Auteur Sujet: [FireEye]Threat actors leverage EternalBlue exploit to deliver non-WannaCry payloads  (Lu 3337 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
Threat actors leverage EternalBlue exploit to deliver non-WannaCry payloads

[html]

The “EternalBlue” exploit (  href="https://technet.microsoft.com/en-us/library/security/ms17-010.aspx">MS017-010)
  was initially used by WannaCry ransomware and Adylkuzz cryptocurrency
  miner. Now more threat actors are leveraging the vulnerability in     href="https://www.fireeye.com/blog/threat-research/2017/05/smb-exploited-wannacry-use-of-eternalblue.html">Microsoft
    Server Message Block (SMB) protocol – this time to distribute
  Backdoor.Nitol and Trojan Gh0st RAT.


 

FireEye Dynamic Threat Intelligence (DTI) has historically observed
  similar payloads delivered via exploitation of CVE-2014-6332
  vulnerability as well as in some email spam campaigns using     href="https://www.fireeye.com/blog/threat-research/2016/09/hancitor_aka_chanit.html">powershell
  commands. Specifically, Backdoor.Nitol has also been linked to
  campaigns involving a remote code execution vulnerability using the
  ADODB.Stream ActiveX Object that affects older versions of Internet
  Explorer. Both payloads have previously been involved in targeted     href="https://www.fireeye.com/content/dam/fireeye-www/current-threats/pdfs/ib-aerospace.pdf">cyber-attacks
    against the aerospace and defense industry.


 

We observed lab machines vulnerable to SMB exploit were attacked by
  a threat actor using the EternalBlue exploit to gain shell access to
  the machine.


 

Figure 1 shows an EternalBlue exploitation attempt.


 


 


 


  Figure 1. Network traffic showing EternalBlue
    attack attempt


 

The initial exploit technique used at the     href="https://www.fireeye.com/blog/threat-research/2017/05/smb-exploited-wannacry-use-of-eternalblue.html">SMB
  level is similar to what we have been seen in     href="https://www.fireeye.com/blog/threat-research/2017/05/wannacry-malware-profile.html">WannaCry
  campaigns; however, once a machine is successfully infected, this
  particular attack opens a shell to write instructions into a VBScript
  file and then executes it to fetch the payload on another server.


 

We have observed the same EternalBlue and VBScript combination used
  to distribute


Tags: