{"id":1554,"date":"2024-04-22T12:39:51","date_gmt":"2024-04-22T12:39:51","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1554"},"modified":"2024-04-29T13:14:46","modified_gmt":"2024-04-29T13:14:46","slug":"exploit-win32-cve-2024-3094","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2024\/04\/22\/exploit-win32-cve-2024-3094\/","title":{"rendered":"Exploit.Win32.CVE-2024-3094"},"content":{"rendered":"<h2>Overview<\/h2>\n<p><strong>Type: <\/strong>Backdoor<br \/>\n<strong>Destruction level:<\/strong> High<br \/>\n<strong>Prevalence:<\/strong> Moderate<\/p>\n<h3>What is a Vulnerability?<\/h3>\n<p>In computer security, Vulnerability is a weak point in a platform that can be exploited by an intruder or malware and cause unauthorized access to the victim\u2019s system. Vulnerabilities let intruders execute arbitrary commands, access to system\u2019s memory, install malware and siphon data, and wipe and change enterprise and organizational critical information.<\/p>\n<p>&nbsp;<\/p>\n<h3>What is Backdoor Malware?<\/h3>\n<p>Backdoors are applications designed to allow hackers to bypass the system security mechanism, granting unauthorized access to various system resources. Hackers can enter the system, with no concern for altered usernames or passwords, bypass authentication protocols. These applications come in various forms and hackers use them upon their needs to breach a system resource.<\/p>\n<p>&nbsp;<\/p>\n<h3>What is Exploit.Win32.CVE-2024-3094?<\/h3>\n<p><strong>Xz-utils<\/strong>, previously known as LZMA Utils, is a set of free command-line software for Unix-like and Windows-like operating systems utilized for data compression. On March 29, 2024, in versions <strong>5.6.0<\/strong> and <strong>5.6.1<\/strong> of the software a backdoor, was detected. This backdoor is identified as<span style=\"color: #ff0000\"> CVE-2024-3094<\/span> with a CVSS score of 10.0 . It is located within the <strong>liblzma<\/strong> library, facilitating unauthorized remote access for potential hackers.<\/p>\n<p>This vulnerability impacts systems running Linux distributions Debian and RPM based on the x86-64 architecture.<\/p>\n<p>&nbsp;<\/p>\n<h2>Technical Review<\/h2>\n<p>The compromise of the source code for versions 5.6.0 and 5.6.1 led to the infiltration of the library file with the backdoor. Generally, encrypted content and the backdoor content are hidden from source code within two files, named as follows and located in the tests\/files path:<\/p>\n<p><span style=\"color: #0000ff\">bad-3-corrupt_lzma2.xz<\/span><br \/>\n<span style=\"color: #0000ff\">good-large_compressed.lzm<\/span><\/p>\n<p>The process of executing source code scripts and generating an infected library is as follows:<\/p>\n<ol>\n<li>The malicious build-to-host.m4 script is executed during the library creation process, decrypting the bad-3-corrupt_lzma2.xz file.<\/li>\n<li>Decryption of bad-3-corrupt_lzma2.xz results in a bash script, which performs a complex decryption process on the good-large_compressed.lzma file, transforming it into another script.<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-4060 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/04\/1-\u0627\u0633\u06a9\u0631\u06cc\u067e\u062a-bash-\u0627\u06cc\u062c\u0627\u062f-\u0634\u062f\u0647-\u062f\u0631-\u0646\u062a\u06cc\u062c\u0647-\u0631\u0645\u0632\u06af\u0634\u0627\u06cc\u06cc-\u0641\u0627\u06cc\u0644-bad-3-corrupt_lzma2.xz_.png\" alt=\"\u0627\u0633\u06a9\u0631\u06cc\u067e\u062a bash \u0627\u06cc\u062c\u0627\u062f \u0634\u062f\u0647 \u062f\u0631 \u0646\u062a\u06cc\u062c\u0647 \u0631\u0645\u0632\u06af\u0634\u0627\u06cc\u06cc \u0641\u0627\u06cc\u0644 bad-3-corrupt_lzma2.xz\" width=\"1009\" height=\"487\" \/>Figure 1 &#8211; Bash script created as a result of decrypting the bad-3-corrupt_lzma2.xz file<\/p>\n<p style=\"padding-left: 30px\">3. The final script extracts a common object called liblzma_la-crc64-fast.o, which is added to the process of compiling liblzma.<\/p>\n<p>This sequence ultimately results in the creation of a modified liblzma library, deployable by any software linked with this library.<\/p>\n<p>&nbsp;<\/p>\n<h3><strong>Indicators of Compromise (IoC)<\/strong><\/h3>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/11\/svg\/1f534.svg\" alt=\"?\" width=\"12\" height=\"12\" \/>\u00a0Existance of xz-utils versions 5.6.0 and 5.6.1 indicates potential system infection to this backdoor. To ascertain the installed xz-utils version, execute the following commands:<\/p>\n<p><strong><span style=\"color: #0000ff\">xz \u2013V<\/span><\/strong><\/p>\n<p>or<\/p>\n<p><strong><span style=\"color: #0000ff\">xz \u2013version<\/span><\/strong><\/p>\n<p>&nbsp;<\/p>\n<h3>Performance Description<\/h3>\n<p><strong>SSHD<\/strong> or <strong>SSH Daemon<\/strong>, a component of the OpenSSH suite, is a server side program responsible for listening to incoming SSH connections from clients.The malicious code integrated into the liblzma creation process affects SSH (SSHD) and permits an attacker possessing the private key <span style=\"color: #0000ff\">Ed448<\/span> to gain unauthorized access to the system.<\/p>\n<p>&nbsp;<\/p>\n<p>The injected code within the liblzma library operates as follows:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/11\/svg\/31-20e3.svg\" alt=\"1\ufe0f\u20e3\" width=\"14\" height=\"14\" \/>\u00a0IFUNC (Indirect Function) feature is one of the main techniques used by this backdoor to gain initial control during execution. <strong>IFUNC<\/strong> in GCC compiler enables developers to create multiple versions of a function selected by the resolver, based on various criteria such as processor type, at runtime.<\/p>\n<p>The attacker abuse ifunc resolver commands, which are crc32_resolve and crc64_resolve functions, to invoke the malicious get_cpuid_ function. This funciton is injected into the library code. The backdoor abuse this mechanism to intercept or hook execution.<br \/>\nThe following figures show the code for the injected functions within the liblzma library and their call hierarchy:<\/p>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/04\/2-%D9%85%D8%AD%D8%AA%D9%88%D8%A7%DB%8C-%D8%AA%D8%A7%D8%A8%D8%B9-crc64_resolve-%DA%A9%D9%87-%D8%AA%D8%A7%D8%A8%D8%B9-get_cpuid-%D8%B1%D8%A7-%D9%81%D8%B1%D8%A7%D8%AE%D9%88%D8%A7%D9%86%DB%8C-%D9%85%DB%8C%E2%80%8C%DA%A9%D9%86%D8%AF.png\" alt=\"\u0645\u062d\u062a\u0648\u0627\u06cc \u062a\u0627\u0628\u0639 crc64_resolve \u06a9\u0647 \u062a\u0627\u0628\u0639 get_cpuid \u0631\u0627 \u0641\u0631\u0627\u062e\u0648\u0627\u0646\u06cc \u0645\u06cc\u200c\u06a9\u0646\u062f\" width=\"481\" height=\"401\" \/><\/p>\n<p style=\"text-align: center\">Figure 2: Content of the crc64_resolve function calling the get_cpuid function.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center\"><img decoding=\"async\" class=\"aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/04\/3-%D9%85%D8%AD%D8%AA%D9%88%D8%A7%DB%8C-%D8%AA%D8%A7%D8%A8%D8%B9-%D9%81%D8%B1%D8%A7%D8%AE%D9%88%D8%A7%D9%86%DB%8C-%D8%B4%D8%AF%D9%87-%D8%AF%D8%B1-get_cpuid.png\" alt=\"\u0645\u062d\u062a\u0648\u0627\u06cc \u062a\u0627\u0628\u0639 \u0641\u0631\u0627\u062e\u0648\u0627\u0646\u06cc \u0634\u062f\u0647 \u062f\u0631 get_cpuid\" \/>Figure 3: Content of the called function in get_cpuid.<\/p>\n<p>&nbsp;<\/p>\n<p style=\"direction: rtl\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-4063 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/04\/4-\u0645\u062d\u062a\u0648\u0627\u06cc-\u062a\u0627\u0628\u0639-\u0645\u062e\u0631\u0628-\u062a\u0632\u0631\u06cc\u0642-\u0634\u062f\u0647-\u062f\u0631-liblzma.png\" alt=\"\u0645\u062d\u062a\u0648\u0627\u06cc \u062a\u0627\u0628\u0639 \u0645\u062e\u0631\u0628 \u062a\u0632\u0631\u06cc\u0642 \u0634\u062f\u0647 \u062f\u0631 liblzma\" width=\"891\" height=\"780\" \/><\/p>\n<p style=\"text-align: center\">Figure 4: Content of the injected malicious function in liblzma.<\/p>\n<p>&nbsp;<\/p>\n<p>2\ufe0f\u20e3\u00a0This backdoor is designed to intercept the RSA_public_decrypt function call within the SSH daemon (SSHD) process. This is done by intercepting (hooking) RSA_public_decrypt functions calls.<br \/>\nThis function is frequently used for decrypting encrypted data using the RSA public key and as part of the signature verification process in secure communications.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"\" src=\"https:\/\/s.w.org\/images\/core\/emoji\/11\/svg\/33-20e3.svg\" alt=\"3\ufe0f\u20e3\" width=\"17\" height=\"17\" \/>\u00a0Subsequently, host signature is verified using a fixed Ed448 key. Successful signature verification implies communication from an attacker that possesses the private key.<\/p>\n<p>4\ufe0f\u20e3Upon verification, the backdoor executes malicious code dispatched by the attacker by sending them to the system() function. This access grants the intruder remote code execution on the compromised system.<\/p>\n<p>Furthermore, the created backdoor codes checks requirements before initiating activities on the target system. These checks typically aim to thwart debugging and backdoor code analysis.<\/p>\n<p>&nbsp;<\/p>\n<h3>Malware Requirements Checklist<\/h3>\n<ul>\n<li>The TERM environment variable is unset. (to avoid operation within interactive terminal sessions or in sandbox environments)<\/li>\n<li>The value [0]argv is set to \/usr\/sbin\/sshd, indicating that sshd is running.<\/li>\n<li>LD_DEBUG and LD_PROFILE are both unset.<\/li>\n<li>LANG must be configured. (This environment variable specifies the user&#8217;s default session settings, including language, Character Encoding and other language-related settings.)<\/li>\n<li>Existence of Debug tools, such as rr and gdb, are checked.<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h2>How to deal with and Clean the system?<\/h2>\n<p>Padvish antivirus detects files associated with this backdoor. Therefore, installing Padvish Antivirus is advised to prevent malware infiltration.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Backdoor Destruction level: High Prevalence: Moderate What is a Vulnerability? In computer security, Vulnerability is a weak point in a platform that can be exploited by an intruder or malware and cause unauthorized access to the victim\u2019s system. Vulnerabilities let intruders execute arbitrary commands, access to system\u2019s memory, install malware and siphon data,&hellip;<\/p>\n","protected":false},"author":27,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[69],"tags":[53,70,71,72],"class_list":["post-1554","post","type-post","status-publish","format-standard","hentry","category-vulnerability","tag-backdoor","tag-exploit-win32-cve-2024-3094","tag-vulnerability","tag-win32-cve-2024-3094"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1554","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1554"}],"version-history":[{"count":6,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1554\/revisions"}],"predecessor-version":[{"id":1560,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1554\/revisions\/1560"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1554"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1554"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1554"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}