Following this week’s headline-grabbing breach, we all learned of an exploit utilizing CVE-2015-5119, a zero-day vulnerability in Adobe Flash. Successful exploitation of this vulnerability allows an attacker to take control of an affected endpoint, making it a critical threat. Various security researchers have since reported that the zero-day was indeed exploited in active attacks.
CVE-2015-5119 can be exploited against all commonly used browsers, including Google Chrome, which is considered to be much harder to exploit relative to other browsers.
This disclosure provides us a rare glimpse into the advanced attack tools market. From my perspective, the critical lesson to take from this incident is not the specific zero-day vulnerability itself, but the acknowledgment that this is merely the tip of the iceberg. One live zero-day exploit was disclosed by chance, but many others are and will be developed, marketed and utilized worldwide.
CVE-2015-5119 is part of an increasing trend of exploiting Flash vulnerabilities. Earlier this year we have referred in this blog to zero days CVE-2015-0311 and CVE-2015-0313, as well as a deep technical analysis of a new Flash vulnerability exploitation. Most recently was the CVE-2015-3113 zero-day, disclosed a week ago. Additional patched Flash vulnerabilities were rapidly reversed by attackers and integrated in the leading exploit kits.
To counter trends like these, the endpoint security paradigm must shift towards a proactive approach, capable of preventing known and zero day exploits. Palo Alto Networks Traps prevents memory corruption exploits in real time, obstructing the core techniques used in exploitation without needing to rely on any prior knowledge of attacks. Traps successfully prevented exploitation zero-day CVE-2015-5119, and users of Traps as part of the Palo Alto Networks Security Platform were already protected from exploitation of these vulnerabilities prior to the disclosure and patch.
Exploits are the default attack vector in the current threat landscape. Traps is the only solution that provides proactive protection from this vector.
Read more about Traps advanced endpoint protection here.
I don’t usually blog about specific product features, but I’m so excited about our new correlation objects, released in our 7.0 update to PAN-OS, that I really can’t help myself. It’s been a month now since we released 7.0, and I’m still particularly jazzed about this new feature!
Correlation objects, available in our PA-5000 Series, PA-3000 Series, the PA-7050, andPanorama, accurately identify infected devices based on patterns of network behavior that are correlated to characteristics of specific threats. So, for example, if a device is infected, the correlation engine can identify a pattern of a behavior: a host having visited a malware URL, then a vulnerability being exploited, and then abnormal DNS requests generated from said host.
Maybe a user took a corporate laptop home and inadvertently picked up some known malware (looks like GlobalProtect wasn’t activated!). When this user reconnects to the network, the correlation object correlates suspicious activities stemming from that device, which may not be of any concern individually, but taken together, alert the security team that this laptop needs to be remediated.
Meanwhile, the infection is stopped from spreading because Threat Prevention IPS, AV, and anti-spyware protections have blocked the malware from moving laterally inside the network and ended its outbound command and control beacons.
What’s really cool about this, though, is how it works with WildFire to dynamically correlate network activities based on zero-day malware.
Take the same concept of looking for patterns of abnormal behavior that point to infection, and from there, factor in zero-day malware that WildFire discovers. As soon as WildFire analyzes new file behavior, which only takes a few minutes for completely unknown files, a report on the file’s malicious behavior is sent back to the security platform. Our correlation engine consumes that report and looks for patterns of behavior specific to the newly discovered malicious file across the device from which it originated and other devices in the network, both going forward (analyzing in real time) and looking back through logs from 96 hours before the file was forwarded to WildFire.
At Palo Alto Networks, we believe that prevention isn’t futile – in fact, it’s central to stopping breaches. However, quick mitigation is also important to limit the damage and learn from threats that get past your defenses. With the right ecosystem of detection, intelligence, and prevention, infection doesn’t have to turn into a catastrophe.
There are currently five correlation objects available: three static objects that were created from Unit 42 research and two that are dynamically fed information from WildFire submissions. These five correlation objects are just the beginning. Our threat research teams, including Unit 42, will eventually be able to create new correlation objects based on their ongoing research into new attack campaigns and deliver them to deployed platforms through weekly content updates.
I often speak with ICS asset owners who are just at the beginning of their next-generation firewall learning curve. They are usually pleasantly surprised at the capabilities it provides in identifying traffic at Layer 7, i.e. application, users and threat/content.
Beyond just being able to see network traffic at this very detailed level, the fact that these key pieces of information are intrinsically correlated — a unique advantage of our single-pass, parallel processing architecture (SP3) — is a major draw. The proverbial “light bulb” turns on very quickly and they understand why this approach means easier anomaly detection, faster forensics and better auditability in their ICS environment.
Understandably, the word “firewall” in the product name often invokes the question of whether the device can be used in a more passive, detection-only model. To support such monitor-only deployments, the Palo Alto Networks Next-Generation Firewall offers a deployment mode called “Tap Mode.” Using this deployment, the next generation firewall can be connected to a SPAN/mirror port on a network device, like a switch or router, to passively monitor the traffic going through this “hub.” Doing this provides not only better visibility, but more importantly, correlated visibility into useful pieces of network traffic information.
Why “monitor-only”?
Why not deploy the device inline as a firewall is meant to be deployed? A common reason in ICS is that the owner has a monitor-only mindset or policy for critical areas of the ICS. Consider, for example, the core of a Distributed Control System (DCS) where there may be zero tolerance for any potential accidental blocking of traffic. They want to avoid any additional inline devices aside from the main equipment needed to run the process and provide connectivity. While this organization may put a security device inline at the IT-OT perimeter, they would never do so within the DCS core. However, a non-invasive visibility tool could prove useful and hence could be considered for deployment.
Another reason for putting the device in passive mode, even at the perimeter of the ICS, such as between corporate and the PCN (process control network), is because the asset owner is not quite ready to do a rip-and-replace of his existing security architecture. While the asset owner may admit that the existing system will need to be replaced eventually due to lagging capabilities, he still prefers a more gradual migration path that feels less disruptive. A device that can be easily dropped in with minimal impact to the current production system, while providing high value, is ideal. Eventually the owner may swap out the old with the new as he validates the new product and gets more comfortable with the technology.
Shedding the light on plant floor traffic
Users of Palo Alto Networks next-generation firewalls now have access to a variety of rich and natively correlated network traffic information including the following:
ICS Protocols and Applications – For example to Modbus, DNP3, OPC, ICCP, OsiSoft Pi, Schneider OASyS, Cygnet, etc. For some protocols, the visibility is provided at the function code level (i.e. Modbus Reads and Writes)
SaaS & Social Media – Applications which typically should not be allowed in ICS environments but are sometimes found, e.g. Dropbox, P2P file sharing, TeamViewer due to irresponsible use by employees
Custom Traffic – Custom “App-IDs” can be easily created using the firewall itself to identify homegrown applications.
User / User Group – The next-generation firewall can utilize different sources of IP-to-user mappings and events to enable user and user-group visibility. These include directory services, authentication events, and even via the API. The user-information will be tied to the application/protocol traffic thereby providing user-based access logs.
Content – The firewall can be used to identify files, strings, URLs.
Known Threats – Network-borne known exploits, malware, and command and control traffic. Again threat information is contextually tied to application/protocol and user information.
Zero-day Malware – If the firewall is connected to the Wildfire service, the device can also be used to identify zero-day malware in as little as 5 minutes for the on-premises Wildfire offering.
Several areas where users are typically interested in gaining more situational awareness and capabilities for auditing traffic include:
ICS core – Monitor traffic off of a switch interconnecting the HMIs, workstations and automation servers on the plant floor. This should mostly be repetitive machine-to-machine traffic so anything out of the ordinary is likely to jump out.
IT-OT perimeter – Use the Next-generation firewall to augment any existing access control device like a Router (ACL) or stateful inspection firewall (limited visibility at the port and IP address level)
3rd party connections – Similar to the IT-OT perimeter, make sure to monitor the connectivity you have with third parties like partners and ICS vendors and systems integrators
Moving beyond monitor-only
In practice, many users start off in tap mode then eventually move into one of two inline deployments modes (VWIRE “bump-in-the-wire”, L2/L3 Firewall Replacement), realizing the powerful network segmentation capabilities of the device. In other scenarios they may deploy the devices in a hybrid model where some areas the firewall is inline with access controls and in some areas the device is in tap mode.
Not all organizations have the same network architecture or the same view on security posture. Our next-generation firewall’s support for multiple deployment modes highlights one of the ways our platform provides flexibility. In fact the multiple ports on a Palo Alto Networks firewall could be configured to support multiple deployment modes simultaneously (Tap, VWIRE, and L2/L3).
Practicing What We Preach – Application Visibility and Risk Report
Interestingly enough, Palo Alto Network field teams often use the firewall in tap mode when conducting free Application Visibility and Risk (AVR) assessments. We basically connect the device in passive mode to the network cluster of interest then provide a report back to the end user on what applications and risks may be present in their network today.
It’s rare to have an AVR which does not result in immediately useful information regarding security risks. It is free and is an easy way to understand the value of correlated, layer-7 visibility and also perhaps to discover any exposures to your organization. Contact your local Palo Alto Networks representative to learn more or sign up for an AVR online.
To learn more about our platform approach to securing industrial control systems, please access the free white paper on 21st century SCADA security.
Unit 42 discovered a new family of Android malware that successfully evaded all antivirus products on the VirusTotal web service. We named this malware family “Gunpoder” based on the main malicious component name, and the Unit 42 team observed 49 unique samples across three different variants. This finding highlights the fine line between “adware,” which isn’t traditionally prevented by antivirus products, and malware, with its ability to cause harm.
Samples of Gunpoder have been uploaded to VirusTotal since November 2014, with all antivirus engines reporting either “benign” or “adware” verdicts, meaning legacy controls would not prevent installation of this malware. While researching the sample, we observed that while it contained many characteristics of adware, and indeed embeds a popular adware library within it, a number of overtly malicious activities were also discovered, which we believe characterizes this family as being malware, such as:
Collecting sensitive information from users
Propagating itself via SMS message
Potentially pushing fraudulent advertisements
Ability to execute additional payloads
Gunpoder targets Android users in at least 13 different countries, including Iraq, Thailand, India, Indonesia, South Africa, Russia, France, Mexico, Brazil, Saudi Arabia, Italy, the United States, and Spain. One interesting observation from the reverse engineering of Gunpoder is that this new Android family only propagates among users outside of China.
Unit 42 investigated Gunpoder using the Palo Alto Networks AutoFocus service, and released protections for users of WildFire, Threat Prevention and Mobile Security Manager for all currently known Gunpoder variants. Thanks to Palo Alto Networks unique prevention capabilities across the attack lifecycle, future members of the Gunpoder malware family could also potentially be blocked.
Evading Detection
By examining the reverse-engineered samples, we found the malware author applied several unique techniques to evade antivirus detection:
Gunpoder samples include aggressive advertisement libraries, such as Airpush, within the samples. Those ad libraries are easily detected and may also include aggressive behaviors. The malware samples successfully use these advertisement libraries to hide malicious behaviors from detection by antivirus engines. While antivirus engines may flag Gunpoder as being adware, by not flagging it as being overtly malicious, most engines will not prevent Gunpoder from executing. Figure 1 shows the VirusTotal scan results on one sample.
Users who have executed Gunpoder are shown a notification that includes the Airpush library. We believe the notification was intentionally added in order to use the Airpush library as a scapegoat.
Gunpoder samples embed malicious code within popular Nintendo Entertainment System (NES) emulator games, which are based on an open source game framework (http://sourceforge.net/p/nesoid/code/ci/master/tree/). Palo Alto Networks has witnessed a trend of malware authors re-packaging open source Android applications with malicious code. Gonpoder makes use of this technique, which makes it difficult to distinguish malicious code when performing static analysis.
Gunpoder targets users not residing in China. Samples observed support online payments, including PayPal, Skrill, Xsolla and CYPay.
Figure 1. Gunpoder sample pretends to be adware and successfully passes the antivirus scan
Let the Gunpoder Begin
Gunpoder samples pretend to be NES games. After installation, the malware will present a declaring statement when opened for the first time (Fig 2). This statement explicitly tells users that this app is ad-supported and allows Airpush to collect information from the device. We strongly believe that the malware author intentionally added the Airpush library as the scapegoat so that it could inconspicuously attribute its malicious behaviors to the Airpush library.
Figure 2. Gunpoder uses Airpush as the scapegoat
Once launched, the app will actively pop up a dialog to ask users to pay for a “lifelong” license of this game (Fig 3). If the user clicks the “Great! Certainly!” button, a payment dialog will pop up, including PayPal, Skrill, Xsolla (the transaction link is no longer active) and CYPay. Users need to register a new PayPal or Skrill account or log in in to their existing account to pay $0.29 or $0.49. The CYPay supports offline gift voucher redeeming. Additionally, this payment dialog will pop up when users click the “Cheats” option within this app. In fact, the malware author added this malicious payment function into this “Cheats” option, which is free in the original app.
By comparing the code between Gunpoder and the open source project, it was determined that the malware author added the payment functionality, as shown below (Fig 4). The payment dialog is shown in Fig 5.
CyPayUtil.payByAdvance(((Context)this));// add by malware author
}
</syntax highlight java source>
Figure 4. Payment code added by the malware author into the open source framework
Figure 5. Dialog pop up for payment (the charge will be USD 0.29)
Propagation via SMS and Google Short URLs
This Gunpoder family propagates by sending SMS to selected contacts with links to download Gunpoder. Due to the size of SMS messages, the download links are Google short URLs:http://goo.gl/KVhRwC (active in June 2015), http://goo.gl/OpnVHv (not active in June 2015).
The propagation SMS messages will be sent out in two scenarios. The first is when the main activity is paused by the user. This makes it very difficult for most dynamic analysis antivirus engines to trigger the sending behaviors (Fig 6).
The second scenario occurs when the user refuses to make a payment to activate the cheating mode (i.e. clicking the “Next Time” button in Fig 3). In this case, Gunpoder will ask the user to share a “fun game,” which is actually a variant of this malware family (Fig 7).
Interestingly enough, the Gunpoder sample will detect the country of the user. If the user is not located in China, this app will automatically send an SMS message, which contains a variant downloading link, to random selected friends in the background (Fig 8).
MainActivity.java
1
2
3
4
5
6
7
<syntax highlight java source>
publicvoidonPause(){
super.onPause();
MobclickAgent.onPause(((Context)this));
newShareTool(((Activity)this)).share();
}
</syntax highlight java source>
Figure 6. Sending SMS when the main activity is paused
Figure 7. Sharing the malware variants with friends
Figure 8. Send a downloading link of variants to randomly selected contacts
Country-Based Application Promotions
The Gunpoder samples will also pop up advertisements to promote other applications. In the code, we see the malware sample targeting as many as 13 different countries. For each country, the author uses specific URLs for downloading promoted applications. However, these download links are not active at the time of writing this post. From the debug code identified within the same sample, the name “Wang Chunlei” (Chinese) was discovered. This name is quite possibly the name of the malware author (Fig 9).
The Gunpoder malware family was discovered to aggressively push fraudulent advertisements to victims via the real Airpush library (Fig. 11). A fraudulent advertisement is one that attempts to trick a victim into clicking on it using subversive techniques. The fraudulent advertisement page attempts to mimic a Facebook page. It requests that victims finish a number of surveys and asks them to install various applications in order to receive a gift.
The captured Gunpoder logs were found to include information about these logs as well (Fig. 10). The malware collects and uploads very detailed user/device information from the victim. We have removed sensitive information from the URL in Fig 10. The commented out information includes the victim’s device id, device model, current location, etc.
Additionally, Gunpoder will collect information about all installed packages on the victim’s device. It also provides capabilities for executing payloads. The dynamic code for loading and executing the payload after decrypting reside in “com.fcp.a” and “com.fx.a” components.
Impact
Thus far, Palo Alto Networks has observed 49 unique samples of the Gunpoder family. We have found three different groups of variants within this family. By comparing samples of the various Gunpoder variants, we were able to make many observations about the evolution of Gunpoder.
Specifically, variants of group 1 (12 samples) can propagate via SMS and entice users to make a payments. Variants of group 2 (16 samples) can only entice users to make a payment, and variants of group 3 (21 samples) do not contain SMS propagation or entice users to make payments. Group 3 was discovered to be the newest of the Gunpoder malware variants.
Furthermore, the same certificate signed the first and second variants, while a different certificate signed the third variant. While the certificate varies between these groupings of variants, we highly suspect that the same malware author wrote all of these samples. A number of constant variables remain consistent between all three variants, such as the following that was identified in “Constants.java.”
Users will have a large bill, if they are tricked. The fake payment costs users only about $0.49 or $0.29, but the bill caused by sending SMS is much more than this. The total amount of the SMS bill depends on how many contacts reside in users’ devices.
Conclusion
Overall, the Gunpoder malware family contains a number of activities associated with adware. However, as we’ve previously discussed, a number of malicious functionalities exist as well. Examples of this include the ability to collect very sensitive information from victims, propagation via SMS messages, and the ability to execute other payloads.
The inclusion of the Airpush advertisement library causes many antivirus programs to simply label Gunpoder samples as adware, which is often not blocked by default. This allows some of the more malicious activity present in Gunpoder to continue unnoticed.
Protections
Palo Alto Networks released protections for users of WildFire, Threat Prevention and Mobile Security Manager for all currently known Gunpoder variants. Due to Palo Alto Networks unique prevention capabilities across the attack lifecycle, future members of the Gunpoder malware family could also potentially be blocked.
Everyone who has experienced a breach has had to have an “uncomfortable talk” with their employees or customers at some point. Telling people who know and trust your brand that they are at heightened risk is never a fun or easy discussion. I know, as in my past life at the U.S. Department of Homeland Security and serving the National Security Council, I shared in the thankless mission of helping agencies and companies to respond to, and recover from exactly these kinds of breaches.
It’s a glaring reality for businesses and government agencies that, despite upgrades to their IT infrastructure, security hasn’t kept pace. Networks could be protecting millions of customers’ data or enabling global operations, but most often organizations still have struggled with moving beyond legacy architectures and appropriately addressing their risk posture. For example, businesses that have undergone mergers and acquisitions face circumstances where old networks are bolted on to existing architectures, joining legacy systems to modern IT environments often with little thought to the new risks that are introduced. The fallout is that breaches repeatedly continue to take place exposing bank accounts, e-mail correspondence, and personally identifiable information.
The solution from both a government and a business standpoint is to work to simplify and strengthen network architecture, risk management practices, and cybersecurity strategy.
Architecting a network to focus on preventing breaches is the first step. Beyond static perimeter defenses, organizations need to think about disrupting cyberattacks at multiple points along their lifecycles. At Palo Alto Networks, our platform approach looks to safely enable applications and provide heightened visibility into user access and content across the network from the perimeter to the endpoint. This integrated approach allows for multiple opportunities to prevent initial intrusions, as well as stop the damaging release of private data.
The second step is for organizations to simplify and strengthen their risk management practices. Leadership should be fully aware of the business and mission risks cyber threats pose and work to focus appropriate resources toward addressing these risks. In corporations this means that CEOs should take an active role in building a risk management approach to cyber threats. Many governments are also moving important legislation forward. In the U.S., government agencies received two new legislative tools earlier this year that codify DHS as the lead for identifying and addressing cybersecurity risks, backed up by OMBs budgetary and oversight hammer to drive stronger cyber risk management practices across the Federal IT enterprise.
Finally, organizations must build a cybersecurity strategy focused on preventing, rather than simply responding to, breaches. In order to disrupt modern adversaries, organizations have to leverage advanced analytics and automation to clear away the cyber threat noise and focus on addressing the biggest risks first. The Palo Alto Networks Security Platform uses our threat intelligence cloud to enable automated prevention of breaches. Security elements such as ourWildFire service and AutoFocus analytics tool enable automated prevention and advanced threat detection for our private sector and government customers.
As more and more organizations suffer breaches involving customer or employee personal data, we must address these cybersecurity challenges by finding effective ways to simplify our security efforts making them accessible to a wide range of organizations. Whether government agency or pizza parlor, these organizations all hold our personal data and face similar challenges that can be addressed by developing sound network architectures, risk management policies, and cybersecurity strategies. The alternative is a world where we are forced to walk away from the benefits of a digitally connected society. Imagine having that talk with your customers…