OWOWA

More in Indicators & C2
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
- Hunting RATs by their own certificates 🕵️
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree:…
⚠️ OWOWAsome module, or IIS kOWOWAren
Researchers reported on the malicious IIS module Owowa, designed to intercept user credentials, back in 2021.
And in 2022, we talked about its evolution at OFFZONE. As practice shows, using this IIS module, attackers can compromise a large number of accounts in a fairly short period of time and obtain user passwords in plaintext.
The module is installed on the system with the command appcmd.exe install module. In all the samples we analyzed, the base class that implements the IHttpModule interface is called ExtenderControlDesigner. After launch, the module intercepts incoming requests using the PreSendRequestContent method.
public class ExtenderControlDesigner : IHttpModule
{
public void Init(HttpApplication context)
{
context.PreSendRequestContent += this.PreSend_RequestContent;
}
private void PreSend_RequestContent(object sender, EventArgs e)
{...
Attackers continued to use this fairly simple IIS module in their most high-profile attacks on Russian companies in 2024 as well. For example, while investigating one information security incident, the PT ESC team discovered a modification of the Owowa stealer. In the updated version, the attackers stopped writing compromised credentials to a log in the file system. Instead, they are stored in a HashSet in RAM.
Example of credentials that are written to the HashSet:
ExtenderControlDesigner.Data item = new ExtenderControlDesigner.Data
{
Id = text,
UserName = userName,
Password = pass,
UserHostAddress = userHostAddress,
XForwardedFor = xForwardedFor,
DateTimeUtc = dateTimeUtc
};
bool flag2 = !ExtenderControlDesigner.hashSetData.Contains(item);
if (flag2)
{
ExtenderControlDesigner.hashSetData.Add(item);
}
The data, as before, is protected with the RSA-2048 algorithm, and the public key is hardcoded in the module. To obtain information about the number of unique records, you can search for the signature 42 5A 68 00; it is the account separator.
memoryStream.Write(new byte[]
{
66,
90,
104,
0
}, 0, 4);
Since the public key of the module used in attacks on companies in Russia is always identical and has not changed since 2022, we can assume that all attacks using it are carried out by a single group of attackers.
The attackers obtain the encrypted list of accounts by sending a valid GET request with the header username: ZaDS0tojX0VDh82.
Example of a GET request in IIS server logs:
2024-07-29 14:32:21 127.0.0.1 GET /owa/ 443 ZaDS0tojX0VDh82 127.0.0.2 Mozilla/5.0+(X11;+Linux+x86_64;+rv:109.0)+Gecko/20100101+Firefox/115.0 - 401 1 1527 14
In addition to intercepting the username and password fields, interception of LOGON_USER and AUTH_PASSWORD was added in the new version.
In the latest version, the attackers removed the RunCommand function, which executed commands on the compromised host via powershell.exe.
IoCs:
Name MD5
ClassLibrary2.dll af6507e03e032294822e4157134c9909
ClassLibrary3.dll 2d240b6ceeaacd2e3dd52c9e7d3fb622
ClassLibrary3.dll 5cc433a2550bb7389f6c90521e7afa25
ExtenderControlDesigner.dll 967e7b6b048d628f36bbb4ca7b0f483f
ClassLibrary3.dll e657eea3b9b7317e28ab4a89c1fa2177
ClassLibrary3.dll 6e6218aac341463496cca32f52b29013
ClassLibrary3.dll 4d66a3bbaf65a2ec36fd2d143c872ef6
YARA:
rule Owowa {
strings:
$s1 = "IHttpModule"
$s2 = "PreSend_RequestContent"
$s3 = "ExtenderControlDesigner"
$u1 = "283c00ecp774ag36boljbpp6" wide
$u2 = "dEUM3jZXaDiob8BrqSy2PQO1" wide
$u3 = "Fb8v91c6tHiKsWzrulCeqO" wide
$u4 = "jFuLIXpzRdateYHoVwMlfc" wide
$u5 = "oACgTsBMliysfk" wide
$u6 = "uW4sSY1CAkN6kI6r6ByXUWnK" wide
$u7 = "ZaDS0tojX0VDh82" wide
$u8 = "zwa879pOX1NAmTom8m3aQvoZ" wide
condition:
uint16be ( 0 ) == 0x4d5a and ( 2 of ( $s* ) ) and ( 2 of ( $u* ) ) and filesize < 20KB
}
Happy hunting!


#hunt #IOC #yara #dfir #detect #win
@ptescalator
More in Indicators & C2
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
- He's not your gsocket
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC…
- Hunting RATs by their own certificates 🕵️
Our colleagues at Censys published a breakdown of the AsyncRAT family, describing an entire genealogical tree:…




