New Mirai Malware Attack on Enterprise Wireless Presentation systems and Supersign TVs


Mirai malware is a powerful strain that compromises a number of Linux devices and uses those devices to launch a massive distributed denial of service attacks.

The new malware variant targets embedded devices such as routers, network storage devices, NVRs, and IP cameras and using numerous exploits against them.

Source: gbhackers

According to Unit 42 researchers the malware particularly targets, “WePresent WiPG-1000 Wireless Presentation systems, and in LG Supersign TVs. Both these devices are intended for use by businesses.”

The new version of the Mirai packed with multiple new exploits along with the old ones, it also adds new credentials to launch brute force attacks on targeted devices. The malware especially targets enterprise devices, where they get huge botnets with huge bandwidth.

The new variant of the Mirai malware contains 27 exploits in total, 11 of them from the new version of the Mirai malware.

According to Bad packets following are the ports targeted.

Bad Packets Report@bad_packets

Top 10 ports/services targeted by Mirai-like botnets:
1⃣ 23/tcp – Telnet
2⃣ 5555/tcp – Android Debug Bridge
3⃣ 2323/tcp – Telnet
4⃣ 80/tcp – HTTP
5⃣ 22/tcp – SSH
6⃣ 8080/tcp – HTTP
7⃣ 81/tcp – HTTP
8⃣ 37215/tcp – Huawei Service Port
9⃣ 8000/tcp – HTTP
🔟 8081/tcp – HTTP

Bad Packets Report@bad_packets

Mirai-like #malware hosts detected last 365 days by daily share of ports/services targeted: https://docs.google.com/spreadsheets/d/1WlTrPz2KpYySaUmhYi1Syjay7MqTwxQbRrYcohgdL_0/edit#gid=1331131542 

View image on Twitter
61 people are talking about this

Unit 42 researchers spotted the new variant had some other differentiating features:

  • It makes use of the same encryption scheme as is characteristic of Mirai with a table key of 0xbeafdead.
  • When decrypting strings using this key, we found certain unusual default credentials for the brute force that we haven’t come across until now:
  • admin:huigu309
  • root:huigu309
  • CRAFTSPERSON:ALC#FGU
  • root:videoflow
  • It uses the domain epicrustserver[.]cf at port 23823 is for C2 communication.
  • In addition to scanning for other vulnerable devices, the new version can be commanded to send out HTTP Flood DDoS attacks.

Mitigation

  • Disable features and services that are not required.
  • Disable Telnet login and use SSH where possible.
  • Disable Universal Plug and Play (UPnP) on routers unless absolutely necessary.
  • Perform an audit of IoT devices used on your network.
  • Change the default credentials on devices. Use strong and unique passwords for device accounts and Wi-Fi networks.
  • Use wired connections instead of wireless, where possible.
  • Regularly check the manufacturer’s website for firmware updates.

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Google photo

You are commenting using your Google account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

Blog at WordPress.com.

Up ↑

%d bloggers like this: