Mokes and Buerak distributed under the guise of security certificates
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | kkjjhhdff.site | 9EAFBF578AF693767A8754 47C5782560D2FE3B80E0596F3FBA84D3 C&C kkjjhhdff[.]site (47.245.30[.]255) oderstrg[.]site Latest Webinars Reports |
| domain | ldfidfa.pw | iframe — with contents loaded from the third-party resource ldfidfa[.]pw — overlaid on top of the original page. The URL bar still |
| domain | oderstrg.site | FE3B80E0596F3FBA84D3 C&C kkjjhhdff[.]site (47.245.30[.]255) oderstrg[.]site Latest Webinars Reports Kaspersky researchers have discov |
| md5 | 094ade4f1bc82d09ad4e1c05513f686d | uerak CE1931C2EB82B91ADB5A9B9B1064B09F Backdoor.Win32.Mokes 094ADE4F1BC82D09AD4E1C05513F686D F869430B3658A2A112FC85A1246F3F9D 5FB9CB00F19EAFBF578AF69376 |
| md5 | 47c5782560d2fe3b80e0596f3fba84d3 | 0B3658A2A112FC85A1246F3F9D 5FB9CB00F19EAFBF578AF693767A8754 47C5782560D2FE3B80E0596F3FBA84D3 C&C kkjjhhdff[.]site (47.245.30[.]255) oderstrg[.]site Late |
| md5 | 5fb9cb00f19eafbf578af693767a8754 | 4F1BC82D09AD4E1C05513F686D F869430B3658A2A112FC85A1246F3F9D 5FB9CB00F19EAFBF578AF693767A8754 47C5782560D2FE3B80E0596F3FBA84D3 C&C kkjjhhdff[.]site (47.2 |
| md5 | b3290148681f8218ecb80ca430f9fdba | ampaign earlier in January. IoC Exploit.Win32.ShellCode.gen B3290148681F8218ECB80CA430F9FDBA (Certificate_Update_v02.2020.exe) Trojan-Downloader.Win32.B |
| md5 | ce1931c2eb82b91adb5a9b9b1064b09f | ificate_Update_v02.2020.exe) Trojan-Downloader.Win32.Buerak CE1931C2EB82B91ADB5A9B9B1064B09F Backdoor.Win32.Mokes 094ADE4F1BC82D09AD4E1C05513F686D F8694 |
| md5 | f869430b3658a2a112fc85a1246f3f9d | 4B09F Backdoor.Win32.Mokes 094ADE4F1BC82D09AD4E1C05513F686D F869430B3658A2A112FC85A1246F3F9D 5FB9CB00F19EAFBF578AF693767A8754 47C5782560D2FE3B80E0596F3F |
Full article458 words · extracted from securelist.com · click to collapse
The technique of distributing malware under the guise of legitimate software updates is not new. As a rule, cybercriminals invite potential victims to install a new version of a browser or Adobe Flash Player. However, we recently discovered a new approach to this well-known method: visitors to infected sites were informed that some kind of security certificate had expired. Unsurprisingly, the update on offer was malicious.
We detected the infection on variously themed websites — from a zoo to a store selling auto parts. The earliest infections found date back to January 16, 2020.
Attack pattern
This is what visitors of any of the hacked websites saw:
The alarming notification consists of an iframe — with contents loaded from the third-party resource ldfidfa[.]pw — overlaid on top of the original page. The URL bar still displays the legitimate address. This is what the malicious piece of code inserted into the original HTML page looks like:
From the screenshot it can be seen that the script parameters depend on the referrer, user_agent, and cookie values of the user. While the following fixed values are used as the user_agent_X and timestamp_X strings:
- user_agent_X = Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.117 Safari/537.36
- timestamp_X = 1579118411.0231 (01/15/2020 @ 8:00pm (UTC))
The code inserted by the cybercriminal loads the external malicious script ldfidfa[.]pw/jquery.js?&up= &ts= &r= &u= &c=
Malicious jquery.js script
The jquery.js script overlays an iframe that is exactly the same size as the page. The iframe content is loaded from the address https[:]//ldfidfa[.]pw//chrome.html. As a result, instead of the original page, the user sees a seemingly genuine banner urgently prompting to install a certificate update.
Clicking the Install (Recommended) button on the banner initiates the download of the file Certificate_Update_v02.2020.exe, which we detect as Exploit.Win32.ShellCode.gen. Analysis of the file showed it to be Trojan-Downloader.Win32.Buerak, packed using Nullsoft Scriptable Install System. It is not the only malware distributed by the attackers. For example, Backdoor.Win32.Mokes was spread via the same campaign earlier in January.
IoC
Exploit.Win32.ShellCode.gen
B3290148681F8218ECB80CA430F9FDBA (Certificate_Update_v02.2020.exe)
Trojan-Downloader.Win32.Buerak
CE1931C2EB82B91ADB5A9B9B1064B09F
Backdoor.Win32.Mokes
094ADE4F1BC82D09AD4E1C05513F686D
F869430B3658A2A112FC85A1246F3F9D
5FB9CB00F19EAFBF578AF693767A8754
47C5782560D2FE3B80E0596F3FBA84D3
C&C
kkjjhhdff[.]site (47.245.30[.]255)
oderstrg[.]site
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/mokes-and-buerak-distributed-under-the-guise-of-security-certificates/96324/