Attacks/Breaches
7/26/2012
08:53 AM
Connect Directly
RSS
E-Mail
50%
50%

Mahdi Malware Makers Push Anti-American Update

Spy malware, seemingly built by Iranians, gets update that searches for "USA" and "gov" on targeted machines, security researcher says at Black Hat.

Seculert found numerous clues suggesting that the malware had been built by Iranians. "We were able to identify strings within the communication that were in Farsi. Also, part of the strings were dates that were in the Persian calendar, which is different than the Gregorian calendar," said Raff, noting that most developers prefer to code in their native tongue.

Previously, four C&C servers controlled all Mahdi infections. "The interesting part is that one server is used mostly with Israeli targets, while the other three are for Iranian and Arab targets," said Raff. "The one used for Israel also targets other Middle Eastern countries, but there are no Israeli targets on the other three." All four C&C servers were also hosted by the same provider in Canada, although a whois lookup on the IP addresses claims that they're really based in Azerbaijan, and in one case on the premises of that country's Royal Bank. But according to Seculert, "we confirmed with several ISPs that the physical addresses of the C&C servers are indeed located in the headquarters of the Canadian hosting provider."

According to Seculert, about half of the 800 known systems infected by Mahdi--all via targeted attacks--have been in Iran, while roughly 7% of infections were in Israel. "Looking deeper into the Mahdi victims' IP addresses, we did find a few dozen IP addresses which seem to be from non-Middle-Eastern countries, such as the U.S and U.K.," according to Seculert, although it appeared that the infected machines were owned by people who were only visiting those countries. But those Seculert findings differed from research subsequently published by Symantec, which claimed that 72% of all Mahdi infections involved PCs in Israel.

What accounts for that discrepancy? "Symantec may have come up with 72% because they were only looking at variants which communicated with the C&C servers targeting entities from Israel," according to Seculert's latest analysis. "Or, maybe they are looking only at their customer's machines which they found to be infected with Mahdi. As an American company, Symantec is not allowed to sell their products to Iran, and therefore they can't see infections in Iran." But Raff noted that Seculert's analysis had come from identifying PCs that had connected to the Mahdi botnet itself.

One final piece of evidence that the botnet was built by Iranians involves its naming conventions. "Each bot node [infected PC] receives a unique identifier," Raff said, which is a text string combining reused prefixes with unique text strings, so that any individual machine can be quickly identified and controlled. Some of the words used to construct those prefixes include these names: Chabehar, Iranshahr, Khash, Nikshahr, Saravan, and Zabol. All of those names refer to cities or counties in Iran. Another prefix also used by developers, meanwhile, was "Flame."

Is that, finally, evidence of a connection between Mahdi and Flame? The answer is likely no. According to Seculert, "the first targeted victim with the 'Flame' prefix began communicating with the C&C server in early June, right after the Kaspersky Lab discovery of Flame went public." In other words, the inclusion of the word "Flame" in Mahdi appeared to have been made after Flame became public knowledge.

Previous
2 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0619
Published: 2014-10-23
Untrusted search path vulnerability in Hamster Free ZIP Archiver 2.0.1.7 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the current working directory.

CVE-2014-2230
Published: 2014-10-23
Open redirect vulnerability in the header function in adclick.php in OpenX 2.8.10 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) dest parameter to adclick.php or (2) _maxdest parameter to ck.php.

CVE-2014-7281
Published: 2014-10-23
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hijack the authentication of administrators for requests that reboot the device via a request to goform/SysToolReboot.

CVE-2014-7292
Published: 2014-10-23
Open redirect vulnerability in the Click-Through feature in Newtelligence dasBlog 2.1 (2.1.8102.813), 2.2 (2.2.8279.16125), and 2.3 (2.3.9074.18820) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter to ct.ashx.

CVE-2014-8071
Published: 2014-10-23
Multiple cross-site scripting (XSS) vulnerabilities in OpenMRS 2.1 Standalone Edition allow remote attackers to inject arbitrary web script or HTML via the (1) givenName, (2) familyName, (3) address1, or (4) address2 parameter to registrationapp/registerPatient.page; the (5) comment parameter to all...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.