Skip to main content

Asnarök Trojan

Asnarök is a newly observed trojan targeting Sophos firewall systems affected by the recently disclosed vulnerability CVE-2020-12271.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Asnarök is a newly observed trojan targeting Sophos firewall systems affected by the recently disclosed vulnerability CVE-2020-12271.


Affected platforms

The following platforms are known to be affected:

  • Sophos XG Firewall - All versions

Threat details

Vulnerable devices are first identified using an unknown scanner. When a device is found, an exploit for CVE-2020-122271 is deployed in order to insert a single command containing a delivery URL into a database table. This command is then triggered to download an initial script from a command and control (C2) server and execute it. This script will attempt to alter certain database entries in an effort to disguise itself before modifying an existing script and dropping two additional scripts. These scripts are then used to ensure persistence and allow for data exfiltration.

Once it gains access, Asnarök will attempt to collect information stored on the affected system, including:

  • Firewall IP address lists, licence, and serial numbers
  • User and administration account email addresses lists
  • User's names, usernames, and encrypted passwords
  • Salted SHA256 hashes of any administration account passwords
  • ID lists for accounts permitted to use the firewall for SSL or clientless VPN connections

This information is then encrypted using Triple DES with the passphrase 'GUCCI' before being sent to a separate C2 address.


Remediation steps

Type Step

Sophos has released an update to address CVE-2020-12271, which Asnarök exploits to gain access. Affected organisations are encouraged to review CC-3436 and apply this update immediately.

Additionally, to prevent and detect a trojan infection, NHS Digital advises that:

  • Secure configurations are applied to all devices.
  • Security updates are applied at the earliest opportunity.
  • Tamper protection settings in security products are enabled where available.
  • Obsolete platforms are segregated from the rest of the network.
  • IT usage policies are reinforced by regular training to ensure all users know not to open unsolicited links or attachments.
  • Multi-factor authentication (MFA) and lockout policies are used where practicable, especially for administrative accounts.
  • Administrative accounts are only used for necessary purposes.
  • Remote administration services use strongly encrypted protocols and only accept connections from authorised users or locations.
  • Systems are continuously monitored, and unusual activity is investigated, so that a compromise of the network can be detected as early as possible.

Please note that NCSC maintains guidance for securely configuring a wide range of end user device (EUD) platforms. For further details refer to their end user device security guidance pages.



Indicators of compromise

Main indicators

IP Addresses

  • 38.27.99[.]69
  • 43.229.55[.]44

URLs

  • filedownloaderserver[.]com
  • filedownloaderservers[.]com
  • filedownloaderserverx[.]com
  • ragnarokfromasgard[.]com
  • sophosenterprisecenter[.]com
  • sophosfirewallupdate[.]com
  • sophosproductupdate[.]com
  • sophostraining[.]org
  • sophoswarehouse[.]com
  • updatefileservercross[.]com

Filepaths

  • /scripts/vpn/ipsec/.generate_curl_ca_bundle.sh
  • /tmp/.a.PGSQL
  • /tmp/.lp.sh
  • /tmp/.n.sh
  • /tmp/.pg.sh
  • /tmp/%s_.xg.rel
  • /tmp/%s_.xg.salt
  • /tmp/2own
  • /tmp/b
  • /tmp/I
  • /tmp/Info.xg
  • /tmp/x.sh
  • /var/newdb/global/.post_MI

SHA256 File Hashes

  • 31e43ecd203860ba208c668a0e881a260ceb24cb1025262d42e03209aed77fe4
  • 4de3258ebba1ef3638642a011020a004b4cd4dbe8cd42613e24edf37e6cf9d71
  • 736da16da96222d3dfbb864376cafd58239344b536c75841805c661f220072e5
  • 8e9965c2bb0964fde7c1aa0e8b5d74158e37443d857fc227c1883aa74858e985
  • 9650563aa660ccbfd91c0efc2318cf98bfe9092b4a2abcd98c7fc44aad265fda
  • a226c6a641291ef2916118b048d508554afe0966974c5ca241619e8a375b8c6b

CVE Vulnerabilities

Last edited: 18 January 2022 8:43 am