HomeSecurityDuri campaign spreads malware via HTML and JavaScript

Duri campaign spreads malware via HTML and JavaScript

A new attack campaign uses a combination of HTML smuggling techniques and data blobs to evade detection and download of the malware. Named Duri, the campaign exploits the JavaScript blob method that creates the malicious file in the browser on the Web, thus avoiding detection by sandbox and proxy.

“Traditional network security solutions such as proxies, firewalls , and sandboxes rely on the transfer of objects over the wire. For example, a sandbox might extract file objects such as .exe, .zip, and other suspicious objects from the wire and then send them to the sandbox for detonation,” states a report published by Menlo Security.

Duri malware HTML Javascript

However, Duri incorporates a special technique known as “HTML smuggling”.

Τον Ιούλιο, ερευνητές στο Menlo Security παρατήρησαν ότι μια ύποπτη λήψη αποκλείστηκε από το πρόγραμμα περιήγησής τους.

Upon closer inspection, they found that the source of the file was not a URL, but the result of JavaScript code that injected a malicious payload into the victim.

Τι είναι το HTML smuggling;

HTML smuggling uses a combination of JavaScript, HTML5, and its technologies, such as “data:” URLs to create the payload on the fly and serve file downloads from the browser, instead of a direct URL that “points” to a server.

“With Duri, the entire payload is built on the client side (browser), so objects are not transferred over the wire and thus the sandbox cannot inspect it”, the Menlo report says.

For those interested, Stan Hegt of Outflank explains the technique perfectly.

Duri campaign spreads malware via HTML and JavaScript

Using a sample macro-loaded Word document (.doc), Hegt demonstrated how the file could be created entirely in JavaScript and how perimeter-based detection systems that rely solely on the file extension would not suspect an HTML file to be malicious.

In the case of Duri, when the user clicks the link provided by the intruder, many redirects lead them to an HTML page hosted on duckdns.org.

Then, this website launches JavaScript code to create a “blob” object from a base64 encoding variable contained in the script.

Duri campaign spreads malware via HTML and JavaScript

Disassembly of the Duri payload

As it appears, a ZIP file is created only by the JavaScript code. At the end of execution, the script requests the download of this file in the web browser.

It is interesting that what is contained in the ZIP is an MSI file, which is not a new payload.

The Menlo report explains, “The malware that Duri downloads is not new. According to Cisco, it was previously delivered via Dropbox, but attackers have now displaced Dropbox with other cloud hosting and have engaged in HTML smuggling to infect endpoints.”

The researchers analyzed the MSI file and discovered a dark JScript.

The detailed analysis of the Duri campaign of the company together with the Zero Trust detection approach that was used and a large list of compromise indicators (IoCs) related to the campaign are provided in their report.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS