Home > ParetoLogic Blogs > Malware Diaries > Exploits 4free
Reply
 
Thread Tools Display Modes
  #1  
Old 06-10-2009, 10:20 PM
Michael Michael is offline
Administrator
Join Date: May 2007
Posts: 313
Default Exploits 4free

Today I was looking at an interesting website and a drive-by-download associated to it.

pic

The file is not a JPG... in fact it is an exploit script. I detail what it does in the diagram below:

fakelogo

The hacker has left its Apache/2.2.9 PHP/5.2.6 Server wide open! The IP is located in Hong Kong China and actually hosts two different domains (that are mirrors of each other).

Because the server is not protected, you can easily browse through its file repository and find all the exploit code in there. If you check the date, these exploits are fairly recent.

exploit0

There is a nice PHP management page, called PHPSpy that allows you to update your exploits:

exploit333

I downloaded all the files in that repository for a closer look.

Amongst them, an AVI file that exploits a vulnerability in Explorer. In my case it just crashed it and did nothing else. The exploit happens when you select the file and it tries to display its properties in the details pane.

exploit1

DLL files compiled in C# that bear no doubt as to what their intent is (exploit Shellcode):

exploit9

Heavily obfuscated html pages loaded with exploits:

exploit6

Following the PHPSpy link  lead me to the Security Angel's website (in Chinese).

A quick translation reveals (more or less) what it's all about:

phpspy

The "Security Angel team" has more exploits for grab:

exploit5

It also has some tutorials and scripts for the newbies, such as this 'man in the middle' attack perl script:

exploit4

man1

I decided to analyze the main executable that these exploits push. It creates a service as well as injects a DLL file into System32.

exploit8

A VirusTotal scan... the sample is detected but the descriptions are vague.

exploit7

Security researchers interested in the actual location of the exploit server can contact me.

Jerome Segura
Reply With Quote
Reply

« Previous Thread | Next Thread »

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


Terms of Use