![]() |
|
#101
|
|||||
|
|||||
|
It looks like the .CPL - Shell etc method has actually been used before, from what i've seen. Here's just a few examples.
Quote:
Quote:
Quote:
Quote:
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#102
|
||||
|
||||
|
Quote:
Sophos also actually mentions SRP/AppLocker in their little blog article: Quote:
Whether or not DLL rules have to be enabled, I don't know. But gut feeling tells me they would need to be enabled, if it's correct that the vulnerability causes the malicious file referenced in the specially-crafted .lnk files to be loaded as a dll library (and not created as a process).
__________________
Save your tears, for your tears will not save you :: Shameless LUA troll |
|
#103
|
||||
|
||||
|
Has this thing any realtion with the current exploit?
http://www.greatis.com/security/expl...artup_hole.htm
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#104
|
|||
|
|||
|
|
|
#105
|
|||
|
|||
|
Quote:
I don't know, but see Malware persistence via DLL search order hijacking. |
|
#106
|
||||
|
||||
|
Ran the POC on XP/SP2, with less than half a dozen MS patches installed.
Enabled Shadow Defender and then Dl'd the Suckme POC and unzipped into a new folder, and then onto a flash stick, and also did the same on my desktop. Made a copys of suckme.lnk_ and then made it "workable" suckme.lnk "supposedly" Started up DbgView.exe and ran the POC, got no alerts from it or ProcessGuard or anything else. Put ProcessGuard in learning mode, cleared rundll.dll from it's list of OK's, and ran it again. Tried it from both the flash stick, and desktop. Clicked permit, and still no sign of anything happening, so ? * Quote:
EDIT Found 3 instances of rundll.32.exe via TM which i couldn't kill ? and one using DSE
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air Last edited by CloneRanger : July 18th, 2010 at 10:37 PM. Reason: Extra DSE & rundll.32.exe info |
|
#107
|
|||
|
|||
|
Quote:
You need to put dll.dll in C:\ EDIT: Also you don't need to click on the lnk file, just put it on your flash stick. |
|
#108
|
||||
|
||||
|
Originally Posted by Sadeghi85
Quote:
OK thanks Then plugged in my USB stick Sure enough i see 2 entries, whatever they mean ? Quote:
I did both. Still don't see anything out of the ordinary happening. What would i expect to find, and where ? TIA
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#109
|
||||
|
||||
|
Some extra info i found.
Quote:
* Quote:
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#110
|
|||
|
|||
|
It's explained here: http://blog.didierstevens.com/2010/0...on-with-ariad/
|
|
#111
|
||||
|
||||
|
Originally Posted by Sadeghi85
Quote:
Yes thanks i read that, but i don't see SUCK etc in my DbgView ? Also Didier Stevens appears to had dll.dll in a folder in D:\ his CD-ROM. I didn't see a mention of placing dll.dll in C:\ ?
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#112
|
|||
|
|||
|
From the h-online.com article posted by CloneRanger:
Quote:
However, it's clear that some modifications could be made to make the exploit more generic. It seems to me that the exploit would still require the user|victim to insert an infected USB drive that had a link file and malware file(s) already on the stick. ---- rich Last edited by Rmus : July 19th, 2010 at 01:31 AM. |
|
#113
|
|||
|
|||
|
Quote:
He wrote: Quote:
You can do that by editing the lnk file. The lnk file that comes with the PoC targets C:\dll.dll I could get it to work on a virtual CD drive, though it didn't work on a flash stick I had to put dll.dll in C:\ and the lnk file onto flash stick. |
|
#114
|
||||
|
||||
|
@Rmus
Hi, you must have been typing and missed post 109 where i linked to the same h-online article and quoted from it It'll be interesting to see how this malware develops, if it does. I wonder what method the people who have already being infected with it were subject to, in order for it to get into their comps ?
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#115
|
||||
|
||||
|
Originally Posted by Sadeghi85
Quote:
You're quite correct Quote:
I see Quote:
Strange as although i did put dll.dll in C:\ and the lnk file onto my flash stick, i'm not aware of anything happening ? What effects did it have on your comp, what/where did you see/find anything ?
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#116
|
|||
|
|||
|
All it does is that "SUCKM3..." message in DbgView’s output.
|
|
#117
|
||||
|
||||
|
Originally Posted by Sadeghi85
Quote:
OK thanks I would like to know though, and i'm sure others might be interested in knowing why it failed too. If anyone has any ideas etc, let us know ![]()
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#118
|
|||
|
|||
|
Quote:
My reason for quoting it was to confirm what I had learned a couple of days ago from the sans.edu Diary. Quote:
---- rich |
|
#119
|
||||
|
||||
|
Originally Posted by Rmus
Quote:
OK. thanks Quote:
Nice conformation Just looked at your Post #47 Island Hopping link, Quote:
* For the record. My USB stick is not a U3-enabled USB flash drive, just a memory stick. I have AutoPlay set to off on my CD/USB drives.
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#120
|
||||
|
||||
|
It works here. I've tried only Windows Explorer and Filezilla I don't have any other file browsers installed ATM.
From Explorer I must right-click on that lnk Properties and for Filezilla not, is enough to browse stick. No alert from CIS. CIS Proactive, FW and D+ in Safe Mode, AV Stateful, Sandbox Enabled/Disabled. XP SP3 all patches.
__________________
If it ain't broke... fix it until it is. CIS 5 user... |
|
#121
|
|||
|
|||
|
Quote:
We would like to take a deeper look into the TmpHider, but we don't have a sample yet. Especially a sample of the mrxnet.sys (016169ebebf1cec2aad6c7f0d0ee9026) would be very interesting to get, because it seems to contain the espionage code. But seems to be inpossible to get the code (or a link to a sample) here in this forum. Maybe someone of the one who owns a sample is able to upload it to the ~ Removed Link as per Policy - We don't want inexperienced users clicking over to a Malware Samples site ~ malware sample database. Would be very helpful. There are multiple sample requests for TmpHider at offensivecomputing but so far no one got a sample. Thanks for any help. Last edited by JRViejo : July 19th, 2010 at 12:25 PM. Reason: Link Removed - JRViejo |
|
#122
|
|||
|
|||
|
Quote:
|
|
#123
|
||||
|
||||
|
Quote:
And yet another Comodo failure.The way Comodo 4 is built leads to very little security in real threats.
__________________
Over & Out! |
|
#124
|
||||
|
||||
|
Agree for now, but I want to see how it's handled by other security suites too.
![]()
__________________
If it ain't broke... fix it until it is. CIS 5 user... |
|
#125
|
||||
|
||||
|
I tried the POC. Just opening my USB stick in explorer.exe triggered laoding of dll.dll.
1- Regarding CIS, the problem is that POC is nothing but a dll loading. CIS and any other HIPS by default don,t intercept dll loading as it gives rise to hundreds of useless pop up alerts. Infact CIS can be configured to give alert about dll.dll loading but it,s not practical at all as in this case CIS also gives dozens of other legit dll loading alerts. So in case of real malware( that was not a dll I think), CIS will give a usuall execution alert. 2- If dll.dll is marked as isolated/ untrusted in GesWall, Explorer.exe falils to load dll.dll. Can any one test DefenceWall and SBIE with this POC? Thanks
__________________
Ubuntu 13.04 AX64 Time Machine, Comodo FW & Defence Plus, |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|