4 ms·
I was curious about a couple of things that weren't clear in the article. 1) Did you actually verify that the IPs provided were part of the Tor network, or did
by DominoTree 10y ago
I was curious about a couple of things that weren't clear in the article.
1) Did you actually verify that the IPs provided were part of the Tor network, or did you just see that their rDNS records currently have the string "tor" in them, as you described in the article?
2) Did you identify the malware you reversed by file hash, or did you find something that hit on the provided Yara sig?
I think adding these details to the article might give technical readers some more insight into and more confidence in the methods used.
- codedokode 10y agoThe file that yara signature refers to is probably a Ukranian "web shell" (a backdoor written in PHP that contains a file manager and simple SQL client) that is distributed freely at http://profexer.name/pas/ http://profexer.name/pas/. Anyone can download it and check. There is also a forum thread at https://rdot.org/forum/showthread.php?t=1567 https://rdot.org/forum/showthread.php?t=1567 started by this software developer in 2011. He answers the questions from the users of his software and asks them to donate to continue development. So it is a publicly available software, not a private tool made by some hacker group for themselves. That is why other people could find it in their systems.
- codedokode 10y agoI also checked the web archive for web shell download page [1]. It turns out that the notice with the text "Made in Ukraine" appears in version on August 31, 2015 [2] but is not present at earlier versions. The forum thread [3] shows that the software has been developed at least since 2011. I also looked through the code of a web shell. The code is written to be compatible with PHP4 and has some complicated parts, like building a zip archive by bytes. It has a lot of fallback methods, for example if some PHP functions are not available or not enabled, it would try several other ways to solve the task. I didn't like the style (a lot of two-letter variables, HTML and PHP code mixed together, hard to read and maintain). It looks like it was written by one person, but it would take some time, not a project one can write in a week. I guess the motivation for developer was to prove that he could write a better web shell than others. Here is a link to a formatted source code [4] if anyone would like to see it and maybe learn some PHP4 programming tricks. [1] https://web.archive.org/web/20150601000000*/http://profexer.name/pas/download.php https://web.archive.org/web/20150601000000*/http://profexer.... [2] https://web.archive.org/web/20150831091357/http://profexer.name/pas/download.php https://web.archive.org/web/20150831091357/http://profexer.n... [3] https://rdot.org/forum/showthread.php?t=1567 https://rdot.org/forum/showthread.php?t=1567 [4] http://pastebin.com/vUpKb3FL http://pastebin.com/vUpKb3FL
- mmaunder 10y agoNot sure why the post above has been downvoted to 0. Too bad. It's some of the best research we've ever done. We didn't look at the hashes or using hashing to identify anything. It's quite a story actually: The report provided a Yara sig for PHP malware. We used that to search our own attack data that we log and we found the full malware sample that matched the sig. But it was encrypted. It's a small piece of PHP that gets a key from a POST param or COOKIE and decrypts the executable code and runs it. Quite smart actually if you want to obfuscate code. So we needed the key. We looked at our attack data and thankfully we logged one of the attempts by an attacker to access the malware including their key. It was just 4 lowercase chars so we could have bruteforced it. We decrypted the malware. That gave us the name and version. We googled that and found the distro site. Claim they're a Ukrainian group and the version DHS has a Yara sig for is several versions behind. We downloaded it. It's a standard PHP 'shell' malware which means it's just a utility to manage a compromised site. File management, upload, OS info, OS command running etc. Nothing super scary and the most common malware we see. Nothing that would infect a workstation in a watering-hole attack. Regarding the IPs: No we just did a PTR lookup and assumed they're Tor exit nodes as they say they are. Mark.
- downandout 10y ago> Not sure why the post above has been downvoted to 0. Too bad. It's some of the best research we've ever done. Any post on HN that implies that anyone other than Vladimir Putin himself is responsible for Clinton's defeat will get downvotes...I've lost about 15 points on various posts downplaying this narrative. The Silicon Valley crowd simply cannot tolerate any hint of an alternate narrative.
- solarengineer 10y agoHN participants are now from all over the world. I'm an Indian in Singapore, for e.g.
- topynate 10y agoTrue enough (I'm in Israel. Hi!) but despite a good measure of international interest, it's the Americans who are most likely to have a strong emotional reaction to this topic. It's their election, after all. I really dislike +/- voting on political comments for just this reason; too easy to convince oneself that a downvote is merited.