CrimePack exploit kit is just like any other exploit kits. It contains various codes that exploit vulnerabilities in a system and also in some of the applications installed. Commonly, these exploit codes download and execute an arbitrary file in the system. We were able to download a Dorkbot Worm in one of the malicious link we got from malwaredomainlist.com (MD5 hash: 9210a2635c63a58af18ed5dffb8f01e8, VirusTotal Scan Result available here).
This particular exploit kit has been around for several years now, version 2.0 appeared in the 1st Quarter of 2010, and the latest, as of this writing, is version 3.1.3. Some of its features are the following:
- Undetected from AV Scanners (Javascript & PDF/JAR/JPG files)
- Random PDF Obfuscation (Not using static pdf file like other packs)
- Blacklist checker & AutoChecker
- Prevent Wepawet, Jsunpack and other JavaScript unpackers to decode your page
- Will autocheck (can be turned off) your domain for blacklist & malware lists, and will notify you if found, Checks the following:
- Norton SafeWeb
- My WebOfTrust
- Malc0de
- Google Safe Browsing
- Malwaredomainlist
- Mcafee SiteAdvisor
- hpHosts
- Malwareurl
Below is a running list of vulnerabilities that have been used by Crimepack exploit kit:
- CVE-2010-1885 - HCP
- CVE-2010-1423 - JRE 'WebStart' RCE
- CVE-2010-0840 - Java getValue Remote Code Execution
- CVE-2010-0806 - IE iepeers Vulnerability (IE7 Uninitialized Memory Corruption/IEPeers Remote Code Execution)
- CVE-2009-3269 - Opera TN3270
- CVE-2009-1136 - OWC Spreadsheet Memory Corruption
- CVE-2009-0927 - Adobe Reader Collab GetIcon
- CVE-2009-0355 - Firefox 3.5/1.4/1.5 exploits
- CVE-2008-5353 - Java Deserialize
- CVE-2008-4844 - Internet Explorer 7 XML Exploit
- CVE-2008-2992 - Adobe Reader util.printf
- CVE-2007-5755 - AOL Radio AmpX Buffer Overflow
- CVE-2007-5659 - Adobe Reader CollectEmailInfo
- CVE-2006-0003 - MDAC (IE6 COM CreateObject Code Execution)
- Aggressive Mode - This is a Java applet that downloads and executes you exe, the feature can be turned on and off in the admin panel
Sources:
websense
offensivecomputing
malwaredomainlist
0 comments:
Post a Comment