Last Updated: 2013-12-07 03:02:54 UTC
by Guy Bruneau (Version: 1)
We have received information about a suspected Rovnix botnet controller currently using at least 2 domains (mashevserv[.]com and ericpotic[.]com) pointing to the same IP address of 126.96.36.199 (AS 44050).
This is the information that we currently have available that should help identify if any hosts in your network is currently contacting this botnet:
- mashevserv[.]com/config.php?version=[value here]&user=[value here]&server=[value here]&id=[value here]&crc=[value here]&aid=[value here] is where the compromised clients send an HTTP GET request to when requesting a configuration file. If the correct values are inputted the server will return an encrypted configuration file.
- mashevserv[.]com/admin appears to be the admin console
- ericpotic[.]com/task.php has similar values appended to it an when the GET request is done it appears to be some sort of check-in to tell the server it is alive.
- Posts to ericpotic[.]com/data.php are use to exfiltrating data. All communications with C&C are unencrypted over TCP 80.
It also appears this malware has very little detection. This is all we currently have. If you can recover samples either on the host or via packets and are willing to share them with us, you can upload them to our contact page.
Guy Bruneau IPSS Inc. gbruneau at isc dot sans dot edu