Analysis: CryptoWall 3.0, Dyre and I2P

For a moment, put yourself in the shoes of a cyber criminal. You’ve collected an array of tools (malware), built up your infrastructure (command and control (C2) servers) and you have a process to make money off your hard work. You wake up on Monday morning and the domains your carefully built malware uses for command and control are shut down. Some security researcher has taken control of them, completely halting your operation. This would certainly be good news to anyone reading this blog, but for the criminal it’s a big setback and source of frustration. These kinds of takedowns are the impetus for some of the most impressive developments in malware technology over the last decade.

Takedown-Resistant Command and Control

Once attackers have infected a PC through some exploit or social engineering, one of their major challenges is keeping control of that system. Antivirus programs running on the PC are trying eradicate the threat, the command and control domains and IPs are being added to blacklists and blocked by networks around the world. Many malware authors have taken to building complex mechanisms to ensure that their malware is resistant to these kind of blocks and takedowns. Some of the more innovative mechanisms include:

  • Peer-to-peer (P2P) Networks: Rather than relying on a single (or small) number of failure ports for command and control, P2P bots communicate with other infected systems that can relay commands from the attacker. These systems aren’t perfect though, as Operation b49proved in the takedown of Waldac.
  • Domain Generation Algorithms (DGAs): Why use one domain for command and control when you could use 100, or 1,000, or more? DGAs work by algorithmically generating possible C2 domains that change over time. The attacker often only needs to register one of these domains to ensure control of the network. Conficker, one of the most well-known DGA-based botnets generated 50,000 possible domains each day in it’s final variant.

These mechanisms are often only used when the primary (and simpler) C2 mechanism has been shut down, but their use makes shutting down a botnet much more challenging.

Abusing I2P

Last year we highlighted two malware families on this blog: CryptoWall 2.0 and Dyreza/Dyre. CryptoWall is one of multiple ransomware families that generated income for the attacker by encrypting files on the infected PC with a private key that is in the control of the attacker. The attacker then charges a ransom (normally around $500) to give up the key that will unlock the files. In October, CryptoWall 2.0 began using the Tor anonymity network to serve web pages to infected users who wanted their encrypted files back. In this case a legitimate service (Tor) was being abused by CryptoWall so it could avoid having its C2 servers shut down. Presently another anonymity network, I2P is being abused by both the latest version of CryptoWall (3.0)and the Dyre banking Trojan.

While I2P is far less popular than Tor, it provides similar functionality to the user. I2P is an overlay network on top of the Internet that creates encrypted links between nodes that are running the I2P software. I2P users can access specific I2P services that are only accessible on I2P, or access Internet resources without exposing their IP address.

In the case of CryptoWall 3.0, the malware is attempting to access multiple .i2p resources only accessible through I2P, also known as “eepSites.”

  • proxy1-1-1.i2p
  • proxy2-2-2.i2p
  • proxy3-3-3.i2p
  • proxy4-4-4.i2p
  • proxy5-5-5.i2p

The CryptoWall 3.0 uses I2P in the same way CryptoWall 2.0 used Tor, to give the victim access to a decrypting service to get their files back.

The Dyre banking Trojan has multiple C2 mechanisms, including encrypted HTTPS requests to a list of hard-coded IP addresses, a DGA generating 1,000 new domains each day as well as an I2P based plugin. These many C2 mechanisms make Dyre much more difficult to fully take down than a simple single (or small group) of C2s. the following IP address are known Dyre C2 servers.

  • 228.17.152
  • 228.17.155
  • 228.17.158
  • 78.103.85
  • 114.0.58
  • 203.50.17
  • 203.50.69
  • 153.35.133
  • 183.172.196
  • 56.214.130
  • 56.214.154
  • 239.209.196
  • 172.179.9
  • 172.181.164
  • 172.184.75
  • 23.8.68
  • 59.2.42
  • 248.224.75
  • 25.134.53
  • 25.138.12
  • 25.145.179
  • 190.139.178
  • 23.196.90
  • 23.61.172

It’s not possible to list all of the domains generated by the DGA, which is the main advantage of this mechanism.

To protect your network from the I2P communication used by both Dyre and CryptoWall 3.0, the easiest route is simply to identify I2P traffic and block it completely. While there are certainly many legitimate reasons to use an anonymity network, many organizations should be weary of I2P (or Tor) traffic transiting their network. Palo Alto Networks App-ID technology can identify I2P traffic as well 51 other tunneling applications.

[Palo Alto Networks Blog]

How To Protect Yourself From the Latest CTB-Locker Campaign

CTB-Locker is a well-known ransomware Trojan used by crimeware groups to encrypt files on the victim’s endpoints and demand ransom payment to decrypt the files back to their original state.  Earlier this week we detailed a new CTB-Locker campaign and why legacy security products won’t protect enterprise networks.

In this blog post we will detail how to protect yourself from CTB-Locker, even if you aren’t protected by Palo Alto Networks next-generation enterprise security.

Since our first blog post on the campaign, here are some updates:

  • We discovered another campaign that started on January 21, and you can see a few paragraphs below the malicious sites used.
  • We can see that during four campaigns over at least three months, attackers kept the IP 213.186.33.4 and 213.186.33.19 in three out of four campaigns. The other servers appear to have been used only for single campaigns.
  • Six of the 20 malicious sites we’ve identified are still live as of this posting, and this is the one of them:

 

There are two possible scenarios for sites like this:

  1. The attackers have gained unauthorized access to those servers or specific websites and planted C&C inside a legitimate website.
  2. The attackers bought this website and have added what appears to be “legit” content to disguise its real purpose.

User Awareness

Here are some things to watch out for:

  • The below icon is used by the attacker against at least two of our protected customers. (Of course, it can be easily replaced by the attacker.)

  • Suspicious file extension (SCR) is almost always malicious (especially if you received it from unknown sender).

New IOC

  • Additional  Mutex 93031785
  • Full server list – you can block traffic to this sites on port 443:

  • The latest campaign is still going on – we have just discovered about 70 new hashes: 
please see attached .csv file.
  • One attack  from the newest campaign called “industriestr_3-7_49832_freren.scr”  (using joefel.com site) is unknown to VirusTotal. Sha256:  614f3d7ef084f12e9034f3723a8016783ced90240c0425fc9fc2324e7d1b5d2e

Conclusion

Earlier this week we identified new CTB-Locker campaigns. Palo Alto Networks Enterprise Security Platform protects from CTB-Locker in a way legacy security solutions can’t.

The above data should help in identifying and understanding CTB-Locker a bit better, but these are temporary solutions. Solving this endless cat-and-mouse game means upgrading to next-generation security. Learn more about Palo Alto Networks Enterprise Security Platform here.

[Palo Alto Networks Blog]

Newest CTB-Locker Campaign Bypasses Legacy Security Products

Introduction

CTB-Locker is a well-known ransomware Trojan used by crimeware groups to encrypt files on the victim’s endpoints and demand ransom payment to decrypt the files back to their original state, but most antiviruses detect it by mistake as CryptoLocker (only one vendor correctly detects it as CTB-Locker). The attack vector is very basic and repeats itself: It begins with a spear phishing email sent with SCR attachments (double zipped). Once executed by the user the first stage malware downloads and executes the ransomware from a fixed hardcoded server list.

The Origins

The first known campaign was launched by Crimeware on November 2014. The first stage downloaded the ransomware from these sites:

  • pubbliemme.com (5.134.122.150)
  • agatecom.fr (213.186.33.19)
  • n23.fr (213.186.33.4)
  • baselineproduction.fr (213.186.33.4)

The Attack: A Legacy Nightmare

A very serious campaign was launched between January 19, 2015 and January 20, 2015, and 
Palo Alto Networks Enterprise Security Platform has discovered more than 1000 unique attacks since. The attacker used a polymorphic malware builder to generate malware with a unique hash for each victim, preventing signature-based solutions from detecting the new attacks before it was too late for the victim. This tactic is a nightmare for legacy security products that are based on legacy techniques such as bytes signatures, since they can only detect attacks after the damage is done instead of preventing it as a true preventive solution should. 
Palo Alto Networks Enterprise Security Platform offers multilayer protection to prevent this attack along with other attacks without the need for prior knowledge of the specific attack.

Some IOCs and statistics

  • breteau-photographe.com (213.186.33.150)
  • voigt-its.de (188.93.8.7)
  • maisondessources.com (213.186.33.19)
  • jbmsystem.fr (213.186.33.3)
  • pleiade.asso.fr (213.186.33.19)
  • scolapedia.org (213.186.33.19)

We can see here that server hostnames were changed but they didn’t change the server IP address – see the attached file with results for files from last week’s campaign fromVirusTotal. Most legacy security programs could not detect this malware at the time it was posted. If you re-test these hashes again from last week you can see an average of 49/57 engines that detect last week’s threat – but that’s too little, too late for anyone who already lost data.

The new (currently ongoing) campaign

This campaign started earlier today, and the malware uses the same techniques and even the same IOCs:

  • same mutex name: wuqntwklyxwhac
  • same job name: cderkbm.job

And only added two new hostnames:

  • joefel.com (64.71.33.177)
  • m-a-metare.fr (213.186.33.4) – same IP as before.

By now you shouldn’t be surprised that one of them is on the same known malicious IP address. We found 147 new unique pieces of malware today alone, two of them fully undetectable by the legacy security solutions in VirusTotal and most of them barely detected by one vendor (few have 4/57 detection rate).

See below:

So basically you have two choices:

  1. Update hashes every week and pray … (see hash list section, we’re happy to help those still trapped using legacy solutions)
  2. Implement next generation security products that can actually prevent this from happening.

IOCs for the latest campaign

The most surprising fact about this campaign is that almost all the IOCs haven’t been changed:

  • Same mutex name: wuqntwklyxwhac
  • Same job name: cderkbm.job .
  • New IOC: additional mutex name – 87281673

For those still using legacy solutions we’ve attached two lists of SHA256 hashes in a text file format for reference. One list shows the new campaign, which continues to progress. The other list is of last week’s campaign by the same attackers (exhaustive or close to it).

Conclusion

Palo Alto Networks Enterprise Security Platform would have stopped this ransomware attack campaign thanks to the platform’s unique integration between the network, endpoint and the cloud to maximize security. Attacks aren’t getting any less sophisticated, so it is time to leave legacy security solutions behind and upgrade to real, prevention-based security.

[Palo Alto Networks Blog]

Standard Web Security Won’t Keep the Internet of Things Safe

The “Internet of Things,” or “IoT” is a fascinating field of technology representing growth of interconnected devices that can be controlled and managed remotely through mobile devices or many other means.

The Internet of Things spans all areas of life and work, especially if we consider:

  • Smart homes with refrigerators ordering groceries, remote controlled HVAC equipment, or smart lighting
  • Connected industries and cities with remote meters, automatic analytics, or robotics.
  • Wearables such as smart watches, fitness bands or smart glasses
  • Connected cars with automatic driving technology, remote diagnostics, or fleet management.

…and much more.

From a business perspective, the IoT offers incremental revenue opportunities as well as productivity and cost savings to companies across the globe. According to analyst firm IDC, the number of IoT devices will grow from approximately 6 billion in this decade to 28 billion in 2020 — a staggering number. The market for wearable smart devices alone is expected to increase at an average rate of 60% per year to $20 billion in 2017.

What is the common characteristic of all of these devices? Connectivity to the Internet through applications. And with this connectivity comes increased exposure to cyber threats. Think of it as today’s mobility market on steroids.

While it will become increasingly important (and common) for most companies to enable Internet-connected devices, a key goal for IT and security departments will remain the safe enablement of the applications that power those devices.  Neither Web nor email security will be able to appropriately protect against future attacks from cybercriminals targeting your organization through the IoT. Many of these applications will most likely utilize more than Web channels to access data and can easily circumvent web security solutions by utilizing uncommon ports.

Now is the time for companies to start thinking about security strategies against tomorrow’s cyber attacks through the Internet of Things. No one has all the answers to the security-related questions posed by the IoT in the coming years, but it helps to ask, at the very least, the following 5 questions to prepare for the onslaught of Internet enabled devices facing your company in the near future:

  1. What IoT devices are likely to be used in your organization in the next decade?
  2. What types of data will these devices access?
  3. What types of devices will your employees own or utilize?
  4. How do these devices interact with your corporate network?
  5. How do you currently ensure safe application enablement across all ports?

The answers to these questions will have a significant impact on your organization’s security strategy in the next few years. The best you currently can do to prepare for the fast approaching army of networked devices is to deploy the best possible application control with a solution monitoring all ports in and out of your network. Palo Alto Networks Enterprise Security Platform not only protects companies against applications utilizing a few common ports, but also offers complete visibility into all enterprise network traffic. Learn more about our approach here.

[Palo Alto Networks Blog]

Unpatched Flash Vulnerability CVE-2015-0311 Blocked by Palo Alto Networks Traps

On January 22 Adobe confirmed the existence of a Zero Day affecting Adobe Flash Player 16.0.0.287 and assigned CVE-2015-0311 to it. This is the classic zero day scenario of exploitation in the wild before any vendor patch was available and in this blog post we will explain how the uniqueness of Palo Alto Networks Traps blocks this vulnerability.

Let’s start with a brief background on CVE-2015-0311 security implications.  Successful exploitation could result in an attacker compromising data security, potentially allowing access to confidential data, or could compromise processing resources in a user’s computer. All versions of Internet Explorer or Firefox, with any version of Windows with Flash up to 16.0.0.287 (included) installed and enabled, are exposed.

Following the disclosure, several security companies reported encounters with attacks utilizing this zero day, as well as a considerable surge in Angler EK activity, mainly in the United States.

Zero days such as CVE-2015-0311 illustrate why signature-based solutions are a dead-end when facing the current advanced threat landscape. Prior knowledge is futile when encountering an attack that is, by definition, unknown. Reliance on vendor patching is also insufficient both from security and operational perspectives – we all know large enterprises do not easily pause company-wide IT activity in favor of mass updates.

Traps Advanced Endpoint Protection is designed to proactively block attacks targeting endpoints, including unknown zero-day exploits. Traps automatically detects and blocks the core set of techniques that every attacker must link together in order to accomplish exploitation. Because of the chain-like nature of an exploit, preventing just one technique in that chain is all that is needed in order to block the entire attack even before a payload is dropped.

The exploitation of CVE-2015-0311 is no different than other exploitations in the essential phases it needs do go through. Traps blocks it.

To further illustrate how, let’s reflect on a common exploitation pattern.  First, there are preparation acts intended to expand the victim machine’s memory attack surface. What usually follows next is an attempt to actually seize a memory portion, and circumvent standard protection means. Upon accomplishing these stages, the exploit still needs to access certain OS functions to gain the required resources for malicious activity. Once all these steps are successful the attacker can remotely run its code on the victim’s machine.

There are several techniques attackers deploy to perform each one of these stages. Obstructing any of these stages terminates the exploitation. Posing obstructions to each and every one of the core techniques creates a powerful multilayered defense which proactively prevents any exploitation attempt from maturing into an ongoing attack.

Moreover, such defense will succeed, regardless of the utilized CVE and regardless of specific exploit prior knowledge since it relies on obstructing the core techniques all exploits utilize.

Applying this defense paradigm to CVE-2015-0311 reveals that despite it being a zero day, and supposedly an unknown attack vector, it is blocked by Palo Alto Networks Traps. Traps prevents the exploit from writing to memory and from accessing OS functions. Each of these is sufficient for successful prevention. Even if the attack is a zero day and not a known exploit, it poses no additional challenge to Traps.

Traps users are exempt from emergency patching and from the concern that an unknown attacker is crawling undiscovered in their endpoints. Traps users were actually protected from CVE-2015-0311 way before it has even existed.

Learn more about Advanced Endpoint Protection here.

[Palo Alto Networks Blog]

English
Exit mobile version