As a computer enthusiast and security researcher, I have always found the intricacies of low-level programming and hacking to be intellectually stimulating and rewarding. I am particularly interested in the fields of reverse engineering, malware analysis, and binary exploitation, which involve techniques such as disassembling and analyzing binary code, identifying vulnerabilities and weaknesses in software.
Today I am going to be writing a concept which seems really interesting thus let’s get started.
In
August 2010, the first Android Trojans, FakePlayer and DroidSMS, were
discovered in the wild, From that moment on, an explosion occured in the
android malware space. Mostly trojans, Android malware covers a
comprehensive range of known malware activities including but not
limited to stolen PII data, dialed premium phone numbers, botnets,
scareware and ransomware, recorded phone calls,photos,backdoor, and root
privileges which seems really hard to detect in order to prevent such
attacks as being a malware analyst :) you must check phone
simultaneously and not downloading free software.there are a lot of
malware types but I am not going to cover at all.
FakePlayer
One
of the first discovered Android malware, FakePlayer, ws a Trojan horse
that attempted to send premium rate SMS messages without the user’s
consent to a hardcoded phone number.It spread under the mask of a movie
player app that was manually installed. The player did not work very wel
but sending SMS messaged worked brilliantly.The payload of SMS messages
only occurs the first time the app runs. A SQLlite database called
movieplayer.db.
DroidSMS
Another
one of the first discovered Android malware, DroidSMS is a classic SMS
fraud app that sends messages to premium rate phone numbers.
FakeInst
Existing
primarily in Russia, FakeInst masquerades as highly popular apps such
as Skype and Instagram. It sends SMS messages to premium rate numbers.
It was one of the first Android malware to be widely discovered in the
wild. It was also one of the first families to have several variants
such as JiFake, RuWapFraud, Opfake, and DepositMobi.
we
are living in 2021 but that does not mean we are %100 being protected
by malware threats.It actually means that the IT war has been started
thus take your control and defeat threat actors:)
GamblerSMS
was viewed as spyware and the official name would show as SMS SPY. It
was capable of monitoring every incoming and outgoing SMS message, and
recording every outgoing phone call. The user was allowed to choose
another phone number to receive the SMS messages and an e-mail address
to send the recorded phone calls. The author kept a copy of all recorded
phone calls.
Nickyspy
Nickyspy
was a Trojan that collected system-specific data from the device. The
device’s IMEI was sent the data via SMS message to the number
15859268161. It also requested permission to do the following: access
cell-ID and WIFI location and updates, GPS location, and WIFI network
details; low-level access to power management, readonly access to phone
sta
DogWars
This
malware sent SMS messages to all contacts on the device. It was a
repackaged version of a game called Dog Wars. Its service name, 22
Android Malware and Analysis which started on every restart of the
device, was com.dogbite.Rabies. Upon installation, the following
permissions were requested: open network sockets, make the phone
vibrate, read-only access to phone state, read user’s contacts data,
receive broadcast messages sent after the system finishes booting, and
send SMS messages
I
was willing to explain everything about these awesome Trojans, but if I
were to do that, the tension was then not being surprised, this series
will be written constantly do not worry thus everyone!!!.,
Today, i will be analyzing a malware called “BPFDoor”. This malware was discovered in 2022.
Before analyzing malware, don’t forget using VM and never forget Host Only connection.
Overview
BPFDoor
is a Linux/Unix malware backdoor which allows threat actors to
distantly connect to Linux shell to gain complete access to a
compromised device.
This
malware shall be dangerous when its being dropped in your Linux/Unix
environment. This malware has specifically been created to allow threat
actors to connect remotely to a compromised system, and does not need
for any open ports to be run in your machine.BPFDoor is a passive
malware, which means that it can listen one or more ports for incoming
packets. The malware uses a Berkeley Packet Filter sniffer, that works
at the network layer. The point of view of mine would say that this
malware has roughly the same functionality what RAT has. The BPFDoor
also renames itself after infecting a system as an evasion technique.
So
far, we have covered about this Linux/Unix malware briefly. I will
explain now what kind of packets it uses. BPFDoor only parses TCP,UDP,
and ICMP packets, this checks for the specific data value.Moreover, if
TCP and UDP packets have the right “magic”, and also the right password,
malware will immediately take his action to get the reverse shell with
help of supported commands.
Take your coffee and let’s analyze this malware briefly.
Basic Static Malware Analysis
We
start off our exploration to analyze malware statically, to see what
kind of malware family it comes from. We will not run this ELF file by
this step.
What you should know before analyzing:
Using antivirus tools to confirm maliciousness
Using hashes to identify malware
Gleaning information from a file’s strings, functions, and headers
Each
technique might be able to provide different information, it will
differ on your goals what you need. It is important to gather much
information as possible.
It’s an ELF file
MD5SUM
In order to understand whether this malware is being packed or not you can use this command “ hexdump -C <filename> |grep -C 1 UPX” this command specifically searches for UPX.
After this process, we used “Certutil” to identify “md5” but however, you can also use “PESTUDIO”
In
some cases, the detections are generic and inaccurately flag the above
Solaris variant as Linux malware, although it is not a Linux binary.
12 strings are blacklisted
Socket: Sockets allow communication between two different processes on the same or different machines
We could also use PEID to identify packers.
What is PEID ?
In
order to detect packed files we can use PEID. You are able to use PEID
to detect the type of packer or compiler employed to build an
application. This is not EXE file but we can convert it from ELF to EXE
but it shall not work because of magic number of this file but lets
try!!
As you can see, it will not work!
I will put the md5sum to virustotal to check the malware family.
In order to confirm this we just copy the hexs to online hex program.
Awesome. We are going to analyze this source code more in depth.
Interesting, we have a function called “getshell()” I will be able to analyze this function.
We also have rc4_ctx, crypt_ctx, decrypt_ctx
RC4: also known as Rivest Cipher 4 is a form of stream cipher.
It encrypts messages one byte at a time via an algorithm. Plenty of
stream ciphers exist, but RC4 is among the most popular. It’s simple to
apply, and it works quickly, even on very large pieces of data.
It will be superb if we can detect that function of “getshell()” to better understand what this function does.
It might seem that the C&C server selects random ephemral port. Because as I mentioned above that “it
can listen on one or more ports for incoming packets from one or more
hosts, that attackers can use to send commands remotely to the
compromised network.” It does not be used for specific port.
tv[0].tv_sec = 1225394246. This part is interesting because; The binary copies itself to /dev/shm/kdmtmpflush which is only in RAM and clears out every reboot.
Have you heard about “epoch” let me explain what it is. This is not trivial.
What is epoch?
In
a computing context, an epoch is the date and time relative to which a
computer’s clock and timestamp values are determined. The epoch
traditionally corresponds to 0 hours, 0 minutes, and 0 seconds
(00:00:00) Coordinated Universal Time (UTC) on a specific date, which
varies from system to system.
If we understand what “epoch” is, we will be able to convert this epoch to human-reable datetime.
This piece of code is of course not supreme.:)
this
could have been generated randomely by the author. This malware has
advantages to do his job; This is supreme because, we spoken about
Berkeley packet filter, and this shall bypass firewall rules in
Linux/Unix.
Bypassing Local Firewall
An
application layer firewall implements a basic rule-based configuration
(very basic). In the absence of its explicit use, it allows
authorizations and listening services to communicate with and from the
system — to ensure that it is “hidden” on the network. When it comes
bypassing firewall this malware will do his job very well. After running
this malware it will rename /dev/shm/ to /dev/shm/kdmtmpflush and it runs itself as well.
This is the directory in Linux→
After running this file, the file will be deleted automatically. You can always check the process Id /proc/<PID> and doing a simple ls command to be able to find the real ID of that malicious process. You should be a root user to run this malware.
I found an awesome article about this step while its doing his malicious activity.
Look at line 683 system() it executes /sbin/iptables.
what is an Iptable?
Iptables are basically a firewall in Linux. The iptables firewall operates by comparing network traffic against a set of rules.
The rules define the characteristics that a packet must have to match
the rule, and the action that should be taken for matching packets.
Windows does not have equilavent of iptables like what Linux has.
After that it will sleep 1 second and while this process is done, it will create sock that listens on port specified earlier.
We
can read from this source that it deletes all directories and
subdirectories from /dev/shm and then copies the string to /dev/shm
again I reckone that it will copy /kdmtmpflush with a permission of 755 ,and after the run will this file be permanently deleted or visible either.
Part
of BPFDoor’s techniques to evade detection is to rename the binary to
appear as a normal Linux daemon using the choices above. I forgot to
mention that;
Hackers leverage compromised Taiwan-located routers as VPN tunnels to run BPFDoor via Virtual Private Servers (VPSs).
This malware uses solaris vulnerability to get root privilege.
In
order for BPFDoor to launch, the threat actor would need to upload the
malicious binary to a server. The best lines of defense are ensuring
that virus and malware signatures are up to date to catch any potential
indicators and creating rules within environments to help detect the
seemingly undetectable.