ZeroHour
Cisco Talospublished ()ingested 1

Threat Source newsletter (Sept. 23, 2021)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-38647
+3 in the same advisory: …38648 …38645 …38649
Unauthenticated RCE in Microsoft Open Management Infrastructure (OMI)

CVE-2021-38647 is an unauthenticated remote code execution flaw (CWE-1390, missing authentication) in Microsoft's Open Management Infrastructure (OMI), the open-source Linux management agent Microsoft bundles into Azure VM management extensions and System Center Operations Manager (SCOM) agents. When OMI is deployed through these extensions (for example the Log Analytics/OMS agent, Azure Monitor, or Azure Automation), its root-privileged server component listens for management traffic on the network (by default ports 5985/5986), and an attacker who can reach that port can send specially crafted, unauthenticated management requests that execute commands as root. Successful exploitation gives an attacker full root-level control of the affected Linux VM, turning network reachability into complete host compromise and a foothold for lateral movement. Any Azure Linux VM with an OMI-based management extension, plus standalone OMI or SCOM-agent deployments on Linux, is affected; CISA added the bug to the KEV on 2021-11-03 with known ransomware use, so exploitation is confirmed in the wild even though no public proof-of-concept is catalogued, and EPSS estimates a ~99.9% near-term exploitation probability.

Do: Upgrade OMI to version 1.6.8-1 or later on all Linux VMs, including updating the bundled OMI inside Azure management extensions (Log Analytics/OMS agent, Azure Monitor, Azure Automation) and applying patched SCOM agent builds. Restrict network access to OMI's listener ports (5985/5986) with NSGs or host firewalls and check whether omiserver runs as root while binding beyond localhost. Because the flaw is in CISA KEV with known ransomware use, prioritize patching hosts whose OMI listener is reachable from untrusted networks and hunt for unexplained root-level activity.

9.8
group max
100% KEV ransomware PoC
  • Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions
mass≈ millions of Linux VMs with OMI-based Azure management extensions

Indicators of compromiseAll →

TypeIndicatorContext
md504c1f4395f80a3890aa8b12ebc2b485566f466bdeff2a716b9aa79faa6677f2895f0b262cf9402deb4b66c MD5: 04c1f4395f80a3890aa8b12ebc2b4855 Typical Filename: zReXhNb Claimed Product: N/A Detection Na
md52915b3f8b703eb744fc54c81f4a9c67f393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc50 7 MD5: 2915b3f8b703eb744fc54c81f4a9c67f Typical Filename: VID[1].dat Claimed Product: N/A Detection
md534560233e751b7e95f155b6f61e7419a0599b11241876ada8ae6f07b48f1abe6590c2440004ea4db5becc9 MD5: 34560233e751b7e95f155b6f61e7419a Typical Filename: SAntivirusService.exe Claimed Product: A
md5830ffb393ba8cca073a1c0b66af78de5b22888724288af038bc0b6e55280ddbbe42a436cdf68889346df18 MD5: 830ffb393ba8cca073a1c0b66af78de5 Typical Filename: smbscanlocal0902.exe Claimed Product: N/A
md59a4b7b0849a274f6f7ac13c7577daad8e188423d31df3ea806272f3daa5eb989e18e9ecf3d94b97b965f8e MD5: 9a4b7b0849a274f6f7ac13c7577daad8 Typical Filename: ww31.exe Claimed Product: N/A Detection N
sha2566c62b768d8b22888724288af038bc0b6e55280ddbbe42a436cdf68889346df18Detection Name: W32.GenericKD:Attribute.24ch.1201 SHA 256: 6c62b768d8b22888724288af038bc0b6e55280ddbbe42a436cdf68889346df18 MD5: 830ffb393ba8cca073a1c0b66af78de5 Typical Filename: smb
sha2568b4216a7c50599b11241876ada8ae6f07b48f1abe6590c2440004ea4db5becc9e: MS17010::mURLin::W32.Auto:6c62b768d8.in03.Talos SHA 256: 8b4216a7c50599b11241876ada8ae6f07b48f1abe6590c2440004ea4db5becc9 MD5: 34560233e751b7e95f155b6f61e7419a Typical Filename: SAn
sha256c1d5a585fce188423d31df3ea806272f3daa5eb989e18e9ecf3d94b97b965f8eSID: 58169 Most prevalent malware files this week SHA 256: c1d5a585fce188423d31df3ea806272f3daa5eb989e18e9ecf3d94b97b965f8e MD5: 9a4b7b0849a274f6f7ac13c7577daad8 Typical Filename: ww3
sha256fad16599a866f466bdeff2a716b9aa79faa6677f2895f0b262cf9402deb4b66cduct: N/A Detection Name: Win.Worm.Coinminer::1201 SHA 256: fad16599a866f466bdeff2a716b9aa79faa6677f2895f0b262cf9402deb4b66c MD5: 04c1f4395f80a3890aa8b12ebc2b4855 Typical Filename: zRe
Full article1,135 words · extracted from blog.talosintelligence.com · click to collapse

Thursday, September 23, 2021 14:00

Good afternoon, Talos readers.

The Russian APT Turla is one of the most notorious threat actors out there today. And they aren't stopping, recently adding a new backdoor to their arsenal that serves as a "last chance" to retain a foothold on victim machines, even after their other malware has been removed.

Elsewhere on the APT landscape, the U.S. Cybersecurity and Infrastructure Security Agency released an advisory warning users and organizations about a recent spike in Conti ransomware attacks. Their report even included a Talos shout-out! If you want to read our recent work on Conti, you can check out our major takeaways from their leaked playbook, and an episode of Talos Takes covering the matter.

Upcoming Talos public engagements

Chats, Cheats, and Cracks: Abuse of Collaboration Platforms in Malware Campaigns at BSides Charlotte

Speaker: Edmund Brumaghin

Date: Sept. 25 at 1:30 p.m. ET

Location: Virtual

Description: Join Edmund Brumaghin from Talos Outreach where he'll be discussing malware campaigns targeting collaboration apps such as Discord and Slack. Following up on Talos' blog post from earlier this year, the presentation will dive into campaigns we've spotted in the wild and discuss how users can stay safe while using these apps.

Workshop: Analysing Android malware at VirusBulletin localhost 2021

Speaker: Vitor Ventura

Date: Oct. 7 - 8

Location: Virtual

Description: Android malware has become prevalent across the landscape. In this workshop, Vitor Ventura will show you reverse engineering techniques for Android malware. This workshop is designed to provide the participants with different approaches to malware analysis so they can perform their own analysis without the use of automated tools. When everything else fails, we need to know what's under the hood. This workshop will cover malware unpacking, string deobfuscation, command and control protocol identification and feature identification.

National Cybersecurity Awareness Month with Cisco Talos Incident Response

Speaker: Brad Garnett

Date: Oct. 18 at 9:30 a.m. ET

Location: Livestream on all Talos social media accounts

Description: Join Cisco Talos Incident Response as we go live to celebrate National Cybersecurity Awareness Month. Brad Garnett, CTIR's general management, will be live to answer your questions, talk about the trends he's seeing on the threat landscape, and the growing threat of ransomware. Please use this page to drop us any questions ahead of time, or join us in the chat live. A recording will be made available shortly after on our YouTube page at cs.co/TalosTube.

Cybersecurity week in review

  • Walgreens mistakenly left customers' COVID-19 testing information exposed online. Until some recent security additions, it was relatively easy for a malicious actor to view a person's name, appointment information, test results and other personal information through the pharmacy chain's website.
  • Apple released iOS 15 this week, which includes several new security features. The company also quietly patched a vulnerability that could allow an attacker to unlock a device using its facial ID features with a 3-D printed version of the user's face.
  • Customer service company TTEC fully recovered from a ransomware attack. The company had to take some of its services offline, affecting customers like Verizon, after the attack on Sept. 12.
  • The U.S. government announced new sanctions against a popular cryptocurrency exchange that officials say attackers used to launder money made in ransomware attacks. The sanctions ban U.S. citizens and companies from transacting with the group.
  • A Russian threat actor demanded a $5.9 million ransom payment from an Iowa grain cooperative after a cyber attack this week. The company was able to recover and develop a workaround so that none of its shipments or operations were disrupted.
  • European police arrested more than 100 individuals charged with carrying out various cybercrime for the Italian mafia. The suspects are charged with SIM swapping and carrying out phishing attacks.
  • A popular voice-over-IP service is experiencing disruptions as of Thursday afternoon due to a distributed denial-of-service attack. The company serves 80,000 customers across more than 100 countries.
  • Alaska's state health department is still recovering two months after a ransomware attack. An unknown number of citizens may have had their personal information compromised, including full names and social security numbers.
  • Lithuanian cybersecurity researchers warned their government to stop using Chinese-produced mobile devices after they discovered several privacy concerns and security holes in the products. Some banned phrases on the phones include "Free Tibet" and "Voice of America."

Notable recent security issues

Title: High-profile Russian APT develops new backdoor tool

Description: Cisco Talos found a previously undiscovered backdoor from the Turla APT that we are seeing in the wild. This simple backdoor is likely used as a second-chance backdoor to maintain access to the system, even if the primary malware is removed. It could also be used as a second-stage dropper to infect the system with additional malware. The adversaries installed the backdoor as a service on the infected machine. They attempted to operate under the radar by naming the service "Windows Time Service," like the existing Windows service. The backdoor can upload and execute files or exfiltrate files from the infected system. In our review of this malware, the backdoor contacted the command and control (C2) server via an HTTPS encrypted channel every five seconds to check if there were new commands from the operator.

ClamAV signature: Win.Trojan.Turla-9891506-1

Cisco Secure OSQuery

Title: Microsoft releases updated protection for OMIGOD vulnerabilities

Description: Microsoft updated its patches for the so-called “OMIGOD” vulnerabilities in Open Management Infrastructure. The most severe vulnerability, CVE-2021-38647, could allow an attacker to remotely execute code. The three others (CVE-2021-38648, CVE-2021-38645 and CVE-2021-38649) could allow an adversary to obtain higher-level privileges on the targeted machine. Microsoft first disclosed these vulnerabilities last week as part of its monthly Patch Tuesday. However, security researchers found that some Linux machines could still be attacked using these exploits, prompting Microsoft to release updated guidance.

Snort SID: 58169

Most prevalent malware files this week

SHA 256: c1d5a585fce188423d31df3ea806272f3daa5eb989e18e9ecf3d94b97b965f8e

MD5: 9a4b7b0849a274f6f7ac13c7577daad8

Typical Filename: ww31.exe

Claimed Product: N/A

Detection Name: W32.GenericKD:Attribute.24ch.1201

SHA 256: 6c62b768d8b22888724288af038bc0b6e55280ddbbe42a436cdf68889346df18

MD5: 830ffb393ba8cca073a1c0b66af78de5

Typical Filename: smbscanlocal0902.exe

Claimed Product: N/A

Detection Name: MS17010::mURLin::W32.Auto:6c62b768d8.in03.Talos

SHA 256: 8b4216a7c50599b11241876ada8ae6f07b48f1abe6590c2440004ea4db5becc9

MD5: 34560233e751b7e95f155b6f61e7419a

Typical Filename: SAntivirusService.exe

Claimed Product: A n t i v i r u s S e r v i c e

Detection Name: PUA.Win.Dropper.Segurazo::tpd

SHA 256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507

MD5: 2915b3f8b703eb744fc54c81f4a9c67f

Typical Filename: VID[1].dat

Claimed Product: N/A

Detection Name: Win.Worm.Coinminer::1201

SHA 256: fad16599a866f466bdeff2a716b9aa79faa6677f2895f0b262cf9402deb4b66c

MD5: 04c1f4395f80a3890aa8b12ebc2b4855

Typical Filename: zReXhNb

Claimed Product: N/A

Detection Name: Auto.FAD16599A8.241842.in07.Talos

Keep up with all things Talos by following us on Twitter. Snort, ClamAV and Immunet also have their own accounts you can follow to keep up with their latest updates. You can also subscribe to the Beers with Talos podcast here and Talos Takes here (as well as on your favorite podcast app). And, if you’re not already, you can also subscribe to the weekly Threat Source newsletter here.

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/threat-source-newsletter-sept-23-2021/