Showing posts with label ZeroAccess. Show all posts
Showing posts with label ZeroAccess. Show all posts

Monday, October 28, 2013

This morning I've read this in the AlientVault blog: "Google was flagging the php.net website as potentialy harmful".

It is really interesting because if you can spread malware from php.net which according to Alexa, php.net is the 228th most visited site in the world, you will be able to infect to millions of computers.

Currently we can't analyze the php.net website because the page which was hosting the malicious code  has been removed, but the guys from Barracuda have published a PCAP file taken from a computer which visited this website and was infected.

If we upload the PCAP file to VirusTotal we can see the URLs which were visited by the infected computer in the "File details" section. You can see the report of this PCAP file here:




We can see that the www.php.net website was visited. If we open the PCAP file with Wireshark and we look at the "Follow TCP Stream" of the petition  www.php.net/userprefs.js  we can see the script with the obfuscated code in the picture below. (This malicious code has been removed from the website)


The guys from Alienvault have decoded the script. Here they have published the picture below with the code de-ofuscated. We can see an IFRAME with a 10x10px size which redirects the connection to another website was able in the php.net site.


If we research with Wireshark the link contained in the IFRAME in the picture above, we can see how the code is trying to get the information about the computer. It wants to know if the browser has the Java or AdobeReader plugins installed and enabled.


The next URL where the computer is redirected is /PluginDetect_All.js. In the payload of this connection we can see that the hackers are using PluginDetect in order to detect the browser plugins.


In the PCAP file we can see how the computer send a POST connection telling to the website if it has the Java or AdobeReader plugin enabled. Then, the web browser is redirected again.


The connection is redirected again to other site...


...where there are another iframe...


... to this site...


..which is the last site visited before to detect a malicious executable.

The next URL which was visited is marked in bold in VirusTotal. This means that the files that were downloaded are categorized as malware by some antivirus engines.


If we click in the sha256 link...


...we can see that this executables are categorized as malicious.


Now, the computer is infected. The first network connection that the malware does is to visit a website where there are a javascript that detects the computer location.



If we check the next network connections, we can see a lot of them creating connections by 16471/UDP port. This port is usually used by the ZeroAccess Trojan. At the bottom of this post you will find the links which redirects you to other Post talking about some analysis of this Trojan.


If we look at the Snort alerts, we can see the security events detected by this IDS. We can see that it has detected the ZeroAcces Trojan and other interesting events.


CONCLUSION

If we trust in the PCAP file that Barracuda offers us, we can tell that www.php.net was compromised. The hackers uploaded a javascript to this site  which redirects to another one where there was a web plugin detector. Depends of what browser plugins are enabled in the computer, the website could redirects you to a Java or AdobeReader exploit. Then, after exploiting the vulnerability,  a trojan that seems to be the ZeroAccess trojan is donwloaded and installed. It seems that this trojan is focused in click-fraud.


You can learn more about ZeroAccess Trojan here:

http://www.behindthefirewalls.com/2013/06/zeroaccess-trojan-network-analysis-part.html

http://www.behindthefirewalls.com/2013/06/zeroaccess-network-analysis-part-ii.html

http://www.behindthefirewalls.com/2013/06/detecting-zeroaccess-in-your-network.html

http://www.behindthefirewalls.com/2013/04/trying-avoid-callbacks-to-botnet-using.html


Great info:

http://www.alienvault.com/open-threat-exchange/blog/phpnet-potentially-compromised-and-redirecting-to-an-exploit-kit

http://news.netcraft.com/archives/2013/10/24/php-net-blocked-by-google-false-positive-or-not.html

http://barracudalabs.com/2013/10/php-net-compromise/

http://www.sophos.com/en-us/medialibrary/PDFs/technical%20papers/Sophos_ZeroAccess_Botnet.pdf 


Posted on Monday, October 28, 2013 by Javier Nieto

1 comment

Monday, July 01, 2013

As I said in ZeroAccess Trojan - Network Analysis Part I ,  the goal of this trojan is to earn money through Click Fraud...

When the host has been already infected and it is a member of the botnet, the host beginning to generate a large amount of clicks on advertisements. With each click on an advertisment they are making money.




I'm going to show you some Ads which have been clicked. (The links can be removed with the passage of time). The majority of the advertisments are from porn sites.

hxxp:// 81.17.18.18/UFxHW1hYR1hQUUdbXEZWCgUADVRdWhkdWFgYDRlYUVwTWQ==
hxxp:// 95.211.198.25/?clid=43pt11qdp185z0
hxxp:// 108.59.9.168/check.php?tim=1372006112.8719&p=sc61a47575def348b9548c6f0163f50a1c&subid=1296741&affid=269
hxxp:// 108.59.9.168/onclick.php?tim=1372006112.8719&p=sc61a47575def348b9548c6f0163f50a1c&subid=1296741&affid=269&z=142&ch=e9d2bc0d8051a4ed65e44b7741e71895
hxxp:// 108.59.9.168/local_bidding/onclick.php?affid=269&subid=1296741&p=lb_5d9455820f97d61b5eea7bb6c91aea70
hxxp:// 95.211.221.146/speedclicks/in.php?pid=44150&spaceid=210916
hxxp:// 95.211.221.146/speedclicks/out.php?1=1&doc=TOyzbE0DTWV9uJY0j7eiQlQTJgvdnJVb7OcviyVYVbhhdj7w%2BWZHLc%2F4ZpKP6RWb&pid=44150&spaceid=210916&xcheck=RJI%2BAl3WVkZe8dx5Y78SiAkOrlXV%2BHOCycakkOkiwPUzipDXcIJuh%2Fs1E7mliTnmGneP4d%2BuancuIEtZs5aySfwriC5rhmOdHY5dPNnb2S%2B5%2BI0a8I2UAW9gCtWt9OwFgBlHNSt6l22BW34mEUKNGw%3D%3D
hxxp:// 66.6.21.144/services/directlinkhandler.ashx?WID=125576487975&promocode=BCODEJ0000045_6|7810|0|es|1|18704|210916&ptype=1
hxxp:// 66.6.21.144/live-sex-chats/?|7810|0|es|1|18704|210916&ptype=1&removewl=0
hxxp:// 93.184.220.90/App_Themes/master.css?v=190&s=635065331693200
hxxp:// 93.184.220.90/App_Themes/wlg_uni_bla_red/private.css?v=190&s=635048126891371
hxxp:// 93.184.220.90/App_Themes/wlg_uni_bla_red/global.css?v=190&s=635058680419510
hxxp:// 173.194.67.95/ajax/libs/jquery/1.6.4/jquery.min.js
hxxp:// 93.184.220.90/App_Themes/wlg_uni_bla_red/images/mainBackground.gif
hxxp:// 93.184.220.90/App_Themes/wlg_uni_bla_red/images/mainBackgroundCenter.png
hxxp:// 66.6.21.144/Services/ScriptGenerator/p,-4601,/live-sex-chats,190.js
hxxp:// 93.184.220.90/App_Themes/PrivateImages/xcams4u/xcams4u_Logo08_03_12_710_03_1.gif?v=190
hxxp:// 93.184.220.90/App_Themes/images/flags/cultures/en-US.png?v=190
hxxp:// 93.184.220.90/App_Themes/images/Over18_popUp/18_pop_up_black.jpg
hxxp:// 93.184.220.90/App_Themes/wlg_uni_bla_red/images/header/new_login_box.png
hxxp:// 93.184.220.90/wl/App_Themes/PrivateImages/xcams4u/xcams4u_Top08_03_12_710_03_2.gif?v=105
hxxp:// 66.6.21.144/Services/NarrowMenu.ashx?act=count&am=1&ac=635075849646385174
hxxp:// 93.184.220.90/App_Themes/images/flags/cultures/languages.png
hxxp:// 93.184.220.90/App_Themes/images/lf_menu_btm_border.gif

Sophos has published a great document here  They have calculated how much money this botnet is making. The picture below from the Shopos document shows us an approximate calculation.


In my opinion, that is a huge amount of money!!!

Posted on Monday, July 01, 2013 by Javier Nieto

No comments

Friday, June 28, 2013

A few days ago, I talked about How to detect ZeroAccess in your Network   Now, I want to show you how this trojan works.

The goal of this trojan is to earn money through Click Fraud... It is a type of crime that abuses pay-per-click advertising to make money through fraudulent or fake clicks on advertisements. ZeroAccess makes money when it generate clicks on Ads. In addition, ZeroAccess has is own botnet. It is ideal for generating a large number of clicks.

I got a sample of this trojan. I uploaded the binary to Virustotal and only 3 antivirus programs detected it as a trojan. If you want a copy, contact me at the botton of this page.

Currently, you can see how many antivirus programs detect the file as malware:
https://www.virustotal.com/es/file/0aae3d7df5c153378596ac03f1796b8800337e14e243529106cfc681005b7ab7/analysis/

I created a virtual machine and I executed this program in a fresh environment.

The first thing ZeroAccess does is connect to http://j.maxmind.com/app/geoip.js in order to locate the infected host in the world.



The second thing the trojan does is connect with some visit counters. It seems the botnet wants to know how many hosts it has infected.

http://www.e-zeeinternet.com/count.php?page=953121&style=LED_g&nbdigits=9
http://www.e-zeeinternet.com/count.php?page=953130&style=LED_g&nbdigits=9
http://www.e-zeeinternet.com/count.php?page=953131&style=LED_g&nbdigits=9
http://www.e-zeeinternet.com/count.php?page=953001&style=LED_g&nbdigits=9
http://www.e-zeeinternet.com/count.php?page=953020&style=LED_g&nbdigits=9




Then, the trojan makes malformated DNS requests... Wireshark detects them as DNS traffic because these packets are sent over port 53 assigned to DNS traffic. Really it isn't DNS traffic, the trojan is establishing connections with the C&C (command and control) servers and the packets are ciphers.


Finally, the trojan begins to generate traffic over port 16464/UDP.



Each time that I restart the virtual machine, ZeroAccess creates a new code to send to other infected hosts over port 16464/UDP.
9e56cb0d28948dabc9c0d199562fcf9e
975dec6d28948dabc9c0d19943b005e1
fcb23c0a28948dabc9c0d19957ffdbcf
a35ecde828948dabc9c0d199d52aaf97
...
...
...

Notice that part of the code is always the same: 28948dabc9c0d19. Maybe it is the the node where my computer is connected.

See the map below, which I've created. In only three hours, the trojan made these connections with other servers or infected hosts over port 16464/UDP
Zeroaccess supernodes part I


ZeroAccess generates some traffic over port 123/UDP. It's the same case than DNS traffic too. It's not a real NTP traffic.



Your can continue reading ZeroAccess Trojan - Network Analysis Part II


Posted on Friday, June 28, 2013 by Javier Nieto

2 comments