[ << ALL_FEED ]

Stealer infection: a new USB strain

More in Malware

  • This is Siemens...

    Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…

  • Anti-antivirus

    Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…

  • .exe .docm .xlsm

    .exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic.…

  • Operation Chewbacca

    At the end of June, the PT ESC team, during incident investigations, discovered a new group…

  • Your Zimbra server is at risk

    Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…

Stealer infection: a new USB strain 👾

Today we’re going to talk about an unusual modification of the WorldWind stealer that we discovered. It is a real, bona fide virus that spreads through close contact between an infected device and a USB drive and causes not only the leakage of confidential information but also the loss of a priceless collection of software on external drives.

The sample, like its predecessors, still continues to use the icanhazip, mylnikov.org services + Google Maps to determine the external IP address and geolocation (screenshot 1). The implementation of the information collection module has also not changed, except for a couple of structures.

🐔 The mutations, however, affected the network part and the stealer’s feature set. It no longer transmits information via Telegram. Instead, messages fly off to the attackers’ C2 server in the following order: checkin → exfiltration → close. The formats of these messages are presented in screenshot 2.

The functions for stealing VPN configs and passwords from game launchers and Wi-Fi have also disappeared from the stealer. But in return, it has developed the ability to spread aggressively via USB drives. If there are executables on the external drive, the stealer will delete them and write itself under their names (screenshot 3).

Don’t you find that it feels like the good old days of wild virus writing? 😏

To reduce the risk of infection, get your signature vaccinations and undergo antivirus checkups.

While we’re at it, let’s cover the stealer with a rule that detects checkin:


alert tcp any any -> any any (msg: "STEALER [PTsecurity] WorldWind checkin"; flow: established, to_server; stream_size: client, <, 80; stream_size: server, =, 1; content: "|46 00 00 00|"; startswith; fast_pattern; content: "{|22|id|22 3a| 0"; within: 8; content: "|22|hwid|22 3a|"; within: 10; content: !"|20|"; distance: 2; within: 32; content: "|22|country|22 3a|"; distance: 32; content: !","; distance: 0; classtype: trojan-activity; metadata: malware_family WorldWind; sid: 1; rev: 1;)

IOCs:


84d52de2b69e14f26259da07297e02eb2c4ac32045a690f65a267fe931da0433
20.208.136.72:12346

Stay healthy and happy hunting!

#hunt #C2 #detect #ioc #malware #network #suricata
@ptescalator

More from global_author

More from global_author

More in Malware

  • This is Siemens...

    Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…

  • Anti-antivirus

    Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…

  • .exe .docm .xlsm

    .exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic.…

  • Operation Chewbacca

    At the end of June, the PT ESC team, during incident investigations, discovered a new group…

  • Your Zimbra server is at risk

    Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…