This is the Gozi IFSB malware,
created to steal data & informations from the victims. In the folder
you will see all the files needed to create your own malware server.
For this malware analysis I will use an .bin
found after google search. With this .bin file I will be 2 steps closer
for the analysis. I don’t have the .doc/.pdf file with the payload, but the
.bin is the downloaded file resulted from the payload.
I will transform the .bin file to
infected.exe(10000.exe)!
008c4bd6ee834d113cfc693af0ea90396eaa47e860bcdd567ffd964b57434e1d.bin
MD5: e6d118192fc848797e15dc0600834783
SHA1: 16d5ded68677f4a870423d3fd30da8377a5b2408
Let’s go to security manipulation and creation
of the malware on the system. The $LN33 it is exported by the executable, after
that will jump to C Runtime Library.
Calling the security_init_cookie for buffer overrun protection to comprommise the system security. Let’s run the infected file to see his actions!
I see that the explorer.exe has some activiti. Cyber security – Malware analysisThere I have some movements… let’s go to
\Roaming\MIcrosoft\ to see the new folder created ‘BthM300C’. An executable(the same .exe with diffrerent
name) created in new folder after runed the infected.exe / D3DCsapi.exe aka
1000.exe The Registry. Prodefence SRLNow… the explorer.exe.
24 .dll are suspicious.
That means some of them are from the injection
process. explorer.exe (2304) – 52074 – 166.124.148.146.bc.googleusercontent.com.
This is an Google Cloud Platform and the
explorer.exe has some connections there. genesisgrandergh.at
Network traffic: In the same way it is using the /POST request for sending stealed data, when the victim visits some bank account, paypal…etc. Botnet host directory and login page:
H**p://xxx.xxx/adminpanel/admin.php
The remove is easy. You just have to follow the path’s to find the droped executables and delete the created registers.
A massive Botnet is forming to create a cyber-storm that could take down the internet.
An estimated million organizations have already been infected.
The Botnet is recruiting IoT devices such as IP Wireless Cameras to carry out the attack.
New
cyber-storm clouds are gathering. Check Point Researchers have
discovered of a brand new Botnet evolving and recruiting IoT devices at a
far greater pace and with more potential damage than the Mirai botnet
of 2016.
IoT Botnets are Internet connected smart devices which
have been infected by the same malware and are controlled by a threat
actor from a remote location. They have been behind some of the most
damaging cyberattacks against organizations worldwide, including
hospitals, national transport links, communication companies and
political movements.
While some technical aspects lead us to
suspect a possible connection to Mirai, this is an entirely new and far
more sophisticated campaign that is rapidly spreading worldwide. It is
too early to guess the intentions of the threat actors behind it, but
with previous Botnet DDoS attacks essentially taking down the Internet,
it is vital that organizations make proper preparations and defense
mechanisms are put in place before an attack strikes.
Ominous
signs were first picked up via Check Point’s Intrusion Prevention System
(IPS) in the last few days of September. An increasing number of
attempts were being made by hackers to exploit a combination of
vulnerabilities found in various IoT devices.
With each passing
day the malware was evolving to exploit an increasing number of
vulnerabilities in Wireless IP Camera devices such as GoAhead, D-Link,
TP-Link, AVTECH, NETGEAR, MikroTik, Linksys, Synology and others. It
soon became apparent that the attempted attacks were coming from many
different sources and a variety of IoT devices, meaning the attack was
being spread by the IoT devices themselves.
So
far we estimate over a million organizations have already been affected
worldwide, including the US, Australia and everywhere in between, and
the number is only increasing.
Our research suggests we are now
experiencing the calm before an even more powerful storm. The next cyber
hurricane is about to come.
For deeper analysis on the rise of this new IoT Botnet, please see the full research publication on our Research Blog.