{"id":35281,"date":"2019-10-31T22:03:25","date_gmt":"2019-10-31T19:03:25","guid":{"rendered":"https:\/\/prohoster.info\/blog\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim\/"},"modified":"2019-10-31T22:03:25","modified_gmt":"2019-10-31T19:03:25","slug":"massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim","title":{"rendered":"Massive attack on vulnerable Exim-based mail servers","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p> Security researchers from Cybereason <noindex><a rel=\"nofollow\" href=\"https:\/\/www.cybereason.com\/blog\/new-pervasive-worm-exploiting-linux-exim-server-vulnerability\">warned<\/a><\/noindex> mail server administrators about detecting a large-scale automated attack exploiting <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50819\">a critical vulnerability<\/a><\/noindex> (CVE-2019-10149) in Exim, identified last week. During the attack, attackers gain execution of their code with root privileges and install malware for cryptocurrency mining on the server.<\/p>\n<p>According to June's <noindex><a rel=\"nofollow\" href=\"http:\/\/www.securityspace.com\/s_survey\/data\/man.201905\/mxsurvey.html\">automated survey<\/a><\/noindex> The share of Exim is 57.05% (up from 56.56% a year ago), Postfix is used on 34.52% (up from 33.79%) of mail servers, Sendmail is at 4.05% (down from 4.59%), and Microsoft Exchange is at 0.57% (down from 0.85%). <noindex><a rel=\"nofollow\" href=\"https:\/\/www.shodan.io\/report\/uSLHrfCA\">data<\/a><\/noindex> Shodan, potentially vulnerable remain over 3.6 million mail servers on the global network that have not been updated to the latest stable release of Exim 4.92. About 2 million potentially vulnerable servers are located in the USA, 192 thousand in Russia. According to <noindex><a rel=\"nofollow\" href=\"https:\/\/pbs.twimg.com\/media\/D89Gf0KUcAAJY44.jpg\">information<\/a><\/noindex> RiskIQ, 70% of servers with Exim have already migrated to version 4.92.<\/p>\n<p><center><img decoding=\"async\" alt=\"Massive attack on vulnerable Exim-based mail servers\" src=\"\/wp-content\/uploads\/2019\/06\/f179c76afaa02fedfe6c542f99dbcb9c.png\" style=\"display:block;margin: 0 auto;\" \/><\/center><\/p>\n<p>Administrators are strongly advised to urgently install updates that were prepared last week by distributions (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2019-10149\">Debian<\/a><\/noindex>,  <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/2019\/CVE-2019-10149.html\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.novell.com\/show_bug.cgi?id=CVE-2019-10149\">The release of SEMMi Analytics 2.0<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.archlinux.org\/packages\/community\/x86_64\/exim\/\">Arch Linux<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/FEDORA-2019-7b741dcaa4\">Alpine<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/fedoraproject.org\/wiki\/EPEL\">EPEL for RHEL\/CentOS<\/a><\/noindex>). In the case of having a compromised version of Exim (from 4.87 to 4.91 inclusive) in the system, it is necessary to ensure that the system is no longer compromised by checking the crontab for suspicious calls and ensuring there are no additional keys in the \/root\/.ssh directory. An attack may also be indicated by logging firewall activity from hosts an7kmd2wp4xo7hpr.tor2web.su, an7kmd2wp4xo7hpr.tor2web.io, and an7kmd2wp4xo7hpr.onion.sh, which are used during the loading of malware. <\/p>\n<p>The first attempts to attack Exim servers <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/freddieleeman\/status\/1137729455181500421\">were recorded<\/a><\/noindex> on June 9. By June 13, the attack <noindex><a rel=\"nofollow\" href=\"https:\/\/twitter.com\/0xAmit\/status\/1139165487093420035\">had taken on<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/forums.zimbra.org\/viewtopic.php?t=65932&#038;start=140\">massive<\/a><\/noindex> proportions. After exploiting the vulnerability, a script is loaded through tor2web gateways from the hidden service Tor (an7kmd2wp4xo7hpr) that checks for OpenSSH (if not <noindex><a rel=\"nofollow\" href=\"https:\/\/pbs.twimg.com\/media\/D88gM2mWsAAhwD4.jpg\">it installs<\/a><\/noindex>), changes its settings (<noindex><a rel=\"nofollow\" href=\"https:\/\/pbs.twimg.com\/media\/D88gZ0sX4AAeHgm.jpg\">allows<\/a><\/noindex> root logins and key-based authentication) and sets up for the root user <noindex><a rel=\"nofollow\" href=\"https:\/\/gist.github.com\/aserper\/e36d382668c6cf2c996c5143025097c0#file-gistfile1-txt\">an RSA key<\/a><\/noindex>, providing privileged access to the system via SSH.<\/p>\n<p>After installing the backdoor in the system, a port scanner is deployed to identify other vulnerable servers. It also searches for existing mining systems, which are removed upon detection. In the final stage, a custom miner is downloaded and registered in crontab. The miner is disguised as an ico file (actually a zip archive with the password \u201cno-password\u201d), containing an executable file in ELF format for Linux with Glibc 2.7+.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50870\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cybereason \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438 \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u043e\u0432 \u043f\u043e\u0447\u0442\u043e\u0432\u044b\u0445 \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u0432 \u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u0438 \u043c\u0430\u0441\u0441\u043e\u0432\u043e\u0439 \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0439 \u0430\u0442\u0430\u043a\u0438, \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u044e\u0449\u0435\u0439 \u043a\u0440\u0438\u0442\u0438\u0447\u0435\u0441\u043a\u0443\u044e \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2019-10149) \u0432 Exim, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u0443\u044e \u043d\u0430 \u043f\u0440\u043e\u0448\u043b\u043e\u0439 \u043d\u0435\u0434\u0435\u043b\u0435. \u0412 \u0445\u043e\u0434\u0435 \u0430\u0442\u0430\u043a\u0438 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0438 \u0434\u043e\u0431\u0438\u0432\u0430\u044e\u0442\u0441\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0441\u0432\u043e\u0435\u0433\u043e \u043a\u043e\u0434\u0430 \u0441 \u043f\u0440\u0430\u0432\u0430\u043c\u0438 root \u0438 \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u044e\u0442 \u043d\u0430 \u0441\u0435\u0440\u0432\u0435\u0440 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0435 \u041f\u041e \u0434\u043b\u044f \u043c\u0430\u0439\u043d\u0438\u043d\u0433\u0430 \u043a\u0440\u0438\u043f\u0442\u043e\u0432\u0430\u043b\u044e\u0442. \u0412 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0438\u0438 \u0441 \u0438\u044e\u043d\u044c\u0441\u043a\u0438\u043c \u0430\u0432\u0442\u043e\u043c\u0430\u0442\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c \u043e\u043f\u0440\u043e\u0441\u043e\u043c \u0434\u043e\u043b\u044f Exim \u0441\u043e\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 57.05% (\u0433\u043e\u0434 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":26492,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-35281","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cybereason \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u0435 \u043f\u043e\u0447\u0442\u043e\u0432\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 Exim | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cybereason \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:03:25+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:03:25+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Massive Attack on Vulnerable Exim-Based Mail Servers | ProHoster","description":"Security researchers from Cybereason have issued a warning.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041c\u0430\u0441\u0441\u043e\u0432\u0430\u044f \u0430\u0442\u0430\u043a\u0430 \u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u0435 \u043f\u043e\u0447\u0442\u043e\u0432\u044b\u0435 \u0441\u0435\u0440\u0432\u0435\u0440\u044b \u043d\u0430 \u043e\u0441\u043d\u043e\u0432\u0435 Exim | ProHoster","og:description":"\u0418\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438 \u0438\u0437 \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u0438 Cybereason \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/massovaya-ataka-na-uyazvimye-pochtovye-servery-na-osnove-exim","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:03:25+00:00","article:modified_time":"2019-10-31T19:03:25+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"35281","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 22:39:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:06:25","updated":"2026-01-21 22:39:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/35281","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=35281"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/35281\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/26492"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=35281"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=35281"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=35281"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}