EITest Leads to Rig EK 185.141.26.72, 185.141.25.207 and 185.141.25.234

IOCs:

Traffic (run 3 and 2 in that order):

traffic-1traffic-2

Hashes:

SHA256: 9bf7ca8dd136b02d7243f4bc367bb498d11f5aa12b540520d37ef8dc5ffc6b6f
File name: RigEK Landing Page Run 2.html

SHA256: 49d5fd5a5b0058eccd888a149f6f995e7c160dd3973c0c0edebf0311365847cd
File name: RigEK Flash Exploit Run 2.swf

SHA256: df74546463c6a9f5a122eb56e2ee47ff9dbbdc1078d09b301c4a73cb3c0d0493
File name: E35.tmp.exe
Hybrid-Analysis Report

SHA256: 0e13ae03dd7765d49b3295351c2acb64f5c0f3e65a0cb295b5f186f9ef63184a
File name: RigEK Landing Page Run 3.html

SHA256: aa640ad259990129c2b6cc4e9a1bbe9a38bb60e6ccd8694e9f155ef0e0cbc347
File name: RigEK Flash Exploit Run 3.swf

SHA256: 17a6bdd76e895dc0f24dc117a7d0e623d139ee4dd21478f9b0e7ef8a6789fd02
File name: EB1F.tmp.exe
Hybrid-Analysis Report

Infection Chain:

The infection chain begins at the compromised website. Once the compromised webpage loads in the browser a malicious script known as EITest redirects the host to a Rig EK server. Below are images of the injected script on the compromised site over the course of a week (run 1, run 2, run 3):

compromised-sitecompromised-site-2compromised-site-3

The URL within the script points to the Rig EK landing page. Once on the landing page the host is sent a Flash exploit followed by the payload.

Below we can see E35.tmp from run 2 and EB1F.tmp from run 3 dropped in %Temp%:

temptemp-2

As soon as the files are executed you can see DNS queries for the domains listed in the IOC section and shown in the Traffic section.

Both 222.206.156.2 and 208.73.206.17 are owned by China’s Education And Research Network. 23.108.245.93 is owned by Nobis Technology Group, LLC.

VirusTotal shows the following domains resolving to 222.206.156.2, 208.73.206.17 and 23.108.245.93:

Notice that all these domains were created recently. That is usually a bad sign. Scanning those domains on VirusTotal shows they are being detected by Sophos as malicious. This could be because they are newly registered domains.

Below are some examples of the TCP stream showing “MyCompany Ltd” used by the malware:

These sometimes trigger alerts for blacklist malicious SSL certificates (ET TROJAN ABUSE.CH SSL Blacklist Malicious SSL Certificate Detected). This looks like it could be Gootkit but I can’t be certain.

Brad over at http://www.malware-traffic-analysis.net had similar post-infection traffic from a EITest to Rig EK infection on 10/31/16. Click HERE to read about that infection.

For now I would recommend blocking the Rig EK IPs as well as 222.206.156.2, 208.73.206.17 and 23.108.245.93 at your perimeter firewall(s).

Leave a Comment

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

%d bloggers like this: