<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AlienVault Labs</title>
	<atom:link href="http://labs.alienvault.com/labs/index.php/feed/" rel="self" type="application/rss+xml" />
	<link>http://labs.alienvault.com/labs</link>
	<description>AlienVault R&#38;D Labs Portal. Get the latest news from our research.</description>
	<lastBuildDate>Sun, 05 May 2013 10:09:38 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>New Internet Explorer zeroday was used in the DoL Watering Hole campaign</title>
		<link>http://labs.alienvault.com/labs/index.php/2013/new-internet-explorer-zeroday-was-used-in-the-dol-watering-hole-campaign/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-internet-explorer-zeroday-was-used-in-the-dol-watering-hole-campaign</link>
		<comments>http://labs.alienvault.com/labs/index.php/2013/new-internet-explorer-zeroday-was-used-in-the-dol-watering-hole-campaign/#comments</comments>
		<pubDate>Sun, 05 May 2013 10:09:38 +0000</pubDate>
		<dc:creator>jaime.blasco</dc:creator>
				<category><![CDATA[Advisory]]></category>
		<category><![CDATA[APT]]></category>
		<category><![CDATA[Attacks]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[CVE-2013-1347]]></category>

		<guid isPermaLink="false">http://labs.alienvault.com/labs/?p=2264</guid>
		<description><![CDATA[A few days ago we reported a new Watering Hole campaign affecting a U.S Department of Labor website. In our first analysis we reported that the exploited vulnerability was CVE-2012-4792 . Further analysis showed that the vulnerability exploited wasn&#8217;t CVE-2012-4792 but a new zeroday vulnerability affecting Internet Explorer 8 (CVE-2013-1347). It was confirmed by Microsoft that released a &#8230; <a href="http://labs.alienvault.com/labs/index.php/2013/new-internet-explorer-zeroday-was-used-in-the-dol-watering-hole-campaign/">Read more <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>A few days ago <a title="http://labs.alienvault.com/labs/index.php/2013/u-s-department-of-labor-website-hacked-and-redirecting-to-malicious-code/" href="http://labs.alienvault.com/labs/index.php/2013/u-s-department-of-labor-website-hacked-and-redirecting-to-malicious-code/">we reported a new Watering Hole campaign affecting a U.S Department of Labor website.</a></p>
<p>In our first analysis we reported that the exploited vulnerability was <a title="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-4792" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-4792">CVE-2012-4792 </a>. Further analysis showed that the vulnerability exploited wasn&#8217;t <a title="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-4792" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-4792">CVE-2012-4792</a> but a new zeroday vulnerability affecting Internet Explorer 8 (CVE-2013-1347). It was confirmed by <a title="http://technet.microsoft.com/en-us/security/advisory/2847140" href="http://technet.microsoft.com/en-us/security/advisory/2847140">Microsoft that released a Security Advisory on Friday</a> and also <a title="http://www.fireeye.com/blog/technical/cyber-exploits/2013/05/ie-zero-day-is-used-in-dol-watering-hole-attack.html" href="http://www.fireeye.com/blog/technical/cyber-exploits/2013/05/ie-zero-day-is-used-in-dol-watering-hole-attack.html">FireEye</a> and <a title="http://www.invincea.com/2013/05/part-2-us-dept-labor-watering-hole-pushing-poison-ivy-via-ie8-zero-day/" href="http://www.invincea.com/2013/05/part-2-us-dept-labor-watering-hole-pushing-poison-ivy-via-ie8-zero-day/">Invincea</a>.</p>
<p>In addition we have found that the U.S Department of Labor website wasn&#8217;t the only entity affected and we can confirm that at least 9 other websites were redirecting to the malicious server at the same time. The list of affected sites includes several non-profit groups and institutes as well as a big european company that plays on the aerospace, defence and security markets.</p>
<p>Finally we detected several redirections to another malicious server located at www[.]sellagreement[.]com (198.96.92.107) that was serving parts of the malicious payloads found on dol[.]ns01[.]us.</p>
<p>We recommend you to search your logs for connections to those domains and IP addresses.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div class="simple_likebuttons_container_small">
      <div class="simple_likebuttons_googleplus">
        <g:plusone size="medium" count="false" href="http://labs.alienvault.com/labs/index.php/2013/new-internet-explorer-zeroday-was-used-in-the-dol-watering-hole-campaign/"></g:plusone>
      </div>
    
      <div class="simple_likebuttons_twitter simple_likebuttons_twitter_s">
        <a href="https://twitter.com/share" class="twitter-share-button" data-count="none" data-url="http://labs.alienvault.com/labs/index.php/2013/new-internet-explorer-zeroday-was-used-in-the-dol-watering-hole-campaign/" data-lang="en">Tweet</a>
      </div>
    </div>]]></content:encoded>
			<wfw:commentRss>http://labs.alienvault.com/labs/index.php/2013/new-internet-explorer-zeroday-was-used-in-the-dol-watering-hole-campaign/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>U.S. Department of Labor website hacked and redirecting to malicious code</title>
		<link>http://labs.alienvault.com/labs/index.php/2013/u-s-department-of-labor-website-hacked-and-redirecting-to-malicious-code/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=u-s-department-of-labor-website-hacked-and-redirecting-to-malicious-code</link>
		<comments>http://labs.alienvault.com/labs/index.php/2013/u-s-department-of-labor-website-hacked-and-redirecting-to-malicious-code/#comments</comments>
		<pubDate>Wed, 01 May 2013 13:15:52 +0000</pubDate>
		<dc:creator>jaime.blasco</dc:creator>
				<category><![CDATA[APT]]></category>
		<category><![CDATA[Attacks]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[CVE-2012-4792]]></category>
		<category><![CDATA[deep panda]]></category>

		<guid isPermaLink="false">http://labs.alienvault.com/labs/?p=2236</guid>
		<description><![CDATA[During the last few hours we have identified that one the U.S. Department of Labor website has been hacked and it is serving malicious code. Clarification: The website affected is the The Department of Labor (DOL) Site Exposure Matrices (SEM) Website  &#8220;The Department of Labor (DOL) Site Exposure Matrices (SEM) Website is a repository of information gathered from &#8230; <a href="http://labs.alienvault.com/labs/index.php/2013/u-s-department-of-labor-website-hacked-and-redirecting-to-malicious-code/">Read more <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>During the last few hours we have identified that one the U.S. Department of Labor website has been hacked and it is serving malicious code.</p>
<p><strong>Clarification:</strong></p>
<p><strong>The website affected is the The Department of Labor (DOL) Site Exposure Matrices (SEM) Website </strong></p>
<p>&#8220;The Department of Labor (DOL) Site Exposure Matrices (SEM) Website is a repository of information gathered from a variety of sources regarding toxic substances present at Department of Energy (DOE) and Radiation Exposure Compensation Act (RECA) facilities covered under Part E of the Energy Employees Occupational Illness Compensation Program Act (EEOICPA)&#8221;</p>
<p>As you can see in the following <a title="http://urlquery.net/report.php?id=2259188" href="http://urlquery.net/report.php?id=2259188">UrlQuery report</a> the website is including code from the malicious server dol[.]ns01[.]us:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/domain_graph.gif"><img class="aligncenter size-full wp-image-2237" alt="domain_graph" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/domain_graph.gif" width="424" height="189" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Once you visit the website the following file is included:</p>
<p>www[.]sem[.]dol[.]gov/scripts/textsize.js that contains the following code:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-13.47.17.png"><img class="aligncenter size-large wp-image-2238" alt="Captura de pantalla 2013-05-01 a la(s) 13.47.17" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-13.47.17-1024x450.png" width="590" height="259" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>The browser will then execute a script from the malicious server dol[.]ns01[.]us:8081/web/xss.php</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-15.11.14.png"><img class="aligncenter size-medium wp-image-2253" alt="Captura de pantalla 2013-05-01 a la(s) 15.11.14" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-15.11.14-300x56.png" width="300" height="56" /></a></p>
<p>&nbsp;</p>
<p><a title="http://labs.alienvault.com/labs/index.php/projects/open-source-ip-reputation-portal/information-about-ip/?ip=96.44.136.115" href="http://labs.alienvault.com/labs/index.php/projects/open-source-ip-reputation-portal/information-about-ip/?ip=96.44.136.115">http://labs.alienvault.com/labs/index.php/projects/open-source-ip-reputation-portal/information-about-ip/?ip=96.44.136.115</a></p>
<p>The script will collect a lot of information from the system and then it will upload the information collected to the malicious server. Some of the functions to collect information are:</p>
<p>flashver(): This function will collect information about the Flash software running on the system, including versions and OS details</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-13.58.18.png"><img class="aligncenter size-medium wp-image-2239" alt="Captura de pantalla 2013-05-01 a la(s) 13.58.18" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-13.58.18-300x183.png" width="300" height="183" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><!--StartFragment-->bitdefender2012check() and disabledbitdefender_2012(): The function will try to determine if BitDefender is running on the system checking for the injected code (netdefender/hui/ndhui.js) on the HTML of the webpage and it will try to deactivate the AV.</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.02.13.png"><img class="aligncenter size-medium wp-image-2240" alt="Captura de pantalla 2013-05-01 a la(s) 14.02.13" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.02.13-300x160.png" width="300" height="160" /></a></p>
<p><!--StartFragment-->avastcheck(): It checks if Avast Antivirus is running on the system detecting the presence of the Chrome extension:<!--EndFragment--></p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.04.53.png"><img class="aligncenter size-large wp-image-2241" alt="Captura de pantalla 2013-05-01 a la(s) 14.04.53" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.04.53-1024x181.png" width="590" height="104" /></a></p>
<p><!--EndFragment--></p>
<p>&nbsp;</p>
<p><!--StartFragment-->aviracheck(): It checks if Avira Antivirus is running on the system detecting the presence of the Chrome extension:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.06.19.png"><img class="aligncenter size-large wp-image-2242" alt="Captura de pantalla 2013-05-01 a la(s) 14.06.19" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.06.19-1024x161.png" width="590" height="92" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><!--StartFragment-->java(): It collects information about Java versions running on the system</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.08.23.png"><img class="aligncenter size-medium wp-image-2243" alt="Captura de pantalla 2013-05-01 a la(s) 14.08.23" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.08.23-300x167.png" width="300" height="167" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><!--StartFragment-->officever(): It collects information about Microsoft Office versions installed on the system<!--EndFragment--></p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.10.37.png"><img class="aligncenter size-medium wp-image-2244" alt="Captura de pantalla 2013-05-01 a la(s) 14.10.37" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.10.37-300x76.png" width="300" height="76" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><!--StartFragment-->plugin_pdf_ie(): It detects if Adobe Reader is installed in the system calling Acrobat Reader&#8217;s ActiveX object:<!--EndFragment--></p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.11.34.png"><img class="aligncenter size-medium wp-image-2245" alt="Captura de pantalla 2013-05-01 a la(s) 14.11.34" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.11.34-300x108.png" width="300" height="108" /></a></p>
<p>&nbsp;</p>
<p>jstocreate(): It detects if the system is running one of the following Antivirus:</p>
<ul>
<li>avira</li>
<li>bitdefender_2013</li>
<li>mcafee_enterprise</li>
<li>avg2012</li>
<li>eset_nod32</li>
<li>Dr.Web</li>
<li>Mse</li>
<li>sophos</li>
<li>f-secure2011</li>
<li>Kaspersky_2012</li>
<li>Kaspersky_2013</li>
</ul>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.14.23.png"><img class="aligncenter size-medium wp-image-2246" alt="Captura de pantalla 2013-05-01 a la(s) 14.14.23" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.14.23-300x190.png" width="300" height="190" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Once all the information has been collected it sends the data to the following URL using a POST request:</p>
<p><!--StartFragment-->dol[.]ns01[.]us:8081/web/js[.]php<!--EndFragment--></p>
<p>An example of the information collected is as follow:</p>
<p>Shockwave Flash 11.6.602,No Java or Disable or user uninstall it(if plugins have java)!,Avast!,Shockwave Flash(Name:NPSWF32_11_6_602_180.dll{Ver:11.6.602.180}),AVG SiteSafety plugin(Name:npsitesafety.dll{Ver:14.2.0.1}),MindSpark Toolbar Platform Plugin Stub(Name:NP4zStub.dll{Ver:1.0.1.1}),TelevisionFanatic Installer Plugin Stub(Name:NP64EISb.dll{Ver:1.0.0.1}),MinibarPlugin(Name:npMinibarPlugin.dll{Ver:1.0.0.1}),Photo Gallery(Name:NPWLPG.dll{Ver:16.4.3505.912}),Yahoo Application State Plugin(Name:npYState.dll{Ver:1.0.0.7}),Silverlight Plug-In(Name:npctrl.dll{Ver:5.1.10411.0}),Microsoft Office 2010(Name:NPSPWRAP.DLL{Ver:14.0.4761.1000}),Microsoft Office 2010(Name:NPAUTHZ.DLL{Ver:14.0.4730.1010}),Microsoft® Windows Media Player Firefox Plugin(Name:np-mswmp.dll{Ver:1.0.0.8}),PDF-XChange Viewer(Name:npPDFXCviewNPPlugin.dll{Ver:2.5.200.0})</p>
<p>Some of the techniques used in this attack are very similar to the ones we identified a few months ago in an attack against a Thailand NGO website:</p>
<p><a title="http://labs.alienvault.com/labs/index.php/2012/thailand-ngo-site-hacked-and-serving-malware/" href="http://labs.alienvault.com/labs/index.php/2012/thailand-ngo-site-hacked-and-serving-malware/">Thailand NGO site hacked and serving malware</a></p>
<p><a title="http://labs.alienvault.com/labs/index.php/2012/thailand-ngo-site-hacked-and-serving-malware/" href="http://labs.alienvault.com/labs/index.php/2012/thailand-ngo-site-hacked-and-serving-malware/"><!--EndFragment--></a></p>
<p>After sending the information about the system the following request is also made:</p>
<p>dol[.]ns01[.]us:8081/update/index.php</p>
<p>After analyzing that file we found the following function:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.33.09.png"><img class="aligncenter size-large wp-image-2247" alt="Captura de pantalla 2013-05-01 a la(s) 14.33.09" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.33.09-1024x220.png" width="590" height="126" /></a></p>
<p>If we decode the eval string we find:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.34.54.png"><img class="aligncenter size-medium wp-image-2248" alt="Captura de pantalla 2013-05-01 a la(s) 14.34.54" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.34.54-300x189.png" width="300" height="189" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>After a quick analysis it seems the malicious server is exploiting CVE-2012-4792 that was fixed earlier this year. We are still verifying this information and we will give you more details when we confirm the vulnerability exploited is CVE-2012-4792.</p>
<p>Once the vulnerability is exploited the system will download the payload from dol[.]ns01[.]us:8081/update/bookmark.png:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.39.24.png"><img class="aligncenter size-medium wp-image-2250" alt="Captura de pantalla 2013-05-01 a la(s) 14.39.24" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-14.39.24-300x228.png" width="300" height="228" /></a></p>
<p>After fixing the PE header we obtained the following PE file:</p>
<p><a title="https://www.virustotal.com/en/file/ea80dba427e7e844a540286faaccfddb6ef2c10a4bc6b27e4b29ca2b30c777fb/analysis/" href="https://www.virustotal.com/en/file/ea80dba427e7e844a540286faaccfddb6ef2c10a4bc6b27e4b29ca2b30c777fb/analysis/">https://www.virustotal.com/en/file/ea80dba427e7e844a540286faaccfddb6ef2c10a4bc6b27e4b29ca2b30c777fb/analysis/</a></p>
<p>It has a detection rate of 2 / 46 at the time of writing this blog post.</p>
<p>Once the payload is executed:</p>
<p>- The malware will create a copy of itself in Documents and Settings\[CURRENT_USER]\Application Data\conime.exe</p>
<p>- It will create a registry key pointing to conime.exe on HKEY_USERS\Software\Microsoft\Windows\CurrentVersion\Run conime to maintain persistence</p>
<p>- It will connect to a C&amp;C on microsoftUpdate.ns1.name currently pointing to a Google DNS server 8.8.8.8.</p>
<p>An available on <a title="malwr.com" href="malwr.com">malwr.com</a> shows that that the DNS name was previously pointing to:</p>
<p><!--StartFragment--><a title="http://labs.alienvault.com/labs/index.php/projects/open-source-ip-reputation-portal/information-about-ip/?ip=173.254.229.176" href="http://labs.alienvault.com/labs/index.php/projects/open-source-ip-reputation-portal/information-about-ip/?ip=173.254.229.176">173.254.229.176</a><!--EndFragment--></p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-15.00.35.png"><img class="aligncenter size-medium wp-image-2251" alt="Captura de pantalla 2013-05-01 a la(s) 15.00.35" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/05/Captura-de-pantalla-2013-05-01-a-las-15.00.35-300x58.png" width="300" height="58" /></a></p>
<p>&nbsp;</p>
<p><a title="https://malwr.com/analysis/YzUyMDk4M2M5YmM4NDgzNDllMDE5MWE1MDY4Y2I1MGM/" href="https://malwr.com/analysis/YzUyMDk4M2M5YmM4NDgzNDllMDE5MWE1MDY4Y2I1MGM/">https://malwr.com/analysis/YzUyMDk4M2M5YmM4NDgzNDllMDE5MWE1MDY4Y2I1MGM/</a></p>
<p>An analysis of the malware shows the payload is using the following GET requests to communicate with the C&amp;C server:</p>
<p>/Photos/Query.cgi?loginid=[RANDOM_NUMBER]</p>
<p>The C&amp;C protocol matches with a backdoor used by a known chinese actor called DeepPanda and described by CrowdStrike in the following analysis:</p>
<p><a title="http://www.crowdstrike.com/sites/default/files/AdversaryIntelligenceReport_DeepPanda_0.pdf" href="http://www.crowdstrike.com/sites/default/files/AdversaryIntelligenceReport_DeepPanda_0.pdf">http://www.crowdstrike.com/sites/default/files/AdversaryIntelligenceReport_DeepPanda_0.pdf</a></p>
<p>We are still investigating this attack and we will update the blog post if we obtain more information about it.</p>
<p>Happy hunting!</p>
<p>&nbsp;</p>
<div class="simple_likebuttons_container_small">
      <div class="simple_likebuttons_googleplus">
        <g:plusone size="medium" count="false" href="http://labs.alienvault.com/labs/index.php/2013/u-s-department-of-labor-website-hacked-and-redirecting-to-malicious-code/"></g:plusone>
      </div>
    
      <div class="simple_likebuttons_twitter simple_likebuttons_twitter_s">
        <a href="https://twitter.com/share" class="twitter-share-button" data-count="none" data-url="http://labs.alienvault.com/labs/index.php/2013/u-s-department-of-labor-website-hacked-and-redirecting-to-malicious-code/" data-lang="en">Tweet</a>
      </div>
    </div>]]></content:encoded>
			<wfw:commentRss>http://labs.alienvault.com/labs/index.php/2013/u-s-department-of-labor-website-hacked-and-redirecting-to-malicious-code/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>UrlQuery Chrome Extension</title>
		<link>http://labs.alienvault.com/labs/index.php/2013/urlquery-chrome-extension/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=urlquery-chrome-extension</link>
		<comments>http://labs.alienvault.com/labs/index.php/2013/urlquery-chrome-extension/#comments</comments>
		<pubDate>Mon, 29 Apr 2013 10:23:34 +0000</pubDate>
		<dc:creator>Eduardo De la Arada</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[chrome extension]]></category>
		<category><![CDATA[exploit kit]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[urlQuery]]></category>

		<guid isPermaLink="false">http://labs.alienvault.com/labs/?p=2213</guid>
		<description><![CDATA[UrlQuery is a service for detecting and analyzing web-based malware, claims its website, this service is very useful and provides a detailed report of the submitted webpage. We use these services a lot in the lab, so we&#8217;ve decided to make our lives easier by developing a simple context menu extension which automatically sends urls to the service. The extension &#8230; <a href="http://labs.alienvault.com/labs/index.php/2013/urlquery-chrome-extension/">Read more <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p><a href="http://urlquery.net/" target="_blank">UrlQuery</a> is a service for detecting and analyzing web-based malware, claims its website, this service is very useful and provides a detailed report of the submitted webpage. We use these services a lot in the lab, so we&#8217;ve decided to make our lives easier by developing a simple context menu extension which automatically sends urls to the service.</p>
<p>The extension adds a new option to the contextual menu. This option sends the link under the cursor to urlQuery.</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Screen-Shot-2013-04-29-at-09.18.03.png"><img class="alignnone size-medium wp-image-2217" alt="Screen Shot 2013-04-29 at 09.18.03" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Screen-Shot-2013-04-29-at-09.18.03-300x139.png" width="300" height="139" /></a></p>
<p>It opens a new tab with the url added to the url&#8217;s queue. You have to wait a few seconds, while the url is being scanned, and then the full report is shown.</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Screen-Shot-2013-04-29-at-09.18.41.png"><img class="alignnone size-medium wp-image-2215" alt="Screen Shot 2013-04-29 at 09.18.41" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Screen-Shot-2013-04-29-at-09.18.41-300x139.png" width="300" height="139" /></a></p>
<p>As urlQuery webpage, this extension has an options page where you can configure the User Agent, Refer, Acrobat Reader and Java versions. Unfortunately, a few options are provided by the original page, but we expect some more parameters in the future.</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Screen-Shot-2013-04-29-at-11.49.41.png"><img class="alignnone size-medium wp-image-2229" alt="Screen Shot 2013-04-29 at 11.49.41" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Screen-Shot-2013-04-29-at-11.49.41-300x74.png" width="300" height="74" /></a></p>
<p>You can get it from <a href="https://chrome.google.com/webstore/detail/urlquery/bhddiephjloagcihffelikdjfpchbjnl">Chome Web Store</a> or from our github repository:</p>
<p><a href="https://github.com/jaimeblasco/AlienvaultLabs/tree/master/urlquery-chrome">https://github.com/jaimeblasco/AlienvaultLabs/tree/master/urlquery-chrome</a></p>
<div class="simple_likebuttons_container_small">
      <div class="simple_likebuttons_googleplus">
        <g:plusone size="medium" count="false" href="http://labs.alienvault.com/labs/index.php/2013/urlquery-chrome-extension/"></g:plusone>
      </div>
    
      <div class="simple_likebuttons_twitter simple_likebuttons_twitter_s">
        <a href="https://twitter.com/share" class="twitter-share-button" data-count="none" data-url="http://labs.alienvault.com/labs/index.php/2013/urlquery-chrome-extension/" data-lang="en">Tweet</a>
      </div>
    </div>]]></content:encoded>
			<wfw:commentRss>http://labs.alienvault.com/labs/index.php/2013/urlquery-chrome-extension/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How cybercriminals are exploiting Bitcoin and other virtual currencies</title>
		<link>http://labs.alienvault.com/labs/index.php/2013/how-cybercriminals-are-exploiting-bitcoin-and-other-virtual-currencies/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=how-cybercriminals-are-exploiting-bitcoin-and-other-virtual-currencies</link>
		<comments>http://labs.alienvault.com/labs/index.php/2013/how-cybercriminals-are-exploiting-bitcoin-and-other-virtual-currencies/#comments</comments>
		<pubDate>Tue, 16 Apr 2013 17:08:29 +0000</pubDate>
		<dc:creator>jaime.blasco</dc:creator>
				<category><![CDATA[Attacks]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Snort]]></category>
		<category><![CDATA[bitcoin]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[darkomet]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[dorkbot]]></category>
		<category><![CDATA[khelios]]></category>
		<category><![CDATA[litecoin]]></category>
		<category><![CDATA[mtgox]]></category>
		<category><![CDATA[wallet]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://labs.alienvault.com/labs/?p=2179</guid>
		<description><![CDATA[ - What is Bitcoin? Bitcoin is an online descentralised virtual currency based on an open source, P2P protocol. Bitcoins can be transferred using a computer without relying on a financial institution. If you haven&#8217;t heard about Bitcoin I recommend you watch the following video: Both the Bitcoin creation and transfer is performed by computers called &#8230; <a href="http://labs.alienvault.com/labs/index.php/2013/how-cybercriminals-are-exploiting-bitcoin-and-other-virtual-currencies/">Read more <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p><strong> - What is Bitcoin?</strong></p>
<p><a title="http://en.wikipedia.org/wiki/Bitcoin" href="http://en.wikipedia.org/wiki/Bitcoin">Bitcoin</a> is an online descentralised virtual currency based on an open source, P2P protocol. Bitcoins can be transferred using a computer without relying on a financial institution.</p>
<p>If you haven&#8217;t heard about Bitcoin I recommend you watch the following video:</p>
<p><iframe width="590" height="332" src="http://www.youtube.com/embed/Um63OQz3bjo?feature=oembed" frameborder="0" allowfullscreen></iframe></p>
<p>Both the Bitcoin creation and transfer is performed by computers called “miners” that confirm the bitcoin&#8217;s creation by adding the information to a descentralized database.  Bitcoins get harder to generate all the time. <a title="http://blockchain.info/charts/total-bitcoins" href="http://blockchain.info/charts/total-bitcoins">There are more that 10 million bitcoins in circulation today.</a> The Bitcoin design only lets the creation of 21 millions and that limit will be reached during the year 2140.</p>
<p>The Bitcoin wallet is what gives you ownership of  one or more Bitcoin addresses. You can use those addresses to send and receive coins from other users.</p>
<p>Due to the complexity of mining bitcoins if you mine on your own it may be a long time until you can make some return. Bitcoin pools are places where multiple users can work together to make bitcoins and share benefits in a fair way.</p>
<p>Finally, you can buy and sell bitcoins using several real world currencies (EUR, USD ..) using several exchanges such as:</p>
<p>- <a title="https://mtgox.com/" href="https://mtgox.com/">MtGox</a></p>
<p>- <a title="https://btc-e.com/" href="https://btc-e.com/">BTC-E</a></p>
<p>- <a title="https://www.cavirtex.com/home" href="https://www.cavirtex.com/home">Virtex</a></p>
<p>&nbsp;</p>
<p><strong>Threat Landscape</strong></p>
<p><!--StartFragment-->Due to the growing popularity of the Bitcoin it has become an attractive and profitable target for cybercriminals. During the last few years we have seen an increase in the number of attacks and threats involving the virtual currency. The bad guys have adapted their tools to steal bitcoins from victims, use compromised systems to mine bitcoins and obtain benefit from it. On the other hand virtual exchanges are also victims and we have seen how the attackers have phished the users of those exchanges and how they have performed Denial of Service attacks to destabilize the exchange rate and profit.</p>
<p>&nbsp;</p>
<p><strong>Wallet stealing</strong></p>
<p>During the last few years the capability of stealing the wallet.dat file has been added to several malware families. In addition, new malware families have appeared with the objective of stealing the wallet file from the infected machines.</p>
<p>For example, a version of the Khelios malware that has been used to send Spam and steal data from infected systems added the capability to steal the wallet.dat file some time ago:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-15-a-las-11.57.55.png"><img class="alignleft size-medium wp-image-2182" title="Captura de pantalla 2013-04-15 a la(s) 11.57.55" alt="" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-15-a-las-11.57.55-300x121.png" width="300" height="121" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>As a result if a Bitcoin&#8217;s user gets infected, the file containing the keys to use your bitcoin addresses will be stolen. The wallet file can be protected by a password but most of the malwares we have found have keylogging capabilities that could steal the wallet password as well.</p>
<p>Another example are several IRC botnets that are running based on the &#8220;AthenaIRCBot&#8221; source code that has the capability of stealing the wallet file as well:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-15-a-las-17.27.07.png"><img class="alignleft size-medium wp-image-2184" alt="" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-15-a-las-17.27.07-300x136.png" width="300" height="136" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Example: <a title="https://www.virustotal.com/en/file/08a9b6a933c8eac7919355d47a811aa2752df74473b8789bcfd567fb779708cd/analysis/" href="https://www.virustotal.com/en/file/08a9b6a933c8eac7919355d47a811aa2752df74473b8789bcfd567fb779708cd/analysis/">08a9b6a933c8eac7919355d47a811aa2752df74473b8789bcfd567fb779708cd</a></p>
<p>&nbsp;</p>
<p><strong>- Bitcoin mining</strong></p>
<p>Apart from stealing the Bitcoin wallet the number of malware families that can use the victim&#8217;s computer power to mine Bitcoins is getting bigger and bigger.</p>
<p>We have found samples that install the Bitcoin daemon in the victim but the most frequently used technique is adding a piece of code that connects to a mining pool (public or private) to mine bitcoins.</p>
<p>You can find variants of very well known malware families such as Zeus/Zbot that added this capability. As an example, we found a Zeus variant more than a year ago that had intalled the Bitcoin daemon to mine bitcoins using the infected systems.</p>
<p>That specific variant was distributed using Fake e-mail messages containing a link to the malicious file.</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-15-a-las-17.47.33.png"><img class="alignleft size-medium wp-image-2185" alt="" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-15-a-las-17.47.33-300x99.png" width="300" height="99" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Once the system got infected the Bitcoin client bitcoind was installed in the system. The Zeus variant was using the configuration file from:</p>
<p>http://www[.]anshaa[.]com/z/config.bin</p>
<p>In the last few months several Dorkbot variants including one that was using Skype to spread added the capability of mining bitcoins.</p>
<p>Once the system gets compromised, a version of the Ufasoft Bitcoin miner is started. In this case the attacker is running his own pooling server.</p>
<p>The Ufasoft software contacts the mining pool server via HTTP:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-15-a-las-18.53.39.png"><img class="alignleft size-medium wp-image-2186" alt="" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-15-a-las-18.53.39-300x73.png" width="300" height="73" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>We have seen samples contacting the following servers that are owned by the same guys behind the botnet:</p>
<p>suppp[.]cantvenlinea[.]biz:1942</p>
<p>ahora[.]revisiondelpc[.]ru:2142</p>
<p>xhuehs[.]cantvenlinea[.]ru:1942</p>
<p>keep[.]hustling4life[.]biz:2142</p>
<p>That infrastructure has been running for at least 5 months.</p>
<p>Another gang has been running several Bitcoin mining servers for more than a year now. They have used Dorkbot as well as other malicious software to infect systems and use their computer power to mine bitcoins. Following is the list of malicious servers they have been using:</p>
<p>m1[.]m94vo3[.]com<br />
xxa[.]m94vo3[.]com<br />
pool[.]dload[.]asia<br />
abcpool[.]dload[.]asia<br />
thehood[.]k4912m[.]com<br />
abc[.]dload[.]asia<br />
paljacinke[.]aquarium-stakany[.]org<br />
entropy[.]k4912m[.]com<br />
xxx[.]z0k3[.]org<br />
xdx[.]8xx5[.]org<br />
xd[.]x1x9[.]asia<br />
xD[.]x3x9[.]asia<br />
www[.]ewgtr[.]us<br />
www[.]btcminers[.]biz<br />
sfx[.]dload[.]asia<br />
thehood[.]k4912m[.]com</p>
<p>We have found instances where the malicious actors are also mining <a title="http://litecoin.org/" href="http://litecoin.org/">Litecoins</a> that is another virtual currency similar to Bitcoin.</p>
<p>During the analysis of one of the malicious servers that was used to compromise users we found a GUI application that the attackers are using to build &#8220;Silent Miners&#8221; that are basically processes that run on the background, connect to the server pool that you configure and mine Litecoins/Bitcoins for you:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-15-a-las-20.37.17.png"><img class="alignleft size-medium wp-image-2188" alt="" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-15-a-las-20.37.17-300x154.png" width="300" height="154" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>The program will generate an executable file prepared to run in the background. It makes it very easy for the attackers to include or distribute the executable in the botnets they are already running.</p>
<p>Apart from the infrastructure we have unveiled, we have found many different malwares with Bitcoin mining capabilities in the last few weeks. Some of them are distributed as fake software in P2P networks, using malicious web redirects (Blackhole Exploit Kit), Fake AV&#8217;s, etc.</p>
<p>A lot of them also use public mining pools that are also used by regular users to mine bitcoins. Following is a list of malicious binaries we have found as well as the pool server and username they use:</p>
<p><strong>
<table id="wp-table-reloaded-id-9-no-1" class="wp-table-reloaded wp-table-reloaded-id-9">
<thead>
	<tr class="row-1 odd">
		<th class="column-1">Hash</th><th class="column-2">Server</th><th class="column-3">Username</th>
	</tr>
</thead>
<tbody>
	<tr class="row-2 even">
		<td class="column-1">b21183ebee87ea86acd11e25a3a3b0d1</td><td class="column-2">notroll.in:6332</td><td class="column-3">tromm.5</td>
	</tr>
	<tr class="row-3 odd">
		<td class="column-1">7fdf03f888932a384b0089d391f01b2e</td><td class="column-2">mining.eligius.st:8337</td><td class="column-3">1663o1jPydX5fgTNsAW33owbsyC1gpwbvn</td>
	</tr>
	<tr class="row-4 even">
		<td class="column-1">544b1a3b310ebb9dc9a9d3858c8c7fe4</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">169TpR47JVcLaQXdGYE6Lv4Ps9DbVqHhSi</td>
	</tr>
	<tr class="row-5 odd">
		<td class="column-1">9b7a5ab5e06c46b88e3182457b1e9a0f</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">17F8N9AvEWSWRMgfR2WncDxhHCm2zLMgST</td>
	</tr>
	<tr class="row-6 even">
		<td class="column-1">6ba659c9f3de5b5d45a77b12c5ca1e7b</td><td class="column-2">mining.eligius.st:8337</td><td class="column-3">17VJ4nebUbfBoydRC7vLynQruXyqMCDY1W</td>
	</tr>
	<tr class="row-7 odd">
		<td class="column-1">e26686c56297f259e936454e4ea3f7ae</td><td class="column-2">mining.eligius.st:8337</td><td class="column-3">17VJ4nebUbfBoydRC7vLynQruXyqMCDY1W</td>
	</tr>
	<tr class="row-8 even">
		<td class="column-1">ae1350e85fb01777d6b5f93384f23bdc</td><td class="column-2">mining.eligius.st: 8337</td><td class="column-3">1ASNjJjUou6RPkmP81nJUuhbZDkxAaHQhX</td>
	</tr>
	<tr class="row-9 odd">
		<td class="column-1">d770554455a70f3a3ad8e3326ddca765</td><td class="column-2">mining.eligius.st:8337</td><td class="column-3">1ASNjJjUou6RPkmP81nJUuhbZDkxAaHQhX</td>
	</tr>
	<tr class="row-10 even">
		<td class="column-1">d911d82dc184bbfc952b77cb4cb1b743</td><td class="column-2">mining.eligius.st:8337</td><td class="column-3">1ASNjJjUou6RPkmP81nJUuhbZDkxAaHQhX</td>
	</tr>
	<tr class="row-11 odd">
		<td class="column-1">2f0312e6c46cd6e045f3be88e16ecb74</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">1Dt8Ai9uNhupwxejr8PN631XTpbECTfQ2y</td>
	</tr>
	<tr class="row-12 even">
		<td class="column-1">e64d98da86cf03ff6088b48612870f83</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">1Dt8Ai9uNhupwxejr8PN631XTpbECTfQ2y</td>
	</tr>
	<tr class="row-13 odd">
		<td class="column-1">20d5c788a075113145261ee5dfab0fa0</td><td class="column-2">mining.eligius.st:8337</td><td class="column-3">1ES11Ke5mxgz9MYiJ2Pb1MgY2FFYnfs5fA</td>
	</tr>
	<tr class="row-14 even">
		<td class="column-1">500d53fbf363ce31d75447a7ac335516</td><td class="column-2">mining.eligius.st:8337</td><td class="column-3">1ES11Ke5mxgz9MYiJ2Pb1MgY2FFYnfs5fA</td>
	</tr>
	<tr class="row-15 odd">
		<td class="column-1">e61b38b75d1cfefe9f631231666a9211</td><td class="column-2">mining.eligius.st:8337</td><td class="column-3">1H1xa5PV522hUKfBqvfXPqu7buS5q9ckiW</td>
	</tr>
	<tr class="row-16 even">
		<td class="column-1">1a155713d6ff01a3e949730d6fe868d9</td><td class="column-2">mining.eligius.st:8337</td><td class="column-3">1HH1Geovwhxq2UnNt6tiscF2kMsxYEVCRM</td>
	</tr>
	<tr class="row-17 odd">
		<td class="column-1">d726542997e8aaca1c8c2809cc859f04</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">1Hy8HbYrLPrXhGko2SmkUtMjBvBpVDEeMh</td>
	</tr>
	<tr class="row-18 even">
		<td class="column-1">974b155cef5cb549dcd81b62d26a7d7e</td><td class="column-2">mining.eligius.st:8337</td><td class="column-3">1Kjvxd9CbnYbigcC13gS5VAd2asNcdVSyH</td>
	</tr>
	<tr class="row-19 odd">
		<td class="column-1">9384cb2d2b69d4023dbe2260b789c509</td><td class="column-2">mining.eligius.st:8337</td><td class="column-3">1KyxrBp8mJRt3U6Q12LfuNLonZ9JHLYnbM</td>
	</tr>
	<tr class="row-20 even">
		<td class="column-1">9f878f2f555e690d447060bff7856dac</td><td class="column-2">mining.eligius.st:8337</td><td class="column-3">1NqV1Dy7jH4SLXgbihQDRYA9qKgqnSfaVJ</td>
	</tr>
	<tr class="row-21 odd">
		<td class="column-1">bfe45e910c94c49e63e969cc2dd8c806</td><td class="column-2">mining.eligius.st:8337</td><td class="column-3">1PyoNmwdNP7PQWQwjCLiK8Av5V9eAGhKcL:x</td>
	</tr>
	<tr class="row-22 even">
		<td class="column-1">bb0449dcb53723f6cb58d7024c16f887</td><td class="column-2">mining.eligius.st:8337</td><td class="column-3">1Q3TM64corp7BCYY98pa88w9RoZSfxrH8</td>
	</tr>
	<tr class="row-23 odd">
		<td class="column-1">9a48fe740b8feff35b1dbc07ab99d949</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">1qGYbXUe48RjdAoHuRhs4vvm118XMY6e3</td>
	</tr>
	<tr class="row-24 even">
		<td class="column-1">35c3c3506064dbad08ba3a8a1ccd742b</td><td class="column-2">eiswoj.uktop40chart.co.uk:80</td><td class="column-3">2thread</td>
	</tr>
	<tr class="row-25 odd">
		<td class="column-1">e32caa62ef6e67e82c2b95c3b2b66db4</td><td class="column-2">litecoinpool.org:3333</td><td class="column-3">8r9di23217.97123y92</td>
	</tr>
	<tr class="row-26 even">
		<td class="column-1">13052239a6a852a4eee3febe10268e25</td><td class="column-2">notroll.in:6332</td><td class="column-3">appap.6</td>
	</tr>
	<tr class="row-27 odd">
		<td class="column-1">6111ebdfcf7c58c953271dcbd594a417</td><td class="column-2">litecoinpool.org:9332</td><td class="column-3">aspen.4</td>
	</tr>
	<tr class="row-28 even">
		<td class="column-1">1c5458ed87729b711310b6f0baf270bf</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">blackweader@hotmail.com_dodi</td>
	</tr>
	<tr class="row-29 odd">
		<td class="column-1">5271a38bd18c8ad51d5e3b158db11b38</td><td class="column-2">eu.triplemining.com:8344</td><td class="column-3">Bool_Bool</td>
	</tr>
	<tr class="row-30 even">
		<td class="column-1">49d8ce6f361cc87f85fe12f4df73bda5</td><td class="column-2">us2.eclipsemc.com:8337</td><td class="column-3">cartoon1996_hm9gjp</td>
	</tr>
	<tr class="row-31 odd">
		<td class="column-1">815ccc9f6a48cab368e41647c8f81722</td><td class="column-2">us2.eclipsemc.com:8337</td><td class="column-3">cartoon1996_server</td>
	</tr>
	<tr class="row-32 even">
		<td class="column-1">2a79e90f44bd136b3a977fe9fc93c1e0</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">cbargas3443@outlook.com</td>
	</tr>
	<tr class="row-33 odd">
		<td class="column-1">0eece32d0d55449366eae4462a4781c7</td><td class="column-2">eu.triplemining.com:8344</td><td class="column-3">comp_pony</td>
	</tr>
	<tr class="row-34 even">
		<td class="column-1">cc3dc3b176bbc34444117057659e9e14</td><td class="column-2">de.btcguild.com:8332</td><td class="column-3">cviper_1</td>
	</tr>
	<tr class="row-35 odd">
		<td class="column-1">75bd6e532370c06c567718d68e551647</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">edwardpafford220@outlook.com</td>
	</tr>
	<tr class="row-36 even">
		<td class="column-1">20c05310dc8bb6dd2cf0e4c642e475a1</td><td class="column-2">uscentral.btcguild.com:8332</td><td class="column-3">epix6_datacenter1</td>
	</tr>
	<tr class="row-37 odd">
		<td class="column-1">4decdf42f9eaf230768220edb361a0e0</td><td class="column-2">uscentral.btcguild.com:8332</td><td class="column-3">epix6_datacenter1</td>
	</tr>
	<tr class="row-38 even">
		<td class="column-1">8c5fd67f62fbccf02f8e0e306341713d</td><td class="column-2">uscentral.btcguild.com:8332</td><td class="column-3">epix6_datacenter1</td>
	</tr>
	<tr class="row-39 odd">
		<td class="column-1">38831b2e4e6ead08c23f7387919999af</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">franklinandrus99@outlook.com</td>
	</tr>
	<tr class="row-40 even">
		<td class="column-1">44ab7103e31a41b53401cedcabf9de6f</td><td class="column-2">us2.eclipsemc.com:8337</td><td class="column-3">happyworld_3</td>
	</tr>
	<tr class="row-41 odd">
		<td class="column-1">b08ef6df987e03e86cc9af30942e8fd2</td><td class="column-2">us2.eclipsemc.com:8337</td><td class="column-3">happyworld_3</td>
	</tr>
	<tr class="row-42 even">
		<td class="column-1">2d150ca060ed2d89ff031c0060275c99</td><td class="column-2">notroll.in:6332</td><td class="column-3">happyworld3000.1</td>
	</tr>
	<tr class="row-43 odd">
		<td class="column-1">d1cc70aa60e76879da80303f0f79a894</td><td class="column-2">dns.domain-crawlers.com:8332</td><td class="column-3">haqidodges@gmail.com</td>
	</tr>
	<tr class="row-44 even">
		<td class="column-1">135cbc204145e63f7af441fff85f4ec7</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">i0nn@mail.ru_4</td>
	</tr>
	<tr class="row-45 odd">
		<td class="column-1">854387049a16de49fc6a02655c38c4eb</td><td class="column-2">eu.triplemining.com:8344</td><td class="column-3">IamX_Worker1</td>
	</tr>
	<tr class="row-46 even">
		<td class="column-1">a401a4a5051feb11fe594aad9b4bdf95</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">Jasoncharles848@outlook.com</td>
	</tr>
	<tr class="row-47 odd">
		<td class="column-1">4b8ad799881c4a79a32ea2a6576a8037</td><td class="column-2">mine3.btcguild.com:8332</td><td class="column-3">JennyEsta_666fuckerhead</td>
	</tr>
	<tr class="row-48 even">
		<td class="column-1">ff925fbce01271e6a033febc27703762</td><td class="column-2">gief3.25u.com:8332</td><td class="column-3">jowsie_cheap2</td>
	</tr>
	<tr class="row-49 odd">
		<td class="column-1">3e4ef7f6727217b01c38ffcab91ef3c9</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">jrodriguez442@outlook.com</td>
	</tr>
	<tr class="row-50 even">
		<td class="column-1">add443fe32e35fb4a46e35ed2052b6f6</td><td class="column-2">miningpool.com:9350</td><td class="column-3">koji35.3</td>
	</tr>
	<tr class="row-51 odd">
		<td class="column-1">4d4fa3c12eb5f77529e08bb9873e54e1</td><td class="column-2">eu.triplemining.com:8344</td><td class="column-3">lezoum2010_pocket</td>
	</tr>
	<tr class="row-52 even">
		<td class="column-1">3f5589b0c8fc9b049e5fde81a642db6c</td><td class="column-2">eu.triplemining.com:8344</td><td class="column-3">loadrs2009_1</td>
	</tr>
	<tr class="row-53 odd">
		<td class="column-1">1fc06c8cdcbcff1fd5ecf07ded4bed93</td><td class="column-2">us2.eclipsemc.com:8337</td><td class="column-3">m1nd_jorgee</td>
	</tr>
	<tr class="row-54 even">
		<td class="column-1">ae08c3c4ab1e43ce8201b572b0b45115</td><td class="column-2">eu.triplemining.com:8344</td><td class="column-3">madhav007_pudge007</td>
	</tr>
	<tr class="row-55 odd">
		<td class="column-1">47d21779b4e1d7195ae3eceafa1b163d</td><td class="column-2">ltcmine.ru:3333</td><td class="column-3">MinerG_0</td>
	</tr>
	<tr class="row-56 even">
		<td class="column-1">ae03b006bb3eb6dcb2a64e3533862367</td><td class="column-2">ltcmine.ru:3333</td><td class="column-3">MinerG_17</td>
	</tr>
	<tr class="row-57 odd">
		<td class="column-1">c3f67b7b4d3d5152757fd71bca6fbbfe</td><td class="column-2">ltcmine.ru:3333</td><td class="column-3">MinerG_18</td>
	</tr>
	<tr class="row-58 even">
		<td class="column-1">202dfdf0ced47d213e833d8a92012d90</td><td class="column-2">ltcmine.ru:3333</td><td class="column-3">MinerG_26</td>
	</tr>
	<tr class="row-59 odd">
		<td class="column-1">0ed23a28270a27e5a4332ae521ee70b8</td><td class="column-2">ltcmine.ru:3333</td><td class="column-3">MinerG_34</td>
	</tr>
	<tr class="row-60 even">
		<td class="column-1">3e348e07f5d98929baa0cb88f00cd8cf</td><td class="column-2">ltcmine.ru:3333</td><td class="column-3">MinerG_7</td>
	</tr>
	<tr class="row-61 odd">
		<td class="column-1">eb375ba9447d20401ee17192c2f9010d</td><td class="column-2">ltcmine.ru:3333</td><td class="column-3">MinerG_8</td>
	</tr>
	<tr class="row-62 even">
		<td class="column-1">c1d4410b41ed7f534457f077370067a6</td><td class="column-2">us2.eclipsemc.com:8337</td><td class="column-3">moi_worker</td>
	</tr>
	<tr class="row-63 odd">
		<td class="column-1">20c258e021449365a42f9b2fc7d0d4c8</td><td class="column-2">us2.eclipsemc.com:8337</td><td class="column-3">Mystical_pike</td>
	</tr>
	<tr class="row-64 even">
		<td class="column-1">2164bd712071628549a25f5eb97a5f35</td><td class="column-2">us2.eclipsemc.com:8337</td><td class="column-3">N785O1c_3cxQO9S</td>
	</tr>
	<tr class="row-65 odd">
		<td class="column-1">2bab5ce7b48baea90b11244278bd6d57</td><td class="column-2">mine2.btcguild.com:8332</td><td class="column-3">o2521666_1</td>
	</tr>
	<tr class="row-66 even">
		<td class="column-1">92b4c95a10d12132138ef15f44c9b9fc</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">pinkywesen@secure-mail.biz</td>
	</tr>
	<tr class="row-67 odd">
		<td class="column-1">86ac869662e4b8f0422fb9cbca77d72e</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">popa_zade@yahoo.com</td>
	</tr>
	<tr class="row-68 even">
		<td class="column-1">c6cf7161100ff107b59b7b07db6</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">popa_zade@yahoo.com</td>
	</tr>
	<tr class="row-69 odd">
		<td class="column-1">b7752d762c5a9ac883caaefd1cc19c1b</td><td class="column-2">eu.triplemining.com:8344</td><td class="column-3">pr3m1era_Bossnigger</td>
	</tr>
	<tr class="row-70 even">
		<td class="column-1">67e591f09ae0cea47f920878f100baa8</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">rainbow101@outlook.com</td>
	</tr>
	<tr class="row-71 odd">
		<td class="column-1">3b6c8728ac3ee82a06bca7096265d666</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">rthrockmorton212@outlook.com</td>
	</tr>
	<tr class="row-72 even">
		<td class="column-1">3eb76d2427c283d2c4b9b396bef275a2</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">ryancaswell772@outlook.com</td>
	</tr>
	<tr class="row-73 odd">
		<td class="column-1">8f4ad4c95adef240f8edb5f3da09f164</td><td class="column-2">us2.eclipsemc.com:8337</td><td class="column-3">shrooms_mining</td>
	</tr>
	<tr class="row-74 even">
		<td class="column-1">da99275413845905166e8470980a155f</td><td class="column-2">eu.triplemining.com:8344</td><td class="column-3">Sisocviper_siso</td>
	</tr>
	<tr class="row-75 odd">
		<td class="column-1">7f1ef23a0076cedaeec0b7bb55b9702d</td><td class="column-2">eu.triplemining.com:8344</td><td class="column-3">smackos_aliens</td>
	</tr>
	<tr class="row-76 even">
		<td class="column-1">1f85e27b2bd33c4d0ca377ad696fa563</td><td class="column-2">us2.eclipsemc.com:8337</td><td class="column-3">SSnack_worker</td>
	</tr>
	<tr class="row-77 odd">
		<td class="column-1">bbfe230a8471e2b5d807df3368836bce</td><td class="column-2">eu.triplemining.com:8344</td><td class="column-3">Strick3n_stricken</td>
	</tr>
	<tr class="row-78 even">
		<td class="column-1">0b04c1538e5f3a37a81ec2086810b8e1</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">svintaz@mail.ru_7</td>
	</tr>
	<tr class="row-79 odd">
		<td class="column-1">b51128a0d8626a9b36f25679854d137e</td><td class="column-2">uswest.btcguild.com:8332</td><td class="column-3">tester20122_3</td>
	</tr>
	<tr class="row-80 even">
		<td class="column-1">ccf5f50c9f919dbd9c0cc9a313ef5a2d</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">titorjohn@rocketmail.com</td>
	</tr>
	<tr class="row-81 odd">
		<td class="column-1">3d31545f1889fa7593defb5f8bbc915a</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">TOGRI2012@hotmail.com</td>
	</tr>
	<tr class="row-82 even">
		<td class="column-1">43cc15d6178c0fa7845fe257a58f5e0b</td><td class="column-2">notroll.in:6332</td><td class="column-3">tophosts.1</td>
	</tr>
	<tr class="row-83 odd">
		<td class="column-1">9425c6b7654e8e9ceba5894862e28970</td><td class="column-2">notroll.in:6332</td><td class="column-3">tromm.14</td>
	</tr>
	<tr class="row-84 even">
		<td class="column-1">865341e5ae9e6fd01eca8e6bb31b4e5d</td><td class="column-2">us2.eclipsemc.com:8337</td><td class="column-3">vapor_worker</td>
	</tr>
	<tr class="row-85 odd">
		<td class="column-1">ce38c3479d126c80298e0fe76e73e8e5</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">victory2egy@yahoo.com</td>
	</tr>
	<tr class="row-86 even">
		<td class="column-1">d20be24e318844a56d3f38f2d1061dde</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">victory2egy@yahoo.com</td>
	</tr>
	<tr class="row-87 odd">
		<td class="column-1">c24700038e25f4ed1aea01bc374ed5a1</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">victory2egy@yahoo.com_v</td>
	</tr>
	<tr class="row-88 even">
		<td class="column-1">d11b21251ef6f8f84efc7130525a4785</td><td class="column-2">pool.50btc.com:8332</td><td class="column-3">vincentbaty87@outlook.com</td>
	</tr>
</tbody>
</table>
</strong></p>
<p>&nbsp;</p>
<p><strong>Show me the money</strong></p>
<p>As you can see in the previous table some of the bad guys were using Bitcoin addresses instead of usernames to connect to the pool servers.</p>
<p><!--StartFragment-->Due to the openness of the Bitcoin&#8217;s protocol we can access the information and the transactions done by those accounts.<!--EndFragment--></p>
<p><!--StartFragment--><a title="http://blockchain.info/address/169TpR47JVcLaQXdGYE6Lv4Ps9DbVqHhSi" href="http://blockchain.info/address/169TpR47JVcLaQXdGYE6Lv4Ps9DbVqHhSi">169TpR47JVcLaQXdGYE6Lv4Ps9DbVqHhSi</a>, 91.39938806 BTC ,$ 8,317.34</p>
<p><a title="http://blockchain.info/address/17F8N9AvEWSWRMgfR2WncDxhHCm2zLMgST" href="http://blockchain.info/address/17F8N9AvEWSWRMgfR2WncDxhHCm2zLMgST">17F8N9AvEWSWRMgfR2WncDxhHCm2zLMgST</a>, 20.89356766 BTC , $ 1,901.31</p>
<p><a title="http://blockchain.info/address/1ASNjJjUou6RPkmP81nJUuhbZDkxAaHQhX" href="http://blockchain.info/address/1ASNjJjUou6RPkmP81nJUuhbZDkxAaHQhX">1ASNjJjUou6RPkmP81nJUuhbZDkxAaHQhX</a>, 420.81569559 BTC, $ 38,294.23</p>
<p><a title="http://blockchain.info/address/1ES11Ke5mxgz9MYiJ2Pb1MgY2FFYnfs5fAm" href="http://blockchain.info/address/1ES11Ke5mxgz9MYiJ2Pb1MgY2FFYnfs5fAm">1ES11Ke5mxgz9MYiJ2Pb1MgY2FFYnfs5fAm</a> 52.33521919 BTC , $ 4,762.50</p>
<p><a title="http://blockchain.info/address/1H1xa5PV522hUKfBqvfXPqu7buS5q9ckiW" href="http://blockchain.info/address/1H1xa5PV522hUKfBqvfXPqu7buS5q9ckiW">1H1xa5PV522hUKfBqvfXPqu7buS5q9ckiW</a>, 31.00274179 BTC , $ 2,821.25</p>
<p><a title="http://blockchain.info/address/1Kjvxd9CbnYbigcC13gS5VAd2asNcdVSyH" href="http://blockchain.info/address/1Kjvxd9CbnYbigcC13gS5VAd2asNcdVSyH">1Kjvxd9CbnYbigcC13gS5VAd2asNcdVSyH</a>, 88.99839055 BTC , $ 8,098.85</p>
<p><a title="http://blockchain.info/address/1KyxrBp8mJRt3U6Q12LfuNLonZ9JHLYnbM" href="http://blockchain.info/address/1KyxrBp8mJRt3U6Q12LfuNLonZ9JHLYnbM">1KyxrBp8mJRt3U6Q12LfuNLonZ9JHLYnbM</a>, 77.55520657 BTC , $ 7,057.52</p>
<p><a title="http://blockchain.info/address/1Q3TM64corp7BCYY98pa88w9RoZSfxrH8" href="http://blockchain.info/address/1Q3TM64corp7BCYY98pa88w9RoZSfxrH8">1Q3TM64corp7BCYY98pa88w9RoZSfxrH8</a>, 48.69058357 BTC , $ 4,430.84<!--EndFragment--></p>
<p>&nbsp;</p>
<p>For instance we can see these two Bitcoin addresses probably belong to the same bad actors:</p>
<p><!--StartFragment-->169TpR47JVcLaQXdGYE6Lv4Ps9DbVqHhSi</p>
<p>1ASNjJjUou6RPkmP81nJUuhbZDkxAaHQhX<!--EndFragment--></p>
<p>Those two accounts sent most of the money to the following account:</p>
<p><a title="http://blockchain.info/es/taint/1827x95K36G3NFxDqiNwo6aE1rH55Ua3p5" href="http://blockchain.info/es/taint/1827x95K36G3NFxDqiNwo6aE1rH55Ua3p5">1827x95K36G3NFxDqiNwo6aE1rH55Ua3p5</a></p>
<p>That Bitcoin address received a total amount of  1050.21 BTC in the last few months. If the bad guys sold that amount of bitcoins some days ago when a single Bitcoin was worth $265 they<strong> could have made $278k</strong>. Not bad for a small Botnet!</p>
<p><strong> </strong></p>
<p><strong>MtGox Fake sites</strong></p>
<p>Mtgox is the largest Bitcoin exchange where you can trade Bitcoins for EUR/US, etc. In the last few weeks the increased popularity of both Bitcoin and Mtgox has made it an attractive target for attackers.</p>
<p>Last week, we detected several websites that were attempting to target Mtgox users. An attacker set up the fake website www[.]mtgox-chat[.]info:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-16-a-las-11.23.18.png"><img class="alignleft size-medium wp-image-2192" alt="Captura de pantalla 2013-04-16 a la(s) 11.23.18" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-16-a-las-11.23.18-300x186.png" width="300" height="186" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>The malicious server looks like an official Mtgox website with a chat on it. Once the user enters the site it will try to load a malicious Java applet:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-16-a-las-11.26.30.png"><img class="alignleft size-medium wp-image-2193" alt="Captura de pantalla 2013-04-16 a la(s) 11.26.30" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-16-a-las-11.26.30-300x148.png" width="300" height="148" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>The Java applet will download and execute a binary file from a remote site.</p>
<p>Once the file is executed the victim gets infected and the system will contact the C&amp;C server on:</p>
<p><!--StartFragment-->tamere123[.]no-ip[.]org<!--EndFragment--></p>
<p>Having access to the victim&#8217;s system the attacker can now get the Mtgox&#8217;s credentials and steal the money/bitcoins from the victim.</p>
<p>&nbsp;</p>
<p><strong>Impact on the enterprise</strong></p>
<p>The detection of mining software in your network could indicate either a misuse of resources by your employees or an infection that could lead to financial losses.</p>
<p>The following best practices will help you prevent these threats:</p>
<p>- Keep software up to date</p>
<p>- Update your Antivirus signatures</p>
<p>- Run a Vulnerability Assessment Program</p>
<p>- Monitor your networks to detect suspicious network behaviors.</p>
<p><!--StartFragment--><a title="http://www.alienvault.com/free-trial?utm_medium=Influencer&amp;utm_Source=labs.alienvault.com&amp;utm_content=BitcoinPost&amp;utm_campaign=" href="http://www.alienvault.com/free-trial?utm_medium=Influencer&amp;utm_Source=labs.alienvault.com&amp;utm_content=BitcoinPost&amp;utm_campaign=">AlienVault Unified Security Management (USM)</a> will detect all the threats mentioned on the blog post (and<a title="http://www.alienvault.com/free-trial?utm_medium=Influencer&amp;utm_Source=labs.alienvault.com&amp;utm_content=BitcoinPost&amp;utm_campaign=" href="http://www.alienvault.com/free-trial?utm_medium=Influencer&amp;utm_Source=labs.alienvault.com&amp;utm_content=BitcoinPost&amp;utm_campaign="> it&#8217;s available as a Free 30 day trial download</a>):</p>
<p><!--EndFragment--></p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-16-a-las-13.15.05.png"><img class="aligncenter size-large wp-image-2199" alt="Captura de pantalla 2013-04-16 a la(s) 13.15.05" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-16-a-las-13.15.05-1024x300.png" width="590" height="172" /></a></p>
<p>&nbsp;</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-16-a-las-13.15.32.png"><img class="aligncenter size-large wp-image-2200" alt="Captura de pantalla 2013-04-16 a la(s) 13.15.32" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/04/Captura-de-pantalla-2013-04-16-a-las-13.15.32-1024x412.png" width="590" height="237" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>If you want to increase your network visibility you can <a title="http://www.alienvault.com/free-trial?utm_medium=Influencer&amp;utm_Source=labs.alienvault.com&amp;utm_content=BitcoinPost&amp;utm_campaign=" href="http://www.alienvault.com/free-trial?utm_medium=Influencer&amp;utm_Source=labs.alienvault.com&amp;utm_content=BitcoinPost&amp;utm_campaign=">try  our Unified Security Management solution</a> or <a title="http://communities.alienvault.com/download.html" href="http://communities.alienvault.com/download.html">download the Open Source version</a>.</p>
<p>&nbsp;</p>
<div class="simple_likebuttons_container_small">
      <div class="simple_likebuttons_googleplus">
        <g:plusone size="medium" count="false" href="http://labs.alienvault.com/labs/index.php/2013/how-cybercriminals-are-exploiting-bitcoin-and-other-virtual-currencies/"></g:plusone>
      </div>
    
      <div class="simple_likebuttons_twitter simple_likebuttons_twitter_s">
        <a href="https://twitter.com/share" class="twitter-share-button" data-count="none" data-url="http://labs.alienvault.com/labs/index.php/2013/how-cybercriminals-are-exploiting-bitcoin-and-other-virtual-currencies/" data-lang="en">Tweet</a>
      </div>
    </div>]]></content:encoded>
			<wfw:commentRss>http://labs.alienvault.com/labs/index.php/2013/how-cybercriminals-are-exploiting-bitcoin-and-other-virtual-currencies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Sykipot developments</title>
		<link>http://labs.alienvault.com/labs/index.php/2013/new-sykipot-developments/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-sykipot-developments</link>
		<comments>http://labs.alienvault.com/labs/index.php/2013/new-sykipot-developments/#comments</comments>
		<pubDate>Thu, 21 Mar 2013 15:57:24 +0000</pubDate>
		<dc:creator>jaime.blasco</dc:creator>
				<category><![CDATA[APT]]></category>
		<category><![CDATA[Attacks]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Snort]]></category>
		<category><![CDATA[CVE-2012-1723]]></category>
		<category><![CDATA[CVE-2012-1889]]></category>
		<category><![CDATA[CVE-2012-4969]]></category>
		<category><![CDATA[CVE-2013-0640]]></category>
		<category><![CDATA[Sykipot]]></category>

		<guid isPermaLink="false">http://labs.alienvault.com/labs/?p=2124</guid>
		<description><![CDATA[Summary During the last few years, we have been publishing about a group of hackers who have focused on targeting DIB (Defence Industrial Base) and other government organizations: - Another Sykipot sample likely targeting US federal agencies - Are the Sykipot’s authors obsessed with next generation US drones? - Sykipot variant hijacks DOD and Windows &#8230; <a href="http://labs.alienvault.com/labs/index.php/2013/new-sykipot-developments/">Read more <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p><strong>Summary</strong></p>
<p>During the last few years, we have been publishing about a group of hackers who have focused on targeting DIB (Defence Industrial Base) and other government organizations:</p>
<p>- <a title="http://labs.alienvault.com/labs/index.php/2011/another-sykipot-sample-likely-targeting-us-federal-agencies/" href="http://labs.alienvault.com/labs/index.php/2011/another-sykipot-sample-likely-targeting-us-federal-agencies/">Another Sykipot sample likely targeting US federal agencies</a></p>
<p><a title="http://labs.alienvault.com/labs/index.php/2011/are-the-sykipots-authors-obsessed-with-next-generation-us-drones/" href="http://labs.alienvault.com/labs/index.php/2011/are-the-sykipots-authors-obsessed-with-next-generation-us-drones/">- Are the Sykipot’s authors obsessed with next generation US drones?</a></p>
<p><a title="http://labs.alienvault.com/labs/index.php/2012/when-the-apt-owns-your-smart-cards-and-certs/" href="http://labs.alienvault.com/labs/index.php/2012/when-the-apt-owns-your-smart-cards-and-certs/">- Sykipot variant hijacks DOD and Windows smart cards</a></p>
<p><a title="http://labs.alienvault.com/labs/index.php/2012/sykipot-is-back/" href="http://labs.alienvault.com/labs/index.php/2012/sykipot-is-back/">- Sykipot is back</a></p>
<p>Sykipot are a  highly skilled group of individuals who have exploited a wide range of zeroday vulnerabilities in the last few years including:</p>
<p><strong>
<table id="wp-table-reloaded-id-6-no-1" class="wp-table-reloaded wp-table-reloaded-id-6">
<thead>
	<tr class="row-1 odd">
		<th class="column-1">CVE</th><th class="column-2">Date</th><th class="column-3">Product</th>
	</tr>
</thead>
<tbody>
	<tr class="row-2 even">
		<td class="column-1">CVE-2007-0671</td><td class="column-2">2007-02-02</td><td class="column-3">Microsoft Excel</td>
	</tr>
	<tr class="row-3 odd">
		<td class="column-1">CVE-2009-3957</td><td class="column-2">2010-12-01</td><td class="column-3">Adobe Reader</td>
	</tr>
	<tr class="row-4 even">
		<td class="column-1">CVE-2010-0806</td><td class="column-2">2010-05-04</td><td class="column-3">Internet Explorer</td>
	</tr>
	<tr class="row-5 odd">
		<td class="column-1">CVE-2010-2883</td><td class="column-2">2010-09-08</td><td class="column-3">Adobe Reader</td>
	</tr>
	<tr class="row-6 even">
		<td class="column-1">CVE-2010-3654</td><td class="column-2">2010-10-28</td><td class="column-3">Adobe Flash Player</td>
	</tr>
	<tr class="row-7 odd">
		<td class="column-1">CVE-2011-2462</td><td class="column-2">2011-12-06</td><td class="column-3">Adobe Reader</td>
	</tr>
</tbody>
</table>
</strong></p>
<p>&nbsp;</p>
<p>In this blog post we will unveil the new vulnerabilities that this group have used using during the last 8 months and we will publish the new infrastructure they have used. We will expose several examples of the campaigns they have launched and new versions of the Sykipot backdoor they have used to access the compromised systems. We have found evidences that show they have exploited at least the following vulnerabilities during the last few months:</p>
<p><strong>
<table id="wp-table-reloaded-id-7-no-1" class="wp-table-reloaded wp-table-reloaded-id-7">
<thead>
	<tr class="row-1 odd">
		<th class="column-1">CVE</th><th class="column-2">Date</th><th class="column-3">Product</th>
	</tr>
</thead>
<tbody>
	<tr class="row-2 even">
		<td class="column-1">CVE-2012-1889</td><td class="column-2">06/13/2012</td><td class="column-3">MSXML/Internet Explorer</td>
	</tr>
	<tr class="row-3 odd">
		<td class="column-1">CVE-2012-1723</td><td class="column-2">06/12/2012</td><td class="column-3">Java 7</td>
	</tr>
	<tr class="row-4 even">
		<td class="column-1">CVE-2012-4969</td><td class="column-2">09/16/2012</td><td class="column-3">Microsoft Internet Explorer</td>
	</tr>
	<tr class="row-5 odd">
		<td class="column-1">CVE-2013-0640</td><td class="column-2">02/12/2012</td><td class="column-3">Adobe Acrobat Reader</td>
	</tr>
</tbody>
</table>
</strong></p>
<p>&nbsp;</p>
<p>Several times the date of the exploit was a few days after the vulnerability had been disclosed and there wasn&#8217;t a patch released by the vendor.</p>
<p><strong>Campaigns</strong></p>
<p>In the past most of the campaigns which we found related to the Sykipot actors were based on SpearPhishing mails with attachments that exploited vulnerabilities in software like Microsoft Office, Adobe Flash, Adobe PDF and some times Internet Explorer. During the last 8-10 months we have seen a change and the number of SpearPhishing campaigns which have included a link instead of an attachment and this has increased. Once the victim clicks in the link the attackers will use vulnerabilities in Internet Explorer, Java, etc to access the system.</p>
<p>Some examples of the campaigns they have launched are detailed below.</p>
<p><!--StartFragment--><strong>gsasmartpay.org &#8211; 2012-06-20</strong></p>
<p>The last summer, we found a malicious site that the Sykipot actors set up to try and phish government employees. When the victim visited the link the following page appeared:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-20-a-las-11.08.351.png"><img class="alignleft size-large wp-image-2137" title="Captura de pantalla 2013-03-20 a la(s) 11.08.35" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-20-a-las-11.08.351-1024x442.png" alt="" width="590" height="254" /></a></p>
<p><!--EndFragment--></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>As we can see it shows the information present in <a title="https://smartpay.gsa.gov/cardholders" href="https://smartpay.gsa.gov/cardholders">https://smartpay.gsa.gov/cardholders</a>.</p>
<p>&#8220;The GSA SmartPay program, established in 1998, is the largest charge card program in the world serving more than 350 federal agencies, organizations, and Native American tribal governments. In FY10, approximately 98.9M transactions were made and $30.2B were charged using the GSA SmartPay charge cards, creating $325.9M in refunds.&#8221;</p>
<p>&#8220;Eligibility for the program is determined by the GSA SmartPay Contracting Officer. Federal agencies, departments, tribal organizations, and approved non-federal entities can apply to obtain charge card services under the GSA SmartPay program.&#8221;</p>
<p>If we take a look at the malicious files we will find that it was exploiting CVE-2012-1889 in the background:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-20-a-las-11.45.00.png"><img class="alignleft size-large wp-image-2138" title="Captura de pantalla 2013-03-20 a la(s) 11.45.00" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-20-a-las-11.45.00-1024x567.png" alt="" width="590" height="326" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>During the exploitation it will load the following files as well:</p>
<p>www[.]gsasmartpay[.]org/cardholders/login/movie[.]swf?apple=AA969692D8CDCD959595CC859183918F83909692839BCC8D9085CD83868D808784CC919584E2E2E2E2<br />
www[.]gsasmartpay[.]org/cardholders/login/deployJava[.]js<br />
www[.]gsasmartpay[.]org/cardholders/login/faq[.]htm</p>
<p>We are not going to show how this vulnerability is exploited since we have showed it in previous blog posts, you can find a good description <a title="http://www.symantec.com/connect/blogs/cve-2012-1889-action" href="http://www.symantec.com/connect/blogs/cve-2012-1889-action">here</a>.</p>
<p><!--StartFragment-->searching-job.net is another domain registered by the Sykipot actors (registered by thomas7610@yahoo.com on 06-20-2012) that was also serving the same exploit at that time:</p>
<p>www[.]searching-job[.]net/list/verification/deployJava[.]js<br />
www[.]searching-job[.]net/list/verification/faq[.]htm<br />
www[.]searching-job[.]net/list/verification/index[.]htm<br />
www[.]searching-job[.]net/list/verification/movie[.]swf?apple=AA969692D8CDCD959595CC91878390818A8B8C85CF888D80CC8C8796CD848B8E878E8B9196CC868396E2E2E2E2<br />
www[.]searching-job[.]net/account_list/verification/index[.]htm</p>
<p>&nbsp;</p>
<p><!--EndFragment--></p>
<p>Apart from gsasmartpay.org we have found several domains registered by the Sykipot actors that they have probably used to phish users in the last few months. Some of the most suspicious ones are detailed below:</p>
<p>- dfasonline.com registered by alcott.churchill@yahoo.com on 06-19-2012</p>
<p>Probably related to Defense Finance and Accounting Service &#8211; DFAS - <a title="http://www.dfas.mil/" href="http://www.dfas.mil/">http://www.dfas.mil/</a></p>
<p><!--StartFragment--> - aafbonus.com registered by janagreen2000@yahoo.com on 06-19-2012</p>
<p>Probably related to American Advertising Federation &#8211; <a title="http://www.aaf.org/ " href="http://www.aaf.org/ ">http://www.aaf.org/ </a></p>
<p><!--StartFragment--> - nceba.org registered by jimgreen200088@yahoo.com on 07-24-2012</p>
<p>Probably related to U.S. BANKRUPTCY ADMINISTRATOR - <a title="http://www.nceba.uscourts.gov/" href="http://www.nceba.uscourts.gov/">http://www.nceba.uscourts.gov/</a></p>
<p><!--StartFragment--> - pdi2012.org registered by alcott.churchill@yahoo.com on 08-18-2011</p>
<p>Probably related to PDI 2012, the premier training event hosted by the American Society of Military Comptrollers</p>
<p><!--StartFragment-->- hudsoninst.com registered by alcott.churchill@yahoo.com on 11-26-2012</p>
<p>Probably related to the Hudson Institute &#8211; <a title="http://www.hudson.org/ " href="http://www.hudson.org/ ">http://www.hudson.org/ </a></p>
<p>Hudson Institute is a nonpartisan, independent policy research organization dedicated to innovative research and analysis that promotes global security, prosperity, and freedom.</p>
<p>&nbsp;</p>
<p><!--StartFragment--><strong>CVE-2012-4969 &#8211; Internet Explorer</strong></p>
<p>In September last year, the Sykipot actors registered several domains to exploit a vulnerability in Internet Explorer (<a title="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4969" href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4969">CVE-2012-4969</a>).</p>
<p><!--StartFragment--> - resume4jobs.net registered by james.wade1@yahoo.com on 03-08-2012</p>
<p>URL&#8217;s involved:</p>
<p>http://www[.]resume4jobs[.]net/account/1024486[.]html</p>
<p>http://www[.]resume4jobs[.]net/account/embed[.]htm</p>
<p>http://www[.]resume4jobs[.]net/jobs[.]exe Sykipot malware that uses info[.]resume4jobs[.]net as the C&amp;C</p>
<p>- paypal1.dns1.us &#8211; Dynamic DNS provider</p>
<p>URL&#8217;s involved:</p>
<p>http://paypal1[.]dns1[.]us/account/1024486[.]html</p>
<p>http://paypal1[.]dns1[.]us/account/embed[.]htm</p>
<p>- pollingvoter.org registered by jimgreen200088@yahoo.com on 06-11-2012</p>
<p>URL&#8217;s involved:</p>
<p>http://www[.]pollingvoter[.]org/ne2012/vote/embed[.]htm</p>
<p>http://www[.]pollingvoter[.]org/life[.]exe Sykipot malware that uses www[.]betterslife[.]com as the C&amp;C</p>
<p><!--StartFragment-->- skyruss.net registered by joneluxara@yahoo.com on 04-17-2012</p>
<p>URL&#8217;s involved:</p>
<p>http://social[.]sns[.]skyruss[.]net/variety/index[.]html</p>
<p>http://forum[.]skyruss[.]net/articles/embed[.]htm</p>
<p><!--StartFragment--></p>
<p>&nbsp;</p>
<p><strong>CVE-2012-1723 &#8211; Java 7</strong></p>
<p><strong><!--EndFragment--></strong></p>
<p><!--EndFragment--></p>
<p>In August, they were exploiting a vulnerability in Java (CVE-2012-1723) to gain access to the victim&#8217;s systems. It seems they were using the Metasploit version of the exploit.</p>
<p>Some examples are:</p>
<p>- slashdoc.org registered by jessantt@gmail.com on 05-21-2012</p>
<p>URL&#8217;s involved:</p>
<p>http://www[.]slashdoc[.]org/default[.]jar</p>
<p>http://www[.]slashdoc[.]org/index[.]html</p>
<p>The index.html page loads the malicious Java applet and it passes the payload they want to execute using the data parameter (the value is hex encoded):</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-20-a-las-12.50.14.png"><img class="alignleft size-large wp-image-2142" title="Captura de pantalla 2013-03-20 a la(s) 12.50.14" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-20-a-las-12.50.14-1024x177.png" alt="" width="590" height="101" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div style="text-align: left;">In this case the host www[.]photosmagnum[.]com was used as the C&amp;C server.</div>
<div></div>
<div>- nceba.org registered by jimgreen200088@yahoo.com on 07-24-2012</div>
<div></div>
<div>URL&#8217;s involved:</div>
<div>http://www[.]nceba[.]org/newsroom/article/news201207240251[.]html</div>
<div>
<p>http://www[.]nceba[.]org/newsroom/article/default[.]jar</p>
<p>Using www[.]betterslife[.]com as the C&amp;C server.</p>
<p>- milstars.org registered by slyan8024@gmail.com on 06-20-2012</p>
<p>URL&#8217;s involved:</p>
<p>http://milstars[.]org/view/default[.]jar</p>
<p>&nbsp;</p>
<p><strong>CVE-2013-0640 &#8211; PDF Exploit targeting Japanese victims</strong></p>
<p>We found the Sykipot actors using the latest Adobe Acrobat exploit (CVE-2013-0640) a few weeks ago.</p>
<p>The version of the exploit is the same that we found in our latest blog post:</p>
<p>- <a title="http://labs.alienvault.com/labs/index.php/2013/latest-adobe-pdf-exploit-used-to-target-uyghur-and-tibetan-activists/" href="http://labs.alienvault.com/labs/index.php/2013/latest-adobe-pdf-exploit-used-to-target-uyghur-and-tibetan-activists/">Latest Adobe PDF exploit used to target Uyghur and Tibetan activists</a></p>
<p>The Javascript code inside the PDF file is very similar to the one found in the Itaduke samples but part of the initial variables and the obfuscation has been removed from the original one.</p>
<p>Once the PDF is opened the following lure file is displayed to the victim:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-20-a-las-13.28.26.png"><img class="alignleft size-large wp-image-2143" title="Captura de pantalla 2013-03-20 a la(s) 13.28.26" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-20-a-las-13.28.26-872x1024.png" alt="" width="590" height="692" /></a></p>
<div></div>
<p>&nbsp;</p>
<p>&nbsp;</p>
</div>
<div></div>
<div></div>
<div></div>
<p><!--EndFragment--></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Based on the content of the lure document the potential victims seem to be somehow related to the <strong>Japanese Ministry of Health, Labour and Welfare</strong></p>
<p>Once the infection takes place the following fiels are created on the system:</p>
<p>\DOCUME~1\ADMINI~1\LOCALS~1\Temp\pfilede.dat 5ED3A94354F27BC7AF0FEF04F89D8EB8<br />
\DOCUME~1\ADMINI~1\LOCALS~1\mpr.dll 84EFAFF343CF7A34D2A0D847A1E5FD50<br />
\DOCUME~1\ADMINI~1\LOCALS~1\setm.ini 00051F392350128BA4DD4CA10F44DDEF<br />
\DOCUME~1\ADMINI~1\LOCALS~1\temp.dll BEA84BE4BFE236652F6A4E382B21A96F</p>
<p>The file setm.ini contains the configuration of Sykipot in this case:</p>
<p>[srv_info]<br />
sleeptime=3600000<br />
url=bassball[.]peocity[.]com (C&amp;C server)<br />
scexe=rsvp.exe<br />
scdll=mpr.dll<br />
runexe=run.exe<br />
mark=0304adbh</p>
<p>The following actions take place in the system:</p>
<p>cmd /c reg add HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run /v start /t REG_SZ /d [sykipot_payload_file].exe -startup /f (persistence)</p>
<p>Several functions are called within the Sykipot&#8217;s DLL:</p>
<p>[sykipot_payload_file].exe -startupEx<br />
[sykipot_payload_file].exe -startup1<br />
cmd /c [sykipot_payload_file].exe -startup</p>
<p>Then the malicious payload will be injected into Internet Explorer.</p>
<p>The malware will communicate with the C&amp;C server once in a while using SSL and the well known communication paths of previous Sykipot payloads:</p>
<p>/kys_allow_put.asp?type=<br />
/kys_allow_get.asp?name=</p>
<p>As we showed in the past most of the Sykipot samples used the key &#8220;19990817&#8243; for encryption.In this sample we have found a new key &#8220;20120709&#8243; that is also a date.</p>
<p>&nbsp;</p>
<p><strong>Infrastructure</strong></p>
<p>Along with the blog post we are making a list of new domains public that weren&#8217;t mentioned in previous Sykipot research:</p>
<p><strong></strong>Unique malicious domains:</p>
<ul>
<li>peocity.com</li>
<li>rusview.net</li>
<li>skyruss.net</li>
<li>commanal.net</li>
<li>natareport.com</li>
<li>photogellrey.com</li>
<li>photogalaxyzone.com</li>
<li>insdet.com</li>
<li>creditrept.com</li>
<li>pollingvoter.org</li>
<li>dfasonline.com</li>
<li>hudsoninst.com</li>
<li>wsurveymaster.com</li>
<li>nhrasurvey.org</li>
<li>pdi2012.org</li>
<li>nceba.org</li>
<li>linkedin-blog.com</li>
<li>aafbonus.com</li>
<li>milstars.org</li>
<li>vatdex.com</li>
<li>insightpublicaffairs.org</li>
<li>applesea.net</li>
<li>appledmg.net</li>
<li>appleintouch.net</li>
<li>seyuieyahooapis.com</li>
<li>appledns.net</li>
<li>emailserverctr.com</li>
<li>dailynewsjustin.com</li>
<li>hi-tecsolutions.org</li>
<li>slashdoc.org</li>
<li>photosmagnum.com</li>
<li>resume4jobs.net</li>
<li>searching-job.net</li>
<li>servagency.com</li>
<li>gsasmartpay.org</li>
<li>tech-att.com</li>
</ul>
<p><!--EndFragment--></p>
<p>We are releasing <a title="https://github.com/jaimeblasco/AlienvaultLabs/tree/master/malware_analysis/Sykipot" href="https://github.com/jaimeblasco/AlienvaultLabs/tree/master/malware_analysis/Sykipot">Snort rules to detect queries to the malicious domains in your network</a>:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-21-a-las-16.51.20.png"><img class="alignleft size-large wp-image-2172" title="Captura de pantalla 2013-03-21 a la(s) 16.51.20" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-21-a-las-16.51.20-1024x351.png" alt="" width="590" height="202" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Thanks to <a title="http://www.emergingthreats.net/" href="http://www.emergingthreats.net/">EmergingThreats</a> for the help. You will find the rules in its ruleset update today as well.</p>
<p>Based in our research, below is the list of unique e-mail addreses used to registered malicious domains:</p>
<ul>
<li>233@lao.com</li>
<li>Joneluxara@yahoo.com</li>
<li>alcott.churchill@yahoo.com</li>
<li>b@bvc.com</li>
<li>calvin.kliff@yahoo.com</li>
<li>carrier.fisher@hotmail.com</li>
<li>conan0557@126.com</li>
<li>james.wade1@yahoo.com</li>
<li>janagreen2000@yahoo.com</li>
<li>jessantt@gmail.com</li>
<li>jimgreen200088@yahoo.com</li>
<li>jimgreen20008@yahoo.com</li>
<li>marialreyna11211919@yahoo.com</li>
<li>morgan.wale1@yahoo.com</li>
<li>mskinner62@yahoo.com</li>
<li>myhog@hotmail.com</li>
<li>parviz7415@yahoo.com</li>
<li>slyan8024@gmail.com</li>
<li>thomas7610@yahoo.com</li>
</ul>
<p><!--EndFragment--></p>
<p>Apart from the list of new domains you should check out the domains mentioned in the following articles that all related to previous Sykipot&#8217;s activity but some of them are still being used in Sykipot&#8217;s operations:</p>
<p>- <a title="http://labs.alienvault.com/labs/index.php/2012/sykipot-is-back/" href="http://labs.alienvault.com/labs/index.php/2012/sykipot-is-back/">Sykipot is back</a> - Alienvault Labs</p>
<p>- <a title="http://www.symantec.com/connect/blogs/sykipot-attacks" href="http://www.symantec.com/connect/blogs/sykipot-attacks">The Sykipot Attacks</a> - Symantec</p>
<p>- <a title="http://blog.trendmicro.com/trendlabs-security-intelligence/the-sykipot-campaign/" href="http://blog.trendmicro.com/trendlabs-security-intelligence/the-sykipot-campaign/">The Sykipot Campaign</a> &#8211; TrendMicro</p>
<p>- <a title="http://securityblog.verizonbusiness.com/2012/10/31/hurricane-sandy-serves-as-lure-to-deliver-sykipot/" href="http://securityblog.verizonbusiness.com/2012/10/31/hurricane-sandy-serves-as-lure-to-deliver-sykipot/">Hurricane Sandy serves as lure to deliver Sykipot</a> - Verizon</p>
<p>- <a title="http://www.symantec.com/connect/blogs/insight-sykipot-operations-0" href="http://www.symantec.com/connect/blogs/insight-sykipot-operations-0">Insight into Sykipot Operations</a> - Symantec</p>
<p>-<a title="http://www.cybersquared.com/wp-content/uploads/downloads/2013/03/Medical-Industry-A-Cyber-Victim-Billions-Stolen-and-Lives-At-Risk.pdf" href="http://www.cybersquared.com/wp-content/uploads/downloads/2013/03/Medical-Industry-A-Cyber-Victim-Billions-Stolen-and-Lives-At-Risk.pdf"> Medical Industry A CYBER VICTIM: BILLIONS STOLEN AND LIVES AT RISK</a> - Cyber Squared</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div class="simple_likebuttons_container_small">
      <div class="simple_likebuttons_googleplus">
        <g:plusone size="medium" count="false" href="http://labs.alienvault.com/labs/index.php/2013/new-sykipot-developments/"></g:plusone>
      </div>
    
      <div class="simple_likebuttons_twitter simple_likebuttons_twitter_s">
        <a href="https://twitter.com/share" class="twitter-share-button" data-count="none" data-url="http://labs.alienvault.com/labs/index.php/2013/new-sykipot-developments/" data-lang="en">Tweet</a>
      </div>
    </div>]]></content:encoded>
			<wfw:commentRss>http://labs.alienvault.com/labs/index.php/2013/new-sykipot-developments/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A theory on the South Korean attacks</title>
		<link>http://labs.alienvault.com/labs/index.php/2013/a-theory-on-the-south-korean-attacks/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=a-theory-on-the-south-korean-attacks</link>
		<comments>http://labs.alienvault.com/labs/index.php/2013/a-theory-on-the-south-korean-attacks/#comments</comments>
		<pubDate>Thu, 21 Mar 2013 01:39:23 +0000</pubDate>
		<dc:creator>jaime.blasco</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://labs.alienvault.com/labs/?p=2159</guid>
		<description><![CDATA[During the day I&#8217;ve been thinking about what have just happened in South Korea. We have published earlier today a quick blog post about how the wiper payload works. It is a very simple piece of code that overwrites the MBR (Master Boot Record) making the affected system unable to start after reboot. Other companies have &#8230; <a href="http://labs.alienvault.com/labs/index.php/2013/a-theory-on-the-south-korean-attacks/">Read more <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>During the day I&#8217;ve been thinking about what have just <a title="http://www.guardian.co.uk/world/2013/mar/20/south-korea-under-cyber-attack" href="http://www.guardian.co.uk/world/2013/mar/20/south-korea-under-cyber-attack">happened in South Korea</a>.</p>
<p><a title="http://labs.alienvault.com/labs/index.php/2013/information-about-the-south-korean-banks-and-media-systems-attacks/" href="http://labs.alienvault.com/labs/index.php/2013/information-about-the-south-korean-banks-and-media-systems-attacks/">We have published earlier today a quick blog post about how the wiper payload works</a>. It is a very simple piece of code that overwrites the MBR (Master Boot Record) making the affected system unable to start after reboot.</p>
<p>Other companies have published information about the wiper payloads but anyone is giving information about how the attackers gained access to the affected networks. To execute that payload they had to gain access to the companies somehow and execute the wiping routine at the same time in the affected computers.</p>
<p>If the goal of the attackers was to create panic it means they hadn&#8217;t to have a specific list of victims, had they?.  From my point of view one of the easiest ways to gain access to several targets without having too much resources/skills would be:</p>
<p>- Buy an exploit kit and a malware kit, hack into websites and redirect victims to your malicious infrastructure.</p>
<p>or even better:</p>
<p>- Rent a botnet(s) that have access to hundreds of computers and try to find victims inside interesting targets.</p>
<p>We have seen in the past that large botnets like <a title="http://www.wired.co.uk/news/archive/2012-11/02/russian-cybercrime" href="http://www.wired.co.uk/news/archive/2012-11/02/russian-cybercrime">Zeus or other financial driven botnets had access to systems within the networks of large organizations such as Bank of America, Amazon and NASA</a>.</p>
<p>Therefore, finding infected systems in Broadcasting &amp; Cable companies in South Korea like KBS, MBC and YTN (victims of the attacks) inside fraud botnets wouldn&#8217;t be unusual, would it be?.</p>
<p>The fact is that after reading some of the Korean news about the attacks:</p>
<p>- <a title="http://m.kukinews.com/view.asp?gCode=news&amp;arcid=0007006484&amp;code=41121111" href="http://m.kukinews.com/view.asp?gCode=news&amp;arcid=0007006484&amp;code=41121111">http://m.kukinews.com/view.asp?gCode=news&amp;arcid=0007006484&amp;code=41121111</a></p>
<p>- <a title="http://www.zdnet.co.kr/news/news_view.asp?artice_id=20130320185309" href="http://www.zdnet.co.kr/news/news_view.asp?artice_id=20130320185309">http://www.zdnet.co.kr/news/news_view.asp?artice_id=20130320185309</a></p>
<p>I found they mentioned several filenames that were involved on the attacks such as apcruncmd.exe, imbc.exe, sbs.exe, kbs.exe, Bull.exe, Sun.exe, asd.exe, 38.exe, 39.exe, Sad.exe, down.exe, v3lite.exe.</p>
<p><strong><a title="http://labs.alienvault.com/labs/index.php/2013/information-about-the-south-korean-banks-and-media-systems-attacks/" href="http://labs.alienvault.com/labs/index.php/2013/information-about-the-south-korean-banks-and-media-systems-attacks/">We&#8217;ve only analyzed ApcRunCmd.exe</a> </strong> that is the payload that overwrites the MBR<strong>.</strong> If the information about the filenames is accurate enough, what about the other filenames?.</p>
<p>Armed with patience we began the search of pieces of malware that could generate those filenames and also be related to South Korea.</p>
<p>The first file we found was <a title="https://www.virustotal.com/en/file/b7c6caddb869d8c64e34478223108c605c28c7b725f4d1f79e19064cffca74fa/analysis/" href="https://www.virustotal.com/en/file/b7c6caddb869d8c64e34478223108c605c28c7b725f4d1f79e19064cffca74fa/analysis/">b7c6caddb869d8c64e34478223108c605c28c7b725f4d1f79e19064cffca74fa</a> that was submitted to VirusTotal two days ago from South Korea.</p>
<p>When the binary is executed, it creates the following files in the system:</p>
<p>- \Local Settings\Temp\1.tmp\bat.bat</p>
<p>- \WINDOWS\Temp\125.exe</p>
<p>- \Temp\<strong>imbc.exe</strong></p>
<p>The content of the bat file is:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-20-a-las-23.40.31.png"><img class="alignleft size-large wp-image-2160" title="Captura de pantalla 2013-03-20 a la(s) 23.40.31" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-20-a-las-23.40.31-1024x225.png" alt="" width="590" height="129" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Basically it clears the DNS cache for Internet Explorer and modifies the etc/hosts file adding new entries.When the victim resolves the South Korean bank&#8217;s domain names included in the modified &#8220;etc/hosts&#8221; file, the domains will point to 103.14.114.156.</p>
<p>It seems the malware is also starting the Task Scheduler service using the command &#8220;net start Task Scheduler&#8221; probably to create some tasks with malicious purposes.Finally it creates an autostart registry key to maintain persistence.</p>
<p>The malware connects to the host home1[.]hades08[.]com (126.7.217.163)</p>
<p>We have found several samples with the same behavior and using the same filename (<strong>imbc.exe</strong>) and connecting to similar C&amp;C servers, examples:</p>
<p>- home2[.]hades08[.]com (126.7.217.163)</p>
<p>- home3[.]hades08[.]com (126.7.217.163)</p>
<p>Other suspicious binaries matching the patterns we were looking for and submitted from South Korean in the last few days were:</p>
<p><a title="https://www.virustotal.com/en/file/11f6569e3453dbf2c8c392a1bf653c84e7b2dbc6d90a22936c95bf843bfcda73/analysis/" href="https://www.virustotal.com/en/file/11f6569e3453dbf2c8c392a1bf653c84e7b2dbc6d90a22936c95bf843bfcda73/analysis/">11f6569e3453dbf2c8c392a1bf653c84e7b2dbc6d90a22936c95bf843bfcda73</a> -</p>
<p>Filename: <strong>kbs.exe</strong></p>
<p>Sigcheck:</p>
<p>publisher&#8230;&#8230;&#8230;&#8230;&#8230;.: nhncorp<br />
product&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;: nhncorp<br />
internal name&#8230;&#8230;&#8230;&#8230;: nhncorp<br />
file version&#8230;&#8230;&#8230;&#8230;.: 1,0,0,0<br />
copyright&#8230;&#8230;&#8230;&#8230;&#8230;.: nhncorp<br />
description&#8230;&#8230;&#8230;&#8230;..: nhncorp</p>
<p><a title="https://www.virustotal.com/en/file/0b445a03690cd857079577da29860c8b036f084a09885bb01499df553e3640c5/analysis/" href="https://www.virustotal.com/en/file/0b445a03690cd857079577da29860c8b036f084a09885bb01499df553e3640c5/analysis/">0b445a03690cd857079577da29860c8b036f084a09885bb01499df553e3640c5</a></p>
<p>Filename: <strong>v3lite.exe</strong></p>
<p>Connects to 121.156.58.135</p>
<p>All the files we mentioned are from the same malware family for sure, they have very similar behaviours with some slightly differences and their filenames match with the list we found in the South Korean news. Some vendors call this family Win32.Morix.</p>
<p>Chinese packer/language</p>
<p>The domain hades08[.]com was registered by smokeno@163.com a week ago.</p>
<p>We found the following subdomain:</p>
<p>ddd[.]hades08[.]com that seems to be serving a version of the <a title="http://www.kahusecurity.com/2012/new-chinese-exploit-pack/" href="http://www.kahusecurity.com/2012/new-chinese-exploit-pack/">Chinese Exploit Kit named GonDad</a>:</p>
<p><a title="http://urlquery.net/report.php?id=1528549" href="http://urlquery.net/report.php?id=1528549">http://urlquery.net/report.php?id=1528549</a></p>
<p><a title="http://www.google.com/safebrowsing/diagnostic?site=http://ddd.hades08.com/king/GbHc0.swf&amp;hl=en" href="http://www.google.com/safebrowsing/diagnostic?site=http://ddd.hades08.com/king/GbHc0.swf&amp;hl=en">According to Google it infected the domain blogermoney[.]com</a></p>
<p>We found another website, d41[.]<em>asdasd2012[.]com serving the GonDad exploit kit.</em></p>
<p><a title="http://urlquery.net/report.php?id=1528774" href="http://urlquery.net/report.php?id=1528774">http://urlquery.net/report.php?id=1528774</a></p>
<p>The domain registrant for asdasd2012[.]com is also smokeno@163.com and it was registered a day after hades08[.].com</p>
<p>The relationship is obvious because dl[.]hades08[.]com is know pointing to the same IP address as mb[.]asdasd2012[.]com (126.7.217.163)</p>
<p>According to Google, the domain asdasd2012[.]com has infected 4 domains in the past 90 days including a South Korean website,<a title="appstory.co.kr" href="appstory.co.kr"> appstory.co.kr</a>.</p>
<p>On the other hand if we get the IP address of the C&amp;C server for the sample with filename <strong>v3lite.exe </strong>we previously mentioned, 121.156.58.135.</p>
<p>Using passive DNS we can found the following subdomains of frcvb[.]com pointed to that IP in the last few days:</p>
<p>tt[.]frcvb[.]com A 121[.]156[.]58[.]135<br />
aaa[.]frcvb[.]com A 121[.]156[.]58[.]135<br />
qqq[.]frcvb[.]com A 121[.]156[.]58[.]135<br />
ttt[.]frcvb[.]com A 121[.]156[.]58[.]135<br />
zzz[.]frcvb[.]com A 121[.]156[.]58[.]135</p>
<p>The domain frcvb[.]com was registered less that a month ago.</p>
<p>According to Google, <a title="http://www.google.com/safebrowsing/diagnostic?site=frcvb.com/" href="http://www.google.com/safebrowsing/diagnostic?site=frcvb.com/">the domain frcvb[.]com has infected 18 domains in the past 90 days</a> including several South Korean websites:</p>
<p><a href="http://www.google.com/safebrowsing/diagnostic?site=koreanmovie.com/">koreanmovie.com/</a></p>
<p><a href="http://www.google.com/safebrowsing/diagnostic?site=chinawoo.kr/">chinawoo.kr/</a></p>
<p>Other domain that we have detected in the same infrastructure is frcob[.]com and it is being used as C&amp;C server for the same malware we previously mentioned</p>
<p><a title="http://www.threatexpert.com/report.aspx?md5=1b40b1ff80738ec2fe5747a28d9726a1" href="http://www.threatexpert.com/report.aspx?md5=1b40b1ff80738ec2fe5747a28d9726a1">http://www.threatexpert.com/report.aspx?md5=1b40b1ff80738ec2fe5747a28d9726a1</a></p>
<p>As another example the following SK websites were also affected by the <em>GonDad exploit kit hosted on frcob[.]com and frcvb[.]com:</em></p>
<p>www.knbox.com<br />
www.keduac.co.kr<br />
raya.co.kr<br />
chinawoo.kr<br />
goam.co.kr<br />
bohumbest.net</p>
<p>&nbsp;</p>
<p><strong>Summary</strong></p>
<p>The fact is we could probably show you dozens of domains hosting versions of the GonDad exploit kit, affecting South Korean websites and related with the malware  family we have been talking about.</p>
<div>It means that hundreds of South Korean websites are pointing to the GonDad exploit kit and probably thousands of South Korean users have been compromised and they are part of a botnet.</div>
<div></div>
<div>If the people behind yesterday&#8217;s South Korean attacks had access to some of the infrastructure we have detailed in the blog post, they could have gained access to hundreds if not thousands of South Korean systems and then they could have chosen which of the compromised systems were in interesting companies. Then they could have manually upload another payload to each of the systems and the could have performed lateral movement to own the network. Once they are in the network they can easily execute the wiping payload.</div>
<div></div>
<div>You should take into account that this is only a theory and it could even be a very small part of all the infrastructure they could have used. Maybe this is only an example and they also bought the service or access to other Exploit kits/botnets as well (Blackhole, Zeus, Koobface&#8230;).</div>
<div></div>
<div>On the other hand both the Exploit kit and the malware mentioned seems to come from China but the attackers could have bought/rent it in the black market. The addresses used to register some of the related domain names were also Chinese ones.</div>
<div></div>
<div></div>
<div class="simple_likebuttons_container_small">
      <div class="simple_likebuttons_googleplus">
        <g:plusone size="medium" count="false" href="http://labs.alienvault.com/labs/index.php/2013/a-theory-on-the-south-korean-attacks/"></g:plusone>
      </div>
    
      <div class="simple_likebuttons_twitter simple_likebuttons_twitter_s">
        <a href="https://twitter.com/share" class="twitter-share-button" data-count="none" data-url="http://labs.alienvault.com/labs/index.php/2013/a-theory-on-the-south-korean-attacks/" data-lang="en">Tweet</a>
      </div>
    </div>]]></content:encoded>
			<wfw:commentRss>http://labs.alienvault.com/labs/index.php/2013/a-theory-on-the-south-korean-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Information about the South Korean banks and media systems attacks</title>
		<link>http://labs.alienvault.com/labs/index.php/2013/information-about-the-south-korean-banks-and-media-systems-attacks/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=information-about-the-south-korean-banks-and-media-systems-attacks</link>
		<comments>http://labs.alienvault.com/labs/index.php/2013/information-about-the-south-korean-banks-and-media-systems-attacks/#comments</comments>
		<pubDate>Wed, 20 Mar 2013 16:36:59 +0000</pubDate>
		<dc:creator>jaime.blasco</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://labs.alienvault.com/labs/?p=2150</guid>
		<description><![CDATA[As many of you would probably know several South Korean banks and media companies have been affected by an attack that has wiped several systems. It seems the South Korean security company Nshc has published more details on his Facebook Page Based on the samples we collected, the malware overwrites the MBR (Master Boot Record) &#8230; <a href="http://labs.alienvault.com/labs/index.php/2013/information-about-the-south-korean-banks-and-media-systems-attacks/">Read more <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>As many of you would probably know several South Korean banks and media companies have been <a title="http://www.guardian.co.uk/world/2013/mar/20/south-korea-under-cyber-attack" href="http://www.guardian.co.uk/world/2013/mar/20/south-korea-under-cyber-attack">affected by an attack that has wiped several systems.</a></p>
<p>It seems the South Korean security company Nshc has published more details on his <a title="https://www.facebook.com/nshc.redalert?ref=hl" href="https://www.facebook.com/nshc.redalert?ref=hl">Facebook Page</a></p>
<p>Based on the samples we collected, the malware overwrites the MBR (Master Boot Record) of the system. After reboot the system can&#8217;t boot anymore.</p>
<p>The samples use the word &#8220;HASTATI&#8221; to overwrite the MBR data:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-20-a-las-17.26.091.png"><img class="alignleft size-medium wp-image-2152" title="Captura de pantalla 2013-03-20 a la(s) 17.26.09" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-20-a-las-17.26.091-300x277.png" alt="" width="300" height="277" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>And then shuts down the system using:</p>
<p>shutdown -r -t 0</p>
<p>We have seen that the samples checks for the presence of several security tools:</p>
<p>AhnLab Policy Agent - pasvc.exe</p>
<p>Hauri ViRobot - clisvc.exe</p>
<p>And tries to kill them using taskkill:</p>
<p>taskkill /F /IM pasvc.exe<br />
taskkill /F /IM clisvc.exe</p>
<p>Within the samples we found references to three words:</p>
<p>PRINCPES<br />
HASTATI.<br />
NCPES</p>
<p><a title="http://en.wikipedia.org/wiki/Hastati" href="http://en.wikipedia.org/wiki/Hastati">According to Wikipedia</a>. &#8220;<em><strong>Hastati</strong></em> (singular: <em>Hastatus</em>) were a class of infantry in the <a title="Structural history of the Roman military" href="http://en.wikipedia.org/wiki/Structural_history_of_the_Roman_military#Manipular_legion_.28509_BC_.E2.80.93_107_BC.29">armies of the early Roman Republic</a> who originally fought as <a title="Spear" href="http://en.wikipedia.org/wiki/Spear">spearmen</a>, and later as <a title="Swordsmen" href="http://en.wikipedia.org/wiki/Swordsmen">swordsmen</a>. They were originally some of the poorest men in the legion, and could afford only modest equipment—light armour and a large shield, in their service as the lighter infantry of the legion. Later, the <em>hastati</em> contained the younger men rather than just the poorer, though most men of their age were relatively poor. Their usual position was the first battle line. They fought in a <a title="Quincunx" href="http://en.wikipedia.org/wiki/Quincunx">quincunx</a> formation, supported by light troops. They were eventually done away with after the <a title="Marian reforms" href="http://en.wikipedia.org/wiki/Marian_reforms">Marian reforms</a> of 107 BC&#8221;</p>
<p>Related samples:</p>
<p>ApcRunCmd.exe db4bbdc36a78a8807ad9b15a562515c4</p>
<p>OthDown.exe 5fcd6e1dace6b0599429d913850f0364</p>
<p>0a8032cd6b4a710b1771a080fa09fb87</p>
<p>f0e045210e3258dad91d7b6b4d64e7f3</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<div class="simple_likebuttons_container_small">
      <div class="simple_likebuttons_googleplus">
        <g:plusone size="medium" count="false" href="http://labs.alienvault.com/labs/index.php/2013/information-about-the-south-korean-banks-and-media-systems-attacks/"></g:plusone>
      </div>
    
      <div class="simple_likebuttons_twitter simple_likebuttons_twitter_s">
        <a href="https://twitter.com/share" class="twitter-share-button" data-count="none" data-url="http://labs.alienvault.com/labs/index.php/2013/information-about-the-south-korean-banks-and-media-systems-attacks/" data-lang="en">Tweet</a>
      </div>
    </div>]]></content:encoded>
			<wfw:commentRss>http://labs.alienvault.com/labs/index.php/2013/information-about-the-south-korean-banks-and-media-systems-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Latest Adobe PDF exploit used to target Uyghur and Tibetan activists</title>
		<link>http://labs.alienvault.com/labs/index.php/2013/latest-adobe-pdf-exploit-used-to-target-uyghur-and-tibetan-activists/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=latest-adobe-pdf-exploit-used-to-target-uyghur-and-tibetan-activists</link>
		<comments>http://labs.alienvault.com/labs/index.php/2013/latest-adobe-pdf-exploit-used-to-target-uyghur-and-tibetan-activists/#comments</comments>
		<pubDate>Thu, 14 Mar 2013 10:55:27 +0000</pubDate>
		<dc:creator>jaime.blasco</dc:creator>
				<category><![CDATA[APT]]></category>
		<category><![CDATA[Attacks]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[IP Reputation]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Snort]]></category>
		<category><![CDATA[CVE-2013-0640]]></category>
		<category><![CDATA[tibet]]></category>
		<category><![CDATA[Uyghur]]></category>
		<category><![CDATA[YNK JAPAN]]></category>

		<guid isPermaLink="false">http://labs.alienvault.com/labs/?p=2071</guid>
		<description><![CDATA[Last month Adobe released a fix to patch a vulnerability that was being exploited in the wild. Kaspersky found that the 0day was being used by a very sophisthicated group to target different governments  using a malware called MiniDuke. Alienvault Labs have detected that a different group of attackers have been using this vulnerability to target &#8230; <a href="http://labs.alienvault.com/labs/index.php/2013/latest-adobe-pdf-exploit-used-to-target-uyghur-and-tibetan-activists/">Read more <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>Last month Adobe <a title="http://www.adobe.com/support/security/bulletins/apsb13-07.html" href="http://www.adobe.com/support/security/bulletins/apsb13-07.html">released a fix to patch a vulnerability</a> that was being exploited in the wild. Kaspersky found that the 0day was being used by a <a title="https://www.securelist.com/en/downloads/vlpdfs/themysteryofthepdf0-dayassemblermicrobackdoor.pdf" href="https://www.securelist.com/en/downloads/vlpdfs/themysteryofthepdf0-dayassemblermicrobackdoor.pdf">very sophisthicated group to target different governments  using a malware called MiniDuke</a>.</p>
<p><a title="http://www.alienvault.com" href="http://www.alienvault.com">Alienvault</a> Labs have detected that a different group of attackers have been using this vulnerability to target non-governmental and human rights organizations.</p>
<p>Together with our partner Kaspersky Labs we are releasing an analysis of this campaign. <a title="https://www.securelist.com/en/blog?weblogid=208194165" href="https://www.securelist.com/en/blog?weblogid=208194165">You can read his report here.</a></p>
<p>Based on the samples we found we believe this group has been running a SpearPhishing campaign from the last few weeks. The files we have analyzed are PDF files that contain code to exploit CVE-2013-0640. Once the victim opens the file, the system gets infected and a lure document is displayed to the victim. Some of the PDF lures we have found are:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-13-a-las-10.24.531.png"><img class="alignleft size-medium wp-image-2075" title="Captura de pantalla 2013-03-13 a la(s) 10.24.53" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-13-a-las-10.24.531-268x300.png" alt="" width="268" height="300" /></a></p>
<p>&nbsp;</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-12-a-las-19.36.122.png"><img class="alignleft size-medium wp-image-2076" title="Captura de pantalla 2013-03-12 a la(s) 19.36.12" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-12-a-las-19.36.122-230x300.png" alt="" width="230" height="300" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Some of the exploit filenames:</p>
<ul>
<li>2013-Yilliq Noruz Bayram Merikisige Teklip.pdf</li>
<li>联名信.pdf</li>
<li>arp.pdf</li>
</ul>
<p>Based on the lures we found it seems the same group is targeting both Tibet and Uyghur activists in the same campaign.</p>
<p>The Javascript code inside the PDF files is very similar to the one found in the Itaduke samples but part of the initial variables and the obfuscation has been removed from the original one.</p>
<p>The shellcode will create the file AcroRd32.exe in the Temp folder. That file decrypts an encrypted block using XOR operations with the key &#8220;0l23kj@nboxu&#8221;.</p>
<p>The malicious payload will perform the following operations:</p>
<p>- Copy \WINDOWS\system32\wuauclt.exe to %APPDATA%\wuauclt\wuauclt.exe<br />
- Drop a malicious DLL under %APPDATA%\wuauclt\clbcatq.dll<br />
- Execute %APPDATA%\wuauclt\wuauclt.exe</p>
<p>Note that wuauclt.exe is a benign system executable. Once the system file is executed, the malicious DLL will be loaded. This technique is known as DLL search order hijacking.</p>
<p>The malicious DLL will be loaded when wuauclt.exe is executed. It is important to show that clbcatq.dll is not exporting all the methods that the original clbcatq.dll has. It only implements the ones that are required to run the malicious code:</p>
<p><strong>Original DLL                                                                       Malicious DLL</strong></p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-13-at-11.07.03-AM.png"><img class="alignleft size-medium wp-image-2079" title="Screen shot 2013-03-13 at 11.07.03 AM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-13-at-11.07.03-AM-233x300.png" alt="" width="233" height="300" /></a></p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-13-at-10.58.04-AM.png"><img class="alignleft size-medium wp-image-2080" title="Screen shot 2013-03-13 at 10.58.04 AM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-13-at-10.58.04-AM-300x88.png" alt="" width="300" height="88" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Once the malicious DLL is loaded, the malicious code will generate the following HTTP request:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-13-at-11.53.14-AM1.png"><img class="alignleft size-medium wp-image-2083" title="Screen shot 2013-03-13 at 11.53.14 AM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-13-at-11.53.14-AM1-300x104.png" alt="" width="300" height="104" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>The server will reply with an encrypted block of code that will be decrypted. The decrypted content is actually a DLL that exports the following functions:</p>
<ul>
<li>GetWorkType</li>
<li>InfectFile</li>
</ul>
<p>The payload will drop the following files:</p>
<ul>
<li>\WINDOWS\system32\wbem\4BA5E980.PBK</li>
<li>\WINDOWS\system32\wbem\mstd32.dll</li>
</ul>
<p>The InfectFile function will modify some code in the system library WINDOWS\system32\mswsock.dll. If we take a look at the patched DLL:</p>
<p>Original version</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-13-at-6.58.23-PM1.png"><img class="alignleft size-full wp-image-2097" title="Screen shot 2013-03-13 at 6.58.23 PM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-13-at-6.58.23-PM1.png" alt="" width="717" height="273" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Modified version:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-13-at-6.55.52-PM1.png"><img class="alignleft size-full wp-image-2098" title="Screen shot 2013-03-13 at 6.55.52 PM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-13-at-6.55.52-PM1.png" alt="" width="724" height="78" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>If we take a look at WSPStartup_0:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-13-at-7.05.44-PM.png"><img class="alignleft size-full wp-image-2099" title="Screen shot 2013-03-13 at 7.05.44 PM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-13-at-7.05.44-PM.png" alt="" width="551" height="138" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>We can see how the malicious DLL mstd32.dll will be loaded everytime the system library mswsock.dll is loaded by a program.</p>
<p>The file mstd32.dll is signed using a certificate issued to “YNK JAPAN Inc. We have seen that certificate being used to sign malware dropped in several NGO attacks in the past.</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-14-at-10.32.50-AM2.png"><img class="alignleft size-medium wp-image-2110" title="Screen shot 2013-03-14 at 10.32.50 AM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-14-at-10.32.50-AM2-300x153.png" alt="" width="300" height="153" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Then the malicious code will perform the following HTTP request every few seconds:</p>
<p><img class="alignleft size-medium wp-image-2082" title="Screen shot 2013-03-13 at 11.52.31 AM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-13-at-11.52.31-AM-300x128.png" alt="" width="300" height="128" /></p>
<div></div>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>The final payload is detected as <strong id="internal-source-marker_0.795006520813331"><a title="http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Trojan%3AWin32%2FSwisyn.K" href="http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Trojan%3AWin32%2FSwisyn.K">Trojan.Win32.Swisyn</a> </strong>and it has a lot of functionality to monitor and steal data from the infected system.</p>
<p>We have identified the following C&amp;C servers for both payloads:</p>
<ul>
<li>ly.micorsofts.net</li>
<li>ip.micrsofts.com</li>
<li>xdx.hotmal1.com</li>
<li>hy.micrsofts.com</li>
</ul>
<div>All the DNS names are pointing to 60.211.253.28 at this time.</div>
<div></div>
<div><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-13-a-las-12.15.30.png"><img class="alignleft size-medium wp-image-2084" title="Captura de pantalla 2013-03-13 a la(s) 12.15.30" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-13-a-las-12.15.30-294x300.png" alt="" width="294" height="300" /></a></div>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Both domains have been registered using the same mail address:</p>
<p><strong>micorsofts.net</strong></p>
<p>Created: 2008-05-12 01:51:10<br />
Expires: 2013-05-12 01:51:10<br />
Last Modified: 2012-05-02 13:26:38</p>
<p>Registrant Contact:<br />
GW SY<br />
li wen li wen (lcb_jn@sina.com)<br />
zq dj<br />
jiningshi, shandongsheng, cn 272000<br />
P: +86.05372178000 F: +86.05372178000</p>
<p><strong>hotmal1.com</strong></p>
<p>Created: 2008-12-30 03:53:18<br />
Expires: 2013-12-30 03:53:18<br />
Last Modified: 2012-12-26 15:32:15</p>
<p>Registrant Contact:<br />
GW SY<br />
li wen li wen (lcb_jn@sina.com)<br />
zq dj<br />
shixiaqu, beijingshi, cn 272000<br />
P: +86.02227238836601 F: +86.02227238836601</p>
<p><a title="http://www.20cn.net/cgi-bin/club/userinfo.pl?user=sdlcb" href="http://www.20cn.net/cgi-bin/club/userinfo.pl?user=sdlcb">Profile of the user on 20cn.net</a></p>
<p>We &#8211; <a title="http://www.alienvault.com" href="http://www.alienvault.com">Alienvault</a> Labs- have written <a title="https://github.com/jaimeblasco/AlienvaultLabs/blob/master/malware_analysis/APT_NGO_wuaclt/snort/apt-wuactl.rules" href="https://github.com/jaimeblasco/AlienvaultLabs/blob/master/malware_analysis/APT_NGO_wuaclt/snort/apt-wuactl.rules">some Snort rules</a> to match the network behavior:</p>
<p style="text-align: left;"> <a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-13-a-las-18.21.36.png"><img class="alignleft size-large wp-image-2093" title="Captura de pantalla 2013-03-13 a la(s) 18.21.36" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-13-a-las-18.21.36-1024x180.png" alt="" width="590" height="103" /></a></p>
<p style="text-align: left;">
<p style="text-align: left;">
<p style="text-align: left;">
<p style="text-align: left;">You can use the <a title="https://github.com/jaimeblasco/AlienvaultLabs/blob/master/malware_analysis/APT_NGO_wuaclt/yara/APT_NGO_wuaclt.yar" href="https://github.com/jaimeblasco/AlienvaultLabs/blob/master/malware_analysis/APT_NGO_wuaclt/yara/APT_NGO_wuaclt.yar">following Yara rule</a> to match the malicious binaries:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-13-a-las-18.20.59.png"><img class="alignleft size-large wp-image-2092" title="Captura de pantalla 2013-03-13 a la(s) 18.20.59" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-13-a-las-18.20.59-1024x387.png" alt="" width="590" height="222" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>And <a title="https://github.com/jaimeblasco/AlienvaultLabs/blob/master/malware_analysis/APT_NGO_wuaclt/yara/APT_NGO_wuaclt_PDF.yar" href="https://github.com/jaimeblasco/AlienvaultLabs/blob/master/malware_analysis/APT_NGO_wuaclt/yara/APT_NGO_wuaclt_PDF.yar">this one</a> to detect the malicious PDF files:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-13-a-las-18.22.19.png"><img class="alignleft size-large wp-image-2094" title="Captura de pantalla 2013-03-13 a la(s) 18.22.19" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Captura-de-pantalla-2013-03-13-a-las-18.22.19-1024x283.png" alt="" width="590" height="163" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Finally, we are releasing some <a title="https://github.com/jaimeblasco/AlienvaultLabs/blob/master/malware_analysis/APT_NGO_wuaclt/OpenIOC/3433dad8-879e-40d9-98b3-92ddc75f0dcd.ioc" href="https://github.com/jaimeblasco/AlienvaultLabs/blob/master/malware_analysis/APT_NGO_wuaclt/OpenIOC/3433dad8-879e-40d9-98b3-92ddc75f0dcd.ioc">OpenIOC indicators</a> as well:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-13-at-8.17.48-PM.png"><img class="alignleft size-full wp-image-2103" title="Screen shot 2013-03-13 at 8.17.48 PM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-13-at-8.17.48-PM.png" alt="" width="619" height="243" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-13-at-8.17.59-PM.png"><img class="alignleft size-full wp-image-2104" title="Screen shot 2013-03-13 at 8.17.59 PM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/03/Screen-shot-2013-03-13-at-8.17.59-PM.png" alt="" width="430" height="135" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>You can find all the content in our <a title="https://github.com/jaimeblasco/AlienvaultLabs/tree/master/malware_analysis/APT_NGO_wuaclt" href="https://github.com/jaimeblasco/AlienvaultLabs/tree/master/malware_analysis/APT_NGO_wuaclt">GitHub repository</a>.</p>
<p>The rules have been included in the <a title="http://www.emergingthreats.net/" href="http://www.emergingthreats.net/">EmergingThreats ruleset </a>as well as in our <a title="http://communities.alienvault.com/" href="http://communities.alienvault.com/">Open Source SIEM</a>.</p>
<p>&nbsp;</p>
<div class="simple_likebuttons_container_small">
      <div class="simple_likebuttons_googleplus">
        <g:plusone size="medium" count="false" href="http://labs.alienvault.com/labs/index.php/2013/latest-adobe-pdf-exploit-used-to-target-uyghur-and-tibetan-activists/"></g:plusone>
      </div>
    
      <div class="simple_likebuttons_twitter simple_likebuttons_twitter_s">
        <a href="https://twitter.com/share" class="twitter-share-button" data-count="none" data-url="http://labs.alienvault.com/labs/index.php/2013/latest-adobe-pdf-exploit-used-to-target-uyghur-and-tibetan-activists/" data-lang="en">Tweet</a>
      </div>
    </div>]]></content:encoded>
			<wfw:commentRss>http://labs.alienvault.com/labs/index.php/2013/latest-adobe-pdf-exploit-used-to-target-uyghur-and-tibetan-activists/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Yara rules for APT1/Comment Crew malware arsenal</title>
		<link>http://labs.alienvault.com/labs/index.php/2013/yara-rules-for-apt1comment-crew-malware-arsenal/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=yara-rules-for-apt1comment-crew-malware-arsenal</link>
		<comments>http://labs.alienvault.com/labs/index.php/2013/yara-rules-for-apt1comment-crew-malware-arsenal/#comments</comments>
		<pubDate>Wed, 20 Feb 2013 17:47:10 +0000</pubDate>
		<dc:creator>jaime.blasco</dc:creator>
				<category><![CDATA[APT]]></category>
		<category><![CDATA[Attacks]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[apt1]]></category>
		<category><![CDATA[CommentCrew]]></category>
		<category><![CDATA[fireeye]]></category>
		<category><![CDATA[VolatilityJSUnpack]]></category>
		<category><![CDATA[yara]]></category>

		<guid isPermaLink="false">http://labs.alienvault.com/labs/?p=2060</guid>
		<description><![CDATA[I&#8217;m sure all of you have heard about Mandiant&#8217;s APT1 report published yesterday. As many of you probably know we have been tracking and exposing this group for a long time as well as other individuals and companies in the security industry. A couple of examples are: - Win32/Coswid - Unveiling a spearphishing campaign and possible ramifications &#8230; <a href="http://labs.alienvault.com/labs/index.php/2013/yara-rules-for-apt1comment-crew-malware-arsenal/">Read more <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>I&#8217;m sure all of you have heard about <a title="http://intelreport.mandiant.com/" href="http://intelreport.mandiant.com/">Mandiant&#8217;s APT1 report published yesterday</a>. As many of you probably know we have been tracking and exposing this group for a long time as well as other individuals and companies in the security industry. A couple of examples are:</p>
<p>- <a title="http://labs.alienvault.com/labs/index.php/2012/win32coswid/" href="http://labs.alienvault.com/labs/index.php/2012/win32coswid/">Win32/Coswid</a></p>
<p>- <a title="http://labs.alienvault.com/labs/index.php/2012/unveiling-a-spearphishing-campaign-and-possible-ramifications/" href="http://labs.alienvault.com/labs/index.php/2012/unveiling-a-spearphishing-campaign-and-possible-ramifications/">Unveiling a spearphishing campaign and possible ramifications</a></p>
<p>During the last few years we have been producing content that we have used to track and detect Comment Crew&#8217;s artifacts such as Snort rules, Yara rules and IOCs. We have decided to publish some of this content and we&#8217;ve completed our information with the great intel Mandiant published.  The first package we are releasing is a set of 81 <a title="http://code.google.com/p/yara-project/" href="http://code.google.com/p/yara-project/">Yara</a> rules that will help malware analysts and incident responders to detect, classify and track the malware arsenal used by Comment Crew.</p>
<p>Some of these rules have been built to specifically detect Comment Crew&#8217;s tools and others are more generic.</p>
<p><a title="https://github.com/jaimeblasco/AlienvaultLabs/blob/master/malware_analysis/CommentCrew/apt1.yara" href="https://github.com/jaimeblasco/AlienvaultLabs/blob/master/malware_analysis/CommentCrew/apt1.yara">You can download the rules from here.</a></p>
<p><strong>How can I use the rules?</strong></p>
<p>The easiest way to use this content is installing Yara (<a title="http://code.google.com/p/yara-project/" href="http://code.google.com/p/yara-project/">http://code.google.com/p/yara-project/</a>). Once installed you can use the cmd tool yara to  detect and classify files in your dataset. Example:</p>
<p>$ ../yara-1.6/yara apt1-2.yara files/<br />
APT1_WEBC2_CLOVER files//01114c2b1212524c550bbae7b2bf9750aba70c7c98e2fda13970e05768d644cf<br />
EclipseSunCloudRAT files//021b4ce5c4d9eb45ed016fe7d87abe745ea961b712a08ea4c6b1b81d791f1eca<br />
APT1_TARSIP_ECLIPSE files//021b4ce5c4d9eb45ed016fe7d87abe745ea961b712a08ea4c6b1b81d791f1eca<br />
APT1_WEBC2_Y21K files//02601a267fe980aed4db8ac29336f7ecf1e06f94e9ac0714e968b64586624898<br />
APT1_WEBC2_CSON files//02601a267fe980aed4db8ac29336f7ecf1e06f94e9ac0714e968b64586624898<br />
APT1_b64_cnc_commands files//02601a267fe980aed4db8ac29336f7ecf1e06f94e9ac0714e968b64586624898<br />
APT1_WEBC2_Y21K files//060764506ad9134d5900fc0cd160fc14de80682f1861a3ef084c7c91a734881f<br />
APT1_b64_cnc_commands files//060764506ad9134d5900fc0cd160fc14de80682f1861a3ef084c7c91a734881f<br />
STARSYPOUND_APT1 files//082323fd0f3d24f8fe31895ad1246ae2116aee78d01be83a28c3cbb856541003<br />
APT1_SY files//082323fd0f3d24f8fe31895ad1246ae2116aee78d01be83a28c3cbb856541003<br />
APT1_WARP files//08af44d381df5250323cf196444aa90597f8049dad55712fe45e80b1a8d8cded<br />
APT1_points files//08af44d381df5250323cf196444aa90597f8049dad55712fe45e80b1a8d8cded<br />
APT1_readynewcmd files//0963ba541d56b9805713aa13d955b91f6bb875318698ba6119d5944d68c45afb<br />
HACKSFASE2_APT1 files//0b9ca6fb32fcde1e6e55e8874982a2a921e73c6ebdf7246177fecf63542a4a83<br />
ccrewSSLBack1 files//0b9ca6fb32fcde1e6e55e8874982a2a921e73c6ebdf7246177fecf63542a4a83<br />
APT1_WEBC2_YAHOO files//0c50ddf7295d4ddfafae479e7c3ce21ca6416442c0c8c5e90aedbb3e583a8b20<br />
APT1_uagent_iphone85 files//0c50ddf7295d4ddfafae479e7c3ce21ca6416442c0c8c5e90aedbb3e583a8b20<br />
APT1_letusgo files//0c50ddf7295d4ddfafae479e7c3ce21ca6416442c0c8c5e90aedbb3e583a8b20<br />
APT1_WEBC2_QBP files//0c8ad4824264dd09b3be02f462f968729bf7339438bf5fa69af9ca995353f6df<br />
APT1_WEBC2_GREENCAT files//0e829513658a891006163ccbf24efc292e42cc291af85b957c1603733f0c99d4</p>
<p>On the other hand there are several projects and products that support Yara as a format. Here are some examples:</p>
<p>- <a title="https://code.google.com/p/jsunpack-n/" href="https://code.google.com/p/jsunpack-n/">JSUnpack</a></p>
<p>- <a title="https://www.virustotal.com/" href="https://www.virustotal.com/">Virustotal VTMIS</a></p>
<p>- <a title="http://code.google.com/p/volatility/" href="http://code.google.com/p/volatility/">Volatility</a>, <a title="http://www.evild3ad.com/956/volatility-memory-forensics-basic-usage-for-malware-analysis/" href="http://www.evild3ad.com/956/volatility-memory-forensics-basic-usage-for-malware-analysis/">example of using the Yara plugin in Volatility</a></p>
<p>- <a title="http://www.fireeye.com/" href="http://www.fireeye.com/">Fireeye</a></p>
<p>We&#8217;ve reviewed the rules to minimize false positives but please send us your feedback and we will improve the Yara rules with that information.</p>
<p>Here is the complete list of <a title="https://github.com/jaimeblasco/AlienvaultLabs/blob/master/malware_analysis/CommentCrew/apt1.yara" href="https://github.com/jaimeblasco/AlienvaultLabs/blob/master/malware_analysis/CommentCrew/apt1.yara">Yara rules released</a>:</p>
<p>LIGHTDART_APT1<br />
AURIGA_APT1<br />
AURIGA_driver_APT1<br />
BANGAT_APT1<br />
BISCUIT_GREENCAT_APT1<br />
BOUNCER_APT1<br />
BOUNCER_DLL_APT1<br />
CALENDAR_APT1<br />
COMBOS_APT1<br />
DAIRY_APT1<br />
GLOOXMAIL_APT1<br />
GOGGLES_APT1<br />
HACKSFASE1_APT1<br />
HACKSFASE2_APT1<br />
KURTON_APT1<br />
LONGRUN_APT1<br />
MACROMAIL_APT1<br />
MANITSME_APT1<br />
MINIASP_APT1<br />
NEWSREELS_APT1<br />
SEASALT_APT1<br />
STARSYPOUND_APT1<br />
SWORD_APT1<br />
thequickbrow_APT1<br />
TABMSGSQL_APT1<br />
CCREWBACK1<br />
TrojanCookies_CCREW<br />
GEN_CCREW1<br />
Elise<br />
EclipseSunCloudRAT<br />
MoonProject<br />
ccrewDownloader1<br />
ccrewDownloader2<br />
ccrewMiniasp<br />
ccrewSSLBack2<br />
ccrewSSLBack3<br />
ccrewSSLBack1<br />
ccrewDownloader3<br />
ccrewQAZ<br />
metaxcd<br />
MiniASP<br />
DownloaderPossibleCCrew<br />
APT1_MAPIGET<br />
APT1_LIGHTBOLT<br />
APT1_GETMAIL<br />
APT1_GDOCUPLOAD<br />
APT1_WEBC2_Y21K<br />
APT1_WEBC2_YAHOO<br />
APT1_WEBC2_UGX<br />
APT1_WEBC2_TOCK<br />
APT1_WEBC2_TABLE<br />
APT1_WEBC2_RAVE<br />
APT1_WEBC2_QBP<br />
APT1_WEBC2_KT3<br />
APT1_WEBC2_HEAD<br />
APT1_WEBC2_GREENCAT<br />
APT1_WEBC2_DIV<br />
APT1_WEBC2_CSON<br />
APT1_WEBC2_CLOVER<br />
APT1_WEBC2_BOLID<br />
APT1_WEBC2_ADSPACE<br />
APT1_WEBC2_AUSOV<br />
APT1_WARP<br />
APT1_TARSIP_ECLIPSE<br />
APT1_TARSIP_MOON<br />
APT1_aspnetreport<br />
APT1_Revird_svc<br />
APT1_letusgo<br />
APT1_dbg_mess<br />
APT1_known_malicious_RARSilent</p>
<p><strong>Update</strong> (02/22/2013): We have improved the ruleset, update to the latest version!</p>
<div class="simple_likebuttons_container_small">
      <div class="simple_likebuttons_googleplus">
        <g:plusone size="medium" count="false" href="http://labs.alienvault.com/labs/index.php/2013/yara-rules-for-apt1comment-crew-malware-arsenal/"></g:plusone>
      </div>
    
      <div class="simple_likebuttons_twitter simple_likebuttons_twitter_s">
        <a href="https://twitter.com/share" class="twitter-share-button" data-count="none" data-url="http://labs.alienvault.com/labs/index.php/2013/yara-rules-for-apt1comment-crew-malware-arsenal/" data-lang="en">Tweet</a>
      </div>
    </div>]]></content:encoded>
			<wfw:commentRss>http://labs.alienvault.com/labs/index.php/2013/yara-rules-for-apt1comment-crew-malware-arsenal/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber espionage campaign against the Uyghur community, targeting MacOSX systems</title>
		<link>http://labs.alienvault.com/labs/index.php/2013/cyber-espionage-campaign-against-the-uyghur-community-targeting-macosx-systems/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cyber-espionage-campaign-against-the-uyghur-community-targeting-macosx-systems</link>
		<comments>http://labs.alienvault.com/labs/index.php/2013/cyber-espionage-campaign-against-the-uyghur-community-targeting-macosx-systems/#comments</comments>
		<pubDate>Wed, 13 Feb 2013 16:54:18 +0000</pubDate>
		<dc:creator>jaime.blasco</dc:creator>
				<category><![CDATA[APT]]></category>
		<category><![CDATA[Attacks]]></category>
		<category><![CDATA[Blog]]></category>
		<category><![CDATA[Code]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[backdoor]]></category>
		<category><![CDATA[macosx]]></category>
		<category><![CDATA[MS09-027]]></category>
		<category><![CDATA[office]]></category>

		<guid isPermaLink="false">http://labs.alienvault.com/labs/?p=2015</guid>
		<description><![CDATA[During the last few days together with our colleagues from Kaspersky Lab we have been investigating a new strain of spearphishing mails sent to the Uyghur community. You can read their analysis here. The mails sent contain a Microsoft Office .doc file that exploits MS09-027 affecting Microsoft Office for Mac, this is the same exploit used in other attacks we discovered &#8230; <a href="http://labs.alienvault.com/labs/index.php/2013/cyber-espionage-campaign-against-the-uyghur-community-targeting-macosx-systems/">Read more <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>During the last few days together with our colleagues from Kaspersky Lab we have been investigating a new strain of spearphishing mails sent to the Uyghur community. <a title="https://www.securelist.com/en/blog/208194116/Cyber_Attacks_Against_Uyghur_Mac_OS_X_Users_Intensify" href="https://www.securelist.com/en/blog/208194116/Cyber_Attacks_Against_Uyghur_Mac_OS_X_Users_Intensify">You can read their analysis here</a>.</p>
<p>The mails sent contain a Microsoft Office .doc file that exploits <a title="http://technet.microsoft.com/en-us/security/bulletin/ms09-027" href="http://technet.microsoft.com/en-us/security/bulletin/ms09-027">MS09-027</a> affecting Microsoft Office for Mac, this is the same <a title="http://labs.alienvault.com/labs/index.php/2012/ms-office-exploit-that-targets-macos-x-seen-in-the-wild-delivers-mac-control-rat/" href="http://labs.alienvault.com/labs/index.php/2012/ms-office-exploit-that-targets-macos-x-seen-in-the-wild-delivers-mac-control-rat/">exploit used in other attacks we discovered in the past</a>.</p>
<p>During the last year we reported a couple of attacks targeting Uyghurs:</p>
<p>- <a title="http://labs.alienvault.com/labs/index.php/2012/new-macontrol-variant-targeting-uyghur-users-the-windows-version-using-gh0st-rat/" href="http://labs.alienvault.com/labs/index.php/2012/new-macontrol-variant-targeting-uyghur-users-the-windows-version-using-gh0st-rat/">New MaControl variant targeting Uyghur users, the Windows version using Gh0st RAT</a></p>
<p>Similar attacks have been reported against various ethnic groups like the Tibetan people and other NGOs and human rights organizations:</p>
<p>- <a title="http://labs.alienvault.com/labs/index.php/2012/targeted-attacks-against-tibet-organizations/" href="http://labs.alienvault.com/labs/index.php/2012/targeted-attacks-against-tibet-organizations/"><span style="font-size: 13px; line-height: 19px;">Targeted attacks against Tibet organizations</span></a></p>
<p><span style="font-size: 13px; line-height: 19px;">- </span><a style="font-size: 13px; line-height: 19px;" title="http://labs.alienvault.com/labs/index.php/2012/ms-office-exploit-that-targets-macos-x-seen-in-the-wild-delivers-mac-control-rat/" href="http://labs.alienvault.com/labs/index.php/2012/ms-office-exploit-that-targets-macos-x-seen-in-the-wild-delivers-mac-control-rat/"><span style="font-size: 13px; line-height: 19px;">MS Office exploit that targets MacOS X seen in the wild – delivers “Mac Control” RAT</span></a></p>
<p>They have even <a title="http://labs.alienvault.com/labs/index.php/2012/alienvault-research-used-as-lure-in-targeted-attacks/" href="http://labs.alienvault.com/labs/index.php/2012/alienvault-research-used-as-lure-in-targeted-attacks/">used our research as lure to target non-governmental organizations</a>.</p>
<p><span style="font-size: 13px; line-height: 19px;">Some of the filenames used in this campaign are:</span></p>
<ul>
<li><span style="font-size: 13px; line-height: 19px;">WUC Hacking Emails.doc</span></li>
<li><span style="font-size: 13px; line-height: 19px;">Concerns over Uyghur People.doc</span></li>
<li><span style="font-size: 13px; line-height: 19px;">Hosh Hewer.doc</span></li>
<li><span style="font-size: 13px; line-height: 19px;">Jenwediki yighingha iltimas qilish Jediwili.doc</span></li>
<li><span style="font-size: 13px; line-height: 19px;">Jenwediki yighingha iltimas qilish Jediwili.doc</span></li>
<li><span style="font-size: 13px; line-height: 19px;">list.doc</span></li>
<li><span style="font-size: 13px; line-height: 19px;">Press Release on Commemorat the Day of Mourning.doc</span></li>
<li><span style="font-size: 13px; line-height: 19px;">The Universal Declaration of Human Rights and the Unrecognized Population Groups.doc</span></li>
<li><span style="font-size: 13px; line-height: 19px;">Uyghur Political Prisoner.doc</span></li>
<li><span style="font-size: 13px; line-height: 19px;">Deported Uyghurs.doc</span></li>
<li><span style="font-size: 13px; line-height: 19px;">Kadeer Logistics detail.doc</span></li>
<li><span style="font-size: 13px; line-height: 19px;">Jenwediki yighingha iltimas qilish Jediwili(Behtiyar Omer).doc</span></li>
</ul>
<div>An easy way to identify the documents is looking for the &#8220;author&#8221; of the document that is always &#8220;captain&#8221;. This author has been used several times in the past to perform similar attacks.</div>
<div></div>
<div><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-1.57.41-PM.png"><img class="alignleft size-medium wp-image-2025" title="Screen shot 2013-02-13 at 1.57.41 PM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-1.57.41-PM-300x244.png" alt="" width="300" height="244" /></a></div>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>The following yara rule can be used to identify those files:</p>
<pre class="wp-code-highlight prettyprint">rule CaptainWord {
    strings:
         $header = {D0 CF 11 E0 A1 B1 1A E1}
         $author = {00 00 00 63 61 70 74 61 69 6E 00}
    condition:
         $header at 0 and $author
}</pre>
<p>Once the victim opens the document the exploit is triggered and the shellcode writes several files on the temporary directory (&#8220;/tmp/):</p>
<pre class="wp-code-highlight prettyprint">1154/0x2610:  fstat(0x26, 0xBFFF4CD0, 0x200)            = 0 0
1154/0x2610:  lseek(0x26, 0x6600, 0x0)          = 26112 0
1154/0x2610:  open(&quot;/tmp/l.sh\0&quot;, 0x602, 0x1FF)                 = 40 0
1154/0x2610:  open(&quot;/tmp/l\0&quot;, 0x602, 0x1FF)            = 41 0
1154/0x2610:  open(&quot;/tmp/l.doc\0&quot;, 0x602, 0x1FF)                = 42 0
1154/0x2610:  read(0x26, &quot;#!/bin/bash\nsleep 1\n/usr/bin/open /tmp/l.doc\ncp /tmp/l /tmp/m\n/tmp/m\0&quot;, 0x44)            = 68 0
1154/0x2610:  write(0x28, &quot;#!/bin/bash\nsleep 1\n/usr/bin/open /tmp/l.doc\ncp /tmp/l /tmp/m\n/tmp/m\0&quot;, 0x44)           = 68 0
1154/0x2610:  read(0x26, &quot;\312\376\272\276\0&quot;, 0x100)           = 256 0
1154/0x2610:  write(0x29, &quot;\312\376\272\276\0&quot;, 0x100)          = 256 0
...
1188/0x2731:  open(&quot;/tmp/l\0&quot;, 0x0, 0x0)                = 4 0
1188/0x2731:  open(&quot;/tmp/m\0&quot;, 0x401, 0x0)              = 19 0
…</pre>
<p>Then the bash file is executed opening both the trojan and a lure document. There are several lure documents all related with Uyghur activities, an example is:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-12.49.12-PM1.png"><img class="alignleft size-medium wp-image-2018" title="Screen shot 2013-02-13 at 12.49.12 PM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-12.49.12-PM1-300x228.png" alt="" width="300" height="228" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>It is also funny that one of the lure documents talks about the &#8220;Rise in possible State-Sponsored hacking&#8221;.</p>
<p>Once executed the malware will try to write both the pslist and the backdoor itself under the LaunchAgents directory. This folder is used by MacOSX to store the configuration files that define the parameters of services run by launchd. It will try both under the system and the current user directory:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-1.12.16-PM.png"><img class="alignleft size-full wp-image-2020" title="Screen shot 2013-02-13 at 1.12.16 PM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-1.12.16-PM.png" alt="" width="651" height="108" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-1.12.39-PM1.png"><img class="alignleft size-full wp-image-2022" title="Screen shot 2013-02-13 at 1.12.39 PM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-1.12.39-PM1.png" alt="" width="554" height="93" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Then the command &#8220;launchctl load&#8221; is used to register the new new daemon. The contents of the apple.pslist file are as follow:</p>
<p>&lt;?xml version=&#8221;1.0&#8243; encoding=&#8221;UTF-8&#8243;?&gt;<br />
&lt;!DOCTYPE plist PUBLIC &#8220;-//Apple//DTD PLIST 1.0//EN&#8221; &#8220;http://www.apple.com/DTDs/PropertyList-1.0.dtd&#8221;&gt;<br />
&lt;plist version=&#8221;1.0&#8243;&gt;<br />
&lt;dict&gt;<br />
&lt;key&gt;KeepAlive&lt;/key&gt;<br />
&lt;true/&gt;<br />
&lt;key&gt;Label&lt;/key&gt;<br />
&lt;string&gt;apple&lt;/string&gt;<br />
&lt;key&gt;Program&lt;/key&gt;<br />
&lt;string&gt;/Users/operator1/library/launchagents/.systm&lt;/string&gt;<br />
&lt;key&gt;ProgramArguments&lt;/key&gt;<br />
&lt;array&gt;<br />
&lt;string&gt;/Users/operator1/library/launchagents/.systm&lt;/string&gt;<br />
&lt;string&gt;1&lt;/string&gt;<br />
&lt;string&gt;2&lt;/string&gt;<br />
&lt;string&gt;3&lt;/string&gt;<br />
&lt;string&gt;4&lt;/string&gt;<br />
&lt;/array&gt;<br />
&lt;key&gt;RunAtLoad&lt;/key&gt;<br />
&lt;true/&gt;<br />
&lt;/dict&gt;<br />
&lt;/plist&gt;</p>
<p>The backdoor contains code from a tool called &#8220;Tiny SHell&#8221;. <a title="http://archive.org/details/tucows_306138_Tiny_SHell" href="http://archive.org/details/tucows_306138_Tiny_SHell">You can download the source code of &#8220;Tiny SHell&#8221; here.</a> You will recognize some of the function names from the source code:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-2.18.46-PM.png"><img class="alignleft size-medium wp-image-2026" title="Screen shot 2013-02-13 at 2.18.46 PM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-2.18.46-PM-201x300.png" alt="" width="201" height="300" /></a></p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-2.23.06-PM1.png"><img class="aligncenter size-medium wp-image-2029" title="Screen shot 2013-02-13 at 2.23.06 PM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-2.23.06-PM1-300x61.png" alt="" width="300" height="61" /></a></p>
<p>&nbsp;</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-2.22.58-PM.png"><img class="aligncenter size-medium wp-image-2028" title="Screen shot 2013-02-13 at 2.22.58 PM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-2.22.58-PM-300x45.png" alt="" width="300" height="45" /></a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>The configuration values are hardcoded in the binary including the encryption key and the C&amp;C address/port:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-2.26.14-PM1.png"><img class="aligncenter size-full wp-image-2035" title="Screen shot 2013-02-13 at 2.26.14 PM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-2.26.14-PM1.png" alt="" width="393" height="77" /></a></p>
<p>&nbsp;</p>
<p>&#8220;Tiny SHell&#8221; uses AES encryption for the C&amp;C communications and as we can see the attackers are using &#8220;12345678&#8243; as the AES secret key:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-2.27.55-PM1.png"><img class="aligncenter size-medium wp-image-2036" title="Screen shot 2013-02-13 at 2.27.55 PM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-2.27.55-PM1-300x222.png" alt="" width="300" height="222" /></a></p>
<p>On the other hand they decided to use the original challenge responses that can be found in the original pel.c file:</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-2.33.54-PM1.png"><img class="aligncenter size-full wp-image-2037" title="Screen shot 2013-02-13 at 2.33.54 PM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-2.33.54-PM1.png" alt="" width="412" height="72" /></a></p>
<p>The backdoor has only a couple of functionalities:</p>
<p>- Remote shell execution</p>
<p>- File transfers (get/put)</p>
<p>Most of the binaries we obtained  were compiled using debug symbols so we were able to obtain some debug paths from the machine where the files were compiled:</p>
<p>/Users/cbn/Documents/WorkSpace/design/server/aes.c<br />
/Users/cbn/Documents/WorkSpace/design/server/build/server.build/Release/server.build/Objects-normal/i386/aes.o<br />
/Users/cbn/Documents/WorkSpace/design/server/build/server.build/Release/server.build/Objects-normal/i386/pel.o<br />
/Users/cbn/Documents/WorkSpace/design/server/build/server.build/Release/server.build/Objects-normal/i386/server.o<br />
/Users/cbn/Documents/WorkSpace/design/server/build/server.build/Release/server.build/Objects-normal/i386/sha1.o<br />
/Users/cbn/Documents/WorkSpace/design/server/build/server.build/Release/server.build/Objects-normal/i386/shell.o<br />
/Users/cbn/Documents/WorkSpace/design/server/build/server.build/Release/server.build/Objects-normal/ppc/aes.o<br />
/Users/cbn/Documents/WorkSpace/design/server/build/server.build/Release/server.build/Objects-normal/ppc/pel.o<br />
/Users/cbn/Documents/WorkSpace/design/server/build/server.build/Release/server.build/Objects-normal/ppc/server.o<br />
/Users/cbn/Documents/WorkSpace/design/server/build/server.build/Release/server.build/Objects-normal/ppc/sha1.o<br />
/Users/cbn/Documents/WorkSpace/design/server/build/server.build/Release/server.build/Objects-normal/ppc/shell.o<br />
/Users/cbn/Documents/WorkSpace/design/server/pel.c<br />
/Users/cbn/Documents/WorkSpace/design/server/server.m<br />
/Users/cbn/Documents/WorkSpace/design/server/sha1.c<br />
/Users/cbn/Documents/WorkSpace/design/server/shell.c</p>
<p>Where &#8220;cbn&#8221; is the username of the user who compiled those files in the attacker&#8217;s system.</p>
<p>The backdoor also writes a VCard containing the data about the current user. The purpose of this is not clear.</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-4.42.03-PM.png"><img class="aligncenter size-full wp-image-2044" title="Screen shot 2013-02-13 at 4.42.03 PM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-4.42.03-PM.png" alt="" width="387" height="89" /></a></p>
<p><strong>Network activity</strong></p>
<p>The attackers are using two different C&amp;C domains:</p>
<p>- apple12[.]crabdance[.]com</p>
<p>- update[.]googmail[.]org</p>
<p>The domain crabdance[.]com is a well known free Dynamic DNS provider. We have been monitoring the second domain googmail[.]org for a while. It has been used by a group we internally named as &#8220;xsldmt&#8221; due to the mail address they use to register most of their domain names the use.</p>
<p>Domain Name:GOOGMAIL.ORG<br />
Created On:16-Dec-2011 03:01:13 UTC<br />
Last Updated On:20-Nov-2012 04:46:22 UTC<br />
Expiration Date:16-Dec-2013 03:01:13 UTC<br />
Sponsoring Registrar:Xin Net Technology Corporation (R118-LROR)<br />
Status:OK<br />
Registrant ID:4jyn2c9u84snj4<br />
Registrant Name:su guang<br />
Registrant Organization:su guang<br />
Registrant Street1:mi quannanguoxiang1hao<br />
Registrant Street2:<br />
Registrant Street3:<br />
Registrant City:changjihuizuzizhizhou<br />
Registrant State/Province:xinjiangweiwuerzizhiqu<br />
Registrant Postal Code:830000<br />
Registrant Country:CN<br />
Registrant Phone:+86.013579984824<br />
Registrant Phone Ext.:<br />
Registrant FAX:+86.09914682953<br />
Registrant FAX Ext.:<br />
Registrant Email:<strong>xsldmt@xj163.cn</strong></p>
<p>The following graph represents the passive DNS data we collected from the ip addresses involved including other potential domains that are probably being used by the same group.</p>
<p>&nbsp;</p>
<p><a href="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-2.57.06-PM.png"><img class="aligncenter size-full wp-image-2041" title="Screen shot 2013-02-13 at 2.57.06 PM" src="http://labs.alienvault.com/labs/wp-content/uploads/2013/02/Screen-shot-2013-02-13-at-2.57.06-PM.png" alt="" width="616" height="308" /></a></p>
<p><strong>Indicators of compromise</strong></p>
<p>Apart from the domain names and ip addresses we released that can be used to check your logs for connections to those addresses, here is a list of file paths that can be checked in your systems to find activity related to these attacks:</p>
<pre class="wp-code-highlight prettyprint">/tmp/l
/tmp/m
/tmp/l.sh
/tmp/l.doc
/tmp/systm
/tmp/.systm
/tmp/__system
/tmp/__system*
/tmp/tmpAddressbook.vcf
/Library/LaunchDaemons/systm
/Library/LaunchDaemons/.systm
/Library/LaunchDaemons/apple.plist
/Users/[CurrentUser]/Library/LaunchAgents/systm
/Users/[CurrentUser]/Library/LaunchAgents/.systm
/Users/[CurrentUser]/Library/LaunchAgents/apple.plist</pre>
<p><span style="font-size: 13px; line-height: 19px;"> </span></p>
<div class="simple_likebuttons_container_small">
      <div class="simple_likebuttons_googleplus">
        <g:plusone size="medium" count="false" href="http://labs.alienvault.com/labs/index.php/2013/cyber-espionage-campaign-against-the-uyghur-community-targeting-macosx-systems/"></g:plusone>
      </div>
    
      <div class="simple_likebuttons_twitter simple_likebuttons_twitter_s">
        <a href="https://twitter.com/share" class="twitter-share-button" data-count="none" data-url="http://labs.alienvault.com/labs/index.php/2013/cyber-espionage-campaign-against-the-uyghur-community-targeting-macosx-systems/" data-lang="en">Tweet</a>
      </div>
    </div>]]></content:encoded>
			<wfw:commentRss>http://labs.alienvault.com/labs/index.php/2013/cyber-espionage-campaign-against-the-uyghur-community-targeting-macosx-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
