Thursday, December 12, 2024
HomeCVE/vulnerabilityLemonDuck Malware Exploiting SMB Vulnerabilities To Attack Windwos Servers

LemonDuck Malware Exploiting SMB Vulnerabilities To Attack Windwos Servers

Published on

SIEM as a Service

The attackers exploited the EternalBlue vulnerability to gain initial access to the observatory farm, creating a hidden administrative share and executing a malicious batch file named p.bat. 

This batch file performed various malicious actions like creating and executing malicious executables, opening firewall ports, setting up port forwarding, and scheduling tasks for persistence. 

It also included anti-detection mechanisms to hinder analysis, while another malicious executable disguised as svchost.exe was created to disable Windows Defender and create exclusions to avoid detection. 

- Advertisement - SIEM as a Service

It also performed similar actions, such as opening firewall ports, setting up port forwarding, and scheduling tasks.

Analyse Any Suspicious Links Using ANY.RUN’s New Safe Browsing Tool: Try for Free

Ultimately, the attackers deleted the administrative share to hide their tracks and maintain exclusive control over the compromised system.

Graph flow of the attack

The attacker brute-forced SMB to gain access as a local administrator, where a hidden administrative share was created on the C: drive for persistence. 

A malicious batch script (p.bat) was created to configure firewall rules, potentially for cryptomining, as outbound traffic is disguised as DNS traffic by proxying to port 53 of a remote server (1.1.1.1). 

Scheduled tasks were also created to execute the batch script and potentially downloaded malware (installed.exe) at regular intervals.

TCP ports open

The malicious script checks for PowerShell, and if present, it downloads and executes a second script from a malicious URL associated with LemonDuck malware. 

It also creates a scheduled task to run another malware (FdQN.exe) every hour. If PowerShell is absent, the script manipulates Windows Scheduler to run malicious scripts (mshta and installed.exe) at various intervals. 

It attempts to start a service (Ddriver) and monitors command prompts.

If more than 10 are detected, it reboots the system, and finally the script deletes itself and evidence (p.bat) before executing another downloaded malware (installed.exe).  

List of schedule tasks with different names

The malware disables Windows Defender’s real-time monitoring excludes the entire C drive from scans, and then opens a port and sets up a proxy for potential C2 communication. 

To evade detection, it renames malicious executables and attempts to download additional scripts via PowerShell or scheduled tasks. 

If PowerShell is unavailable, it restarts the Task Scheduler service and replaces existing tasks with one that fetches a potentially malicious payload every 50 minutes, which suggests the malware uses multiple download URLs and task names for persistence.  

Exploitation method

The analysis by NetbyteSec revealed msInstall.exe (LemonDuck variant) as a malicious executable targeting remote systems, which employs a brute-force attack with user/password lists to gain access. 

Once in, the malware exploits the EternalBlue vulnerability (CVE-2017-0144) to achieve SYSTEM privileges and then establishes persistence by copying itself to the target system, creating scheduled tasks, and potentially modifying firewall rules. 

The malware also attempts to download additional malicious scripts and utilizes Mimikatz to steal credentials, potentially enabling lateral movement within the network.

Strategies to Protect Websites & APIs from Malware Attack => Free Webinar

Latest articles

Resecurity introduces Government Security Operations Center (GSOC) at NATO Edge 2024

Resecurity, a global leader in cybersecurity solutions, unveiled its advanced Government Security Operations Center...

Reserachers Uncovered Zloader DNS Tunneling Tactics For Stealthy C2 Communication

Zloader, a sophisticated Trojan, has recently evolved with features that enhance its stealth and...

US Charged Chinese Hackers for Exploiting Thousands of Firewall

The US Treasury Department's Office of Foreign Assets Control (OFAC) has sanctioned Sichuan Silence...

DMD Diamond Launches Open Beta for v4 Blockchain Ahead of 2025 Mainnet

DMD Diamond - one of the oldest blockchain projects in the space has announced the...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Reserachers Uncovered Zloader DNS Tunneling Tactics For Stealthy C2 Communication

Zloader, a sophisticated Trojan, has recently evolved with features that enhance its stealth and...

Hackers Deploy Weaponized LNK Files for Malicious Payload Delivery

Researchers reported a phishing attack on December 4th, 2024, where malicious emails purportedly from...

APT-C-60 Hackers Penetrate Org’s Network Using a Weapanized Google Drive link

The Japan Computer Emergency Response Team Coordination Center (JPCERT/CC) has confirmed an advanced cyber...