Rewterz
Rewterz Threat Advisory – CVE-2018-16871 – Linux Kernel “nfsd4_verify_copy()” Vulnerability
June 3, 2019
Rewterz
Rewterz Threat Alert – GoldBrute Botnet Brute Forcing 1.5 Million RDP Servers
June 10, 2019

Rewterz Threat Alert – Eight Exploits Used in BlackSquid Attacks

Severity

Medium

Analysis Summary

A new malware family they have labeled “BlackSquid”. This malware targets web servers, network drives, and removable drives. For defense, BlackSquid employs anti-virtualization, anti-debugging, and anti-sandboxing methods, and will abort its installation if it determines it is being examined. Usernames are checked against a list of common sandbox usernames, diskdrive model names are compared to common virtual drive names, and the device driver names are also compared against a list of common names to determine if the infection should continue or not. For offense, it utilizes eight exploits, including EternalBlue and DoublePulsar, as well as dictionary attacks to gain access to its target. Once installed, it has the ability to propagate laterally within the network.

Vulnerabilities Exploited

CVE-2014-6287

CVE-2014-6287

CVE-2017-8464

CVE-2017-12615

CVE-2017-0146

CVE-2017-0145

CVE-2017-0144

Impact

Exposure of sensitive information

Indicators of Compromise

URLs

  • http[:]//m9f[.]oss-cn-beijing[.]aliyuncs[.]com/A[.]exe
  • http[:]//m9f[.]oss-cn-beijing[.]aliyuncs.com/Black[.]hta

Malware Hash (MD5/SHA1/SH256)

  • 14f8dc79113b6a2d3f378d2046dbc4a9a7c605ce24cfa5ef9f4e8f5406cfd84d
  • 3596e8fa5e19e860a2029fa4ab7a4f95fadf073feb88e4f82b19a093e1e2737c
  • 515caf6b7ff41322099f4c3e3d4846a65768b7f4b3166274afc47cb301eeda98
  • 8974da4d200f3ca11aa0bc800f23d7a2be9a3e4e6311221888740c812d489116
  • 8dbd331784e620bb0ca33b8515ca9df9a7a049057b39a2da5242323943d730b4
  • aa259b168ec448349e91a9d560569bdb6fabd811d78888c6080065a549f60cb0

Remediation

  • Block threat indicators at your respective controls.
  • Make sure all vulnerable devices are up-to-date and patched against these vulnerabilities.