Translate

Posts mit dem Label Indonesia werden angezeigt. Alle Posts anzeigen
Posts mit dem Label Indonesia werden angezeigt. Alle Posts anzeigen

5/20/2014

SSH Rootkit Ebury
Category MALICIOUS IP: 203.153.108.227 (INDONESIA)
Listed at SPAMHAUS (CBL)
Linux, FreeBSD or some other form of UNIX

The IP Address 203.153.108.227 is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy or some other form of botnet. It was last detected at 2014-05-20 07:00 GMT (+/- 30 minutes), approximately 10 hours ago.

Screenshot of 203.153.108.227


We have detected that this IP is NATting for, or is infected itself, with a Linux (or possibly some other Unix-like system such as FreeBSD) Trojan spam mailer script. This is no joke. This infection is extremely dangerous as it can download anything it wishes, and needs to be removed ASAP.

We do not know how the malware got installed onto the machine, but we know a lot of what it does. The main thing we've seen it doing is sending staggering large volumes of email spam. But it can do a lot more than that, and that is the real danger.

NEW

Of late some of these infections are facilitiated by a SSH Rootkit called "ebury". See this link for more detail.

In most cases, this IP address would be that of a shared hosting environment. If you are a customer of this environment, you will almost certainly not be able to do anything about it, only the administrators of the hosting environment itself can. Please contact your administrators, and refer them to this page. If the administrators are reluctant to do anything please try to convince them, because there is nothing you can do to fix this problem.

For further Info, please read the Screenshots made earlier in the Day (at the End of this Post).

----------------------------------------------------------------------------------------------------------------------------------------------

Analysis:

MALICIOUS IP (PHISH RISK: RouterOS router configuration page):

Heuristic.LooksLike.HTML.Suspicious-URL.E
http://203.153.108.227/
  • https://www.virustotal.com/de/url/0a964415fc55b5cdc18c0d36636601c5510eb3646d5ecf9a7513698add2a9817/analysis/1400587343/
Heuristic.LooksLike.HTML.Suspicious-URL.E
  • https://www.virustotal.com/de/file/e23ec81b12a8af1412ab02d126086162b758908f1cf3e26a3f9797c3da242a74/analysis/1400587434/
  • http://quttera.com/detailed_report/203.153.108.227
  • http://zulu.zscaler.com/submission/show/4b322c1b6dd9f1d6b3f50243c20b5c37-1400587353
  • http://www.wpbl.info/cgi-bin/detail.cgi?ip=203.153.108.227

SPAMSERVER & DICTIONARY ATTACKER:
  • https://www.projecthoneypot.org/ip_203.153.108.227
  • http://www.senderbase.org/lookup/?search_string=203.153.108.227
LISTED AT SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/bl?ip=203.153.108.227
CBL LISTED:
  • http://cbl.abuseat.org/lookup.cgi?ip=203.153.108.227
OTHER MALICIOUS FILE:
http://203.153.108.227/winbox/winbox.exe
  • https://www.virustotal.com/de/url/d2563f5885fbe8174154ed20d776233135b80220e97d21b3b42b231c38e69311/analysis/1400602467/
  • https://www.virustotal.com/de/file/dcc31d4643e17d31db636c8ccc7e34d004876f18b5d48828ea37e2e8e5e19bcf/analysis/1400068690/
----------------------------------------------------------------------------------------------------------------------------------------------


4/23/2014

Category MALICIOUS IP: 203.153.99.142 (cds-id.com , dart.co.id)

"This IP is infected with a spam or malware forwarding link.
In other words the site has been hacked."


SPAMBOT & DICTIONARY ATTACKER
3 "Hacked" entries
46 "SPAM" entries
(INDONESIA)



The IP Address 203.153.99.142 is listed in the CBL (Composite Blocking List). This web site (IP) has a redirect that takes the user's browser to a spam or malware site. It's mainly fake russian pills or pornography.

The web server's host name is "www.dart.co.id", and this link has an example of the redirect: "http://www.dart.co.id/stylish.html?dijupiho".
http://www.dart.co.id/
  • https://www.virustotal.com/de/url/032f38a47d19c6c6e68793600ee7bdc011a82459e1a416079b208381566a4133/analysis/1398254023/
http://www.dart.co.id/stylish.html?dijupiho
  • https://www.virustotal.com/de/url/6f6fe170ab65546d0ee38ba507e945373c52e12d9de1b4edde3858dae7455fdd/analysis/1398254023/
Infected servers are usually shared web hosting environments running Cpanel, Plesk, Joomla or Wordpress CMS software that have become compromised either through a vulnerability (meaning the CMS software is out of date and needs patching), or users account information (userids/passwords) have been compromised, and malicious software/files are being uploaded by ftp or ssl.

We believe that these specific infections are frequently done by altering web server access control mechanisms (example, ".htaccess" files on Apache web servers), and causing the redirect to occur on all "404 url not found" errors. We would appreciate it if you can give us copies of the modifications that this infection has made to your system.



It probable that the change was made via SSL or ftp login using userid/password stolen from the "owner" of the hostname/domain. They should run anti-virus tools on their computers, and the password they use to access the web site should be changed immediately.

If you do not recognize the hostname www.dart.co.id as belonging to you, it means that some other account on this shared hosting site has been compromised, and there is NOTHING you (or we) can do to fix the infection. Only the administrator of this machine or the owner of www.dart.co.id can fix it.

--------------------------------------------------------------------------------------------------------------------------------------------

MALICIOUS IP FROM INDONESIA:
SPAMBOT, DICTIONARY ATTACKER
http://203.153.99.142/
  • https://www.virustotal.com/de/url/3eed7d8163d563a7f2cee883ca1b0627e6af286dcf89a63831ee311b14cb0f2f/analysis/1398250732/
  • https://www.virustotal.com/de/ip-address/203.153.99.142/information/
DOMAIN & HOSTNAME (See Senderbase as Reference):
http://cds-id.com/
  • https://www.virustotal.com/de/url/d58f4bda3839bea826584e8f98e3b0b1ed3ebeb72508f400a53770f60c1238af/analysis/1398252129/
HTML (406 Not Acceptable)
  • https://www.virustotal.com/de/file/390814aae53b4fe7b317f869b6bb97b242131cad27c8cdfd86e8ba70a677653f/analysis/1398252281/
NUMBER OF SPAM-MAILS RECEIVED FROM THIS IP: 174
DICTIONARY ATTACKS FROM THIS IP: 21
  • https://www.projecthoneypot.org/ip_203.153.99.142
LISTED AT SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/bl?ip=203.153.99.142
LISTED AT CBL:
  • http://cbl.abuseat.org/lookup.cgi?ip=222.165.193.218&.pubmit=Lookup
LISTED AT SPAMCOP:

In the past 78.1 days, it has been listed 19 times for a total of 18.9 days

Causes of listing:
System has sent mail to SpamCop spam traps in the past week (spam traps are secret, no reports or evidence are provided by SpamCop)
  • http://spamcop.net/w3m?action=checkblock&ip=203.153.99.142
LISTED AT SORBS:
Current Listings (active)

  • 3 "Hacked" entries (01:08:09 16 Apr 2013 GMT)
  • 46 "Spam" entries (20:13:30 30 May 2013 GMT)
 
Historical Listings (inactive)
  • 22 "Spamvertised" entries (21:37:31 22 Apr 2013 GMT)
http://www.au.sorbs.net/lookup.shtml
LISTED AT CISCO SENDERBASE:

Fwd/Rev DNS Match: NO
EMAIL REP.: POOR
  • http://www.senderbase.org/lookup/?search_string=203.153.99.142
SEE ALSO:
NETCRAFT: 7/10
  • http://toolbar.netcraft.com/site_report?url=203.153.99.142

4/18/2014

Category MALICIOUS IP: 203.153.100.82

Infected with a spam sending trojan, proxy or some other form of botnet.
It HELOs as a bare IP address
(INDONESIA)

The IP Address 203.153.100.82 is listed in the CBL (Composite Blocking List). It appears to be infected with a spam sending trojan, proxy or some other form of botnet. It was last detected at 2014-04-18 18:00 GMT (+/- 30 minutes), approximately 1 hours ago.

It has been relisted following a previous removal at 2014-04-09 01:07 GMT (9 days, 17 hours, 55 minutes ago).

The listing of this IP is because it HELOs as a bare IP address (A bare ip address looks like: "54.33.33.5"). It is not HELO'ing as itself ("203.153.100.82"). Not only is this a violation of RFC2821/5321 section 4.1.1.1, it's even more frequently a sign of infection.




These listings are often a sign of a compromised SSH account. If you are running a SSH service (especially on Linux), please check your ssh server logs (often/var/log/auth.log) for logins from unusual IP addresses not normally associated with that login id. If you find any, secure the associated account. This usually means changing the password or disabling the account.

If it's a mail server, see naming problems for details on how to diagnose and fix the problem. If you are running Symantec Protection Center, this appeared to be a known issue in the past. See this Knowlege Base item. Their KB item was updated October 18, 2010 to indicate that they now understand the issue. The KB item indicates that the problem will be resolved in a "future build", but no ETA was provided. If you have SPC's email notification feature turned on, we recommend checking through the Knowledge Base item to see if your version has this issue fixed. If not we recommend turning SPC's notification feature off before delisting your IP address as a temporary workaround.

--------------------------------------------------------------------------------------------------------------------------------------------

MALICIOUS IP:




Heuristic.LooksLike.HTML.Suspicious-URL.K
SPAMBOTSERVER, COMMENT SPAMMER, DICTIONARY ATTACKER, MALWARE
http://203.153.100.82/
  • https://www.virustotal.com/de/url/4d0bf7e41c8dceaebbafa1bf0c70c8b1560a49ce397a92df5a1913a979f70f37/analysis/1397848027/
  • https://www.virustotal.com/de/ip-address/203.153.100.82/information/
Heuristic.LooksLike.HTML.Suspicious-URL.K
  • https://www.virustotal.com/de/file/8822bad3d62e9fbc8dc272644c42f81e4fec540ef7f05c9fd7bcaa26aee7a61b/analysis/
HOSTNAME:
http://ip-82-100-static.velo.net.id/
  • https://www.virustotal.com/de/url/85f9e6aa401e85da826c0d9590b8b671a24afac3000580f79754982b0f9ffadf/analysis/1397850756/

IP BLACKLISTED AT:
1) SPAMHAUS (CBL):
  • http://www.spamhaus.org/query/ip/203.153.100.82
2) COMPOSITE BLOCKING LIST:
  • http://cbl.abuseat.org/lookup.cgi?ip=203.153.100.82
3) SPAMCOP:
  • http://www.spamcop.net/w3m?action=checkblock&ip=203.153.100.82
4) CISCO SENDERBASE:
  • http://www.senderbase.org/lookup/?search_string=203.153.100.82
5) BLOCKLIST.DE:
  • http://www.blocklist.de/en/view.html?ip=203.153.100.82
6) PSBL.ORG:
  • http://psbl.org/listing?ip=203.153.100.82
7) WPBL.INFO:
  • http://www.wpbl.info/cgi-bin/detail.cgi?ip=203.153.100.82
8) PROJECT HONEYPOT:
  • https://www.projecthoneypot.org/ip_203.153.100.82
9) SORBS:
  • http://www.au.sorbs.net/lookup.shtml
10) NiX SPAM:
  • http://www.dnsbl.manitu.net/lookup.php?language=en&value=203.153.100.82
------------------------------------------

SEE ALSO:
  • https://urlquery.net/report.php?id=1397848399616
  • http://zulu.zscaler.com/submission/show/0d60892bc9e925ace8bf7a1c422b7358-1397848147
http://203.153.100.82/winbox/winbox.exe
  • https://www.virustotal.com/de/url/2e48031a59a5f99f23b91508988285232203405cb8640f3c8c40c24e1a702284/analysis/1397848218/
  • https://www.virustotal.com/de/file/eabfa1fd55a53367b901364486f5a5607b9ab04ad94403b7d0fc12509ad85321/analysis/

1/31/2014

baliwirama.com
NEWLY DETECTED MALWARE SITE FROM INDONESIA
Infected with: JS/Agent.NKW



MALWARE SITE: JS/Agent.NKW (INDONESIA)
baliwirama.com
  • https://www.virustotal.com/de/url/dbc20c54922fb960055179e0aa8265d0a54b3ece538884d44af3bf19f60f6b64/analysis/1391188710/

INFECTED WITH: JS/Agent.NKW
  • https://www.virustotal.com/de/file/f797dc468d8b6c3bd7f7289da9460634b9760d267efd8a62f160d4d43e66eca4/analysis/1391189355/
  • https://www.virustotal.com/de/file/a242aac8cef9c83b268245fc66798230e4ad477e1c4d124996a8741180d0d411/analysis/1391190176/
  • http://jsunpack.jeek.org/dec/getfile?hash=346e/58b83054013e0939980028cad3726695a957
  • http://app.webinspector.com/public/reports/19817951
  • http://sitecheck.sucuri.net/results/baliwirama.com



IP:
101.50.1.27
  • https://www.virustotal.com/de/url/15c15f75ada5333d59d57b50fca49cd53f32c23f81292942f03a9ed132948ffb/analysis/1391190377/
Bad Host Appearances: 15
  • https://www.projecthoneypot.org/ip_101.50.1.27
  • https://www.virustotal.com/de/ip-address/101.50.1.27/information/

1/24/2014

NEW MALWARE CODE:
Trojan-Clicker.HTML.IFrame.api & Trojan.JS.Agent.cfe & Trojan.JS.Agent.cff & Trojan.JS.Agent.cfg
found on
iprostate.org (FRANCE) & 89.161.179.50 (POLAND) & aixuaxoh.corpellis.com (FRANCE)






MALICIOUS DOMAIN INFECTED:
iprostate.org
  • https://www.virustotal.com/de/url/60a26b91beaa3f637236fd90c0337dbbbbca80eeef890fe65ccf4e08d1e47dcf/analysis/1390565063/


NEW MALICIOUS CODE: Trojan-Clicker.HTML.IFrame.api
  • https://www.virustotal.com/de/file/e985726550f1e3d0e509d7b137b0fb8e638e0206be3dac95aa3374b68b75f9c4/analysis/1390565399/
  • http://wepawet.iseclab.org/view.php?hash=95b6d14c905bb68bb00acc216aeee6ea&t=1390565037&type=js
  • http://jsunpack.jeek.org/?report=544ce445dec7f573fde5dbae940cf8e1a877d501
  • http://www.urlvoid.com/scan/iprostate.org/
--->
 
DOMAIN: (POLAND)
89.161.179.50
  • https://www.virustotal.com/de/url/3eb048bbc38acf47bc1fc56d6ba0bca27af49befb9501ba7e6217f1fd1f855a8/analysis/1390566648/
INFECTED WITH: JS:Includer-APY [Trj] & Trojan.JS.Blacole.Gen
  • https://www.virustotal.com/de/file/e7b478aeb97b77d2b7603ec9b3c01a67c9283b5773dc220fa181aec6b106502c/analysis/1390566981/
  • http://urlquery.net/report.php?id=8956027
  • http://wepawet.iseclab.org/view.php?hash=71f5f7a455f222fa3632d2fa5513d733&t=1390567166&type=js
  • http://jsunpack.jeek.org/?report=d0d24f41d2763479e8bdd80e573321b1495b3ee5

89.161.179.50/AC_RunActiveContent.js
  • https://www.virustotal.com/de/url/46559ae6b42b98f6a5636e639f20cf218a21dbe4e74bde08627368d5e4004efa/analysis/1390567518/
NEW MALICIOUS CODE: Trojan.JS.Agent.cfg
  • https://www.virustotal.com/de/file/8dd5ca26ad29dbb78104867199d67d6cf93115b3af206c434470d8f896c6df6b/analysis/1390567519/
SPECIFIC REMOTE LINK:
89.161.179.50/pub/MQZ11znP.php?id=27367098
  • https://www.virustotal.com/de/url/db69ece38e9a7d922b2fc7f4363d7c763e1f7393e7f60aeb049334e56b25324d/analysis/1390565939/

NEW MALICIOUS CODE: Trojan.JS.Agent.cfe
  • https://www.virustotal.com/de/file/da207e5f0c04455f4a759e81fa7930be4e92bff35786ac69fa647c31588bd0dd/analysis/1390565729/
--->
DOMAIN:
aahaimie.corpellis.com
  • https://www.virustotal.com/de/url/74b62220ddfd4194ec8353076c5a47dc6d75169cee68a0b1b04183042ea90971/analysis/1390566439/

SPECIFIC REMOTE LINK:
aahaimie.corpellis.com:8000/kbgvqiqyg?bwiossxvihjt=6621548
  • https://www.virustotal.com/de/url/716660bdafda01452ff3383dc54d57578b33620ce3f2b60c5a04b085262aa26b/analysis/


NEW MALICIOUS CODE: Trojan.JS.Agent.cff
 

  • https://www.virustotal.com/de/file/e7b478aeb97b77d2b7603ec9b3c01a67c9283b5773dc220fa181aec6b106502c/analysis/
--->

DOMAIN: (UKRAINE)
91.217.91.104
  • https://www.virustotal.com/de/url/600b14a0354cde620db64861fd6865d7395f8e3cbb744240c842ab09f01fb577/analysis/1390568047/
91.217.91.104//?id=1&se_referer=&charset=utf-8
  • https://www.virustotal.com/de/url/b1edaeb1d47b89d2747466822d49aba12752e79a004de1643bca1f70d03f7584/analysis/1390568170/
  -----------------------------------------------------------------------------------

OTHER DOMAINS INVOLVED


1) DOMAIN: (U.S.)
akmc-engg.com
  • https://www.virustotal.com/de/url/704c9b0de1bad345c1af1094c1f130a9e3af891aeb5e01aca4634e189ad2cb7f/analysis/1390568688/
SPECIFIC LINK:
akmc-engg.com/cO5hpbRz.php?id=27367098
  • https://www.virustotal.com/de/url/15901dee78bb8e1a89187df6e9482f84379cea7ba8f78d2fbb79755058286f19/analysis/1390568698/
  • https://www.virustotal.com/de/file/afee46604646db0e32c46dd0f423e1da7c2f9d2a2be31990ab287585f825ba83/analysis/1390566117/

----------------------------------------------------------------------------------- 

2) DOMAIN: (U.S.)
karocchio.eu
  • https://www.virustotal.com/de/url/fff4fdeb39bb94d2696dc08f21a116135f90045b60a1c634c48d6f75a9efc81d/analysis/1390569353/

-----------------------------------------------------------------------------------



3) DOMAIN: (ICELAND)
bobomo.mynumber.org
  • https://www.virustotal.com/de/url/315bdb1eaf95fcaeb3bf417a5185a4b1b7a69c888a133707df227201cd8c7921/analysis/1390569679/
Dynamic DNS URL
  • http://urlquery.net/report.php?id=8956217
  • http://www.urlvoid.com/scan/bobomo.mynumber.org/

----------------------------------------------------------------------------------- 

4) DOMAIN: (INDONESIA)
inez.co.id
  • https://www.virustotal.com/de/url/a3a8f91034a79665ee1a2c92c8a7d4dcb8536440f4acf9472c2a6650046c4445/analysis/1390570093/
  • https://www.virustotal.com/de/file/7212d36a24d79b733ee726e38c0db6734e4a55b290a2680504de57683ed49a07/analysis/1390570210/
  • http://www.urlvoid.com/scan/inez.co.id/
SPECIFIC LINK (INFECTED):
inez.co.id/edocus/tSB0NuE7.php?id=19034511
  • https://www.virustotal.com/de/url/17b184b7e0f250eda98b7314b3e2316a6540701029647b3814705fddbbde9c57/analysis/1390570447/
 
INFECTED WITH: HEUR:Trojan.Script.Generic
  • https://www.virustotal.com/de/file/521de2e5d3c5140f17a06400840f7002bd2ec33f6e085171fc3df768efb4413f/analysis/1390570748/
  • https://www.virustotal.com/de/file/b671d0390dcde53d9b0fd1e0bd3a8b145409e57f58b00bc47d11c449037a7468/analysis/1390570733/
  • http://jsunpack.jeek.org/?report=d9152fba62fa51859e1955854a0a447e785e73c0

----------------------------------------------------------------------------------- 

5) DOMAIN: (FRANCE) Dynamic DNS URL
www.urofrance.org
  • https://www.virustotal.com/de/url/ad735bc21d8858b255a8688cd78c3d04ee7ccf483dfea7e0147a5b92915774f5/analysis/1390571126/
www.urofrance.org/congres-et-formations/calendrier.html
  • https://www.virustotal.com/de/url/de91fb23ff3add27e1b0b61c9e6a57043ffe33c927a4bd40201ed79e2ac0f03b/analysis/1390571128/
Dynamic DNS URL
  • http://urlquery.net/report.php?id=8956326
-----------------------------------------------------------------------------------

6) DOMAIN: (SWITZERLAND)
www.healthonnet.org
  • https://www.virustotal.com/de/url/ffe8ada5a6b6a7eca744223b20087bebb2fe5339ef3b9f983f2e38b62056dada/analysis/1390572210/
  • http://quttera.com/detailed_report/www.healthonnet.org
----------------------------------------------------------------------------------- 

7) DOMAIN: (FRANCE) - LINK TO iprostate.org found
www.spdesigner1.com
  • https://www.virustotal.com/de/url/aabf7f0ce3e2507fe39cf3a2d7c1488ec96e81bbec5899771bad3944845639e9/analysis/1390573845/
www.spdesigner1.com/js/carouFredSel.js
  • https://www.virustotal.com/de/url/87ff75c131dd793787cc905b4c86b65fa62cea025f29ce837efc9863bf003919/analysis/1390574236/
PUA
  • https://www.virustotal.com/de/file/babe4ebb46ac2dbe59de631e65409bd31133a3c48b0e3069d8543aed9af13f98/analysis/1386751724/
LINK FOUND TO: iprostate.org
  • http://www.UnmaskParasites.com/security-report/?page=www.spdesigner1.com