Aerosol Posted January 22, 2015 Report Posted January 22, 2015 CONTENTSIntroduction 4Executive summary 41 The initial incident 52 Analysis 62.1 Plug-in ................................................................................................................................................ 62.2 Origin.................................................................................................................................................. 92.3 Features............................................................................................................................................ 112.4 Setup ................................................................................................................................................ 112.5 CMS integration................................................................................................................................ 132.6 Crypto and Communication ............................................................................................................. 152.7 Manual Control ................................................................................................................................ 172.8 Configuration.................................................................................................................................... 182.9 Backup communication.................................................................................................................... 192.10 Purpose: Blackhat SEO ..................................................................................................................... 202.11 Possible author................................................................................................................................. 223 Infrastructure 233.1 Spreading.......................................................................................................................................... 233.2 Command and control servers......................................................................................................... 244 Checking for CryptoPHP in plug-ins and themes 264.1.1 WordPress......................................................................................................................... 264.1.2 Joomla ............................................................................................................................... 274.1.3 Drupal................................................................................................................................ 275 Appendix: Indicators of Compromise 285.1 Network detection ........................................................................................................................... 285.2 File hashes........................................................................................................................................ 295.3 Command and Control servers......................................................................................................... 305.3.1 Version 0.1......................................................................................................................... 305.3.2 Version 0.1 (other variant) ................................................................................................ 305.3.3 Version 0.2, 0.2x1, 0.2x2, 0.2b3, 0x2x4, 0.2x9, 0.3, 0.3x1................................................. 355.3.4 Version 1.0, 1.0a................................................................................................................ 395.4 Backup communication email addresses......................................................................................... 425.4.1 Version 0.1......................................................................................................................... 425.4.2 Version 0.1 (other variant) ................................................................................................ 425.4.3 Version 0.2, 0.2x1, 0.2x2, 0.2b3, 0.2x4, 0.2x9, 0.3 ............................................................ 425.4.4 Version 1.0, 1.0a................................................................................................................ 50Read more: http://dl.packetstormsecurity.net/papers/evaluation/cryptophp-whitepaper-foxsrt-v4.pdf 1 Quote