Showing posts with label Mpack. Show all posts
Showing posts with label Mpack. Show all posts

RBN – Google Search Exploits

The Russian Business Network (RBN) has been busy again with a significant amount of loaded web search results which lead to malware sites as reported by Sunbelt.


The good news first is being able to precisely pin point the exploiters back to newer RBN core retail centers as previously exposed in this blog on Nov 8th 07 – i.e. iFramecash, myrdns, hostfresh, and AS 27595 i.e. Atrivo, Intercage, Inhoster. Also as reported this is the same end route as the Bank of India hack, fake anti-spywares and fake codecs.


The bad news is, as predicted and one of the probable reasons for dropping their RBnetwork IP ranges , the RBN is increasingly using botnet based fast-flux techniques (see Wikipedia) to hide the initial delivery sites behind an ever-changing network of compromised hosts i.e. "double-flux" nodes within the network registering and de-registering their addresses as part of the DNS SOA (start of authority) record list for the DNS (domain name server). This provides an additional layer of redundancy and survivability within the malware network as seen in the case of the fake codecs.


This particular web search exploit for the unfortunate end user can be shown as:




From investigation into the actual Trojan downloads this shows the use of the newer undistributed till now edition of MPack which includes a host of exploits including the scam.Iwin, keyloggers, DNS changers, etc. Despite the difficulty of tracking botnet fast-flux usage by detailed investigation of the specific domain name servers the details are as follows, with this information Google and other search engines should easily eliminate such a threat, and hopefully provides law enforcement with further evidence:



1 – The web search “fake” sites.


All researched in this exploit all these fake web search sites emanate from 2dayhost.com an apparent botnet based at AS8001 Net Access Corporation 1719 Route 10 Suite 318 Parsippany, NJ 07054. In the following sample of the domains and name servers involved at this stage: feidqaadppta.cn - igekqzeabkwz.cn - luewusxrijke.cn - zhvmizyycuzz.cn All were registered very recently on Nov 25th 2007 under Name Server: ns1.erik-kartman2.com and Name Server: ns2.erik-kartman2.com – also based at 2dayhost.com / AS8001 Net Access Corporation (please note despite the .cn the domains and registrant have nothing to do with China).


Figure2 – Fake search site map



2 – Victim Reception sites.

As mentioned earlier the “usual suspects” of iFramecash, myrdns, hostfresh, and AS 27595 i.e. Atrivo, Intercage, Inhoster, are responsible. The following 3 figures show the relationship (click on the pic to see full size):



Figure 3. Victim reception A




Figure 4. Victim reception B



Figure 5. Victim reception C

RBN – Russian Business Network, Chinese Web Space and Misdirection

There has been recent speculation concerning the Russian Business Network (RBN) and its increasing use of Chinese web space. By way of discussing this topic it is useful to quantitatively view this aspect via a practical example. We can kill 2 birds with one stone and do this via a requested update on “iFrame Cash”.

The iFrame Cash is an active RBN enterprise we call here part of the RBN “Retail Division”. Simply the RBN pays webmasters or small web hosts a commission for planting or injecting IFrame exploits on web sites, this is done via the web site iframedollars.com and others.

Iframedollars has recently changed its IP location as it has done regularly since 2004, joining the dots (NB. Click on the images to see the detail):


1. iframedollars.com

= 58.65.234.17, ns1.iframedollars.com = 58.65.234.17, ns2.iframedollars.com = 58.65.234.18, MX iframedollars.com (mail server) = 58.65.234.17

58.65.234.0/24 = HOSTFRESH Internet Service Provider Pacific Internet (Hong Kong) Limited (Customer Route) REACH (Customer Route) = China?



2. myrdns.com / hostfresh.com

ns1.hostfresh.com = 58.65.238.100, ns2.hostfresh.com = 58.65.238.101

For, myrns.com sharing IP records = us1core.hostfresh.com, jishuqi.cn, shippingnv.com



3. For us1core.hostfresh.com


4. AS27595 = Intercage






So at this time:


(A) iFrame dollars facts ;
Host = Hostfresh, ICANN registrar = Estdomains, IP address changes = 14 (2 years), Who is records = 44 (since 2004). Alexa rank = #605,524 up 62,752 in the last 3 months

(B) Hostfresh facts ;
Host = Myrdns, ICANN registrar – IP address changes = 5 (2 years), Who is records = 233 (since 2004). Alexa rank = # 361,013 up 387,6323 in the last 3 months


(C) Intercage facts:
As reported earlier Intercage = AKA; Inhoster (xbox.dedi.inhoster.com - Ukraine), Atrivo (US), Estdomains, (Note: also interestingly Broadwing Communications a backbone internet operation now owned by Level 3 Communications, Inc - NASDAQ: LVLT- appears to be the core mail carrier and mirrored hosting for AS 27595). This hosts or acts as a name server for at least 34 of the 40 RBN fakes.


(D) IMPORTANT NOTE;
58.65.239.66 was also one of the 2 domains involved in the Bank of India hack.


In conclusion; 58.65.232.0 - 58.65.239.255 = HOSTFRESH = Hong Kong (PRC) / China?

This is Intercage again, to restate, many forum and other Internet user complaints dating back to 2004, and blacklisted by Spamhaus. However such blacklists are predominately used to block access “from” e.g. spam, we need a CYBERINT system to prevent access to. Currently only systems such as McAfee’s Site Advisor provide a web users guide and this is not perfect.




Also hopefully this example demonstrates that when watching the RBN because an IP address shows a Hong Kong / Chinese / Russian registrant or has Chinese or Russian writing does not mean it is actually based and hosted there.



Simple observation, just assume anything associated with the RBN is based on misdirection in the first place.

RBN - The Good, Bad and the Ugly


An interesting story in Wired.com by Ryan Singel, based on email correspondence from a representative claiming to be from the Russian Business Network (RBN). As reported, the RBN's man said current reports about the organization “..... is subjective opinion based on guesswork." In keeping with this blog's "quantitative" format we make an attempt to shed some light on this.



Figure 1. Shows a representation of the RBN from the perspective of web infrastructure, it provides three levels of operation:


1. “Good” & "Bad" - RBN Autonomous System (AS) – backbone internet structure (see diagram 2)


2. “Bad” - RBN Global – Core server hosting operations, e.g. RU, UA, BR, DE (Denic.de, crew-gmbh.de), CH (rbnetwork.biz), IT, NL, Panama, UK (Too coin via – Ripe representation – sbttel), Seychelles.


3. “Ugly” - RBN Retail –Specific exploit, ID theft, MPack. e.g. iFrameCash, 76Service.


For the purpose of the Wired.com article there needs to be focus on the RBN Autonomous System – Figure 2.




The problem is the RBN's Autonomous System is integrated within the whole of the Russian , Eastern European, and Eastern Scandinavian internet system overall. For example three of the following:

  • AS41181 RUSTELECOM, = AS4589 EASYNET, AS20597 ELTEL (general internet for Russia as a whole)
  • AS34596 CONNECTCOM ConnectCom Ltd Autonomous System, – included within are # AS8426(CLARANET AS ClaraNET UK AS of European ISP)# AS20597(ELTEL AS ELTEL net Autonomous System) any # AS34596 & # AS24919(CUBIO AS Cubio Communications Ltd Helsinki Finland)
  • AS39848 DELTASYS Delta Systems network – included within # AS20597(ELTEL AS ELTEL net Autonomous System) any AS39848, # AS24919(CUBIO AS Cubio Communications Ltd Helsinki Finland)


Although they are in the RBN Autonomous System they are within other Autonomous Systems. These should be discounted from the RBN "bad" or "ugly" groups.

Therefore, CONNECTCOM’s spokesman to Wired.com is either:

(a) Another innocent caught in the bad and ugly RBN’s maelstrom, they may actually own the RBN, but not the one we know.

(b) A RBN (bad or ugly) stooge trying to misdirect

As with earlier posts here, re; RBN hiding within US hosts, we have to recognize the RBN does the same in Russia and elsewhere. The requirement is to focus on the RBN "ugly" Retail Division. The specific source for website exploits, ID theft, etc.


RBN - MPack

MPack is the latest and greatest tool for sale on the Russian Underground. $ash sells MPack for around $500-1,000. In a recent posting $ash attempted to sell a "loader" for $300 and a kit for $1,000. The author claims that attacks are 45-50 percent successful, including the animated cursor exploit and many others, including ANI overflow, MS06-014, MS06-006, MS06-044, XML Overflow, WebViewFolderIcon Overflow, WinZip ActiveX Overflow, QuickTime Overflow (all these are $ash names for exploits). Attacks from MPack , aka WebAttacker II, date back to October 2006 and account for roughly 10 percent of web based exploitation today according to one public source.


More than 10,000 referral domains exist in a recent MPack attack, largely successful MPack attack in Italy, compromising at least 80,000 unique IP addresses. It is likely that cPanel exploitation took place on host provider leading to injected iFrames on domains hosted on the server. When a legitimate page with a hostile iFrame is loaded the tool silently redirects the victim in an iFrame to an exploit page crafted by MPack. This exploit page, in a very controlled manner, executes exploits until exploitation is successful, and then installs malicious code of the attacker's choice.


Torpig is one of the known payloads for MPack attacks to date. This code relates back to the Russian Business Network (RBN), through which many Internet-based attacks take place today. The RBN is a virtual safe house for attacks out of Saint Petersburg, Russia, responsible for Torpig and other malicious code attacks, phishing attacks, child pornography and other illicit operations. The Italian hosts responsible for most of the domains seen in a recent MPack attack are using cPanel, a Web administration tool for clients. A zero-day cPanel attack took place in the fall of 2006 leading up to the large scale vector mark-up language (VML) attacks at that time. It appears likely that the Russian authors of the cPanel exploit, Step57.info, who are also related to the RBN used the exploit to compromise the Italian ISP and referral domains used in the latest mPack attack.


MPack uses a command and control website interface for reporting of MPack success. A JPEG screenshot of a recent attack is attached to this message.


QUOTES


1. MPack is a powerful Web exploitation tool that claims about 50 percent success in attacks silently launched against Web browsers.


2. $ash is the primary Russian actor attempting to sell mPack on the underground, for about $1,000 for the complete MPack kit.


3. MPack leverages multiple exploits, in a very controlled manner, to compromise vulnerable computers. Exploits range from the recent animated cursor (ANI) to QuickTime exploitation. The latest version of mPack, .90, includes the following exploits:

MS06-014
MS06-006
MS06-044
MS06-071
MS06-057
WinZip ActiveX overflow
QuickTime overflow
MS07-017


4. The Russian Business Network (RBN) is one of the most notorious criminal groups on the Internet today. A recent MPack attack installed Torpig malicious code hosted on an RBN server. RBN is closely tied to multiple attacks including Step57.info cPanel exploitation, VML, phishing, child pornography, Torpig, Rustock, and many other criminal attacks to date. Nothing good ever comes out of the Russian Business Network net block.


5. MPack attacks experience high success, according to attack log files analyzed by VeriSign-iDefense. In just a few hours more than 2,000 new victims reported to an MPack command and control website. A recent attack, largely focused in the area of Italy, involved more than 80,000 unique IPs.