ZeroHour
Security Affairspublished ()ingested @securityaffairs

CSE Malware ZLab – Malware Analysis Report: The Bandios malware suite

mediumMalwareimportance 35CVE-2017-1182

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-1182
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-server default

IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-server default communications, HTTP, are being used. IBM X-Force ID: 123493.

NVD description · AI analysis pending
7.59%
  • ibm tivoli monitoring

Indicators of compromiseAll →

TypeIndicatorContext
domainozkngbvcs.bkt.gdipper.com1beb8b6f4bf0c1ba6b021e9e3f6f72” Moreover, the site “ http://ozkngbvcs[.]bkt[.]gdipper[.]com/” is used as a repository for the entire colony of th
sha2563f11ea10cb7dc4ed8e22de64e9218b1c481beb8b6f4bf0c1ba6b021e9e3f6f72e hosted on the “/OnlineInstaller.exe” path, with the hash “3f11ea10cb7dc4ed8e22de64e9218b1c481beb8b6f4bf0c1ba6b021e9e3f6f72” Moreover, the site “ http://ozkngbvcs[.]bkt[.]gdipper[.]co
Full article297 words · extracted from securityaffairs.com · click to collapse

The researchers at CSE ZLab have spotted a new family of malware, tracked as Bandios malware spreading in the wild.

The peculiarity of  Bandios malware is the fact that this malware is in a rapid and constant evolution and development.

Experts observed several versions of the malware stored on the same websites, they represent the evolution of the malicious code that is continuously updated by the authors. ZLab researchers analyzed all these samples and noticed that they have the same behavior, the last compilated and thus the most recent is the sample hosted on the “/OnlineInstaller.exe” path, with the hash “3f11ea10cb7dc4ed8e22de64e9218b1c481beb8b6f4bf0c1ba6b021e9e3f6f72”

Moreover, the site “http://ozkngbvcs[.]bkt[.]gdipper[.]com/” is used as a repository for the entire colony of this malware:

The main malware sample is installable from the simple path “OnlineInstaller.exe.”

During the analysis, the researchers observed several versions of this malware published in the same path, some of them are test versions because they cannot be executed due to the presence of coding errors.

The Bandios malware implements an advanced evasion and anti-analysis technique, the executable leverages a common technique dubbed “TLS callback.”

Another peculiarity of the Bandios malware is the usage of digital certificates revoked by the certification authority.

Finally, the above figure shows that we have a punctual separation and categorization of all the samples, based on Windows version (7 or XP), architecture (32 or 64 bit) or the exploit, in particular, the exploit code for the CVE-2017-1182 Microsoft Office Exploit vulnerability.

Further details on the Bandios malware suite, including IoCs and Yara Rules available in the report published by researchers at ZLAb.

You can download the full ZLAB Malware Analysis Report at the following URL:

http://csecybsec.com/download/zlab/20180424_CSE_Bandios_malware_suite.pdf

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – Bandios malware suite, cybercrime)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/71721/malware/bandios-malware-suite.html