Rewterz Threat Advisory – CVE-2018-16871 – Linux Kernel “nfsd4_verify_copy()” Vulnerability
June 3, 2019Rewterz Threat Alert – GoldBrute Botnet Brute Forcing 1.5 Million RDP Servers
June 10, 2019Rewterz Threat Advisory – CVE-2018-16871 – Linux Kernel “nfsd4_verify_copy()” Vulnerability
June 3, 2019Rewterz Threat Alert – GoldBrute Botnet Brute Forcing 1.5 Million RDP Servers
June 10, 2019Severity
Medium
Analysis Summary
A new malware family they have labeled “BlackSquid”. This malware targets web servers, network drives, and removable drives. For defense, BlackSquid employs anti-virtualization, anti-debugging, and anti-sandboxing methods, and will abort its installation if it determines it is being examined. Usernames are checked against a list of common sandbox usernames, diskdrive model names are compared to common virtual drive names, and the device driver names are also compared against a list of common names to determine if the infection should continue or not. For offense, it utilizes eight exploits, including EternalBlue and DoublePulsar, as well as dictionary attacks to gain access to its target. Once installed, it has the ability to propagate laterally within the network.
Vulnerabilities Exploited
CVE-2014-6287
CVE-2014-6287
CVE-2017-8464
CVE-2017-12615
CVE-2017-0146
CVE-2017-0145
CVE-2017-0144
Impact
Exposure of sensitive information
Indicators of Compromise
URLs
- http[:]//m9f[.]oss-cn-beijing[.]aliyuncs[.]com/A[.]exe
- http[:]//m9f[.]oss-cn-beijing[.]aliyuncs.com/Black[.]hta
Malware Hash (MD5/SHA1/SH256)
- 14f8dc79113b6a2d3f378d2046dbc4a9a7c605ce24cfa5ef9f4e8f5406cfd84d
- 3596e8fa5e19e860a2029fa4ab7a4f95fadf073feb88e4f82b19a093e1e2737c
- 515caf6b7ff41322099f4c3e3d4846a65768b7f4b3166274afc47cb301eeda98
- 8974da4d200f3ca11aa0bc800f23d7a2be9a3e4e6311221888740c812d489116
- 8dbd331784e620bb0ca33b8515ca9df9a7a049057b39a2da5242323943d730b4
- aa259b168ec448349e91a9d560569bdb6fabd811d78888c6080065a549f60cb0
Remediation
- Block threat indicators at your respective controls.
- Make sure all vulnerable devices are up-to-date and patched against these vulnerabilities.