL list
The collected information form webmail, social media and the banking sites are stored in "log.dat" file.

Log file path
C&C communication & Cryptography:
 
The POST request to C&C server contains encrypted system information like system volume & version information.  The cryptography routine is a simple byte 'XOR' with an 8 bit 'ROR' of the key after each write. 

Send Data Encryption

A sample Tinba POST request to DGA domains with 157 bytes of encrypted data is shown below.


C&C POST Request
Geo distribution of C&C call back attempts that we blocked in past one month:

Geo Location
We have seen following C&C server IP addresses:
Conclusion:
     Tinba also known as small banking Trojan continues to be prevalent in the wild.  The arrival method varies from e-mail spam, drive-by downloads and most recently Exploit Kit infection cycle. Zscaler ThreatlabZ is actively monitoring this malware family and ensuring coverage for our customers.

Friday, April 3, 2015

Angler Exploit Kit Utilizing 302 Cushioning and Domain Shadowing

Overview
Angler Exploit Kit is one of the most prevalent and advanced exploit kits in use today and is continually evolving. Angler continues to utilize malvertising to push landing pages and malicious actors are still registering domains solely for serving exploits, but recently, we've noticed an increase in two new infection vectors - 302 Cushioning and Domain Shadowing.

302 Cushioning, or a 'cushion attack', is used to redirect victims to malicious sites without the use of more traditional techniques, such as hidden iframes or external 'script src' tags. The attackers are using HTTP 302 redirects over iframes here to evade detection by traditional signature-based IDS/IPS engines. This technique is not new and was discussed back in 2013Domain shadowing, a term coined by Cisco, involves compromising the parent domain and creating multiple sub-domains that point to malicious code. This means that in the majority of cases, a victim's hosting account credentials are compromised. These sub-domains can be created and deleted quickly, making this an attractive technique for bypassing domain and URL blocklists.

These developments are notable since they show an evolving approach to exploit delivery. Angler has long used obfuscation and encryption on landing pages and payloads Combined with cushioning and domain shadowing, Angler adds yet another layer of stealth for defenders to counter.

Exploit Cycles
The exploit cycle typically starts with compromised websites followed by a 302 Cushioning attack & Domain Shadowing leading to an Exploit Kit hosting site as seen below:
Fig 1: Exploit cycle seen during these attacks
Direct exploitation, as shown below, happens immediately when accessing the compromised site.

Fig 2: Wireshark showing direct path to exploit
The full cycle from victim site to successful exploitation is shown in the annotated Fiddler screenshot below.

Fig 3: Full sample exploit cycle
Session 2 (above) corresponds to the initial 302 cushion upon accessing the victim site (detailed in Fig 2). Session 3 contains a small block of code (Fig 4 below) to initiate session 4. Session 4 302's to the actual Angler landing page in session 5.

Fig 4: Initiate session 4 via top.location.replace
Note that the sub-domain changes between sessions 4 and 5:

Fig 5: Sub-domain change for landing page
Indirect exploitation is similar to the direct exploitation method described above, but occurs after a domain is accessed that utilizes remotely hosted content. Once the content is accessed, there is a similar 302 cushion to the exploit domain.

Fig 6: 302 cushion from intermediary domain


Fig 7: Domain graph showing indirect exploitation
Landing Page Analysis
The landing page for Angler is typical, with a substantial amount of randomized code and whitespace, but scrolling to the bottom reveals that there are multiple strings delimited with '3~4' and the split function is declared toward the top of the page.

Fig 8: Split function for 3~4

Fig 9: Delimited string simply uses fromCharCode
This is followed by an 'eval' of the variable 'kzfzSU' which contains the deobfuscated code:

Fig 10: eval(deobfuscated code)
Taking a look at the deobfuscated code, there are several structures that are consistent with well-known exploits being served, including functions for 'flash_run' and 'GetSLV':

Fig 11: IE11 - CVE-2014-4130 
Fig 12: flash_run - Flash CVE-2015-0336

Fig 13: GetSLV - Silverlight CVE-2013-0074

Fig 14: IE 10 - CVE-2013-2551
The majority of this is standard and has been documented by many researchers. Kafeine has done an excellent job chronicling Angler and other exploit kits and additional information on the landing page exploits can be found on his pastebin.

Exploits & Payload
The exploit we examined was Flash exploit CVE-2015-0336. One interesting point is that the SWF file was LZMA compressed, which appears to be an attempt to evade detection.

Fig 15: LZMA compressed SWF exploit payload
The SWF takes a parameter, which is an encrypted URL pointing to the location of the binary payload that is executed upon successful exploitation. The binary payload is also encrypted:

Fig 16: Encrypted malware payload

VirusTotal detection on the SWF was very poor with only 1/56 vendors alerting at time of upload.



The malware payload dropped at the end of a successful exploit cycle belongs to the Carberp Banking Trojan family. The Carberp Trojan family is known for stealing online banking credentials as well as user credentials for a variety of applications. It is also capable of downloading additional malware on the victim machine. It's important to note that the payload is downloaded in an encrypted form and decrypted in memory on the victim machine before being executed by the SWF exploit payload.

The malware binary has better detection coverage with 31/57 AV engines presently providing detection.


Conclusion
A 302 Cushioning attack combined with a Domain Shadowing technique is clearly aimed to exploit the current enterprise security posture which still relies heavily on URL categorization and Domain based blocking. With the growing threat landscape, enterprises have started to adopt multiple security solutions to guard their perimeter; however, it is still common for these enterprises to leverage URL categorization to further decide on which traffic goes through some of the more advanced layers of security inspection. Domain Shadowing techniques will cause these attacks to slip through such security policies.

It will not be surprising to see an increase in the usage of these techniques by the cyber-criminals in future attack campaigns. We at ThreatLabZ are closely monitoring this attack vector and ensuring protection for the Zscaler customers.

Thank you to Peleus Uhley from Adobe's PSIRT for quick response in confirming the SWF exploit.

IOC List
We've created a couple pastes with a subset of the primary and full domains we've observed.

Full domains (including subdomain)
Primary domains only

Note that many of these domains are detectable with simple regex searches. Also note that the URI includes base64-encoded data about the referrer, among other datapoints. Decoded examples:
  • myfineiu=qsphhyzxgn&time=15032408472520608466&src=63&surl=js.sonoo.info&sport=80&key=700EE759&suri=/
  • vocvokxj=gwttjva&time=15032408474283214620&src=76&surl=myfilestore.com&sport=80&key=A6D9DE16&suri=/download.php%3fid=c01aa495
  • js=1&ankheji=pj&time=15032408324140253339&src=205&surl=www.fiercebook.com&sport=80&key=E3907BB8&suri=/js/msdropdown/jquery.dd.min.js
  • gshspa=lnrsclzpan&time=15032408322451558688&src=77&surl=www.einkaufscenter-in-deutschland.de&sport=80&key=9A9DC80&suri=/index.php
  • sxlzlq=dwhi&time=1503240817829836824&src=33&surl=www.thailandsusu.com&sport=80&key=521A223A&suri=/webboard/index.php%3faction=dlattach%3battach=175685%3btype=avatar
  • neygvev=ii&time=15032407471753639860&src=76&surl=url4short.info&sport=80&key=50B3117&suri=/1503e6bd
  • yrwzim=hzflgicmos&time=15032407022641179106&src=76&surl=myfilestore.com&sport=80&key=ADE2C3CF&suri=/download.php%3fid=728768e6
  • yrwzim=hzflgicmos&time=15032407022641179106&src=76&surl=myfilestore.com&sport=80&key=70625872&suri=/download.php%3fid=728768e6
  • wxzyhrcf=gmejggpbvw&time=15032406171268943104&src=76&surl=filestore72.info&sport=80&key=7377ADCF&suri=/download.php%3fid=79ad4669
  • gptpil=yjostm&time=15032406023680222021&src=76&surl=filestore72.info&sport=80&key=A52D850E&suri=/download.php%3fid=faa55a6b
  • js=1&gumsczeo=gpgqfxln&time=15032406022626420737&src=128&surl=www.pho-thong.com&sport=81&key=949218C1&suri=/include/jquery.js
  • sulylnp=ceilsubfx&time=15032405321533647318&src=136&surl=kodseries.com&sport=80&key=6425E43B&suri=/title-00215

Links to VT sample pages:
289ac177212625026b679c4b73849e00 - SWF
340e19aea447bee696453b9c4bd9f65c - Carberp