Closed
Bug 1490492
Opened 7 years ago
Closed 7 years ago
Affiliate Advertiser Iced Coffee Code Execution
Categories
(Firefox :: Security, defect)
Tracking
()
People
(Reporter: u623723, Unassigned)
Details
Attachments
(2 files)
User Agent: Mozilla/5.0 (Android 8.0.0; Mobile; rv:62.0) Gecko/62.0 Firefox/62.0
Build ID: 20180906142540
Steps to reproduce:
Unknown Cause, Unknown Source.
Windows 10, latest. Intel x64.
The vulnerability likely has something to do with WebRTC.
The Malicious Link is http://trk.dsllgal.com/?utm_medium=c3da5eaf624eb0bd8b0053a8e4eca65ade8adf95&utm_campaign=SK_CA
Do not open this link, as McAfee flagged it as a Potentially Unwanted Program.
This seems to be a drammer type exploit on WebRTC, that allows Remote Code Execution as the process Firefox.
Firefox can then modify it's own file structure by using the update process, with a fake update file already provided in the RAM. Once it is updated to the malicious version of firefox.exe, then it has the ability to start doing a drammer like privilege escalation attack on the Operating System Components and other Programs. But of course, this is going to be a multi-stage attack, so naturally firefox is an internet multi-resource, so malware is going to use firefox and not reverse system socket to access it's second or third stage. This also has the ability of bypassing most AV systems, since a newly created malicious URL has to be flagged before it can be caught by the majority of AV systems, where as a reverse system socket is managed by advanced IPS and IDS firewalls, so it is unlikely that the malware would ever make it past the second stage with a reverse system socket. This way, the malware can be confused as legitimate user behaviour of accessing a website, vs downloading malware. The file IO prevention can be explained as Malicious Firefox.exe using a drammer like technique to rewrite the part of the RAM that the file write code is contained in, to corrupt it, and make file write operations impossible. This is useful, since it prevents any AV scanners that did somehow figure out that firefox is now Malicious, from quarantining it. It also allows firefox.exe to continue re-writing RAM in order to privilege escalate, and to steal secrets. This malware doesn't need file write IO, it just needs file read IO, and drammer like abilities to be able to do what it needs for the second or third stage.
Actual results:
Malware has 0-day exploited firefox core, not extensions. Now firefox redirects all web pages to a specific malicious site, targeted malware (by region). It has turned into a worm, as has rewritten the firefox.exe executable. No other files on the computer were modified. Firefox.exe now runs in the background, and the foreground (when opened). Firefox.exe also seems to have the ability to block all file write operations from happening, even know there is no rootkit or modified system files. So this means the inability to copy, move, rename, or delete files. The inability to modify files is only present in normal operation mode, and does not exist in safe mode.
Expected results:
There should have been exploit protection, and signature enforcement, as well as memory sandboxing. Plus Firefox should have prevented the user from accessing a site know to be a PUP.
Severity: normal → major
Iteration: --- → 63.5 - Sep 3
status-firefox62:
--- → affected
status-firefox63:
--- → affected
status-firefox64:
--- → ?
status-firefox-esr60:
--- → ?
status-geckoview62:
--- → affected
relnote-firefox:
--- → ?
Component: Untriaged → Security
OS: Unspecified → Windows 10
Hardware: Unspecified → x86_64
Version: 62 Branch → 63 Branch
Summary: Code Execution Malware → WebRTC Drammer Spectre Code Execution Malware
Comment 1•7 years ago
|
||
A "Potentially Unwanted Program" is a program that claims to be something you want (sometimes even anti-malware!) in order to trick you into downloading it and running it -- that act bypasses many security protections on your operating system and runs at the same privilege as Firefox so Firefox cannot, at that point, protect itself.
Is that what happened? If so the problem seems to be that the Firefox SafeBrowsing list doesn't include this site when apparently it's known to McAfee.
A downloaded executable should also have received "The Mark of the Web" and Windows should also have warned that it's dangerous to run an executable. Did that happen? (If not there's another bug to investigate.)
Neither of the above involves WebRTC, signature enforcement, or memory sandboxing. What symptoms are you seeing that makes you think those are involved? If this doesn't involve downloading anything yourself then it's some kind of Firefox exploit and the "potentially unwanted program" bit is the red herring. This is a very important distinction! That would definitely involve memory sandboxing issues, but I'm still not sure why you think WebRTC is involved. Is it a video-calling site? The current content doesn't seem to be but I haven't followed all the suspicious redirects yet.
Where did you come across this URL?
Flags: needinfo?(neoredstone)
Updated•7 years ago
|
relnote-firefox:
? → ---
So, oddly enough, I scanned the entire contents of the machiene with virustotal (using lots of zip files), and nothing but false positives show up, except for maybe this one thing from yandex, which specifies deep learning detection of firefox trojan/adware in the cache files of firefox. Just to note, that there were no Programs/addons installed for at least 3 months before this, just windows updates (auto), that and firefox updates. So then I put Sophos Intercept X and Sophos ML on the machiene, scanned it, and Nothing.
The behaviour is that firefox opens its self automatically using scheduled tasks, Unknown source, no log files associated, and then firefox immediately opens up to that link. There was no indication of any other exploit points other than firefox itself. Everything on the system is automatically updated daily. Everything was on the latest version. Then when you close Firefox, it runs in the background, then opens its self up again after about 10 seconds. When the firefox process is running background or foreground, it does an insane amount of system calls, so much that any file IO that you may want to do, is about a single 1kb file per second, on an ssd that is brand new, and benchmarks about 1Gbps, to a USB stick that is about 300Mbps.
So that is a crippling performance drop, that does not happen when firefox is not running.
There is no foreign processes or foreign services running, I checked, the only one is firefox core, and all of the firefox regular processes.
So I renamed all of the firefox executables, every single one, and now it doesn't open anymore. So no more firefox.exe, but now also no more extreme file IO overhead, and now no more firefox threatening to download malware onto your computer.
I would love to know which files to send, also the files are benign, unless executed outside of a sandbox.
Just to clear things up, that link is most definitely malicious, that link is the link opened by malicious firefox, and the get parameters/variables, are different from machiene to machiene. I'm assuming that the utm_medium variable is a Hash or base64 encoded parameter defining the system configuration or the UUID, and the utm_campaign variable is a location marker, to let analytics/regional psycho profiling to be done on a regional basis, so that any type of humanly attempt to remove the malware in that province/state, is undermined by the fact that the second stage is using culturally targeted masking techniques, to hide it's self on the machiene.
Flags: needinfo?(neoredstone) → needinfo?(wleung)
Correction, the suspicious detecting scanner is Zillya, with the detection of Adware.BrowseFox.Win32.231353, with virustotal reference of https://www.virustotal.com/#/file/91026e907d76cec1ccba9c36f87f3673b7bbdb54cbdc9ce2c96a870068c6e0fb/detection.
AND I JUST FOUND CYRILLIC TEXT ON A LINK FILE, on a western machine, with western only user, and western only programs, and western only language pack. https://www.virustotal.com/#/file/b68e121586ef846dc2be14897087566ac72f6e6339f193609a5fc6f766e5c4aa/details
The detected files will be sent zipped.
Here is the detected file on google drive https://drive.google.com/file/d/1_hUT9GYpw2jlbjElJ7GtC3GUicXtx6No/view?usp=sharing.
Found in the Firefox Profile Folder, Contains Links to Russian Websites that were never willingly accessed by the user.
Flags: needinfo?(dveditz)
(In reply to neoredstone from comment #6)
> Created attachment 9012309 [details]
> Found in the Firefox Profile Folder, Contains Links to Russian Websites that
> were never willingly accessed by the user.
>
> Found in the Firefox Profile Folder, Contains Links to Russian Websites that
> were never willingly accessed by the user.
Also doesn't it seem highly suspicious that there is a site named rbc.ru, listed as visited (the user never visited this site), when there is an rbc.ca, and the two sites are not owned by the same person/organization. Also, another thing that is highly suspicious, is that there is a malware scanner named yandex, used in virustotal, but again yandex.ru, was never accessed by the owner of the machine, and there is no other physical access to the machine.
Suspicious Sites (The User did Not Willingly Access these sites):
google.com.af (maybe not)
orf.at
willhaben.at
58.com
gp.58cdn.com.cn
amazon.cn (maybe not)
dangdang.com
ddimg.cn
douyin.com
bytecdn.cn
focus.cn
t.focus-res.cn
gome.com.cn
app.gomein.net.cn
jrj.com.cn
jrjimg.cn
mtime.com
m.mtime.cn
pku.edu.cn (seen a lot of spyware coming from edu.cn sites recently)
sina.com.cn
mjs.sinaimg.cn
sohu.com
zmt.itc.cn
tianya.cn
w3school.com.cn (very suspicious)
weibo.com
sinaimg.cn
weibo.cn
zhaopin.com
zhaopin.cn
zhiding.cn (very suspicious)
csfd.cz
img.csfd.cz
idnes.cz
1gr.cz
seznam.cz
autoscout24.de
bild.de
chip.de
ebay-kleinanzeigen.de
focus.de
lidl.de
otto.de
spiegel.de
t-online.de
img.toi.de
tagesschau.de
thomann.de
images.static-thomann.de
web.de (very suspicious)
welt.de
wetteronline.de
zdf.de
zeit.de
google.com.do (maybe not)
google.com.eg (maybe not)
20minutos.es
rs.20m.es
abc.es
elmundo.es
e00-elmundo.uecdn.es
marca.com
e00-marca.uecdn.es
sport.es
onet.pl
ocdn.eu
20minutes.fr
assets-v.20mn.fr
credit-agricole.fr
francetvinfo.fr
free.fr
leboncoin.fr (extremely suspicious)
lefigaro.fr
a.f1g.fr
lemonde.fr
lemde.fr
lequipe.fr
orange.fr
pole-emploi.fr
sfr.fr
dikaiologitika.gr
in.gr
secure.gravatar.com (maybe not)
0.gravitar.com (maybe not)
skroutz.gr (extremely suspicious)
zougla.gr
discuss.com.hk
google.com.hk (maybe not)
hsbc.com.hk
brainly.co.id
dream.co.id
cdns.klimg.com
kaskus.co.id
s.kaskus.id
uzone.id
panet.co.il
ynet.co.il
cleartax.in
epfindia.gov.in
moneycontrol.com
moneycontrol.co.in
scroll.in
divar.ir
s.cafebazaar.ir
corriere.it
corrierobjects.it
gazzetta.it
gazzettaobjects.it
ilfattoquotidiano.it
ilmeteo.it
libero.it
i.plug.it
raiplay.it
repubblica.it
repstatic.it
subito.it
virgilio.it
ameblo.jp
ameba.jp
ana.co.jp
biglobe.ne.jp
blog.jp
goo.ne.jp
mixi.jp
nicovideo.jp
sp.res.nimg.jp
rakuten.co.jp
sakura.ne.jp
so-net.ne.jp
tenki.jp
yahoo.co.jp (maybe not)
s.yimg.jp
zozo.jp
avito.ma
masterani.me
mercadolibre.com.mx
pirateproxy.mx (extremely suspicious)
finn.no
nrk.no
vg.no
yr.no
dailypakistan.com.pk
daraz.pk
cda.pl
filmweb.pl
fwcdn.pl
gazeta.pl
interia.pl
o2.pl
onet.pl
wiocha.pl
wp.pl
abola.pt
sapo.pt
1tv.ru
2gis.ru
adme.ru
aif.ru
citilink.ru
drive2.ru
drom.ru
c.rdrom.ru
gismeteo.ru
gosuslugi.ru
gu-st.ru
hh.ru
i-m.hh.ru
irecommand.ru
ivi.ru
st.tivision.ru
kinopoisk.ru
kp.ru
lenta.ru
lifehacker.ru (maybe not)
mail.ru
imgsmail.ru
mamba.ru
mk.ru
mvideo.ru
ok.ru
pikabu.ru
rambler.ru
rbc.ru
rbk.ru
rp5.ru
sberbank.ru
sbrf.ru
seasonvar.ru
smi2.ru
sport-express.ru
sportbox.ru
sportmail.ru
sports.ru
worldoftanks.ru
yandex.ru
youla.ru
aftonbladet.se
gfx.aftonbladet-cdn.se
blocket.se
ria.ru
aksam.com.tr
hurriyet.com.tr
milliyet.com.tr
sabah.com.tr
isbh.tmgroup.com.tr
star.com.tr
turkiye.gov.tr
yandex.com.tr
gismeteo.ua
privatbank.ua
prom.ua
uaprom.net
telegraf.com.ua (extremely suspicious)
metro.co.uk
newsnow.co.uk
gov.uk
24h.com.vn
kehn14.vn
vtv.vn
zing.vn
mediacdn.vn
Comment 9•7 years ago
|
||
So the interesting part to know here would be how this malware got installed and which files it initially modified; once it's installed it can cause all sorts of things to happen, sites to be visited (even if the user never sees them), etc.
"lots of zipfiles" tends to imply to me the user tended to download stuff, probably including executables in some cases - this may not be a browser vulnerability at all, but malware which once on the system hijacks the browser (this is rather common - think clickfraud, for example)
| Reporter | ||
Comment 10•7 years ago
|
||
Or you know, TOR exit node using udp nat transversal. But yeah, there is no zip files. And it looks like I might have to take the computer into the RCMP/FEDS to get any info, since basically every malware and virus scanner did not find a shred of anything. Is it possible that the actions that the firefox executable has taken, is a result of cache injection?
Flags: needinfo?(dveditz) → needinfo?(rjesup)
Comment 11•7 years ago
|
||
Two things that can be tried:
run firefox with a new profile in safe mode (firefox.exe -profilemanager --safe-mode) from a shell
See if it reoccurs. If it doesn't, it's something in the profile or an extension.
It it still happens: reboot the machine and *don't* start firefox. Verify this with Process Explorer from sysinternals.
Use Edge to download a new copy of firefox from mozilla.org. Install it (you can put it in a different directory. Do not run from the install; start from a shell again with a new profile in safemode.
If it still happens, the system is infected. Perhaps a rootkit not visible to scanners. A Tor node is a serious potential honeypot/target I'd imagine.
Note about zip files: you said "So, oddly enough, I scanned the entire contents of the machiene with virustotal (using lots of zip files)" so I assume you meant scanning zip files
Flags: needinfo?(rjesup)
Comment 12•7 years ago
|
||
Also, I still don't know why you believe WebRTC is involved here, or any proof a "drammer" attack is being used
Updated•7 years ago
|
Flags: needinfo?(neoredstone)
| Reporter | ||
Comment 13•7 years ago
|
||
Because every malware and virus scanner that exists, says that there is no malware or viruses on the machiene. Which leads means that this is either trollware (relatively new), or an incident completely isolated to firefox. Based off the history, it looks like it is ad networks using js to re-write one of the cache files, using an experimental js library, in this case WebRTC, and it somehow makes firefox do a whole bunch of weird stuff, including running in the background when closed, re-opening to a PUP link, and casting so many system calls that File IO basically doesn't work.
There was no malicious executable downloaded.
Just some experimental js code in a cache that it doesn't belong in.
From affiliate advertisment networks. (The only advertisment stream that does not have 3rd party js).
Considering that drammer is a poorly mitigated hardware vulnerability, it is safe to say that attackers have already found a way around the mitigations, at least for inner-process RAM. As far as I know, Windows has a secure method of mitigating Drammer from accessing the Privileged/System Memory.
So what I am going to provide, is the entire path of files that firefox has, excluding the downloads. Then you will see if you can replicate the result in a air-gapped virtual machiene, and given your amazing debug skills, you should be able to determine how the system of events works.
And in return, this feed will never be made public, or the files will be deleted/completely sanitized before it is made public.
Flags: needinfo?(neoredstone)
| Reporter | ||
Comment 14•7 years ago
|
||
Oh yeah, trollware, a relatively new tactic, is just a simple script designed to do random things that catch the users attention. It is essentially a disinformation campaign on the health of your computer. It is designed to make the user consume all of his/her time on figuring out the trollware, when really the efforts will be completely exhaustful, since there is no real health problem with the computer. So it's not cyber-warfare, it's psychological warfare instead. Because once the person is exhausted, they give up, and that provides a great economic gain to rivals, and they also can get you with other things when your guard is down.
Summary: WebRTC Drammer Spectre Code Execution Malware → Affiliate Advertiser Cache Code Execution
| Reporter | ||
Comment 15•7 years ago
|
||
Reviewing all of the code, events, and files, I can say almost for certain that we are looking at an Iced Coffee JS code execution Attack. All of the affected files remain in firefox, except for any modified files from a meterpreter session. So this is most definitely the work of RUSSIAN hacking group, Turla.
Summary: Affiliate Advertiser Cache Code Execution → Affiliate Advertiser Iced Coffee Code Execution
Comment 16•7 years ago
|
||
I don't see a specific question for wleung, removing needinfo
Flags: needinfo?(wleung)
Comment 17•7 years ago
|
||
Iced Coffee is an attack on Office Documents, not browsers. Once an infected document is opened on a vulnerable machine the malware will be downloaded and installed at which point it can create all the symptoms you mention.
> The behaviour is that firefox opens its self automatically using scheduled tasks, [...]
This doesn't necessarily mean Firefox itself is infected, it means the installed malware (which sounds like "adware") is opening the default browser. If you change the default browser to Chrome or Edge does the problem shift to the other browser?
| Reporter | ||
Comment 18•7 years ago
|
||
You know, there was some word documents downloaded and opened around the time that this happened, with source of University of Regina. I am not the end-user, just simply somebody that has enough technical knowledge to be able to help end-users with computer issues. And from what I was reading, Iced Coffee is a javascript exploit. If you could please direct me to the official explanation of Iced Coffee from the source, like FBI or Microsoft or Symantec, etc.
Just to re-clarify, it does not open in safe-mode, since scheduled tasks is not running. But when you startup firefox in safe mode, it does the behaviours as listed before, including running in the background after the user closes it. Just not the ability to use scheduled tasks to run or re-run itself in safe mode.
As well, ran an offline scan on the machiene with sophos ML, and it detected no rootkits. So there is literally no possibility of a rootkit, since there was no operating system running on the drive being scanned, and the OS that was scanning, was clean just like TAILS.
| Reporter | ||
Comment 19•7 years ago
|
||
This also may share similarities with bug #1493900 CVE-2018-12386. As I am 90% certain that it was a javascript exploit of some kind, based on the behavioural psychology of the malware patterns.
| Reporter | ||
Comment 20•7 years ago
|
||
Another fact that classifies it as iced coffee, is that I found all of the crypt stores for the Intel Wireless Controller, accessed or modified on the date that the malware took hold.
Updated•7 years ago
|
Status: UNCONFIRMED → RESOLVED
Closed: 7 years ago
Resolution: --- → INCOMPLETE
Updated•6 years ago
|
Updated•6 years ago
|
Group: firefox-core-security
You need to log in
before you can comment on or make changes to this bug.
Description
•