Security Audit

Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.

Trainings

We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

angler exploit kit domain shadowing

It has been touted as the biggest exploit kit campaign which indulges in the hijacking of registered domains to create a huge amount of subdomains. These sub-domain hijacking has proved to be vital for hackers in redirecting the users to pages with malicious content. This campaign has been largely attributed to the very infamous and known Angler Exploit Kit with fileless exploits serving various malicious payloads, cited Cisco in an official blog.

angler exploit kit domain shadowing

The much talked about "Angler Exploit Kit" which is ranked highly in the market but it is yet to dethrone "Blackhole" from top honours in terms of volume has been adjudicated the best by researchers due to high level of sophistication exploits which are believed to integrate 0-days better than any other kit.

Attack dubbed as "Domain Shadowing"

"Attackers have been phishing for domain accounts to create large amounts of malicious subdomains for some time. This technique has not been covered in detail before so a new descriptive term needed to be created, Domain Shadowing. Domain shadowing is the process of gathering domain account credentials in order to silently create subdomains pointed at malicious servers without tipping off the actual owner. Talos has been able to identify hundreds of accounts that have been compromised, some for a year or more. Not surprisingly, the majority of the domains are held by GoDaddy which controls almost a third of the active domains ", Cisco Reported.

GoDaddy Accounts Compromised!

GoDaddy has some serious work ahead to be fixed as the researchers have identified that only a third of the total domains (roughly handling close to 59 million domains) that attackers have access to are utilized leaving a suspicion that major trouble could be brewing up for many top websites that generate huge volume of traffic on daily basis. The attacks with Angler exploit kit kicks off with a malicious ad which redirects the victim to web page controlled by the attackers using the first set of sub-domians. quickly within a few seconds the victim gets redirected again to the another subdomain and the entire process goes on for a few minutes before victim gets back to the website. The ratio of exploit subdomains to redirect subdomains is 5:1.

angler exploit kit domain shadowing

Fast Flux

Similar to Domain Shadowing, Fast Flux is a technique that rapidly changes the IP address associated with a domain to evade detection and blocking techniques. Fast Flux rotates a single domain or DNS entry to a large list of IP addresses rapidly. Domain Shadowing rotates subdomains associated with a single domain rapidly. These subdomains can point to a single IP or a small group of IP addresses depending on the circumstances. Below is a diagram illustrating both processes.

The exploit kit campaign has been targeting & exploiting Adobe flash and Microsoft Silverlight vulnerabilities. The post by researchers show the amount of activity is growing rapidly with more subdomains flooding the market than ever before. There are some other differentiators between the redirecting domains and the exploit domains. The redirecting domains only made use of third level domains that were english word based (i.e. says.imperialsocks.com). The landing page / exploit kit subdomains are random string based and recently have branched into using both third level and fourth level domains (i.e. brandmuellergekwantifiseer.astarentals.co.uk & 3e3qcq.plante.bplawfirm.net)

From an IP address perspective the same IP is utilized across multiple subdomains for a single domain and multiple domains from a single domain account. There are also multiple accounts with subdomains pointed to the same IP. The addresses are being rotated periodically with new addresses being used regularly. Currently more than 75 unique IPs have been seen utilizing malicious subdomains.

Conclusion

Users facing risks of this malicious ad campaign struggle against it's prevention as it is specifically designed to leave no trail of detection. The attackers can use almost any website due to their hold on their a large pools of registered domains with the help of Domain Shadowing at a large scale. The process of Domain Shadowing is effective not only because it makes blacklisting difficult but also leverages that most users only login to their domain registrar to renew the registration. This threat example clearly demonstrates the ongoing evolution of threat actors. Actors are always going to try and stay ahead of detection technologies, and increasingly the researchers.

See more of Cyber Intelligence by logging in.
Connect with cyber security experts,Discover job opportunities,Online Training, Information Security Advisory and lot more.