Showing posts with label Windows. Show all posts
Showing posts with label Windows. Show all posts

Tuesday, May 7, 2019

Remote Desktop Protocol (RDP) a Deep Dive Webinar


Save the Date: Friday Noon EST, May 10th 
Click Here to Register

Wapack Labs is excited to invite you to our 2nd Cyber Intelligence on-line Briefings (CIB). This webinar is a deep dive into Remote Desktop Protocol (RDP). Jesse Burke, Advanced Cyber Analyst, will share research on RDP Wrap, Backdoors, Inception, and MiTM. Join our webinar on Friday noon for the webinar and the reports.

Monday, November 13, 2017

B.I.T.S Loader Attracting Cybercriminals

TLP AMBER ANNOUNCEMENT:

The Background Intelligent Transfer Service (BITS) is a legitimate Microsoft program used for creating and monitoring jobs over the network. Since it is a Windows legacy program it isn’t widely detected by AV solutions, making it attractive to cybercriminals for malware delivery and persistence. Recent emails targeting the Financial sector utilize BITS functionality by embedding it in heavily obfuscated Word documents, and with the use of LNK files. Monitoring BITS jobs in work environments is important to identify unwanted or unauthorized downloads and uploads. In the past, BITS was used to deliver banking trojans like DarkComet and GlobeImposter ransomware, and it is assessed with high confidence that it will continue to be utilized for both malware delivery and persistence, particularly against Windows based systems that would otherwise be considered highly locked down or security hardened. This report focuses on these two recent implementations of BITS, and looks at other ways BITS is leveraged in the wild...READ MORE

Wapack Labs has cataloged and reported on malware targeting the financial sector in the past. An archive of related reporting can be found in the Red Sky Alliance portal.  

WWW.WAPACKLABS.COM

This TLP AMBER report is available only to Red Sky Alliance members.

Wednesday, October 18, 2017

CVE-2017-12615

Wapack labs observed a recent Common Vulnerabilities and Exploit (CVE), CVE-2017-12615, being discussed in a Romanian hacker forum. A moderator on the forum posted an explanation of the exploit, a link to the National Vulnerability Database, and a GitHub link documenting how to weaponize the exploit in the Metasploit-framework. CVE-2017-12615 is assessed with a high severity rating (8.1/10) as it allows an attacker unauthorized modification to Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled. HTTP PUT places a file or resource at a specific URI, and exactly at that URI. If there is already a file or resource at that URI, PUT replaces that file or resource. If there is no file or resource there, PUT will create one. PUT is idempotent, but, paradoxically, PUT responses are not cacheable. Successful exploitation enables an attacker to upload a JSP file, request the file and execute its contents to gain remote access to the system. Wapack Labs is providing this report to Red Sky Alliance members for situation awareness. With the CVE and methods being posted in the wild, hackers may be more likely to attempt this attack. Wapack Labs recommends all Red Sky Members who use Apache Tomcat apply a security update and ask their Red Team members to test network assets to ensure the patch updated correctly...READ MORE

Wapack Labs has cataloged and reported CVEs in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Wednesday, June 28, 2017

Ransomware Affecting APM Terminals

27 June 2017, According to open source reporting, numerous high-profile organizations have released statements stating that they are affected by a SMB exploit. Merck & Co, Rosneft, Boryspil International Airport, Antonov State Company, Ukrenergo, and WPP are among victim companies. The Maersk Group, on behalf of their subsidiary APM Terminals, confirmed infections in APM facilities. At the time of this report, the bitcoin (BTC) wallet associated with the ransomware has thirty-one (31) received payments totaling 3.27744736 BTC ($7908.12 USD). Maersk has issued the following statement: “We can confirm that Maersk IT systems are down across multiple sites and business units. We are currently assessing the situation.” Open source reporting has confirmed that ports in Rotterdam, NL and Mobile, Alabama, US are affected and currently closed until network systems are restored. It is probable that all ports with APM facilities are affected due to the malware’s multiple lateral movement capabilities. PetrWrap ransomware is being spread using the EternalBlue SMB exploit. The malware will also leverage Windows Management Instrumentation Command-line (WMIC) and PsExec to spread internally across a network.

Wapack Labs has cataloged and reported extensively on maritime vulnerabilities and ransomware in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Tuesday, April 18, 2017

Shamoon2 Overwrites and Attacks Saudi Targets


Wapack Labs's research has uncovered Iranian actors using Shamoon2 against Saudi infrastructure and industry targets. Shamoon2 renders infected systems inoperable by overwriting the Master Boot Records (MBR). The actors responsible are using commercially available kernel drivers, which may indicate a lack of experience with Windows kernel development. Though, there is evidence indicating the malware was designed by reverse engineering malware attributed to a nation-state, suggesting that their skills are improving. Further attacks against Saudi-related targets using the Shamoon-family of malware are highly likely...READ MORE

Wapack Labs has cataloged and reported extensively on malware in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Monday, February 27, 2017

A (Fruit) Fly on the Wall: Surveillance Malware


The Fruit Fly malware is designed to exploit web cams that are used for surveillance. There are both Windows and Mac versions. Attribution is currently unknown; however, Fruit Fly has been installed in numerous university research centers, which have long been of particular interest to Chinese state actors looking to obtain intellectual property in order to accelerate their own research and development efforts.

Wapack Labs has extensively reported on surveillance and malware in the past. An archive of related reporting can be found in the Red Sky Alliance Portal. 

TLP: AMBER
ACTOR TYPE: (IV)
SERIAL: FR17-001
COUNTRIES: All
INDUSTRIES: All, Academia
REPORT DATE: 20170221

The Economical RAT: Luminosity.Link


The Luminosity.Link Remote Administration Tool (RAT) has been observed by a number of companies over the past year being spread through phishing emails. The Luminosity.Link RAT is sold openly online and contains numerous features that make it popular among cyber criminals. Luminosity.Link is designed using the .NET framework for use on Windows Operating systems. 

The Key Findings of our analysis revealed:
  • Recent samples leverage the AutoIt scripting tool
  • Luminosity.Link uses the SundownEK (Exploit Kit) for delivery
  • Luminosity.Link samples contain encrypted configurations
Luminosity.Link is an economical RAT for cyber criminals. Coupling it with Exploit Kits targeting Windows systems further increases infection success rates. We assess with high confidence that the development and use of the Luminosity.Link RAT will continue...READ MORE

Wapack Labs has extensively reported on Remote Access Tools (RAT) in the past. An archive of related reporting can be found in the Red Sky Alliance Portal. 

TLP: AMBER
ACTOR TYPE: (I&II)
SERIAL: FR17-002 
COUNTRIES: Worldwide 
INDUSTRIES: Any, DIB 
REPORT DATE: 20170221