Auteur Sujet: [FireEye]A Not-So Civic Duty: Asprox Botnet Campaign Spreads Court Dates and Malware  (Lu 2799 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
A Not-So Civic Duty: Asprox Botnet Campaign Spreads Court Dates and
Malware



  Executive Summary


 

FireEye Labs has been tracking a recent spike in malicious email
  detections that we attribute to a campaign that began in 2013. While
  malicious email campaigns are nothing new, this one is significant in
  that we are observing mass-targeting attackers adopting the malware
  evasion methods pioneered by the stealthier APT attackers. And this is
  certainly a high-volume business, with anywhere from a few hundred to
  ten thousand malicious emails sent daily – usually distributing
  between 50 and 500,000 emails per outbreak.


 

Through the     href="/content/fireeye-www/en_US/mandiant/threat-intelligence.html">FireEye
    Dynamic Threat Intelligence (DTI) cloud, FireEye Labs discovered
  that each and every major spike in email blasts brought a change in
  the attributes of their attack. These changes have made it difficult
  for anti-virus, IPS, firewalls and file-based sandboxes to keep up
  with the malware and effectively protect endpoints from infection.
  Worse, if past is prologue, we can expect other malicious,
  mass-targeting email operators to adopt this approach to bypass
  traditional defenses.


 

This blog will cover the trends of the campaign, as well as provide
  a short technical analysis of the payload.


 


  Campaign Details


 


        src="https://www.fireeye.com/content/dam/legacy/blog/2014/06/fig1.png"
      alt="fig1" class="aligncenter  wp-image-5732 landscape-med"
      width="540" height="296" />


 

Figure 1: Attack Architecture


 

The campaign first appeared in late December of 2013 and has since
  been seen in fairly cyclical patterns each month. It appears that the
  threat actors behind this campaign are fairly responsive to published
  blogs and reports surrounding their malware techniques, tweaking their
  malware accordingly to continuously try and evade detection with success.


 

In late 2013, malware labeled as Kuluoz, the specific spam component
  of the Asprox botnet, was discovered to be the main payload of what
  would become the first malicious email campaign. Since then, the
  threat actors have continuously tweaked the malware by changing its
  hardcoded strings, remote access commands, and encryption keys.


 

Previously, Asprox malicious email campaigns targeted various
  industries in multiple countries and included a URL link in the body.
  The current version of Asprox includes a simple zipped email
  attachment that contains the malicious payload “exe.” Figure 2 below
  represents a sample message while Figure 3 is an example of the
  various court-related email headers used in the campaign.


 


        src="https://www.fireeye.com/content/dam/legacy/blog/2014/06/fig2.png"
      alt="fig2" class="aligncenter  wp-image-5731 landscape-med"
      width="546" height="273" />


 

Figure 2 Email Sample


 


        src="https://www.fireeye.com/content/dam/legacy/blog/2014/06/fig3.png"
      alt="fig3" class="aligncenter  wp-image-5730 landscape-sm"
      width="434" height="421" />


 

Figure 3 Email Headers


 

Some of the recurring campaign that Asporox used includes themes
  focused around airline tickets, postal services and license keys. In
  recent months however, the court notice and court request-themed
  emails appear to be the most successful phishing scheme theme for the campaign.


 

The following list contains examples of email subject variations,
  specifically for the court notice theme:


 
  • Urgent court notice
  • Notice to Appear in Court

  •    
  • Notice of appearance in court
  • Warrant to appear

  •    
  • Pretrial notice
  • Court hearing notice
  • Hearing
        of your case
  • Mandatory court appearance

 

The campaign appeared to increase in volume during the month of May.
  Figure 4 shows the increase in activity of Asprox compared to other
  crimewares towards the end of May specifically. Figure 5 highlights
  the regular monthly pattern of overall malicious emails. In
  comparison, Figure 6 is a compilation of all the hits from our analytics.


 


        src="https://www.fireeye.com/content/dam/legacy/blog/2014/06/fig4.png"
      alt="fig4" class="aligncenter  wp-image-5729 landscape-med"
      width="540" height="220" />


 

Figure 4 Worldwide Crimeware Activity


 


        src="https://www.fireeye.com/content/dam/legacy/blog/2014/06/fig5.png"
      alt="fig5" class="aligncenter  wp-image-5728 landscape-med"
      width="540" height="256" />


 

Figure 5 Overall Asprox Botnet tracking


 


        src="https://www.fireeye.com/content/dam/legacy/blog/2014/06/fig6.png"
      alt="fig6" class="aligncenter  wp-image-5727 landscape-med"
      width="540" height="250" />


 

Figure 6 Asprox Botnet Activity Unique Samples


 

These malicious email campaign spikes revealed that FireEye
  appliances, with the support of DTI cloud, were able to provide a full
  picture of the campaign (blue), while only a fraction of the emailed
  malware samples could be detected by various Anti-Virus vendors (yellow).


 


        src="https://www.fireeye.com/content/dam/legacy/blog/2014/06/fig7.png"
      alt="fig7" class="aligncenter  wp-image-5726 landscape-med"
      width="540" height="232" />


 

Figure 7 FireEye Detection vs.
  Anti-Virus Detection


 

By the end of May, we observed a big spike on the unique binaries
  associated with this malicious activity. Compared to the previous days
  where malware authors used just 10-40 unique MD5s or less per day, we
  saw about 6400 unique MD5s sent out on May 29th. That is a
  16,000% increase in unique MD5s over the usual malicious email
  campaign we’d observed. Compared to other recent email campaigns,
  Asprox uses a volume of unique samples for its campaign.


 


        src="https://www.fireeye.com/content/dam/legacy/blog/2014/06/fig8.png"
      alt="fig8" class="aligncenter  wp-image-5725 landscape-med"
      width="540" height="229" />


 

Figure 8 Asprox Campaign Unique Sample Tracking


 


        src="https://www.fireeye.com/content/dam/legacy/blog/2014/06/fig9.png"
      alt="fig9" class="aligncenter  wp-image-5724 landscape-med"
      width="539" height="344" />


 

Figure 9 Geographical Distribution of
  the Campaign


 


        src="https://www.fireeye.com/content/dam/legacy/blog/2014/06/fig10.png"
      alt="fig10" class="aligncenter  wp-image-5723 landscape-med"
      width="539" height="276" />


 

Figure 10 Distribution of Industries Affected


 


  Brief Technical Analysis


 


        src="https://www.fireeye.com/content/dam/legacy/blog/2014/06/fig11.png"
      alt="fig11" class="aligncenter  wp-image-5722 landscape-med"
      width="540" height="296" />


 

Figure 11 Attack Architecture


 


  Infiltration


 

The infiltration phase consists of the victim receiving a phishing
  email with a zipped attachment containing the malware payload
  disguised as an Office document. Figure 11 is an example of one of the
  more recent phishing attempts.


 


        src="https://www.fireeye.com/content/dam/legacy/blog/2014/06/fig12.png"
      alt="fig12" class="aligncenter  wp-image-5721 portrait-sm"
      width="114" height="133" />


 

Figure 12 Malware Payload Icon


 


  Evasion


 

Once the victim executes the malicious payload, it begins to start
  an svchost.exe process and then injects its code into the newly
  created process. Once loaded into memory, the injected code is then
  unpacked as a DLL. Notice that Asprox uses a hardcoded mutex that can
  be found in its strings.


 
  1. Typical Mutex Generation
    1. "2GVWNQJz1"

    2.    
  2. Create svchost.exe process
  3. Code injection
        into svchost.exe

 


  Entrenchment


 

Once the dll is running in memory it then creates a copy of itself
  in the following location:


 

%LOCALAPPDATA%/[8 CHARACTERS].EXE


 

Example filename:


 

%LOCALAPPDATA%\lwftkkea.exe


 

It’s important to note that the process will first check itself in
  the startup registry key, so a compromised endpoint will have the
  following registry populated with the executable:


 

HKCU\Software\Microsoft\Windows\CurrentVersion\Run


 


  Exfiltration/Communication


 

The malware uses various encryption techniques to communicate with
  the command and control (C2) nodes. The communication uses an RSA
  (i.e. PROV_RSA_FULL) encrypted SSL session using the Microsoft Base
  Cryptographic Provider while the payloads themselves are RC4
  encrypted. Each sample uses a default hardcoded public key shown below.


 

Default Public Key


 

-----BEGIN PUBLIC KEY-----


 

MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDCUAUdLJ1rmxx+bAndp+Cz6+5I'


 

Kmgap2hn2df/UiVglAvvg2US9qbk65ixqw3dGN/9O9B30q5RD+xtZ6gl4ChBquqw


 

jwxzGTVqJeexn5RHjtFR9lmJMYIwzoc/kMG8e6C/GaS2FCgY8oBpcESVyT2woV7U


 

00SNFZ88nyVv33z9+wIDAQAB


 

-----END PUBLIC KEY-----


 

First Communication Packet


 

Bot ID RC4 Encrypted URL


 

POST /5DBA62A2529A51B506D197253469FA745E7634B4FC


 

HTTP/1.1


 

Accept: */*


 

Content-Type: application/x-www-form-urlencoded


 

User-Agent: <host useragent>


 

Host: <host ip>:443


 

Content-Length: 319


 

Cache-Control: no-cache


 

<knock><id>5DBA62A247BC1F72B98B545736DEA65A</id><group>0206s</group><src>3</src><transport>0</transport><time>1881051166</time><version>1537</version><status>0</status><debug>none<debug></knock>


 


  C2 Commands


 

In comparison to the campaign at the end of 2013, the current
  campaign uses one of the newer versions of the Asprox family where
  threat actors added the command “ear.”


 

if ( wcsicmp(Str1, L"idl") )


 

{


 

if ( wcsicmp(Str1, L"run") )


 

{


 

if ( wcsicmp(Str1, L"rem") )


 

{


 

if ( wcsicmp(Str1, L"ear")


 

{


 

if ( wcsicmp(Str1, L"rdl") )


 

{


 

if ( wcsicmp(Str1, L"red") )


 

{


 

if ( !wcsicmp(Str1, L"upd") )


 
   
     
   
                class="c09_td"> This
            commands idles the process to wait for
        commands
          class="c09_td_value is-hidden-mml">This commands idles the
          process to wait for commands

   
                class="c09_td"> Download
            from a partner site and execute from a specified
        path
          class="c09_td_value is-hidden-mml">Download from a partner
          site and execute from a specified path

   
                class="c09_td"> Remove
        itself
          class="c09_td_value is-hidden-mml">Remove itself

   
                class="c09_td"> Download
            another executable and create autorun entry

          Download another
          executable and create autorun entry

   
                class="c09_td"> Download,
            inject into svchost, and run
          class="c09_td_value is-hidden-mml">Download, inject into
          svchost, and run

   
                class="c09_td"> Download
            and update
          class="c09_td_value is-hidden-mml">Download and
      update

   
                class="c09_td"> Modify the
        registry
          class="c09_td_value is-hidden-mml">Modify the
      registry
C2 commands       class="c09_td">Description

        idl
      class="c09_td_value is-hidden-mml">idl

        run
      class="c09_td_value is-hidden-mml">run

        rem
      class="c09_td_value is-hidden-mml">rem

        ear
      class="c09_td_value is-hidden-mml">ear

        rdl
      class="c09_td_value is-hidden-mml">rdl

        upd
      class="c09_td_value is-hidden-mml">upd

        red
      class="c09_td_value is-hidden-mml">red

 


  C2 Campaign Characteristics


 


        src="https://www.fireeye.com/content/dam/legacy/blog/2014/06/fig13.jpg"
      alt="fig13" class="aligncenter  wp-image-5720 landscape-med"
      width="547" height="443" />


 

For the two major malicious email campaign
  spikes in April and May of 2014, separate sets of C2 nodes were used
  for each major spike.


 
   
     
   
                class="c09_td">
        192.69.192.178
      class="c09_td_value is-hidden-mml">192.69.192.178

   
                class="c09_td">
        213.21.158.141
      class="c09_td_value is-hidden-mml">213.21.158.141

   
                class="c09_td">
        213.251.150.3
      class="c09_td_value is-hidden-mml">213.251.150.3

   
                class="c09_td">
        27.54.87.235
      class="c09_td_value is-hidden-mml">27.54.87.235

   
                class="c09_td">
        61.19.32.24
      class="c09_td_value is-hidden-mml">61.19.32.24

   
                class="c09_td">
        69.64.56.232
      class="c09_td_value is-hidden-mml">69.64.56.232

   
                class="c09_td">
        72.167.15.89
      class="c09_td_value is-hidden-mml">72.167.15.89

   
                class="c09_td">
        84.234.71.214
      class="c09_td_value is-hidden-mml">84.234.71.214

   
                class="c09_td">
        89.22.96.113
      class="c09_td_value is-hidden-mml">89.22.96.113

   
                class="c09_td">
        89.232.63.147
      class="c09_td_value is-hidden-mml">89.232.63.147

   
                class="c09_td">
        91.121.20.71
      class="c09_td_value is-hidden-mml">91.121.20.71

   
                class="c09_td">
        91.212.253.253
      class="c09_td_value is-hidden-mml">91.212.253.253

   
                class="c09_td">
        91.228.77.15
      class="c09_td_value is-hidden-mml">91.228.77.15
April       class="c09_td">May-June

        94.23.24.58
      class="c09_td_value is-hidden-mml">94.23.24.58

        94.23.43.184
      class="c09_td_value is-hidden-mml">94.23.43.184

        1.234.53.27
      class="c09_td_value is-hidden-mml">1.234.53.27

        84.124.94.52
      class="c09_td_value is-hidden-mml">84.124.94.52

        133.242.134.76
      class="c09_td_value is-hidden-mml">133.242.134.76

        173.45.78.226
      class="c09_td_value is-hidden-mml">173.45.78.226

        37.59.9.98
      class="c09_td_value is-hidden-mml">37.59.9.98

        188.93.74.192
      class="c09_td_value is-hidden-mml">188.93.74.192

        187.16.250.214
      class="c09_td_value is-hidden-mml">187.16.250.214

        85.214.220.78
      class="c09_td_value is-hidden-mml">85.214.220.78

         
      class="c09_td_value is-hidden-mml">

         
      class="c09_td_value is-hidden-mml">

         
      class="c09_td_value is-hidden-mml">

 


  Conclusion


 

The data reveals that each of the Asprox botnet’s malicious email
  campaigns changes its method of luring victims and C2 domains, as well
  as the technical details on monthly intervals. And, with each new
  improvement, it becomes more difficult for traditional security
  methods to detect certain types of malware.


 


  Acknowledgements:


 

Nart Villeneuve, Jessa dela Torre, and David Sancho. Asprox Reborn.
  Trend Micro. 2013. http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-asprox-reborn.pdf


Source: A Not-So Civic Duty: Asprox Botnet Campaign Spreads Court Dates and
Malware

Tags: