Trustwave Rapid Response: CrowdStrike Falcon Outage Update. Learn More

Trustwave Rapid Response: CrowdStrike Falcon Outage Update. Learn More

Managed Detection & Response

Eliminate active threats with 24/7 threat detection, investigation, and response.

Co-Managed SOC (SIEM)

Maximize your SIEM investment, stop alert fatigue, and enhance your team with hybrid security operations support.

Advisory & Diagnostics

Advance your cybersecurity program and get expert guidance where you need it most.

Penetration Testing

Test your physical locations and IT infrastructure to shore up weaknesses before exploitation.

Database Security

Prevent unauthorized access and exceed compliance requirements.

Email Security

Stop email threats others miss and secure your organization against the #1 ransomware attack vector.

Digital Forensics & Incident Response

Prepare for the inevitable with 24/7 global breach response in-region and available on-site.

Firewall & Technology Management

Mitigate risk of a cyberattack with 24/7 incident and health monitoring and the latest threat intelligence.

Offensive Security
Solutions to maximize your security ROI
Microsoft Exchange Server Attacks
Stay protected against emerging threats
Rapidly Secure New Environments
Security for rapid response situations
Securing the Cloud
Safely navigate and stay protected
Securing the IoT Landscape
Test, monitor and secure network objects
Why Trustwave
About Us
Awards and Accolades
Trustwave SpiderLabs Team
Trustwave Fusion Security Operations Platform
Trustwave Security Colony
Technology Alliance Partners
Key alliances who align and support our ecosystem of security offerings
Trustwave PartnerOne Program
Join forces with Trustwave to protect against the most advance cybersecurity threats
SpiderLabs Blog

Lord EK: A New Exploit Kit with an Ambitious Name

After a bit of a lull in the world of exploit kits, a new exploit kit by the name of “Lord EK” has been discovered out in the wild. This blog post will give an overview of what’s already been talked about as well as add some insights that I believe have not yet been shared publicly and provide Trustwave customers with some additional information for relevant products.

A few weeks ago Adrian Luca of Virus Bulletin spotted a new exploit kit that goes by the name of “Lord EK”. Finding a name for this kit was easy, as the author themselves stamped the landing page with the kit’s name, which can be seen with just a bit of de-obfuscation work:

deobfuscation LordEK Lord EK

Figure 1: The source code of the landing page (left) and the de-obfuscated version of the code (right)

Brad Duncan of Malware Traffic Analysis shared samples of Lord EK, and Jérôme Segura of Malwarebytes did a nice write-up on the kit, including some IoCs.

While analyzing this kit as part of the research for Trustwave SWG, I noticed something strange about Lord EK that has yet to be mentioned. We already know that there is a script within the page which collects information about the victim’s machine (specifically the victim’s Flash Player version, IP address, country, state, and city) and sends it back to the server.

A couple of requests later, when it seems that the decision has been made to deliver an exploit to the victim, a cookie by the name of “session” is set on the victim machine using the Set-Cookie HTTP header, this cookie is returned back to the server in the follow-up request for the Flash exploit. What caught my eye about this cookie is that it looked like base64 encoded data:

The cookie data before decodingFigure 2: The cookie data before decoding

And attempting to decode the data confirmed my suspicion, here is the cookie after a base64 decode:

cookie after a base64 decodeFigure 3: Cookie data after a base64 decode operation

The decoded string already appears to be a little more meaningful, with several values separated by pipe (“|”) characters. The first can easily be identified as a unix timestamp which appears to note the current time when the cookie is issued. The second part seems to contain some more base64-encoded data, which decodes into the following:

Cookie data after a second base64 decode operationFigure 4: Cookie data after a second base64 decode operation

or, in a more readable format:

Formatted data extracted from the cookieFigure 5: Formatted data extracted from the cookie

Here we can clearly see that the cookie contains information regarding the CVE used, the URL of the payload and the type of exploit. Note that the payload link correlates to that observed in the SWF exploit file itself which is definitely not static since we observed different temporary names used for the .vbs file in different attacks:

ActionScript code from within the malicious SWFFigure 6: ActionScript code from within the malicious SWF

Now, we know from previous work with EKs that exploit kit authors often like to retain information and statistics regarding victims, like which CVEs were delivered and whether the attack was successful, but usually this is all done on the server. There is technically no need for any of this to involve the victim, which makes this behavior a little odd.

Unfortunately, the server became unresponsive before we could test whether data from the cookie is directly used in the construction of the Flash or whether the kit’s author has simply chosen an odd way of collecting data. Either way, it’s an interesting piece of the puzzle that is Lord EK.

Taking a step back from Lord EK specifically, drive-by web attack trends are always interesting to observe, we’ve been seeing web miners replacing exploit kits for a while, but in the context of the demise of CoinHive (and consequential decline in web miners), does the appearance of a new exploit kit imply a renewed demand for drive-by exploits?

Time will tell…

Trustwave SWG customers are (and have been) protected against the Lord Exploit Kit and its observed payloads, additional detection logic will be added soon to help identify Lord EK specifically. Trustwave IDS and NGFW customers are also protected against Lord EK.

Latest SpiderLabs Blogs

Cloudy with a Chance of Hackers: Protecting Critical Cloud Workloads

If you've been following along with David's posts, you'll have noticed a structure to the topics: Part I: The Plan, Part II: The Execution and now we move into Part III: Security Operations. Things...

Read More

Trustwave Rapid Response: CrowdStrike Falcon Outage Update

Trustwave is proactively assessing and monitoring our clients who may have been impacted by CrowdStrike’s recently rolled-out update for its Windows users. The critical issue identified with...

Read More

Using AWS Secrets Manager and Lambda Function to Store, Rotate and Secure Keys

When working with Amazon Web Services (AWS), we often find that various AWS services need to store and manage secrets. AWS Secrets Manager is the go-to solution for this. It's a centralized service...

Read More