Analyzing DotkaChef Exploit Pack
"DotkaChef" (aka DotCache, DotCacheF) was discovered by Chris Wakelin (@EKwatcher) several months ago. Today we noticed that several things have changed but it's functionally the same.
If you look closely at the websites infecting visitors’ computers linked to "DotkaChef", they are running Invision Power Board (IP.Board). It’s quite possible that cybercriminals have been targeting a vulnerability in old installations of IP.Board, specifically versions <= 3.3.4 (CVE-2012-5692 - Unserialized PHP Code Execution).
When a website is successfully compromised, the "DotkaChef" Pack gets uploaded to the server in one folder with random characters. This appears to be a self-contained, portable exploit pack.
Back in June or so, the URLs looked like this (and thus its name):
Since then, the URL formats have changed and no longer use the “/.cache/” folder.
Let’s have a closer look...
The URL for the landing page has a bunch of random characters. This is actually base64 characters in reverse. Reversing and de-base64’ing the string reveals the following.
The pipe character is used as a delimiter to separate out “fs”, the website path, a 14-digit “key”, and the payload. When the malicious URLs are generated, the “k” variable contains a 16-digit number with the 14-digit “key” as the base.
The “f” variable is associated with the malicious Java applet. This kit uses two Java exploits and the “a(tom.jar)” and “s(ite.jar)” values correspond to the exploit to be used.
If you were to hit the page with an incorrect URL, you will see this error message:
The deobfuscated version looks like this. It's calling up the “atom.jar” exploit which abuses CVE-2013-2423.
Using JD-GUI, we can see that there's little in the way of obfuscation as it’s using base64 to convert its strings. It reads in the URL from the landing page and sends the payload to the computer. It reads in the URL from the landing page and sends the payload to the computer.
The other Java applet is basically doing the same thing. This applet exploits CVE-2013-1493.
The payload comes down with the “mp3” file extension that gets renamed then executed. You will get one of two payloads – Zbot or Zaccess.
Finally, the exploit pack keeps track of successful and unsuccessful loads. Each row contains the key, a pipe delimiter, and a status code. The status code of “466” indicates it was a successful load.
By reviewing the logs, there are quite a number of successful loads making this a simple yet effective exploit pack.
File: atom.jar (CVE-2013-2423)
File: site.jar (CVE-2013-1493)
File: bb.mp3 (Zbot)
File: sm_main.mp3 (Zaccess)