Showing posts with label Vawtrak. Show all posts
Showing posts with label Vawtrak. Show all posts

Friday, January 9, 2015

Chanitor Downloader actively installing Vawtrak

We at ThreatLabZ are keeping an eye on a fairly active downloader called Chanitor. This malware is being delivered via phishing emails purporting to be "important" documents, for example, voicemails, invoices, and faxes; all are actually screensaver executables with the extension ‘.scr’. Another unique feature of this downloader Trojan family is the usage of tor2web.org and tor2web.ru over SSL for its Command & Control (C2) communication.

Upon execution, Chanitor copies itself to ‘%APPDATA%\Roaming\Windows\winlogin.exe’ by running the following command:

cmd /D /R type "C:\<path-to-binary>\winlogin.exe" > ___ && move /Y ___ "C:\Users\<username>\AppData\Roaming\Windows\winlogin.exe"

It then waits for a few seconds before deleting the original file, and executes the copy via the following command:


cmd /D /R ping -n 10 localhost && del "C:\<path to original exe>" && start /B "" "C:\Users\<username>\AppData\Roaming\Windows\winlogin.exe" && exit


Once the command executes, it creates a registry entry for persistence:



Chanitor encrypts some key components like C2 server locations that is decrypted only when used on run time. For example, "tor2web.org" is decrypted using a xor loop:



The next step is enumeration of functions for making outbound SSL connections and making connections to the command and control server. These connections are shown in the screenshot below.



The first connection (#1 above) is to retrieve the public IP of the infected host. The success or failure of this request isn’t checked though, so the next request happens regardless. This request (#2) is a beacon to the command and control server on TOR via tor2web.org. Chanitor uses SSL for all communication and beacons via POST requests to /gate.php. If the request is successful, the C2 server will provide further instructions which during our analysis was to download additional binary payload. The download is shown in session #3 above. Once the download finishes, there is a subsequent beacon which presumably means success (#4). Strangely enough, there is a failed request to tor2web.ru (#5). This domain does not exist, so the purpose of this request is unknown.

The screenshot below shows detail of the initial beacon (#2) and server response to download a stage 2 binary:



Each beacon takes the following form:
{<MALWARE GENERATED UNIQUE IDENTIFIER>}<SHORT STRING><4 SPACE PADDING>}<USERDOMAIN><58 SPACE PADDING>}<IP ADDRESS>


If the request to api.ipify.org is unsuccessful, the IP address will be the machine's RFC1918 address instead of a public IP. The C2 server replies with an instruction to download a file (highlighted in red above) and the download is initiated immediately. The beacon information, with the exception of the IP address, is also stored in the registry:



After downloading and reporting success, the original binary will then sleep for approximately 5 minutes (there's some variation for slightly longer and slightly shorter) before beaconing again:




Downloaded Binary

The downloaded binary is a dropper Trojan and is saved as C:\Users\<username>\AppData\Local\Temp\__<4 alphanumeric characters>.exe. Chanitor will run the downloaded payload via the following command:

cmd /D /R start /B "" "C:\Users\<username>\AppData\Local\Temp\___16AE.exe" && exit

Upon execution, the binary checks for the presence of a debugger. If no debugger is found, the binary then unpacks an embedded DLL and writes it to disk. This DLL is a new variant of the Vawtrak Trojan.






The DLL is registered with regsvr32.exe via the following command to ensure persistence:


The Vawtrak dropper Trojan then deletes itself from the target system. The Vawtrak dropper binary and the DLL are compressed using aPLib v1.01 library as seen below:




Vawtrak, also known as NeverQuest and Snifula, is a powerful information stealing backdoor Trojan that has been gaining momentum over past few months. It primarily targets user's bank account via online banking websites.

Indicators of Compromise

C2 Domains
https://svcz25e3m4mwlauz.tor2web[.]org/gate.php
https://ho7rcj6wucosa5bu.tor2web[.]org/gate.php
https://o3qz25zwu4or5mak.tor2web[.]org/gate.php
https://lctoszyqpr356kw4.tor2web[.]org/gate.php


File Locations
C:\Users\<username>\AppData\Roaming\Windows\winlogin.exe
C:\ProgramData\TigaPjopw\VofcOhhel.zvv -- these names appear random
C:\Users\<username>\AppData\Local\Temp\~004BFD62.tmp -- this name appears random
C:\Users\<username>\AppData\Local\Temp\___16AE.exe -- this name appears random

Conclusions

The samples collected date back to the beginning of October 2014 and have changed in measurable ways over the past few months. The first samples would not run on Windows 7 unless in compatibility mode, required administrative privileges, and did not have icons that matched the purported filetype or theme, but the recent samples have evolved to run without errors and appear to be more refined. We attempted to contact tor2web at abuse@tor2web.org and at info@tor2web.org and received bouncebacks followed a few days later by a delivery failure notification. Since the C2 servers are hosted on TOR, tracking the individuals behind this campaign may prove difficult, but blocking access to tor2web would be effective for the time being.



Sunday, December 21, 2014

Compromised Wordpress sites serving multiple malware payloads

During our daily log monitoring process, we observe many interesting threat events. One such event led to a compromised WordPress site campaign, which was found to serve multiple malware families including Upatre/Hencitor/Extrat Xtreme RAT/Vawtrak. The URLs which were serving malware were found to adhere to a particular pattern. Infected WordPress sites observed, included URLs with "/1.php?r”. Emerging Threats (ET) had previously released a Snort signature for this campaign on 12/08/2014. Since then, we have been continuously monitoring the activities related to it. The following is the snort signature released by ET.
 
Snort Signature
alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET
CURRENT_EVENTS Probable malicious download from e-mail link /1.php";
flow:established,to_server; urilen:8; content:"/1.php?r"; http_uri;
content:!"Referer|3a 20|"; http_header;
flowbits:set,et.exploitkitlanding; classtype:bad-unknown; sid:2019894;
rev:1;)

Below are the compromised websites observed, which have been found to be serving multiple malware families.

Compromised wordpress websites
airlessspraysupplies[.]com/wp-includes/1[.]php?r
altero[.]be/1[.]php?r
alzina[.]cat/1[.]php?r
angeladoesfood[.]com/wp-admin/1[.]php?r
apsmiles[.]com/wp-content/themes/rfx/1[.]php?r
architecture[.]web[.]auth[.]gr/1[.]php?r
augustgifford[.]com/wp-admin/1[.]php?r
bankruptcy-software[.]com/wp-content/themes/classic/1[.]php?r
bernie[.]jshall[.]net/wp-content/themes/twentytwelve/1[.]php?r
beta[.]pescariusports[.]ro/images/1[.]php?r
blackwellanddenton[.]com/components/com_contact/1[.]php?r
blog[,]longboardsicecream[.]com/wp-content/plugins/1[.]php?r
blog[.]ridici-jednotky[.]cz/wp-content/plugins/simple4us/1[.]php?r
blog[.]topdealslondon[.]com/wp-content/uploads/1[.]php?r
cartorioalbuquerque[.]com[.]br/images/1[.]php?r
climatechange[.]mobi/images/1[.]php?r
core[.]is/1[.]php?r
couponshare[.]me/1[.]php?r
dannygill[.]co[.]uk/wp-content/plugins/simple4us/1[.]php?r
dlaciebie[.]org/wp-admin/1[.]php?r
geototal[.]az/en/ru/engine/editor/scripts/common/codemirror/mode/xml/1[.]php?r
kba1f9684c70[.]nazwa[.]pl/images/1[.]php?r
linkleads[.]vn/1[.]php?r
lionel[.]my/wp-content/plugins/akismet/1[.]php?r
livedoor[.]eu/1[.]php?r
ludovicharollais[.]org/wp-admin/1[.]php?r
m11[.]mobi/images/1[.]php?r
matthewkarant[.]com/wp-content/themes/twentynine/1[.]php?r
mcymbethel[.]com[.]ar/modules/mod_ariimageslider/1[.]php?r
merklab[.]eu/1[.]php?r
mitoyotaseagarrota[.]com/components/com_banners/1[.]php?r
mlmassagetherapy[.]com[.]au/wp-content/uploads/1[.]php?r
monitoring[.]sensomedia[.]hu/1[.]php?r
newwww[.]r11mis[.]be/images/1[.]php?r
odelia-coaching[.]co[.]il/wp-content/plugins/google-sitemap-generator/1[.]php?r
odelia-coaching[.]co[.]il/wp-content/plugins/google-sitemap-generator/1[.]php?r
osp[.]ruszow[.]liu[.]pl/images/1[.]php?r
pms[.]isovn[.]net/images/1[.]php?r
prodvizhenie-sajta[.]com/images/1[.]php?r
redmine[.]sensomedia[.]hu/1[.]php?r
salihajszalon[.]hu/1[.]php?r
sonicboommusic[.]com[.]au/components/com_banners/1[.]php?r
sparkledesign[.]ro/1[.]php?r
thebestcookbooks[.]co[.]uk/wp-content/plugins/1[.]php?r
thefoodstudio[.]co[.]nz/wp-content/themes/food-cook/1[.]php?r
thietkekientruca4[.]vn/1[.]php?r
treasurething[.]com/wp-includes/pomo/1[.]php?r
tsv-penzberg[.]de/wp-admin/1[.]php?r
turbomarketingteam[.]com/1[.]php?r
tusengangerstarkare[.]ingelaclarin[.]se/wp-admin/1[.]php?r
twobyones[.]com/1[.]php?r
xhmeiastokyma[.]gr/1[.]php?r
youreverlastingmemories[.]co[.]uk/1[.]php?r

These compromised WordPress sites may have been used by Exploit Kit (EK) authors as drop sites for serving malware. Another potential attack vector could involve email spam.
The following table shows different types of malware we have seen dropped from the aforementioned compromised sites. All malware was found to be zipped.
 
ZIP MD5ZIPFILE NAME
2f225283c66032c9f7dcb44f42697246fax_20141204_385.pdf.zip
6696527bfda97b1473d1047117ded8d6invoice.pdf.zip
93babef06bfd93bcbb5065c445fb57d4label_08122014_23.pdf.zip
bea9be813bb7df579d5be3e4543dc6a4payment_details9427923.pdf.zip
1159fe7ec4d0b2cfde57dfb28b98f0c9ePackage_12092014_42.pdf.zip
038710b2029046c39ca4082e2c34f9b3wav_voice20141208.zip
ec35acdbe331c73e5e6883ebc08f896dpayment_invoice_182734.pdf.zip
8f00cfdf067b01462670212ba5874cdbpdf_efax_9823612397.zip

Lets take a look at the files after unzipping them. All of the files are Windows screen savers and include fake icons of legitimate software packages, to persuade the victims to click on them.

Downloaded files:


For this post we've chosen to focus on the Hencitor malware. Hencitor’s typical behavior is to download additional malware onto the victim’s machine and execute it. 

MD5: 6bb3b23ff3e736d499775120aa8d6ae2
VT Score: 9/56 (At the time of analysis)

Lets take a look at some important things noted while conducting dynamic analysis of this malware.
  • Copies itself to 
    • "C:\Users\Win7 64Bit\AppData\Roaming\Windows\winlogin.exe”
  • Creates autostart registry key entry
    • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run
      • "winlogin” = "C:\Users\Win7 64Bit\AppData\Roaming\Windows\winlogin.exe”
  • Uses ping.exe to check the status of other devices and networks.
    • cmd /D /R ping -n 10 localhost && del C:\payment_invoice_182734.pdf.scr.exe && start /B C:\Users\Win7 64Bit\AppData\Roaming\Windows\winlogin.exe && exit
  • Creates a thread in following existing process on the system.
    • C:\Windows\explorer.exe
    • C:\Windows\System32\sppsvc.exe
    • C:\Windows\System32\wbem\WmiPrvSE.exe
    • C:\Windows\System32\conhost.exe
  • Deletes itself after installation 
    • c:\payment_invoice_182734.pdf.scr.exe
  • Malware seen to resolve couple of suspicious tor sites. 
    • o3qz25zwu4or5mak.tor2web[.]org 
    • o3qz25zwu4or5mak.tor2web[.]ru 
Conclusion:
Compromising vulnerable WordPress sites to spread malware has become one of the more widely used attack vectors by EK’s and email spam campaigns. Such campaigns generally drop variants of well known malware families,  which are undetected by the AV vendors. By the time of analysis we observed poor detection rates for the malware samples involved in this campaign.

-Stay Safe