Online Services

Category: Security

  • In-Depth Analysis of a Criminal Organization Targeting WordPress Websites

    Today we are posting an in-depth analysis of a prolific brute force attacker. We show that their motives are financial and are based on a wide-spread campaign to market counterfeit sports apparel websites. We describe the threat actor’s tactics, techniques and procedures. Finally, we follow a financial trail to uncover individuals who are behind the campaign and prove that they are connected to each other and are likely part of a criminal organization. We have code-named this organization JerseyShore.

    Introduction

    The number of brute force attacks that we see each month targeting WordPress is incredibly high. Last Month Wordfence blocked an average of 25 million brute force attacks per day as you can see in our January WordPress Attack Activity Report:

    Brute Force Attacks on WordPress in January 2017

    Late this month (February) we noticed a new surge in attacks. One IP address that we noticed is 91.200.12.103. Wordfence blocked 1.7 million attacks from this IP targeting over 22,000 websites from February 21st until February 28th.

    We decided to take a closer look at what kind of activity this IP is engaging in and we ended up uncovering a vast network of attack sites, what their tactics, techniques and procedures are (TTPs) and who is behind them.

    Analyzing the IP and who hosts it

    The IP address 91.200.12.103 is owned by an organization called “PP SKS-LUGAN” (PSL) which we have written about previously. In December of last year, we noted that most of the brute force attacks we were seeing during a December spike were originating from PSL.

    The following shows the top IP addresses at PSL for a single day in December and how many attacks they generated in just 24 hours. 

    Top 8 Ukraine Attack IP's

    Multiple complaints to PSL have resulted in no change in this behavior and PSL IP addresses are continuing to engage in a large number of brute force attacks.

    When analyzing 91.200.12.103 we looked at it in various dimensions:

    Based on the open ports, the server appears to be a Windows machine. It seems to be associated with a domain called heilink which, based on archive.org, belongs to someone who was selling World of Warcraft gear and the site is now down. That is probably the previous owner of that IP address.

    Based on the number of attacks we’re seeing coming from PSL’s netblock, we think that they are a “bullet proof hosting provider“. In other words, they are providing hosting for individuals and organizations who are engaged in activity that is clearly malicious and PSL will not respond or react to complaints about customers, but will allow the customer to continue using their services to engage in illegal activity.

    What else comes from 91.200.12.103?

    One of our customer sites that is participating in the Wordfence security network was hit by a defacement attack from 91.200.12.103. This is a departure from the standard brute-force-attacks we normally see from this IP address.

    We grabbed the sample and it contained the following:

    As you can see the spam contains a number of domains that are marketing sports apparel. So in addition to brute force hacking, this IP is also engaging in website defacement attacks with the same aim.

    A Network of Counterfeit Sports Apparel Sites

    We used the list of domains we found in the spam above to find out what other defacement attacks the Wordfence firewall has blocked that contain those domains. We discovered a range of IP addresses that are engaging in this defacement campaign and which are promoting a list of websites that are all selling counterfeit sports apparel.

    The table below shows a list of the websites that we encountered that are part of this campaign. Out of the 24 websites that are being actively marketed, 19 of them, or 80%, are still up and running and have not been taken down due to trademark infringement. (see below for details)

    Website Status Purpose
    www.wholesalejerseysgaa.com up SEO
    www.wholesalejerseys-cheapest.com up Sales
    www.wholesalejerseychinashop.com up Sales
    www.wholesalejerseychinaoutlet.com up Sales
    www.jerseywholesalechinabiz.com up Sales
    www.jerseyschinabizwholesale.us up Sales
    www.jerseysbizwholesalecheap.com up Sales
    www.wholesalecheapjerseysfree.com up Sales
    www.cheapjerseysbizwholesale.us up Sales
    www.cheapjerseysap.com up Sales
    www.cheapjerseyssa.com Down DNS Error
    www.bizcheapjerseyswholesalechina.com up Sales
    www.cheapestjerseys-wholesale.com up Sales
    www.cheapjerseysfootballshop.com up Sales
    www.cheapjerseysa.com up Sales
    www.chinacheapelitejerseys.com up SEO
    www.chinajerseyswholesalecoupons.com up Sales
    www.jerseychinabizwholesale.us up Sales
    www.jerseyswholesalechinalimited.com up Sales
    www.jerseywholesaleelitestore.com up Sales
    www.nfljerseyscheapchinabiz.com Down Takedown Notice
    www.chinaelitecheapjerseys.com Down Takedown Notice
    www.jerseywholesalebizchina.com Down Takedown Notice
    www.nfljerseysforsalewholesaler.com Down Takedown Notice
    www.nfljerseyscheapbiz.us Down DNS Error
    www.jerseychinabizwholesale.com Down Takedown Notice

     

    We profiled a handful of these sites and established a link between 91.200.12.103 and other sites in the spam network, through the domains that they are promoting:

    The above image shows 6 IP addresses that are part of this campaign. We show what attack or spam methods they are using and similarities in behavior between IPs. We also show which sites each IP is promoting and how there is cross promotion between IPs.

    As you can see in the above image, 91.200.12.103 is engaging in high frequency brute force attacks. It is also spamming a range of domains. One of those domains is bizcheapjerseyswholesalechina.com which is linked to two other IP addresses in the spam network.

    One of those linked IPs is engaging in the same kind of comment spam as an additional two IPs in the network. Or in tactical terms, it is using the same TTPs (tactics, techniques and procedures). Furthermore, one of the IPs we linked via TTPs is also spamming the Simple Ajax Chat plugin, which yet another IP address in the list is also doing.

    The above is a very basic analysis of just 5 IP addresses that are related to 91.200.12.103. We have high confidence that other IP addresses in the spam network can be linked to 91.200.12.103 in the same way.

    A long list of lawsuits

    Many of the websites that are engaged in this spam campaign have been taken down by a law firm representing the NFL, MLB, NHL and the NBA. Once a site is taken down, a notice appears on the site similar to the image on the left.

    The procedure for these takedowns is to file a complaint, then apply for a temporary restraining order (TRO) against the site. In the case of the site on the left, the TRO was applied for the following day, December 7th, 2016.

    Then the law firm files for a preliminary injunction about a week later. One month later the law firm files a motion for default judgement.

    The owners of these sites don’t show up to defend themselves, and so this legal process proceeds unattended by the site owners until a default judgment is issued in the trademark owners favor.

    This process allows the trademark owners to take control of the website and take it down. Once the website is taken down, a notice like the one on the left is placed on the website.

     

    Following the Money

    The sites we analyzed that are selling counterfeit sports apparel prefer to get paid via either Western Union Money Transfer or MoneyGram. The checkout on one of these sites looks like this:

    In every case, the payment recipients are based in China. Across the range of sites we analyzed, we found the following recipients:

    • Yanxing Chen
    • ChunYu Lin
    • HuangMin Lai
    • YouZhong Zeng
    • LingKun Gong
    • Xin Cai
    • YuanLe Duan

    As you can see in the screenshot above, there are different payment recipients for Western Union vs MoneyGram. To illustrate that these individuals are connected to each other, we have created the following analysis of four individuals in this network:

     

    As you can see in the diagram above, each individual is connected to every other individual via the sites that they receive payments for. The payment recipients are probably low ranking individuals in, what is clearly, a criminal organization.

    Wrapping it Up

    What we have shown here is that a criminal organization selling counterfeit sports apparel is engaging in spam to promote their retail websites. In addition to spam, we have shown that they are also using brute force attacks, targeting WordPress websites, from one of their spam servers which is hosted at a well known bullet proof host, Pp Sks Lugan, based in Ukraine.

    US based law firms are engaged in an ongoing campaign to take down these counterfeit apparel retailers based on trademark infringement lawsuits, TROs and default judgements. The battle between the trademark infringers and the law firms representing the trademark owners appears to be ongoing.

    This analysis should help you understand what the motive is behind some of the brute force attacks that target your WordPress website. The motive in this case is financial and the attackers are using compromised WordPress websites to sell and market counterfeit sports apparel.

    Credits: Authored by Robert McMahon and Mark Maunder with assistance from Panagiotis Vagenas. Thank you to Dan Moen for editing.

    The post In-Depth Analysis of a Criminal Organization Targeting WordPress Websites appeared first on Wordfence.

  • The February 2017 WordPress Attack Report

    Today we are releasing the WordPress attack report for February 2017. You can also find our January 2017 and December 2016 attack reports on the blog.

    This report contains a new kind of analysis on the top 25 attacking IPs, called topology analysis. We have used this technique to identify groups of IPs acting in concert with each other. It is a fun visual kind of analysis and is a powerful way to analyze graph data. I think you are going to find it provides a clearer picture of the WordPress threat landscape.

    The report also contains the data you have come to expect, including top 25 attacking IPs and their details, charts of brute force and complex attacks, top attacked themes and plugins and top attacking countries.

    Most Active IPs

    I’m including our usual explanation of how the table below works. If you’re familiar with our attack reports, you can skip down to the table below which contains the February data and read my comments that follow the table.

    Brief introduction if you’re new to viewing these reports

    In the table below we have listed the most active attack IPs for February 2017. Note that the ‘Attacks’ column is in millions and is the total of all attacks that originated from each IP. Further right in the table (you may have to scroll right) we break out the attacks into ‘brute force’ attacks and ‘complex’ attacks.

    Brute force attacks are login guessing attacks. What we refer to as ‘complex’ attacks are attacks that were blocked by a rule in the Wordfence firewall.

    We have also included the netblock owner which is the organization, usually a company, that owns the block of IP addresses that the attack IP belongs to. You can Google the name of the owner for more information. A Google search for any of these IP addresses frequently shows reports of attacks.

    The hostname included is the PTR record (reverse DNS record) that the IP address owner created for their IP, so this is not reliable data but we include it for interest. For example, we have seen PTR records that claim the IP is a Tor exit node, but it is clearly not, based on traffic.

    We also include the country and a country flag. To the far right of the report we show the date in February we started logging attacks and the date attacks stopped. For many of these IPs we logged attacks for the entire month. For some you can see there is a clearly defined attack ‘window’ where the IP started and stopped.

    The Top 25 Most Active IPs

    Note that the table below contains many more columns than are visible. You can scroll to the right to see the rest of the columns.

    If we display our list of the top 25 attacking IPs for February visually, a trend becomes clear. (Click the image for a full size version)

    The red squares above are our top 25 IPs. We have added additional data showing who owns each IP address and how they are linked. The green splotches are network ASNs or autonomous system numbers. The little houses are organization names associated with each IP.

    Turkish Provider “Ideal Hosting” generated 23.85 million attacks from 9 IPs

    As you can see the cluster on the top left has 9 attacking IP addresses on the same network. We zoom into that cluster below. The AS number for that network is 29262 which belongs to an organization called Ideal Hosting based in Turkey. Their company website is at: http://www.idealhosting.net.tr/.

    Ideal Hosting provides managed services with ports speeds up to 10Gbps. Their website includes full contact info, so we don’t think that they are a bullet proof host but are instead just suffering from a severe security problem across multiple IP addresses. They may be leasing dedicated servers to a smaller hosting provider who is not securing the servers correctly, providing an attack platform.

    All of the attacks from this network were brute force attacks. Every IP except one is a new entrant onto our top 25 list. The highest spot they achieved was 25 in January for a single IP. Now they’re up to 9 IPs attacking and have hit the number 7 spot on our top 25 list.

    Dutch Provider HostKey.com generated 17.53 million attacks from 6 IPs during February

    The second cluster on the right of our image is AS number 57043 which belongs to a Dutch hosting provider called HostKey. They also sell dedicated servers.

    As is the case above, HostKey may be leasing servers to a customer that is not securing them and who has inadvertently created an attack platform. HostKey appeared on our top 25 list for the first time with 3 IP addresses at positions 8, 9 and 12 respectively. They have now expanded to 6 IP addresses on the list and have generated a total of 17.53 million attacks across the sites we protect for February.

    Connecting Attackers Across Hosts

    In today’s report it is clear that specific hosting providers are generating large numbers of attacks. So it is tempting to believe that the hosting providers themselves are malicious actors.

    Lets take a look at the data through a different lens. We are going to perform topological analysis on our attack data in February for the top 25 IPs. This will give us a visual indication of how attacking IPs are connected to the sites they attack and to each other.

    Topological analysis of the Top 25 attacking IPs in February

    To do this we are going to include all attacks originating from our top 25 IP addresses during the month of February. We have a lot of data, so to pare it down, we are only going to consider target websites that received more than 100 attacks from a single IP address during any 24 hour period in February.

    What we end up with is: The top 25 IP addresses and which websites they attacked more than 100 times in any day during February.

    The attack data is represented graphically showing the attacking IPs as large blobs connected by threads to the websites they attacked, which are small blobs.

    The above image, while quite beautiful, represents brute force attacks from our top 25 IP addresses targeting websites during February. The image actually contains a lot of data:

    • Attacking IPs are large blobs and their size is dependent on the number of attacks they launched.
    • The lines linking nodes indicates an IP attacking a target website.
    • The websites are all small blobs.
    • The colorization indicates related communities of attackers.

    To explain what is happening here, lets zoom into the topmost cluster.

    As you can see in the above cluster, the IP addresses include all 9 of the 185.X.X.X IPs in our top 25 that belong to Ideal Hosting. 

    It also includes all four IPs that are 5.39.X.X from HostKey.com in the Netherlands.

    Lets drag the IPs out of that cluster and separate them from the websites they are attacking to clear things up.

     

    The cluster above shows that the attacking IPs in that cluster all appear to be attacking, for the most part, the same cluster of websites. They are attacking other websites, but there is a clear and large group of websites that these IPs are all attacking together. The IPs above appear to be behaving as a group.

    What does normal non-related behavior look like? 

    In the cluster that appears on the right of our overview image, about halfway down, you can see what is more independent behavior by attacking IP addresses. In this case the mushroom shapes are groups of websites that are only being attacked by the IP address they are connected to and by no other attacker. That shows independent behavior.

    You can also see in the above image that there are clear groups of victim websites that are being targeted by two IPs. And then in the center there are groups of websites that are being targeted by multiple IPs.

    It is inevitable that many of the websites that Wordfence protects will be attacked by several of our most prolific attackers, so those center clusters are expected. The two-IP clusters are also expected for the same reason – because we have two attackers who overlapped in their attacks.

    One possible reason for attackers targeting the same websites is “Google dorking” where an attacker identifies a vulnerable website based on data from Google’s index. If attackers use the same technique to locate target websites, they will end up attacking the same clusters of websites.

    When we have a large mushroom shape, it indicates that IP is acting alone and is the only one attacking the sites in that cluster. So in the case of this purple cluster, these IPs appear to be acting independently because each of them is the only one attacking a large cluster of websites.

    Completely independent behavior by 220.227.234.129

    At the very bottom of our overview image, we have a single IP address belonging to Reliance Communications based in Hyderabad, India. The IP is attacking a large number of websites that no other IP in our top 25 is attacking. This IP is the only IP based in India in our top 25 list.

    One possible theory to explain the completely independent behavior of this IP is that it is targeting Indian websites. The attacker may also have a unique way of locating target websites that no other IP in our top 25 used.

    By performing topological analysis on the behavior of our top 25 attacking IPs for February, it reveals behaviors and patterns that we would otherwise miss. In this case it has revealed that IPs at our two most prolific hosting providers are actually behaving as a group and are probably controlled by a single attacker.

    Brute Force Attacks on WordPress in February 2017

     

    As you can see we experienced a huge spike in brute force attack activity this February starting at approximately February 20th and sustaining until the end of the month. As a reminder, these are simply login guessing attacks. Wordfence blocked an average of 30 million brute force attacks per day across the websites that we protect in February. This is an increase from the 26 million attacks per day average we saw in January.

    Complex Attacks on WordPress in February 2017

    While brute force attacks were up significantly in February, complex attacks on WordPress sites dropped from 4.6 million per day average in January to only 3.3 million per day. Complex attacks are attacks that are blocked by our firewall and that try to exploit vulnerabilities in plugins, themes, WordPress core and other products installed with WordPress.

    Attacks on Themes for February 2017

    Once again we are not seeing much change in the rankings in the themes that are targeted for attack in WordPress. The biggest change is the ‘authentic’ theme has climbed 11 places to number 4 for February. This attack is probably trying to exploit the arbitrary file download vulnerability in that theme and is of course blocked by Wordfence.

    Attacks on Plugins for February 2017

    Our biggest gainer among attacked plugins in February is wp-pagenavi which gained 28 places. Attackers occasionally install fake versions of this plugin once a site is compromised. These may be attempts by attackers to access a fake plugin as part of a check to see if a site has been compromised. These are blocked by Wordfence.

    Attacks by Country for February 2017

    There are a few changes in the top 25 attacking countries for February 2017. Indonesia has made their debut into the top 25 by climbing 19 places since last month. The Philippines and Malaysia are also big gainers climbing 12 and 10 places respectively.

    Conclusion

    That concludes the attack report for February 2017. I hope this has given you a clear picture of the threat landscape that confronts WordPress currently. In this report the new topology analysis we included has provided unique insight on how threat actors spread themselves across countries and hosting providers.

    We saw a huge spike in brute force attacks in February and an average drop in the number of complex attacks. There was little change in the attacked themes and some change in the plugins we are seeing targeted.

    As always you are welcome to share your thoughts and questions in the comments and I will be around to read and reply where needed.

    Mark Maunder – Wordfence Founder/CEO.

    The post The February 2017 WordPress Attack Report appeared first on Wordfence.

  • Clef Two Factor Authentication is Shutting Down

    This morning, two-factor authentication plugin Clef, also known as GetClef, announced that they are shutting down. They currently have more than 1 million active WordPress websites using their two-factor authentication plugin.

    According to the announcement on their blog, their team will be joining another company and they will provide more info in the coming weeks. At this point we don’t have any more detail on who Clef is joining and under what circumstances.

    Clef will continue operating for another three months, starting today. Their final shutdown date is June 6th, at which point their apps will be removed from the Google Play and Apple App stores.

    Clef have been kind enough to recommend their users transition to Wordfence. They have written a guide to help ease the transition. Wordfence Premium supports traditional SMS based cellphone sign-in along with two factor using Google Authenticator.

    Wordfence currently has over 40,000 customers who also use Clef. If you fall into that group, we recommend you disable and remove the Clef plugin and switch to using Wordfence two-factor authentication. You may need to upgrade to Premium to do this if you aren’t already a Wordfence Premium customer.

    If you are one of the 1 million+ websites who use Clef and don’t currently have Wordfence installed, we recommend you install Wordfence and upgrade to Premium, which will provide you with SMS based two-factor authentication along with the ability to use the Google Authenticator app if you prefer that.

    This announcement caught many of us by surprise. The entire Wordfence team wishes the Clef team well as they join another company and we look forward to learning more about their future projects.

    The post Clef Two Factor Authentication is Shutting Down appeared first on Wordfence.

  • WordPress 4.7.3 Security Release – Upgrade ASAP

    WordPress 4.7.3 has just been released. It is the third in a series of recent security releases for WordPress core.

    WordPress 4.7.2 was released on January 26th to fix a now famous WordPress defacement vulnerability. WordPress 4.7.1 was released on January 11th which fixed a vulnerability in PHPMailer.

    This new 4.7.3 core release fixes three Cross Site Scripting vulnerabilities:

    • Cross-site scripting (XSS) via media file metadata.
    • Cross-site scripting (XSS) via video URL in YouTube embeds.
    • Cross-site scripting (XSS) via taxonomy term names.

    It also fixed the following additional security issues:

    • Control characters can trick redirect URL validation.
    • Unintended files can be deleted by administrators using the plugin deletion functionality.
    • Cross-site request forgery (CSRF) in “Press This” leading to excessive use of server resources.

    WordPress 4.7.3 also contains 39 maintenance fixes to fix a range of non-security related issues.

    A few minutes ago, the Department of Homeland Security released an upgrade advisory via US-CERT’s National Cyber Awareness System:

     

    We would recommend that you don’t delay in upgrading to this new release. This release fixes multiple security vulnerabilities and now that the code changes are publicly visible, we may see attacks targeting these vulnerabilities emerge in the coming days.

    The post WordPress 4.7.3 Security Release – Upgrade ASAP appeared first on Wordfence.