{"id":79199,"date":"2013-06-02T22:40:44","date_gmt":"2013-06-02T20:40:44","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=79199"},"modified":"2013-06-03T08:18:14","modified_gmt":"2013-06-03T06:18:14","slug":"mangaung-website-hacked-serving-malware-from-jamaica","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/79199-mangaung-website-hacked-serving-malware-from-jamaica.html","title":{"rendered":"Mangaung website hacked, serving malware from Jamaica"},"content":{"rendered":"<p>The website for the Mangaung municipality (mangaung.co.za, bloemfontein.co.za) is serving malware hosted on the website of the Jamaica Cultural Development Commission (jcdc.gov.jm).<\/p>\n<p>At the time of writing, more than a day after informing both the State Information Technology Agency (<a title=\"SITA\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/313647-State-Information-Technology-Agency-(SITA)\">SITA<\/a>) and the JCDC, a Windows executable is automatically downloaded to your computer when you visit the website of the Mangaung municipality.<\/p>\n<p>Interestingly, visiting the the JCDC website did not trigger the file download.<\/p>\n<p>The executable is called \u201cfirefox.exe\u201d and it was embedded in the Mangaung website using a simple HTML &lt;iframe&gt; tag pointing to http:\/\/www.jcdc.gov.jm\/uploads\/firefox.exe.<\/p>\n<p>The source of the Mangaung website also contained an iframe pointing to a firefox.exe file hosted on shell32.tk, but it appeared to be inaccessible.<\/p>\n<div id=\"attachment_79203\" style=\"width: 454px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-79203\" class=\"size-full wp-image-79203\" alt=\"Mangaung firefox.exe malware download prompt\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/05\/Mangaung-firefox.exe-malware-download-prompt.jpg\" width=\"444\" height=\"302\" \/><p id=\"caption-attachment-79203\" class=\"wp-caption-text\">Mangaung firefox.exe malware download prompt<\/p><\/div>\n<h3 class=\"my-4\">Masquerading as Firefox? Smells like FinSpy<\/h3>\n<p>A report recently released by <a title=\"Citizen Lab\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/513056-Citizen-Lab\">Citizen Lab<\/a> revealed that a spyware suite used by governments known as FinFisher sometimes had its trojan (FinSpy) masquerade as Firefox.<\/p>\n<p>Add to this that Citizen Lab reported that it had discovered command &amp; control servers for the spyware suite on the Telkom network in South Africa, and a logical first reaction is to suspect that a version of the FinSpy trojan was being hosted on the Mangaung website.<\/p>\n<p>However, Citizen Lab\u2019s report suggests that FinSpy would use far less overt methods of infecting a machine.<\/p>\n<p>An investigation by Citizen Lab, which was later confirmed by <a title=\"Sensepost\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/313979-SensePost\">Sensepost<\/a>, indicated that the malware was not FinFisher.<\/p>\n<h3 class=\"my-4\">Taiwanese spyware?<\/h3>\n<p>A quick check on VirusTotal did not provide conclusive results as to what this malware might be, but further prodding from Sensepost revealed that the trojan was written in .NET.<\/p>\n<p><a title=\"Jeremy du Bruyn\" href=\"http:\/\/mybroadband.co.za\/vb\/showthread.php\/531556-Jeremy-du-Bruyn\">Jeremy du Bruyn<\/a>, a security expert at Sensepost, explained the trojan\u2019s code had been obfuscated, making it more difficult to see what its purpose is.<\/p>\n<p>\u201cIt employs a number of measures to make static analysis of the malware more difficult, for instance by calling \u2018IsDebuggerPresent\u2019 to check if it is being analysed and if so exit; as well as not using any hardcoded strings,\u201d Du Bruyn said.<\/p>\n<p>The trojan developer appears to be Chinese-speaking, Du Bruyn said, which he said correlates with the Taiwanese IP address of the command &amp; control server.<\/p>\n<p>\u201cThe Trojan communicates with an IP in Taiwan, specifically 114.34.216.71 on port 888,\u201d Du Bruyne said.<\/p>\n<div id=\"attachment_79201\" style=\"width: 610px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-79201\" class=\"size-full wp-image-79201\" alt=\"Jeremy du Bruyn from Sensepost\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/05\/Jeremy-du-Bruyn-The-Panda.jpg\" width=\"600\" height=\"400\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/05\/Jeremy-du-Bruyn-The-Panda.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2013\/05\/Jeremy-du-Bruyn-The-Panda-250x166.jpg 250w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><p id=\"caption-attachment-79201\" class=\"wp-caption-text\">Jeremy du Bruyn from Sensepost<\/p><\/div>\n<h3 class=\"my-4\">Malware still being served<\/h3>\n<p>At the time of publication the Mangaung website was still serving the malware, despite SITA and the JDCD being alerted to it on Thursday, 30 May 2013.<\/p>\n<p>While the JDCD did not respond by the time of publication, a SITA spokesperson did tell MyBroadband that they don\u2019t provide the hosting for this particular government website.<\/p>\n<p><em>Thanks to Siavosh, Jeremy, and Dominic of Sensepost for their work in analysing the malware. Thanks to John and the team from Citizen Lab who also provided valuable information for this article.<\/em><\/p>\n<h3 id=\"related\">More on information security in South Africa<\/h3>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/78873-adsl-router-security-concern-in-sa.html\"><strong>ADSL router security concern in SA<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/78753-saps-website-still-vulnerable-hacker.html\"><strong>SAPS website still vulnerable: hacker<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/internet\/78368-slow-adsl-it-could-be-a-cyber-attack.html\"><strong>Slow ADSL? It could be a cyber-attack<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/77814-spyware-servers-in-south-africa-the-plot-thickens.html\"><strong>Spyware servers in South Africa: the plot thickens<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/77196-sa-first-in-africa-for-malware.html\"><strong>SA first in Africa\u2026 for malware<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/77022-aarto-website-hack-are-you-at-risk.html\"><strong>AARTO website hack: are you at risk?<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/78242-internet-bank-fraud-affects-few-absa.html\"><strong>Internet bank fraud affects few: Absa<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A South African government website is serving malware hosted on a Jamaican government website<\/p>\n","protected":false},"author":15,"featured_media":77198,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[9639,35,19723,801,18068],"class_list":["post-79199","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-hacked","tag-headline","tag-jamaican-cultural-development-commission-jcdc","tag-malware","tag-state-information-technology-agency-sita"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/79199"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=79199"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/79199\/revisions"}],"predecessor-version":[{"id":79283,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/79199\/revisions\/79283"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/77198"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=79199"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=79199"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=79199"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}