Summary
Starting on Sep 7th, 2024 at 00:00 UTC our AllSky installation (version v2023.05.01_03) stopped working. Checking it out, we have found a strange config.sh
file with some Base64 content, decoding it appears to be a script to download and execute software from a remote server.
Details
The malicious content has appeared in config.sh
, with a suspicious header:
### IMPORTANT ALLSKY LINE, DO NOT REMOVE!
PoC
Content of ~/allsky/config/config.sh
:
![WhatsApp Image 2024-09-11 at 17 30 48](https://private-user-images.githubusercontent.com/851745/366526723-28e5b677-683c-4bf8-9cd8-ced3d28da37b.jpeg?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkzMTIzNDAsIm5iZiI6MTczOTMxMjA0MCwicGF0aCI6Ii84NTE3NDUvMzY2NTI2NzIzLTI4ZTViNjc3LTY4M2MtNGJmOC05Y2Q4LWNlZDNkMjhkYTM3Yi5qcGVnP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI1MDIxMSUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNTAyMTFUMjIxNDAwWiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9YzUyNDJmODFmY2IyNGVhMDNjYjQ3MDQ5MzQ0YzdmZTI5ZTEyYTAyMjI1ZTAxMTYwNGQ0MjA5ODA0ZWFlNjA0ZSZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QifQ.4ZUA1WKmujX4fhPd2VFSECw6xJKqzgpOGaAt8DV12eQ)
Decoded content:
![WhatsApp Image 2024-09-11 at 17 31 26](https://private-user-images.githubusercontent.com/851745/366526709-733405b0-d6b5-4eb3-8433-7f6b836ccd58.jpeg?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkzMTIzNDAsIm5iZiI6MTczOTMxMjA0MCwicGF0aCI6Ii84NTE3NDUvMzY2NTI2NzA5LTczMzQwNWIwLWQ2YjUtNGViMy04NDMzLTdmNmI4MzZjY2Q1OC5qcGVnP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI1MDIxMSUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNTAyMTFUMjIxNDAwWiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9NTE2MjI1NTk5NGRlODI5YzU4MmZlOGY4MjlkMDRmOGM0Yzk0MDA5ZWQwZWI0N2EyMTEzMDc4OWE0YzliZWJlNyZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QifQ.dnhLq7tJNm5CqlLtIh-IAFcB2McuDXmRd8fydMyzbTM)
Impact
We do not know the effect of the execution of the remote software.
Summary
Starting on Sep 7th, 2024 at 00:00 UTC our AllSky installation (version v2023.05.01_03) stopped working. Checking it out, we have found a strange
config.sh
file with some Base64 content, decoding it appears to be a script to download and execute software from a remote server.Details
The malicious content has appeared in
config.sh
, with a suspicious header:PoC
Content of
![WhatsApp Image 2024-09-11 at 17 30 48](https://private-user-images.githubusercontent.com/851745/366526723-28e5b677-683c-4bf8-9cd8-ced3d28da37b.jpeg?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkzMTIzNDAsIm5iZiI6MTczOTMxMjA0MCwicGF0aCI6Ii84NTE3NDUvMzY2NTI2NzIzLTI4ZTViNjc3LTY4M2MtNGJmOC05Y2Q4LWNlZDNkMjhkYTM3Yi5qcGVnP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI1MDIxMSUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNTAyMTFUMjIxNDAwWiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9YzUyNDJmODFmY2IyNGVhMDNjYjQ3MDQ5MzQ0YzdmZTI5ZTEyYTAyMjI1ZTAxMTYwNGQ0MjA5ODA0ZWFlNjA0ZSZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QifQ.4ZUA1WKmujX4fhPd2VFSECw6xJKqzgpOGaAt8DV12eQ)
~/allsky/config/config.sh
:Decoded content:
![WhatsApp Image 2024-09-11 at 17 31 26](https://private-user-images.githubusercontent.com/851745/366526709-733405b0-d6b5-4eb3-8433-7f6b836ccd58.jpeg?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkzMTIzNDAsIm5iZiI6MTczOTMxMjA0MCwicGF0aCI6Ii84NTE3NDUvMzY2NTI2NzA5LTczMzQwNWIwLWQ2YjUtNGViMy04NDMzLTdmNmI4MzZjY2Q1OC5qcGVnP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI1MDIxMSUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNTAyMTFUMjIxNDAwWiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9NTE2MjI1NTk5NGRlODI5YzU4MmZlOGY4MjlkMDRmOGM0Yzk0MDA5ZWQwZWI0N2EyMTEzMDc4OWE0YzliZWJlNyZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QifQ.dnhLq7tJNm5CqlLtIh-IAFcB2McuDXmRd8fydMyzbTM)
Impact
We do not know the effect of the execution of the remote software.