« Big ‘Patch Tuesday’ out
Money talks »

Exploits 4free

June 10th, 2009

Today I was looking at an interesting website and a drive-by-download associated to it.

pic

The file is not a JPG… in fact it is an exploit script. I detail what it does in the diagram below:

fakelogo

The hacker has left its Apache/2.2.9 PHP/5.2.6 Server wide open! The IP is located in Hong Kong China and actually hosts two different domains (that are mirrors of each other).

Because the server is not protected, you can easily browse through its file repository and find all the exploit code in there. If you check the date, these exploits are fairly recent.

exploit0

There is a nice PHP management page, called PHPSpy that allows you to update your exploits:

exploit333

I downloaded all the files in that repository for a closer look.

Amongst them, an AVI file that exploits a vulnerability in Explorer. In my case it just crashed it and did nothing else. The exploit happens when you select the file and it tries to display its properties in the details pane.

exploit1

DLL files compiled in C# that bear no doubt as to what their intent is (exploit Shellcode):

exploit9

Heavily obfuscated html pages loaded with exploits:

exploit6

Following the PHPSpy link  lead me to the Security Angel’s website (in Chinese).

A quick translation reveals (more or less) what it’s all about:

phpspy

The “Security Angel team” has more exploits for grab:

exploit5

It also has some tutorials and scripts for the newbies, such as this ‘man in the middle’ attack perl script:

exploit4

man1

I decided to analyze the main executable that these exploits push. It creates a service as well as injects a DLL file into System32.

exploit8

A VirusTotal scan… the sample is detected but the descriptions are vague.

exploit7

Security researchers interested in the actual location of the exploit server can contact me.

Jerome Segura

    This entry was posted on Wednesday, June 10th, 2009 at 1:20 pm and is filed under Exploits, Research. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

    Comments:

    1.      by
    2.      by
    3.      by
    4.      by
    • (0) comments
    • |
    • Add your comments




RSS feed to this site Twitter Linkedin YouTube Channel

 

RSS feed to this site Jerome Segura is a Security Analyst working at ParetoLogic.

You can contact him at:
MalwareDiaries Email

 

Pages

  • Live Malware Map
  • VB2009 pictures
  • Zheng™ Technology
  • About
  • Contact Us



Security Software

  • XoftSpySE Anti-Spyware
  • Anti-Virus PLUS
  • Privacy Controls



Malware Top 10

  • Koobface Worm
  • DNS Changer Trojan
  • Fake Alert Trojan
  • Windows System Suite
  • Smart Protector
  • Home Antivirus 2010
  • PC Antispyware 2010
  • System Security
  • AVCare
  • Perfect Defender 2009



Archives

  • November 2009
  • October 2009
  • September 2009
  • August 2009
  • July 2009
  • June 2009
  • May 2009
  • April 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008



Categories

  • Adware (1)
  • Banker Trojans (3)
  • Botnets (2)
  • Conferences (4)
  • DDos (1)
  • Exploits (32)
  • Fake codecs (30)
  • IM threats (1)
  • Interviews (5)
  • Keyloggers (1)
  • Mac security (14)
  • Malware Trends (67)
  • Phishing (7)
  • Podcast (1)
  • ransomware (1)
  • Research (33)
  • Rogue software (47)
  • Rootkits (2)
  • scams (3)
  • Social Networking (4)
  • Uncategorized (104)
  • Wireless Security (1)
  • world map (1)



 
 
 

© 2009 ParetoLogic Inc.