
The recently discovered flaw CVE-2019-2725 in Oracle WebLogic, which received a patch some time ago, is still being used in Cryptojacking, according to security researchers at Trend Micro.
This is a zero-day remote command execution vulnerability affecting the wls9_async and wls-wsat components of Oracle Weblogic. All versions of Weblogic are vulnerable to the vulnerability, including the latest, which has wls9_async_response.war and wls-wsat.war enabled.
The flaw could be exploited by a hacker by sending a specially modified HTTP request.
While the CVE-2019-2725 flaw was patched in late April, a few days later malicious actors began using the Oracle WebLogic Server vulnerability to spread the Sodinokibi ransomware.
Experts from the SANS Institute reported that the flaw was already being exploited by hackers to carry out Cryptojacking campaigns.
According to security experts at Trend Micro, the malware, in order to remain hidden, hides its malicious codes in certificate files. Once the malware is installed on the system, it begins to exploit the flaw and initiates a series of chain attacks.
The attack starts with a PowerShell script that downloads a certificate file from the C2 server. The malicious code uses the CertUtil tool to decrypt the file and then executes it using PowerShell. The downloaded file is then deleted using cmd.
The certificate file appears as PEM (Privacy-Enhanced Mail).
The command in the certificate file is used by the crooks to download and execute another PowerShell script in memory. The script downloads and executes multiple files, including Sysupdate.exe (Monero miner), Config.json (configuration file for the Miner), Networkservice.exe (likely used to propagate and exploit WebLogic), Update.ps1 (the PowerShell script for memory), Sysguard .exe (watchdog for the mining process), and Clean.bat (deletes other items).
Experts found that the update.ps1 file containing the decoded certificate file is replaced with the new update.ps1 and a scheduled task is created to run the new PowerShell script every 30 minutes.
The practice of hiding malicious code in certificates to avoid detection is nothing new. Sophos tackled one such case in a test demonstration last year.
