HomeSecurityHow does the new Frebniis malware work?

How does the new Frebniis malware work?

New malware, Frebniis, has been unleashed by hackers on Microsoft's Internet Information Services (IIS). This stealthy malware executes commands sent via web requests.

See also: Citrix patches vulnerabilities in Workspace, Virtual Apps and Desktops

How does the new Frebniis malware work?

Symantec's Threat Hunter team has uncovered Frebniis, which is currently being used by an unknown malicious actor to target victims from Taiwan.

Microsoft IIS is a powerful web server and web app hosting platform for services like Outlook on the Web for Microsoft Exchange, allowing users to easily access their email messages from any device.

Symantec recently discovered attackers abusing an IIS feature called “Failed Request Event Buffering” (FREB). Its purpose is to collect metadata such as IP address, HTTP headers, and cookies. It is intended to help server admins troubleshoot unexpected HTTP status codes or request processing issues.

The malware injects malicious code into a specific function of a DLL file that controls FREB (“iisfreb.dll”) to allow the attacker to intercept and monitor all HTTP POST requests sent to the ISS server. When the malware detects specific HTTP requests sent by the attacker, it analyzes the request to determine which commands to execute on the server.

See also: New Mirai malware variant infects Linux devices to create DDoS botnets

According to Symantec, malicious actors must compromise an IIS server to compromise the FREB module, however, the exact approach to the infiltration was unknown.

The code injected is a .NET backdoor that supports proxying and executing C# code without ever touching disk, making it completely hidden. It looks for requests made to the logon.aspx or default.aspx pages with a specific password parameter.

A second HTTP parameter, which is a base64 encoded string, instructs Frebniis to communicate and execute commands on other systems through the compromised IIS, potentially reaching protected internal systems that are not exposed to the internet.

This malware can execute the following commands:

Frebniis

The main advantage of abusing the FREB component for the described purposes is avoiding detection by security tools. This unique HTTP backdoor leaves no traces or files and does not create suspicious processes on the system.

Although the initial compromise pathway is unknown, updating your software is generally recommended to minimize the chances of hackers exploiting known vulnerabilities.

See also: Scandinavian Airlines: Cyberattack led to data leak

Using advanced network traffic monitoring tools can help identify any irregular behavior from malware like Frebniis.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS