
Recently, the full source code of the GhostDNS exploit kit was released online . For those who don't know what it is, GhostDNS is software that uses “cross-site request forgery (CSRF)” methods to change DNS settings and send phishing pages to users, with the aim of stealing their login credentials.
The source code of the program, as well as files from several different phishing websites, were found inside a ZIP archive, which is hosted on a file-sharing platform. Because the user who uploaded the file had not set a security password, Avast 's security application was able to analyze it and discover the GhostDNS exploit kit code.
“We downloaded the file for research purposes and subsequently discovered the source code of the Program,” the company. Shortly afterwards, the Avast Threat Intelligence team shared details about how GhostDNS works, as well as the other files contained in “KL DNS.rar.”

From the file name, it seems that it uses DNS hijacking and keylogging to steal data from its victims. Avast confirmed this after a detailed inspection of the files. The inspection also revealed that the file contains two different attack methods, known as Router EK and BRUT.
As shown in the image below, both methods use CSRF requests to change the DNS settings of the targeted device. However, Router EK cannot work on its own, as it requires the user to open the infected link. On the other hand, the BRUT method works without the user’s help.

In addition to the GhostDNS kit files, the researchers also discovered a list containing many targeted IP addresses, located in over 70 different countries. A large percentage of these addresses are located in South America, Brazil, Australia, and Germany.
According to Avast, the archive also contained several phishing templates. Some of these templates mimicked the websites of Brazil's largest banks, as well as Netflix.
