Overview
On Friday, May 12, attackers spread a massive ransomware attack worldwide using the EternalBlue exploit to rapidly propagate the malware over corporate LANs and wireless networks. EternalBlue, originally exposed on April 14 as part of the Shadow Brokers dump of NSA hacking tools, leverages a vulnerability (MS17-010) in Microsoft Server Message Block (SMB) on TCP port 445 to discover vulnerable computers on a network and laterally spread malicious payloads of the attackers choice. This particular attack also appeared to use an NSA backdoor called DoublePulsar to actually install the ransomware known as WannaCry.
Over the subsequent weekend, however, we discovered another very large-scale attack using both EternalBlue and DoublePulsar to install the cryptocurrency miner Adylkuzz. Initial statistics suggest that this attack may be larger in scale than WannaCry: because this attack shuts down SMB networking to prevent further infections with other malware (including the WannaCry worm) via that same vulnerability, it may have in fact limited the spread of last weeks WannaCry infection.
Symptoms of this attack include loss of access to shared Windows resources and degradation of PC and server performance. Several large organizations reported network issues this morning that were originally attributed to the WannaCry campaign. However, because of the lack of ransom notices, we now believe that these problems might be associated with Adylkuzz activity. However, it should be noted that the Adylkuzz campaign significantly predates the WannaCry attack, beginning at least on May 2 and possibly as early as April 24. This attack is ongoing and, while less flashy than WannaCry, is nonetheless quite large and potentially quite disruptive.
The Discovery
In the course of researching the WannaCry campaign, we exposed a lab machine vulnerable to the EternalBlue attack. While we expected to see WannaCry, the lab machine was actually infected with an unexpected and less noisy guest: the cryptocurrency miner Adylkuzz. We repeated the operation several times with the same result: within 20 minutes of exposing a vulnerable machine to the open web, it was enrolled in an Adylkuzz mining botnet.
Figure 1: EternalBlue/DoublePulsar attack from one of several identified hosts, then Adylkuzz being download from another host - A hash of a pcap of this capture is available in the IOCs table
The attack is launched from several virtual private servers which are massively scanning the Internet on TCP port 445 for potential targets.
Upon successful exploitation via EternalBlue, machines are infected with DoublePulsar. The DoublePulsar backdoor then downloads and runs Adylkuzz from another host. Once running, Adylkuzz will first stop any potential instances of itself already running and block SMB communication to avoid further infection. It then determines the public IP address of the victim and download the mining instructions, cryptominer, and cleanup tools.
It appears that at any given time there are multiple Adylkuzz command and control (C&C) servers hosting the cryptominer binaries and mining instructions.
Figure 2 shows the post-infection traffic generated by Adylkuzz in this attack.
Figure 2: Post-infection traffic associated with the attack
In this attack, Adylkuzz is being used to mine Monero cryptocurrency. Similar to Bitcoin but with enhanced anonymity capabilities, Monero recently saw a surge in activity after it was adopted by the AlphaBay darknet market, described by law enforcement authorities as a major underground website known to sell drugs, stolen credit cards and counterfeit items. Like other cryptocurrencies, Monero increases market capitalization through the process of mining. This process is computationally intensive but rewards miners with funds in the mined currency, currently 7.58 Moneros or roughly $205 at current exchange rates.
Figure 3 shows Adylkuzz mining Monero cryptocurrency, a process that can be more easily distributed across a botnet like that created here than in the case of Bitcoin, which now generally requires dedicated, high-performance machines.
Figure 3: Part of the behavioral analysis from an Adylkuzz-infected VM showing it, among other things, closing SMB door and launching Monero Mining
One of several Monero addresses associated with this attack is shown in Figure 4. The hash rate shows the relative speed with which the specific associated instance of the botnet is mining Moneros, while the total paid shows the amount paid to this particular address for mining activities. In this case, just over $22,000 was paid out before the mining associated with this address ceased.
Figure 4: One of several Monero addresses associated with income from Adylkuzz mining
Looking at the mining payments per day associated with a single Adylkuzz address, we can see the increased payment activity beginning on April 24 when this attack began. We believe that the sudden drop that occurred on May 11 indicates when the actors switched to a new mining user address (Figure 5). By regularly switching addresses, we believe that the actors are attempting to avoid having too many Moneros paid to a single address.
Figure 5: Daily payment activity associated with a single Adylkuzz mining address
Statistics and payment history for a second payment address are shown in Figure 6. This address has had just over $7,000 paid to date.
Figure 6: A second Monero address associated with income from Adylkuzz mining
A third address shows a higher hash rate and a current payment total of over $14,000 (Figure 7).
Figure 7: A third Monero address associated with income from Adylkuzz mining
We have currently identified over 20 hosts setup to scan and attack, and are aware of more than a dozen active Adylkuzz C&C servers. We also expect that there are many more Monero mining payment addresses and Adylkuzz C&C servers associated with this activity.
Conclusion
Like last weeks WannaCry campaign, this attack makes use of leaked NSA hacking tools and leverages a patched vulnerability in Microsoft Windows networking. The Adylkuzz campaign, in fact predates WannaCry by many days. For organizations running legacy versions of Windows or who have not implemented the SMB patch that Microsoft released last month, PCs and servers will remain vulnerable to this type of attack. Whether they involve ransomware, cryptocurrency miners, or any other type of malware, these attacks are potentially quite disruptive and costly. Two major campaigns have now employed the attack tools and vulnerability; we expect others will follow and recommend that organizations and individuals patch their machines as soon as possible.
Acknowledgments
We want to thank:
Indicators of Compromise
Also available in MISP JSON format.
Select Dropped Samples
Executed commands:
taskkill /f /im hdmanager.exe C:Windowssystem32wbemwmiprvse.exe -secured -Embedding taskkill /f /im mmc.exe sc stop WELM sc delete WELM netsh ipsec static add policy name=netbc netsh ipsec static add filterlist name=block netsh ipsec static add filteraction name=block action=block netsh ipsec static add filter filterlist=block any srcmask=32 srcport=0 dstaddr=me dstport=445 protocol=tcp description=445 netsh ipsec static add rule name=block policy=netbc filterlist=block filteraction=block netsh ipsec static set policy name=netbc assign=y C:WindowsFontswuauser.exe --server C:WindowsFontsmsiexev.exe -a cryptonight -o stratum+tcp://xmr.crypto-pool.fr:443 -u 49v1V2suGMS8JyPEU5FTtJRTHQ9YmraW7Mf2btVCTxZuEB8EjjqQz3i8vECu7XCgvUfiW6NtSRewnHF5MNA3LbQTBQV3v9i -p x -t 1 C:WindowsTEMP\s2bk.1_.exe /stab C:WindowsTEMP\s2bk.2_.log taskkill /f /im msiexev.exe netsh advfirewall firewall delete rule name="Chrome" netsh advfirewall firewall delete rule name="Windriver" netsh advfirewall firewall add rule name="Chrome" dir=in program="C:Program FilesGoogleChromeApplicationchrome.txt" action=allow netsh advfirewall firewall add rule name="Windriver" dir=in program="C:Program FilesHardware Driver Managementwindriver.exe" action=allow C:Windows445.bat C:Windowssystem32PING.EXE ping 127.0.0.1 net stop Windows32_Update attrib +s +a +r +h wuauser.exe C:Windowssystem32SecEdit.exe secedit /configure /db C:Windowsnetbios.sdb C:Windowssystem32net1 stop Windows32_Update
Select ET signatures
2024217 || ET EXPLOIT Possible ETERNALBLUE MS17-010 Heap Spray 2024218 || ET EXPLOIT Possible ETERNALBLUE MS17-010 Echo Response 2024216 || ET EXPLOIT Possible DOUBLEPULSAR Beacon Response 2000419 || ET POLICY PE EXE or DLL Windows file download 2826160 || ETPRO TROJAN CoinMiner Known Malicious Stratum Authline (2017-04-28 1) 2017398 || ET POLICY Internal Host Retrieving External IP via icanhazip.com - Possible Infection 2022886 || ET POLICY Crypto Coin Miner Login
The rest is here:
Adylkuzz Cryptocurrency Mining Malware Spreading for Weeks ...
- Cryptocurrency News Round-Up: Bitcoin in Space & MtGox 2.0 [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- This week in bitcoin: Visualizing cryptocurrency [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- PotCoin cryptocurrency aiming to aid Colorados cash-only pot shops [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Crypto()Currency - CryptoCurrency.org [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- As Bitcoin Soars in Value, Alternative Cryptocurrencies ... [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Cryptocurrency - Wikipedia, the free encyclopedia [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bitcoin vs. Political Power: The Cryptocurrency Revolution - Stefan Molyneux at TNW Conference - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- TNW - Stefan Molyneux - Money, Power and Politics The Cryptocurrency Revolution - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bit coin and Cryptocurrency - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Atencoin is the First AML Compliant CryptoCurrency - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- How to Set Up a Ripple (CryptoCurrency) Generating System! - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bitcoin / Cryptocurrency - An Extensive FAQ - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- --- The Great Debate --- Bitcoin vs Altcoin @ The CryptoCurrency Convention 4/9/14 - - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bryce Weiner @ CryptoCurrency Convention 4/9/14 - - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Popularcoin @ CryptoCurrency Convention 4/9/14 - Joshua Nold - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- TimeKoin @ CryptoCurrency Convention 4/9/14 - Michael Brown - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Infinitecoin @ CryptoCurrency Convention 4/9/14 - Loring Small - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Bitcoin Exchange CryptoRush Loses Millions of BlackCoin Cryptocurrency - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Brock Pierce, Entrepreneur "FireSide Chat" @ CryptoCurrency Convention NYC - 4/9/14 - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Dogecoin Founder Speaks on the Future of Cryptocurrency [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Flash Gordon Conquers the Universe 3 Captured by Shark Men (1940) - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- [OFFICIAL SPONSOR] Nick Spanos, Bitcoin Center NYC @ CryptoCurrency Convention 4/9/14 - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- AuroraCoin @ CryptoCurrency Convention NYC 4/9/14 - David Lio - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Florincoin @ CryptoCurrency Convention NYC 4/9/14 - Joe Fiscella - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- DigiByte @ CryptoCurrency Convention NYC 4/9/14 - Jared Tate - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Digitalcoin @ CryptoCurrency Convention NYC 4/9/14 - Andrew Davidson - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- PotCoin @ CryptoCurrency Convention NYC 4/9/14 - Nick Iversen - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- ZenithCoin @ CryptoCurrency Convention NYC 4/9/14 - Eddie Corral - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- BitAngels Co-Founder, David Johnson @ CryptoCurrency Convention NYC 4/9/14 - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- New York to Regulate Bitcoin: Is the Cryptocurrency Biz Like the Wild West? - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Australian dogecoin founder speaks on the future of cryptocurrency [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- Cryptocurrency [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- How to Buy Bitcoins BTC Litecoins LTC Quarks QRK Cryptocurrency Altcoins - Video [Last Updated On: April 28th, 2014] [Originally Added On: April 28th, 2014]
- Coinnext Cryptocurrency Exchange Coming Soon - Video [Last Updated On: April 30th, 2014] [Originally Added On: April 30th, 2014]
- Cryptocurrency News Round-Up: MtGox Hearing Begins as Bitcoin gets Bloomberg Endorsement [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- mTrader.org - Cryptocurrency Mining System - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Ripple XRP Decentralized CryptoCurrency Bitcoin Exchange Open-Sourced BlockChain - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Cryptocurrency News Round-Up: Transparent Exchange & Bitcoin Banks [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- Bitcoin Cryptocurrency Crash Course with Andreas Antonopoulos - Jefferson Club Dinner Meet - Video [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- MAX KEISER & ALEX JONES talks about BITCOIN - Is Cryptocurrency the FUTURE? - Video [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- CryptoCurrency - cryptobars commodity Launch! - Video [Last Updated On: May 2nd, 2014] [Originally Added On: May 2nd, 2014]
- Coin Pursuit Launches SliceFeeds Interactive Cryptocurrency Network [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- CS 171 Final Project: Cryptocurrency Visualizations - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- The Mises View: "Taxing Cryptocurrency" | Jeff Deist - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Cryptocurrency Explained The Tech Guy 1046 - Video [Last Updated On: May 3rd, 2014] [Originally Added On: May 3rd, 2014]
- Such Dogecoin. Much Validity. How one altcoin may have turned into cryptocurrencys best marketing tool [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- Cryptocurrency | Ground Zero with Clyde Lewis [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- Know How 74 Cryptocurrency - Video [Last Updated On: May 4th, 2014] [Originally Added On: May 4th, 2014]
- MIT undergrads will each receive $100 in bitcoin [Last Updated On: May 5th, 2014] [Originally Added On: May 5th, 2014]
- Bitcoin wins US election panel's approval for political donations [Last Updated On: May 9th, 2014] [Originally Added On: May 9th, 2014]
- CryptoCurrency of the World Unite! - Video [Last Updated On: May 10th, 2014] [Originally Added On: May 10th, 2014]
- The Bitcoin Stats Show - Ep 6: 16th April 2014 - Video [Last Updated On: May 10th, 2014] [Originally Added On: May 10th, 2014]
- Bitcoin vs. Political Power: The Cryptocurrency Revolution Stefan Molyneux at TNW Conferen - Video [Last Updated On: May 11th, 2014] [Originally Added On: May 11th, 2014]
- AMD cuts Radeon R9 280 price as inflation woes die down [Last Updated On: May 15th, 2014] [Originally Added On: May 15th, 2014]
- BBT Presents: Ode to Cryptocurrency - Video [Last Updated On: May 15th, 2014] [Originally Added On: May 15th, 2014]
- The Cryptocurrency Certification Consortium - Video [Last Updated On: May 15th, 2014] [Originally Added On: May 15th, 2014]
- Scryptify Cryptocurrency Video - Crypto Currency Exchanges - Video [Last Updated On: May 15th, 2014] [Originally Added On: May 15th, 2014]
- Bitpagar Cryptocurrency - Video [Last Updated On: May 16th, 2014] [Originally Added On: May 16th, 2014]
- How to Mine Cryptocurrency Safely - Video [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Bunnycoin - Innovative New Cryptocurrency - Video [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Cubieboard 1 2 Mining Peercoins SHA256 based Cryptocurrency - Video [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Megacoin Teaser Video New CryptoCurrency Bitcoin Best AltCoin 2014 Anonymous Zerocoin - Video [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Jan Irvin on Learning, Statism, Culture, Cryptocurrency and Voluntarism -- Potent News Podcast #1 - Video [Last Updated On: May 17th, 2014] [Originally Added On: May 17th, 2014]
- Nxt cryptocurrency platform: Proof of Stake mining system - Video [Last Updated On: May 19th, 2014] [Originally Added On: May 19th, 2014]
- Givecoin.info Announces Partnership with Do A Bit of Good: World's First Charitable Mining Screensaver [Last Updated On: May 21st, 2014] [Originally Added On: May 21st, 2014]
- Cryptocurrency: Get Mining! - Video [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- Violincoin - The first cryptocurrency for musician - - Video [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- Trollcoin - The Fun Cryptocurrency! - Video [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- The Cryptocurrency Store (Spanish/Espagnol) - Video [Last Updated On: May 23rd, 2014] [Originally Added On: May 23rd, 2014]
- How To Trade CryptoCurrency: Sign up to a safe and reliable exchange for trading CryptoCurrency - Video [Last Updated On: May 23rd, 2014] [Originally Added On: May 23rd, 2014]
- UT students to launch cryptocurrency exchange [Last Updated On: May 24th, 2014] [Originally Added On: May 24th, 2014]
- Cryptocurrency and Nonprofits with Eric Nakagawa - Video [Last Updated On: May 24th, 2014] [Originally Added On: May 24th, 2014]
- The Cryptocurrency Store - Video [Last Updated On: May 24th, 2014] [Originally Added On: May 24th, 2014]
- Videoconferencia Cryptocurrency 201243946 - Video [Last Updated On: May 27th, 2014] [Originally Added On: May 27th, 2014]
- VideoCharla Jesus Ramos Cryptocurrency - Video [Last Updated On: May 27th, 2014] [Originally Added On: May 27th, 2014]
- Cryptocurrency Round-Up: Bitcoin Pioneer Dies and Digital Currency's Status in Australia [Last Updated On: September 1st, 2014] [Originally Added On: September 1st, 2014]
- Bleutrade Cryptocurrency Exchange Review - Video [Last Updated On: September 1st, 2014] [Originally Added On: September 1st, 2014]
- Bitcoin enthusiasts discuss the cryptocurrency - Video [Last Updated On: September 1st, 2014] [Originally Added On: September 1st, 2014]
- Make Fast 1.0 up to 10.00 BTC or Any Cryptocurrency REAL CASH - Video [Last Updated On: September 1st, 2014] [Originally Added On: September 1st, 2014]
- Halcyon cryptocurrency - Video [Last Updated On: September 1st, 2014] [Originally Added On: September 1st, 2014]