{"id":17231,"date":"2019-12-18T07:20:53","date_gmt":"2019-12-18T15:20:53","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2019\/12\/18\/news-10967\/"},"modified":"2019-12-18T07:20:53","modified_gmt":"2019-12-18T15:20:53","slug":"news-10967","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2019\/12\/18\/news-10967\/","title":{"rendered":"MyKings botnet spreads headaches, cryptominers, and Forshare malware"},"content":{"rendered":"<p><strong>Credit to Author: Gabor Szappanos| Date: Wed, 18 Dec 2019 14:16:38 +0000<\/strong><\/p>\n<div class=\"entry-content\">\n<p>There&#8217;s a pretty good chance everyone who reads this story will have had some degree of interaction with a botnet we call MyKings (and others call DarkCloud or Smominru), whether you know it or not. For the past couple of years, this botnet has been a persistent source of nuisance-grade opportunistic attacks against the underpatched, low-hanging fruit of the internet. It&#8217;s probably <a href=\"https:\/\/news.sophos.com\/en-us\/2019\/04\/30\/a-taste-of-the-onslaught-at-the-networks-edge\/\" target=\"_blank\" rel=\"noopener\">knocking at your firewall<\/a> right now. They <a href=\"https:\/\/news.sophos.com\/en-us\/2019\/05\/24\/gandcrab-spreading-via-directed-attacks-against-mysql-servers\/\" target=\"_blank\" rel=\"noopener\">certainly wouldn&#8217;t<\/a> <a href=\"https:\/\/news.sophos.com\/en-us\/2019\/10\/01\/lemon_duck-powershell-malware-cryptojacks-enterprise-networks\/\" target=\"_blank\" rel=\"noopener\">be the first<\/a>.<\/p>\n<p>This botnet is a relentlessly redundant attacker, targeting primarily Windows-based servers hosting any of a variety of services: MySQL, MS-SQL, Telnet, ssh, IPC, WMI, Remote Desktop (RDP), and even the servers that run CCTV camera storage.<\/p>\n<p>While much has been said about individual components of the botnet, in <a href=\"https:\/\/www.sophos.com\/en-us\/medialibrary\/pdfs\/technical-papers\/sophoslabs-uncut-mykings-report.pdf\" target=\"_blank\" rel=\"noopener\">a report on MyKings SophosLabs is releasing today<\/a>, principal malware researcher Gabor Szappanos writes that his goal is &#8220;to provide a full picture of the operation of the botnet&#8221; looking at all its tools and behaviors, globally.<\/p>\n<p><span id=\"more-62764\"><\/span><\/p>\n<p>Attacks by the MyKings botnet operators follow a predictable pattern: The botnet attempts a stable of different attacks against a server. Unpatched, or underpatched, Windows servers may be vulnerable to a wide range of attacks, the goal of which is to deliver a malware executable, more often than not, a Trojan named Forshare.<\/p>\n<p>The infected endpoints we observed totaled about 43900 unique IP addresses. This number includes only those endpoints that have a public IP address; internal addresses were not counted (we found 10973 more using internal NAT ranges) but then we would have less confidence that we were counting unique computers.<\/p>\n<p><a href=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/pie_logo.png\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"62801\" data-permalink=\"https:\/\/news.sophos.com\/en-us\/2019\/12\/18\/mykings-botnet-spreads-headaches-cryptominers-and-forshare-malware\/pie_logo\/\" data-orig-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/pie_logo.png\" data-orig-size=\"787,483\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"pie_logo\" data-image-description=\"\" data-medium-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/pie_logo.png?w=300\" data-large-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/pie_logo.png?w=640\" class=\"alignnone wp-image-62801\" src=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/pie_logo.png?w=503&#038;h=309\" alt=\"\" width=\"503\" height=\"309\" srcset=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/pie_logo.png?w=503&amp;h=309 503w, https:\/\/sophos.files.wordpress.com\/2019\/12\/pie_logo.png?w=150&amp;h=92 150w, https:\/\/sophos.files.wordpress.com\/2019\/12\/pie_logo.png?w=300&amp;h=184 300w, https:\/\/sophos.files.wordpress.com\/2019\/12\/pie_logo.png?w=768&amp;h=471 768w, https:\/\/sophos.files.wordpress.com\/2019\/12\/pie_logo.png 787w\" sizes=\"auto, (max-width: 503px) 100vw, 503px\" \/><\/a>The countries with the highest population of infected hosts include:<\/p>\n<ul>\n<li>China<\/li>\n<li>Taiwan<\/li>\n<li>Russia<\/li>\n<li>Brazil<\/li>\n<li>USA<\/li>\n<li>India<\/li>\n<li>Japan<\/li>\n<\/ul>\n<p>The botnet attacks like it&#8217;s playing in a CTF competition: It establishes a beachhead, then clears out any trace of the competition, removing indicators of competing malware families, then securing the door it used to break in behind itself.<\/p>\n<p><a href=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-kill-list.png\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"62803\" data-permalink=\"https:\/\/news.sophos.com\/en-us\/2019\/12\/18\/mykings-botnet-spreads-headaches-cryptominers-and-forshare-malware\/mykings-kill-list\/\" data-orig-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-kill-list.png\" data-orig-size=\"1121,513\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"mykings kill list\" data-image-description=\"\" data-medium-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-kill-list.png?w=300\" data-large-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-kill-list.png?w=640\" class=\"alignnone size-full wp-image-62803\" src=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-kill-list.png?w=640&#038;h=293\" alt=\"\" width=\"640\" height=\"293\" srcset=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-kill-list.png?w=640&amp;h=293 640w, https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-kill-list.png?w=150&amp;h=69 150w, https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-kill-list.png?w=300&amp;h=137 300w, https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-kill-list.png?w=768&amp;h=351 768w, https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-kill-list.png?w=1024&amp;h=469 1024w, https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-kill-list.png 1121w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a>This kill list is how MyKings looks for and attempts to terminate the processes or services of a variety of endpoint security tools.<\/p>\n<p><a href=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/redundant.png\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"62804\" data-permalink=\"https:\/\/news.sophos.com\/en-us\/2019\/12\/18\/mykings-botnet-spreads-headaches-cryptominers-and-forshare-malware\/redundant\/\" data-orig-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/redundant.png\" data-orig-size=\"880,556\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"redundant\" data-image-description=\"\" data-medium-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/redundant.png?w=300\" data-large-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/redundant.png?w=640\" class=\"alignnone size-full wp-image-62804\" src=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/redundant.png?w=640&#038;h=404\" alt=\"\" width=\"640\" height=\"404\" srcset=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/redundant.png?w=640&amp;h=404 640w, https:\/\/sophos.files.wordpress.com\/2019\/12\/redundant.png?w=150&amp;h=95 150w, https:\/\/sophos.files.wordpress.com\/2019\/12\/redundant.png?w=300&amp;h=190 300w, https:\/\/sophos.files.wordpress.com\/2019\/12\/redundant.png?w=768&amp;h=485 768w, https:\/\/sophos.files.wordpress.com\/2019\/12\/redundant.png 880w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><em>Redundant<\/em> is also part of the MyKings pattern, and plays a key part in its persistence mechanism. There are several component parts to MyKings, and each of them does a very similar self-update procedure. Everything repeats itself several times over, using a variety of command combinations.<\/p>\n<p>Even if most of the components of the botnet are removed from the computer, the remaining ones have the capability to restore it to full strength simply by updating themselves. All of this is orchestrated using self-extracting RAR archives and Windows batch files. One of the downloaded components is a WinRAR self-extracting archive that creates two files, n.vbs and c3.bat. This batch file is the cornerstone of Mykings operations: A lot of activities are concentrated into this single component.<\/p>\n<figure id=\"attachment_62805\" aria-describedby=\"caption-attachment-62805\" style=\"width: 640px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/rar-drop-relation.png\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"62805\" data-permalink=\"https:\/\/news.sophos.com\/en-us\/2019\/12\/18\/mykings-botnet-spreads-headaches-cryptominers-and-forshare-malware\/rar-drop-relation\/\" data-orig-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/rar-drop-relation.png\" data-orig-size=\"713,386\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"rar drop relation\" data-image-description=\"\" data-medium-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/rar-drop-relation.png?w=300\" data-large-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/rar-drop-relation.png?w=640\" class=\"wp-image-62805 size-full\" src=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/rar-drop-relation.png?w=640&#038;h=346\" alt=\"\" width=\"640\" height=\"346\" srcset=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/rar-drop-relation.png?w=640&amp;h=346 640w, https:\/\/sophos.files.wordpress.com\/2019\/12\/rar-drop-relation.png?w=150&amp;h=81 150w, https:\/\/sophos.files.wordpress.com\/2019\/12\/rar-drop-relation.png?w=300&amp;h=162 300w, https:\/\/sophos.files.wordpress.com\/2019\/12\/rar-drop-relation.png 713w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><figcaption id=\"caption-attachment-62805\" class=\"wp-caption-text\">The n.vbs map of its relationship to other processes<\/figcaption><\/figure>\n<p>The MyKings network attacks go through constant refinement, so they change over time. The criminals behind this botnet prefer to use open source or other public domain software and have enough skills to customize and enhance existing source code. For instance, the botnet has begun to experiment with hiding malware payloads in plain sight, storing the file in an image using a process called steganography.<\/p>\n<p><a href=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/tay-plus-data.png\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"62807\" data-permalink=\"https:\/\/news.sophos.com\/en-us\/2019\/12\/18\/mykings-botnet-spreads-headaches-cryptominers-and-forshare-malware\/tay-plus-data\/\" data-orig-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/tay-plus-data.png\" data-orig-size=\"1024,512\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"tay plus data\" data-image-description=\"\" data-medium-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/tay-plus-data.png?w=300\" data-large-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/tay-plus-data.png?w=640\" class=\"alignnone size-full wp-image-62807\" src=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/tay-plus-data.png?w=640&#038;h=320\" alt=\"\" width=\"640\" height=\"320\" srcset=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/tay-plus-data.png?w=640&amp;h=320 640w, https:\/\/sophos.files.wordpress.com\/2019\/12\/tay-plus-data.png?w=150&amp;h=75 150w, https:\/\/sophos.files.wordpress.com\/2019\/12\/tay-plus-data.png?w=300&amp;h=150 300w, https:\/\/sophos.files.wordpress.com\/2019\/12\/tay-plus-data.png?w=768&amp;h=384 768w, https:\/\/sophos.files.wordpress.com\/2019\/12\/tay-plus-data.png 1024w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a>In this sample image, a Windows malware executable (identifiable by its characteristic MZ header bytes and text) appears within the image data in a modified .jpg photo of Taylor Swift. MyKings&#8217; operators uploaded this innocuous-looking image file to a public repository, and then used it to deliver an update to the botnet.<\/p>\n<p>MyKings also redundantly employs a number of methods of establishing persistence on the infected host: It uses a bootkit, which launches the botnet immediately upon reboot; sets Registry run keys; and creates a number of Scheduled Tasks and WMI listeners.<\/p>\n<p>MyKings is not content to remain on your internet-facing server for long. The malware leverages the EternalBlue exploit and other exploits leaked by the Shadow Brokers. We know that because the first version of the MyKings package used a compressed archive that named them all. We found two very different EternalBlue implementations used in MyKings campaigns.<\/p>\n<p><a href=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-eternalzip.png\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"62809\" data-permalink=\"https:\/\/news.sophos.com\/en-us\/2019\/12\/18\/mykings-botnet-spreads-headaches-cryptominers-and-forshare-malware\/mykings-eternalzip\/\" data-orig-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-eternalzip.png\" data-orig-size=\"766,317\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"mykings eternalzip\" data-image-description=\"\" data-medium-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-eternalzip.png?w=300\" data-large-file=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-eternalzip.png?w=640\" class=\"alignnone size-full wp-image-62809\" src=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-eternalzip.png?w=640&#038;h=265\" alt=\"\" width=\"640\" height=\"265\" srcset=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-eternalzip.png?w=640&amp;h=265 640w, https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-eternalzip.png?w=150&amp;h=62 150w, https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-eternalzip.png?w=300&amp;h=124 300w, https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings-eternalzip.png 766w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>The earlier version, found in August 2018, was completely based on the files leaked by the Shadow Brokers, along with the MyKings additions. It was literally named nsa.zip.<\/p>\n<p>It is a self-extracting ZIP file with a couple of custom components inserted. The comment is turned out to be in Chinese, and it is the same as in the .bat file: &#8220;The following comments contain self-extracting script commands&#8221;The botnet is medium sized, has about 45,000 infected hosts.<\/p>\n<h3>What&#8217;s it all for?<\/h3>\n<p>Unbelievably, all this effort was made in order to deliver one of various different Monero cryptominers. Forshare gets used to ensure the miners are running.<\/p>\n<p>The criminals who run the botnet have reportedly earned about 9,000 XMR over its lifetime, estimated to be valued at about $3 million. The current MyKings income is about $300 per day, mainly due to a lower Monero exchange rate.<\/p>\n<p>For more on the botnet and how it operates, please read <strong><a href=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/mykings_report_final.pdf\" target=\"_blank\" rel=\"noopener\">MyKings: The slow but steady growth of a relentless botnet<\/a><\/strong>.<\/p>\n<h2>IoCs<\/h2>\n<p>All IoCs relating to this publication can be found <a href=\"https:\/\/github.com\/sophoslabs\/IoCs\/blob\/master\/malware-MyKings\" target=\"_blank\" rel=\"noopener\">on the SophosLabs Github<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<\/p><\/div>\n<p><a href=\"http:\/\/feedproxy.google.com\/~r\/sophos\/dgdY\/~3\/Bs6eVtcm9SE\/\" target=\"bwo\" >http:\/\/feeds.feedburner.com\/sophos\/dgdY<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/sophos.files.wordpress.com\/2019\/12\/tay-plus-data-no-text.png\"\/><\/p>\n<p><strong>Credit to Author: Gabor Szappanos| Date: Wed, 18 Dec 2019 14:16:38 +0000<\/strong><\/p>\n<p>All this trouble just for some Monero&lt;img src=&#8221;http:\/\/feeds.feedburner.com\/~r\/sophos\/dgdY\/~4\/Bs6eVtcm9SE&#8221; height=&#8221;1&#8243; width=&#8221;1&#8243; alt=&#8221;&#8221;\/&gt;<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10377],"tags":[15826,23794,23795,23796,10538,23797,23798,21854,18324,23118,18513,16549,23799,12844],"class_list":["post-17231","post","type-post","status-publish","format-standard","hentry","category-security","category-sophos","tag-cryptominers","tag-darkcloud","tag-forshare","tag-ipc","tag-monero","tag-ms-sql","tag-mykings","tag-mysql","tag-rdp","tag-smominru","tag-sophoslabs-uncut","tag-ssh","tag-telnet","tag-wmi"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17231","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17231"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17231\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17231"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17231"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17231"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}