Sunday, April 24, 2016

Cyberwatch Weekly - Threats to the Industrial Services Sector

This report provides a snapshot of malware and malware campaigns affecting the Industrial Services sector. The content of this report is derived from both open source and proprietary collections. Like other organizations, Wapack Labs only sees a portion of the larger picture. As such, this information should be leveraged in conjunction with other sources for full situational awareness. 

Saturday, March 19, 2016

Cyberwatch: Comparing the affects of your security picture to your stock price

Ever consider the affect your security threat landscape might have on your company's stock price?


Need information to show your Board, CEO, or CFO why you need additional security funding?

Want to monitor the threat profile of your supply chain? 

Introducing Wapack Labs Cyberwatch(R). 

We took a chance, and started monitoring chatter in a ton of primary sourced intelligence locations. What's primary sourced? It means that it's not being reported elsewhere or in social media.  When we see a Red Sky member, or Wapack Labs subscriber, we notify them. Because it's in intelligence space and not open source, it's often times early warning... sometimes not, but often is. 

At the same time, we thought we'd try something different. If we count the number of times we see our members names, IP addresses, etc., in that intelligence space, and plot that number on a moving timeline, what would it look like? And then, we plotted the company's stock price on the same moving timeline. Wow. The results were amazing. I can guarantee that we've not gotten this 100% right, but it's pretty darn cool. We call it "Cyber Threat Index(R)" and we've been showing early users how to use it to track portfolios of supply chain customers. 

The current site shows one company --the domain you log in with, plus it's stock price. Compare your Cyber Threat Index(R) to those of the Dow, or S&P 500. You can also search by industry or geography  by clicking on "RedXRay" on the bottom left menu.  Subscribers can click through the Cyber Threat Index graph to get the indicators of the day --those things you should monitor and/or block before you have your first coffee in the morning. Red Sky members receive these twice daily today. 

The site's not fully integrated. This is version .03, but we wanted to get it out there and get some feedback. We demo'd this at RSA one night until my phone gave out.

We'll be adding features and cleaning up documentation (i.e.: FAQ page) as we go along. We're intel people not UX developers, but we're getting better. 

Have a look.  It takes about an hour to pull your IP addresses, domains, etc. Log in, enter your stuff, and confirm your email account, then stop back later today. Hopefully you won't have any findings, but if you do, at least you'll know. 

I'd love to hear your thoughts. 

Thanks!
Have a great weekend!
Jeff

(Cyberwatch and Cyber Threat Intelligence are registered trademarks of Wapack Labs. Processes associated with the Cyber Threat Index is patent pending with the USPTO.)




Monday, March 14, 2016

Introduction to Wapack Labs' Threat Recon Indicator Database




Wapack Labs has been populating this database for about a year. It's essentially the indicators taken from our own analysis, and then grown.

Every day we get asked "Why buy another feed?"  This is a bit different. If I'm a bad guy and I have one domain registered for a C2 node, there's a good chance my other domains are also used for C2 nodes. We try and find all of them, starting from the one we know, and then provide them all to our subscribers... and they're in Threat Recon.

Sign up for your free API key. Every user gets 20 queries and 1000 free indicators per month. Plug in your search and off you go. Threat Recon runs from the web interface, or machine to machine.

Enjoy.
Jeff

Saturday, March 12, 2016

Converged Maritime and Port Security…So What?

March 12, 2016: Chuck Nettleship

I attend a series of meetings last week with a partner company regarding converged maritime and port security.  Converged meaning both physical and cyber aspects related to assessments, maturity models, risk management, and internal/external threats related to financial and insurance implications.

To my astonishment, many maritime and port entities – both public and private – are of the group think mindset of “So what?” regarding converged security risks.  Many within the maritime and port community “check the block” using open source intelligence (OSINT) threat assessments – very few consider OSINT combined with real-time cyber threat intelligence (CYINT).  Many view cyber security as a “known unknown” risk versus return on investment.  Another operational cost burden in a low margin business.  Think again!

Let’s look at an under reported area impacting the maritime and port “converged security” area overlooked from a cyber perspective.  It is understandable within an industry culture of tangible “hands-on” equipment, that cyber “1’s and 0’s” is neglected: ICS (Industrial Control Systems) and SCADA (Supervisory Control and Data Acquisition).  ICS-SCADA is a general term describing industrial automation systems responsible for data acquisition, visualization and control of industrial processes, often found in various industrial sectors and Critical Infrastructures – including maritime and port infrastructure. ICS play a critical role in maintaining the continuity of industrial maritime processes ensuring functional and technical safety, preventing large industrial accidents, environmental disasters and financial ruin.

The criticality of control systems in the maritime and port sectors due to the high impact in case of disruption, makes ICS a major target for malicious activities. Based on the ICS-CERT Monitor (part of U.S. Department of Homeland Security), between 2009 and 2014 the number of reported cyber security incidents in the ICS-SCADA area increased more than 27 times. This does not take into account global maritime and port operations impacted by cyber security incidents.  At the same time more than half of the incidents (59% in 2013) were aimed at the energy and critical manufacturing sectors and around 55% involved advanced persistent threats (APT). Most ICS-SCADA cyber security incidents stay undetected or unreported.

Getting back to the “So what?” think of the undetected and unknown cyber ICS vulnerabilities within the maritime industry occurring DAILY:
  • Compromised ERP (Enterprise Resource Planning hardware/software and cloud system
  • Financial data theft and manipulation
  • Equipment failure (vessel and port) including GPS, computers and ICS/SCADA
  • Falsified manifests and documentation – high and low value cargo theft
  • Insurance claims, false resupply claims, market manipulation, environmental issues
  • Drugs, smuggling and terrorism threat on the supply chain/cargo
  • Physical security breaches (security cameras, security equipment, security access control points)
  • Compromised employees and Insider threats

Wapack Labs has discovered numerous ports, vessels and maritime “systems” compromised with malware and key-loggers that are “owned” by the cyber underground in our “Daily Show” reports.  Most of the cyber threats are related to financial gain and market (oil/gas) manipulation.


If you or your peers in the maritime/port, transportation, supply chain and energy infrastructure sectors want to change your view from “So what?” to “So how can Wapack Labs help!” give us a call or email to enlighten through our Daily Show reports, Cyberwatch® and Cyber threat Index® to keep your organization financially sound through our Red Sky Alliance Member Information Sharing Portal.

Saturday, March 5, 2016

DROWN (Decrypting RSA with Obsolete and Weakened eNcryption)

03-04-2016. Joseph M Gant.

SSL and TLS servers have fallen prey to a newly developed attack. Though SSLv2 has been considered obsolete for some time, it still exists on many servers. This is due mostly to poorly maintained systems or older servers that still make their connections via SSLv2, either by default or due to poor configuration.

DROWN (Decrypting RSA with Obsolete and Weakened eNcryption) steals information through VPN connections made to web and mail servers that use SSLv2. Even systems using a more modern encryption method are prone to this exploit if they connect to systems which still employ the obsolete SSLv2. Thirty-three percent of browser-trusted HTTPS sites are in fact vulnerable to DROWN attacks. This is because faults in SSLv2 are used by DROWN to exploit TLS connections when these protocols communicate with each other. It is a serious, cross-platform threat.

To counter DROWN, one should ensure that SSLv2 is disabled on their systems and prevent the sharing of private keys to servers that use the protocol. There is no need to reissue certificates. And as always, be sure that one's crypo packages are up to date. Tools like public_drown_scanner and drowncheck are hosted on Github and are recommended if one fears that a compromise has occurred. OpenSSL released a patch last Tuesday to address this threat.

Focused on antivirus evasion, the Veil Framework is a suite of security implementations geared toward detection evasion: Veil-Evasion uses a variety of techniques to generate antivirus-evasion. Veil-PowerView is a powershell tool used to gain network access in Windows machines. Veil-Catapult is a psexec-type of system that works with Veil-Evasion, and Veil-Pillage is a post-exploitation integration of Veil-Evasion. The recently updated Veil Framework is aimed at pentesters, but is likewise a threat to be aware of.

The glibc DNS client, libresolv, has had a vulnerability exposed which makes it susceptible to stack overflow attacks. This allows for remote execution of code including ssh, php, sudo, as well as others. Under prime conditions for attack, a discrepancy in the stack buffer, generated by larger than normal DNS requests, creates a stack buffer overflow. Most exploitable fronts are protected by technologies like ASLR and stack-overflow-protection which can be built into the software when compiling applications locally. Information on building software with a hardened toolchain  can be read here Hardened Gentoo.

Linset is an 'evil twin' bash script circulating through darknet circles. 'Linset' is a recursive acronym-- 'Linset Is Not A Social Engineering Tool.' Linset performs the following:
  • Scan networks
  • Capture handshakes
  • Mounts FakeAP
  • Serves DHCP on FakeAP
  • Creates DNS server to redirect traffic from the host
  • Deauthenticates users on the network in order to connect to  FakeAP and introduce passwords
  • The validity of introduced passwords is checked
  • The attack ends upon successful, authenticated, password capture
Linset is simply a bash script implementing a number of applications such as aircrack-ng, dhcpcd, and hostapd to name a few. Most of these tools are found on any Linux distribution that ships a full suite of applications, and the well known pentester distro, Kali Linux contains all of these tools and more to round out Linset as a threat. Linset ships in Spanish and in the hands of any scrip kiddie with a working knowledge of Espanol and a keyboard, can be dangerous. While its unlikely Linset will be able to hijack an enterprise server, the cyber vandalism it can cause is troublesome to repair.

Sources:
http://76qugh5bey5gum7l.onion

Joseph Gant is a guess blogger, a security junky and a glassblower by trade. Though he holds degrees a degree in Scientific Glass technology, his life's study encompasses many variables --a long-time student of Tibetan region and culture, science, music, and a lover of literature. 

Friday, February 19, 2016

Custom Macro Delivers Locky

The new Locky ransomware has been making big headlines recently due to its reported links to the Dridex botnet. This week, the team at Wapack Labs took a closer look at a unique malicious macro that has been downloading Locky payloads for the past couple days.


Similar to Dridex, the macro is delivered via large scale phishing attacks and it is embedded in Microsoft Excel documents. The good news is the macro will not be launched upon rendering the host document, it requires user interaction in order to enable it.



All macro malware will either launch embedded files or download remote files. Variants that download malware have become increasingly popular as they trigger less static detections. Typically the download URLs that are embedded in these macros are obfuscated so as to make detection and analysis more difficult. Fortunately, these URL obfuscation tactics are often rudimentary and they also present unique artifacts for malware identification.

The Locky macro is no different. Close to 300 specimens were identified and every one makes use of the same simple URL obfuscation. This method is characterized by ASCII character codes which are delimited with |1. The following is an example observed in strings:



After removing the |1 delimiter and converting the remaining ASCII codes, we are left with the download URL which consists of a compromised website.  Despite identifying hundreds of recent specimens in the past two days, only 17 distinct URL download sites were identified – all delivering the same payload.

meow://organichorsesupplements.co.uk/system/logs/7647gd7b43f43[.]exe
meow://vipkalyan.com.ua/system/logs/7647gd7b43f43[.]exe
meow://sekiedge.co.uk/system/logs/7647gd7b43f43[.]exe
meow://tramviet.vn/system/logs/7647gd7b43f43[.]exe
meow://jurisdocs.3forcom.net/system/logs/7647gd7b43f43[.]exe
meow://shop.zoomyoo.com/image/templates/7647gd7b43f43[.]exe
meow://kaminus.com.ua/admin/view/7647gd7b43f43[.]exe
meow://cms.insviluppo.net/images/slides/7647gd7b43f43[.]exe
meow://sugarhouse928.com.my/system/logs/7647gd7b43f43[.]exe
meow://ramevent.ru/system/logs/7647gd7b43f43[.]exe
meow://merichome.com/system/logs/7647gd7b43f43[.]exe
meow://alkofuror.com/system/engine/7647gd7b43f43[.]exe
meow://tutikutyu.hu/system/logs/7647gd7b43f43[.]exe
meow://mppl.ca/system/logs/7647gd7b43f43[.]exe
meow://remont-krovlia.ru/system/cache/7647gd7b43f43[.]exe
meow://neways-eurasia.com.ua/system/logs/7647gd7b43f43[.]exe
meow://acilkiyafetgulertekstil.com/system/logs/7647gd7b43f43[.]exe

All observed file names use the same naming convention which contains the prefix “Rechnung”, German for bill, followed by randomized hex ascii. Examples:

Rechnung-FF8-16909.xls
Rechnung-649-748599.xls
Rechnung-784-074688.xls
Rechnung-56BE-68985.xls
Rechnung-AA-62891.xls
Rechnung-674-80222.xls

Among all of these Locky macros, there was no consistent AV detection ratio. Some had zero detection while others had over 20. Nevertheless, a large amount had poor detection with more than 40% detected by less than 10 AV vendors. Unfortunately, this poor AV detection exemplifies macro malware as a whole and explains the popularity of this tactic.

We suspect that we haven’t seen the last of Locky and that more of these will be popping up in the near future. Happy hunting and stay vigilant!

Analyst Resources:

The following python code may be used to de-obfuscate the Locky macro URLs:

url = '1104|1116|1116|1112|1058|1047|1047|1110|1101|1119|1097|1121|1115|1045|1101|1117|1114|
1097|1115|1105|1097|1046|1099|1111|1109|1046|1117|1097|1047|1115|1121|1115|1116|1101|
1109|1047|1108|1111|1103|1115|1047|1055|1054|1052|1055|1103|1100|1055|1098|1052|1051|1102|
1052|1051|1046|1101|1120|1101'
url = url[1:]
url = url.split('|1')
url_int = []

for u in url:
    url_int.append(int(u))

decoded_url = ''.join(chr(i) for i in url_int)
print decoded_url

The following yara rule will detect files that leverage the URL obfuscation observed in the Locky macro downloaders:


rule Locky_URL_Encoding
{
meta:

description = "Detects unique URL obfuscation seen in Locky macro downloaders"
author = "Chris Hall (chall@wapacklabs.com)"

strings:

$http = "1104|1116|1116|1112"
$exe = "|1046|1101|1120|1101"

condition:
all of them
}







Saturday, February 13, 2016

Russian hackers tested manipulation of exchange rates by hacking into bank trading system

The markets are in danger. We’ve seen market manipulation in cyber activities ranging from mining
operations to ships being held at sea.  As well, I proofed, last night a report suggesting direct access to an overseas stock exchange. Fraud is rampant, but now, attackers are testing direct market manipulation. It was only a matter of time.  

Group-IB reported recently on what it claims is the first documented case of hackers directly attacking trading system to change prices and increase volatility. Over $400M in sales executed on that day in 2015 resulted in $3.2M direct losses to the affected bank. While primary targeting by Corkow/Metel trojan being Russia infections in US were growing fast too.

Damages?

·       Direct losses due to malicious trades ($3.2M)
·       Initial investigation by the country authorities who thought the bank is manipulating the market
·       Loss of the trust from partners who thought bank is covering it's own technical trading mistakes. Information about the breach may cause some reputation cost as well.

Possible benefit scenarios for hackers:

·       Direct purchases/sales on their own capital (according to Group-IB it was not the case this time)
·       Direct connections with traders who executed trades after hackers changed prices (according to Group-IB it was not the case this time)
·       Indirect and difficult to detect game on futures market which allows to multiply capital in this case up to 20-fold
·       Executing an order of competitors or having self-interest to hurt the affected financial institution
·       As a step in an extortion scheme

Details:

“In February 2015 the first major successful attack on a Russian trading system took place, when hackers gained unsanctioned access to trading system terminals using a Corkow Trojan resulting in trades of more than $400 million. The criminals made purchases and sales of US dollars in the Dollar/Ruble exchange program on behalf of a bank using malware. The attack itself lasted only 14 minutes, however, it managed to cause a high volatility in the exchange rate of between 55 - 62 (Buy/Sell) rubles per 1 dollar instead of the 60 - 62 stable range. Losses to financial institution were estimated in the millions. To conduct the attack criminals used the Corkow malware, also known as Metel, containing specific modules designed to conduct thefts from trading systems, such as QUIK operated by ARQA Technologies and TRANSAQ from ZAO “Screen market systems”. Corkow provided remote access to the ITS - Broker system terminal by «Platforma soft» Ltd., which enabled the fraud to be committed.


Timeline of the attack
In August 2015 a new incident related to the Corkow (Metel) Trojan was detected. An attack on a bank card systems , which included about 250 banks which used the bank card system to service cash withdrawals from Visa and MasterCard cards under a special tariff. This attack resulted in the hundreds of millions of rubles being stolen via ATMs of the systems members.

According to Group-IB statistics, as of the beginning of 2015 this botnet encompassed over 250,000 infected devices worldwide including infecting more than 100 financial institutions with 80% of them from the top 20 list. Hackers target primarily companies in Russia and CIS countries, though it is noticed that the amount of attacks targeting the USA has increased 5 times since 2011. Antiviruses are not capable of effectively preventing these threats. The majority of computers infected by this malware have antivirus installed and active. The Trojan can stay undetected in the system for more than 6 months.

In 2014 Corkow had a QUIK v.1.0. module for collecting data from the Quik trading software developed by ARQA Technologies. In 2015 Corkow’s developers updated the QUIK module to v.1.1. and released another module TRZQ v.1.0. to copy information from the trading system’s application TRQNSAQ developed by ZAO «Screen market systems». The re-development of the old QUIK module and development of the new TRANSAQ module show the Corkow group’s continued interest in targeting trading system.

The attack itself lasted only 14 minutes, during which all losses were sustained, however, the preparations for this intrusion took a much longer time. Hackers gained access to a computer in the trading system in September 2014. From this time the Trojan was functional and constantly updated itself to avoid detection by antivirus software installed at the bank which was in functioning order. As of the Group-IB investigation of this malware program in March 2015, Corkow v.7.118.1.1 had not been detected by a single antivirus program Starting in December 2014, the criminal group began running keyloggers in the infected system. On the 27th of February, 2015 Corkow provided remote access to the trading system which enabled the hackers to launch programs and enter data at the same time as the system operator did.”
  
Previosly hackers from Ukraine gained access to unpublished stock reports used that information in cooperation with some brokers.

Ivan Turchynov and Oleksandr Ieremenko, two Ukrainian hackers, were indicted on 10 August 2015, for the $100 million insider trading scheme that relied on stealing unpublished press releases. These hackers likely penetrated financial and media databases for years and are likely sophisticated programmers who were very active in the Russian and Ukrainian hacker communities prior to the 2010 breach. Wapack Labs analysts were able to identify these individuals on the Ukrainian Internet as well as connections and possible co-conspirators who may have researched the targets.

One of the companies named in the SEC complaint concerning Ukrainian hackers DSU and Lamarez sharing stolen unpublished press-releases with traders is Exante LTD. This company was registered in Malta by three Russians, Knyazev, Maslyakov and Kirienko, with backgrounds in markets and IT. One of the most unusual of Exante's projects was Bitcoin Fund – ability to invest in Bitcoins. On the peak Bitcoin Fund had up to $100M (92,000 Btc). And coincidently(?) they sold their Bitcoin investments and recommended the same to their clients on the very peak of the Bitcoin price.

One of those attackers, Oleksandr Ieremenko (Alexander Eryomenko, AKA “Lamarez”, “Zl0m”, “Ded.Mcz” and “Sh..)”, is the domain registrant for a Black Energy malware command and control domain.






[1] www.group-ib[.]ru/brochures/Group-IB-Corkow-Report-EN.pdf