T95 Allwinner T616 Malware Analysis
github.com
github.com
[1] - https://github.com/badmojr/1Hosts [listed but only in Xtra]
[2] - https://github.com/Perflyst/PiHoleBlocklist.git [not listed]
Not that it matters, as the malware uses 8.8.8.8 if it doesn't like the DNS reply -- Then it tries a DNS server on port 5353!
tcpdump -i any -p -NNnnt -s0 -c512 proto 6 and 'tcp[13] == 2' # get syn packets, use "-i any" to see direction
I'm not sure where malware authors find their libraries but they do not try at all to look like normal traffic [Edit] or perhaps their government is telling them to add/remove specific options.In hindsight I should have made this an Ask HN post...
I am surprised that none of the usual threats lists have picked these domains up.
Using those techniques, nobody would get a chance to see this second fall-back.
EDIT to clarify: Thanks for listing this, it's definately good to list these addresses as 'bad' for others to be aware, but DNS blocking won't slow down this malware, not even a bit.
Here's what it took for me to see cbpheback.com -- Install Pi-hole on the Android device and add these rules to iptables:
adb shell iptables -t nat -A OUTPUT -p udp --dport 53 -j DNAT --to 127.0.0.1:53
adb shell iptables -t nat -A OUTPUT -p tcp --dport 53 -j DNAT --to 127.0.0.1:53
adb shell iptables -t nat -A OUTPUT -p tcp --dport 5353 -j DNAT --to 127.0.0.1:53
adb shell iptables -t nat -A OUTPUT -p udp --dport 5353 -j DNAT --to 127.0.0.1:53Yep, in a world of encrypted DNS transports, it is a folly to believe that DNS-based blocks would be affective at thwarting any sort of malware. That said, some IoC (indicators of compromise) setups do rely on it nevertheless.
you make it sound like people dumb for relying on something that works in certain situations. that's just hubris on your part if that's what you actually feel.
this is where I'm drawing my conclusion. no snake oil accusations necessary. the sentence is read with an implied "nevertheless, [dumbasses|idiots|noobies]" type of ending
https://search.censys.io/search?q=services.ssh.server_host_k...
To be honest I'm surprised Google is not cracking down hard on this, because it absolutely tarnishes the Android brand. They really feel like a "warez" version of AOSP plus cracked Google Play. I half expected "Google Play Protect" to throw up warnings about the device being non-genuine, but I actually never saw anything of the sorts.
iiic they require a license to redistribute their binaries, including Google Play. Obviously these boxes running a stolen phone ROM have not paid the licence fee.
As for the rest, these Allwinner chips are actually pretty good, but they're crippled by proprietary drivers and closed device tree. With open drivers and proper software support, they'd probably be equivalent to a Raspberry Pi 3 or better.
I love Android but the ecosystem is already ruined, both by vendor cruft like Samsung's sluggish UI, and by Google Play store being filled with microtransaction cancer. Google Play was good maybe 8 years ago but the lure of Google getting a cut of everyone's IAP destroyed it long ago.
Some obscure cheapo unenforceable Chinese copyright violation has almost no effect in comparison.
Ofcourse, Apps of 3rd party data hoarding, Democracy destroying services wouldn't bother releasing to F-Droid and I'm glad for that.
With microG version of LineageOS the app updates are seamless due to the F-Droid PE patch bundled in the ROM.
Lately I'm finding myself increasingly dependent on F-Droid only apps like Termux and Tusky.
There are many good apps only on Google Play, if you know where to look, usually specifically for the app name or by trawling through a dozen inferior alternatives first.
The chances of the best mist respectful apps being suggested to you instead of the Editor Choice in-app-purchase garbage are zero.
Rpi1 is 700MHz ARM11. Pretty much anything made in last 8 years to run android is stronger than that.
Nobody's using these boxes for anything besides pirated IPTV. The market for Android boxes has existed for a decade.
There is not going to be much crossover between people buying hardware like this (to view pirated cable), and the people Google markets Chromecast/Chromeboxes too, because all those do is show paid/ad-funded 'legit' content.
https://www.engadget.com/2016-12-22-barnes-and-noble-nook-sp...
Actually it more resembles the CopyCat malware. My challenge is finding the hook in system_server that downloads the payload from C2.
* https://www.checkpoint.com/downloads/resources/copycat-resea...
No big loss though, it hasn't been used in years.
Not sure what happened in your case, I flashed many ROMs and ran the script against them to see if anything bad would happen. No issues.
In any case it won't be a Hard Brick. Power off, hold [volume-up] insert power jack and tap the [power] button 10 times. (I think. I lost my remote ages ago and can't check.)
You might have some insight using Xposed, but I'm not sure if it works with AndroidTV. Feel free to contact me (email on my profile).
Of course, that doesn't fully prevent malware, but it's a more reassuring than buying something that fell off the back of a truck, in a dark alley(baba).
If you want to buy their chips, they insist on setting you up with one of their partners. Fair enough, but that other company is an Allwinner employee's side hustle. They ended up selling us boards that looked like surplus from a settop box project. Outdated, weirdly modified Android version, Google stuff but no license, lots of diagnostic tools installed and ADB wide open like in the article. No source code provided, even though it was agreed upon. We managed to get the source, but it wouldn't build. Then I flew over to our factory in China and asked to meet the guy, so we can sit down and he can show me how to build it. He never came of course, but we suddenly got a mail with the correct source... That's just a fraction of the stories we had with them.
With all the development effort, RMA cases and lost sales I would say our company lost a bunch of money thanks to Allwinner. I wonder how Allwinner still manages to exist. Maybe their stuff is "good enough" in those cases where cheap trumps everything else? We did stick with them for quite a long time and sold a couple of their boards after all...
If H616 was the mainstream/volume chip box to have in 2021, then I'm super-interested to see what their 2023 H618 boxes look like. They are all over Amazon with loads of reviews on YouTube, just like its predecessor.
Considering the interest this write-up has generated I'm inclined get one and 'take the bullet' to see if this behaviour is continues. Given your insight about how these chips get sold, chances seem quite high.
Well doh.
First of those cheap multimedia CPUs that figures out that having good docs/"out of the box" working open support gives them sales will eat the market.
Also aren't allwinner chips one of better mainstream kernel supported ones out of ARM bunch ?
> Nope. While basic Linux support is slowly materializing, two major blockers are still at the same spot - HDMI audio (no useful driver) and bug in display driver (big code change may be required to fix it).
https://forum.libreelec.tv/thread/24275-allwinner-h616-suppo...
I will only trust devices that have readily available, fully opensource platform firmware, bootloader, and OS. That beats some blind trust in "a massive blob that has control over everything and runs on an independent CPU from OS, because companies would not do bad things, because...brand??" anytime.
"Otherwise please use the original title, unless it is misleading or linkbait; don't editorialize."
The "T95" is likely an unbranded TV box and some people that bought it, got pre-installed malware in it. Is that the case with all T95 TV boxes? We don't know. Likely but we don't know.
Did the seller infect the TV boxes with the malware before selling? Probably.
Is this some malware that is implemented in the hardware of the TV box? Hell, no.
Here's a couple of specific mod comments if you didn't get that far in the search results:
I don't really care if there is malware running in my living room. Makes no difference to me if it runs there or at the north pole. It isn't exactly wasting much of my power or network with a tiny allwinner CPU and probably only 54Mbit WiFi.
And as long as this thing keeps steaming TV, I'm quite happy for it to be full of malware.
Harboring such a pest, typically used in extortion, is just not nice, even if you personally do not directly feel any ill effects.
A lot of those "residential proxy services" work by routing traffic through infected devices. The operators of them just buy "installs" (dirt cheap) from botnet operators, etc.
An infected device on the home network can also be staging for (automated) attacks against other shit on your network. Fun times.
Oh? With what result at the end of all that?
Otherwise this reads like typical "infosec" fearmongering turned up to 11. No different than doomsday preppers.
This all gets bought and sold on black markets, and gets used weeks and months after being stolen. Spam sent covertly from your mail account, mystery charges on your CC, etc. Not pleasant. At the worst case, a full identity theft, then behold a $30k loan taken in your name, for you to repay with interest.
What if a super-volcano erupts tomorrow, do you have enough canned beans?
Using your accounts presumably - so at the very least this thing has access to your hulu/netfliux/hbo/disney+ account information... That alone should be enough to make one reconsider.
An Internet connected fishtank thermometer was the initial point of entry for attackers against a casino:
https://www.businessinsider.com/hackers-stole-a-casinos-data...
Without paywall: https://archive.ph/K1nPe
Q: What this malware does?
A: probably nothing , but You kind of gave keys to Your device to 3rd party. And 2nd party (that also has keys ) doesn't like that.
Ideally You the owner should have the key and nobody else.