[ << ALL_FEED ]

OWOWA

More in Indicators & C2

⚠️ OWOWAsome module, or IIS kOWOWAren

Researchers reported on the malicious IIS module Owowa, designed to intercept user credentials, back in 2021.

And in 2022, we talked about its evolution at OFFZONE. As practice shows, using this IIS module, attackers can compromise a large number of accounts in a fairly short period of time and obtain user passwords in plaintext.

The module is installed on the system with the command appcmd.exe install module. In all the samples we analyzed, the base class that implements the IHttpModule interface is called ExtenderControlDesigner. After launch, the module intercepts incoming requests using the PreSendRequestContent method.


  public class ExtenderControlDesigner : IHttpModule
  {
    public void Init(HttpApplication context)
    {
      context.PreSendRequestContent += this.PreSend_RequestContent;
    }
    private void PreSend_RequestContent(object sender, EventArgs e)
    {...

Attackers continued to use this fairly simple IIS module in their most high-profile attacks on Russian companies in 2024 as well. For example, while investigating one information security incident, the PT ESC team discovered a modification of the Owowa stealer. In the updated version, the attackers stopped writing compromised credentials to a log in the file system. Instead, they are stored in a HashSet in RAM.

Example of credentials that are written to the HashSet:


ExtenderControlDesigner.Data item = new ExtenderControlDesigner.Data
    {
      Id = text,
      UserName = userName,
      Password = pass,
      UserHostAddress = userHostAddress,
      XForwardedFor = xForwardedFor,
      DateTimeUtc = dateTimeUtc
    };
    bool flag2 = !ExtenderControlDesigner.hashSetData.Contains(item);
    if (flag2)
    {
      ExtenderControlDesigner.hashSetData.Add(item);
    }

The data, as before, is protected with the RSA-2048 algorithm, and the public key is hardcoded in the module. To obtain information about the number of unique records, you can search for the signature 42 5A 68 00; it is the account separator.


memoryStream.Write(new byte[]
    {
      66,
      90,
      104,
      0
    }, 0, 4);

Since the public key of the module used in attacks on companies in Russia is always identical and has not changed since 2022, we can assume that all attacks using it are carried out by a single group of attackers.

The attackers obtain the encrypted list of accounts by sending a valid GET request with the header username: ZaDS0tojX0VDh82.

Example of a GET request in IIS server logs:


2024-07-29 14:32:21 127.0.0.1 GET /owa/  443 ZaDS0tojX0VDh82 127.0.0.2 Mozilla/5.0+(X11;+Linux+x86_64;+rv:109.0)+Gecko/20100101+Firefox/115.0 - 401 1 1527 14

In addition to intercepting the username and password fields, interception of LOGON_USER and AUTH_PASSWORD was added in the new version.

In the latest version, the attackers removed the RunCommand function, which executed commands on the compromised host via powershell.exe.

IoCs:


Name               MD5
ClassLibrary2.dll  af6507e03e032294822e4157134c9909
ClassLibrary3.dll  2d240b6ceeaacd2e3dd52c9e7d3fb622
ClassLibrary3.dll  5cc433a2550bb7389f6c90521e7afa25
ExtenderControlDesigner.dll  967e7b6b048d628f36bbb4ca7b0f483f
ClassLibrary3.dll   e657eea3b9b7317e28ab4a89c1fa2177
ClassLibrary3.dll   6e6218aac341463496cca32f52b29013
ClassLibrary3.dll  4d66a3bbaf65a2ec36fd2d143c872ef6

YARA:


rule Owowa {
  strings:
    $s1 = "IHttpModule"
    $s2 = "PreSend_RequestContent"
    $s3 = "ExtenderControlDesigner"
$u1 = "283c00ecp774ag36boljbpp6" wide
    $u2 = "dEUM3jZXaDiob8BrqSy2PQO1" wide
    $u3 = "Fb8v91c6tHiKsWzrulCeqO" wide
    $u4 = "jFuLIXpzRdateYHoVwMlfc" wide
    $u5 = "oACgTsBMliysfk" wide
    $u6 = "uW4sSY1CAkN6kI6r6ByXUWnK" wide
    $u7 = "ZaDS0tojX0VDh82" wide
    $u8 = "zwa879pOX1NAmTom8m3aQvoZ" wide
  condition:
    uint16be ( 0 ) == 0x4d5a and ( 2 of ( $s* ) ) and ( 2 of ( $u* ) ) and filesize < 20KB
} 

Happy hunting!

#hunt #IOC #yara #dfir #detect #win
@ptescalator

More from oUth0R

More from oUth0R

More in Indicators & C2