June 10, 2019
Anomali Threat Research

Weekly Threat Briefing: Magecart Skimmers Found on Amazon CloudFront CDN

<div id="weekly"><p id="intro">The intelligence in this week’s iteration discuss the following threats: <strong>Botnet, Data breach, Misconfigurations, Ransomware, Threat groups,</strong> and <strong>Vulnerabilities</strong>. Morphus Labs announced the discovery of a new brute force campaign against 1.5 million Remote Desktop Protocol (RDP) servers by a botnet called "GoldBrute." The campaign targets the problem of RDP servers left exposed to the Internet by the BlueKeep vulnerability (CVE-2019-0708) in Windows XP and 7's Remote Desktop Services (RDS) which use RDP. According to Morphus, 1,596,571 servers have been subjected to an attempted brute-force attacks targeting RDP accounts. While limiting the number of times a password can be guessed is a vital practice, "GoldBrute" is trying to fly under the radar by limiting itself to one attempt per compromised host.
MITRE ATT&CK: [MITRE ATT&CK] Brute Force (T1110) | [MITRE ATT&CK] Remote Desktop Protocol (T1076) Hosted JavaScirpt libraries within the Contect Delivery Network (CDN) were tampered with and injected with web skimmers. Upon analyzing the breaches, it was found that they were a continuation of a campaign from Magecart threat actors attempting to affect a large number of web properties at once. The sites identified had nothing in common other than the fact that they were all using their own custom CDN to load libraries. The victims identified in this campaign were contacted by Malwarebytes, and some have remediated the breach. Additionally, abuse reports were filed directly with Amazon. According to researchers at Tenable, no exploits have been seen in the wild, though they expect at least proof-of-concept exploits to appear in the near future. A patch has since been released for the vulnerability. According to vpnMentor researchers, a log management server was leaking system-wide information, exposing "payment information, PII, and full company and account details for end-users and MSPs." Client API keys, bank and payment information, and usernames and unencrypted passwords were exposed, as well as employee Personally Identifiable Information, including full names, phone numbers, and physical addresses. The exposed database was discovered on June 2, 2019 and was fixed within 48 hours. The malicious campaign is attempting to exploit vulnerabilities via Internet Explorer. If successful, a series of commands would download the ransomware and then execute it. Exploit Kit researcher nao_sec spotted a malvertising campaign redirecting users to the RIG exploit kit, which then drops the Buran ransomware as a payload. Being a new variant of VegaLocker ransomware, Buran ransomware uses a similar encryption process. While there is no known way to decrypt this ransomware for free as of yet, it is currently being researched.
MITRE ATT&CK: [MITRE ATT&CK] User Execution (T1204) | [MITRE ATT&CK] Exploitation for Client Execution (T1203) According to FireEye researchers, upon successful infection, HAWKBALL offers the attackers a range of malicious capabilities, including creating, deleting, and uploading files, delivering additional payloads,and surveying the host to collect victim information. To deliver the backdoor, attackers send a malicious document claiming to be from an anti-terrorist organization. The file uses an OLE object "that uses Equation Editor to drop the embedded shellcode in %TEMP%" and exploits two Microsoft Office vulnerabilities, "CVE-2017-11882" and "CVE-2018-0802" to infect a target machine. HAWKBALL communicates with a hard-coded C2 server over HTTP to exfiltrate the victim's information, to include computer name, IP address, OS version, and user name, and performs actions to check if it is being debugged.
MITRE ATT&CK: [MITRE ATT&CK] User Execution (T1204) | [MITRE ATT&CK] Spearphishing Attachment (T1193) | [MITRE ATT&CK] System Information Discovery (T1082) | [MITRE ATT&CK] Data Encrypted (T1022) | [MITRE ATT&CK] File Deletion (T1107) | [MITRE ATT&CK] Obfuscated Files or Information (T1027) | [MITRE ATT&CK] Exploitation for Client Execution (T1203) | [MITRE ATT&CK] Exfiltration Over Alternative Protocol (T1048) The campaign was named "Frankenstein," referring to the actor's ability to piece together and leverage four different open-source techniques to build the malicious tools. The campaign used components of an article to detect when a sample is being run in a VM, leverages MSbuild to execute a PowerShell command, uses "Fruityc2" to build a stager, and utilizes the GitHub project "PowerShell Empire" for their agents. As the Cisco Talos research team concluded, the use of open source and publicly available components for building the tools allowed the threat actors to avoid standing out, making it difficult for experts to attribute attacks to a particular actor.
MITRE ATT&CK: [MITRE ATT&CK] User Execution (T1204) | [MITRE ATT&CK] Scripting (T1064) | [MITRE ATT&CK] PowerShell (T1086) | [MITRE ATT&CK] Obfuscated Files or Information (T1027) | [MITRE ATT&CK] Scheduled Task (T1053) | [MITRE ATT&CK] Windows Management Instrumentation (T1047) | [MITRE ATT&CK] Custom Command and Control Protocol (T1094) | [MITRE ATT&CK] Exfiltration Over Alternative Protocol (T1048) The misconfigured ElasticSearch server contained over 1.6 million individual donor records, and was left unprotected on the Internet without a password. The records contained personal information, such as birth dates, full names and addresses, phone numbers, and wealth information and status. At the time of this writing, the exposed server has been taken down. According to the official statement made by University of Chicago Medicine, the university is conducting a forensic investigation, "...and have determined that no unauthorized parties – beyond this security researcher – accessed the information in the database." Student academic records were accessed, as well as information provided to the university for administrative purposes. This additional information may include addresses, bank account details, dates of birth, emergency contact details, names, passport details, payroll information, personal email addresses, phone numbers, and tax file numbers. The university's Vice Chancellor Brian Schmidt stated that systems involving research work were not impacted in the breach. At this stage of the investigation, the university has not been able to attribute the attack to any known actor, and have referred the data breach to the Australian authorities. The billings collection service provider, American Medical Collection Agency (AMCA), informed Quest Diagnostics that an unauthorized user had access to AMCA systems containing personal information received from Quest. The SEC filing filed by Quest Diagnostics reveals that the attackers had access to the AMCA's system between August 1, 2018 and March 30, 2019. An AMCA spokesperson said that they have taken down their web payments page and are investigating the security breach with the help of a third-party forensics firm. Quest Diagnostics have suspended sending collection requests to AMCA for the moment. BlackSquid is named after its registries and component file names and uses some of the most notorious exploits today including: EternalBlue; DoublePulsar (the exploits for CVE-2014-6287, CVE-2017-12615, and CVE-2017-8464), and three ThinkPHP exploits for multiple versions. If successful, this malware may enable an attacker to escalate unauthorized access and privileges, launch attacks on an organization, render hardware and software useless, or steal proprietary information. However, all of the exploited vulnerabilities have patches that have been available for years, so organizations following updated and proper patching procedures are unlikely to be affected.
MITRE ATT&CK: [MITRE ATT&CK] Data from Network Shared Drive (T1039) | [MITRE ATT&CK] Scripting (T1064) | [MITRE ATT&CK] Exploitation for Privilege Escalation (T1068) | [MITRE ATT&CK] Exploitation for Client Execution (T1203) | [MITRE ATT&CK] Exfiltration Over Alternative Protocol (T1048) OilRig, also known as APT34 and HelixKitten, is a group linked to the Iranian government. The tool is called "Jason" and is not detected by antivirus engines on VirusTotal, at the time of this writing. The tool works by trying various email account passwords until it finds the correct one. The brute-force activity is aided by a list with password samples and four text files containing numerical patterns. This utility is the seventh tool associated with the OilRig group that has been made publicly available. As of this writing, it is unknown who is responsible for exposing some of the APT group's malware and tools, it is possible it was done so in hopes that publishing the tools will be a disruption to future operations by the threat group.
MITRE ATT&CK: [MITRE ATT&CK] Brute Force (T1110)
Observed Threats
This section includes the top threats observed from the Anomali Community user base as well as sensors deployed by Anomali Labs. OilRig
The Advanced Persistent Threat (APT) group "OilRig" is believed to be an Iranian-based group that has been active since at least 2014. OilRig conducts cyber espionage operations focused on reconnaissance that benefits Iranian nation-state interests. OilRig uses a mix of public and custom tools to primarily target entities located in the Middle East.
MageCart Timeline of Malicious Activity
MageCart is a particularly interesting threat group because of the sheer amount of sites, approximately 100,000, they have either compromised or successfully skimmed card credentials from since being first identified in 2015. The name MageCart refers to multiple groups, according to RiskIQ. It appears that MageCart is a collective term used to track payment information-stealing activity from at least 12 separate groups. Researchers also point out that Group 9 was interfering Group 3's skimmer by manipulating the last credit or debit card number, which appears to indicate that MageCart is indeed an umbrella term used to track malicious activity. It may be difficult for individuals to determine separate groups because some of the groups use similar and common data-stealing methods, however, RiskIQ does note their methodology in their joint paper with Flashpoint on how they identify the different groups.[1]

