Wednesday, March 6, 2019

Its that time again

Yup.  Like it says, here we go.

PirateMatryoshka

Torrent site infecting people with malware

Makes for great headlines.  Here's the actual report on securelist for deeper reading.

Torrents make for easy targets, since the people using the are stereotyped to be doing so for less than above board reasons.  Any judgements aside, caution needs to be exercised regardless of why you are torrenting a file.

For downloaders:


  • Be cautious.  Look at the number of seeders and peers.  It's easy to abuse and inflate.  Use https://iknowwhatyoudownload.com/en/api/ and sign up for the API.  Look for the amount of activity there and double check it against what you are seeing.
  • Look up the tracker.  If you can't easily find it via your favorite search engine, reconsider downloading from it.
  • Look for comments.  See if they sound human and make sense.  You know what to do if they don't.
  • Any kind of instructions are a dead give away to a likely bad file.  If it asks for you to log in, provide data, authenticate, etc -- you are about to be phished, infected or generally done over in a very painful way.
  • File types matter.  Use caution with an archive (rar, zip, 7zip, etc.) and completely avoid executable files if possible.
  • Download to a safe location.  If you can, use a virtual machine.


For Researchers:

Head to here.  Sign up for an API key.  You can query up to a 1000 times for free.  You can pivot off a lot of interesting elements here.  My favorite one is the infohash, which provides a JSON of the following fields back.


Feel free to dig to your heart's content.  Here's the full breakdown of what's available via the API.

You can also do it yourself with a bit of elbow grease:  http://labs.boramalper.org/magnetico/

Friday, March 1, 2019

Less malware and just malware related fun

I read this article on March Malware Madness.  The points in the article are articulated well enough that its worth the read and time on the points.

The marketing spin is only lightly applied so you won't be drowning in exhorts that their product does everything and anything security but you won't miss them either.

While the four scenarios and points were well done, they miss the number one hard thing that really is the at the root of the issue (root cause analysis, anyone?) that's being addressed:  people.



Like this shamelessly borrowed unknown attributed image I found says, its really the people who are the root cause.

The right training, review of processes and company cultural changes that support security would go as far or, dare I say, farther to mitigate and control the problem.





Saturday, February 23, 2019

Separ


Password stealer virus with some interesting trends.

Community Names:
  Separ
Tactics:

  • Living off the Land

Attack Vectors:

  • Primarily phishing emails with fake adobe pdf/installer infected attachments
  • Some entry points are by accident when people stumble across the infected sites


References:


  • https://hackercombat.com/whats-new-with-separ-malware-family-in-2019/
  • https://www.deepinstinct.com/2019/02/19/a-new-wave-of-the-separ-info-stealer-is-infecting-organizations-through-living-off-the-land-attack-methods/
  • https://threatpost.com/separ-malware-credentials-phishing/142009/
  • https://blog.talosintelligence.com/2018/06/threat-roundup-0622-0629.html

Friday, February 22, 2019

Shlayer

Shlayer is a macOS trojan first discovered by researchers at Intego in February 2018. It was first distributed masquerading as an Adobe Flash Player installer. This new variant is being distributed in a similar fashion, this time as an Adobe Flash update via browser pop-ups on hijacked or spoofed websites. In addition, malvertising has also been observed as another distribution method in this new campaign. The new campaign was discovered by Carbon Black’s Threat Analysis Unit (TAU). It was targeting all macOS released up to 10.14.3 Mojave, arriving as files signed by a legitimate Apple developer ID


Wednesday, February 20, 2019

Speak Up

Community Synonyms
  • Named after its C2.
  • Likely discovered under different names (TBD)

Detection Characteristics & Behavior
  • The initial infection vector is targeting the recently reported vulnerability in ThinkPHP and uses command injection techniques for uploading a PHP shell that serves and executes a Perl backdoor.

Attribution links
  • Check Point Researchers were able to correlate SpeakUp’s author with malware developer under the name of Zettabit.



Malware References
  • https://research.checkpoint.com/speakup-a-new-undetected-backdoor-linux-trojan/

Tuesday, February 19, 2019

GoScanSSH

GoScanSSH

Community Synonyms
  • None noted at this time.
YARA
  • https://github.com/raw-data/signatures/blob/master/yara/trojan_linux_GoScanSSH.yar
Possible Code
  • https://github.com/ofalk/scanssh

Context of use
  • https://community.ubnt.com/t5/UniFi-Routing-Switching/USG-Pro-High-CPU/td-p/2245371
  • https://searchsecurity.techtarget.com/answer/GoScanSSH-How-does-this-malware-work-and-differ-from-others

Malware References

  • https://threatpost.com/goscanssh-malware-targets-ssh-servers-but-avoids-military-and-gov-systems/130812/
  • https://blog.talosintelligence.com/2018/03/goscanssh-analysis.html
  • https://www.ssh.com/attack/GoScanSSH
  • https://exchange.xforce.ibmcloud.com/collection/GoScanSSH-Malware-078ff9e71f01695186d4a7d10abc1a81/reports
  • https://www.birger.technology/press/emerging-threat-malware-goscanssh-targets-ssh-devices