Auteur Sujet: [FireEye]LadyBoyle Comes to Town with a New Exploit  (Lu 2802 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
[FireEye]LadyBoyle Comes to Town with a New Exploit
« le: mai 15, 2019, 08:00:16 »
LadyBoyle Comes to Town with a New Exploit


  [Update: February 12, 2013] By now you have probably heard of
  the new zero-day exploit in Adobe Flash that was patched today.
  FireEye Labs identified the exploit in the wild on February 5, 2013,
  which based on the compile time and document creation time is the same
  day the malicious payload was generated. Adobe PSIRT has released
  information about this threat     href="http://blogs.adobe.com/psirt/2013/02/security-updates-available-for-adobe-flash-player-apsb13-04.html"
  target="_self">here. They have also released an     href="http://www.adobe.com/support/security/bulletins/apsb13-04.html"
  target="_self">advisory with details on versions and platforms
  affected along with applicable patches. The two exploits have been
  assigned CVE-2013-0633 and CVE-2013-0634. It is highly recommended
  that you apply this patch right away, as this threat is active in the wild.


 

We will examine the payload executed as a part of this threat in the
  wild. We have identified two unique word files containing
  CVE-2013-0634 so far. It is interesting to note that even though the
  contents of Word files are in English, the codepage of Word files are
  "Windows Simplified Chinese (PRC, Singapore)". The Word
  files contain a macro to load an embedded SWF Flash object.


 

The SWF file contains an action script with the name “LadyBoyle”
  that contains the exploit code. The exploit only supports limited
  version of Flash as evident in the action script seen in Figure 1. It
  also checks for the presence of activex component.


 


        href="/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017ee851c5f6970d-320wi.png">      class="asset  asset-image at-xid-6a00d835018afd53ef017ee851c5f6970d landscape-med"
      title="Image1" alt="Image1" src="https://www.fireeye.com/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017ee851c5f6970d-320wi.png" />


 

Figure 1


 

It drops multiple exe files and a DLL payload. The payload that is
  dropped and executed when the exploit is successful is also embedded
  in the SWF file in an SWFTag (Figure 2). The payload is 64-bit and was
  compiled recently on February 4, 2013. The malware family is not new
  though and we have seen it being used in attacks before.


 


        href="/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017c36ae6ffa970b-650wi.png">      class="asset  asset-image at-xid-6a00d835018afd53ef017c36ae6ffa970b landscape-med"
      title="Image2" alt="Image2"
      src="https://www.fireeye.com/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017c36ae6ffa970b-650wi.png" width="650" />


 

Figure 2


 

One of the dropped executable files is digitally signed with an
  invalid certificate from MGAME Corporation, a Korean gaming company.
  The same executable renames itself to try to pass itself off as the
  Google update process.


 


        href="/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017ee851c8c7970d-320wi.png">      class="asset  asset-image at-xid-6a00d835018afd53ef017ee851c8c7970d landscape-med"
      title="Image3" alt="Image3" src="https://www.fireeye.com/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017ee851c8c7970d-320wi.png" />


 

Figure 3


 

It creates startup registry entries for persistence after reboot.
  The malware checks for presence of the AV processes listed below:


 

avp.exe


 

ctray.exe


 

tray.exe


 

360tray.exe


 

It also creates a configuration file under %appdata%config.sys. This
  configuration file is XOR encoded with the key ‘0xCF’. The decrypted
  configuration file is as shown in figure 4. It contains the C2 domain
  contacted by the malware.


 


        href="/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017ee851c9fc970d-500wi.png">      class="asset  asset-image at-xid-6a00d835018afd53ef017ee851c9fc970d landscape-med"
      title="Image4" alt="Image4" src="https://www.fireeye.com/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017ee851c9fc970d-500wi.png" />


 

It has a unique callback with the keyword “9002” and beacons to the
  CnC server at ieee.boeing-job.com


 


        href="/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017ee851cb2e970d-320wi.png">      class="asset  asset-image at-xid-6a00d835018afd53ef017ee851cb2e970d landscape-med"
      title="Image5" alt="Image5" src="https://www.fireeye.com/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017ee851cb2e970d-320wi.png" />


 

Figure 5


 


  On mining our database we found
    multiple domains associated with this threat:


 

369p.mail-signin.com


 

bm1k8.4pu.com


 

cti.moobesring.com


 

domcon.microtrendsoft.com


 

engage.intelfox.com


 

funny.greenitenergy.com


 

i0i0i.3322.org


 

ieee.boeing-job.com


 

krjregh.sacreeflame.com


 

lol.dns-lookup.us


 

lywja.healthsvsolu.com


 

matrix.linkerservices.com


 

mx.dns221.com


 

piping.no-ip.org


 

ru.pad62.com


 

stmp.allshell.net


 

support.icoredb.com


 

svr01.passport.serveuser.com


 

ukupdate.masteradvz.com


 

update.mysq1.net


 

update.updates.mefound.com


 

update1.mysq1.net


 

update3.effers.com


 

updatedns.itemdb.com


 

updatedns.serveuser.com


 

The md5's of crafted document files are listed below:


 


  3de314089db35af9baaeefc598f09b23


 

2568615875525003688839cb8950aeae


 

We will continue to research this threat and provide updates as we
  find more information.


 


  [Update: February 8, 2013]


 


      href="/content/fireeye-www/en_US/blog/threat-research/2013/02/lady-boyle-comes-to-town-with-a-new-exploit.html"
    target="_self">Yesterday, we blogged about the new Flash exploit
  we identified in the wild on February 5, 2013. Since then AlienVault
  has also     href="https://www.alienvault.com/blogs/labs-research/adobe-patches-two-vulnerabilities-being-exploited-in-the-wild">published
    a blog detailing the threat. Peleus Uhley from Adobe     href="http://blogs.adobe.com/asset/2013/02/raising-the-bar-for-attackers-targeting-flash-player-via-office-files.html">published
    some information on an new feature in the upcoming version of
  Flash. This feature would identify if Flash content is being run from
  within an older version of Office that does not have protected mode
  and warns the user of potentially malicious content before it is
  executed. Every extra step in making the attackers job more difficult counts.


 

It is interesting to note, as also observed by AlienVault, that the
  Flash content and the payloads are not obfuscated or encrypted at all.
  It is odd and sloppy for a threat attempting industrial espionage.


 

We continued looking into the payload which is part of this exploit
  and found some additional interesting behavior. The malware creates a
  registry entry under
  "HKEY_CURRENT_USERSoftwareClassessoftbin." The value of this
  registry key is a large amount of XOR encrypted data. The key used for
  this encryption was "0xC4." The decrypted data is shown in
  Figure 6. After some initial data in the decrypted content, it
  contains an embedded executable. This executable contains code for
  HTTP POSTS as seen in Figure 7.


 


        href="/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017ee859e303970d-800wi.png">      class="asset  asset-image at-xid-6a00d835018afd53ef017ee859e303970d image-full landscape-med"
      title="Boyle1" alt="Boyle1"
      src="https://www.fireeye.com/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017ee859e303970d-800wi.png" border="0" />


 

Figure 6


 


        href="/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017c36b68eb0970b-800wi.png">      class="asset  asset-image at-xid-6a00d835018afd53ef017c36b68eb0970b image-full landscape-med"
      title="Boyle2" alt="Boyle2"
      src="https://www.fireeye.com/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017c36b68eb0970b-800wi.png" border="0" />


 

Figure 7


 

After allowing the malware to run for an extended period of time we
  observed HTTP POSTs being generated by the malware. The URI is
  incremented sequentially in these requests.


 


        href="/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017c36b68e4f970b-800wi.png">      class="asset  asset-image at-xid-6a00d835018afd53ef017c36b68e4f970b image-full landscape-med"
      title="Boyle3" alt="Boyle3"
      src="https://www.fireeye.com/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017c36b68e4f970b-800wi.png" border="0" />


 

Figure 8


 

The HTTP post data for these requests is the same as shown below.
  The CnC server is not responding to the POSTS at this time.


 


        href="/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017d40e51c89970c-650wi.png">      class="asset  asset-image at-xid-6a00d835018afd53ef017d40e51c89970c landscape-med"
      title="Boyle4" alt="Boyle4"
      src="https://www.fireeye.com/content/dam/legacy/blog/2013/02/6a00d835018afd53ef017d40e51c89970c-650wi.png" width="650" />


 

Figure 9


 


  [Update: February 12, 2013]


 

After further analysis we have confirmed that the exploit used in
  the analyzed documents is  CVE-2013-0634 and not CVE-2013-0633 as
  originally stated.


 

 


 

 

 


 


  This post was written by FireEye researchers Josh Gomez, Thoufique
    Haq, and Yichong Lin.


Source: LadyBoyle Comes to Town with a New Exploit

Tags: