8 ms·
T95 Allwinner T616 Malware Analysis
- throwawayapples 4y agoycxrl.com (registered at godaddy with privacy) is the command-and-control domain mentioned in the article, which currently resolves to 192.53.113.52 (Linode). DNS is run through DOMAINCONTROL.COM, which seems to be a nextcloud instance?
- perryh2 4y agoThe domaincontrol.com nameservers are operated by GoDaddy.
- palebluedot 4y agoLooks like 139.162.63.161 may also be involved, it has the same ssh server key: https://search.censys.io/search?q=services.ssh.server_host_key.fingerprint_sha256%3D%223cefded7c878f75026b5de2cc3dd0abe163bb06aaf8241ab6d883c877456e43a%22&resource=hosts https://search.censys.io/search?q=services.ssh.server_host_k...
- andrecarini 4y ago> If anyone can offer guidance on how to find these hooks into system_server let me know You might have some insight using Xposed, but I'm not sure if it works with AndroidTV. Feel free to contact me (email on my profile).
- DesktopECHO 4y agoFollow-up to my earlier report about the stock firmware on these Android TV devices, with a script to de-fang Stage 0 by preventing the payload from downloading (chattr +i FTW!)
- LinuxBender 4y agoFor what it's worth that domain in your repo is also listed in the 1Hosts block-list [1] but only in the Xtra category, not sure why. It seems that is a known malware site. Oddly enough it is not listed in the PiHoleBlocklist [2] [1] - https://github.com/badmojr/1Hosts https://github.com/badmojr/1Hosts [listed but only in Xtra] [2] - https://github.com/Perflyst/PiHoleBlocklist.git https://github.com/Perflyst/PiHoleBlocklist.git [not listed]
- DesktopECHO 4y agoYeah only the primary server seems to be on blocklists. The malware uses 3 DNS addresses, all on Linode. Not that it matters, as the malware uses 8.8.8.8 if it doesn't like the DNS reply -- Then it tries a DNS server on port 5353!
- LinuxBender 4y agoAnother thing to look at if you have time is packet characteristics. I have found that many malware and bot installations appear to use really odd network libraries. Just do a tcpdump for a while and see what sticks out, such as missing MSS, really high TTL, missing SackOK, timestamps enabled this seems to be default on Android. Also look at the TCP header sizes vs. the normal TCP header sizes from legit devices on your network. tcpdump -i any -p -NNnnt -s0 -c512 proto 6 and 'tcp[13] == 2' # get syn packets, use "-i any" to see direction I'm not sure where malware authors find their libraries but they do not try at all to look like normal traffic [Edit] or perhaps their government is telling them to add/remove specific options.
- DesktopECHO 4y agoThanks for the guidance here. Where I'm really stuck is when tcpdump tells me about the presence of the offending traffic and correlating process. In this case, it's the Android "system_server" process and I'm not sure how to find the hook into it that downloads the malware. In hindsight I should have made this an Ask HN post...
- dylan604 4y agojust reading you comment about differing packets, I was already thinking that seems like a dumb thing to have look different. Then you end with exactly that. Just goes to so that the world is so insecure that even minimal effort will get quite a return in this world. If it gets a big enough return so that even those that do stop it still makes it worth while, then why spend energy trying to do more. Hell, even Bill Gates is attributed to saying something about why should he pay for optimizing when disk space and cpu is always increasing faster than any optimizations could.
- srhngpr 4y agoWhat does this have to do with Amazon specifically, especially when you mention that the same units can be purchased on AliExpress? "Otherwise please use the original title, unless it is misleading or linkbait; don't editorialize."
- jacquesm 4y agoAs the author they could make the article title match the HN one!
- DesktopECHO 4y agoFair point, thanks. Added AliExpress.
- srhngpr 4y agoCheers, thank you!
- deleted 4y ago[deleted]
- tyingq 4y agoIt's fairly unrelated to Allwinner also.
- le-mark 4y agoIndeed allwinner SOCs are pretty remarkable for how cheap they are.
- chasil 4y agoIt sounds similar to Barnes and Noble shipping ADUPS on their Nook tablets. https://www.engadget.com/2016-12-22-barnes-and-noble-nook-spyware-adups-malware.html https://www.engadget.com/2016-12-22-barnes-and-noble-nook-sp...
- DesktopECHO 4y agoFunny you mention it, as it also had ADUPS. By itself, I can deal with that. Actually it more resembles the CopyCat malware. My challenge is finding the hook in system_server that downloads the payload from C2. * https://www.checkpoint.com/downloads/resources/copycat-research-report.pdf https://www.checkpoint.com/downloads/resources/copycat-resea...
- aritmo 4y agoIt's an "Android TV Box", model name "T95". Where is that information in the title?
- DesktopECHO 4y agoTitle was changed by the mods so that's how it stays! :)
- aritmo 4y agoIt's the same title of your post on github. The mods did not change anything.
- DesktopECHO 4y agoClearly you never saw the original title before it was changed by the mods, but believe whatever you like.
- deleted 4y ago[deleted]
- pvg 4y agohttps://hn.algolia.com/?dateRange=all&page=0&prefix=false&query=by%3Adang%20%22work%20a%20little%22&sort=byDate&type=comment https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
- aritmo 4y ago"work a little". How is that relevant here? The "T95" is likely an unbranded TV box and some people that bought it, got pre-installed malware in it. Is that the case with all T95 TV boxes? We don't know. Likely but we don't know. Did the seller infect the TV boxes with the malware before selling? Probably. Is this some malware that is implemented in the hardware of the TV box? Hell, no.
- pvg 4y ago
- mrtweetyhack 4y ago[dead]
- neilv 4y agoNice properties of the Raspberry Pi SoC devices include that there are brands involved that aren't going to fly-by-night, and the brands and the people behind them could be reached by civil and criminal action. Of course, that doesn't fully prevent malware, but it's a more reassuring than buying something that fell off the back of a truck, in a dark alley(baba).
- captainmuon 4y agoThese things also show up on Amazon. I think the real problem is Allwinner. I've dealt with them before and it was nightmarish. If you want to buy their chips, they insist on setting you up with one of their partners. Fair enough, but that other company is an Allwinner employee's side hustle. They ended up selling us boards that looked like surplus from a settop box project. Outdated, weirdly modified Android version, Google stuff but no license, lots of diagnostic tools installed and ADB wide open like in the article. No source code provided, even though it was agreed upon. We managed to get the source, but it wouldn't build. Then I flew over to our factory in China and asked to meet the guy, so we can sit down and he can show me how to build it. He never came of course, but we suddenly got a mail with the correct source... That's just a fraction of the stories we had with them. With all the development effort, RMA cases and lost sales I would say our company lost a bunch of money thanks to Allwinner. I wonder how Allwinner still manages to exist. Maybe their stuff is "good enough" in those cases where cheap trumps everything else? We did stick with them for quite a long time and sold a couple of their boards after all...
- DesktopECHO 4y agoThanks for this fascinating insight. The jankyness you describe lines-up exactly with what I'm seeing here. If H616 was the mainstream/volume chip box to have in 2021, then I'm super-interested to see what their 2023 H618 boxes look like. They are all over Amazon with loads of reviews on YouTube, just like its predecessor. Considering the interest this write-up has generated I'm inclined get one and 'take the bullet' to see if this behaviour is continues. Given your insight about how these chips get sold, chances seem quite high.
- verytrivial 4y agoI would be super interested to see what the command and control channel would actually try to do (in a virtual network/honey pot of course).
- 0x0 4y agoI remember looking at a few of these cheapo "androidtv" boxes. My instant reaction was that the entire build seemed super shady and I wouldn't be surprised if they were full of keyloggers and malware. Fortunately I never signed in with a real google account. Some aren't even real AndroidTV, they identify as an Android (not AndroidTV) device in several spots, probably to allow installation of google play applications that aren't designed for androidtv. They often come with multiple app stores, in addition to Google Play (which seems like an unlicensed hack, I would have thought Google would require a minimum of quality for approving a device to carry Google Play, especially for AndroidTV - heck, even uploading a closed alpha testing application that is AndroidTV enabled to google play requires a lot more reviews than regular android apps). All kinds of super weird processes running, some with bundle ids such as just "a" or "com.example.a" (instead of "com.example.realcompanyname.whatever"). If I remember correctly they also came pre-rooted with su/sudo setuid root. The CPU was super weak but they seem to have some sort of hardware accelerated H.264 decoding, that's probably why they can stream and play online HD video, but the minute you try to do anything outside of regular streaming, it is painfully obvious that the chip is weaker than a raspberry pi 1. To be honest I'm surprised Google is not cracking down hard on this, because it absolutely tarnishes the Android brand. They really feel like a "warez" version of AOSP plus cracked Google Play. I half expected "Google Play Protect" to throw up warnings about the device being non-genuine, but I actually never saw anything of the sorts.
- DesktopECHO 4y agoThese boxes identify themselves as a Google Pixel 2 (walleye) because, reasons!
- pifm_guy 4y agoI'd like to see what this malware actually does. I don't really care if there is malware running in my living room. Makes no difference to me if it runs there or at the north pole. It isn't exactly wasting much of my power or network with a tiny allwinner CPU and probably only 54Mbit WiFi. And as long as this thing keeps steaming TV, I'm quite happy for it to be full of malware.
- nine_k 4y agoSuch malware may sit dormant until ordered to be a small part of a DDoS attack. It will continue stream your TV in the meantime. Harboring such a pest, typically used in extortion, is just not nice, even if you personally do not directly feel any ill effects.
- nibbleshifter 4y agoOr acts as a proxy allowing people to route all kinda of shit through (or into) your network... A lot of those "residential proxy services" work by routing traffic through infected devices. The operators of them just buy "installs" (dirt cheap) from botnet operators, etc. An infected device on the home network can also be staging for (automated) attacks against other shit on your network. Fun times.
- vagrantJin 4y ago> An infected device on the home network can also be staging for (automated) attacks against other shit on your network. Fun times Oh? With what result at the end of all that? Otherwise this reads like typical "infosec" fearmongering turned up to 11. No different than doomsday preppers.
- nine_k 4y agoYour windows machine likely have more lax permissions for the internal LAN. It's easier to try and install a keylogger, and steal your passwords on various sites, card numbers, etc. This all gets bought and sold on black markets, and gets used weeks and months after being stolen. Spam sent covertly from your mail account, mystery charges on your CC, etc. Not pleasant. At the worst case, a full identity theft, then behold a $30k loan taken in your name, for you to repay with interest.
- BlueTemplar 4y agoIs John Connor aware of these ? Might just be what reverses the war against Skynet !
- deleted 4y ago[deleted]
- sodality2 4y agoWelp. Had one running for years. ADB'd into it and no sign of an infection despite it being the exact one to be. I don't use anything important on it so I'm considering burning it. OP, do you know of any way to flash a clean OS onto it? If the malware is as deep as it is described maybe a full system reinstall would be best instead of just uninstalling known badware.
- DesktopECHO 4y agoI'm with you on that. There are efforts underway to get plain-old Linux running, but it's some time away as this chip only went into mainline as of kernel 6.0
- sodality2 4y agoAgh, your script seemed to have bricked my device. It sends it into a loop forever booting and doesn't reach anything. :/ No big loss though, it hasn't been used in years.
- DesktopECHO 4y agoWow sorry to hear that. If you can, check if the device is still available over ADB. If it is, try re-running the script. Not sure what happened in your case, I flashed many ROMs and ran the script against them to see if anything bad would happen. No issues. In any case it won't be a Hard Brick. Power off, hold [volume-up] insert power jack and tap the [power] button 10 times. (I think. I lost my remote ages ago and can't check.)
- sodality2 4y agoYep I actually toyed around with it and got it to boot - thanks for the help!
- analog31 4y agoAsk HN: I've been thinking about getting an Android tablet to read sheet music. I'm a technically inclined person, but certainly not a security expert. Can anybody recommend one or more online guides for how to find out if a new device contains such egregious malware?
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- abawany 4y agoI recommend looking at the list of devices recommended by one of LineageOS (https://wiki.lineageos.org/devices/ https://wiki.lineageos.org/devices/), /e/ (https://doc.e.foundation/devices https://doc.e.foundation/devices), or PostmarketOS (assuming the application will run on plain Linux vs. Android) to see if they will work for you. The tablets they recommend are often older models so you will likely have to find these used/refurbished. It might be easier to get a detachable or 360-hinge PC laptop instead (e.g. MS Surface) if the weight/dimensions/application work better for you due to the high flexibility that PC OS-es offer compared to Android. Alternatively, a ChromeOS device, most of which can run Android apps, are a much better bet with long support, respectable vendors, and good flexibility.
- rchaud 4y agoWhy not just get something from Samsung? That's a reputable brand and they have no incentive to add in stuff like this. This is a $50 Android box made my some no-name OEM tha sells on Amazon.
- userbinator 4y agoBetter that it comes with malware you can remove, than a device that has been "secured" against you with unremovable malware under the guise of "security"...
- deleted 4y ago[deleted]