Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Partner Perspectives  Connecting marketers to our tech communities.
SPONSORED BY
4/19/2018
09:00 AM
Andrey Shalnev
Andrey Shalnev
Partner Perspectives
50%
50%

Researchers Discover Second rTorrent Vulnerability Campaign

This time attackers appears to have spoofed the Recording Industry Association of America (RIAA) and New York University (NYU) user-agents.

F5 threat researchers have discovered a second campaign targeting an earlier rTorrent configuration error, this time to disguise threat actors’ activities with user-agents that appear to be legitimate from the Recording Industry Association of America (RIAA) and New York University (NYU) user-agents.

  • The campaign (running in January) appears to have spoofed RIAA and NYU user-agents.
  • F5 researchers do not believe either of these user-agents are legitimately from RIAA or NYU because of the origin of returning IP addresses and other attacks seen from those addresses as well. 
  • The sending server for the RIAA user-agent is a proxy server in the Netherlands set up with the hosting company Hostkey B.V. Activity from the same IP address includes scans of ports commonly used by Torrent software, and scans for Intel AMT ports.
  • The sending servers for the NYU user-agent resolve to various hosting companies around the world from which malicious activity has been seen previously, including SSH brute force scans.

Why the RIAA?

The RIAA helps members protect copyrighted works from piracy. It’s also widely known that BitTorrent is a file sharing protocol that is primarily used to illegally share software, movies, music, and other protected works—the very same materials RIAA exists to protect. In 2001, the RIAA tried to fight piracy of copyrighted works by filing lawsuits against offenders. It even drafted an amendment to proposed legislation (the USA Act of 2001) that would have allowed the RIAA to hack distributors’ computers to delete stolen content from their file systems and indemnified them from any responsibility for damage caused to distributors’ computers.

We reference this historical proposed legislation (which, by the way, was never signed into law) because the RIAA user-agent “RIAALABS” appears in the configuration snapshot of the January campaign, shown in Figure 1.

 

Figure 1: RIAA Labs user agent

The HTTP POST request targets rTorrent’s XML-RPC interface and tries to invoke a “system.client_version” method on the frequently used path “/RPC2”. Upon successful execution of this method, it returns the rTorrent version number as shown in Figure 2.

Figure 2: Campaign collects torrent client version

New York University?

The NYU campaign was spotted just one day after the RIAA campaign. As with the RIAA campaign, we cannot be sure who is behind this campaign. NYU started a Torrent tracking project in 2015, so this spoofed user-agent could be trying to disguise itself as that project. Again, this campaign tries to query the XML-RPC interface to get the Torrent client version.

Origins of these Campaigns

There is no obvious connection between the source of these two campaigns except the timeframe. The RIAA campaign originates from a single IP address: 5.39.223.136. The NYU campaign uses three different IP addresses: 185.130.104.198, 62.210.152.47, and 203.24.188.242. All of the IP addresses are owned by hosting companies.

RIAA Campaign

F5 and our data partner Loryka checked our systems to see if the originating IP address (5.39.223.136) for the RIAA campaign had shown up as malicious over the past five years. The first time we saw it engaging in malicious activity was June 1, 2017. Other scanning activity from this IP address includes destination ports 16992, likely looking for Intel AMT-vulnerable systems, and various TCP ports commonly used by torrent software (see torrent invite site). Because of this additional malicious traffic, we do not believe this is the actual RIAA, rather a spoofed user agent. 

NYU Campaign

All of the originating IP addresses for the NYU campaign (185.130.104.198, 62.210.152.47, and 203.24.188.242) are also launching SSH brute force attacks. Because of these additional attacks, we assume these are threat actors spoofing an NYU user agent.

For now, it’s unclear what happens once a vulnerable host is found. The misconfiguration vulnerability enables attackers to invoke methods on a victim’s machine that can provide a great deal of information about the shared materials on the host. (If, for example, the goal was to delete stolen, copyrighted material), or execute their own code and use the system to mine crypto-currency like we found in the February Monero campaign. Since rTorrent is the defacto standard for threat actors attacking seedboxes, which could be great crypto-miners, we are not surprised to see attacks leveraging this rTorrent misconfiguration vulnerability to compromise hosts.

Since the IP address related to the RIAA user-agent has been engaging in other malicious activity, it’s highly unlikely this is the work of the RIAA. Rather, a threat actor is pretending to be the RIAA as a deceptive tactic, or perhaps just for their own amusement. Because this campaign was seen at least a month before the Monero crypto-mining campaign, it could have been the inspiration for cybercriminals.

Of course, it’s never okay to steal and share copyrighted works, but if you are using rTorrent for legitimate purposes, please see the misconfiguration remediation actions in our previous post. 

Get the latest application threat intelligence from F5 Labs.

 

F5 makes apps go-faster, smarter, and safer. With solutions for the cloud and the data center, F5 technology provides unparalleled visibility and control, allowing customers to secure their users, applications, and data. For more information, visit www.f5.com. View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
US Turning Up the Heat on North Korea's Cyber Threat Operations
Jai Vijayan, Contributing Writer,  9/16/2019
MITRE Releases 2019 List of Top 25 Software Weaknesses
Kelly Sheridan, Staff Editor, Dark Reading,  9/17/2019
Preventing PTSD and Burnout for Cybersecurity Professionals
Craig Hinkley, CEO, WhiteHat Security,  9/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-14821
PUBLISHED: 2019-09-19
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->l...
CVE-2019-15032
PUBLISHED: 2019-09-19
Pydio 6.0.8 mishandles error reporting when a directory allows unauthenticated uploads, and the remote-upload option is used with the http://localhost:22 URL. The attacker can obtain sensitive information such as the name of the user who created that directory and other internal server information.
CVE-2019-15033
PUBLISHED: 2019-09-19
Pydio 6.0.8 allows Authenticated SSRF during a Remote Link Feature download. An attacker can specify an intranet address in the file parameter to index.php, when sending a file to a remote server, as demonstrated by the file=http%3A%2F%2F192.168.1.2 substring.
CVE-2019-16412
PUBLISHED: 2019-09-19
In goform/setSysTools on Tenda N301 wireless routers, attackers can trigger a device crash via a zero wanMTU value. (Prohibition of this zero value is only enforced within the GUI.)
CVE-2019-16510
PUBLISHED: 2019-09-19
libIEC61850 through 1.3.3 has a use-after-free in MmsServer_waitReady in mms/iso_mms/server/mms_server.c, as demonstrated by server_example_goose.