The never ending Exploit Kit shift
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2011-3544 | Remote Code Execution in Oracle Java SE JRE Applet Rhino Script Engine CVE-2011-3544 is an access control flaw in the Rhino JavaScript Script Engine component used by Java applets in Oracle's Java Runtime Environment. It is triggered when a user's browser loads a malicious Java applet, allowing script executed through the Rhino engine to bypass Java's access restrictions. An attacker who successfully exploits it gains the ability to run arbitrary code on the victim's machine with the privileges of the logged-in user, typically via drive-by download from a compromised or attacker-controlled website. Any system with a vulnerable Oracle Java SE JDK or JRE and an enabled Java browser plugin is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-03-03, carries a 96.7% EPSS probability of exploitation within 30 days, and contemporary reports show it weaponized in the BlackHole/Whitehole exploit kits and used in mass OS X exploitation. Do: Apply updated Oracle Java SE builds per Oracle's vendor instructions, prioritizing internet-facing and end-user systems listed in the KEV guidance. Where patching is delayed, disable the Java browser plugin or block Java applets at the web gateway, since the attack vector is malicious applets served over the web. Review endpoints for signs of exploit-kit drive-by compromise, especially legacy Windows and OS X machines with outdated Java. | — | 97% | KEV |
| masshundreds of millions of desktops and servers with a Java runtime installed; exact count unknown | |
| CVE-2012-1723 | Remote Arbitrary Code Execution in Oracle Java SE (Hotspot Component) Oracle Java SE's Java Runtime Environment contains an unspecified flaw in its Hotspot component that allows remote attackers to affect confidentiality, integrity, and availability — characterized by CISA as arbitrary code execution. The available data does not document the exact trigger beyond 'unknown vectors related to Hotspot,' but flaws in the JVM's execution engine of this type are typically reached remotely by having the runtime process malicious Java content. A successful attacker gains code execution in the context of the process running the JVM, taking control of the affected host. Any deployment running affected, unpatched Oracle Java SE — particularly legacy JRE installs — is affected. The vulnerability is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03) with known ransomware use and a 93.7% EPSS probability of exploitation in the next 30 days, confirming active in-the-wild exploitation, though the reviewed data lists no public PoC. Do: Per CISA's required action, apply updates per vendor instructions: upgrade every Oracle Java SE installation to a currently supported patched release and inventory for legacy JRE builds that predate the 2012 Hotspot fix. Disable or restrict the Java browser plugin where it is not needed, and given known ransomware use, prioritize legacy Java systems for patching and threat-hunting. | — | 94% | KEV ransomware |
| mass≈ millions of endpoints running legacy, unpatched Java (exact count unknown) | |
| CVE-2013-2465 | Unspecified Flaw in Oracle Java SE 2D Component Exploited in the Wild (CVE-2013-2465) CVE-2013-2465 is an unspecified vulnerability in the Java Runtime Environment (JRE) component of Oracle Java SE, located in the 2D graphics/rendering subsystem. It is triggered via unknown vectors related to 2D, typically when a hostile applet or application causes the JRE to process crafted graphical content. An attacker who successfully exploits it can affect confidentiality, integrity, and availability, which in practice means remote compromise of the affected system without user credentials. Any deployment of Oracle Java SE — end-user desktops with the browser plugin and servers running JRE releases current at the time of the June 2013 Oracle Critical Patch Update — is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-28 with known ransomware use, EPSS assigns it a 98.7% probability of exploitation within 30 days (top percentile), and related 2013-era reporting around exploit kits such as LightsOut documents the era's heavy exploit-kit targeting of Java. Do: Apply the June 2013 Oracle Java SE Critical Patch Update, or any later supported Java SE release, per vendor instructions as CISA requires. Audit environments for legacy JRE installs and enabled Java browser plugin/applet support — especially on user-facing and internet-exposed legacy servers — and remove or upgrade them. Because CISA lists known ransomware use, prioritize patching external-facing and end-user systems. | — | 99% | KEV ransomware |
| masshundreds of millions of endpoints at the time of 2013 disclosure; today, a residual population of legacy Java deployments of unknown size |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| sha256 | 3c3172a47915fe77ef1f2d38ccb5c786d30f13d8c5161fd0f2411c3b0459a036 | 35AB90 -- CVE-2014-0515 1.jar appears to be several hashes: 3C3172A47915FE77EF1F2D38CCB5C786D30F13D8C5161FD0F2411C3B0459A036 -- CVE-2011-3544 C35A5AA55C911F1F1CFF733E0F422C0DE316CFFAF3 |
| sha256 | 4525f4fe895d887ae354ce6221bad424690503dafebc87a43cf54092faa9cbe8 | 3E0F422C0DE316CFFAF3B285ABA57A4CFDB7188341 -- CVE-2012-1723 4525F4FE895D887AE354CE6221BAD424690503DAFEBC87A43CF54092FAA9CBE8 -- CVE-2012-1723 C1806E59BAE8CD3A320FB249223852D25DD6229984 |
| sha256 | 4788cca43f06752bd6d52978cbf8058fa4a3aeb76bc5242ee83da4223ec2de13 | u.swf, 1.swf, and 2.swf, these appears to be a single hash: 4788CCA43F06752BD6D52978CBF8058FA4A3AEB76BC5242EE83DA4223EC2DE13 -- CVE-2013-0634 n3.swf, however, is a different hash: 8A5E |
| sha256 | 7f04e3b43fa259984aee7cf9fbe83a2c0994fb321d650e5b9fdfdfb11435f05e | 265825FBAC3887F6840B1DBB2E2556148F597D80C7 -- CVE-2013-2465 7F04E3B43FA259984AEE7CF9FBE83A2C0994FB321D650E5B9FDFDFB11435F05E -- CVE-2013-2465 2.jar appears to be a single hash: C945046 |
| sha256 | 8a5edd1e23db8054e6b7b76193a70edc7c0924320f4d26ab963aa53cea35ab90 | DE13 -- CVE-2013-0634 n3.swf, however, is a different hash: 8A5EDD1E23DB8054E6B7B76193A70EDC7C0924320F4D26AB963AA53CEA35AB90 -- CVE-2014-0515 1.jar appears to be several hashes: 3C3172 |
| sha256 | c1806e59bae8cd3a320fb249223852d25dd62299844cf045d5af4ae1df0452af | 6221BAD424690503DAFEBC87A43CF54092FAA9CBE8 -- CVE-2012-1723 C1806E59BAE8CD3A320FB249223852D25DD62299844CF045D5AF4AE1DF0452AF -- CVE-2012-1723 C43DBBADD79F2C50F67BFC265825FBAC3887F6840B |
| sha256 | c35a5aa55c911f1f1cff733e0f422c0de316cffaf3b285aba57a4cfdb7188341 | 38CCB5C786D30F13D8C5161FD0F2411C3B0459A036 -- CVE-2011-3544 C35A5AA55C911F1F1CFF733E0F422C0DE316CFFAF3B285ABA57A4CFDB7188341 -- CVE-2012-1723 4525F4FE895D887AE354CE6221BAD424690503DAFE |
| sha256 | c43dbbadd79f2c50f67bfc265825fbac3887f6840b1dbb2e2556148f597d80c7 | 49223852D25DD62299844CF045D5AF4AE1DF0452AF -- CVE-2012-1723 C43DBBADD79F2C50F67BFC265825FBAC3887F6840B1DBB2E2556148F597D80C7 -- CVE-2013-2465 7F04E3B43FA259984AEE7CF9FBE83A2C0994FB321D |
| sha256 | c9450462f9a58c2c854e93ff8a6782c7af677653097347f20dd679939ea19b5a | 435F05E -- CVE-2013-2465 2.jar appears to be a single hash: C9450462F9A58C2C854E93FF8A6782C7AF677653097347F20DD679939EA19B5A -- CVE-2013-2465 The hostnames where this exploit kit has b |
Full article407 words · extracted from blog.talosintelligence.com · click to collapse
Thursday, June 12, 2014 11:27
Recently we've been able to observe several shifts in exploit kit techniques, so I thought it would be good to share the IOC information for the exploit kits so that administrators and network defenders can take a look at their devices and logs to remediate on their networks.
Bleeding Life
Bleeding life, traditionally, was not one of the more subtle exploit kits.
In the past, the exploit kit would attempt to get the exploits through fairly obvious URI methods. For example:
"/load_module.php?e=Adobe-2010-2884"
"/load_module.php?e=Java-2010-3552"
"/modules/helpers/Java-2010-0842.jar"
The URI would be explicit about which vulnerability the kit was going to download and run on the client. However, as of the beginning of of May, subtlety increased slightly, as we've seen a shift in this technique. The jar and swf files are now named much simpler. So, for example:
"/modules/2.swf"
"/modules/1.swf"
"/modules/nu.swf"
"/modules/n3.swf"
"/modules/1.jar"
The vulnerabilities have been updated to more modern exploits as well. (I'll detail the hashes and vulnerabilities here in a second.)
The landing page appears to have shifted format in URI as well. For example:
"/load_module.php?user=", in which the variable issued to user is either "n1, 1, 2, or 11" or for those of you that speak regular expression: user=(n1|11?|2)
Now for some hashes:
nu.swf, 1.swf, and 2.swf, these appears to be a single hash:
4788CCA43F06752BD6D52978CBF8058FA4A3AEB76BC5242EE83DA4223EC2DE13 -- CVE-2013-0634
n3.swf, however, is a different hash:
8A5EDD1E23DB8054E6B7B76193A70EDC7C0924320F4D26AB963AA53CEA35AB90 -- CVE-2014-0515
1.jar appears to be several hashes:
3C3172A47915FE77EF1F2D38CCB5C786D30F13D8C5161FD0F2411C3B0459A036 -- CVE-2011-3544
C35A5AA55C911F1F1CFF733E0F422C0DE316CFFAF3B285ABA57A4CFDB7188341 -- CVE-2012-1723
4525F4FE895D887AE354CE6221BAD424690503DAFEBC87A43CF54092FAA9CBE8 -- CVE-2012-1723
C1806E59BAE8CD3A320FB249223852D25DD62299844CF045D5AF4AE1DF0452AF -- CVE-2012-1723
C43DBBADD79F2C50F67BFC265825FBAC3887F6840B1DBB2E2556148F597D80C7 -- CVE-2013-2465
7F04E3B43FA259984AEE7CF9FBE83A2C0994FB321D650E5B9FDFDFB11435F05E -- CVE-2013-2465 2.jar appears to be a single hash:
C9450462F9A58C2C854E93FF8A6782C7AF677653097347F20DD679939EA19B5A -- CVE-2013-2465 The hostnames where this exploit kit has been hosted in the past 30 days (that we've seen) are the following:
www.rouleta.org
tsp-team.com
www.air-bilet.ru
www.cook-n-eat.net
www.preotech.ru
With the following as "Referers":
www.vz.ru
tvzvezda.ru
www.westernbeef.com
paranormal-news.ru
rollen.ru
www.insur-info.ru
The following hashes, for example, are shared between Bleeding Life and the Nuclear exploit kit:
4788CCA43F06752BD6D52978CBF8058FA4A3AEB76BC5242EE83DA4223EC2DE13
7F04E3B43FA259984AEE7CF9FBE83A2C0994FB321D650E5B9FDFDFB11435F05E
C35A5AA55C911F1F1CFF733E0F422C0DE316CFFAF3B285ABA57A4CFDB7188341
4525F4FE895D887AE354CE6221BAD424690503DAFEBC87A43CF54092FAA9CBE8
C43DBBADD79F2C50F67BFC265825FBAC3887F6840B1DBB2E2556148F597D80C7
The fact that so many exploits are shared between the two, in my mind, draws a connection. I don't know if it's a connection in the same way that Cool and Blackhole were related (written by the same person), but I find it interesting.
All these hashes are detected and prevented with both ClamAV and FireAMP, and Sourcefire IPS/Snort's detection will ship in the form of SIDs:
31229-31232
This blog was made possible by contributions and assistance from Emmanuel Tacheau from our Cisco TRAC team.
Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/the-never-ending-exploit-kit-shift/