Showing posts with label Compromised WordPress. Show all posts
Showing posts with label Compromised WordPress. Show all posts

Friday, September 25, 2015

Compromised WordPress Campaign - Spyware Edition

[Update - October 9, 2015] 

Multiple Drupal & Joomla sites affected..

The Spyware campaign we wrote about two weeks ago continues to be active, although the number of infected websites has gone down. We are also seeing two other popular Content Management Systems (CMS), Drupal and Joomla sites being compromised and leveraged in this campaign.

Spyware campaign hits from last 7 days

The compromised Joomla and Drupal site pages are injected with identical malicious JavaScript  redirecting users to the download of Spyware and Potentially Unwanted Applications as seen below:

Compromised Drupal Site with injected JavaScript

Compromised Joomla Site with injected JavaScript

Introduction

The Zscaler security research team started investigating multiple WordPress related security events earlier this month and came across a new widespread compromised WordPress campaign leading to the download of unwanted applications. This has been briefly covered by dynamoo and has been reported by some users on official WordPress forums.

During our research, we discovered that this campaign started in the first week of August, 2015 and has been fairly active since then resulting in over 20,000 security events to date from over 2,000 web pages. Majority of the WordPress sites affected by this campaign are running latest version 4.3.1 but the compromise could have occurred prior to the update.

Figure 1: August 2015 WordPress Campaign hits


Figure 2: September 2015 WordPress Campaign hits

Infection Cycle

The infection starts when a user visits a compromised WordPress site. The compromised pages will have injected JavaScript shown below:

Figure 3: Injected malicious JavaScript code


The deobfuscated JavaScript code contains an iframe to the malicious server location:

Figure 4: Deobfuscated JavaScript containing the iframe


Although the target domains varied across the transactions that we saw, the associated server IP address has remained the same.

Target domains seen
c11.n4.i.teaserguide[.]com
i.illuminationes[.]com
c11n4.i.teaserguide[.]com
kfc.i.illuminationes[.]com
kfc.i.teaserguide[.]com
xn--c11n4-ix3b.i.teaserguide[.]com
xn--kfc-rp0a.i.illuminationes[.]com
c114.i.teaserguide[.]com
rm3a.r.mega-us-pills[.]ws

The IP Address 91.226.33.54 associated with these domains is hosted in Latvia through a VPS hosting provider.

The injected iframe loads additional JavaScript that gathers information such as current system timestamp, timezone, and presence of Adobe Flash Player.

Figure 5: User system information gathering script


Figure 6: Function to check the presence of Flash Plugin and version information


















The collected information is relayed back to the same server via a HTTP GET request. This is followed by a series of redirects leading to download of spyware or potentially unwanted applications (PUA) masquerading as legitimate applications.

Figure 7: Redirects from Latvia VPS server leading to PUA download














Fake Flash Player - Win32.InstallCore

In one of the cases, we observed the user is prompted to update the Flash Player as seen below:

Figure 8: Out of date Flash Player warning
The page prompts the user to update or install a new flash player update. Regardless of the option the user selects, a fake Adobe Flash Player application is downloaded.

FileName : Adobe Flash Player.exe
MD5 : fa75abf137224fc2c60b9b3c35c80a5e

This file is a .NET Compiled executable which downloads and executes another setup file named FlashSetup.exe.

FileName : Flash Setup.exe
MD5: 87234af45b30740309c8bffcdf2167dc



Figure 9: Fake Flash Player download
The downloaded file flashsetup.exe is a variant of Potentially Unwanted Application Win32.InstallCore. During the installation of the Adobe Flash Player, several other websites offering other unwanted scareware applications are displayed. One such case where the spyware installer prompts the user to download and install Windows 7 PC Repair tool is shown below:
 
Figure 8: Scareware Windows 7 Repair utility



Figure 9: Download from third party sites & adware traffic from PUA

Once the spyware installation is complete, the user is redirected to the legitimate Adobe page indicating that the installation was not successful prompting the user to start over. If the user chooses to start over the installation, Adobe Flash Player will be installed from the genuine Adobe site.

Figure 10: User redirected to legitimate Adobe Flash Player





















Fake MediaDownloader update - Win32.DownloadAssistant

In another case, the webpage prompts the user with a fake MediaDownloader software update which is a variant of PUA Win32.DownloadAssistant.

FileName: Setup.exe
MD5: a885f33c308721831498a2ac581bd91c
Figure 11: Fake MediaDownloader Update

The end result is same where a potentially unwanted application is downloaded and installed on the victim machine. These applications have the capability to download additional malicious or unwanted applications.

We also saw instances of fake web browser plugins being downloaded and installed. Below is an example of a Google Chrome Plugin - NewTabTV plus.

Figure 12: Fake Google Chrome Plugin download

The compromised sites involved in this campaign are distributed worldwide and not limited to one particular region.

Figure 13: Geo distribution of the compromised WordPress sites - September 2015

















Conclusion

WordPress, being one of the most popular Content Management Systems & Blogging platform, remains an attractive target for cybercriminals. Unlike previous campaigns involving Malware Authors and Exploit Kit operators, the end payload getting served in this campaign involves spyware and potentially unwanted applications. These applications may seem innocuous but can facilitate malvertising based attacks through unsolicited advertisements.


Zscaler ThreatLabZ is actively monitoring this campaign and ensuring that Zscaler customers are protected.

Analysis by Jithin Nair and Sameer Patil


Thursday, June 4, 2015

Signed CryptoWall 3.0 variant delivered via MediaFire

Introduction

Ransomware has evolved immensely over the past few years, with CryptoLocker being the ground breaking strain reaping huge profits for cybercriminals. According to a report in December 2013, the CryptoLocker malware authors collected 27 million USD worth of bitcoins from their victims over a period of 3 months. Looking at the success enjoyed by the CryptoLocker strain, it's not surprising that many new copy cat variants including CryptoWall emerged in the wild starting in late 2013.

CryptoLocker suffered a major setback and the number of infections were reduced to nearly zero post Operation Tovar. This gave way to a worthy successor in CryptoWall, which has since evolved into one of the nastiest and most successful strains of Ransomware in the wild today.

The following are some of the notable features responsible for the success enjoyed by CryptoLocker and CryptoWall variants:
  • Asymmetric (public-key) encryption to encrypt user documents, making recovery infeasible
  • Holding user files hostage with a timer that increases the ransom amount over time
  • Ransom collected in bitcoins or as pre-paid cash vouchers
  • Usage of anonymizing networks like Tor & i2p

Recent 'crypt4' campaign - CryptoWall 3.0

CryptoWall has been known to arrive via spammed e-mail attachments, exploit kits and drive-by downloads. Recently, we started seeing a new campaign involving multiple signed CryptoWall 3.0 samples in our Cloud Sandboxes being downloaded from a popular file hosting service, MediaFire.

A quick Open Source Intelligence (OSINT), search lead us to this e-mail campaign where the attachment contains a Microsoft Compiled HTML help (CHM) file that leads to the download and execution of the the latest CryptoWall 3.0 variant hosted on MediaFire. The CHM file downloads and executes the CryptoWall executable from a hardcoded MediaFire location as seen in screenshot below:

Malicious CHM file - Extracted HTML code

Some of the file names we have seen in this campaign:
  • IPv6_updater.exe
  • IPv4_updater.exe
  • flashplayer17_ga_install.exe
Analysis of the new variant

The CryptoWall 3.0 payloads that we saw getting downloaded as part of this campaign were all signed by a valid certificate belonging to MDG Advertising as seen in the screenshot below:

Valid MDG Advertising certificate used to sign CryptoWall 3.0

The malware performs following file system changes to ensure persistence:
  • Dropped files
%USER%\APPDATA\7cc6cc79.exe [random alphanumeric name]
%USER%\Start Menu\Programs\Startup\7ddfa86e.exe [random alphanumeric name]
  • Registry entry
HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run dd574bd = "%USER%\APPDATA\7cc6cc79.exe"
It also deletes the original copy of itself.

The malware then attempts to connect to the Command & Control (C&C) server to report the infection via a POST request as seen below:

C&C communication - Register infection

It uses RC4 encryption for the data being sent in the POST request. The original data is of the format
{1|crypt4|UniqueMD5Hash|2|1|2|PublicIP}
- "crypt4" string represents the Campaign ID
- "UniqueMD5Hash" is calculated from Computer Name, Volume Serial Number, Processor & OS information
The RC4 key is generated by doing a simple alpha-numeric sort on a string stored inside the binary as seen in the screenshot below. The unsorted RC4 key is also sent as part of the POST request.

RC4 Key encrypted POST request to C&C server

The malware then performs another POST request and in response it gets RC4 encrypted Tor domain & public key to use for encrypting the victim files. The Tor domain is leveraged for the decryption instruction. Screenshots below, show the original communication & decrypted response:

C&C communication - Requesting Public Key

C&C communication - Decrypted response with public key

Upon successful encryption of the files on the victim machine using the public key, it reports back the number of files that were encrypted to the C&C server. The information collected by the C&C server is leveraged to present a more personalized decryption instruction page that includes user's operating system, public IP address, and the number of files encrypted as seen below.

Personalized ransom payment page
The ransom amount requested in our case was $500 USD and to prove authenticity, the malware authors also offer the victim a "Decrypt 1 file for FREE" option, which is limited to a 512 kilobyte file.

Below is the geo distribution of the CryptoWall C&C servers we oberved in the past week:

CryptoWall C&C servers

CryptoWall C&C country distribution

Compromised WordPress sites used for C&C communication

We are also seeing an increase in the number of compromised WordPress sites being used for CryptoWall C&C communication. Below are some of the locations where the malicious scripts are being hosted on these servers:
  • /wp-content/plugins/revslider/temp/update_extract/
  • /wp-content/uploads/wpallimport/uploads/
  • /wp-content/themes/pptitan/
You can get full list of the Compromised WordPress sites that we have oberved in past one week here.

Conclusion

CryptoWall remains a potent threat to enterprises and individual users alike. Traditional AntiVirus applications continue to struggle against this nasty strain of ransomware, as once the infection is successful, there is very little AV vendors can do, even by adding signatures reactively. A hybrid and multi-layered security approach is required to counter this threat.

Taking regular backup remains the most effective counter measure against ransomware.

Deepen Desai & Avinash Kumar