Finding Humor in Governance, Risk and Control

Andrew Tarvin is a best-selling author and professional stand-up and improv comedian. He teaches people and organizations how to use humor to be more effective and productive. Tarvin has worked with more than 100 organizations including Procter & Gamble, GE and Western & Southern Life Insurance, speaking, training, and coaching on topics ranging from humor in the workplace to communicating confidently to strategic disengagement.

ISACA Now recently sat down with Tarvin, who will present Agile Leadership:  How to Lead Up, Across, and Down in a VUCA (Volatile, Uncertain, Complex and Ambiguous) World at the 2016 Governance, Risk and Control Conference from 22-24 August in Fort Lauderdale, Florida, USA.

ISACA Now:  There are so many potential landmines when it comes to using humor at work, but overthinking humor can result in stilted un-funniness. What’s the solution?
Tarvin:  This a great question and a common concern for using humor in the workplace. While there are potential landmines, that doesn’t mean humor shouldn’t be used at all. Sending an email could theoretically get you fired (such as if you hit “reply all” on a distribution list causing a massive “Don’t hit reply all” flurry of emails), but we still use email. Just as email is a tool, humor is a tool.

The key to avoiding landmines while still being funny is intent. If you are using humor to get back at someone or really even “just to be funny,” it is more likely to come across negatively. However, if you have a specific reason for using humor (to connect with someone, get people to read an email, etc.), and come from a positive, inclusive perspective, your humor will be better received, creating laughter without offense.

Another way to think about it is that using humor doesn’t give you an excuse to be a jerk or talk about taboo subjects in the workplace. An offensive joke may “just be a joke,” but it’s still offensive.

ISACA Now:  Governance, risk and control are not known for their ability to inspire humor. How can someone inject appropriate humor in otherwise serious tasks and jobs?
Tarvin:  Who says IT governance can’t inspire humor? There’s so much to laugh about in the auditing and control of computer systems…

OK, so it can be a little dry, but the drier the material, the easier it is to instill humor because it’s so unexpected. Just because a job or work is serious doesn’t mean that it can’t be done in a fun, engaging and inspiring way. When I was a project manager at Procter & Gamble, small changes to how I worked had a huge impact. Simple things like using images in my presentations or giving my project team nicknames, went a long way in making the work more enjoyable. My colleagues from one team still call me Drewsito.

Don’t think about using humor as changing what you do, just how you do it. No matter your role, you still have to communicate messages, build relationships and be productive—all things that humor can help you do.

ISACA Now:  Can humor be instilled in an entire organization? How?
Tarvin:  Humor can be instilled in an entire organization, and the answer to how is simple… but not necessarily easy. It’s like how cooking is simple (follow the instructions) but not necessarily easy (my chicken always comes out burnt).

Humor in an organization comes down to individuals making a choice to find ways to enjoy their work more. The best way to encourage people to make that choice is to support them when they attempt to use humor. If someone adds humor to a presentation or email, let them know that you appreciate it (yes, even if the humor didn’t necessarily make you laugh).

Having a leadership team that embraces and uses humor is a huge help as well. The number 1 reason people don’t use humor at work more often is that they don’t think their boss or coworkers would approve. If you can dispel that myth, people will start to try new things; encourage that behavior, and it will start to spread.

It’s like a zombie apocalypse. It all starts with a patient zero and spreads from there. (For a more corporate metaphor, see Margaret Mead:  “Never doubt that a small group of thoughtful, committed citizens can change the world; indeed, it’s the only thing that ever has.”)

ISACA Now:  We’ve all had a supervisor who used humor—or what they thought was humor—in a passive-aggressive or even an active-aggressive manner that was off-putting and more about power than leadership. Can we use humor to safely defuse those situations? How?
Tarvin:  You certainly can use humor to defuse a situation, but how you do it comes down the specific circumstances. Perhaps one of the biggest challenges with humor is that it is very situational; what works in one setting for one person could backfire in a different setting with a different (or even the same) person.

For example, I think puns are like the coolest technologies we support—everyone should want to use them every day. Instead, they tend to be more like audits—people groan whenever they hear about them (sorry, just a joke to all of my auditors out there).

Safely using humor to defuse the situation goes back to having positive intent about the humor you use and really understanding your purpose.

ISACA Now:  Oftentimes when teams want to solve a significant problem or do some major brainstorming the words, “Okay, let’s get serious and focus,” are used. How can humor regain a seat at the table?
Tarvin:  It’s important to recognize that serious work doesn’t mean it can only be done in a serious way. In fact, the more serious something is, the more power humor tends to have, particularly when it comes to problem solving. Humor and creativity are both about finding unique connections and providing a new perspective.

In one study, students who watched a 20-minute comedy video before being asked to solve a problem were nearly 4 times more likely to solve the problem than students who didn’t watch the film. (If you want to know what problem they had to solve, check out the Candle Problem.) Humor gets the brain looking for new connections. Take this simple joke:  “I can’t believe I got fired from the calendar factory. All I did was take a day off.” In order to understand it, your brain started making connections between “calendar factory” and “take a day off.” That same process is how we solve problems.

If you’re serious about solving a problem, you’ll use the best means to solve that problem, and humor is one of them.

Andrew Tarvin, Author, 2016 Governance, Risk and Control Conference Presenter

[ISACA Now Blog]

Recent MNKit Exploit Activity Reveals Some Common Threads

Unit 42 recently identified a variant of MNKit-weaponized documents being used to deliver LURK0 Gh0st, NetTraveler, and Saker payloads. The documents were delivered to targets involved with universities, NGOs, and political/human rights groups concerning Islam and South Asia. Reuse of this MNKit variant, sender email addresses, email subject lines, attachment filenames, command and control domains, XOR keys, and targeted recipients show a connection between the different payload families delivered.

MNKit is the name given to a builder that generates CVE-2012-0158 exploit documents. The documents are in MHTML format and install a malicious payload on the compromised host. We believe MNKit is privately shared between multiple attack groups, but is not widely available.

Information about previous attack campaigns using MNKit is available in the following reports:

For more details on MNKit, see the Sophos publication, Office exploit generators.

Typical MNKit MHTML files have used User123 or User323 as the Author and LastAuthor element values within their DocumentProperties sections and C:/2673C891/Doc1.files/ as a file directory location. The samples discussed in this blog use User323 and User426 as Author and LastAuthor element values and C:/23456789/Doc1.files/ as a file directory location.

LURK0 Delivery

LURK0 is a family of remote access trojans derived from Gh0st RAT. It has been used by attack groups for years, as discussed by CitizenLab in a publication from 2012 on Tibet-related information operations and has been fairly well analyzed in publicly available reporting. Contained within a subset of the MNKit exploit documents were malicious SFX PE files that delivered LURK0 implants. These PE files were encoded using a decrementing XOR function with the key beginning at 127. Within each SFX are five files:

The execution of the self-extracting zips side-loading of LURK0 payloads is identifiable by the registry key they create

The hashes and compile times of the malicious RasTls.dll files follow:

http://www.amerikauyghur[.]top and dge.123nat[.]com are two command and control domains resolved by the malware. The first domain was previously mentioned by Arbor Networks in a report detailing the targeting of Tibetan, Hong Kong, and Taiwanese interests in their report, The Four-Element Sword Engagement. A subdomain of 123nat[.]com, manhaton.123nat[.]com, was also referenced in Arbor’s report as a LURK0 command and control domain. Below shows theLURK0 string used in the first five bytes of an implant beacon.

Saker Delivery

Saker, often also called ‘Xbox’ and ‘Mongall’, is a malware family used by targeted attack groups who have also deployed NetTraveler and Gh0stRAT.

Two of the sending addresses used to distribute the above LURK0 samples,dolkun2015@gmail[.]com and duqdiniishlari@gmail[.]com, were also used to distributed other types of malware. By observing overlaps in the sending and receiving email addresses as well as the filenames of attachments, we were able to identify additional MNKit exploit documents that also included self-extracting PE files. These PE files were again XOR encoded in the attached documents using the same decrementing key (beginning with 127). These additional SFX PE files are password protected using one of the following passwords:

Instead of including RasTls.exe to sideload payloads (as the LURK0 payloads did), within each of the embedded PEs is a single DLL file named msdis.dll which exports a function namedJustTempFun. The recently compiled and deployed msdis.dll files’ SHA256 hashes and compile timestamps follow:

Saker samples construct strings during execution. One such string is the origin of the malware’s name.

The Saker PEs also contain a user agent strings (also constructed manually during execution) of Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; .NET CLR 1.1.4531) and Mozilla/6.0 (compatible; MSIE 9.0; Wis NT 8.1; .NET CLR 2.13431). This second user agent is similar to the user agent, <code>Mozilla/4.0 (compatible; MSIE 6.0; Wis NT 5.0; .NET CLR 1.1.4322), as outlined by FireEye in 2014.

The command and control locations for the Saker samples delivered via MNKit follow:

amerikauyghur[.]top overlaps with the LURK0 samples previously mentioned. Bothonebook[.]top (registered with a registrant email address of interestbook@sina.com and bsnl.wang (registered with a registrant email address of jgjop@yahoo.com) have resolved previously to 103.232.222[.]20.

Using AutoFocus, we were able to locate additional samples that resolved to these domains. The samples are a mix of LURK0, Saker, and PlugX. Their hashes follow:

Pivoting from the first rather unique user agent string we located the following Saker samples ontotalhash:

These samples beacon to http://www.togolaga[.]com (103.246.246[.]221) and unisers[.]com (123.254.104[.]32) which respectively were mentioned by the Sophos Rotten Tomatoes publication.

Within AutoFocus the user-agent string was also seen being used by the following Saker sample hashes:

These resolve and connect to the following domain names:

notebookhk[.]net, also mentioned in the Rotten Tomatoes report, was at one point a known PlugX command and control domain. This domain as well as http://www.dicemention[.]com are noted Korplug (often used to load PlugX) domains outlined by ESET in a blog post here. These domains as well as other overlapping indicators, such as the export function nameJustTempFun, were discussed by ProofPoint in a 2015 publication on PlugX targeting Russian military and telecom organizations and by Kaspersky in part 1 of their publication on NetTraveler.

NetTraveler Delivery

NetTraveler is a backdoor used to install other malware, steal information, and provide remote control of a compromised system. The targets previously mentioned by Kaspersky Lab of the NetTraveler operators aligns closely with the recipients of a new set of samples.

Three additional MNKit documents were located as MNKit exploit attachments. Unfortunately, we were unable to locate emails the attachments were sent with. These three samples also included SFX PE files encoded using the same decrementing XOR. Within each PE are three files which side-load NetTraveler. The files are named:

The hashes and compile timestamps for each fslapi.dll follow:

The fslapi.dll files load their accompanying fslapi.dll.gui files that are XOR encoded. The decoded fslap.dll.gui DLLs include the following embedded URLs, the first of which was previously documented by Unit 42 as a red herring within NetTraveler samples.

The fslapi.dll files contain an overlay that is used to decode the real C2 as documented in the same Unit 42 NetTraveler blog. The decoded command and control URLs include:

Both domains have previously resolved to 103.231.184[.]163 which has also hostedhttp://www.tassnews[.]net http://www.info-spb[.]com, both of which have also been used as NetTraveler command and control domains. http://www.tassnews.net is also the resolved by

the SFX PE (encoding using the same decrementing XOR) decoded from

another sample of this MNKit variant.

Tassnews[.]net was registered with a registrant email address of ghjksd@gmail[.]com and info-spb[.]com was registered with a registrant email address of kefj0943@yahoo[.]com.Riaru[.]net was registered with a registrant email address of fjknge@yahoo[.]com on 29 March 2016, which also registered one other domain name, yandax[.]net, on 16 June 2016 using the same authoritative DNS servers and registrar. Interfaxru[.]com was registered with a registrant email address of ganh@gmail[.]com on 18 April 2016 using the same registrar and authoritative DNS servers as riaru[.]net and yandax[.]net. Only one domain name is currently registered byganh@gmail[.]com, however it would be no surprise if an additional domain is registered by this registrant in the near future.

Putting it All Together

While MNKit has been associated with multiple different groups the reuse of domain names, IPv4 addresses, phishing themes, XOR schemes, and email accounts are strong evidence for linkage between these new attacks and the previously documented ones. The change in PE SFX contents over the three sets of SFX PE files between February 2016 to March 2016, March 2016 to April 2016, and April 2016 to June 2016 time frames show a slight deviation is payload but consistencies in delivery methods. The best defense against MNKit is to ensure your systems are patched for CVE-2012-0158, but in situations where this isn’t possible, exploit mitigation technology like Traps is warranted.

While attribution is a challenging art, it’s likely whoever is behind these recent attacks is, through infrastructure, malware families and delivery techniques, somehow related to the previously reported attacks. The attackers have been active for years, will likely continue to be active, and seem to prefer to change tactics only subtly.

AutoFocus users can track the malware discussed above using the following tags:

Examined MNKit Samples and Payloads

MNKit MIME attachments carrying LURK0 payloads:

LURK0 payload files contained within MNKit documents:

MNKit MIME attachments carrying Saker payloads:

Saker payload files contained within MNKit documents:

MNKit MIME attachments carrying NetTraveler payloads:

NetTraveler payload files contained within MNKit documents:

[Palo Alto Networks Research Center]

Securing the Industrial Internet of Things with Palo Alto Networks and Honeywell

Last week I had the good fortune to attend the 2016 Honeywell Users Group Americas event in San Antonio, Texas. At this annual event, Honeywell customers from around the world come together to solve common problems in SCADA/ICS and attend keynote speeches and roundtable discussions on topics such as the industrial internet of things (IIoT), cybersecurity, alarm management, and more.

It also served as the first public exhibit of the results of the partnership we announced with Honeywell in February to jointly develop industrial cybersecurity solutions. As described in Honeywell’s keynote address, Honeywell has integrated Palo Alto Networks Next-Generation Firewall technology into their industrial cybersecurity solution, Risk Manager, to provide advanced network traffic inspection. With our next-generation firewall technology, Honeywell’s industrial control customers will have much more insight into who is using which applications on the network, what assets and data they are accessing, and what threats may be trying to breach or pivot around the OT network. With that information, customers can take a more proactive approach to industrial cybersecurity, even protecting their networks from previously unknown attack methodologies.

In addition to our next-generation firewall technology, Honeywell is offering the Palo Alto Networks WildFire WF-500 zero-day, on-premises sandboxing device to augment theirHoneywell Managed Industrial Cyber Security Services offering. Designed to provide cybersecurity consulting services to customers who don’t have the required expertise in-house, the services offering uses WildFire to provide Honeywell’s security experts with the latest threat intelligence in real time.

Ariel Cohen of Palo Alto Networks at the 2016 Honeywell Users Group. The monitor displays a diagram of Honeywell’s industrial cybersecurity reference solution featuring Palo Alto Networks Next-Generation Firewall technology.

If you’d like to learn more about Honeywell’s integration of Palo Alto Networks next-generation security technology, you can download this solution brief.

For more information about cybersecurity and the IIoT, take a moment to read some other blog posts I’ve authored on the subject.

[Palo Alto Networks Research Center]

English
Exit mobile version