Showing posts with label Exploit Kit. Show all posts
Showing posts with label Exploit Kit. Show all posts

Tuesday, January 12, 2016

There Goes The Neighborhood - Bad Actors on GMHOST Alexander Mulgin Serginovic

Introduction

Whether they encourage it or not, some network operators become known and favored by criminals such as those that operate exploit kit (EK) and malware infrastructure. After following up the Sundown EK recently pointed out by @malwareforme on the Threatglass database, we found Neutrino (looking like Angler) and other bad behavior in the same network "neighborhood".

It's not clear what reputation this hoster has within the underground community, but the Sundown and Neutrino campaigns both appeared within the same address space registered under "Alexander Mulgin Serginovic" (AMS) with the first Neutrino hits coinciding with the last few hits of Sundown's December 2015 campaign. We have not identified any link between these campaigns apart from the hoster, but we wanted to provide a quick look at some of these activities and the specific indicators we have seen.

Sundown Behavior

Other analysts have observed the emergence of the Sundown EK (aka Beta Exploit Pack), with Kafeine in particular commenting that Sundown is a very simple EK compared to the more mature kits like Angler. This continues to be the case, however we have seen that the group operating Sundown has made adjustments, including some changes that happened in the midst of this campaign.

Injects

The campaign on ForoMTB Sundown used a small malicious inject within one of the included JavaScript libraries:


On CinemaHD, we saw a basic IFRAME inserted directly into the page:


Gates

During December we saw the gate "millychiccolo[.]space/jhgrjhk.php", and after the new year we have seen "pienadigrazia[.]space/counter.php" though we also saw direct traffic from the compromised sites.

Landing Pages

In the past 45 days we have seen Sundown operate with various domains hosting the landing pages, but only on two different IPs: 81.94.199.16 and 185.86.77.160. The path component of the landing page has gone through several iterations. The early hits in this campaign were seen to "millychiccolo[.]space/?9b5b49f7f8c07f43effe4aecc67bf254". Later, the landing page path was encoded with base64 as such: "millychiccolo.space/?OWI1YjQ5ZjdmOGMwN2Y0M2VmZmU0YWVjYzY3YmYyNTQ=". It should be noted that this base64 string decodes to the same MD5-looking path used in the first instance. Sundown changed up the underlying "MD5" for the new year, and we have seen landing pages at "arbitraryh.top/?NjExODEzY2MzNTkyZTkyYWYxZmNlYjExODQzMzAz" (the path decodes to 611813cc3592e92af1fceb11843303).

These are some of the domains we saw delivering Sundown landing pages, exploits, and malware payloads:
nomeatea.space
millychiccolo.space
pianolessons.co.vu
tequeryomuch.space
ilsignoreconte.space
arbitraryh.top
pienadigrazia.space

Despite the path changes, the behavior of the Sundown landing page is still quite simple: a "carpet bombing" where many or all possible exploits are tried, in some cases with multiple successes. An example of the exploitation flow:
ilsignoreconte[.]space/new/e/360a296ea1e0abb38f1080f5e802fb4b.html
ilsignoreconte[.]space/new/e/053d33558d578d2cafe77639209ab4d9.html
ilsignoreconte[.]space/new/e/49c58cc2b166b1a5b13eab5f472a4f7b.html
ilsignoreconte[.]space/new/e/49c58cc2b166b1a5b13eab5f472a4f7b.swf

Exploit Payloads

Sundown was seen sending the following exploit payloads:
poc2.flv - CVE-2015-3113
49c58cc2b166b1a5b13eab5f472a4f7b.swf - CVE-2015-5122
865hkjjhgfhjrgjkgyjtyg6lkjthyrkljtgh.html - CVE-2015-2419
8573855j6lhk4j54kl5jhk53j654364354.html - CVE-2013-2551
8500d58389eba3b3820a17641449b81d.html - CVE-2014-6332
360a296ea1e0abb38f1080f5e802fb4b.swf - CVE-2014-0515
053d33558d578d2cafe77639209ab4d9.swf - CVE-2015-3113 (via poc2.flv)

Malware Payloads

The delivery of the malware samples was another aspect of Sundown that we saw change. Through December 26, the malware payloads were downloaded from the URL "tequeryomuch[.]space/new/download.php?d=9b5b49f7f8c07f43effe4aecc67bf254". On the 27th we saw payloads coming from "tequeryomuch[.]space/?NGFlY2M2N2JmMjU0&d=9b5b49f7f8c07f43effe4aecc67bf254".

Some of the samples we observed during this campaign:
Sample
4BAEEE098C34B463EB8AC709B9BD9967 (the sample seen on Threatglass)

Behavior
{"dropped_path":"C:\\Documents and Settings\\user\\Application Data\\ZlFZQkBA\\twunk_32.exe","dropped_md5":"4BAEEE098C34B463EB8AC709B9BD9967"}
{"dropped_path":"C:\\WINDOWS\\Tasks\\ZlFZQkBA.job","dropped_md5":"22D5FD2A8675CF3B673D84716384AE8A"}

{"url":"imagescdn[.]ru/redir.php","destIP":"5.206.60.129","ua":"Mozilla/5.0 (Windows NT 6.1; WOW64; rv:39.0) Gecko/20100101 Firefox/38.0, Content-type: application/x-www-form-urlencoded","method":"POST","destPort":"80"}
{"url":"imagescdn[.]ru/redir.php","destIP":"178.137.82.42","ua":"Mozilla/5.0 (Windows NT 6.1; WOW64; rv:39.0) Gecko/20100101 Firefox/38.0, Content-type: application/x-www-form-urlencoded","method":"POST","destPort":"80"}
{"url":"imagescdn[.]ru/redir.php","destIP":"213.231.31.192","ua":"Mozilla/5.0 (Windows NT 6.1; WOW64; rv:39.0) Gecko/20100101 Firefox/38.0, Content-type: application/x-www-form-urlencoded","method":"POST","destPort":"80"}
Sample
D754B473AF45B8D3565C1323D29EAD51

Behavior
{"dropped_path":"C:\\Documents and Settings\\user\\Application Data\\ZlFZQkBA\\taskman.exe","dropped_md5":"D754B473AF45B8D3565C1323D29EAD51"}
{"dropped_path":"C:\\WINDOWS\\Tasks\\ZlFZQkBA.job","dropped_md5":"07808D2E9A1D1607FCB81C1E0CA03358"}

{"url":"imagescdn[.]ru/redir.php","destIP":"109.251.77.14","ua":"Mozilla/5.0 (Windows NT 6.1; WOW64; rv:39.0) Gecko/20100101 Firefox/38.0
Content-type: application/x-www-form-urlencoded","method":"POST","destPort":"80"}
{"url":"imagescdn[.]ru/redir.php","destIP":"109.251.77.14","ua":"Mozilla/5.0 (Windows NT 6.1; WOW64; rv:39.0) Gecko/20100101 Firefox/38.0
Content-type: application/x-www-form-urlencoded","method":"POST","destPort":"80"}
{"url":"imagescdn[.]ru/redir.php","destIP":"213.111.238.98","ua":"Mozilla/5.0 (Windows NT 6.1; WOW64; rv:39.0) Gecko/20100101 Firefox/38.0
Content-type: application/x-www-form-urlencoded","method":"POST","destPort":"80"}
Sample
6580F61B8B1AABFE3CAD6983CA9B2505

Behavior
{"dropped_path":"C:\\DOCUME~1\\user\\LOCALS~1\\Temp\\svchost.exe","dropped_md5":"FAA8EA9027ED6B6C875C247E59285270"}
{"dropped_path":"C:\\Documents and Settings\\user\\Application Data\\programutiliity\\filename.exe","dropped_md5":"A1429E43D7F19EB893FCC5D7BD2B21E9"}
{"dropped_path":"C:\\Documents and Settings\\user\\Start Menu\\Programs\\Startup\\filename.bat","dropped_md5":"7C444F8193480F6DC571BB6483E60A6A"}

Geographic Distribution

We've primarily seen this Sundown campaign affect users located in Spain, though this may have more to do with the fact that the primary infected site is a Spanish-language forum.



Control Panel Login

Though we did not make any efforts to break into the Control Panel, we found it interesting that the login portal was so readily available to anyone who bothered to poke around at all. It's definitely looking a little flashier since Kafeine's analysis.


Neutrino Behavior

Neutrino, like Sundown, operates in the shadow of Angler. In this case, the first signs of activity seen in the campaign actually look very much like Angler, so much so that Blue Coat's blog about the same activity was later updated to correct the identification. Regardless of whether the initial traffic is actually Angler or not, the campaign changed noticeably over the observed duration. The early stage of the campaign triggered Angler signatures from a variety of sources. As can be seen below, the code features the "malware.dontneedcoffee.com" test that has been common to Angler.


Later stages of the campaign showed more expected Neutrino behavior: where the first stage after the infected website was initially an Angler-alike landing page, the injected code instead directs users to an HTML page that loads a malicious Flash object. This can be clearly seen below in the side-by-side comparison.


Infected Sites and Landing Pages

Many of the sites serving this Neutrino campaign were registered under .CZ, the top-level domain (TLD) for the Czech Republic. Since full list is too long to include here, we have created a Pastebin with the data.

We saw landing pages served up from these IPs:
185.86.77.52
89.38.146.229
37.157.195.55
45.32.238.202
185.12.178.219
89.38.144.75 
The list of landing page domains is again too long to reproduce here, so please see our Pastebin for the data.

Payloads

While we did not observe a malicious payload from the "Angler" behavior, we found the later stage of the campaign delivered a CyrptoWall 4.0 payload. Shown below is the notice from the locker malware.

Geographic Distribution

The geographic distribution of clients affected by this campaign is somewhat more dispersed than the Sundown campaign, though the majority of users were located in the US.


Malware Command and Control

In addition to Sundown and Neutrino (with a case of multiple personality disorder), we also identified Necurs and Radamant callback activity on the AMS network. We include details of this activity below.

Necurs Activity

Necurs is a fairly well-known rootkit that is often distributed by EKs and spam e-mails. We did not identify the infection vector for this campaign, but we saw some post infection activity to a Necurs C&C server hosted by AMS. The AMS C&C is only one of many C&Cs we saw, but in an interesting trend, we saw the Necurs callback activity drop off almost entirely going into 2016.




Please find the list of Necurs callback IPs on our Pastebin.

Radamant Activity

Radamant is yet another file locker, that according to BleepingComputer just recently became available as of December 7 2015. While we haven't seen very widespread distribution of Radamant yet, we have seen examples from as early as December 4, attempting communication with a server at our new favorite hoster as seen below.

{"url":"checkip.dyndns.org/","destIP":"91.198.22.70","ua":"","method":"GET","destPort":"80"}
{"url":"185[.]86.79.100/API.php","destIP":"185.86.79.100","ua":"","method":"POST","destPort":"80"}
{"url":"185[.]86.79.100/API.php","destIP":"185.86.79.100","ua":"","method":"POST","destPort":"80"}
{"url":"185[.]86.79.100/API.php","destIP":"185.86.79.100","ua":"","method":"POST","destPort":"80"}
{"url":"185[.]86.79.100/mask.php","destIP":"185.86.79.100","ua":"","method":"POST","destPort":"80"}

Conclusion

AMS may host many legitimate customers, and while we didn't intend to call them out specifically, we wanted to share some of the malicious behavior we have seen involving this network (and others) in an effort to help other defenders. ThreatLabZ will continue to monitor these campaigns and ensure protection for organizations using the Zscaler Internet security platform.

Tuesday, November 3, 2015

Chinese Government Website Compromised, Leads to Angler

Introduction

Despite a recent takedown targeting the Angler Exploit Kit (EK), it's back to business as usual for kit operators. On 30-October-2015, ThreatLabZ noticed a compromised Chinese government website that led to the Angler Exploit Kit with an end payload of Cryptowall 3.0. This compromise does not appear targeted and the compromised site was cleaned up within 24 hours. We have noticed some recent changes to Angler, as well as the inclusion of newer Flash exploits. A set of indicators for this compromise is at the end of this post.

Compromised Site

The "Chuxiong Archives" website, www.cxda[.]gov.cn, was compromised with injected code. The site has a similar look and feel to both the Chuxiong Yi Prefecture and Chuxiong City websites and appears somewhat inactive, but surprisingly the site was remediated in less than 24 hours. The full infection cycle from compromised site to encrypted payload is shown in the fiddler session below.

Fig 1. Infection cycle
The injected code was before the opening HTML tag and was heavily obfuscated. The code, shown below, is very similar to other recent compromises we've observed and was present on every page of the site, suggesting a complete site compromise.

Fig 2. Injected script
Consistent with other recent examples, the injected code appears to target Internet Explorer (IE) since Firefox and Chrome consistently throw errors when attempting to execute the code and no redirection occurs. IE has no issues executing the code, however, which unsurprisingly decodes to an iframe leading to an Angler EK landing page:

Fig 3. Decoded injected code
While we did not have access to the server-side code, it likely retrieves landing page URLs from a remote server since we observed iframes leading to multiple different Angler domains within a brief period of time.

Landing Page

The landing page for Angler is immediately recognizable, but with some notable recent changes. For example, instead of using a long block of around seven-character long strings inside divs tag, the newer landing pages use 'li' tags and most of the strings are only about two characters long. Additionally, there's a conspicuous 'triggerApi' function toward the top of the main script block:

Fig 4: Short strings and triggerApi function
Outside of these changes, the functionality of the landing page appears unchanged, and the goal is naturally to serve up a malicious SWF:

Fig 5. Decoded landing page SWF objects

Malicious SWF - CVE-2015-7645

Kafeine already broke the news that Angler is exploiting Flash 19.0.0.207, and we can corroborate that with the samples we've observed.
Fig 6. Flash 19.0.0.207 being exploited
In fact, we compared the sample from his recent post with one obtained from this infection and the structure is identical, with very few changes in the actionscript. The biggest change we saw was in the embedded binary data.

Fig 7. SWF structure, 30-Oct sample on the left, Kafeine's sample on the right

Fig 8. Comparison of binary data, 30-Oct sample on the left, Kafeine's sample on the right
Upon successful exploit cycle, a new CryptoWall 3.0 variant from the crypt13 campaign is downloaded and installed on the target machine. The image below shows a decrypted Command & Control (C&C) communication message from the CryptoWall variant which also contains the total number of files encrypted on the target system:

Fig 9. CryptoWall 3.0 C&C message reporting encrypted file count

Final Thoughts

As stated, this seems to be business as usual for Angler EK operators. While these attacks were not targeted in nature, this is the first instance where we saw EK operators leveraging a government site to target end users. One interesting observation is that we no longer see any Diffie-Helman POST exchange to prevent replaying captured sessions for offline analysis. Additionally, there was a much larger number of C&C servers than we've previously observed, and some of the domain names seem to suggest multi-use hosts (e.g.: spam, bitcoin mining, etc). Note that none of the C&C servers are pseudo-randomly generated domains. ThreatLabZ will continue to track new developments with the Angler Exploit Kit.

Indicators of Compromise


Domain IP Address Description
cxda.gov[.]cn118.123.7.122Chinese government site
erteilend-taendelt.sewnydine[.]com104.129.192.32Angler Domain
repersuasionboldoblique.classactoutlet[.]com104.129.192.32Angler Domain
ayh2m57ruxjtwyd5.stopmigrationss[.]com95.128.181.195Payment Server
ayh2m57ruxjtwyd5.starswarsspecs[.]comfailedPayment Server
ayh2m57ruxjtwyd5.malerstoniska[.]com109.70.26.37,194.85.61.76Payment Server
ayh2m57ruxjtwyd5.blindpayallfor[.]com95.128.181.195Payment Server
flat.splo1t[.]ru188.127.239.164C&C connections
sanliurfapastanesi[.]com95.173.190.210C&C connections
wesalerx[.]xyz46.148.18.100C&C connections
urfakaplanticaret[.]com95.173.190.210C&C connections
taigastyle[.]ru37.140.192.180C&C connections
flickstudio[.]com103.21.59.22C&C connections
mydaycarewebsite[.]com104.24.102.98,104.24.103.98C&C connections
sampiyonvitamin[.]com95.173.190.210C&C connections
xmest.web-zolotareva[.]ru82.146.36.185C&C connections
aandwrentalspm[.]com142.4.6.13C&C connections
orucogluelektronik[.]com95.173.190.210C&C connections
gaja24[.]pl91.234.146.241C&C connections
developmysuccess[.]com50.30.46.201C&C connections
20dollarhomebusiness[.]com50.30.46.201C&C connections
rizvanogluhafriyat[.]com95.173.190.210C&C connections
sanliurfapastanesi[.]com95.173.190.210C&C connections
newatena[.]com95.173.190.210C&C connections
stalkerbanget[.]com68.65.120.182C&C connections
primevisionstudio[.]com192.185.206.97C&C connections
i-tem[.]ru62.173.143.242C&C connections
localuzzweb[.]com143.95.32.179C&C connections
getpostivemind[.]com158.85.170.253C&C connections
zemli72.chaukakau[.]ru62.173.143.242C&C connections
grandmedianetwork[.]com111.118.215.77C&C connections
karakoprudugunsalonu[.]com95.173.190.210C&C connections
sanliurfaparke[.]com95.173.190.210C&C connections
nsdstudio[.]net192.185.206.97C&C connections
meble-simone[.]eu91.234.146.241C&C connections
vsedveri33[.]ru81.177.165.33C&C connections
osk-wojcikiewicz[.]pl91.234.146.241C&C connections
love-deep[.]com111.118.215.77C&C connections
turizmkirov[.]ru82.146.36.185C&C connections
new.turizmkirov[.]ru82.146.36.185C&C connections
avtoreliv[.]com.ua91.234.34.80C&C connections
localwebsitepro[.]com192.185.41.191C&C connections
makrol[.]net91.234.146.241C&C connections
altopics[.]com111.118.215.77C&C connections
burnfatquicky[.]com184.168.221.57C&C connections
mediaopt33[.]ru81.177.165.33C&C connections
otmanad[.]com91.234.146.241C&C connections
markossolomon[.]com104.27.181.171,104.27.180.171C&C connections
kominki-gorlice[.]pl91.234.146.241C&C connections
chaukakau[.]ru62.173.143.242C&C connections
crm.ruhtech[.]com202.160.165.21C&C connections
takas3aya.xsrv[.]jp183.90.232.25C&C connections
famouswhiskybrands[.]com103.21.59.21C&C connections
edwardbrownjr[.]com50.30.46.201C&C connections
avatar77[.]ru62.173.143.242C&C connections
bollywoodupdate[.]net95.173.190.210C&C connections
asiaroyaldeveloper[.]com103.21.59.22C&C connections
asattyres[.]com192.185.206.97C&C connections
records.karika[.]in.ua91.234.34.80C&C connections
ppcprofitz[.]com143.95.32.180C&C connections
ecodeva[.]ru62.173.143.242C&C connections
btcdoubler[.]bizfailedC&C connections
18dollars1time[.]info50.30.46.201C&C connections
urfaeleganceoptik[.]com95.173.190.210C&C connections

Wednesday, September 23, 2015

An Update on Nuclear (Reverse) Engineering


Introduction

Although Angler continues to be the leading exploit kit, Nuclear is a significant threat to web surfers and seems to have been very active lately. ThreatLabZ recently encountered a Nuclear campaign originating from a variety of compromised sites. These compromises continue the trend of WordPress sites serving malcode, and in this case included the web-presence of a UK-based healthcare organization.

Example of recent Nuclear landing page to exploit cycle


The execution flow of this campaign is typical: an infected site includes an embedded iframe that loads the exploit kit landing page. The landing page checks the browser family and version and tests the available Flash version before choosing one of several exploit payloads. From here, multiple possible payloads may be downloaded, particularly Fareit Infostealer Trojan and Troldesh Ransomware Trojan.

Nuclear Landing

As covered recently, WordPress continues to be one of the most effective traffic sources for exploit kits. However, the majority of traffic we have seen does not feature the visitorTracker component, but merely includes a hidden iframe in the footer of the WordPress page.


The malicious iframe is preceded by a large number of blank lines


The iframe loads the landing page, which features obfuscated JavaScript and random-looking text blocks. It turns out that some of the random looking text blocks are actually obfuscated components that the JavaScript eventually deobfuscates and executes.


Lines 7 and 9 are overlaid with the script invocations that decode the HTML blocks


Nuclear Exploit Payloads

The landing pages we evaluated led to two possible Flash exploits as well as one Internet Explorer exploit. Specifically, we saw CVE-2015-5122 and CVE-2015-5560 exploits for Flash, and a highly obfuscated CVE-2014-6332 exploit for IE.

The first Flash payload stage checks Flash Player version and prepares the appropriate exploit

As noted by Kafeine, Nuclear has integrated the same Diffie-Hellman Angler first pioneered, only now it is implemented in Flash to protect the CVE-2015-5560 payload. This campaign also features an XTEA function with modified constants.

A Diffie-Hellman key exchange implementation is used to protect the new Flash payload

Besides making reverse engineers lives harder, the authors have also decided to include some friendly shoutouts to those analyzing their code. In the case of the featured Flash payloads, the string "fuckAV" is used as a special constant.


This function returns an XOR key when "fuckAV" is supplied as a parameter

Nuclear Fallout

Once the browser is exploited, Nuclear first drops a Fareit payload. Fareit is an infostealer, and as can be seen in the strings below, is looking to steal user credentials for multiple applications and websites as well as BitCoin wallet information.

A sample of the files and paths Fareit checks for user credentials


While stealing users information, Fareit attempts to hide its command and control communication by sending its check-in request in the midst of a batch of HTTP requests to innocuous looking websites.


After checking connectivity on MSN.com, multiple POSTs are performed

In addition to the Fareit payload, a Troldesh ransomware payload was also seen. Troldesh is yet another in the line of ransomware families that encrypt user files and attempt to extract a ransom payments in exchange for decryption keys. This campaign is using the email addresses files100005(at)gmail.com and files100006(at)gmail.com and the Tor address a4yhexpmth2ldj3v.onion.


Troldesh bundles a Tor proxy to protect its communication

Although they might prefer to infect the machines of non-analysts, the Troldesh author does take the opportunity to greet their reverse engineer friends. This message is less aggressive than the greeting in the Nuclear flash payload.


Thanks, but I don't drink coffee!

Conclusion

While Nuclear may not be the exploit kit that regularly debuts the latest advances, the authors certainly make an effort to keep up with new exploits and new obfuscation techniques. ThreatLabZ will continue to monitor Nuclear (and Fareit and Troldesh) for any new developments or greetings.



Appendix:

Indicators:





Thursday, August 20, 2015

Neutrino Campaign Leveraging WordPress, Flash for CryptoWall

Overview

Neutrino Exploit Kit (EK) appeared on the scene around March of 2013 and continues to remain active and incorporate new exploits. In the beginning of July, Neutrino reportedly incorporated the HackingTeam 0day (CVE-2015-5119), and in the past few days we've seen a massive uptick in the use of the kit. The cause for this uptick appears due to widespread WordPress site compromises.

ThreatLabZ started seeing a new campaign where WordPress sites running version 4.2 and lower were compromised, and the image below illustrates the components involved in this campaign.

Fig 1. Complete Neutrino WordPress campaign

In analyzing the infection cycle, there are multiple recent changes in the Neutrino code, some that are normally characteristics of Angler Exploit Kit, but others that remain unique to Neutrino.

WordPress Compromises

Similar to Angler Exploit Kit, the new wave of Neutrino is targeting outdated versions of WordPress. In fact, we have seen over 2600 unique WordPress sites being used in this campaign where more than 4200 distinct pages have been logged with dynamic iframe injection in the last month. As mentioned, all the targeted websites were running WordPress version 4.2 and lower.

Fig 2. Event timeline overview

The goal of this campaign is to completely and fully compromise the site, which includes adding a webshell, harvesting credentials, and finally injecting an iframe that loads a Neutrino landing page. The iframe is injected into the compromised site immediately after the BODY tag, and is almost identical to recent Angler samples. Compare these recent Neutrino and Angler samples below.

Fig 3. Neutrino on the left, Angler on the right

The code specifically targets Internet Explorer, so those using other browsers won't be served the iframe, and a cookie is used to prevent serving the iframe multiple times to the same victim.

The actual Neutrino landing pages are retrieved on the backend through the injected php code, a sample of which is below:

Fig 4. Injected php code

Note the base64 encoded value boxed in red above; this decodes to the URL below, where X, Y, and Z are integers:
http://93.171.205.64/blog/?bf4z&utm_source=XXXXX:YYYYYY:ZZZ
This URL is used to retrieve an updated landing page URL, and we've noted that the URLs change very frequently. Additionally, the primary IP hosting the majority of landing page domains is '185.44.105.7' which is owned by VPS2DAY.com. We reached out to them via email briefly explaining what we were seeing and received no response.

Neutrino Landing Page

The landing page has been updated and contains some JavaScript that only declares variables, and then a flash loader:

Fig 5. Neutrino landing page

If flash isn't installed on the victim machine, an old flash cab is pushed to the user prior to serving the malicious SWF. Note the departure from using base64 encoded data blobs, or really using very much code at all on the landing page.

Neutrino SWF

Past versions of the Neutrino SWF contained multiple exploit payloads encrypted via RC4. Examining this SWF shows that things have apparently changed as the structure is very different:

Fig 6. SWF structure

Taking a look at the code shows that instead of RC4, there is a decode function that uses the input of one binary data blob to decode a second binary blob; the decoded data reveals a second SWF:

Fig 7. Decode function for embedded SWF

Detection results for the SWF are very poor with only one vendor detecting it:

Fig 8. Poor detection results on SWF

Carving out the embedded SWF and analyzing it shows a much more familiar structure for Neutrino, with some additional enhancements. Notably similar is the use of multiple embedded binary blobs that are RC4 encrypted:

Fig 9. Binary data inside embedded SWF

Fig 10. Script data inside embedded SWF - characteristic of Neutrino

These binary blobs contain multiple payloads, and this has been analyzed and documented in the past, notably by Kafeine and Dennis O'Brien on Malwageddon. However, unlike past Neutrino SWFs, the RC4 keys are no longer in cleartext and decoding them requires tracing through multiple function calls. The ActionScript structure is still very recognizable though:

Fig 11. Decoder for one binarydata 'exploitWrapper' blob
Detection on the embedded SWF is also quite poor.
Fig 12. Embedded SWF VT detection

Payload

Successful exploitation of a victim leads to an encrypted executable download. The binary is decrypted and begins beaconing almost immediately:

Fig 13. Initial beacon summary
Fig 14. Full beacon/response sample

Looking at the traffic, we can immediately see this is CryptoWall 3.0. Sure enough, a couple minutes later we see the all too familiar 'HELP_DECRYPT' page and see connections out to the payment servers:

Fig 15. Payment server connections

Fig 16. CryptoWall 3.0 HELP_DECRYPT page

To read more about CryptoWall, please see our previous writeup here.

Campaign Information

As stated, the primary IP for the observed Neutrino landing pages is '185.44.105.7' which is owned by VPS2DAY.com. Many of the domains pointing to that IP utilize 'xyz', 'ga', 'gq', and 'ml' TLDs. Taking a look at the whois data for some of these domains, a common attribute seems to be the name 'Max Vlapet' for .XYZ domains. Full whois domain sample for completeness:

WHOIS MOHGROUP.XYZ

Domain Name: MOHGROUP.XYZ 
Domain ID: D9543161-CNIC 
WHOIS Server: whois.alpnames.com 
Referral URL: 
Updated Date: 2015-08-18T08:34:04.0Z 
Creation Date: 2015-08-18T08:34:03.0Z 
Registry Expiry Date: 2016-08-18T23:59:59.0Z 
Sponsoring Registrar: AlpNames Limited 
Sponsoring Registrar IANA ID: 1857 
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited 
Domain Status: serverTransferProhibited https://icann.org/epp#serverTransferProhibited 
Domain Status: addPeriod https://icann.org/epp#addPeriod 
Registrant ID: ALP_44867689 
Registrant Name: Max Vlapet 
Registrant Organization: N/A 
Registrant Street: Mausoleum str, pl.13 
Registrant City: Moscow 
Registrant State/Province: Moscow 
Registrant Postal Code: 123006 
Registrant Country: RU 
Registrant Phone: +7.4959826524 
Registrant Phone Ext: 
Registrant Fax: 
Registrant Fax Ext: 
Registrant Email: maxvlapet@gmail.com 
Admin ID: ALP_44867689 
Admin Name: Max Vlapet 
Admin Organization: N/A 
Admin Street: Mausoleum str, pl.13 
Admin City: Moscow 
Admin State/Province: Moscow 
Admin Postal Code: 123006 
Admin Country: RU 
Admin Phone: +7.4959826524 
Admin Phone Ext: 
Admin Fax: 
Admin Fax Ext: 
Admin Email: maxvlapet@gmail.com 
Tech ID: ALP_44867689 
Tech Name: Max Vlapet 
Tech Organization: N/A 
Tech Street: Mausoleum str, pl.13 
Tech City: Moscow 
Tech State/Province: Moscow 
Tech Postal Code: 123006 
Tech Country: RU 
Tech Phone: +7.4959826524 
Tech Phone Ext: 
Tech Fax: 
Tech Fax Ext: 
Tech Email: maxvlapet@gmail.com 
Name Server: NS2.MOHGROUP.XYZ 
Name Server: NS1.MOHGROUP.XYZ 
DNSSEC: unsigned 
Billing ID: ALP_44867689 
Billing Name: Max Vlapet 
Billing Organization: N/A 
Billing Street: Mausoleum str, pl.13 
Billing City: Moscow 
Billing State/Province: Moscow 
Billing Postal Code: 123006 
Billing Country: RU 
Billing Phone: +7.4959826524 
Billing Phone Ext: 
Billing Fax: 
Billing Fax Ext: 
Billing Email: maxvlapet@gmail.com 
>>> Last update of WHOIS database: 2015-08-19T00:44:12.0Z <<< 

Unfortunately, very little information is available for the other TLDs in use. The backend IP serving new landing page URLs is registered to a company called 'VDS INSIDE' located in Ukraine.

A dump of the 700+ malicious domains and/or landing pages we've collected is on pastebin: http://pastebin.com/946rPaGx

Conclusion

WordPress, being a widely popular and free Content Management System (CMS), remains one of the most attractive targets for cyber criminals.  WordPress compromises are not new, but this campaign shows an interesting underground nexus starting with backdoored WordPress sites, a Neutrino Exploit Kit-controlled server, and the highly effective CryptoWall ransomware. This campaign also reconfirms that Neutrino Exploit Kit activity is on the rise and is still a major player in the exploit kit arena.

ThreatLabZ is actively monitoring this campaign and ensuring that Zscaler customers are protected.

Acknowledgement

Special thanks to Dhruval Gandhi for profiling compromised WordPress sites

Write-up by: John Mancuso, Deepen Desai



Monday, May 18, 2015

Magnitude Exploit Kit leading to Ransomware via Malvertising

Magnitude Exploit Kit is a malicious exploit package that leverages a victim’s vulnerable browser plugins in order to download a malicious payload to a system.  This technique is known as a drive-by-download attack, which is often leveraged on compromised websites and malicious advertising networks.

We recently found a number of compromised pages following the structure of fake search engine pages. The following sites have been seen to redirect to malicious content:

  • hymedoraw[dot]com/search[dot]php
  • awerdeall[dot]com/search[dot]php
  • index-html[dot]com/
  • joomla-green[dot]com/
  • bestcool-search[dot]com/
  • joyo-search[dot]com/
  • megas-search[dot]com/
  • speeds-search[dot]com/
  • sample-data[dot]com/
  • lazy-summer[dot]com/
  • tundra-search[dot]com/
  • death-tostock[dot]com/
  • adoncorst[dot]com/search[dot]php
  • demo-content[dot]com/
  • enable-bootstrap[dot]com/
  • rospecoey[dot]com/search[dot]php
  • aranfleds[dot]com
  • adoncorst[dot]com/search[dot]php
  • malpithia[dot]com/search[dot]php
  • noutademn[dot]com/search[dot]php
We've also seen a high volume of Malvertising activity leading to Magnitude Exploit Kit hosting sites. The biggest offender of this Malveritising activity is from "click2.systemaffiliate.com" operated by the ad network Sunlight Media, as seen in the list below:
  • click2[dot]systemaffiliate[dot]com/filter/?keyword=Area+Rugs+Cleaning+hotels+for+sale+by+owner
    • b7b6o[dot]y2ff[dot]3b1f767u[dot]dc[dot]3d478d[dot]t97a2as[dot]pdf0q[dot]zf1[dot]eaq6907579[dot]hatentries[dot]in/?17657271747b7e747c2539646e6463727a7671717e7b7e7663723974787a
  • click2[dot]systemaffiliate[dot]com/filter/?keyword=backhoes+for+sale+Granite+Counter+Tops
    • nd4e61i[dot]0fedz[dot]i9390[dot]11f[dot]b8e0[dot]c1i[dot]51aa8a5x[dot]b22n[dot]z1037n6z[dot]rulesreturning[dot]in/?3f4d5a595c53565c540d114c464c4b5a525e59595653565e4b5a115c5052
  • click2[dot]systemaffiliate[dot]com/filter/?keyword=direct+tv+dallas+tx+financial+services+companies
    • kfb39c[dot]ec526[dot]k149t[dot]13f44d[dot]gfb9820[dot]q5c[dot]c778eg[dot]c47b0v3diz2[dot]backedmisuse[dot]in/?1567707376797c767e273b666c666170787473737c797c7461703b767a78
  • click2[dot]systemaffiliate[dot]com/filter/?keyword=business+processes+management+Metaire+Construction+Management+Service
    • a19602cr[dot]773a9be[dot]bd407edi[dot]m602f890[dot]wfd6b[dot]eay836h7h[dot]bytessounds[dot]in/?3a485f5c595653595108144943494e5f575b5c5c5356535b4e5f14595557
  • click2[dot]systemaffiliate[dot]com/filter/?keyword=michelin+tire+Shingle+Roofer
    • 0eeda91z[dot]w8cb575d[dot]b8[dot]s247[dot]maf35794i[dot]q9b[dot]yc79p[dot]b[dot]y7siiy61xy[dot]bytessounds[dot]in/?295b4c4f4a45404a421b075a505a5d4c44484f4f404540485d4c074a4644
  • click2[dot]systemaffiliate[dot]com/filter/?keyword=compact+suv+internet+hosting+company
    • u0b49r[dot]b9l[dot]r76783b2i[dot]ce01s[dot]k25o[dot]8f3t[dot]w32[dot]1d1dl[dot]u63g[dot]s45t[dot]xk6z4x0ok4[dot]isessentially[dot]in/?3f4d5a595c53565c540d114c464c4b5a525e59595653565e4b5a115c5052
  • click2[dot]systemaffiliate[dot]com/filter/?keyword=hotel+prices+Air+Duct+Cleaning+Service
    • za46[dot]1375623[dot]e53cb4[dot]2014[dot]50ebd[dot]t1c06f[dot]61[dot]y7f8vkub0[dot]safelyinstall[dot]in/?16647370757a7f757d2438656f6562737b7770707f7a7f7762733875797b
  • click2[dot]systemaffiliate[dot]com/filter/?keyword=supercuts+coupons+sales+presentation+equipment
    • 01e717[dot]i06917c[dot]36f5[dot]j056[dot]m66a[dot]176f3f[dot]5ej[dot]p6e[dot]h2xb793w17[dot]safelyinstall[dot]in/?285a4d4e4b44414b431a065b515b5c4d45494e4e414441495c4d064b4745
  • click2.systemaffiliate[dot]com/filter/?keyword=free+latest+accounting+software+Laptops
    • of62b8a[dot]x43f292x[dot]a674q[dot]r5ec03a[dot]y01c9b[dot]f7367u[dot]cgh63008[dot]husbandhides[dot]in/?3f4d5a595c53565c540d114c464c4b5a525e59595653565e4b5a115c5052
  • click2[dot]systemaffiliate[dot]com/filter/?keyword=marine+equipment+and+supply+company+real+esate+hotline
    •  g1812c47[dot]t6060f09l[dot]t74711a[dot]m69131[dot]l88[dot]z874f0h[dot]b88z8j4s31ji[dot]husbandhides[dot]in/?2b594e4d484742484019055852585f4e464a4d4d4247424a5f4e05484446
The Malvertising networks lead to redirector domains utilizing 302 cushioning. Our recent data shows the following redirector domains to have been heavily utilized:

  • paypal-invest[.]net
  • paypal-invest[.]info
  • paypal-invest[.]biz

Following the 302 redirect, Magnitude delivers both a malicious Flash payload as well as a highly obfuscated JavaScript payload (MS13-009 Microsoft Internet Explorer COALineDashStyleArray Integer Overflow exploit). Once the browser has been exploited, Magnitude proceeds to a new step in the infection cycle where the malware payload would normally be downloaded immediately following exploitation, we are now seeing a shellcode payload being served.


Shellcode being served

The shellcode is a simple payload that utilizes the Windows library ‘urlmon.dll’ to attempt to fetch a list of URLs contained within the shellcode. In the cases we have seen so far, only the first URL results in a payload (CryptoWall 3.0), while the others return no data.

CryptoWall payload download

This is a highly profitable ransomware payload that leverages Bitcoin transactions executed over the Tor Anonymizer to monetize the attack. Threat Actors utilize this method of collection because it can't be reliably traced back to the them. Victims are especially vulnerable to this type of extortion since very few people seem to backup their critical files such as documents and pictures.

CryptoWall decryption instruction

ThreatLabZ has been actively monitoring this Magnitude EK activity and the image below illustrates the transactions we saw for this campaign:


The Green represents Payload activity; The Blue represents Landing Page activity.

As with most threat actors, once they find a location that allows them to host their attacks they tend to stick with it. The lion's share of target IPs seen from our research show that Germany is the biggest hosting location for this activity.


Other countries seen to host this activity: NL (3%) US(2%) JP(2%)

Conclusion
Exploit Kits are evolving to bypass standard security solutions that utilize basic URL filtering techniques. Attackers are utilizing various methods of infection, including malvertising and iFrame injection on compromised pages. Ransomware is a highly profitable, recording up to $33,000 per day at one point. The sophistication of these attacks are on the rise and security leaders need to keep apprised of this maturing illegal market.

Analysis done by Edward Miles & Chris Mannon