Ammyy Admin hit by malware once more with World Cup used as camouflage

von Satoshi Nakamoto

Ammyy Admin hit by malware once more with World Cup used as camouflage


Web site altered to serve a malware-tainted model of in any other case official software program with the worldwide occasion in Russia appearing as a smokescreen




Customers who downloaded the free distant administration device Ammyy Admin from its official web site ammyy.com on June 13 or 14, beware!


In keeping with ESET’s evaluation, inside that timeframe the web site was compromised to serve a malware-tainted model of this in any other case official software program. So as to add an attention-grabbing twist to the incident, the attackers tried to cover their malicious exercise behind the model of the continuing FIFA World Cup.


It feels nearly like touring again in time. In October 2015, the web site providing a free model of Ammyy Admin software program began serving malicious code linked to the cybercrime group Buhtrap. Now historical past repeats itself and the positioning appears to be compromised once more. The difficulty was first noticed by ESET researchers shortly after midnight on June 13 and persevered till the morning of June 14.


Distant admin with Kasidet bot on the facet

Customers who downloaded software program from ammyy.com within the aforementioned timeframe obtained extra than simply the requested software program – a part of the bundle was additionally a multipurpose Trojan and banking malware detected by ESET as Win32/Kasidet. ESET advises all potential victims to take precautionary measures and use a dependable safety product to scan and clear their units.


Win32/Kasidet is a bot that's offered in underground crime markets and is actively utilized by varied cybercriminal teams. The construct detected on the ammyy.com web site on June 13 and 14, 2018 had two predominant objectives:


Stealing recordsdata that might include passwords or entry information for cryptocurrency wallets and accounts of the victims. It achieves this by trying to find filenames that match the next masks and by sending them to the C&C server:
bitcoin
cross.txt
passwords.txt
pockets.dat

2. Reporting processes whose names embrace any of the next strings:


armoryqt
bitcoin
exodus
electrum
jaxx
keepass
kitty
mstsc
multibit
putty
radmin
vsphere
winscp
xshell

The URL of the command and management server, hxxp://fifa2018begindata/panel/duties.php, was additionally attention-grabbing – it appears as if it was designed by the attackers to make use of the continuing FIFA World Cup as cowl for his or her malicious community communication.


ESET researchers noticed a number of similarities to the 2015 assault. Again then, attackers have been misusing ammyy.com to serve quite a few malware households, altering them on an nearly every day foundation. Within the 2018 case, ESET programs detected solely Win32/Kasidet, nevertheless, the obfuscation of the payload modified on three events, in all probability to keep away from detection by safety merchandise.


One other similarity between the incidents was the an identical identify of the file – Ammyy_Service.exe –containing the payload. The downloaded installer AA_v3.exe might look official at first sight, nevertheless the attackers have used SmartInstaller and constructed a brand new binary, which drops the Ammyy_Service.exe earlier than putting in Ammyy Admin software program.


Conclusion

As the positioning has been equally compromised previously, ESET recommends that customers run a dependable up-to-date — and up to date — multi-layered antimalware answer each time they attempt to obtain software program from this web site.


Whereas Ammyy Admin is a official device, it has a protracted historical past of being misused by fraudsters. Consequently, a number of safety merchandise, together with ESET’s, detect it as a Probably Unsafe Software. Nonetheless, it's nonetheless broadly used, largely in Russia.


We notified Ammyy in regards to the challenge. As Ammyy Admin is broadly used, we really feel you will need to warn its customers about its present safety points.


Particular due to Jakub Souček, who pointed us to the compromise and supplied the evaluation.


IoCs

ESET detection names
Win32/Kasidet
SHA-1 hashes
Installer
6D11EA2D7DC9304E8E28E418B1DACFF7809BDC27
6FB4212B81CD9917293523F9E0C716D2CA4693D4
675ACA2C0A3E1EEB08D5919F2C866059798E6E93
Win32/Kasidet
EFE562F61BE0B5D497F3AA9CF27C03EA212A53C9
9F9B8A102DD84ABF1349A82E4021884842DC22DD
4B4498B5AFDAA4B9A2A2195B8B7E376BE10C903E
C&C Servers
fifa2018begindata




Ondrej Kubovič 11 Jul 2018 - 02:57PM


(function() (window._fbq = );
if (!_fbq.loaded)
var fbds = document.createElement('script');
fbds.async = true;
fbds.src = "http://connect.facebook.net/en_US/fbds.js";
var s = document.getElementsByTagName('script');
s.parentNode.insertBefore(fbds, s);
_fbq.loaded = true;

_fbq.push();
)();
window._fbq = window._fbq || ;
window._fbq.push();
(function(d, s, id)
var js, fjs = d.getElementsByTagName(s);
if (d.getElementById(id)) return;
js = d.createElement(s); js.id = id;
js.src = "http://connect.facebook.net/en_US/sdk.js#xfbml=1&version=v2.3";
fjs.parentNode.insertBefore(js, fjs);
(document, 'script', 'facebook-jssdk'));


Source link

Read the full article
Porträt von Satoshi Nakamoto

Satoshi Nakamoto

Zur Person

Satoshi Nakamoto