Dridex Banking Trojan Distributed Through Word Documents

Dridex, the latest descendent of the Bugat/Feodo/Cridex banking Trojan lineage has been a constant source of attacks using the malware since its release in July. To date, Dridex has centered on sending executable attachments via e-mail. That seems to have changed this week, as we’ve seen a tactical shift to sending those executable attachments via Microsoft Word documents loaded with macros that download and execute the malware.

Like its precursors, Dridex is a sophisticated Banking Trojan, similar to the infamous Zeus malware. Its core functionality is to steal credentials of online banking websites and allow a criminal to use those credentials to initiate transfers and steal funds. Dridex uses an XML-based configuration file to specify which websites it should target and other options for the malware. For instance, the configuration specifies which websites to capture form submissions from, and which to ignore with the following XML.

<formgrabber>

<url type=”deny”>\.(swf)($|\?)</url>

<url type=”deny”>/isapi/ocget.dll</url>

<url type=”allow”>^https?://aol.com/.*/login/</url>

<url type=”allow”>^https?://accounts.google.com/ServiceLoginAuth</url>

<url type=”allow”>^https?://login.yahoo.com/</url>

<url type=”allow”>^https?://login.live.com/</url>

<url type=”deny”>^https?://(\w+\.)?aol.com</url>

<url type=”deny”>^https?://(\w+\.)?facebook.com/</url>

<url type=”deny”>^https?://(\w+\.)?google</url>

<url type=”deny”>^https?://(\w+\.)?yahoo</url>

<url type=”deny”>^https?://(\w+\.)?youtube.com</url>

<url type=”deny”>^https?://(\w+\.)?live.com</url>

<url type=”deny”>^https?://(\w+\.)?twitter.com</url>

<url type=”deny”>^https?://(\w+\.)?vk.com</url>

<url type=”deny”>^https.*ocsp\..+$</url>

<url type=”deny”>^https.*safebrowsing\..+$</url>

<url type=”deny”>^https?://fhr\.data\.mozilla\.com</url>

<url type=”deny”>^https://s.*\.symcd\.com</url>

<url type=”deny”>^https://s.*\.symcb\.com</url>

<url type=”deny”>^https.*ocsp2\..+$</url>

<url type=”deny”>localhost.+skypectoc/.+$</url>

<url type=”deny”>\.messenger\.live\.com</url>

<url type=”deny”>pipe\.skype\.com</url>

<url type=”deny”>\.optimatic\.com</url>

<url type=”deny”>hiro\.tv</url>

<url type=”deny”>spotxchange\.com</url>

<url type=”deny”>nielsen\.com</url>

<url type=”deny”>mapquest\.com</url>

<url type=”deny”>^https://.+\.skype\.com/api/</url>

<url type=”deny”>(//|\.)lphbs.com</url>

<url type=”deny”>(//|\.)zynga.com</url>

</formgrabber>

The first wave of this attack began on October 21, with e-mails claiming to carry invoices fromHumber Merchant’s group. On October 22 and 23 (and today) we’ve seen new brands abused but the e-mails continued to use invoice themes.  The organizations we’ve seen receiving these files break down into the following countries.

With this latest wave, WildFire has detected nine distinct Word documents, each of which uses the same technique to install Dridex.  The word documents contain a complex VBA macro that downloads an executable from one of the following URLs and executes it on the system.

These are all legitimate websites that appear to be compromised by the actors running this Dridex campaign. The files are each different versions of the Dridex malware that communicate with their command and control servers over HTTP. Kimberly from StopMalvertising has a great article on how this communication process works and allows Dridex to download its main criminal components.

While the latest attack began this week, Dridex has been in the wild since late July, and since then our WildFire system has been detecting Dridex variants very effectively. As a result, we pulled data on all of the malware we’ve seen talking to known Dridex command and control servers to get an idea of the volume of Dridex activity since its release. Abuse.ch operates theFeodo Tracker, which tracks these servers and those used by earlier versions of the Trojan.

While the latest attacks are certainly significant, the volume we’ve observed has been much lower than in July and August when the first variants of Dridex were first observed.

You can protect yourself against this wave of Dridex attacks by disabling macros in Microsoft Word. Macro-based malware has been around for over well over a decade. Most organizations should have them disabled by default, enabling macros only for trusted files.

[Palo Alto Networks Blog]

CIP Version 5 Approaches: How Best to Secure Energy Utilities

The effective date for CIP version 5 Standards is rapidly approaching and entities are beginning to implement new controls to meet the updated requirements.

Palo Alto Networks expert Del Rodillas, along with experts from EnergySec and ENMAX will discuss the new requirements and potential technical approaches to meeting compliance obligations.

Register now, and see full details below:

CIP Version 5 Standards: Electronic Security Perimeters and Interactive Remote Access

  • Wednesday, October 29, 2014, 10 a.m. PT / 1 p.m. ET
  • Register now.

For more on Palo Alto Networks solutions for ICS, SCADA and utilities

[Palo Alto Networks Blog]

Ransomware Attacks Subvert Ad Networks

Security vendor Proofpoint warns in a new report that a “malvertising” campaign has been launching ransomware attacks against users of numerous high-profile websites, including search site Yahoo, dating site Match.com, and an AOL real estate site.

Proofpoint says it saw a surge earlier this month of malvertising exploits involving attackers serving real-looking advertisements that harbor malware on legitimate advertising networks.

“These types of malware infections are particularly effective because often the end user is not aware they have been infected,” says Mark James, an information security researcher at anti-virus firm ESET. “What would appear as an ordinary [legitimate] advertisement on a website can contain code that once the advertisement is clicked will infect your systems and could still deliver the advertised product.” Attackers often vary their attacks based on geography, which can make related malvertising campaigns difficult to spot, at least until the related levels of activity reach a “significant” level, Proofpoint says.

In the case of this criminal campaign, attackers’ malicious advertisements first targeted website users with the FlashPack Exploit Kit, which is designed to automatically exploit a number of known vulnerabilities in users’ browsers and browser plug-ins. If successful, the exploit kit then installed ransomware – malware that encrypts all data on a user’s PC and then demands a payment for the decryption key – called Cryptowall 2.0.

Tracking Cryptowall 2.0

The 2.0 version of Cryptowall was first spotted earlier this month by Finnish anti-virus firm F-Secure, which says the malware is using a custom component that allows it to communicate with command-and-control servers via the anonymizing Tor network, which helps disguise related infections. F-Secure says it first spotted criminals testing related tweaks to Cryptowall 1.0 this past summer, after which the changes were formally packaged up and released as Cryptowall 2.0. “We expect to see a lot more of Cryptowall 2.0 in the near future,” F-Secure trainee Artturi Lehtiö said in an Oct. 2 blog post.

That prediction soon came to pass. Proofpoint says it saw the malvertising campaign begin in late September. But related attacks didn’t spike until earlier this month, when they grew to expose approximately 3 million website users daily to related attacks.

Proofpoint says it contacted affected advertising networks, and by Oct. 18, they’d blocked the accounts that were being used to serve the malware. “The sites themselves were not compromised; rather, the advertising networks upon which they relied for dynamic content were inadvertently serving malware – which in turn, was not due to an explicit compromise of the networks; rather, it was due to the networks accepting ads from a malicious source without [proper] screening,” Proofpoint says.

While AOL and Match.com didn’t immediately respond to a request for comment about the Proofpoint report, a Yahoo spokeswoman confirms that the company has taken measures to block such attacks. “As soon as we detected the incident, we promptly removed the advertising and have continued to monitor and block any advertising being used for this activity,” she says.

Meanwhile, attackers continue to use Cryptowall for other in-the-wild attacks. Firewall vendorPalo Alto Networks reports that since Sept. 30, it’s spotted 84 new Cryptowall 2.0 variants. These variants target consumers “primarily through e-mail attachments but also through malicious PDFs and Web exploit kits,” it says. Those malicious PDFs would target users via phishing attacks, meaning the malicious documents would arrive attached to fake but real-looking e-mails.

Exploit Kits

While attackers continue to develop and refine their ransomware, the exploit kits they’re using to install Cryptoware – and numerous other types of malware – on victims’ PCs likewise continue to evolve. That’s due in large part to market demand: Exploit kits are predicated on exploiting a user’s PC through any means available, and security experts say there’s fierce competition among exploit-kit authors in search of more paying subscribers for their crimeware.

One currently popular crimeware kit, for example, is the Fiesta exploit kit, which security researchers at Cisco describe as being “aggressive” because it includes the ability to exploit not only common Java vulnerabilities, but also bugs in Microsoft Silverlight. While Oracle and Microsoft have released related patches, many users and businesses fail to install those updates in a timely manner, thus leaving them vulnerable to exploit-kit attacks.

After vendors release a security update for a product to fix flaws, exploit kit authors typically reverse-engineer the fixes to identify the flaws, and then add the ability to exploit those vulnerabilities to their kit.

How quickly do exploit kits get updated to take advantage of the latest flaws? This week, the Fiesta exploit kit reportedly received an update that allows it to exploit a Flash flaw that was patched by Adobe only last week. The “weaponized” version of the Flash flaw – an integer-overflow bug that’s been designated CVE-2014-0569 – was discovered by the malware researcher “Kafeine,” who maintains the “Malware don’t need Coffee” blog. Kafeine reports that the competing Angler exploit kit may also now be able to exploit the flaw.

In other words, just one week – or less – elapsed between Adobe issuing a public warning as well as related update that fixes the flaw, and attackers integrating the vulnerability into an exploit kit. That short timeframe shows the challenges facing consumers and enterprises that must keep their browser plug-ins – especially Flash and Java – up to date, or face a nearly constant risk of being hacked.

“The bad guys are not going to run short of vulnerabilities they can weaponize at a quicker rate than ever before,” security researcher Jérôme Segura, who works for anti-malware software firm Malwarebytes, says in a blog post. “This leaves end users with very little room for mistakes, such as failing to diligently apply security patches sooner rather than later.”

Follow Mathew J. Schwartz on Twitter: @euroinfosec

[Gov InfoSecurity]

NIST Privacy Workshop Moves Forward with Framework Development

I attended the second National Institute of Standards and Technology (NIST) Privacy Engineering Workshop on behalf of ISACA, which was held in September in San Jose, California, USA. NIST took the information that they collected at their first workshop in April 2014 and put together a proposed high-level draft of the beginning of what will eventually become the privacy engineering framework—the “Preliminary Concepts” that will ultimately become integrated with the U.S. Framework for Improving Critical Infrastructure Cybersecurity, which was published early this year.

This workshop focused on four primary activities:

  1. Reviewing the proposed privacy engineering definitions
  2. Reviewing the proposed “System Privacy Risk Equation”
  3. Determining a lexicon of privacy objectives, establishing common terms and categorizing potential privacy harms
  4. Hearing from engineers, privacy experts and privacy advocates about additional issues

Proposed Privacy Engineering Lexicon
If engineers are expected to be able to understand privacy principles and then build privacy controls into their systems, devices and processes to effectively protect privacy, then they must be operating under a common vocabulary to understand the terms in the same way across the enterprise and then consistently implement the privacy controls. Some of the terms proposed by NIST, based upon their research and feedback from the April workshop, include three primary privacy engineering objectives and some primary privacy terms that all engineers need to know and understand.

The proposed privacy engineering objectives include (with my interpretations shown):

  • Predictability: These are actions to support reasonable assumptions individuals have about how their personal information is collected, used and shared.
  • Manageability: These are actions to allow individuals to access, correct, delete and selectively disclose their associated personal information as they determine to be appropriate.
  • Confidentiality: These are actions to ensure only authorized access to personal information occurs.

There was also discussion of the need for a possible fourth objective: data subject disclosure and rights. However, as various speakers and attendees pointed out, this is something that could be a challenge to actually engineer.

A few of the key privacy terms proposed by NIST include:

  • Data Actions: The typical information systems operations where personal information is involved.
  • Problematic Data Actions: These are data actions taken with personal data that violate the objectives of predictability, manageability and confidentiality. For example, distortion, misappropriation and surveillance, just to name a few.
  • Context: A critical term for engineers to understand. This is a concept that I emphasize all the time to my clients and in the classes I teach. It is also something most systems engineers do not take into consideration Context refers to the actions that should be taken based upon the reasons personal information is collected, and the ways in which it was intended to be used.

Defining Categories of Privacy Harms
NIST has proposed the following categories of privacy harms to be addressed by the privacy engineering framework.

  • Loss of Self-Determination: These would include loss of autonomy, exclusion, and loss of liberty.
  • Discrimination: These would include stigmatization and power imbalance.
  • Loss of Trust: This would include situations where a breach of promises has occurred.
  • Economic Loss: Direct financial losses resulting from identity theft and other misuse of personal information.

I firmly believe physical harm and safety should be another category added to the list. Here are just two considerations to support this.

  1. We now have many devices that attach to individuals, and are used by individuals, to control their health, environment, etc. If the personal information and associated data within these devices was inappropriately accessed, used, altered, etc., it could result in physical harm to the associated individuals.
  2. The types of surveillance methods and technologies continue to proliferate. They could be used to locate individuals, determine when individuals are alone, and reveal other aspects of an individual that could enable a malicious individual to bring harm to the individual in ways that could not occur without these surveillance methods and technologies.

Proposed System Privacy Risk Equation
NIST created a proposed “System Privacy Risk Equation” to help engineers to determine privacy risks in a similar way to how they use the information security risk formulas to determine information security risks. The big difference, though, is that the components focus on the likelihood of harm to the individuals involved, not to the organization itself. Which makes sense since the focus of privacy is on the individual.

The proposed System Privacy Risk Equation was presented as a diagram. Here is my interpretation in a more mathematical representation:

System privacy risk is the risk of problematic data actions occurring during
(Personal Information Collected or Generated +
Data Actions Performed on that Information +
Context)
= System Privacy Risk

One concept missing from this formula is stakeholder input. Without such input, it will be very hard to truly determine the associated privacy risk. I will look for this to be included in the updated equation, based upon discussions at the workshop.

Additional Issues to Address
In addition to the components of the proposed framework above, some of the additional issues that attendees expressed a need to add included:

  • The need for basic privacy education for all involved with engineering privacy controls, in addition to providing detailed guidance documents and case studies
  • Related to this, the need to educate the public on what is reasonable to expect from organizations with regard to preserving their privacy, and what they themselves need to take responsibility for
  • The establishment of metrics to measure how well each of the privacy areas are being addressed within the organization, and to support a determination of an organization’s privacy program maturity model
  • Addressing how engineers can include privacy actions within existing systems and software development models, such as agile and waterfall methodologies
  • The need to shift the business view of privacy from being a compliance checklist responsibility to being a more holistic evaluation of privacy risks activity

You can download the documents containing the full details of the items discussed above, including the NIST proposed definitions, from www.nist.gov/itl/csd/privacy-engineering-workshop-september-15-16-2014.cfm.

Privacy is about the individual; security is about the business
A couple of recurring thoughts that were described during the workshop that are very important points for organizations to be able to effectively understand and then take appropriate actions to preserve privacy are:

  1. The primary focus for privacy risks and mitigations generally is on individuals. This is different than the primary focus for information security, which generally is on the business.
  2. Privacy must become part of the business culture and be addressed throughout every aspect of business activities where personal information is involved in any way.

Going Forward
This was an important next step toward establishing actionable privacy standards to include within the US Cybersecurity Framework to provide a reference that engineers will be able to effectively utilitize within their current systems and software development frameworks to help build in the controls currently missing that are needed to most effectively protect personal information and mitigate privacy risks. I do not see this as the last workshop, however; there were several issues that were left open and some that were not addressed at this workshop. NIST also emphasized that the privacy engineering initiative was a distinctively separate effort from the cybersecurity work, implying that there would be at least another workshop down the road.

I look forward to seeing the resulting NIST Interagency Report (IR) that Naomi Lefkovitz indicated would be created as a result of the workshop, and then attending the next workshop where the Privacy Framework likely will be finalized.

Rebecca Herold, CISA, CISM, CISSP, CIPP, FLMI
Owner & CEO, Rebecca Herold & Associates

[ISACA]

Palo Alto Networks Honored With 2014 STAR Award for Support Services Innovation

Palo Alto Networks has received a 2014 STAR Award for Innovation in the Delivery of Support Services!

The STAR Awards, which are presented by the Technology Services Industry Association (TSIA), are among the highest honors in the technology services industry, and were handed out this week at the Technology Services World 2014 Service Transformations conference in Las Vegas.

You can view the TSIA release and the full list of 2014 STAR Award winners here.

[Palo Alto Networks Blog]

English
Exit mobile version