Showing posts with label Malware analysis. Show all posts
Showing posts with label Malware analysis. Show all posts

Saturday, May 10, 2014

Did You Know? ... or ... What Is Normal?

We all know that in Windows, explorer.exe (the user shell, graphical file system interface) is the parent process to applications launched by the user, such as Internet Explorer, (iexplore.exe).  That's normal; we all know it, and it looks a little something like this:


That's great and all, but did you know that's not always the case, at least in the matter of iexplore.exe?  Sure, of course you did.  Maybe you haven't thought about it before, but you do know.

What happens when you're on a 64-bit system, and launch the 64-bit version of Internet Explorer?  Did you note the drop-down arrow next to it in the screenshot?  Well, that looks a little something like this:

First, there's the "parent" iexplore.exe (pay no attention to the changing PIDs, please).  Path is "Program Files."  But then the "child" iexplore.exe; path is "Program Files (x86)," indicating this is a 32-bit spawn of (well, you know...) which thus means that the parent is 64-bit.  So, a "new" "normal," then?

   



                  

And of course you realize that if IE is the default browser, and hasn't been launched when you click a link in an email application (such as Outlook), then Outlook will be the parent of IE, rather than Explorer.  Another normal.  You get it.  Here's how that pans out:



So, the user clicks a link in email (outlook.exe), which then spawns the browser (iexplore.exe).  Just as I noted above.  What's cool here is that the command-line parameters (on the right in the screenshot) show where the user was being taken.  Good stuff.

So anyway, the other day I thought I'd do some digging into all the times that Explorer is NOT the parent of IE; partly I wanted to challenge my knowledge, but also to see if I had an opportunity to find any evil, or build query filters that would help separate the signal from the noise for evil in the future.  I ran some queries to find all instances of IE in my environment, where Explorer was NOT the parent process.  There are actually quite a few, you might be surprised.  The predominant ones were:  iexplore.exe, svchost.exe, and outlook.exe.  Okay, we've already discussed the first and last of those, but the middle?  Do what?

First, let's revisit the first one, because this is not the same as above; this is 32-bit on 32-bit action at its tabular best:



Parent process is on the left, child on the right.  Then on the right in the middle, you have the SCODEF and CREDAT references, which indicate an IE tab.  SCODEF points to the PID of the parent.  If you look back up at the ProcessHacker screenshots above, you'll see the parent IE is PID 7760; this is referenced by SCODEF for the child process.  And it's not just me, covered in Cheetos (R) dust, making this stuff up.  Here's a reference (granted, for IE8) from MSDN Blogs. 

SVCHOST!  SVCHOST!  WE WANT SVCHOST!  

Yes, yes, I promised you svchost.exe as a parent to IE.  Now, let's pause for a second and remind ourselves what is normal for svchost.exe, too.  While there may be multiple instances of svchost.exe running at any one time, the parent will always be services.exe.  That's normal, and we all know it.  Okay, remember that.  There is a scenario, which if you've spent some time reviewing the SANS DFIR Find Evil poster you are aware of, wherein IE can be started via the command-line "-embedding" parameter; in this instance, the parent won't be explorer.exe.  Looks like this:



That -embedding switch is over on the right, and as you see on the left, the parent is svchost.exe.  Done, right?  No, not quite yet.  Take a peak at what's next...



What we're looking at here is just a wee bit different.  This isn't so much about IE, although that's come into play, too, but more to the point of svchost.exe, and it's parent.  If you see a parent other than services.exe, you may start getting concerned about malware.  Then you see rpcnet.exe, which sounds legit (ish), but still isn't normal, and you're probably more concerned about malware, since malware often uses names similar to legit names, so as to look "normal."  In addition, this rpcnet.exe is signed, and we all know that signed code is used to bypass detections in antivirus, HIPS, and other products.  So, is this malware?  

Well, opinions might vary, and it certainly behaves like malware.  However, it is - in this instance - normal and legit.  It's actually associated with embedded tracking software to help deal with stolen computer assets.  Of course, while I might "know" that, someone could be trying to get one over on me by masquerading their malware as a process I'd expect to see, so how could I further verify that?  If you know anything about this tracking software, it's not designed to be "normal" and is difficult to validate - it really truly does operate very much like malware.  So I'd most likely have to turn to other sources of evidence, possibly even packet captures, to see where it was going and how it was communicating.  If you want to know more about why validating your findings and being able to do so from multiple types/sources of evidence, come to my talk (To Silo, or Not to Silo: That is the Question) at the SANS DFIR Summit in Austin this June.  

Anyway, the SANS DFIR Find Evil poster talks about knowing what "abnormal" is, but in order to know that, you have to know what "normal" is.  Old story, but that's the same way people are trained to spot counterfeit money - know what "good" money looks like, to be able to spot what's not.  When it comes to normal with computers, and especially in enterprises, there are "global" norms and "environmental" norms.  The globals are things like the 32-bit spawn from the 64-bit parent IE, the SCODEF references for child tabs (which includes the home page, by the way), and Outlook links spawning instances of IE to reach the websites.  Environmentals aren't out to save the computer, but are things like tracking software sitting in between services.exe and svchost.exe.  If you know what those are for your world, you'll be much better off when it comes to finding evil, and separating the signal from the noise.

Happy Hunting!

Monday, December 16, 2013

What's Hash Got To Do With It? (Part 2)


Just a quick follow-up to yesterday's post, as promised.  I decided to do it as a new post rather than an edit/update, figuring it would be easier to track this way.  Not much to it, just a little more info to round things out.

First, I got my hands on the infected PC today, pulled the hard drive, and extracted some files.  I wasn't able get RAM, but I do have hiberfil and pagefile to work with, along with the user profile and registry hives, but that's not the point here.  (I will note, however, that unless I can find evidence of the malware's activities in hiberfil or pagefile, I'm still - to an extent - surmising how it spawned msiexec.exe in the first place.)  I found three separate executables under the user profile, as created by msiexec.exe.  I copied them off into a separate directory and used md5deep to hash the files, so that I could look for them on VT or Malwr.com as well (there, now this is a post about md5deep too!).  Here's what I ended up with (my own formatting):

26e57bde90b43cf6dae6fd5731954c61 | msevaxlgn.exe  
26e57bde90b43cf6dae6fd5731954c61 | mssuhin.exe
26e57bde90b43cf6dae6fd5731954c61 | msyaam.exe

Did you notice that?  All hashed the same.  Okay, maybe that's expected, or not too unexpected at least.  But did anyone note the hash value from yesterday, for the initial executable (from inside the zip)?  Well, in case not, here it is again (in the same format):

26e57bde90b43cf6dae6fd5731954c61 | order_jd4320480293.exe

See that?  Yes, that's right - another md5 match, and I doubt it's due to collisions.  :-)  So basically, the original malware spawns msiexec.exe, creates a new executable(s) that is (or are) identical to the original (except for the name); the original is deleted, and the show goes on.  I don't know about you, but that's not what I commonly see from malware.

Now for a few more tidbits...

A little header info from a network capture:
POST /se/gate.php HTTP/1.1
Cache-Control: no-cache
Connection: close
Pragma: no-cache
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/4.0
Content-Length: 74
Host: finley.su

IP Addresses, as seen by the C2 blocking device:


Now, I mentioned before that there was a .ru TLD involved, and here that is:



Haven't looked at that traffic yet, and it never made it to the device that blocked the C2 traffic, as it had already been blocked for other reasons.  And of course, until I examine the pcaps, I won't know what that traffic was (still might not - since it was blocked, it will be a one-side conversation).

Last of all, a screenshot of the offending email (note some inconsistencies outlined in red):


SupportAmazonyu?  AmazonStoreIdecoa?  I could get it with "Amazon," but what's with the other stuff?  And the order numbers don't match up anywhere.  And finally, it says, "Well let ..." rather than "We'll let ..."

Well, I guess you can't patch users!  At least not without regression testing first.  ;-)

I think that's it for now; if I do come up with anything else that looks interesting or useful, I'll post another update.  Aside from that, I told a friend I'd post about some specific uses for md5deep; we'll see how that works out, but hopefully it will be coming soon.

Happy Hunting!


Sunday, December 15, 2013

What's Hash Got To Do With It?

Well, because that's how we're going to kick off this little story.  Without further ado, here ya go:  26E57BDE90B43CF6DAE6FD5731954C61

Before we go too far into that, however, I need to take a step back.  It's been a long time since my last post.  Too long indeed (my job makes it difficult, to say the least), so let's not dwell on that, shall we?  With that out of the way, I'll give just a quick back story on the above-referenced md5 hash value.  Last week, on Wednesday and Thursday, I came across this malicious gem.  Well, I think it was the same both times.  From a network perspective, it was behaving the same - reaching out to the same C2 channels, attempting to post the same type of encrypted data (based on format, appearance of cipher-text, etc.).  However, as it turns out there wasn't an appropriate endpoint sensor on the first box, to be able to pull back more relevant info.

That fact is important as we go on - that unless you have evidence across different DFIR disciplines (host and network, with all their subsets), you really can't say for certain what is occurring.  You can postulate, and may very well be correct, but without RAM, RE, timeline and other host data, and various points of NSM (network security monitoring) such as FW logs, IDS/IPS, netflow, you're left at least somewhat in the dark.  Anyhow, from a network perspective, these two appeared to be the same, and fortunately there was an endpoint sensor on the second box; I got to have some fun, and thought I'd share.

As it turns out, the infections originated not from some stealthy drive-by or infected website, but via an executable inside a zip file sent along with an "Amazon" email to personal email accounts.  In the case of the second one, the user had received two previous ones that were ignored and deleted; the third was just too much and curiosity won out.  User opens zip file.  Oops #1.  User double-clicks executable.  Oops #2.  At that point it's all over but the tears, and the malware has its fun.  The positive side was that - finally - I got to have some fun too!

Now, I didn't know all that at first.  All I knew was that C2 traffic to finley.su had been blocked.  That was the same domain as the previous day, so my interest was piqued.  The system that blocked didn't have any info about the malware, just knew that the traffic was bad, so that was no help.  I went in to my sensor logs from that box, and found the application reaching out to finley.su was msiexec.exe, from the c:\windows\system32 directory.  Ooh, now that's not right.  The parent process for msiexec.exe was order_jd4320480293.exe.  Now that's not good either.  And it was running from inside a zip under the user's temp directory, with a parent of explorer.exe.  Alright, that's not unexpected, especially at this point.

I was able to pull a copy of the binary for order_jd4320480293.exe that the sensor had pushed to my analysis server, and saw that it had 9 hits by hash on Virus Total, so I went to check that out.  There were indeed 9 engines that detected it; one from the 11th, and eight from the 12th.  Most had generic names as yet; the most relevant one appeared to be from McAfee, which had it as a ZBot variant.  Searching on that lead me to Malwr.com, where the binary had apparently been uploaded and analyzed already.  As a side note, the next morning VT had 14 detections, and is now up to 23 (What's funny is that some of the vendors I submitted a sample to, now say they detected it back then.  Hmm, really?).  Since there's some RE type info on VT and Malwr, I won't try to go into that; I'll give you some reference links to go enjoy that.  I will, however, give a quick rundown of what I saw.  I will probably come back and add some IP addresses for the finley.su domain, as well as a .ru TLD I saw from the endpoint, so watch for an update.

So here's the quick high-level rundown:
*  User downloads zip from fake Amazon email, opens, and runs order_jd4320480293.exe
*  Malware executes, and order_jd4320480293.exe spawns (loads) msiexec.exe from c:\windows\system32 as a child process 
*  Child process msiexec.exe creates a new executable under the user profile, named (one example) msyaam.exe or msevaxlgn.exe (another example)
*  Child process msiexec.exe adds a runkey for the new executable, in the user hive, under Software\Microsoft\WindowsNT\Current Version\Load
*  Child process msiexec.exe deletes original executable, order_jd4320480293.exe

Along in there somewhere, msiexec.exe packages up some data (probably credentials), encrypts, and tries to ship it out to remote servers.  Unsuccessfully.  Defense in depth... ;-)

Well, that's it for now.  Given the info available elsewhere about this malware, I probably won't post anything about its actions on the system, unless I see a very different  approach take place.  But I will look to post some IPs and perhaps some other tidbits that might be helpful from an IOC perspective.  Other than that, here are some links:


Happy Hunting!