I tripped over an instance of Mumblehard. This is my bulk encounter with the purveyors of that botnet.
I'll concentrate on analysis of how these instances differ, rather than carefully examine any one piece of code.
- Careful, expert coding
- Multiple languages: PHP and Perl
- Ongoing development, including bug fixes
- Use of multiple obfuscation methods simultaneously
- Multiple attack vectors, albeit all web shells
- Time coordinated attacks
- Little or no re-use of IP addresses
- Linux-based command and control
This is quite a campaign.
These files got downloaded from a global array of IP addresses.
| IP address | Download time | DNS name |
|---|---|---|
| 46.4.61.180 | 2017-11-23T09:12:52.000-0700 | static.180.61.4.46.clients.your-server.de |
| 85.214.116.207 | 2017-11-23T09:12:54.000-0700 | h2245961.stratoserver.net |
| 87.106.242.16 | 2017-12-15T06:18:39.000-0700 | s15316012.onlinehome-server.info |
| 176.9.85.238 | 2017-12-15T06:18:41.000-0700 | instarcom.org |
| 78.46.106.89 | 2017-12-15T06:18:45.000-0700 | h.enterned.ru |
| 188.93.209.151 | 2018-01-11T08:15:21.000-0700 | N/A |
| 148.251.22.155 | 2018-01-11T08:15:28-0700 | static.155.22.251.148.clients.your-server.de |
| 144.76.157.92 | 2018-01-12T06:02:52-0700 | promitheas2.multiserver.gr |
| 98.130.2.20 | 2018-01-13T08:40:30-0700 | web417.opentransfer.com |
| 198.23.60.134 | 2018-01-13T03:50:34-0700 | hosted.by.liquidnetlimited.com |
| 104.238.72.65 | 2018-01-13T03:50:37-0700 | ip-104-238-72-65.ip.secureserver.net |
| 37.247.120.74 | 2018-01-13T03:50:40-0700 | dns22.virtualns.net |
| 94.73.150.26 | 2018-01-14T10:01:55-0700 | 94-73-150-26.cizgibilgisayar.com |
| 209.54.60.219 | 2018-01-15T09:10:38-0700 | N/A |
| 94.73.146.65 | 2018-01-15T05:05:59-0700 | 94-73-146-65.cizgi.net.tr |
| 50.63.137.109 | 2018-01-16T06:48:31-0700 | ip-50-63-137-109.ip.secureserver.net |
| 130.211.93.58 | 2018-01-22T04:39:56-0700 | 58.93.211.130.bc.googleusercontent.com |
| 31.131.251.74 | 2018-01-23T11:09:31-0700 | deadline.media |
| 5.196.39.196 | 2018-01-23T11:09:43-0700 | N/A |
| 62.244.56.8 | 2018-01-23T12:00:41-0700 | vh2.lucky.net |
| 202.144.134.247 | 2018-01-24T09:23:52-0700 | www.sherubtse.edu.bt |
| 144.76.196.70 | 2018-01-24T07:48:27-0700 | static.70.196.76.144.clients.your-server.de |
| 163.44.207.227 | 2018-03-07T09:09:31-0700 | v163-44-207-227.a006.g.han1.static.cnode.io |
| 50.63.9.129 | 2018-03-07T09:09:36-0700 | ip-50-63-9-129.ip.secureserver.net |
| 151.236.47.145 | 2018-03-07T09:09:39-0700 | 151.236.47.145 |
| 198.71.51.167 | 2018-03-07T09:49:47-0700 | pianoarc.com |
| 5.196.0.45 | 2018-03-16T04:54:26-0600 | web21.pocetak.net |
| 88.208.204.45 | 2018-03-16T05:12:24-0600 | ted.lynkit.net |
| 154.34.28.155 | 2018-03-16T05:12:28-0600 | orange-horse-f27631d0a03eac4f.znlc.jp |
| 162.243.87.197 | 2018-03-16T06:05:41-0600 | www.bestapproach.com |
| 38.96.175.127 | 2018-04-01T06:20:14-0600 | N/A |
| 185.98.60.237 | 2018-04-02T03:27:46-0600 | server.ikaajans.net |
| 203.6.149.67 | 2018-04-02T03:27:51-0600 | N/A |
| 94.73.151.29 | 2018-04-02T05:33:32-0600 | 94-73-151-29.cizgi.net.tr |
| 208.113.221.89 | 2018-04-10T10:20:08-0600 | maximillian.dreamhost.com |
| 139.59.236.204 | 2018-04-10T10:20:14-0600 | N/A |
| 64.111.127.93 | 2018-04-20T03:00:43-0600 | turner.dreamhost.com |
| 173.201.34.182 | 2018-04-20T04:45:12-0600 | ip-173-201-34-182.ip.secureserver.net |
| 113.192.5.66 | 2018-04-21T03:19:02-0600 | N/A |
| 188.165.23.99 | 2018-04-21T07:43:35-0600 | k1.ageno.pl |
| 112.78.201.102 | 2018-04-23T08:08:08-0600 | N/A |
| 151.80.84.20 | 2018-04-23T08:08:12-0600 | www.theoreo.it |
| 185.195.76.76 | 2018-04-30T04:16:58-0600 | ip-tr-185-195-76-76.speedhosting.com.tr |
| 132.148.141.38 | 2018-04-30T04:17:01-0600 | ip-132-148-141-38.ip.secureserver.net |
| 77.246.156.85 | 2018-04-30T04:17:04-0600 | prosx1.example.com |
| 35.200.213.141 | 2018-04-30T04:26:22-0600 | 141.213.200.35.bc.googleusercontent.com |
| 193.93.216.3 | 2018-04-30T16:26:26-06:00 | astra.in.ua |
| 103.76.50.196 | 2018-05-02T05:36:19.000-0600 | N/A |
I run p0f3 on my gateway machine.
I correlated what p0f3 can guess about the OS sending the TCP SYN packet
with the HTTP requests.
All the above connections were made by Linux machines.
| Timestamp | IP Address | From TCP port | p0f3 OS guess |
|---|---|---|---|
| 2017-11-23T09:12:52 | 46.4.61.180 | 52692 | Linux 3.x |
| 2017-11-23T09:12:54 | 85.214.116.207 | 57248 | Linux 3.1-3.10 |
| 2017-12-15T06:18:39 | 87.106.242.16 | 45897 | Linux 2.6.x |
| 2017-12-15T06:18:41 | 176.9.85.238 | 33782 | Linux 3.1-3.10 |
| 2017-12-15T06:18:44 | 78.46.106.89 | 33318 | Linux 3.11 and newer |
| 2017-12-17T22:17:43 | 202.144.134.247 | 39323 | Linux 2.6.x |
| 2018-01-11T08:15:21 | 188.93.209.151 | 45576 | Linux 3.1-3.10 |
| 2018-01-11T08:15:28-07 | 148.251.22.155 | 46606 | Linux 3.1-3.10 |
| 2018-01-12T06:02:52 | 144.76.157.92 | 52816 | Linux 3.1-3.10 |
| 2018-01-13T08:40:29 | 98.130.2.20 | 54035 | Linux 2.6.x |
| 2018-01-13T15:50:34 | 198.23.60.134 | 52144 | Linux 3.1-3.10 |
| 2018-01-13T15:50:37 | 104.238.72.65 | 41371 | Linux 3.1-3.10 |
| 2018-01-13T15:50:40 | 37.247.120.74 | 44139 | Linux 2.2.x-3.x (no timestamps) |
| 2018-01-14T10:01:55 | 94.73.150.26 | 48860 | Linux 3.11 and newer |
| 2018-01-15T09:10:37 | 209.54.60.219 | 42296 | Linux 3.1-3.10 |
| 2018-01-15T17:05:59 | 94.73.146.65 | 57904 | Linux 3.11 and newer |
| 2018-01-16T06:48:31 | 50.63.137.109 | 55113 | Linux 2.6.x |
| 2018-01-22T15:35:44 | 94.73.150.26 | 38178 | Linux 3.11 and newer |
| 2018-01-22T16:39:55 | 130.211.93.58 | 50746 | Linux 3.1-3.10 |
| 2018-01-23T11:09:30 | 31.131.251.74 | 46660 | Linux 3.11 and newer |
| 2018-01-23T11:09:43 | 5.196.39.196 | 47676 | Linux 3.1-3.10 |
| 2018-01-23T12:00:41 | 62.244.56.8 | 56971 | Linux 3.1-3.10 |
| 2018-01-24T09:23:52 | 202.144.134.247 | 36254 | Linux 2.6.x |
| 2018-01-24T14:54:51 | 94.73.150.26 | 50468 | Linux 3.11 and newer |
| 2018-01-24T14:54:51 | 103.76.50.196 | 49154 | Linux 3.1-3.10 |
| 2018-01-24T19:48:27 | 144.76.196.70 | 46225 | Linux 3.11 and newer |
| 2018-01-30T06:07:08 | 88.208.204.45 | 46444 | Linux 3.1-3.10 |
| 2018-01-30T06:10:59 | 31.131.251.74 | 34730 | Linux 3.11 and newer |
| 2018-03-07T09:09:30 | 163.44.207.227 | 54476 | Linux 3.11 and newer |
| 2018-03-07T09:09:36 | 50.63.9.129 | 45615 | Linux 2.6.x |
| 2018-03-07T09:09:38 | 151.236.47.145 | 60845 | Linux 3.1-3.10 |
| 2018-03-07T09:49:47 | 198.71.51.167 | 59403 | Linux 3.1-3.10 |
| 2018-03-16T04:54:26 | 5.196.0.45 | 33768 | Linux 3.1-3.10 |
| 2018-03-16T05:12:23 | 88.208.204.45 | 39240 | Linux 3.1-3.10 |
| 2018-03-16T05:12:28 | 154.34.28.155 | 52976 | Linux 3.1-3.10 |
| 2018-03-16T06:05:41 | 162.243.87.197 | 48919 | Linux 2.2.x-3.x |
| 2018-04-01T06:20:14 | 38.96.175.127 | 46705 | Linux 3.11 and newer |
| 2018-04-02T03:27:46 | 185.98.60.237 | 38448 | Linux 3.1-3.10 |
| 2018-04-02T03:27:50 | 203.6.149.67 | 35371 | Linux 3.1-3.10 |
| 2018-04-02T05:33:31 | 94.73.151.29 | 33176 | Linux 3.11 and newer |
| 2018-04-02T05:33:33 | 173.201.34.182 | 47150 | Linux 2.6.x |
| 2018-04-10T10:20:08 | 208.113.221.89 | 37132 | Linux 2.2.x-3.x (no timestamps) |
| 2018-04-10T10:20:13-06 | 139.59.236.204 | 42038 | Linux 3.11 and newer |
| 2018-04-20T15:00:43 | 64.111.127.93 | 58096 | Linux 2.2.x-3.x (no timestamps) |
| 2018-04-20T16:45:11 | 173.201.34.182 | 56029 | Linux 2.6.x |
| 2018-04-21T03:19:01 | 113.192.5.66 | 41269 | Linux 2.6.x |
| 2018-04-21T19:43:34 | 188.165.23.99 | 35833 | Linux 2.6.x |
| 2018-04-23T08:08:08 | 112.78.201.102 | 46210 | Linux 2.6.x |
| 2018-04-23T08:08:12 | 151.80.84.20 | 60652 | Linux 3.1-3.10 |
| 2018-04-24T15:12:00 | 37.247.120.74 | 40201 | Linux 2.2.x-3.x (no timestamps) |
| 2018-04-30T16:16:57 | 185.195.76.76 | 58402 | Linux 3.1-3.10 |
| 2018-04-30T16:17:01 | 132.148.141.38 | 47660 | Linux 3.1-3.10 |
| 2018-04-30T16:17:04 | 77.246.156.85 | 55593 | Linux 3.1-3.10 |
| 2018-04-30T16:26:21 | 35.200.213.141 | 38270 | Linux 3.11 and newer |
| 2018-04-30T16:26:26-06 | 193.93.216.3 | 47707 | Linux 3.11 and newer |
| 2018-05-02T05:36:19 | 103.76.50.196 | 55167 | Linux 3.1-3.10 |
| 2018-05-10T05:08:05 | 209.54.60.219 | 56340 | Linux 3.1-3.10 |
Those IP addresses have only attempted to download Mumblehard to my honey pot, except for 104.238.72.65, which apparently scans for unmaintained WordPress sites:
Only one of these IP addresses has TCP port 33778 open (2018-05-27), so I can't say that the existing mumblehard relay system gets used to distribute mumblehard to new hosts.
| Time Stamp | IP Address | Requested URI |
|---|---|---|
| 2016-04-22 13:59:48-06 | 104.238.72.65 | /old/wp-admin/ |
| 2016-06-20 20:33:08-06 | 104.238.72.65 | /test/wp-admin/ |
| 2016-08-16 00:37:06-06 | 104.238.72.65 | /blog/wp-admin/ |
| 2016-09-21 12:28:11-06 | 104.238.72.65 | /wp/wp-admin/ |
| 2016-10-31 14:42:42-06 | 104.238.72.65 | /wp/wp-admin/ |
| 2016-11-09 23:16:32-07 | 104.238.72.65 | /wp-admin/ |
| 2017-11-23 09:12:52-07 | 46.4.61.180 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2017-11-23 09:12:54-07 | 85.214.116.207 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2017-12-15 06:18:39-07 | 87.106.242.16 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2017-12-15 06:18:41-07 | 176.9.85.238 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2017-12-15 06:18:45-07 | 78.46.106.89 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2017-12-17 22:17:44-07 | 202.144.134.247 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-11 08:15:21-07 | 188.93.209.151 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-12 06:02:52-07 | 144.76.157.92 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-13 08:40:30-07 | 98.130.2.20 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-13 15:50:34-07 | 198.23.60.134 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-13 15:50:37-07 | 104.238.72.65 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-13 15:50:40-07 | 37.247.120.74 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-14 10:01:55-07 | 94.73.150.26 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-15 09:10:38-07 | 209.54.60.219 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-15 17:05:59-07 | 94.73.146.65 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-16 06:48:31-07 | 50.63.137.109 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-22 15:35:44-07 | 94.73.150.26 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-22 16:39:56-07 | 130.211.93.58 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-23 11:09:31-07 | 31.131.251.74 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-23 11:09:43-07 | 5.196.39.196 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-23 12:00:41-07 | 62.244.56.8 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-24 09:23:52-07 | 202.144.134.247 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-24 14:54:51-07 | 94.73.150.26 | /wp-content/themes/sketch/404.php |
| 2018-01-24 14:54:52-07 | 103.76.50.196 | /wp-content/themes/sketch/404.php |
| 2018-01-24 19:48:27-07 | 144.76.196.70 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-01-30 06:07:08-07 | 88.208.204.45 | /wp-content/plugins/revslider/temp/update_extract/revslider/info.php |
| 2018-01-30 06:10:59-07 | 31.131.251.74 | /wp-content/plugins/revslider/temp/update_extract/revslider/info.php |
| 2018-03-07 09:09:31-07 | 163.44.207.227 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-03-07 09:09:36-07 | 50.63.9.129 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-03-07 09:09:39-07 | 151.236.47.145 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-03-07 09:49:47-07 | 198.71.51.167 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-03-16 04:54:26-06 | 5.196.0.45 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-03-16 05:12:24-06 | 88.208.204.45 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-03-16 05:12:28-06 | 154.34.28.155 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-03-16 06:05:41-06 | 162.243.87.197 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-04-01 06:20:14-06 | 38.96.175.127 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-04-02 03:27:46-06 | 185.98.60.237 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-04-02 03:27:51-06 | 203.6.149.67 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-04-02 05:33:32-06 | 94.73.151.29 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-04-02 05:33:33-06 | 173.201.34.182 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-04-10 10:20:08-06 | 208.113.221.89 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-04-20 15:00:43-06 | 64.111.127.93 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-04-20 16:45:12-06 | 173.201.34.182 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-04-21 03:19:02-06 | 113.192.5.66 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-04-21 19:43:35-06 | 188.165.23.99 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-04-23 08:08:08-06 | 112.78.201.102 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-04-30 16:16:58-06 | 185.195.76.76 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-04-30 16:17:01-06 | 132.148.141.38 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-04-30 16:17:04-06 | 77.246.156.85 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-04-30 16:26:22-06 | 35.200.213.141 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-05-02 05:36:19-06 | 103.76.50.196 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
| 2018-05-10 05:08:05-06 | 209.54.60.219 | /wordpress/wp-content/plugins/revslider/temp/update_extract/revslider/db.php |
These are all commonly invoked URIs, at least for my WordPress honey pot. One odd thing: 3 different methods of obfuscation, clearly intended for 3 different web shells, all get sent to a single URI. Someone's sloppy and not cleaning their URL lists. It's not that they use different host names, like "www.stratigery.com" and "stratigery.com": all requests are made of "stratigery.com".
There is one other interesting exception:
A visit
from 148.251.22.155 on 2018-04-10T10:35:42-06.
Unfortunately, there's nothing there.
It's a visit to a presumed WSO web shell:
the only POST parameter is pass, which a value of nhzgrf,
a very common password for WSO shells.
The user agent, the URI and all the HTTP parameters are the
same as other mumblehard download accesses.
It's the only access that's not an attempt to download,
and it arrives about 15 minutes after a download attempt from 208.113.221.89.
My WSO honey pot shows 10 of the last uploaded files as part of it's default output,
but it doesn't keep any other history.
This access can't be for checking on a mumblhard-related file's existence,
as mumblehard only exists as a running process,
and a randomly named file in /var/tmp/ or /tmp/.
Real WSO would give a listing of the directory in the WordPress
install in which it resides.
That wouldn't be /var/tmp/ or /tmp/.
These all got downloaded via a fake WSO web shell that's part of my WordPress honey pot. It's clear based on HTTP POST parameters, that the attacker targeted 3 different web sheels. The method of obfuscation is tied to the intended web shell.
Some attempts sent 'ev', 'sc' and 'pass><input' as names of POST HTTP parameters. The use of an 'ev' parameter matches another backdoor I've caught, but that backdoor does not need a 'sc' or 'pass><input' parameter to work.
Other attempts sent 'pass', 'a', 'ajax' and 'p1' as names of POST HTTP parameters. These are names of parameters used by the well known WSO or "FilesMan" web shell. For these download attempts, the attacker tried to invoke WSO's "Php" action.
The attacker probably intended XOR-obfuscated downloads for a WSO 4.x web shell.
All of the downloads have a user agent string of:
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2) Gecko/20100115 Firefox/3.6
I have Apache access_log files dating back to 2009 for my domain name.
This user agent string appears from 2010-02-01 to 2013-08-02,
apparently from real browsers,
because requests for HTML files are accompanied by
/favicon.ico requests.
That user agent string does not appear again until 2015-03-22,
when 66.232.129.200 requests /wp-content/plugins/wp_systems/mod_systems1.php,
which it almost certainly believed was a WSO web shell.
It looks like that user agent string is hard coded in some malware-invoking code.
The Eset report on mumblehard lists a user agent string of:
Mozilla/5.0 (Windows NT 6.1; rv:7.0.1) Gecko/20100101 Firefox/7.0.1
My Apache logs have 2011-10-01T17:48:04-06 as the first time
this user agent got used,
and 2016-07-21T15:35:51-06 as the last time it got used.
These seem like human-driven accesses,
mostly hitting a specific URL, then asking for /favicon.ico.
I did deobfuscating with scripts, because I had too many files to do each individually. See deobfuscation notes for ugly details.
Four separate obfuscations exist.
- Plain PHP dropper with base64-encoded daemon.
The files for these instances exist in
files/ - WSO 4.x base64-encoded and XOR'ed.
The files for these exist in
files2/ - Base64-encoded dropper, essentially another layer around (1)
These files exist in
files3/ - WSO 4.x base64-encoded and XOR'ed, plain PHP dropper, files in
files4/
Methods 1 and 3 got sent to unknown web shell, WSO 2.x web shell, WSO 4.x web shell.
After deobfuscation, each mumblehard download has three parts:
- Dropper
- Daemon
- Cron job
There's 5 exceptions: the daemon code downloaded by 112.78.201.102, 113.192.5.66, 173.201.34.182, 188.165.23.99, 151.80.84.20 does not install the cron job code.
There's nothing special about the dropper, except that it's very persistant about getting the daemon started.
The PHP dropper code contains a Base64-encoded piece of Perl. The dropper code decodes it, writes it to a file, and does its level best to start the Perl in its own process.
6 different daemons got downloaded. By downloading IP address:
- 104.238.72.65, 198.23.60.134, 31.131.251.74, 5.196.39.196, 37.247.120.74, 130.211.93.58, 144.76.157.92, 144.76.196.70, 188.93.209.151, 202.144.134.247, 209.54.60.219, 50.63.137.109, 62.244.56.8, 94.73.146.65, 94.73.150.26, 98.130.2.20, 148.251.22.155
- 154.34.28.155, 163.44.207.227, 185.98.60.237, 203.6.149.67, 50.63.9.129, 88.208.204.45, 151.236.47.145, 162.243.87.197, 198.71.51.167, 208.113.221.89, 38.96.175.127, 5.196.0.45, 64.111.127.93, 94.73.151.29, 139.59.236.204
- 46.4.61.180, 85.214.116.207
- 176.9.85.238, 87.106.242.16, 78.46.106.89
- 112.78.201.102, 113.192.5.66, 173.201.34.182, 177.246.156.85, 88.165.23.99, 151.80.84.20
- 132.148.141.38, 185.195.76.76, 103.76.50.196, 35.200.213.141, 193.93.216.3
Group 1 daemons claim to be version 11.
Group 2 daemons also claim to be version 11.
Groups 1 and 2 differ in the persistent payload/cron job they carry.
Group 3 daemons drop a FreeBSD ELF file as a persistent payload. The other groups drop Perl persistent payloads. They also claim to be verision 8.
Group 4 daemons claim to be version 8, but drop Perl persistent payloads.
Groups 3 and 4 differ in "configuration" details, like IP addresses to test for SMTP and DNS availability, and in some code details. For example, group 3 daemons use "HELO" to initiate an SMTP session. Group 4 daemons use "EHLO".
Group 5 daemons claim to be version 112.
Group 6 dameons also claim to be version 112, but do not carry a persistent payload.
Groups 5 and 6 differ only in whether or not they carry a persistent payload/cron job.
The daemon contains uuencoded payloads, an unusual choice of encoding.
Two of the downloads I caught have an ELF-format-file, this and this.
The file command says:
"ELF 32-bit LSB executable, Intel 80386, version 1 (FreeBSD), statically linked, not stripped".
A quick strings command indicates this is true. Incidentally, these are
the two oldest downloads.
At a guess,
since these ELF files have a function named xordat,
there's some other code hidden inside, exclusive-or-encoded.
If I was thorough,
I'd get that dumped and decoded.
Based on the Eset yara rule these 2 ELF files are both "mumblehard packer".
The other persistent payloads are all the same Perl code, differing only in one IP address, one of two IP addresses used as "dead drops" to pick up new code from.
The Perl persistent payload (run every 10 minutes by cron) chooses
to retrieve a file
from a list of IP addresses.
These IP addresses change from download to download.
In fact, this is the only difference between persistent payloads.
Arbitrarily, A type persistent code uses 5.135.42.98, 77.72.83.83. B type persistent code uses 5.135.42.98 and 198.245.49.106.
Five of the daemons don't carry any persistent payload.
5.135.42.98 is an OVH dedicated server in France, according to geoiplookup.
198.245.49.106 is an OVH Hosting IP in Canada.
77.72.83.83 is from Quasinetworks in UK.
| IP address | Download time | Obfuscation | Daemon group | Payload | POST parameters |
|---|---|---|---|---|---|
| 46.4.61.180 | 2017-11-23T09:12:52.000-0700 | plain | 3 | ELF file | pass, a, ajax, p1 |
| 85.214.116.207 | 2017-11-23T09:12:54.000-0700 | plain | 3 | ELF file | pass><input, ev |
| 87.106.242.16 | 2017-12-15T06:18:39.000-0700 | plain | 4 | B | pass, a, ajax, p1 |
| 176.9.85.238 | 2017-12-15T06:18:41.000-0700 | plain | 4 | B | pass><input, ev |
| 78.46.106.89 | 2017-12-15T06:18:45.000-0700 | XOR | 4 | B | pass, a, p1, ajax |
| 188.93.209.151 | 2018-01-11T08:15:21.000-0700 | Extra layer | 1 | B | pass><input, ev |
| 148.251.22.155 | 2018-01-11 08:15:28-07 | XOR plain | 1 | B | pass, a, p1, ajax |
| 144.76.157.92 | 2018-01-12T06:02:52.000-0700 | Extra layer | 1 | B | pass><input, ev |
| 98.130.2.20 | 2018-01-13T08:40:30.000-0700 | Extra layer | 1 | B | pass><input, ev |
| 198.23.60.134 | 2018-01-13T03:50:34.000-0700 | plain | 1 | B | pass, a, ajax, p1 |
| 104.238.72.65 | 2018-01-13T03:50:37.000-0700 | plain | 1 | B | pass><input, ev |
| 37.247.120.74 | 2018-01-13T03:50:40.000-0700 | XOR | 1 | B | pass, a, p1, ajax |
| 94.73.150.26 | 2018-01-14T10:01:55.000-0700 | Extra layer | 1 | B | pass><input, ev |
| 209.54.60.219 | 2018-01-15T09:10:38.000-0700 | Extra layer | 1 | B | pass><input, ev |
| 94.73.146.65 | 2018-01-15T05:05:59.000-0700 | Extra layer | 1 | B | pass><input, ev |
| 50.63.137.109 | 2018-01-16T06:48:31.000-0700 | plain | 1 | B | pass><input, ev |
| 130.211.93.58 | 2018-01-22T04:39:56.000-0700 | Extra layer | 1 | B | pass><input, ev |
| 31.131.251.74 | 2018-01-23T11:09:31.000-0700 | plain | 1 | B | pass, a, ajax, p1 |
| 5.196.39.196 | 2018-01-23T11:09:43.000-0700 | plain | 1 | B | pass><input, ev |
| 62.244.56.8 | 2018-01-23T12:00:41.000-0700 | Extra layer | 1 | B | pass><input, ev |
| 202.144.134.247 | 2018-01-24T09:23:52.000-0700 | Extra layer | 1 | B | pass><input, ev |
| 144.76.196.70 | 2018-01-24T07:48:27.000-0700 | Extra layer | 1 | B | pass><input, ev |
| 163.44.207.227 | 2018-03-07T09:09:31.000-0700 | plain | 2 | A | pass, a, ajax, p1 |
| 50.63.9.129 | 2018-03-07T09:09:36.000-0700 | plain | 2 | A | pass><input, ev |
| 151.236.47.145 | 2018-03-07T09:09:39.000-0700 | XOR | 2 | A | pass, a, p1, ajax |
| 198.71.51.167 | 2018-03-07T09:49:47.000-0700 | Extra layer | 2 | A | pass><input, ev |
| 5.196.0.45 | 2018-03-16T04:54:26.000-0600 | Extra layer | 2 | A | pass><input, ev |
| 88.208.204.45 | 2018-03-16T05:12:24.000-0600 | plain | 2 | A | pass, a, ajax, p1 |
| 154.34.28.155 | 2018-03-16T05:12:28.000-0600 | plain | 2 | A | pass><input, ev |
| 162.243.87.197 | 2018-03-16T06:05:41.000-0600 | Extra layer | 2 | A | pass><input, ev |
| 38.96.175.127 | 2018-04-01T06:20:14.000-0600 | Extra layer | 2 | A | pass><input, ev |
| 185.98.60.237 | 2018-04-02T03:27:46.000-0600 | plain | 2 | A | pass, a, ajax, p1 |
| 203.6.149.67 | 2018-04-02T03:27:51.000-0600 | plain | 2 | A | pass><input, ev |
| 94.73.151.29 | 2018-04-02T05:33:32.000-0600 | Extra layer | 2 | A | pass><input, ev |
| 208.113.221.89 | 2018-04-10T10:20:08.000-0600 | Extra layer | 2 | A | pass><input, ev |
| 139.59.236.204 | 2018-04-10 10:20:13-06 | XOR plain | 2 | A | pass, a, p1, ajax |
| 64.111.127.93 | 2018-04-20T03:00:43.000-0600 | Extra layer | 2 | A | pass><input, ev |
| 173.201.34.182 | 2018-04-20T04:45:12.000-0600 | Extra layer | 5 | None | pass><input, ev |
| 113.192.5.66 | 2018-04-21T03:19:02.000-0600 | Extra layer | 5 | None | pass><input, ev |
| 188.165.23.99 | 2018-04-21T07:43:35.000-0600 | Extra layer | 5 | None | pass><input, ev |
| 112.78.201.102 | 2018-04-23T08:08:08.000-0600 | Extra layer | 5 | None | pass><input, ev |
| 151.80.84.20 | 2018-04-23 08:08:12-06 | XOR plain | 5 | None | pass, a, p1, ajax |
| 185.195.76.76 | 2018-04-30T04:16:58.000-0600 | plain | 6 | A | pass, a, ajax, p1 |
| 132.148.141.38 | 2018-04-30T04:17:01.000-0600 | plain | 6 | A | pass><input, ev |
| 77.246.156.85 | 2018-04-30T04:17:04.000-0600 | XOR | 5 | None | pass, a, p1, ajax |
| 35.200.213.141 | 2018-04-30T04:26:22.000-0600 | Extra layer | 6 | A | pass><input, ev |
| 193.93.216.3 | 2018-04-30 16:26:26-06 | XOR plain | 6 | A | pass, a, p1, ajax |
| 103.76.50.196 | 2018-05-02T05:36:19.000-0600 | Extra layer | 6 | A | pass><input, ev |
Amusing. They start with the ELF file persistent payloads, move to the Perl "version 8", then move to version 11, then version 112. Looks like I may be missing versions 9 and 10. Version 112 might be a bug fix release. It looks like the persistent payload/cron job is developed on a different schedule than the daemon.