logo.png
Guided Website Threat Review

Foregenix Blog

Benjamin Hosack

Alert: New PHP Webshell Identified

web security, Magento

,03/03/17 11:50

A new piece of malware has been identified by the Foregenix DFIR team.  The malware is a PHP webshell - a script, which when installed on a compromised system, presents a sophisticated administration platform allowing the attacker to browse the filesystem of the compromised server, upload, create, edit, download or delete files or stop running processes.

The Malware

It even has functionality to add a further backdoor onto the system which would allow the attacker to connect back to the server as desired. The malware, named ‘BArNEr’ within the code, appears to be present on a number of systems in the wild and may be connected to an Indonesian cyber crime collective called the ‘Indonesia HackRs’. 

New PHP Malware.png

The code that creates the web shell is generally found “hidden” at the end of a JPEG image.

Known as a ‘dropper’, this file would first be placed on a compromised system and then activated by the attacker requesting it from the website. During analysis it was found that the code for the web shell did not work on PHP 7 (due to its use of a depreciated function) but would function as intended if the affected website was running PHP5.

Foregenix urges website owners to examine their systems for presence of this malware. 

How do I detect this malware on my website?

Guided Website Threat ReviewDetection is simple with the right tools.  Apply for a Guided Threat Review of your website and our team will scan the internal file system of your website using FGX-Web for this malware and many others.

Alternatively, the following grep commands should reveal these files if they are present:

Ajax Harvester  Initialiser

grep -slr‘\\x6F\\x6E\\x65\\x70\\x61\\x67\\x65\\x7C\\x63\\x68\\

x65\\x63\\x6B\\x6F\\x75\\x74\\x7C\\x6F\\x6E\\x65\\x73\\x74\\x65\\

x70\\x7C\\x66\\x69\\x72\\x65\\x63\\x68\\x65\\x63\\x6B\\x6F\\x75\\x74’ .

 

Ajax Harvester – Harvester

grep –slr‘\\x73\\x65\\x6C\\x65\\x63\\x74\\x5B\\x69\\x64\\x3D\\x22\\x73\\

x74\\x72\\x69\\x70\\x65\\x43\\x61\\x72\\x64\\x45\\x78\\x70\\x69\\x72\\

x79\\x59\\x65\\x61\\x72\\x22\\x5D’ .

 

Webshell Dropper

grep -slrR 'file_exists\|BADUBAMM' .

 

BArNEr’ Webshell

grep -slr '7P15f9s4kjgO/737+ex7YDSejj12rNOH4o6nqfs+rTOdn4ciKYoSJcqk7t' .

TRENDING POSTS

Duncan Slater
Alert: Major UK Payment Service Provider iFrame Man-In-The-Middle Breach

The Foregenix Digital Forensics and Incident Response Team recently reported a man-in-the-middle ...

Read More
Kirsty Trainer
The "Key" to Secure Data - P2PE - Derived Unique Key Per Transaction (DUKPT)

Written by Andrew McKenna, PCI QSA, PCIP at Foregenix The encryption key infrastructure usually ...

Read More

Cyber Security Insights

Alex Constantinou
15/06/17 10:34

Password Manager OneLogin breached.

With the amount of websites and services which require passwords for authentication increasing, it can be difficult at times to remember all our ...

Read More

Ewan Gardner
01/06/17 12:20

General Data Protection Regulation (GDPR) is coming. Don't bury your head in the sand.

What does May 25th 2017 mean to you? The 40th anniversary of Star Wars being released in cinemas? The 78th birthday of celebrated actor Sir Ian ...

Read More

Duncan Slater
26/05/17 14:08

“Mind the Gap” – As a Small eCommerce Business, Who is Responsible for Your Security?

  Major corporations spend hundreds of thousands of pounds and in some cases employ teams of people dedicated to manage and ensure the security of ...

Read More

Kirsty Trainer
23/05/17 10:48

8 Critical Steps to Reduce the Risk of Ransomware Infection

The WannaCry ransomware infestation is a wake-up call for all entities connected to public networks, such as the internet, to recognise ...

Read More

Mike Hinton
16/05/17 17:24

Foregenix announce new partnership with Juno Web Design

We’re delighted to announce a new partnership between ourselves and Nottinghamshire based agency ‘Juno’. With the rapidly increasing threat to ...

Read More