Monday, April 20, 2009

Black Hat SEO - RBN Hacks, p.4

The silent threat: Black Hat SEO, exploits, hacks, botnets

Crimeware toolkits in the wild

READ THIS page if you need more information

WARNING: All sites listed on this page are dangerous (live URL with exploits)
which lead to trojans beeing automatically installed on your computer.
Do NOT visit them unless you know what you are doing.
(only links are safe)

Another very good example on the site below which lead to other domain in the network previously cited "Eurohost LLC " shows that this attack seems to be everywhere.

IFrames injected, pdf malware + viruses. Attached some screenshots.


Infected page:

hxxp://team-sleep.by.ru/default2.html

Analysis

hxxp://8addition.info/t/?75724cae9d
hxxp://sexbases.cn/in.cgi?16&161b72
hxxp://utevox.site90.com/f/index.php

************
Infected page:

hxxp://team-sleep.by.ru/demo.html

Analysis

Requests:

hxxp://bizoplata.ru/pay.html?
hxxp://bizoplata.ru/ballast.html
hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php
hxxp://bizoplata.ru/post.html
hxxp://sunmaiamibich.ru/pupu/in.php
hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php
hxxp://mixbunch.cn/thread.html
hxxp://mixbunch.cn/golf.html
hxxp://mixbunch.cn/bowling.html
hxxp://famajormusic.ru/jjkj/pdf.php

Redirects:

hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php

hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php

************
Infected page:

hxxp://team-sleep.by.ru/gold.html

Analysis

Requests:

hxxp://team-sleep.by.ru/gold.html
hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php
hxxp://mixbunch.cn/thread.html
hxxp://mixbunch.cn/golf.html
hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php
hxxp://mixbunch.cn/bowling.html
hxxp://sunmaiamibich.ru/pupu/in.php
hxxp://famajormusic.ru/jjkj/pdf.php

Redirects:

hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php

hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php


************
Infected page:

hxxp://team-sleep.by.ru/googleanalyticsru.html

Analysis

Requests:

hxxp://team-sleep.by.ru/googleanalyticsru.html
hxxp://mixbunch.cn/thread.html
hxxp://mixbunch.cn/golf.html
hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php
hxxp://mixbunch.cn/bowling.html
hxxp://sunmaiamibich.ru/pupu/in.php
hxxp://sunmaiamibich.ru/

Redirects:

hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php

************
Infected page:

hxxp://team-sleep.by.ru/media.html

Analysis

Requests:

hxxp://team-sleep.by.ru/media.html
hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php
hxxp://mixbunch.cn/thread.html
hxxp://mixbunch.cn/golf.html
hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php
hxxp://mixbunch.cn/bowling.html
hxxp://sunmaiamibich.ru/pupu/in.php
hxxp://famajormusic.ru/jjkj/pdf.php

Redirects:

hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php

hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php


************
Infected page:

hxxp://team-sleep.by.ru/menu.html

Analysis

Requests:

hxxp://team-sleep.by.ru/menu.html
hxxp://bizoplata.ru/pay.html?
hxxp://bizoplata.ru/ballast.html
hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php
hxxp://bizoplata.ru/post.html
hxxp://sunmaiamibich.ru/pupu/in.php
hxxp://famajormusic.ru/jjkj/pdf.php
hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php
hxxp://mixbunch.cn/thread.html
hxxp://mixbunch.cn/golf.html
hxxp://mixbunch.cn/bowling.html

Redirects:

hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php

hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php


************
Infected page:

hxxp://team-sleep.by.ru/news.html

Analysis

Requests:

hxxp://moneypuller.site90.net/images/gallery/index.php
hxxp://error.000webhost.com/not_found.html
hxxp://www.000webhost.com/?id=1
hxxp://www.000webhost.com/
hxxp://mixbunch.cn/thread.html
hxxp://mixbunch.cn/golf.html
hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php
hxxp://mixbunch.cn/bowling.html
hxxp://sunmaiamibich.ru/pupu/in.php
hxxp://famajormusic.ru/jjkj/pdf.php

Redirects:

hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php

************
Infected page:

hxxp://team-sleep.by.ru/photo2.html

Analysis

Requests:

hxxp://mixbunch.cn/thread.html
hxxp://mixbunch.cn/golf.html
hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php
hxxp://mixbunch.cn/bowling.html
hxxp://sunmaiamibich.ru/pupu/in.php
hxxp://famajormusic.ru/jjkj/pdf.php
hxxp://bizoplata.ru/pay.html?
hxxp://bizoplata.ru/ballast.html
hxxp://bizoplata.ru/post.html
hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php

Redirects:

hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php

hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php


************
Infected page:

hxxp://team-sleep.by.ru/poem.html

Analysis

Requests:

hxxp://mixbunch.cn/thread.html
hxxp://mixbunch.cn/golf.html
hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php
hxxp://mixbunch.cn/bowling.html
hxxp://sunmaiamibich.ru/pupu/in.php
hxxp://famajormusic.ru/jjkj/pdf.php
hxxp://bizoplata.ru/pay.html?
hxxp://bizoplata.ru/ballast.html
hxxp://bizoplata.ru/post.html

Redirects:

hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php

************
Infected page:

hxxp://team-sleep.by.ru/press_reviews.html

Analysis

Requests:

hxxp://mixbunch.cn/thread.html
hxxp://mixbunch.cn/golf.html
hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php
hxxp://mixbunch.cn/bowling.html
hxxp://sunmaiamibich.ru/pupu/in.php
hxxp://famajormusic.ru/jjkj/pdf.php
hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php

Redirects:

hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php

hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php


************
Infected page:

hxxp://team-sleep.by.ru/team-sleep.html

Anaysis

Redirects:

hxxp://mixbunch.cn/thread.html
hxxp://mixbunch.cn/golf.html
hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php
hxxp://mixbunch.cn/bowling.html
hxxp://sunmaiamibich.ru/pupu/in.php
hxxp://famajormusic.ru/jjkj/pdf.php
hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php

Redirects:

hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php

hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php


************
Infected page:

hxxp://team-sleep.by.ru/gmail.php

Analysis

Requests:

hxxp://counnter.cn/top100_00.js
hxxp://counnter.cn/z/count.php?o=1
hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php

Redirects:

hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php


************
Infected page:

hxxp://team-sleep.by.ru/haitou.php

Analysis

Requests:

hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php

************
Infected page:

hxxp://team-sleep.by.ru/in.php

Analysis

Requests:

hxxp://www.rogercombs.org/index.php
hxxp://5rublei.com/unique/index.php
hxxp://tochtonenado.com/yes/index.php

************
Infected page:

hxxp://team-sleep.by.ru/photo/team.html

Analysis

Requests:

hxxp://analytics-google.info/s/urchin.js
hxxp://mixbunch.cn/golf.html
hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php
hxxp://mixbunch.cn/bowling.html
hxxp://sunmaiamibich.ru/pupu/in.php
hxxp://famajormusic.ru/jjkj/pdf.php
hxxp://77.221.133.172/.if/go.html?
hxxp://by.ru/info/?where

************
Infected page:

hxxp://team-sleep.by.ru/photo/wallz.html

Analysis

Requests:

hxxp://analytics-google.info/s/urchin.js
hxxp://mixbunch.cn/thread.html
hxxp://mixbunch.cn/golf.html
hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php
hxxp://mixbunch.cn/bowling.html
hxxp://sunmaiamibich.ru/pupu/in.php
hxxp://famajormusic.ru/jjkj/pdf.php
hxxp://bizoplata.ru/pay.html?
hxxp://bizoplata.ru/ballast.html
hxxp://bizoplata.ru/post.html
hxxp://by.ru/info/?where

************
Infected page:

hxxp://team-sleep.by.ru/photo/live/index2.html

Analysis

Requests:

hxxp://utevox.site90.com/f/index.php
hxxp://mixbunch.cn/thread.html
hxxp://mixbunch.cn/golf.html
hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php
hxxp://mixbunch.cn/bowling.html
hxxp://sunmaiamibich.ru/pupu/in.php
hxxp://famajormusic.ru/jjkj/pdf.php

************
Infected page:

hxxp://team-sleep.by.ru/photo/live/imagepages/image1.html


Analysis

Requests:

hxxp://analytics-google.info/s/urchin.js
hxxp://mixbunch.cn/thread.html
hxxp://mixbunch.cn/golf.html
hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php
hxxp://mixbunch.cn/bowling.html
hxxp://sunmaiamibich.ru/pupu/in.php
hxxp://famajormusic.ru/jjkj/pdf.php

************
Infected page:

hxxp://team-sleep.by.ru/photo/members/imagepages/image1.html

Analysis

Requests:

hxxp://analytics-google.info/s/urchin.js
hxxp://mixbunch.cn/thread.html
hxxp://mixbunch.cn/golf.html
hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php
hxxp://mixbunch.cn/bowling.html
hxxp://sunmaiamibich.ru/pupu/in.php
hxxp://famajormusic.ru/jjkj/pdf.php

************
Infected page:

hxxp://team-sleep.by.ru/photo/team/imagepages/image1.html

Analysis

On this page the domain appears to be previously involved in the Asprox malware campaign. As you can see the fgg.js and script.js are still present on the page.

However all of these are not responding.

Finjan report
Google Searchfor fgg.js
Google Search for www.netcfg9.ru

hxxp://www.jve4.ru/fgg.js
hxxp://www.nmr43.ru/fgg.js
hxxp://www.mj5f.ru/script.js
hxxp://www.vswc.ru/script.js
hxxp://www.pkseio.ru/script.js
hxxp://www.4log-in.ru/script.js
hxxp://www.netcfg9.ru/script.js
hxxp://www.sitevgb.ru/script.js
hxxp://www.errghr.ru/script.js
hxxp://www.81dns.ru/script.js
hxxp://mixbunch.cn/thread.html
hxxp://mixbunch.cn/golf.html
hxxp://tixwagoq.cn/in.cgi?4
hxxp://paylayos.cn/nuc/index.php
hxxp://mixbunch.cn/bowling.html
hxxp://sunmaiamibich.ru/pupu/in.php
hxxp://famajormusic.ru/jjkj/pdf.php


************
Infected page:

hxxp://tochtonenado.com/yes/index.php
hxxp://tochtonenado.com/yes/load.php?stat=Windows

Analysis

Trojan Waledac.GEN

Anubis Report

Botnet Controller

89.149.244.140:80 - [djbobroff.ru]
Request: GET /spm/index.php?id=584E5E43
Response: 200 "OK"
Request: GET /spm/index.php?id=584E5E43&download=0000138F
Response: 200 "OK"
Request: POST /spm/index.php?id=584E5E43&mid=5007
Response: 200 "OK"

C:\WINDOWS\system32\DRIVERS\asyncmac.sys

*****************

Exploits:

hxxp://5rublei.com/unique/index.phpAnalysis - VirusTotal - Anubis
hxxp://bizoplata.ru/ballast.htmlAnalysis
hxxp://bizoplata.ru/courier.htmlAnalysis
hxxp://bizoplata.ru/pay.html?Analysis
hxxp://bizoplata.ru/post.htmlAnalysis
hxxp://dasretokfin.com/load.phpAnalysis
hxxp://mixbunch.cn/thread.htmlAnalysis
hxxp://mixbunch.cn/golf.htmlAnalysis
hxxp://mixbunch.cn/bowling.htmlAnalysis
hxxp://peskufex.cn/ss/in.cgi?2Source
hxxp://startdontstop.ru/bigmac.htmlAnalysis
hxxp://sunmaiamibich.ru/pupu/in.phpAnalysis
hxxp://sunmaiamibich.ru/pupu/load.phpVirusTotal - Anubis
hxxp://tixwagoq.cn/in.cgi?4Analysis
hxxp://tochtonenado.com/yes/index.php Analysis
hxxp://tochtonenado.com/yes/load.phpAnubis
hxxp://tochtonenado.com/yes/include/spl.phpAnalysis
hxxp://utevox.site90.com/f/index.phpAnalysis
hxxp://utevox.site90.com/f/load.phpdead


91.212.41.91

hxxp://mixbunch.cn
hxxp://sunmaiamibich.ru

91.212.65.7

hxxp://peskufex.cn

95.129.144.228

hxxp://5rublei.com
hxxp://dasretokfin.com
hxxp://tochtonenado.com

95.129.144.13

hxxp://bizoplata.ru
hxxp://startdontstop.ru

64.235.52.170

hxxp://utevox.site90.com

************************

Domain Name: mixbunch.cn
ROID: 20081108s10001s82359461-cn
Domain Status: clientTransferProhibited
Registrant Organization: Raymond Keaton
Registrant Name: Raymond Keaton
Administrative Email: Keaton@cybernauttech.com
Sponsoring Registrar: 广东时代互联科技有限公司
Name Server:ns1.softwaresupport-group.com
Name Server:ns2.softwaresupport-group.com
Registration Date: 2008-11-08 16:06
Expiration Date: 2009-11-08 16:06

domain: sunmaiamibich.ru
type: CORPORATE
nserver: ns1.softwaresupport-group.com.
nserver: ns2.softwaresupport-group.com.
state: REGISTERED, DELEGATED
person: Private person
phone: +7 910 3478712
e-mail: dmitrijstanislavskij@yandex.ru
registrar: REGRU-REG-RIPN
created: 2009.04.16
paid-till: 2010.04.16
source: TC-RIPN

Domain Name: peskufex.cn
ROID: 20090315s10001s50367993-cn
Domain Status: clientDeleteProhibited
Domain Status: clientTransferProhibited
Registrant Organization: 永也进出口公司
Registrant Name: 张龙
Administrative Email: alvin_555@yeah.net
Sponsoring Registrar: 易名中国
Name Server:ns2.dnsmytruedns.com
Name Server:ns1.dnsmytruedns.com
Registration Date: 2009-03-15 15:37
Expiration Date: 2010-03-15 15:37

Domain Name: 5rublei.com
Registrar: BIZCN.COM, INC.
Whois Server: whois.bizcn.com
Referral URL: http://www.bizcn.com
Name Server: NS1.EVERYDNS.NET
Name Server: NS2.EVERYDNS.NET
Name Server: NS3.EVERYDNS.NET
Name Server: NS4.EVERYDNS.NET
Status: clientDeleteProhibited
Status: clientTransferProhibited
Updated Date: 31-mar-2009
Creation Date: 30-jun-2008
Expiration Date: 30-jun-2010

Domain Name: dasretokfin.com
Registrar: REGTIME LTD.
Whois Server: whois.regtime.net
Referral URL: http://www.webnames.ru
Name Server: NS1.AFRAID.ORG
Name Server: NS2.AFRAID.ORG
Name Server: NS3.AFRAID.ORG
Name Server: NS4.AFRAID.ORG
Status: ok
Updated Date: 24-mar-2009
Creation Date: 18-feb-2009
Expiration Date: 18-feb-2010

Domain Name: tochtonenado.com
Registrar: UK2 GROUP LTD.
Whois Server: whois.hostingservicesinc.net
Referral URL: http://www.uk2group.com/
Name Server: NS1.EVERYDNS.NET
Name Server: NS2.EVERYDNS.NET
Name Server: NS3.EVERYDNS.NET
Name Server: NS4.EVERYDNS.NET
Status: clientTransferProhibited
Updated Date: 25-mar-2009
Creation Date: 25-mar-2009
Expiration Date: 25-mar-2010

domain: bizoplata.ru
type: CORPORATE
nserver: ns1.sevensearchon.ru
nserver: ns2.sevensearchon.ru
state: REGISTERED, DELEGATED
person: Private Person
phone: +7 495 0000000
e-mail: tuhov83@mail.ru
registrar: CT-REG-RIPN
created: 2009.01.23
paid-till: 2010.01.23
source: TC-RIPN

domain: startdontstop.ru
type: CORPORATE
nserver: ns1.sevensearchon.ru.
nserver: ns2.sevensearchon.ru.
state: REGISTERED, DELEGATED
person: Private Person
phone: +7 916 7843219
e-mail: ale32888049@yandex.ru
registrar: NAUNET-REG-RIPN
created: 2009.04.14
paid-till: 2010.04.14
source: TC-RIPN