ZeroHour
Palo Alto Unit 42published ()ingested Brad Duncan

Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky

lowRansomware exploited in the wildimportance 15
AI summary · glm-5.3-flash

The Afraidgate exploit kit campaign stopped distributing CryptXXX and now delivers the .zepto Locky variant exclusively through Neutrino EK since July 2016.

By mid-July 2016, the Afraidgate campaign switched from CryptXXX ransomware to consistently delivering the .zepto (Zepto) variant of Locky, using the Neutrino exploit kit after Angler EK disappeared in early June 2016. The campaign starts from compromised websites with injected scripts that redirect to Afraidgate domains and then Neutrino EK landing pages on .top domains. Zepto emerged after the Necurs botnet returned from a three-week outage, bringing new anti-sandboxing and evasion techniques.

  • Afraidgate last delivered CryptXXX on July 11, 2016, then switched to the .zepto Locky variant
  • Neutrino EK now distributes the majority of EK-based ransomware following Angler EK's disappearance
  • Zepto variant uses .zepto extension and adds anti-sandboxing and evasion techniques
  • IOCs include gate domains, .top Neutrino EK domains, and Locky post-infection C2 servers

Indicators of compromiseAll →

TypeIndicatorContext
domainactivebeliever.comom - GET /rokmediaqueries.js 188.166.38.125 port 80 - siber.activebeliever[.]com - GET /plugins/fancybox-for-wordpress/js/jquery.easing.1.
domainafraid.orgn continues to utilize gate domains using name servers from afraid.org. Changing Payloads As early as June 29, 2016 , we saw the A
domainatchisoncountyrecorder.com- GET /scripts/jquery.form.js 46.101.26.161 port 80 - motor.atchisoncountyrecorder[.]com - GET /js/blog.js 46.101.26.161 port 80 - motor.atchisonc
domainblautechnology.comom[.]br - GET /gantry-totop.js 46.101.26.161 port 80 - snow.blautechnology[.]com - GET /scripts/libs.js 46.101.26.161 port 80 - start.pute
domainbluechristian.toprdfngwg.blueelizabeth[.]top 185.140.33.99 port 80 - clfdkbl.bluechristian[.]top 185.140.33.99 port 80 - drhffhveq.greenjessica[.]top 185.
domainblueelizabeth.tophxmst.rautumngreen[.]top 185.140.33.99 port 80 - bkhrdfngwg.blueelizabeth[.]top 185.140.33.99 port 80 - clfdkbl.bluechristian[.]top 185.1
domainbsuperpink.toprt 80 - azbepfasz.yintored[.]top 5.2.72.236 port 80 - bkubf.bsuperpink[.]top 5.2.72.114 port 80 - iynwzttqd.hautumngreen[.]top 5.2.72.
domaincom.brcripts/custom.js 46.101.26.161 port 80 - oskol.migustapizza.com[.]br - GET /gantry-totop.js 46.101.26.161 port 80 - snow.blaut
domaingreenjessica.topfdkbl.bluechristian[.]top 185.140.33.99 port 80 - drhffhveq.greenjessica[.]top 185.140.33.99 port 80 - rklfdprel.blueelizabeth[.]top Loc
domainhautumngreen.top80 - bkubf.bsuperpink[.]top 5.2.72.114 port 80 - iynwzttqd.hautumngreen[.]top 5.2.72.236 port 80 - mxoug.yintored[.]top 5.2.72.236 port
domainladeratutors.com.]com - GET /js/addOnLoad.js 188.166.38.125 port 80 - nepal.laderatutors[.]com - GET /rokmediaqueries.js 188.166.38.125 port 80 - siber.
domainmafterred.topegoxmvzpx.bsuperpink[.]top 185.140.33.76 port 80 - erfxsnvj.mafterred[.]top 185.140.33.76 port 80 - hxmst.rautumngreen[.]top 185.140.
domainoautumnyellow.top- GET /to_top.js Neutrino EK: 5.2.72.236 port 80 - avukytj.oautumnyellow[.]top 5.2.72.236 port 80 - azbepfasz.yintored[.]top 5.2.72.236
domainonion.tostructions: mphtadhci5mrdlju.tor2web[.]org mphtadhci5mrdlju.onion[.]to zjfq4lnfbs7pncr5.tor2web[.]org zjfq4lnfbs7pncr5.onion[.]t
domainpolatoglumimarlik.comery.easing.1.3.min.js?ver=1.3 188.166.38.125 port 80 - zine.polatoglumimarlik[.]com - GET /scripts/jquery.sliderkit.1.9.2.pack.js 188.166.38.
domainputerasyawal.com[.]com - GET /scripts/libs.js 46.101.26.161 port 80 - start.puterasyawal[.]com - GET /js/addOnLoad.js 188.166.38.125 port 80 - nepal.lad
domainrautumngreen.top80 - erfxsnvj.mafterred[.]top 185.140.33.76 port 80 - hxmst.rautumngreen[.]top 185.140.33.99 port 80 - bkhrdfngwg.blueelizabeth[.]top 18
domainstmaryschooldmt.comhe Afraidgate campaign: Gates: 46.101.26.161 port 80 - leon.stmaryschooldmt[.]com - GET /scripts/jquery.form.js 46.101.26.161 port 80 - mot
domaintor2web.orgDomains from the decryption instructions: mphtadhci5mrdlju.tor2web[.]org mphtadhci5mrdlju.onion[.]to zjfq4lnfbs7pncr5.tor2web[.]or
domainyintored.topavukytj.oautumnyellow[.]top 5.2.72.236 port 80 - azbepfasz.yintored[.]top 5.2.72.236 port 80 - bkubf.bsuperpink[.]top 5.2.72.114 po
ipv4185.117.153.17650.135 port 80 - 185.5.250.135 - POST /upload/_dispatch.php 185.117.153.176 port 80 - 185.117.153.176 - POST /upload/_dispatch.php 185.
ipv4185.118.66.83.176 port 80 - 185.117.153.176 - POST /upload/_dispatch.php 185.118.66.83 port 80 - 185.118.66.83 - POST /upload/_dispatch.php Domain
ipv4185.140.33.76ored[.]top 5.2.72.236 port 80 - yegoxmvzpx.bsuperpink[.]top 185.140.33.76 port 80 - erfxsnvj.mafterred[.]top 185.140.33.76 port 80 -
ipv4185.140.33.99rred[.]top 185.140.33.76 port 80 - hxmst.rautumngreen[.]top 185.140.33.99 port 80 - bkhrdfngwg.blueelizabeth[.]top 185.140.33.99 port
ipv4185.5.250.13554.202 port 80 - 77.222.54.202 - POST /upload/_dispatch.php 185.5.250.135 port 80 - 185.5.250.135 - POST /upload/_dispatch.php 185.11
ipv4188.166.38.1251 port 80 - start.puterasyawal[.]com - GET /js/addOnLoad.js 188.166.38.125 port 80 - nepal.laderatutors[.]com - GET /rokmediaqueries.j
ipv446.101.26.161compromise associated with the Afraidgate campaign: Gates: 46.101.26.161 port 80 - leon.stmaryschooldmt[.]com - GET /scripts/jquery.
ipv45.187.0.137.253.173 port 80 - 5.9.253.173 - POST /upload/_dispatch.php 5.187.0.137 port 80 - 5.187.0.137 - POST /upload/_dispatch.php 77.222.5
ipv45.2.72.114.yintored[.]top 5.2.72.236 port 80 - bkubf.bsuperpink[.]top 5.2.72.114 port 80 - iynwzttqd.hautumngreen[.]top 5.2.72.236 port 80 -
ipv45.2.72.236zine.polatoglumimarlik[.]com - GET /to_top.js Neutrino EK: 5.2.72.236 port 80 - avukytj.oautumnyellow[.]top 5.2.72.236 port 80 -
ipv45.9.253.173rklfdprel.blueelizabeth[.]top Locky post-infection traffic: 5.9.253.173 port 80 - 5.9.253.173 - POST /upload/_dispatch.php 5.187.0.
ipv477.222.54.20287.0.137 port 80 - 5.187.0.137 - POST /upload/_dispatch.php 77.222.54.202 port 80 - 77.222.54.202 - POST /upload/_dispatch.php 185.5.
Full article722 words · extracted from unit42.paloaltonetworks.com · click to collapse

By mid-July 2016, the Afraidgate campaign stopped distributing CryptXXX ransomware. It is now distributing the ".zepto" variant of Locky. Afraidgate has been using Neutrino exploit kit (EK) to distribute malware after Angler EK disappeared in early June 2016. As we previously reported, this campaign continues to utilize gate domains using name servers from afraid.org.

Changing Payloads

As early as June 29, 2016, we saw the Afraidgate campaign deliver Locky ransomware. This campaign switched between delivering CryptXXX and Locky ransomware during the next two weeks. July 11, 2016, was the last time we saw Afraidgate deliver CryptXXX. Since then, this campaign has been consistently delivering Locky.

Figure 1: Flow chart for an infection from the Afraidgate campaign.

This variant of Locky uses a .zepto file extension for any encrypted files. We started seeing this Zepto variant of Locky after a three-week outage of the Necurs botnet ended on June 21, 2016. Locky had been absent during the outage, but after the botnet returned, Locky also reappeared with new anti-sandboxing and evasion techniques.

Some security vendors have named this new variant Zepto ransomware, but they still highlight its similarities with the previous Locky variant.

Figure 2: Desktop of a Windows host infected with the Zepto variant of Locky.

From Angler EK to Neutrino

Like most campaigns, Afraidgate switched to Neutrino EK after Angler EK disappeared in early June 2016. We have seen two other large-scale campaigns also move from Angler to Neutrino EK: the EITest and pseudo-Darkleech campaigns. For now, Neutrino appears to be distributing the majority of ransomware for EK-based infections. Outliers still exist, like Magnitude EK distributing Cerber ransomware. Rig EK has also been noted for an occasional ransomware infection. But the bulk of EK-based ransomware infections are most often attributed to Neutrino EK.

Example of an Afraidgate Infection

Figure 3: Traffic from an Afraidgate infection filtered in Wireshark.

As noted in our previous post on EK fundamentals, EK-based campaigns start with a compromised website. Pages from the compromised site have injected script that, in this case, lead to an Afraidgate domain behind the scenes.

Figure 4: Injected script in page from a compromised website.

After the victim's computer connects to the URL on an Afraidgate domain, the server returns more Javascript with an iframe leading to a Neutrino EK landing page.

Figure 5: Afraidgate domain leading to the Neutrino EK landing page.

Neutrino EK domains for this campaign tend to use .top as the top level domain (TLD). Otherwise, we see no surprises. Neutrino is a well-known EK that has been documented by others.

Conclusion

Domains, IP addresses, and other indicators associated with Neutrino EK and Locky are constantly changing. We continue to investigate this activity for applicable indicators to inform the community and further enhance our threat prevention platform.

WildFire continues to detect submitted samples of Locky ransomware, and AutoFocus identifies this threat under the Unit 42 Locky tag.

Indicators of Compromise

So far in July 2016, we have seen the following indicators of compromise associated with the Afraidgate campaign:

Gates:

  • 46.101.26.161 port 80 - leon.stmaryschooldmt[.]com - GET /scripts/jquery.form.js
  • 46.101.26.161 port 80 - motor.atchisoncountyrecorder[.]com - GET /js/blog.js
  • 46.101.26.161 port 80 - motor.atchisoncountyrecorder[.]com - GET /scripts/custom.js
  • 46.101.26.161 port 80 - oskol.migustapizza.com[.]br - GET /gantry-totop.js
  • 46.101.26.161 port 80 - snow.blautechnology[.]com - GET /scripts/libs.js
  • 46.101.26.161 port 80 - start.puterasyawal[.]com - GET /js/addOnLoad.js
  • 188.166.38.125 port 80 - nepal.laderatutors[.]com - GET /rokmediaqueries.js
  • 188.166.38.125 port 80 - siber.activebeliever[.]com - GET /plugins/fancybox-for-wordpress/js/jquery.easing.1.3.min.js?ver=1.3
  • 188.166.38.125 port 80 - zine.polatoglumimarlik[.]com - GET /scripts/jquery.sliderkit.1.9.2.pack.js
  • 188.166.38.125 port 80 - zine.polatoglumimarlik[.]com - GET /html5shiv.js
  • 188.166.38.125 port 80 - zine.polatoglumimarlik[.]com - GET /to_top.js

Neutrino EK:

  • 5.2.72.236 port 80 - avukytj.oautumnyellow[.]top
  • 5.2.72.236 port 80 - azbepfasz.yintored[.]top
  • 5.2.72.236 port 80 - bkubf.bsuperpink[.]top
  • 5.2.72.114 port 80 - iynwzttqd.hautumngreen[.]top
  • 5.2.72.236 port 80 - mxoug.yintored[.]top
  • 5.2.72.236 port 80 - yegoxmvzpx.bsuperpink[.]top
  • 185.140.33.76 port 80 - erfxsnvj.mafterred[.]top
  • 185.140.33.76 port 80 - hxmst.rautumngreen[.]top
  • 185.140.33.99 port 80 - bkhrdfngwg.blueelizabeth[.]top
  • 185.140.33.99 port 80 - clfdkbl.bluechristian[.]top
  • 185.140.33.99 port 80 - drhffhveq.greenjessica[.]top
  • 185.140.33.99 port 80 - rklfdprel.blueelizabeth[.]top

Locky post-infection traffic:

  • 5.9.253.173 port 80 - 5.9.253.173 - POST /upload/_dispatch.php
  • 5.187.0.137 port 80 - 5.187.0.137 - POST /upload/_dispatch.php
  • 77.222.54.202 port 80 - 77.222.54.202 - POST /upload/_dispatch.php
  • 185.5.250.135 port 80 - 185.5.250.135 - POST /upload/_dispatch.php
  • 185.117.153.176 port 80 - 185.117.153.176 - POST /upload/_dispatch.php
  • 185.118.66.83 port 80 - 185.118.66.83 - POST /upload/_dispatch.php

Domains from the decryption instructions:

  • mphtadhci5mrdlju.tor2web[.]org
  • mphtadhci5mrdlju.onion[.]to
  • zjfq4lnfbs7pncr5.tor2web[.]org
  • zjfq4lnfbs7pncr5.onion[.]to

Text extracted automatically; images, tables and formatting may be missing. Original: https://unit42.paloaltonetworks.com/unit42-afraidgate-major-exploit-kit-campaign-switches-from-cryptxxx-ransomware-back-to-locky/