[ << ALL_FEED ]

Through blockchain to data

More in General

Through the blockchain to the data ⭐️

Researchers from Socket and Checkmarx have reported on an interesting malicious campaign in NPM. The attackers mimicked plugins for Puppeteer and blockchain clients. A smart contract in the Ethereum blockchain is used to obtain the IP address of the current command server 😦

Of the curious details — the library code uses several comments in Russian:

• console.error("Ошибка при получении IP адреса:", err);
• console.error("Ошибка при запуске файла:", _0x88fda8);
• console.error("Ошибка установки:", _0x14ce94);

Socket suggests being cautious with attribution, as this could be a consequence of code reuse or done deliberately.

Depending on your platform, one of the following executable files will be downloaded and run: node-win.exe, node-linux, node-macos. Below we will refer to them as agents.

We studied the campaign in more detail and discovered several more interesting details.

1️⃣ Despite the fact that Socket and Checkmarx cite only one IP address as a network IoC, the function for assigning a new URL in the smart contract was called several times. In total, we know of five addresses, and the earliest of them was http://localhost:3001 😈, the rest are VPS servers.

2️⃣ The agent can establish persistence in the system and, just like the JS libraries that download and run it, obtain C2 through the blockchain. The executable file is a Node.js Single Executable Application, which packages the project and the JS interpreter into a single file.

3️⃣ The agent periodically polls the server for commands in the form of JS code. The first payload collects information about the victim’s system: CPU model, number of cores, amount of RAM, data about the graphics card. The collected information is sent back to the server.

4️⃣ The agents simply receive true if there are no new tasks. Of the interesting details: the root of the HTTP server returned the following error:

{"statusCode":404,"message":"ENOENT: no such file or directory, stat '/root/botnet-server/public/index.html'"}
Code language: JSON / JSON with Comments (json)

This line sheds light on the possible goals of the attacker ☕️

IoCs:

http://194.53.54.188:3001
http://193.233.201.21:3001
http://45.125.67.172:1337
http://45.125.67.172:1228
194.53.54.188
193.233.201.21
45.125.67.172
Code language: YAML (yaml)

#ti #npm #pyanalysis #scs
@ptescalator

More from ti_author

More from ti_author

More in General