PA-7050 Series Named a 2014 Readers’ Choice Award Winner

We’re pleased to announce that the PA-7050 Series was named a winner in the Enterprise Firewall category of the Information Security™ magazine and SearchSecurity.com™ 2014 Readers’ Choice Awards, presented by the editors of the two publications.

As noted in Information Security magazine and on SearchSecurity.com, “The Palo Alto Networks PA-7050 received top scores from Readers’ Choice voters for its ability to identify users via directory integration and for the company’s service and support. The firewall’s ability to block intrusions, attacks and unauthorized network traffic; its logging, monitoring and reporting capabilities –and the overall return on investment –impressed Information Securityreaders.” Read more on why the PA-7050 was 2014 Readers’ Choice Award recipient.

The 2014 Readers’ Choice Award winners were selected based on an extensive, in-depth survey of Information Security magazine and SearchSecurity.com readers that included over 1,700 information security executives and managers, who were asked to assess and rate products deployed within their organizations from a listing of more than 400 products spanning 22 product categories.

Learn more about the PA-7050

[Palo Alto Networks Blog]

Defend Your SCADA Network from Zero Day Threats with the WildFire Appliance

Palo Alto Networks recently announced availability of PAN-OS 6.1, the newest version of our operating system.  As with all our operating system releases, there is an amazing list of new features to help our customers better secure their networks, respond more quickly to incidents and reduce operational overhead.  Given my focus on cybersecurity for Industrial Control Systems, the one feature I am particularly excited about is the capability of the WildFire appliance, the WF-500, to generate threat prevention signatures on premises.

WildFire is of course a service available in our security platform that isolates suspicious payloads (e.g. executables, MS-Office documents) at the network, detonates them in our Threat Intelligence Cloud, then sends a report back to the user about the nature of a payload.  Not only that, if the payload is malicious, the cloud sends threat prevention signatures (anti-virus, malicious URL, malicious DNS) back to the firewall, essentially converting the unknown threat into a known, stoppable threat.

Many of the critical infrastructure and manufacturing asset owners I work with have told me they like the idea of WildFire and the threat intelligence cloud, but faced constraints in sending files out to the public cloud. Many have general privacy concerns, some have regulatory constraints, and on occasion, they cite the unavailability of an internet connection (airgap).

We are excited to announce with the release of PAN-OS 6.1 that we can now address these concerns via the WF-500’s ability to generate on-premise malware signatures in as little as 5 minutes. This update will come in very handy in securing several perimeters and even internal zone traffic within the automation environment — assuming you have proper segmentation! – and here’s how:

  • Corporate-to-SCADA perimeter: Some of the traffic which you may be allowing on a limited basis from the Enterprise IT side may be file-bearing. Use the WF-500 to inspect this for malicious content.
  • Vendor/Partner-to-SCADA: Just because you are using a secure VPN to let your partner or vendor into your SCADA system doesn’t mean the content is secure. Implement a zero-trust model and inspect all traffic.
  • Operator/Engineering to Server: Files may be introduced by removable media at HMIs and Engineering workstations or via mobile laptops connected in the LAN. Use WF-500 to detect and block zero days that originate from within.
  • Inter-plant traffic: Yes other plants are behind the IT-OT firewall and considered trusted, but again, don’t assume anything and be vigilant of malware that may come from other sites within the organization.

Remember: one WF-500 supports multiple next-generation firewalls, essentially transforming each firewall into a sensor for detecting unknown threats in hundreds of file-bearing applications across standard and non-standard ports, with the ability to automatically prevent them as well.  This is a fundamental difference from other detection-only, point solutions which require one or more application-specific sandboxing appliances at each point of inspection in the network, resulting in partial, open-loop security at high costs to you.

WildFire is of course one element of our entire solution.  For more details on our complete security platform which spans network security (Next-Generation Firewall), endpoint (Traps Advanced Endpoint Protection) and the cloud (Threat Intelligence Cloud), please feel free to read our brief whitepaper on protecting critical infrastructure.

[Palo Alto Networks Blog]

Palo Alto Networks News of the Week – November 8

Check out all of the top Palo Alto Networks news from this week.

Have you ever seen love like this?

We recently published a new research paper on WireLurker, a family of malware targeting both Mac OS and iOS systems for the past six months.

Shortly after we released the above research paper, Jaime Blasco from AlienVault Labs notified us about Windows executable file that contains WireLurker’s command and control server address. After analyzing and investigating the sample, it is confirmed that it is an older version of WireLurker. Read the follow on post here.

 

If you love great cybersecurity books we hope you will get involved in the Cybersecurity Canon by writing a review of your favorite and submitting it for consideration. Rick Howard explains how.

 

Tsugunori Sugawara on how PAN-DB will add more protection to your Palo Alto Networks Enterprise Security Platform by protecting your network from advanced attacks and playing a critical role in the Cyber “Kill Chain.”

Ask firewall administrators about their day-to-day challenges and sooner or later they will come around to a challenge that Matt Keil describes as policy chaos. Here, he explores bringing a semblance oforder to this policy chaos.

There are many ways to look at cloud computing and what it means for your business. Overall, cloud governance means discovery, control and safe enablement. In this post from Isabelle Dumont, learn tips on doing your security due diligence on cloud services.

 

 

We’re on the road with VMware and VMUG in the U.S. and Canada to discuss how you can strengthen your data center security without compromising application performance. Find an event near you to learn best practices for implementing advanced security services in a SDDC, to hear customer insights for deploying VMware NSX with micro-segmentation, and to get hands-on experience test-driving an integrated VMware-Palo Alto Networks solution.

 

 

We’re also on the road across North and South America with Citrix and CA for the next few weeks to talk about how enterprises can streamline virtualized data centers, radically simply network services for delivering critical applications and reduce complexity and cost, all without sacrificing performance and security. Join us at an event near you.

 

 

Here are upcoming events around the world that you should know about:

Datacenter Consolidation Seminar Series – Chicago, IL

  • When: November 11, 2014 11:00 AM – 1:00 PM CST
  • Where: Rosemont, IL

Datacenter Consolidation Seminar Series – Nashville, TN

  • When: November 11, 2014 2:30 PM – 5:00 PM CST
  • Where: Nashville, TN

You Can Have It All

  • When: November 11, 2014 11:30 AM – 1:30 PM CST
  • Where: New Orleans, LA

11月12日(水)製品導入・運用支援トレーニング [Japanese]

  • When: November 12, 2014 1:30 PM – 5:00 PM GMT+9:00
  • Where: 千代田区

Datacenter Consolidation Seminar Series – Salt Lake City, UT

  • When: November 12, 2014 11:00 AM – 1:00 PM MST
  • Where: Salt Lake City, UT

Datacenter Consolidation Seminar Series – Santiago, Chile

  • When: November 12, 2014 12:00 PM – 2:00 PM GMT-4:00
  • Where: Las Condes Región Metropolitana

Datacenter Consolidation Seminar Series – Toronto, ON

  • When: November 12, 2014 11:00 AM – 2:00 PM EST
  • Where: Toronto, ON

Palo Alto Networks: Live Demo

  • When: November 12, 2014 9:00 AM – 10:00 AM PST
  • Where: Online

Datacenter Consolidation Seminar Series – Buenos Aires, Argentina

  • When: November 13, 2014 12:00 PM – 3:00 PM GMT-3:00
  • Where: Buenos Aires

Datacenter Consolidation Seminar Series – Los Angeles, CA

  • When: November 13, 2014 11:00 AM – 2:00 PM PST
  • Where: Los Angeles, CA

Datacenter Consolidation Seminar Series – Montreal, QC

  • When: November 13, 2014 11:00 AM – 2:00 PM EST
  • Where: Montreal, QC

Er du forberedt til å håndtere ukjente trussler i ditt nettverk? [Norwegian]

  • When: November 13, 2014 1:00 PM – 1:30 PM CET
  • Where: Online

11月14日(金)製品実感トレーニング [Japanese]

  • When: November 14, 2014 1:30 PM – 5:00 PM GMT+9:00
  • Where: 千代田区

Lunch: Scott Stevens discusses a Zero Trust model for Security

  • When: November 17, 2014 12:30 PM – 2:00 PM GM
  • Where: Brisbane, QLD

Datacenter Consolidation Seminar Series – Washington, DC

  • When: November 18, 2104 11:00 AM – 2:00 PM EST
  • Where: Washington DC

Join Unit 42 and Uncover a New Source of Cyberthreats

  • When: November 18, 2014 8:30 AM – 10:30 AM EST
  • Where: Toronto, ON

Take the Ultimate Test Drive!

  • When: November 18, 2014 8:30 AM – 12:30 PM EST
  • Where: Bohemia, NY

Webinar Santé

  • When: November 18, 2014 10:30 AM – 11:30 AM EET
  • Where: Online

11月19日(水)製品実感トレーニング(大阪) [Japanese]

  • When: November 19, 2014 1:30 PM – 5:00 PM GMT
  • Where: 大阪市北区

Datacenter Consolidation Seminar Series – Lima, Peru

  • When: November 19, 2014 12:00 PM – 3:00 PM EST
  • Where: Lima, Peru

Join Unit 42 and Uncover a New Source of Cyberthreats

  • When: November 19, 2014 8:30 AM – 10:30 AM MST
  • Where: Calgary, AB

Online Demonstration og oplev vores Næste Generations Firewall’s

  • When: November 19, 2014 1:00 PM – 2:00 PM CET
  • Where: Online

Palo Alto Networks: Live Demo

  • When: November 19, 2014 9:00 AM – 10:00 AM PST
  • Where: Online

Palo Alto’s Next-Generation Security

  • When: November 19, 2014 10:00 AM – 3:00 PM EST
  • Where: Wayne PA

Ultimate Test Drive Workshop on NSX

  • When: November 19, 2014 9:00 AM – 12:30 PM
  • Where: Melbourne, VIC

Black Hat Webcast Series – Amazon Web Services Security Basics

  • When: November 20, 2014 11:00 AM – 12:00 PM PST
  • Where: Online

Er du forberedt til å håndtere ukjente trussler i ditt nettverk? [Norweigen]

  • When: November 20, 2014 1:00 PM – 1:30 PM MEZ
  • Where: Online

Join Unit 42 and Uncover a New Source of Cyberthreats

  • When: November 20, 2014 8:30 AM – 10:30 AM PST
  • Where: Vancouver, BC

11月21日(金)製品体感 [Japanese]

  • When: November 21, 2014 1:30 PM – 5:00 PM GMT
  • Where: 千代田区

[Palo Alto Networks Blog]

Kuluoz Trends – October 2014

The Asprox/Kuluoz malware family has a special place in our hearts at Palo Alto Networks. This botnet-related Trojan malware has evolved from its 2007 roots into a simple and yet robust mass e-mail phishing threat that is the origin of a significant percentage of Internet spam today. This post further explores trends for this malware family, based on October 2014 data from ourWildFire platform.

Some Background

The modern Kuluoz is known for the following:

  • High distribution volume through geolocation-associated spam e-mail templates
  • Use of e-mail attachments and Web links that masquerade as document or media files
  • Modular design, promoting extensibility
  • Distinct, default botnet node roles of spam generator for continued botnet propagation, downloader of additional malware and distributor of generalized commercial spam
  • Platform-specific malware delivery based on user agent detection

Themes for Kuluoz propagation spam have ranged across legal notices (e.g., court order),package delivery messages (e.g., FedEx, UPS, DHL), voicemail service notifications (e.g.,WhatsApp), general current events (e.g., 2014 polar vortex), and online deals (e.g., free pizza from Pizza Hut) – to name a few.

October 2014 Analysis

Figure 1 depicts October 2014 WildFire sessions (individual occurrences) that were flagged as Kuluoz, broken out by day.

Figure 1: WildFire-detected Kuluoz sessions, by day, for October 2014

An interesting pattern emerges for significant session count valleys spaced roughly seven days apart, which are followed by major peaks two to five days out. These valleys correspond with weekends, while the peaks occur mid-week. This makes sense in the context of the standard business workweek and the broad swath of enterprises included in Kuluoz targeting.

Figure 2 displays WildFire unique Kuluoz sample counts (based on SHA256 hash) for the same period.

Figure 2: Unique WildFire-detected Kuluoz samples, by day, for October 2014

This second figure matches the general valleys and peaks trend for total sessions detected by WildFire. Note that this figure does not represent new/never-seen-before sample detections, but instead represents all unique Kuluoz samples detected for a given day. Kuluoz employs low-effort but effective methods of altering binaries enough to evade detection by hash alone, which significantly increases unique sample counts when comparing standard binary hashes. Accordingly, the above figure demonstrates the cumulative effect and possible escalation in unique Kuluoz sample generation, a trend previously noted by FireEye in June.

Closer inspection of WildFire session delivery/receipt for Kuluoz reveals the expected leader: e-mail/webmail (Figure 3).

 

Figure 3: WildFire-detected Kuluoz delivery/receipt for October 2014

Most of the remaining sessions were delivered via the Web, which includes cloud and file sharing services. A relatively small number of Kuluoz sessions leveraged File Transfer Protocol (FTP). Finally, WildFire also received a number of Kuluoz samples through user submission.

Over 98% of WildFire-detected Kuluoz filenames for October 2014 employed one of the following six themes, ordered by prevalence:

  • Notice to Appear in Court
  • Delta Airline Ticketing
  • Purchase Order / Invoice / Shipping
  • Voicemail Message
  • Starbucks eGift
  • Pizza Hut Coupon

Conclusion

Kuluoz continues to thrive, employing various social engineering pressure tactics to successfully propagate and serve as a bridge for other malware families.

Thorough mitigation of this threat includes several layers:

  • User awareness: Awareness and training for users is a good idea to reduce the impact of any type of e-mail phishing. A number of Kuluoz variants require extra steps to be performed by a user (e.g., unzipping of a ZIP archive and then running a malicious binary). Encourage users to be wary of unexpected/unsolicited e-mails, especially those that employ any sort of pressure tactic and/or leverage the themes cited above.
  • Protocol monitoring and control: Visibility into the protocols used by Kuluoz for delivery and Command and Control (HTTP, SMTP, IMAP, FTP) with structured and clearly defined response actions (most of which can and should be automated) prevent or reduce associated impacts. Palo Alto Networks Next Generation Firewall solutions offer this level of granular application monitoring and control.
  • Automated analysis: Automation of static and dynamic analysis for unknown samples addresses the natural gap between the development of a variant for a threat and its coverage through signature-based technology. Anti-virus and other security control related signatures fall short. Solutions such as Palo Alto Networks WildFire platform allow for enterprises to identify new and emerging threats that remain unknown to other security controls in the environment.
  • Intelligence fusion: Leveraging actionable intelligence is a cornerstone of Computer Network Defense (CND) operations. Threats such as Kuluoz rely heavily on embedded initial Command and Control (C2) communications to fully realize the potential of its role(s) within the botnet. Up-to-date feeds on malicious domains, IPs, file signatures and hashes, as well as integration of intelligence gleaned from automated solutions in the environment, enable robust security solutions that empower network defenders.

[Palo Alto Networks Blog]

WireLurker for Windows

Summary

Yesterday we published a whitepaper introducing WireLurker, the first malware attacking both non-jailbroken and jailbroken iOS devices from a Mac OS X system. Shortly after we released the paper, Jaime Blasco from AlienVault Labs notified us that he’d found a Windows executable file that contains WireLurker’s command and control server address. We analyzed and investigated the sample and have confirmed that it is an older version of WireLurker.

This variant is being distributed by a different Chinese source that is hosting 180 Windows executables and 67 Mac OS X applications, each of which contains a version of the WireLurker Trojan. The Windows variant opens a new vector for iOS users to be infected with WireLurker, but appears to have been less successful than its Mac OS X descendent.

Samples of this older variant display a user interface and are advertised as an installer for specific pirated iOS apps. Between March 13 and today these programs have been downloaded 65,213 times, with 97.7% of the downloads being the Windows version. Like the latest WireLurker, this variant tries to infect jail-broken iOS devices with the WireLurker iOS malware.

This version of the malware also installs the sfbase.dylib tweak to the iOS file system, which is an earlier version of the malicious iOS binary file mentioned in our earlier report. These samples also indicate that the creator of WireLurker may have a direct relationship with the Maiyadi App Store.

Palo Alto Networks has released protections for all versions of WireLuker in our Antivirus, WildFire, IPS, and URL Filtering products. We’ve updated our detection code in Github to detect the older Mac OS versions of the malware and plan to release a tool to detect the Windows variant.

Early Versions of WireLurker for Windows and OS X

A Different Source

Previously we knew the WireLurker was distributed through the Maiyadi App Store. However, the newly revealed samples were directly uploaded to Baidu YunPan (a public cloud storage service of Baidu) by user “ekangwen206” (Figure 1). When we investigated this source we found the user had uploaded 247 samples in total, of which 180 are Windows software and the other 67 are OS X applications. All OS X samples were uploaded on March 12 and all Windows samples on March 13, over a month before the Mayaidi App store infections.

We downloaded and confirmed that all of these files belong to a new variant of WireLurker and should be classified as Trojan malware.

Figure 1: Samples of WireLurker list in the Baidu cloud storage system

These samples are listed as “green” (e.g. good or clean) IPA installers for specific pirated iOS apps. Some of the named iOS apps are extremely popular, while some of the others are pre-installed iOS system apps, including the following:

  • Facebook
  • WhatsApp Messenger
  • Twitter
  • Instagram
  • Minecraft
  • Flappy Bird
  • Bible
  • GarageBand
  • Calculator
  • Keynote
  • iPhoto
  • Find My iPhone
  • iMovie
  • iBooks

Baidu YunPan provides statistics of views and downloads for every single file. Through this feature, we found that in the past eight months, the 247 samples were downloaded a total of 65,213 times. Also according to their statistics, 97.7% of the downloads were Windows samples, which is consistent with the market share of Windows in China.

File Information and Structures

Based on the file information in PE structure, all of the Windows samples of  were created on March 13 on a Windows XP computer. Each Windows sample contains a malicious PE executable file, six normal DLL files and a manual TXT file.

Each PE executable file has two extra IPA files (iOS app’s installation bundle file) appended to them, shown in Figure 2. The first IPA file, named “apps.ipa”, is a malicious iOS application; the second one, named “third.ipa”, is the pirated iOS app advertised by the sample. These two IPA files will be dropped to “C:\Documents and Settings\<USER>\Local Settings\Temp\” directory after the installer is executed.

Figure 2: Two IPA files were appended to the PE executable file

OS X samples of this variant have a fixed bundle executable name “appinstaller”. The IPA files are packed in the Resources directory in the OS X applications: one is named “infoplistab” for “apps.ipa”; the other is “third.ipa”.

User Interaction

After users download the samples and run them on Windows or OS X, a GUI appears as Figure 3 and Figure 4. If iTunes isn’t installed on the Windows system, the malware guides users to an official site of Apple China to download and install it.

Figure 3: GUI of a Windows sample

Figure 4: GUI of a OS X sample

If iTunes is installed the user interface shows a message of waiting for iOS device connection. After the user connects their device to the computer, the device’s name will appear in the GUI and a “click to install” button becomes available.

Install iOS application and iOS malware

If the user runs the samples and clicks the installation button the pirated iOS application shown in the interface will be installed on the device, but only if the device is jailbroken. At the same time the program will secretly install the apps.ipa file.

During our analysis, we connected an iPhone 5s running iOS 7.1 (jailbroken) and a 3rd gen iPad running iOS 6 (jailbroken) to infected Windows 7 and Windows XP systems. When using the iPhone 5s/iOS 7.1, the installer crashed after clicking the button; with the iPad, the interface shows “installation is successful”, but we did not find any new icon in the iPad display.  We believe this failure was caused by poor coding quality and incompatibility between the malware and the iOS device, but the malware code does attempt the installation.

Pirated iOS Apps

The pirated iOS apps that the malware attempts to install are cracked versions of legitimate iOS apps. Their code signatures and DRM protection were removed before the IPA files were appended to EXE files or packed into OS X applications.

For example, in Figure 5, we can see the pirated WhatsApp has cryptid value 0, which means DRM encryption by Apple was removed by the attacker, something that can be easily achieved through many publicly available automatic hacker tools.

Figure 5: Pirated iOS apps haven’t DRM protection

The iOS Malware

The iOS malware these samples attempt to install into iOS devices contains both sfbase.dylib and sfbase.plist files. In our previous report on WireLurker, we mentioned that sfbase.dylib is a MobileSubstrate tweak that steals the user’s contacts information and other private data and sends it to a C2 server.

Figure 6: The iOS malware contains code for ARM64

The main executable of this malware is named “apps”. It’s a Mach-O universal binary file that contains binary code for three different architectures and CPU types:

  • 32-bit ARMv7
  • 32-bit ARMv7s
  • 64-bit ARM64

As far as we know, this is the first iOS malware that attacks the ARM64 architecture.

The main functionality of this malware is to copy sfbase.dylib and sfbase.plist in its Resources directory to specific locations to make them perform as a MobileSubstrate tweak, shown in Figure 7. Additionally, the malware will communicate with the C2 server “www.comeinbaby.com”, the same server used by the version of WireLurker we revealed yesterday.

Figure 7: The iOS malware copies sfbase.dylib to a specific location

The dropped sfbase.dylib has nearly identical code and functionalities as the sample we detailed in our previous report. However, the earlier version was listed as 4.0.0, 4.0.1 or 4.0.2. This sfbase.dylib is version 2.0.0 as shown by its [mydUtils getCurrentVersion] method.

Another difference in this older version is that it uses the following URL when checking for updated code (Figure 8):

Figure 8: Earlier version of sfbase.dylib check for update from Maiyadi

Note that, this domain name is that of the Maiyadi App Store which spread later versions of WireLurker. Later versions of WireLurker used the domain www[.]comeinbaby.com but accessed the exact same GET request path.

Similarly, when uploading the user’s contacts information and other private data, this version of sfbase.dylib uses this URL:

Clues link Attacker to Maiyadi

Based on our analysis of this earlier version of sfbase.dylib, we suspect that Maiyadi has a close relationship with the creator of WireLurker. Beyond the link to the command and control server we’ve found additional clues.

First, all OS X samples in this variant have a bundle identifier named “com.maiyadi.installer”, as well as a copyright information that contains  a reference to Maiyadi (Figure 9).

Figure 9: Copyright information in the OS X malware

Second, in the malicious iOS app, we found a certificate that belongs to “li fei” which was issued by Apple on March 6th, 2014 (Figure 10).

Additionally, the name “li fei” exists in all Windows malware samples and sfbase.dylib in the following strings:

  • E:\lifei\libimobiledevice-win32-master_last\Release\appinstaller.pdb
  • /Users/lifei/Library/Developer/Xcode/DerivedData/SDMMobileDevice-dbskckexyqfxypdzrwfwereecnot/Build/Products/Debug-iphoneos/sfbase.app/sfbase

These two strings are automatically generated by Visual Studio on Windows and Xcode on OS X for debugging when the developer built appinstaller and sfbase.dylib.

Figure 10: Attacker’s certificate in the iOS malware

Solutions

Palo Alto Networks has updated our signatures for Antivirus, WildFire, IPS, and URL Filtering products to protect our customers by blocking associated malicious URLs and traffic patterns of all known versions of WireLurker.

We have also open sourced a project on Github to help everyone in detecting WireLurker on their desktop computers. That project is available here:

https://github.com/PaloAltoNetworks-BD/WireLurkerDetector

We’ve already updated our OS X script to cover this newly discovered variant and we’re planning to release another tool to help Windows users scan their computers for WireLurker.

Updates on the Threat from WireLurker

After we published the WireLurker report and related detection tool, some OS X users in China discovered that their Mac computers were infected by WireLurker and posted screenshots on Weibo (Chinese social network similar to Twitter), shown in Figure 11. One of the users contacted us and provided all detected samples on his Mac, which we identified as the newest known version of WireLurker (version C).

Figure 11: A Chinese victim reporting their Mac was infected by the WireLurker

As we were writing this blog, Apple also announced that they’ve “blocked the identified apps to prevent them from launching” and we noted that the command and control domain, www[.]comeinbaby.com no longer resolves to the command and control server IP.

Nick Arnott mentioned to us on Twitter that in iOS 8, the system no longer shows distribution profiles in the settings menu; users may need to use Xcode or the iPhone Configuration Utility to check or remove these abused enterprise distribution profiles.

Acknowledgements

Jaime Blasco from AlienVault first found a Windows variant of WireLurker and sent to us. Thank you Jaime!

We would like to thank Laura Hartmann, Zhi Xu, Wei Xu, Yanxin Zhang and Suli Xu at Palo Alto Networks for quickly processing this new variant and updating our products. It’s their work that ensures our products defend our customers from the latest threats.

We would also like to thank all people who have shared comments on the report and detection code or shared more information with us through Twitter, Github and email.

[Palo Alto Networks Blog]

English
Exit mobile version