Massive attack on vulnerable Exim-based mail servers

Security researchers from Cybereason warned mail server administrators about detecting a large-scale automated attack exploiting a critical vulnerability (CVE-2019-10149) in Exim, identified last week. During the attack, attackers gain execution of their code with root privileges and install malware for cryptocurrency mining on the server.

According to June's automated survey the share of Exim is 57.05% (up from 56.56% a year ago), Postfix is used on 34.52% (up from 33.79%), Sendmail at 4.05% (down from 4.59%), Microsoft Exchange at 0.57% (down from 0.85%). According to data Shodan, potentially vulnerable remain over 3.6 million mail servers on the global network that have not been updated to the latest stable release of Exim 4.92. About 2 million potentially vulnerable servers are located in the USA, 192 thousand in Russia. According to information RiskIQ, 70% of servers with Exim have already migrated to version 4.92.

Massive attack on vulnerable Exim-based mail servers

Administrators are strongly advised to urgently install updates that were prepared last week by distributions (Debian, Ubuntu, The release of SEMMi Analytics 2.0, Arch Linux, Alpine, EPEL for RHEL/CentOS). In the case of having a compromised version of Exim (from 4.87 to 4.91 inclusive) in the system, it is necessary to ensure that the system is no longer compromised by checking the crontab for suspicious calls and ensuring there are no additional keys in the /root/.ssh directory. An attack may also be indicated by logging firewall activity from hosts an7kmd2wp4xo7hpr.tor2web.su, an7kmd2wp4xo7hpr.tor2web.io, and an7kmd2wp4xo7hpr.onion.sh, which are used during the loading of malware.

The first attempts to attack Exim servers were recorded on June 9. By June 13, the attack had taken on massive proportions. After exploiting the vulnerability, a script is loaded through tor2web gateways from the hidden service Tor (an7kmd2wp4xo7hpr) that checks for OpenSSH (if not it installs), changes its settings (allows root logins and key-based authentication) and sets up for the root user an RSA key, providing privileged access to the system via SSH.

After setting up the backdoor, a port scanner is installed in the system to identify other vulnerable servers. The system also searches for existing mining systems, which are removed if found. In the final stage, a proprietary miner is loaded and registered in crontab. The miner is disguised as an ICO file (actually a zip archive with the password "no-password"), containing an executable file in ELF format for Linux with Glibc 2.7+.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster