Recent MNKit Exploit Activity Reveals Some Common Threads

Unit 42 recently identified a variant of MNKit-weaponized documents being used to deliver LURK0 Gh0st, NetTraveler, and Saker payloads. The documents were delivered to targets involved with universities, NGOs, and political/human rights groups concerning Islam and South Asia. Reuse of this MNKit variant, sender email addresses, email subject lines, attachment filenames, command and control domains, XOR keys, and targeted recipients show a connection between the different payload families delivered.

MNKit is the name given to a builder that generates CVE-2012-0158 exploit documents. The documents are in MHTML format and install a malicious payload on the compromised host. We believe MNKit is privately shared between multiple attack groups, but is not widely available.

Information about previous attack campaigns using MNKit is available in the following reports:

For more details on MNKit, see the Sophos publication, Office exploit generators.

Typical MNKit MHTML files have used User123 or User323 as the Author and LastAuthor element values within their DocumentProperties sections and C:/2673C891/Doc1.files/ as a file directory location. The samples discussed in this blog use User323 and User426 as Author and LastAuthor element values and C:/23456789/Doc1.files/ as a file directory location.

LURK0 Delivery

LURK0 is a family of remote access trojans derived from Gh0st RAT. It has been used by attack groups for years, as discussed by CitizenLab in a publication from 2012 on Tibet-related information operations and has been fairly well analyzed in publicly available reporting. Contained within a subset of the MNKit exploit documents were malicious SFX PE files that delivered LURK0 implants. These PE files were encoded using a decrementing XOR function with the key beginning at 127. Within each SFX are five files:

The execution of the self-extracting zips side-loading of LURK0 payloads is identifiable by the registry key they create

The hashes and compile times of the malicious RasTls.dll files follow:

http://www.amerikauyghur[.]top and dge.123nat[.]com are two command and control domains resolved by the malware. The first domain was previously mentioned by Arbor Networks in a report detailing the targeting of Tibetan, Hong Kong, and Taiwanese interests in their report, The Four-Element Sword Engagement. A subdomain of 123nat[.]com, manhaton.123nat[.]com, was also referenced in Arbor’s report as a LURK0 command and control domain. Below shows theLURK0 string used in the first five bytes of an implant beacon.

Saker Delivery

Saker, often also called ‘Xbox’ and ‘Mongall’, is a malware family used by targeted attack groups who have also deployed NetTraveler and Gh0stRAT.

Two of the sending addresses used to distribute the above LURK0 samples,dolkun2015@gmail[.]com and duqdiniishlari@gmail[.]com, were also used to distributed other types of malware. By observing overlaps in the sending and receiving email addresses as well as the filenames of attachments, we were able to identify additional MNKit exploit documents that also included self-extracting PE files. These PE files were again XOR encoded in the attached documents using the same decrementing key (beginning with 127). These additional SFX PE files are password protected using one of the following passwords:

Instead of including RasTls.exe to sideload payloads (as the LURK0 payloads did), within each of the embedded PEs is a single DLL file named msdis.dll which exports a function namedJustTempFun. The recently compiled and deployed msdis.dll files’ SHA256 hashes and compile timestamps follow:

Saker samples construct strings during execution. One such string is the origin of the malware’s name.

The Saker PEs also contain a user agent strings (also constructed manually during execution) of Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; .NET CLR 1.1.4531) and Mozilla/6.0 (compatible; MSIE 9.0; Wis NT 8.1; .NET CLR 2.13431). This second user agent is similar to the user agent, <code>Mozilla/4.0 (compatible; MSIE 6.0; Wis NT 5.0; .NET CLR 1.1.4322), as outlined by FireEye in 2014.

The command and control locations for the Saker samples delivered via MNKit follow:

amerikauyghur[.]top overlaps with the LURK0 samples previously mentioned. Bothonebook[.]top (registered with a registrant email address of interestbook@sina.com and bsnl.wang (registered with a registrant email address of jgjop@yahoo.com) have resolved previously to 103.232.222[.]20.

Using AutoFocus, we were able to locate additional samples that resolved to these domains. The samples are a mix of LURK0, Saker, and PlugX. Their hashes follow:

Pivoting from the first rather unique user agent string we located the following Saker samples ontotalhash:

These samples beacon to http://www.togolaga[.]com (103.246.246[.]221) and unisers[.]com (123.254.104[.]32) which respectively were mentioned by the Sophos Rotten Tomatoes publication.

Within AutoFocus the user-agent string was also seen being used by the following Saker sample hashes:

These resolve and connect to the following domain names:

notebookhk[.]net, also mentioned in the Rotten Tomatoes report, was at one point a known PlugX command and control domain. This domain as well as http://www.dicemention[.]com are noted Korplug (often used to load PlugX) domains outlined by ESET in a blog post here. These domains as well as other overlapping indicators, such as the export function nameJustTempFun, were discussed by ProofPoint in a 2015 publication on PlugX targeting Russian military and telecom organizations and by Kaspersky in part 1 of their publication on NetTraveler.

NetTraveler Delivery

NetTraveler is a backdoor used to install other malware, steal information, and provide remote control of a compromised system. The targets previously mentioned by Kaspersky Lab of the NetTraveler operators aligns closely with the recipients of a new set of samples.

Three additional MNKit documents were located as MNKit exploit attachments. Unfortunately, we were unable to locate emails the attachments were sent with. These three samples also included SFX PE files encoded using the same decrementing XOR. Within each PE are three files which side-load NetTraveler. The files are named:

The hashes and compile timestamps for each fslapi.dll follow:

The fslapi.dll files load their accompanying fslapi.dll.gui files that are XOR encoded. The decoded fslap.dll.gui DLLs include the following embedded URLs, the first of which was previously documented by Unit 42 as a red herring within NetTraveler samples.

The fslapi.dll files contain an overlay that is used to decode the real C2 as documented in the same Unit 42 NetTraveler blog. The decoded command and control URLs include:

Both domains have previously resolved to 103.231.184[.]163 which has also hostedhttp://www.tassnews[.]net http://www.info-spb[.]com, both of which have also been used as NetTraveler command and control domains. http://www.tassnews.net is also the resolved by

the SFX PE (encoding using the same decrementing XOR) decoded from

another sample of this MNKit variant.

Tassnews[.]net was registered with a registrant email address of ghjksd@gmail[.]com and info-spb[.]com was registered with a registrant email address of kefj0943@yahoo[.]com.Riaru[.]net was registered with a registrant email address of fjknge@yahoo[.]com on 29 March 2016, which also registered one other domain name, yandax[.]net, on 16 June 2016 using the same authoritative DNS servers and registrar. Interfaxru[.]com was registered with a registrant email address of ganh@gmail[.]com on 18 April 2016 using the same registrar and authoritative DNS servers as riaru[.]net and yandax[.]net. Only one domain name is currently registered byganh@gmail[.]com, however it would be no surprise if an additional domain is registered by this registrant in the near future.

Putting it All Together

While MNKit has been associated with multiple different groups the reuse of domain names, IPv4 addresses, phishing themes, XOR schemes, and email accounts are strong evidence for linkage between these new attacks and the previously documented ones. The change in PE SFX contents over the three sets of SFX PE files between February 2016 to March 2016, March 2016 to April 2016, and April 2016 to June 2016 time frames show a slight deviation is payload but consistencies in delivery methods. The best defense against MNKit is to ensure your systems are patched for CVE-2012-0158, but in situations where this isn’t possible, exploit mitigation technology like Traps is warranted.

While attribution is a challenging art, it’s likely whoever is behind these recent attacks is, through infrastructure, malware families and delivery techniques, somehow related to the previously reported attacks. The attackers have been active for years, will likely continue to be active, and seem to prefer to change tactics only subtly.

AutoFocus users can track the malware discussed above using the following tags:

Examined MNKit Samples and Payloads

MNKit MIME attachments carrying LURK0 payloads:

LURK0 payload files contained within MNKit documents:

MNKit MIME attachments carrying Saker payloads:

Saker payload files contained within MNKit documents:

MNKit MIME attachments carrying NetTraveler payloads:

NetTraveler payload files contained within MNKit documents:

[Palo Alto Networks Research Center]

Securing the Industrial Internet of Things with Palo Alto Networks and Honeywell

Last week I had the good fortune to attend the 2016 Honeywell Users Group Americas event in San Antonio, Texas. At this annual event, Honeywell customers from around the world come together to solve common problems in SCADA/ICS and attend keynote speeches and roundtable discussions on topics such as the industrial internet of things (IIoT), cybersecurity, alarm management, and more.

It also served as the first public exhibit of the results of the partnership we announced with Honeywell in February to jointly develop industrial cybersecurity solutions. As described in Honeywell’s keynote address, Honeywell has integrated Palo Alto Networks Next-Generation Firewall technology into their industrial cybersecurity solution, Risk Manager, to provide advanced network traffic inspection. With our next-generation firewall technology, Honeywell’s industrial control customers will have much more insight into who is using which applications on the network, what assets and data they are accessing, and what threats may be trying to breach or pivot around the OT network. With that information, customers can take a more proactive approach to industrial cybersecurity, even protecting their networks from previously unknown attack methodologies.

In addition to our next-generation firewall technology, Honeywell is offering the Palo Alto Networks WildFire WF-500 zero-day, on-premises sandboxing device to augment theirHoneywell Managed Industrial Cyber Security Services offering. Designed to provide cybersecurity consulting services to customers who don’t have the required expertise in-house, the services offering uses WildFire to provide Honeywell’s security experts with the latest threat intelligence in real time.

Ariel Cohen of Palo Alto Networks at the 2016 Honeywell Users Group. The monitor displays a diagram of Honeywell’s industrial cybersecurity reference solution featuring Palo Alto Networks Next-Generation Firewall technology.

If you’d like to learn more about Honeywell’s integration of Palo Alto Networks next-generation security technology, you can download this solution brief.

For more information about cybersecurity and the IIoT, take a moment to read some other blog posts I’ve authored on the subject.

[Palo Alto Networks Research Center]

Former White House CIO Talks Cyber Awareness, Protecting POTUS’s Data, and More

ISACA Now recently sat down with Theresa Payton, Former White House chief information officer (CIO), cybersecurity authority and expert on identity theft and the Internet of Things, for a Q&A on the future of cybersecurity, her days in the White House, and how women (and men) can break into the cybersecurity profession. Payton will present Big Data and the Internet of Things: Boon or Bust for Your Cybersecurity Efforts? in General Session 1 at the 2016 Governance, Risk and Control (GRC) Conference, 22-24 August, Fort Lauderdale, Florida.

ISACA NOW:  With cybersecurity often looking like a chaotic collection of pitched battles between the good guys and the bad guys, do you envision a future where the good guys actually win? If so, how can that happen? If not, how do you envision the future state of cybersecurity? Payton:  As the headlines grow in stature, so does people’s awareness, and that is why I am optimistic about the state of cybersecurity. Now, more than ever, as companies see how unrelenting and crafty hackers can be to get what they want (for example, infiltrating Target via an HVAC vendor) they know it CAN happen to them. Words that were foreign to consumers are now very familiar such as “phishing.” When you learn what these things are, how easily you can be manipulated, then you know not to be complacent because we are sure of one thing:  hackers aren’t going anywhere. It is too lucrative for them.
Knowledge is power!

ISACA NOW:  What was the most challenging cybersecurity-related issue  during your time at the White House? Why?
Payton:  As former White House CIO, my team knew security at the White House came down to people. We knew we had to address the complexity of our systems and technology. We also had to win over the hearts and minds of the staff if we wanted to protect their privacy and security. Our security protocols were meaningless if we made them too difficult for people to do their jobs.

Of course, everything at the White House was considered “critical” and “sensitive” data, but we knew we couldn’t protect every asset the same way. Just as the United States Secret Service has a clear focus:  to physically protect the President and Vice President. We followed that same principle of a clear focus in the CIO’s office.

The CIO’s office was there for protection and to keep all assets safe. However, with a limited time frame and resources, we always had a laser beam focus on the top two most critical assets.

The first example of how we took this approach might remind you of Downton Abbey. Many people may not realize that the Usher’s Office has a long and rich history of providing elegant service, and it follows strict protocols steeped in a rich history. Yet, modern times are evident in the Usher’s office. For example, every chicken breast and every flower stem has to be barcoded. This inventory system enables the White House to know when they need to order more and which budget pays for it. Obviously, we wanted to protect the inventory of food and flowers that came into the White House but those digital assets did not have the same prioritization for protection as the President’s schedule.

ISACA NOW:  You are a woman who has made it to the top of a male-dominated profession. What advice do you have for women who are either just starting out or at the mid-point in a technology career?
Payton:  I have spent my entire career in the field of cyber security. When I stuck my toe into the water, I did not see many women in the field, and today I take heart that this predicament is slowly changing. However, if we were in a race car, now would be the perfect time to step on the gas and go full throttle. We need all hands on deck to defeat our cyber foes and prepare for the future. If you have any inkling to enter this field, here are some tips that helped me along the way:

Volunteer time at FBI InfraGard, which is a partnership between the FBI and the private sector. This is an amazing collaboration between people who represent businesses, academic institutions, state and local law enforcement agencies, all dedicated to sharing information and intelligence to prevent hostile acts against the U.S.

Take online or community college classes to see what you like and dislike about the field. Now that the field of cyber security is growing at such a fast rate, colleges and universities have to catch up. Consequently, they are offering all sorts of classes. To that end, you can also attend a cybersecurity workshop or seminar in your community. Even if you ultimately do not choose this as a career path it surely helps to know the best ways to keep your own data safer!

Talk to people in the field. Find out more about the roles they play and what helped them get started, or even shadow a cybersecurity professional at work. This is what really clinched it for me. The more people I met in the field, the more I knew I wanted to be a part of it. That holds true to this day. The field of cyber security is ever-changing and even more rewarding.

For more on the 2016 GRC and Payton’s appearance, click here.

Theresa Payton, President & CEO, Fortalice Solutions

[ISACA Now Blog]

Tech Docs: Simplify Firewall Management Using Template Stacks

How Do Template Stacks Help Me Manage Firewalls?

Managing how firewalls operate in your network can be complex, especially if their locations and functions affect the settings you configure. Firewalls in one country might communicate with a different DNS server than firewalls in another country. Operations center firewalls might have different administrators than branch office firewalls. At the same time, maybe all your firewalls use the same roles for those administrators. You can simplify management by using a Panorama template to configure the settings that are common to all the firewalls in a particular location or functional group. However, if you have to manage both common and unique settings across many firewall groups, templates would be even more useful if you could modularize and reuse a few (building-block templates) to create many combinations. Template stacks make this not only possible, but easy.

Assigning firewalls to a template stack eliminates the need to configure common settings in each template because the firewalls inherit the settings from all the building-block templates in the stack. You can reduce both the number of templates and the number of settings in each by modularizing: create one template with common settings and function- or location-specific templates with unique settings. This approach is a lot less work than configuring all the common and unique settings in each template for each firewall group.

How Do I Configure a Template Stack?

The following infographic describes how to configure a template stack. The steps are:

  1. Plan the templates and their priority order. If multiple templates have the same settings, the settings in higher priority templates override lower priority templates.
  2. Create the templates.
  3. Create the template stack and assign templates (in the desired priority order) and firewalls to the stack.

(Click to view downloadable PDF.)

For detailed instructions, refer to Configure a Template Stack in the PAN-OS 7.1 Administrator’s Guide.

[Palo Alto Networks Research Center]

Microsoft Azure Closes IaaS Adoption Gap with Amazon AWS

Industry analyst firm Gartner predicts that the infrastructure as a service (IaaS) market will grow 38.4% in 2016 to reach $22.4 billion by the end of the year. A new report from the Cloud Security Alliance (download a free copy here) finds that Microsoft is quickly catching up with industry leader Amazon in the race to tap this growing market. Amazon, Google, and Microsoft collectively own 82.0% of the IaaS market today. Even at companies that have a strict “no cloud” philosophy, IT leaders admit that nearly one fifth of their computing workloads will be in the public cloud this year versus their own data centers.

Amazon remains the dominant IaaS provider but Microsoft is closing their gap in market share. IT professionals at 37.1% of companies indicated that Amazon AWS is the primary IaaS platform at their organization. Microsoft Azure is a close second, at 28.4% followed by Google Cloud Platform at 16.5%. Enterprises using public cloud benefit in many ways including greater agility, lower cost of ownership, and faster time to market. IaaS providers, meanwhile, are also benefitting. In April 2016, Amazon reported that AWS is its most profitable division and is growing 64% annually.

 

IaaS adoption trends
Enterprises are increasingly relying on public cloud infrastructure providers such as Amazon, Microsoft, and Google for their computing resources, rather than managing their own data centers. A plurality of organizations (45.1%) have a “hybrid cloud” philosophy, another 25.1% prefer private cloud, and 21.5% take a predominantly public cloud approach. Just 8.2% of enterprises have a “no cloud” philosophy. Today, 31.2% of an enterprise’s computing resources come from infrastructure as a service (IaaS) providers. IT professionals expect that number to rapidly grow to 41.0% of computing workloads in the next 12 months.

Not surprisingly, companies with a “public cloud” philosophy have more computing in the public cloud. At these companies, nearly one half (47.8%) of computing resides in the public cloud today and IT professionals at these organizations expect a majority of their computing (56.5%) will reside in the public cloud 12 months from now. Even companies with a “no cloud” philosophy estimate that 14.6% of their computing nevertheless resides in the public cloud, and they expect that number will grow to 18.8% in the next 12 months. There is a sizable amount of computing in public cloud IaaS even for organizations that are philosophically opposed to cloud.

There is a clear correlation between company size and IaaS adoption. Companies with fewer employees rely on public IaaS platforms for more of their computing today. Companies with 1-1,000 employees have the largest share of computing workloads in the public cloud (37.1%) versus companies with more than 10,000 employees (22.3%). However, in the next 12 months, companies with more than 10,000 employees are anticipating growing their use of IaaS to 32.9%, which would eclipse companies with 5,000-10,000 employees and would put them roughly on par with companies with just 1,000-5,000 employees. Public IaaS appears to be reaching an inflection point in the enterprise.

Barriers to IaaS projects
Despite the rapid growth of public cloud infrastructure, there are still barriers holding back IaaS adoption. The most common barrier reported by IT professionals is concern about the security of the IaaS platform itself (62.1% of respondents). The next most common roadblock is also security related – 40.5% of respondents indicated that concern about the ability to secure applications deployed on IaaS platforms is a barrier to adoption. The third most common barrier, reported by 37.9% of respondents, is the inability to store data within their country to comply with data privacy laws (e.g. EU General Data Protection Regulation).

Despite concerns, overall confidence in cloud
Despite concerns about security, an overwhelming 61.6% of IT leaders believe that, generally speaking, custom applications they deploy on IaaS platforms are as secure, if not more secure, than applications they deploy in their own datacenter. That may be due in part to the significant investments cloud providers have made in their own security, and in achieving compliance certifications such as ISO 27001 and 27018 to demonstrate their investments. It could also be due to a growing sentiment that cloud companies such as Amazon, Microsoft, and Google can dedicate far more resources to IT security than the average company where IT is not their core business.

Cameron Coles, Director of Product Marketing, Skyhigh Networks

[Cloud Security Alliance Blog]

English
Exit mobile version