Wednesday, April 3, 2019

Malware Analysis: RDP Backdoor (Gh0st variant)

A little while ago I caught this RDP backdoor in my honeypot that I thought was kinda interesting, so I figured I would do a write-up on it. The author of this malware took minimal measures to hide its functionality.

I searched for the md5 hash on virustotal and someone had already uploaded it here.

CFF Explorer output:


Aside from some function calls being stored as character arrays, there was hardly any obfuscation in this malware. It was packed with UPX, so unpacking was trivial.

I searched the source IP in Shodan and got this:

The first thing I noticed was "220 RMNetwork FTP". This is indicative of being part of the Ramnit botnet. RDP is also enabled. Before I took this screenshot of the Shodan results, I was able to connect to it via RDP. Its a Windows 2003 server in China. I'm under the impression that this server has been infected multiple times by different malware. I found a few things that didn't match up with being related to the Ramnit botnet.

From Thor APT Scanner:

Signature Match - THOR APT Scanner

Detection
============================
Rule: IronTiger_Gh0stRAT_variant
Ruleset: Chinese Threat Groups
Description: This is a detection for a s.exe variant seen in Op. Iron Tiger
Reference: http://goo.gl/T5fSJC
Author: Cyber Safety Solutions, Trend Micro
Score: 70

Detection Snapshot
============================
Detection Timestamp: 2018-12-17 18:19
AV detection ratio: 50 / 70

Within the binary I found a reference to a script called "jingtisanmenxiachuanxiao.vbs", which is referenced in this whitepaper about Operation PZCHAO written by Bitdefender.


After some static analysis I discovered that this creates a new user and enables RDP. 

**POST IN PROGRESS**

2 comments:

  1. href=https://www.vcaretechs.in/windows-game-development.php ">Windows game developmet is an exciting and dynamic field that has seen significant growth in recent years. With millions of Windows users worldwide, there is a huge potential market for game developers to tap into. In this blog post, we will explore some of the tools and resources available for developers who are interested in creating games for Windows.
    One of the most popular tools for Windows game development is Unity. Unity is a powerful and versatile game engine that allows developers to create games for multiple platforms, including Windows, macOS, Linux, Android, and iOS. With its easy-to-use interface and vast library of assets and resources, Unity is an excellent choice for both beginner and experienced game developers.
    Another popular tool for Windows game development is Unreal Engine. Unreal Engine is a powerful game engine that is used by many AAA game developers to create high-quality games. It offers a wide range of features, including advanced physics, a powerful rendering engine, and AI tools. While Unreal Engine may be more challenging to learn than Unity, it offers more advanced capabilities for developers who want to create complex and sophisticated games.

    ReplyDelete
  2. A digital marketing agency in Delhi is a company that provides various online marketing services to businesses and organisations in the Delhi region. These agencies specialise in leveraging digital channels such as search engines, social media platforms, email marketing, content marketing, and more to help their clients reach and engage their target audience, generate leads, and drive conversions.
    Here are some key services offered by a digital marketing agency in Delhi:
    Search Engine Optimization (SEO): SEO involves optimising a website to improve its visibility in search engine rankings. This includes keyword research, on-page optimization, technical SEO, link building, and more.
    Pay-Per-Click Advertising (PPC): PPC campaigns involve running targeted ads on search engines like Google or social media platforms like Facebook. Agencies create and manage PPC campaigns to drive relevant traffic to their clients' websites.
    Social Media Marketing: This service involves managing and leveraging social media platforms like Facebook, Twitter, Instagram, LinkedIn, etc., to build brand awareness, engage with the target audience, and drive traffic and conversions.
    Content Marketing: Content marketing focuses on creating and distributing valuable and relevant content to attract and engage the target audience. It includes creating blog posts, articles, videos, infographics, and more to establish thought leadership and drive organic traffic.
    Email Marketing: Agencies help clients create effective email marketing campaigns to nurture leads, promote products or services, and build customer loyalty. This includes email list management, designing compelling newsletters, and analysing campaign performance.
    Conversion Rate Optimization (CRO): CRO involves optimising a website or landing page to increase the percentage of visitors who take a desired action, such as making a purchase or filling out a contact form. Agencies use data analysis, A/B testing, and user experience optimization techniques to improve conversions.

    ReplyDelete