4 ms·
There is a nice writeup about the exploit which includes more information about the indicators of compromise (IOCs) on the (drweb) site: https://vms.drweb.com/
by this_steve_j 4y ago
There is a nice writeup about the exploit which includes more information about the indicators of compromise (IOCs) on the (drweb) site:
https://vms.drweb.com/virus/?i=25604695 https://vms.drweb.com/virus/?i=25604695
For example, the binary file has a SHA1 of 215a4470063080696630fb6015378938e8c16a15. It reaches out to a C2 server with the IP address 109[.]234.38[.]69. It injects a script called "lone.js" which contacts another server. Etc.
Someone has also submitted it to Virustotal very recently, and there is additional information available to explore. https://www.virustotal.com/gui/file/7ab779b39a7ff2a8e4e4957e91be885e3b193959ff19f7d57f7befd8e6ce39b4 https://www.virustotal.com/gui/file/7ab779b39a7ff2a8e4e4957e...
Yara is among the tools which can be used to search a system for these IOCs provided a set of rules written in the appropriate syntax.
- mort96 4y agoHow is that a nice write-up? It's describing the malware as both a backdoor and a trojan, but it's not a trojan and nothing in the description indicates that it's a backdoor. And after reading the write-up it's not even clear to me whether the Go program is running on the same machine as the WordPress (if it is, why does it need to exploit plug-in vulnerabilities? If not, how does the Go program itself spread? Is this where the "trojan horse" part comes in?)
- this_steve_j 4y agoI would agree that the author of the write-up took some creative liberties in applying certain malware category terms like "trojan" and "backdoor" and that it lacks the polish and depth found in other reports from malware reverse engineers. However it contains enough basic information for a site operator to search their logs and filesystem to see if they have those indicators of compromise. It's "nice" in the sense that someone published the details of an attack quickly and provided some key details to the community, who can expand on these findings or use them in signature-based antivirus detection tools. I also linked to the Virustotal report which has more information about the go executable including headers, exported symbols and debug information that you can see for free, and which has more detailed analysis for security researchers who have an enterprise subscription.
- mort96 4y agoI wouldn't really call it "creative liberties", I would simply call it misleading the reader. Words mean things, and seeing it described as a "trojan horse" might lead you to think you're safe if you haven't downloaded and run anything dubious. But I agree that among the BS, there is useful information there. It's worth reading for people who may be affected even if I don't think it's "nice".
- this_steve_j 4y agoWhat would you consider a misleading about its description of the behavior as a “backdoor? The write-up describes it as a persistent executable payload and goes on to enumerate the C2 commands that it reportedly received from a remote server, for which some IPs are provided. Whether or not it’s a trojan depends on how it got onto the system in the first place. There isn’t more information in the article about how the system was infected, but maybe the author didn’t have evidence to share. That doesn’t mean it’s wrong, just that more details would be needed to substantiate that aspect of the attack.