• Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
  • Delicious

Anti-Malware Laboratory

Yet Another Malware Blog

About

An informal blog from your friendly neighborhood software security humans.

Blog Archive

  • ▼  2015 (5)
    • ▼  October (1)
      • Another Macro Script Technique in Executing Malware
    • ►  August (2)
    • ►  May (1)
    • ►  March (1)
  • ►  2014 (8)
    • ►  October (1)
    • ►  July (1)
    • ►  June (1)
    • ►  May (4)
    • ►  April (1)
  • ►  2013 (12)
    • ►  December (3)
    • ►  November (5)
    • ►  August (2)
    • ►  March (2)
  • ►  2012 (35)
    • ►  April (4)
    • ►  March (12)
    • ►  February (17)
    • ►  January (2)

Categories

adobe (1) android (10) android february (1) baksmali (1) Black Hole (2) crimepack (1) disassembler (1) exploit (3) Exploits (4) Fakeav Winrar sfx (1) Fishbowl (1) flash (1) gift certificates (1) Google Authenticator (1) google play (1) hcp (1) java (1) Malware (5) mdac (1) Mobile (24) NSA Mobility Program (1) obfuscated script (1) pdf (1) Reversing (2) rhino (1) skype (1) smali (1) spam (1) test (1) Unpacking (1) vouchers (1) vulnerability (3)

Popular Posts

  • Bank of America spam: An Analysis
    An email claiming to be from Bank of America lures users to open an attachment that shows how to open secure emails from the bank. The mess...
  • [BE CAUTIOUS] Dragon Ball Z: Resurrection of F MALWARE and SCAM
    Be wary of downloading movies in torrent sites.  Executables can also be executed with a file size as huge as a gigabyte...
  • Unpacking MFC Compiled CryptoWall Malware
    Unpacking MFC Compiled CryptoWall Malware Introduction First and foremost, this article does not intend to analyze what CryptoWall malw...

Visitors to this blog

Showing posts with label Exploits. Show all posts
Showing posts with label Exploits. Show all posts

Tuesday, March 13, 2012

Fake Skype Vouchers website leads to Java Exploits

Posted on Tuesday, March 13, 2012 by Red Horse | No comments
Originally posted by kazmot.

I stumbled upon a fake website that targets Skype users through vouchers or gift certificates. Below is the definition of Skype vouchers from their website:


Skype vouchers are electronic Skype Credit vouchers sold in various retail outlets. You don’t have to pay for the vouchers online and they make a great gift for family and friends so that you can keep in touch through Skype.

Vouchers are sometimes included with Skype accessories, or as part of a promotion.


Let's have a look of what is inside the said fake page:

[caption id="attachment_514" align="aligncenter" width="300" caption="Figure 1: Source of the fake website"][/caption]

Figure 1 shows the misleading title. You can also see a hidden iframe connecting to a different website.

Following the hidden iframe, we will now get an obfuscated script.

[caption id="attachment_512" align="aligncenter" width="300" caption="Figure 2: Obfuscated script"][/caption]

Some variables are highlighted in Figure 2. These variables will eventually become a window.eval() function when the script is executed. Now, let us modify the script in order for our script emulator to capture the result of the eval() function:

[caption id="attachment_510" align="aligncenter" width="300" caption="Figure 3: Modification part 1"][/caption]

Figure 3 shows that we need to remove some "if-statements" to make sure that our script will execute. You will also notice that one if-statement checks for the current year. The script will not run properly if it was not satisfied. In addition, proper deobfuscation of the script also depends on the value of the integer in the year check. We will tackle more about this in a while. For now, let's just deobfuscate this script.

[caption id="attachment_511" align="aligncenter" width="300" caption="Figure 4: Modification part 2"][/caption]

Figure 4 shows which variable will become the eval() function. After the modifications, execute the script and then dump the eval result. Figure 5 below will show you the result.

[caption id="attachment_513" align="aligncenter" width="300" caption="Figure 5: Deobfuscated script code"][/caption]

Now, you will see another set of hidden iframes that connect to another site. The said site will now load 2 malicious Java files:

[caption id="attachment_515" align="aligncenter" width="300" caption="Figure 6: Load Java applets"][/caption]

Sample 1: Java Exploit
MD5 hash: d3f933524c85c96a76f7ffd516d335c0
Virus Total scan result available here

Sample 2: Java Exploit
MD5 hash: 58db6e6e25d9b8e4742f2ef9b43c3818
Virus Total scan result available here

These Java files exploit the following vulnerability:


    CVE-2011-3544 - Oracle Java Applet Rhino Script Engine Remote Code Execution


Going back to the date check and value change, Figure 7 shows that we changed the integer value from "012" to "011".

[caption id="attachment_524" align="aligncenter" width="300" caption="Figure 7: Integer value modification"][/caption]

Now, let's dump the result to a file.

[caption id="attachment_521" align="aligncenter" width="300" caption="Figure 8: Result of the wrong value"][/caption]

You can see in Figure 8 that the result is now just a bunch of non-readable strings.

Source:
malwaredomainlist


References:
Skype
Virustotal
cve.mitre.org
Sourceforge
Read More

Tuesday, March 6, 2012

Fake Intuit Quickbooks Page Leads to Black Hole Exploit

Posted on Tuesday, March 06, 2012 by Red Horse | No comments
Originally posted by kazmot.

The Blackhole Exploit kit is still a very popular attack on the web. Malwares use this exploit kit to propagate and infect unsuspecting users. Here is a detailed analysis of a fake Intuit page that leads to the exploit kit and the obfuscation technique used by the attack. In this specific targeted attack, we were able to download a Cridex worm, 2 PDF files, and an obfuscated Javascript.

Let's see first what the fake page looks like:

[caption id="attachment_380" align="aligncenter" width="300" caption="Figure 1: Fake Intuit Page"][/caption]

In the above screenshot, we can immediately notice that it is really fake. You may view the legitimate site of Intuit Quickbooks here. The title on the web browser shows "Intuit" but you will see on the status bar that a hidden connection goes to a different remote site.

Now, Let's see what is in this HTML file...

[caption id="attachment_386" align="aligncenter" width="300" caption="Figure 2: Content of the Fage Page"][/caption]

I used Malzilla to connect to the site and get its content. You can see that, other than the usual title and header shown earlier, it also contains an obfuscated script.

Now to decode this script...

You will notice that I highlighted some variables in Figure 2. These variables will become a window.eval() function when the script is executed. window.eval() is a javascript function that executes an argument. This function was used to execute the "deobfuscated" code. Malicious scripts commonly use this technique to avoid script debuggers/emulators that hook this function to create a dump of the deobfuscated code.

So now, we need to modify the script so that Malzilla will be able to get the argument of the eval() function...

[caption id="attachment_388" align="aligncenter" width="300" caption="Figure 3: Removing IF conditions"][/caption]

Figure 3 shows that in this specific sample, we need to remove some IF statements to make sure that the script is executed.

[caption id="attachment_389" align="aligncenter" width="300" caption="Figure 4: Run script and Show Eval() results"][/caption]

If you take a look again at the highlighted variables in Figure 2, you will see that the variable "e" will become the window.eval() function. Figure 4 shows the modifications that we applied. Run the script and then hit the "Show eval() results" button. At the bottom box of Figure 4, you will see the deobfuscated code. It is a hidden iframe that connects to a remote site.

Let's follow this site, shall we...

Again using Malzilla, you need to repeat the steps in order to analyze this remote site. On the Download tab, paste the URL and then hit the "Get" button.

[caption id="attachment_394" align="aligncenter" width="300" caption="Figure 5: Contents of the remote site."][/caption]

Figure 5 shows that this site contains two script tags, so we need to use "Send all scripts to Decoder". Again, like the first site, you can see here that it uses the same technique where window.eval has been assigned to a variable "e". Apply the same modification that we did earlier, run the script, and then get the eval result. Figure 5 also shows which part of the script you need to change.

[caption id="attachment_397" align="aligncenter" width="300" caption="Figure 6: Black Hole exploit code."][/caption]

Figure 6 shows the result. You will now see here the "Please wait page is loading...". This display page is very common on Black Hole exploit codes. Initially, the code is in a single line which makes reading it a little bit hard. You can use a "javascript formatter" to insert newlines and tabs in the script. An example is jsbeautifier.org.

Let's now take a look at the exploit code...

It searches for vulnerable applications installed in the target system. In this sample, it checks for the following:

  • Adobe Reader

  • Flash Player

[caption id="attachment_413" align="aligncenter" width="300" caption="Figure 7: Check installed applications."][/caption]

It deploys an MDAC exploit (CVE-2006-0003 - IE6 COM CreateObject Code Execution) to download and execute a malicious file.

  • File: Cridex worm

  • MD5 hash: c3124a2981d8e1b9e13e8c21c96448f7

  • Virustotal Scan Results


[caption id="attachment_418" align="aligncenter" width="300" caption="Figure 8: Deploying MDAC exploit."][/caption]


It deploys the following PDF exploits:

    • CVE-2008-2992 - Adobe Reader util.printf


      • File: Pdfjsc exploit

      • MD5 hash: 8ad89d5477fe5b074b1767a826207c8a

      • Virustotal Scan Results



    • CVE-2009-0927 - Adobe Reader Collab GetIcon


      • File: Pdfjsc exploit

      • MD5 hash: 84fbc15c2d3e460183b853c566bf3ccf

      • Virustotal Scan Results



[caption id="attachment_419" align="aligncenter" width="300" caption="Figure 9: Deploying PDF exploits."][/caption]

It deploys HCP exploit (CVE-2010-1885):

[caption id="attachment_417" align="aligncenter" width="300" caption="Figure 10: Deploying HCP exploit."][/caption]

The file in the link is an obfuscated script. When the deobfuscated code is saved in a file:


  • File: Javascript iframe

  • MD5 hash: 1f082ef7e2bc87efa2926a81925e6c46

  • Virustotal Scan Results


[caption id="attachment_426" align="aligncenter" width="300" caption="Figure 11: Deobfuscated HCP exploit script"][/caption]

Finaly, it deploys a flash player exploit (CVE-2011-0611 - Adobe Flash Player Memory Corruption):

[caption id="attachment_414" align="aligncenter" width="300" caption="Figure 12: Deploying Flash exploit."][/caption]

More Information:
Black Hole exploit kit

Sample source:
malwaredomainlist.com

References:
Imperva
ZScaler ThreatLab
Read More

Black Hole exploit kit

Posted on Tuesday, March 06, 2012 by Red Horse | No comments
Originally posted by kazmot.

The Black Hole exploit kit is an unethical off-the-shelf Web application.  The first instance - v.1.0.0 beta - has appeared on the black market and was advertised in August 2010 as a "System for network testing".  As with most of  the exploit kits, it is based on PHP and a MySQL backend. The payload of this kit usually targets Windows operating systems and applications installed on those systems, but depends on the criminals' end goal.

The Black Hole exploit kit uses several protection mechanisms such as:


    • Integrated Antivirus based on an API of popular blackhats' AVCheck services

    • Forms database of blacklists based on referrers and IP addresses including ranges to block access to the system


Below is a running list of vulnerabilities that have been used with the Black Hole exploit kit:


    • CVE-2011-0611 - Adobe Flash Player Memory Corruption Vulnerability

    • CVE-2010-1885 - HCP

    • CVE-2010-1423 - Java argument injection vulnerability in the URI handler in Java NPAPI plugin

    • CVE-2010-0886 - Java Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE

    • CVE-2010-0842 - Java JRE MixerSequencer Invalid Array Index Remote Code Execution Vulnerability

    • CVE-2010-0840 - Java trusted Methods Chaining Remote Code Execution Vulnerability

    • CVE-2009-1671 - Java buffer overflows in the Deployment Toolkit ActiveX control in deploytk.dll

    • CVE-2009-0927 - Adobe Reader Collab GetIcon

    • CVE-2008-2992 - Adobe Reader util.printf

    • CVE-2007-5659 - Adobe Reader CollectEmailInfo

    • CVE-2006-0003 - MDAC (IE6 COM CreateObject Code Execution)


Related topic:
Fake Intuit Quickbooks Page Leads to Black Hole Exploit

Sources:
Websense
Read More

Monday, March 5, 2012

CrimePack exploit kit

Posted on Monday, March 05, 2012 by Red Horse | No comments
Originally posted by kazmot.

CrimePack exploit kit is just like any other exploit kits. It contains various codes that exploit vulnerabilities in a system and also in some of the applications installed. Commonly, these exploit codes download and execute an arbitrary file in the system. We were able to download a Dorkbot Worm in one of the malicious link we got from malwaredomainlist.com (MD5 hash: 9210a2635c63a58af18ed5dffb8f01e8, VirusTotal Scan Result available here).

This particular exploit kit has been around for several years now, version 2.0 appeared in the 1st Quarter of 2010, and the latest, as of this writing, is version 3.1.3. Some of its features are the following:

  1. Undetected from AV Scanners (Javascript & PDF/JAR/JPG files)

  2. Random PDF Obfuscation (Not using static pdf file like other packs)

  3. Blacklist checker & AutoChecker

  4. Prevent Wepawet, Jsunpack and other JavaScript unpackers to decode your page

  5. Will autocheck (can be turned off) your domain for blacklist & malware lists, and will notify you if found,  Checks the following:


    • Norton SafeWeb

    • My WebOfTrust

    • Malc0de

    • Google Safe Browsing

    • Malwaredomainlist

    • Mcafee SiteAdvisor

    • hpHosts

    • Malwareurl

Below is a running list of vulnerabilities that have been used by Crimepack exploit kit:

  • CVE-2010-1885 - HCP

  • CVE-2010-1423 - JRE 'WebStart' RCE

  • CVE-2010-0840 - Java getValue Remote Code Execution

  • CVE-2010-0806 - IE iepeers Vulnerability (IE7 Uninitialized Memory Corruption/IEPeers Remote Code Execution)

  • CVE-2009-3269 - Opera TN3270

  • CVE-2009-1136 - OWC Spreadsheet Memory Corruption

  • CVE-2009-0927 - Adobe Reader Collab GetIcon

  • CVE-2009-0355 - Firefox 3.5/1.4/1.5 exploits

  • CVE-2008-5353 - Java Deserialize

  • CVE-2008-4844 - Internet Explorer 7 XML Exploit

  • CVE-2008-2992 - Adobe Reader util.printf

  • CVE-2007-5755 - AOL Radio AmpX Buffer Overflow

  • CVE-2007-5659 - Adobe Reader CollectEmailInfo

  • CVE-2006-0003 - MDAC (IE6 COM CreateObject Code Execution)

  • Aggressive Mode - This is a Java applet that downloads and executes you exe, the feature can be turned on and off in the admin panel



Sources:
websense
offensivecomputing
malwaredomainlist
Read More
Older Posts Home
Subscribe to: Posts (Atom)
volute-glacial
volute-glacial
volute-glacial
volute-glacial
Copyright © Anti-Malware Laboratory | Powered by Blogger
Design by Fabthemes | Blogger Template by NewBloggerThemes.com