Showing posts with label Bedep. Show all posts
Showing posts with label Bedep. Show all posts

Tuesday, April 21, 2015

Malvertising, Exploit Kits, ClickFraud & Ransomware: A thriving underground economy


Malvertising
Malvertising involves using malicious online advertisements as a means to serve malware payloads to unsuspecting users. Cybercriminals leverage compromised advertising networks to serve malicious advertisements on legitimate websites which subsequently infect the visitors. This has become one of the most successful vectors of malware delivery for cybercriminals. Malvertising campaigns in most cases will involve a malicious advertisement redirecting the user to an Exploit Kit (EK) landing page.

Exploit Kits
Exploit Kits are web-based frameworks that attempt to exploit browser application plugins for known vulnerabilities. Upon successful exploitation, the EK will silently download and install a malware payload on the victim machine. The entire exploit cycle is completely hidden from the end user.

The Exploit Kit infection cycle typically moves through three distinct stages:

Stage 1 - Loading stage: This stage involves the initial delivery mechanism which causes the user to visit a compromised website or advertisement. This compromised website then leads the user to the actual Exploit Kit landing page which may involve a series of web redirects.

The initial delivery vector can be any of the following:
  • Spam & phishing e-mail
  • Social Networking sites
  • SEO poisoning
  • Compromised website
  • Malvertising on legitimate sites
It is important to note that malvertising is one of the most dangerous and extremely successful initial delivery mechanism here as even the most cautious user is susceptible to this attack while visiting a perfectly legitimate website. In most other cases, a well informed user can avoid the attack by carefully inspecting the link in an e-mail or search results.

Stage 2 - Landing Stage: During this stage, the victim machine visits the actual EK hosting site and the exploit cycle is started. The EK code will attempt to exploit the identified vulnerable plugins by downloading the relevant exploit payloads.

Upon successful exploitation, the EK will lead to the download of the malware payload as configured by the EK operator. The entire exploit cycle may not require any user intervention in most cases, which greatly increases the success rates.

Stage 3 - Malware Payload Delivery: This is the final stage of the Exlpoit Kit infection cycle where the malware executable is downloaded and installed on the victim machine. This is usually achieved, after successful exploitation, by one of the EK payloads that was served during the landing stage.

The EK operators strive to ensure that the EK code, exploit payloads and the end malware payloads have very low to zero antivirus detection. Over the past few years, EK authors have implemented multiple new features to improve the effectiveness & infection success rates:
  • Anti-VM and Anti-Analysis features
  • Detection of known antivirus drivers
  • Multiple levels of highly obfuscated JavaScript code
  • Dynamic construction of exploit payload URLs only when a vulnerable plugin is found
  • Short lived exploit payload URLs often restricted to one visit per IP address
  • Obfuscated and repackaged exploit payloads
  • Repackaged malware payloads
Recent Malvertising & EK campaigns
After last year’s infamous “Kyle & Stan” malvertising campaign that affected Google, Yahoo, YouTube and multiple other popular websites, this year has been no different. We have seen a malvertising campaign leading to a zero day Flash Exploit payload via the Angler EK to start of the year, followed by a Malvertising campaign targeting European Transit users. There have been numerous other instances of Malvertising which involved popular sites like huffingtonpost.com, yahoo.com, zillow.com and we only expect this trend to continue throughout the year.

Malvertising attempts blocked [Last 7 days]
Users targeted globally by Malvertising [Last 7 days]

Advanced techniques to evade detection
We have also noticed some new techniques being introduced in the Malvertising & EK exploit chain this year to further evade detection by URL reputation & network scanners:
  • 302 cushioning, or a 'cushion attack', is used to redirect victims to malicious sites via simple HTTP 302 redirects rather than traditional techniques like iframes or JavaScript redirects which are easy to detect by network IDS/IPS devices.
  • Domain Shadowing, involves compromising the parent domain and creating multiple sub-domains that point to malicious code.

Please refer to our most recent write-up describing it in more detail.

A typical Malvertising infection cycle would involve following stages:

Malvertising infection cycle

Cybercrime Infrastructure & Business Model

Threat actors involved at different stages of the infection cycles are part of a thriving Cybercrime infrastructure & business model that is all interconnected as seen below:

Cybercrime Infrastructure & Business Model

The top Exploit Kits that we have seen involved in various Malvertising campaigns in 2015 are:
  • Angler
  • Nuclear
  • Magnitude
  • RIG
Angler Exploit Kit
Angler Exploit Kit is one of the most prevalent exploit kits in existence today and has many similarities with other exploit kits. Victims are usually served Angler landing pages via compromised websites where an iframe or script has been injected into the compromised site's page and loads Angler's exploit page. The landing page for Angler is very similar to Nuclear, but instead of displaying totally randomized text for obfuscation, random passages from the novel "Sense and Sensibility" are used. Angler domains at first glance may look like legitimate domains, for example:
inspirablebacktenter.modernlifestyle[.]com

Angler EK operators are leveraging domain shadowing technique to shield their landing sites from URL categorization-based detection. Over the past few months, we've seen Angler changing tactics somewhat. In late 2014, the landing page took the form of a 10 character alphanumeric php page, for example: 
/l86dvw7qfp.php
/62ynh7h2e9.php
/ukvugw2mct.php
This format quickly changed to exclude the php extension, then changed to an entirely new format:
/govern_wickets_insulator/1305714616
/pews-bathrobe-understatement/2333676765
/pions_fingertips_rebuff/8057907058341
/pounces-garrotted-bedfellow-mingling/387249683138585374
This is another attempt to blend in with normal looking web traffic. Exploit pages and payloads have a similarly consistent format that has not noticeably changed since late 2014:
/3R6sqI6COwSVqj-FeU2X7WK5qWYlpQskmTr-ivR7ZSZuIbap/9Oj96BjEJ7Rpe-CuvXMl_DVaDQFeQV53vYrJekoio1vi9dIc/eS9vXVpGOZhiD1CflWv8J9AeWGa_auetZVWzsTeBZqZTSXlR/VZsq9DV0HzNyc0_HxSiYUpc4_NiyZW729YthGRWUQOssgshN/JQqtNNYjlHsJNYAFZDsQEJIFAF227hht8nMx0qCyo6HRXuO8
The majority of the recent Angler EK infections were serving the Bedep AdFraud bot.

Angler EK instances blocked
Angler EK server locations

Nuclear Exploit Kit
Nuclear EK is arguably the most advanced exploit kit currently in use and includes a variety of different exploits. First appearing in 2009, the kit is very actively developed, with new exploits and defenses added incrementally over the years, and it is used to serve any number of payloads, including ransomware, click fraud, and multiple backdoors. Nuclear contains exploits for multiple common software components, including Flash, Internet Explorer, Java and Silverlight. Notably, in March 2015, the kit began including a Flash exploit for CVE-2015-0336 only a week after a patch was released by Adobe. Similar to Angler EK, Nuclear uses compromised webservers to serve exploits via 302-cushioning and domain shadowing, but free subdomain and dynamic DNS providers are also heavily used.
sstmxixcdr.serveftp[.]com/xqpjvl5oabhksk1fqq1bwl1afxdcs09xxxbjf1pdva.html
fu7bncm7xzjwu6hcfhuwwgg.90saniye[.]com/xvsobfbfaayaaxcou1gfcfvbs1wrefrrulaoebvovlfixfjkufgphacxulkl.html
azwbm2qdqs276gxw9qj82fg.akildakalici[.]net/rkklfaaacu1yh0aexaniauyvawypak8rcebtxquavh9ydl4kvvbsbfspulgxc1is.html
Using new subdomains of compromised sites enables Nuclear to evade older, domain-based blocking and allows for rapid rotation or one-time use of subdomains to hinder analysis by security researchers. In addition, before actually serving the exploit kit's landing page, potential victims are sent through an intermediary hop via 302-redirection; the victim is either 302-redirected to the landing page if this is a new victim, or sent to the desired non-malicious page.

Another interesting feature of Nuclear is that various fields are Base64-encoded and passed to the malicious domain:
ce79suqo5euujfchllkmwwf.alumni-year-book[.]com/index.php?a=cmtpbWJwZ2Q9cWEmdGltZT0xNTA0MTUwNjU0NjExNjY2ODgyJnNyYz0zMjImc3VybD1vbmVoYWxseXUuY29tJnNwb3J0PTgwJmtleT0xOUZGM0EwJnN1cmk9L3RvcGljLzQ0NzU0LSUyNUUyJTI1OTklMjVBNS10aGUtb2ZmaWNpYWwtJTI1RTIlMjU5OSUyNUE1LW5hbXNvbmctY291cGxlLSUyNUUyJTI1OTklMjVBNS10aHJlYWQtJTI1RTIlMjU5OSUyNUE1Lw==
--base64 decoded--
rkimbpgd=qa&time=1504150654611666882&src=322&surl=onehallyu.com&sport=80&key=19FF3A0&suri=/topic/44754-%25E2%2599%25A5-the-official-%25E2%2599%25A5-namsong-couple-%25E2%2599%25A5-thread-%25E2%2599%25A5/
Similar to Angler, the landing page contains sections of highly obfuscated JavaScript in between chunks of text; however, unlike Angler, Nuclear uses totally randomized text, which makes landing pages more difficult to detect using traditional signatures.
<textarea id='DjwvKE' title='riaXWWvroLTqxkFhlrC' name='MTdak' cols='84' rows='7'>cbkKKLhgidYWpsNmcSUOJXFDrjdbvBIScsdmDKTlorIdjVQMnlaxJgAAPecLfkdIdGvgRPSFGbjqwACkmcivIjwYOYjuJNCmUySlNlrUMbKJbMuNpcJyMFWadGUnTXZnVsYjdQDqrOATbuhQXqPjvlJZseMLBmyXeXGInJyfYyzztgPQWeASQJsInFUprSMVqSddccJAbIzUoPlLuleLvWUjboYSHloxDRbgukhVthqixbtrNYDIuXsWMQpTBdQFvsmpcTLVBCDyexqrVtAQRsndJcxLGORBGDriXDEYFIXkGNbcG</textarea>
<h2>QMx sKWhYGWu eZJGyZ aFnKgWwC xfgcc KmTs rOETlec oBWPHKZ yVrHkWnM AXkEQvfe oPeaHHcdWk kYVRPcClQO GmV gQl</h2>
<h4>fQgQqXM gvllOkaC HknmN qvPFFFKKja TRNMxyHikW JYAb QOWuNSKTX mhzDYzV</h4>
The majority of the recent Nuclear EK infections were serving Teslacrypt Ransomware.


Nuclear EK instances blocked
Nuclear EK server locations

Magnitude Exploit Kit
Magnitude EK, like Angler and Nuclear, is heavily reliant on landing page javascript obfuscation as a means of both exploiting the victim’s system and hindering detection. First documented in October 2013, the kit targets users with outdated Browser application plugins and CVE-2015-0336 was recently included in the kit’s arsenal of exploits. This exploit kit has historically leveraged malvertising for distribution rather than compromising individual websites. ThreatLabZ has observed numerous ad networks being used as intermediaries, including one campaign which saw Yahoo! ads redirecting victims to Magnitude landing pages.

A Magnitude landing page is easy to spot at a glance since they typically have an unusually large number of subdomains, as seen in the examples below.
55e3a.76ec.b9.d9a6a.b863cb4.01962.4abd.c0s7894l6e3.basicmagic[.]pw/?17657271617e787b766376796376637e3974787a
ba5.861fa24.4f.f40.e0c1.f51.afb.47340.7a.o7faf55lqj.workerscertain[.]in/?2b594e4d5d4244474a5f4a455f4a5f4205484446
The payload page for these threats is the same hostname and domain followed by a 32-40 character hexadecimal string. The final payload is ransomware called CryptoWall 3.0, which encrypts the victim’s files. CryptoWall displays a message demanding payment for decrypting the files; this ransom increases depending on how long the victim waits. This is done to give the victim less time to find an alternative solution and to get the maximum amount of money from the victim. 

Magnitude EK instances blocked
Magnitude EK server locations

RIG Exploit Kit
The RIG EK has been a relative newcomer to the exploit kit ecosystem. Since its debut in early 2014, it has been a prevalent threat to web-surfers. The developers have been very active in updating it with the latest features common to other exploit kits, and is currently making heavy use of domain shadowing. One major difference between RIG and others seems to be the modularity of the kit itself. RIG doesn't contain any exploits directly, but relies on a backend service for providing exploits. This is evidenced by the source code that was supposedly leaked by a RIG developer in February 2015. The leak seems to have been the result of internal squabbles between the developers, with the leak intended as a final blow to the development team. Customer posts on underground forums complained that their RIG deployments would occasionally be hijacked to deliver malware payloads that they did not designate for use. These issues point to a rogue developer in the RIG team, and the availability of the source will surely result in the emergence of derivative exploit kits.

Though RIG has made news by being injected into some major sites such as JQuery.org and AskMen.com, it appears that RIG is most frequently encountered via a combination of Malvertising and search poisoning. We commonly see redirectors that match the following two patterns:
domain.tld/search
domain.tld/search.php
There’s a two stage landing page that follows the redirectors, with the landing pages hosted on a variety of domain-shadowed hostnames:
far[.]capacitorsfordownhole[.]com
min[.]closinglawyer[.]net
deal[.]customdetonatorcapacitor[.]com
road[.]detonationcapacitor[.]com
home[.]autoqueen[.]net
calls[.]hightempcaps[.]com
add[.]hightempceramiccaps[.]com
top[.]highfrequencycapacitors[.]com
take[.]buriedbroadbandcapacitors[.]com
pro[.]customdetonatorcapacitor[.]com
An example of the redirector and two-stage landing page:

Two-stage landing page


Analysis of the URI paths on the landing pages shows that there are a few distinct parts. In the example above, the path “?xXmNd7GfKB7KA4M=l3SKfPrfJxzFGMSUb-nJDa9GPkXCRQLPh4SGhKrXCJ-ofSih17OIFxzsmTu2KV_OpqxveN0SZFT_zR3AaQ4ilotXQB5MrPzwnEqWwxWeioWA_0TfZl4W-5rBHbU6iw6gyLRGJMlzk0TQu2gCz-kaUEgbrA” features two distinct components separated by an equal sign (“=”). The first part (“xXmNd7GfKB7KA4M”) appears to be a unique client identifier while the much longer second part appears to be related to the overall campaign, with the same characters starting the string. A selection of campaign strings follow:
l3SKfPrfJxzFGMSUb-nJDa9GPkXCRQLPh4SGhKrXCJ-ofSih17OIFxzsmTu2KV_OpqxveN0SZFT_zR3AaQ4ilotXQB5MrPzwnEqWwxWeioWKrBLZZl9B_ZqXHOJqjl-gzeQSdpovwBbQuGhVxL4ZVUgbrAl3SKfPrfJxzFGMSUb-nJDa9GPkXCRQLPh4SGhKrXCJ-ofSih17OIFxzsmTu2KV_OpqxveN0SZFT_zR3AaQ4ilotXQB5MrPzwnEqWwxWeioXX9RyJNA5A_8CUQrY80Vz0ybYWJMslzxCE7GMBzeMdVkgbrAl3SKfPrfJxzFGMSUb-nJDa9GPkXCRQLPh4SGhKrXCJ-ofSih17OIFxzsmTu2KV_OpqxveN0SZFT_zR3AaQ4ilotXQB5MrPzwnEqWwxWeioWB9RWMZQJArcHEHbYy3A_3neJGdJl0lUKA4TQFxbtPVUgbrAl3SKfPrfJxzFGMSUb-nJDa9GPkXCRQLPh4SGhKrXCJ-ofSih17OIFxzsmTu2KV_OpqxveN0SZFT_zR3AaQ4ilotXQB5MrPzwnEqWwxWeioWLqBXeMgoQrZOVE7k-31-nnLNHI8lywhfUvGJQmu5IVUgbrAl3SKfPrfJxzFGMSUb-nJDa9GPkXCRQLPh4SGhKrXCJ-ofSih17OIFxzsmTu2KV_OpqxveN0SZFT_zR3AaQ4ilotXQB5MrPzwnEqWwxWeioWE9RyKZQhBq5KQErIz2FSmnOUVeM11wUXU4TUDz7kYVEgbrAl3SKfPrfJxzFGMSUb-nJDa9GPkXCRQLPh4SGhKrXCJ-ofSih17OIFxzsmTu2KV_OpqxveN0SZFT_zR3AaQ4ilotXQB5MrPzwnEqWwxWeioWE9RyKZQhBq5KQErIz2FSmnOUVeM11wUXU4TUDz7kYVEgbrAl3SKfPrfJxzFGMSUb-nJDa9GPkXCRQLPh4SGhKrXCJ-ofSih17OIFxzsmTu2KV_OpqxveN0SZFT_zR3AaQ4ilotXQB5MrPzwnEqWwxWeioWK9BPcNAsT-MHBR-Bp3Vv1zbJBJJgllROB7mJXzLhLVEgbrA


RIG EK instances blocked

RIG EK server locations

Malware Payload: ClickFraud & Ransomware

Exploit kits can serve a variety of different payloads, from Backdoors and Ransomware, to generic Downloaders. We’ve noted that the ultimate goal of many exploit kits is to monetize the infected system as much as possible, most commonly via Adfraud/ClickFraud. To support this goal, a very common payload for exploit kits is the Trojan Bedep, which can download additional malware and is used to perpetrate advertising fraud. In order to evade detection, Bedep is usually downloaded in an encrypted form and decrypted in memory as part of the infection process. Once decrypted, Bedep uses a domain generation algorithm (DGA) to communicate with its command and control servers. This communication is over normal HTTP, but messages are encrypted and then Base64 encoded, making analysis and detection more difficult.

When used for advertising fraud, Bedep creates a hidden desktop (a desktop instance not visible to the end user), shown below, that is not normally accessible in Windows, then begins displaying loading web pages and advertisements to commit advertising fraud.


Bedep Adfraud traffic & hidden desktop used to display Ads

Multiple windows are created to display ads (shown below) and in practice, this heavily impacts the performance of the infected system.

Bedep displaying multiple Ads on hidden desktop


Pages are quickly cycled to make as much money from the Ads as possible. In general, Bedep’s Adfraud traffic takes the form of ‘/r.php?key=’ or ‘/ads.php?sid=’ followed by a 32-character alphanumeric string, for example:
keppertoolsmaster[.]com/r.php?key=722445fbcd3e90f18f451c1344bdcc85
Another popular payload for exploit kits is ransomware, such as CryptoLocker and CryptoWall. This type of ransomware encrypts files on an infected system, and then demands payment to decrypt the files. CryptoLocker was first discovered in 2013 and quickly became popular due to the use of asymmetric encryption to hold user’s files for ransom, which is expected to be paid in Bitcoins. Additionally, recent samples contact a command and control infrastructure hosted on TOR hidden servers via TOR proxy gateways, such as tor2web.org. ThreatLabZ recently analyzed a sample of CryptoWall 3.0, a derivative clone of CryptoLocker, and found the binaries were hosted with a “.jpg” extension to avoid raising suspicion. Some of the other features of this CryptoWall sample include:
  • Decryption service hosted on TOR
  • CAPTCHA on decryption service
  • High ransom amount (700 USD, increasing to over 1400 USD)
  • Multiple payment options accepted besides Bitcoin
Ransomware is an attractive payload for criminals since many individuals and companies with no or incomplete data backups are likely to pay the ransom to recover sensitive files. Since the victim’s files are already encrypted, there is little to fear from traditional anti-virus signatures or blocking command and control traffic. Finally, even if someone pays the ransom, there is no guarantee that any files will be decrypted.

Multi-tasking example from a recent infection
A recent development we’ve observed is using Bedep to install ransomware as well as committing advertising fraud. In the observed sample, Angler EK first installed Bedep on the compromised system, which immediately downloaded a piece of ransomware called “Threat Finder v2.4.” Like other popular ransomware, Threat Finder displays a “HELP_DECRYPT” message which instructs users to send 300 USD of Bitcoins to a Bitcoin wallet in order to decrypt files. The screenshot below shows both the Threat Finder ransom window and advertising fraud sessions captured by Fiddler. Installing both ransomware and committing advertising fraud potentially generates even more money for the perpetrators.


Threat Finder v2.4, Bedep, dual infection


Trust us, we'll decrypt your files.... but only if you pay!

Conclusion
Malvertising campaigns have seen a significant uptick in 2015 and continue to be the most lucrative initial delivery mechanism for Exploit Kits. The fact that the legitimate websites becoming target of these campaigns have very little to no control for preventing such attacks makes this a very dangerous vector and a popular choice for cybercriminals.

The users should ensure that all the Browser application plugins are always patched with latest updates and disable the plugins that are not used. We also highly recommend using click-to-play feature available in many browser for Java & Flash plugins.

Analysis by: Deepen Desai, John Mancuso, Ed Miles, Chris Mannon

Wednesday, February 11, 2015

Ongoing Angler Exploit Kit and Bedep Fraud Campaign

In our recent post covering CVE-2015-0311, two of the Command and Control (C&C) domains used in the Domain Generation Algorithm (DGA), mapped back to the same Server IP address - 46.105.251.1. They were also using the same nameservers for resolution:
  • ns1.regway.com
  • ns2.regway.com
We took a closer look at the domains using these nameservers and found a distinct correlation between the C&C servers being used in this and other, possibly unrelated campaigns. In the past month, we've tracked over 70 domains involved in malware C&C or other malicious activity involving Click Fraud & Ransomware campaigns. These domains were registered via "Domain Context" and use "Regway.com" nameservers for resolution.

To recap, we saw the initial binary was executed via the CVE-2015-0311 exploit, which then attempted resolution of multiple domains that were generated through a DGA:



Below is partial whois information for the two domains that resolved at that time:





Taking a closer look at these domains, we noticed that they share some commonalities, specifically their nameservers and IPs:


Comparison of C2 Domains
Domain IP Observed Method Registrar Creation Date Contact Nameserver(s)
gaabbezrezrhe1k.com 46.105.251.1 POST / domaincontext 2015-01-19 contact @privacyprotect.org ns1.regway.com, ns2.regway.com
wzrdirqvrh07.com 46.105.251.1 POST / domaincontext 2015-01-21 yingw90 @yahoo.com ns1.regway.com, ns2.regway.com


Taking a look at other domains registered around that time via "Domain Context" by 'yingw90@yahoo.com' and also utilizing "regway.com" for resolution, we find the following 39 domains:

aslfnsdifhsfdsa.com
avzxpjvrndi6g.com
bnxjgqotkqaftj.com
cavnplxhlwjzld.com
dtnvleoidsncuz7i.com
ggrdyqtlgdbpkkjf0e.com
gqzrdawmmvaalpevd0.com
grqtnsmqveprdc8f.com
jacafyfugdnvoov.com
jdioermutrealo.com
jxouhxclhzdlwa1d.com
jzkebkiznfttde.com
kdioqw873-kioas.com
koslnotreamouyer.com
krbewsoiitaciki2s.com
mcoihsopejaue.com
mlhxqydhcjqvei.com
nertafopadertam.com
noieutrabchpowewa.com
nwlxjqxstxclgngbw7.com
nyrtazolas.com
piragikolos.com
pndrdbgijushci.com
qhmbdzygdevxk0m.com
qvllupuqjknz5.com
roppsanaukpovtrwl.com
rwermezqpnf4.com
tuchrtwsabl7b.com
uowcvvknkrtipj.com
vsdylqjfrdqaxzyd.com
vucjunrhckgaiyae.com
vxmsrlsanrcilyb7o.com
vxuiweipowe92j.com
xgihfqovzurg8.com
xmoqu38hasdf0opw.com
xqirefjyjkcn7u.com
yoksfffhvizk8z.com
yyfaimjmocdu.com
zmbkfrdpnaec.com

Looking at the same time period for domains registered through "Domain Context", using "Privacy Protect", and using "regway.com" for resolution, we find an additional 32 domains, which also seem to fit the general theme of a DGA:

394iopwekmcopw.com
agdedopribili.com
asop83uyteramxop.com
balamodaevi.com
cawnqrvbmfgfysdb.com
deertraefople.com
gpsnypbnygqidxj.com
gurtgusinoi.com
gypqlkwgkmzapx33.com
iludyamdostaetsya.com
iqjlyjxplidpbbpuh.com
istinuskazat.com
itdlwcwonkhjrxlzuh.com
jddhbxrssjgqlsr.com
jyjhsvgkpeni0g.com
kbazarnomuondnu.com
kosnetsyanetolko.com
muzhikgusei.com
nabarishispeshil.com
neochenvezhlivo.com
predlinnoihvorostinoi.com
prodavatipravdu.com
retravopoytem.com
sokgtxioqzxvuksf1.com
tamgusyam.com
tuzlynlyvrbrdhrpx.com
vpsbxfdyphdykmlct.com
xnanomailing.com
yamuzhikainevenu.com
ytpliogapddu5.com
zhcjrjolbeuiylkyzx.com
zoidpyjhij36.com

The vast majority of these domains were resolving to Bedep's C&C servers. The following is a POST request to a C&C server from a Bedep infected system containing base64 encoded data:





However, some of the domains are being used in other seemingly unrelated malicious campaigns. For example the domain 'xmoqu38hasdf0opw.com' was identifed by Kafeine as hosting a Reveton ransom page. 

Other domains being used to monetize Bedep infections via click fraud include:

394iopwekmcopw.com/ads.php
394iopwekmcopw.com/r.php?key=41c7eed67784325bb935f2b6543ff37d
asop83uyteramxop.com/ads.php?sid=1910
asop83uyteramxop.com/r.php?key=c8a0293dce08d582ca645449d849543d
koslnotreamouyer.com/ads.php?sid=1905
koslnotreamouyer.com/r.php?key=666fe962677224b1799919a70c7c2c9e

And the following domains are intermediaries hosting encrypted files:

kosnetsyanetolko.com/slwsbpetw.eqmh
kdioqw873-kioas.com/asdfsfsdf1.php
nertafopadertam.com/2/showthread.php
nyrtazolas.com/1/search.php
piragikolos.com/asdfsfsdf1.php

Unfortunately, there are several different IPs in use on various ASNs:


C2 IP Information
IP Netblock ASN
46.105.251.1 46.105.0.0/16 OVH ISPOVH_65488197 OVH Static IP AS16276
5.135.16.201 5.135.0.0/16AS16276FR-OVH-20120706 OVH SAS AS16276
94.23.204.16 94.23.0.0/16 OVH ISPOVH OVH SAS Dedicated Servers AS16276
5.196.196.149 5.196.196.0/22AS197890FR-OVH-20120823 OVH SAS AS16276
46.105.251.0 46.105.0.0/16 OVH ISPOVH_65488197 OVH Static IP AS16276
37.187.76.177 37.187.0.0/16 OVHOVH OVH SAS Dedicated servers AS16276
206.222.13.164 206.222.0.0/19 RR-RC-Enet-ColumbusEE3-DOM AS10297
23.105.135.219 23.105.128.0/1923.104.0.0/13Route for Nobis Technology Group, LLCNETBLK-NOBIS-TECHNOLOGY-GROUP-18 AS15003
23.105.135.218 23.105.128.0/1923.104.0.0/13Route for Nobis Technology Group, LLCNETBLK-NOBIS-TECHNOLOGY-GROUP-18 AS15003
151.80.95.8 151.80.0.0/16151.80.0.0/17 OVHIUNET-BNET80 OVH SAS AS1267
80.82.70.104 80.82.70.0/24 AS29073 Route objectNL-ECATEL-20100816 Ecatel LTD AS29073
79.143.82.203 79.143.80.0/22Redstation LimitedRSDEDI-KBPNNOIL Dedicated Server Hosting AS35662
79.143.80.42 79.143.80.0/2279.143.80.0/24Proxy-registered route objectRSDEDI-IBOBAPEP Dedicated Server Hosting AS35662
217.23.12.145 217.23.0.0/20WORLDSTREAM-BLK-217-23-0-0WORLDSTREAM WorldStream IPv4.19 AS49981
173.224.126.29 173.224.112.0/20Hosting Solutions InternationalHSI-3 AS30083
173.224.126.19 173.224.112.0/20Hosting Solutions InternationalHSI-3 AS30083
50.30.36.1 50.30.32.0/20Hosting Solutions InternationalHSI-4 AS30083
209.239.115.228 209.239.112.0/20209.239.115.0/24Proxy-registered routeHSI-2 AS30083


Conclusions

Attackers continue to move away from single IPs and small IP pools, preferring to distribute the infrastructure across multiple netblocks. This ensures their infrastructure is more resilient to blocks and takedown attempts allowing the attackers to continue to profit from compromised devices. Likewise, if a registrar or nameserver with poor reputation is found, specific actors will continue to leverage them until mitigations are put in place. 

Thursday, January 22, 2015

Malvertising leading to Flash Zero Day via Angler Exploit Kit


UPDATE [01/25/2015]: Adobe released an update yesterday (APSA15-01) for CVE-2015-0311 that fixes the zero day exploit mentioned in this blog. Given the number of exploit attempts we are seeing for this vulnerability in the wild, it is critical for users to update the Adobe Flash player to the latest version 16.0.0.296.

Background

Earlier this week, Kafeine published a blog mentioning an Angler Exploit Kit (EK) instance serving a possible zero day Adobe Flash exploit payload. The ThreatLabZ Research Team reviewed Angler Exploit Kit activity across the cloud and were able to identify multiple instances of Angler Exploit Kit hosting sites serving a new Adobe Flash payload that is able to exploit the latest Flash Player version 16.0.0.257.  [Adobe released a patch (APSB15-02) for CVE-2015-0310 today and we can confirm that the patch does not prevent exploitation of the 0day discussed in this blog. The latest version 16.0.0.287 is still vulnerable and is being actively exploited in the wild.]

Upon further investigation, we discovered that this appears to be yet another case of a Malvertising campaign leading unsuspecting users to Angler EK instances. Upon successful exploitation, we observed a new variant of the Bedep Trojan getting dropped and executed on the victim machine. We tested this on a Windows 7 64-bit system and the payload dropped was a 64-bit Bedep Trojan variant which generated a high volume of AdFraud traffic from the infected system.

The affected advertising networks found in this case were:
  • oneclickads.net
  • adcash.com
Infection Cycle

The infection cycle involves users visiting a legitimate site that displays certain advertisements from the compromised advertising networks, which will redirect them to an Angler EK hosting site and begin the exploit cycle. If the exploit is successful, a new variant of Bedep Trojan gets downloaded in an encrypted form and installed on the target system.

The entire infection cycle occurs silently in the background and is completely transparent to the end user.


The exploit page has the title "Welcome to new site" and is comprised of 220 hidden input elements, followed by three inline scripts.


The first script code snippet is obfuscated with block comment text (ie: /* random text */), but also appears purposefully broken for multiple JavaScript engines. Looking at the code, there are multiple period characters inserted throughout the script which leads to syntax errors at runtime:


The second script code snippet calls a function in the first script leading to "eval" and resulting in JavaScript code that performs Browser plugin detection:



The third script code snippet drew our attention, as it is not obfuscated and simply loads an SWF object. This script serves the Adobe Flash 0-day and it is interesting to note that the script will only execute if the earlier script has thrown an error. The flash payload is only triggered if a variable defined in the first script is undefined:



Successful exploitation will result in download of the Bedep Trojan payload that appears to be encrypted using an incremental XOR technique.

Malware Payload activity - Bedep Trojan

The malware payload dropped is a 64-bit DLL belonging to Bedep Trojan family.  This malware family is known to download additional malware. It is also responsible for generating AdFraud and ClickFraud activity from the infected system.

File: neth.dll
Size: 219608
MD5: EFB584DEA6CBC03765487633BD5A5920
Compiled: Wed, Nov 28 2007, 15:51:15  - 64 Bit DLL
Version: 5.3.3790.3959 (srv03_sp2_rtm.070216-1710)

It drops a copy of itself at the following locations:

C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}\neth.dll
C:\Users\All Users\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}\neth.dll

It creates the following registry entries to achieve persistence in a discreet manner:

HKLM\SOFTWARE\Classes\CLSID\{F6BF8414-962C-40FE-90F1-B80A7E72DB9A}\InprocServer32\: "C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}\neth.dll"
HKLM\SOFTWARE\Classes\CLSID\{F6BF8414-962C-40FE-90F1-B80A7E72DB9A}\InprocServer32\ThreadingModel: "Apartment"


HKU\S-USERID-1000_Classes\CLSID\{F6BF8414-962C-40FE-90F1-B80A7E72DB9A}\InprocServer32\: "C:\ProgramData\{9A88E103-A20A-4EA5-8636-C73B709A5BF8}\neth.dll"
HKU\S-USERID-1000_Classes\CLSID\{F6BF8414-962C-40FE-90F1-B80A7E72DB9A}\InprocServer32\ThreadingModel: "Apartment"

This ensures that it runs in the context of system process "explorer.exe":


It appears to determine the infected system's timezone and location by connecting to "earthtools.org", however we noticed that it is not able to supply the latitude and longitude parameters in the request, essentially resulting in getting back UTC date and time information.

It employs a Domain Generation Algorithm technique to hide the actual Command & Control server as seen below:



 We found the following two C&C domains registered in past 48 hours:

  • gaabbezrezrhe1k.com
  • wzrdirqvrh07.com






It attempts to connect to these Command & Control servers to report the infection and receive further instructions. It presumably gets a list of ClickFraud tasking servers, following which we started seeing high volume of ClickFraud activity.




Conclusion
This is the first 0Day Adobe Flash Player exploit for year 2015 and not surprisingly, we are seeing it getting served through a malvertising campaign. The fact that the end malware payload getting served in this case is also involved in AdFraud activity leads us into believing that this campaign appears to be from a gang indulging in ClickFraud and AdFraud activity.

Zscaler ThreatLabZ has deployed multiple layers of protection against this threat to ensure that the customers are protected.

Analysis by Deepen Desai & John Mancuso