Showing posts with label learning. Show all posts
Showing posts with label learning. Show all posts

Saturday, October 19, 2013

You're Owned and Just Don't Know It. The Malware Obfuscation attack.

Note
NO company listed on this page offers a "Magic Bullet Solution or Tool.  Just wanted to clarify that   FYI.  Some remediation and solution providers are listed at the bottom.

As far as solution providers and tools:  Everyones environment is different, and each requires its own set of tools based on budget, corporate culture, and topology. 


Onward,

  I'm going to ask you a question that I don’t want you to answer.  Just to take a moment and think about it.  Do you think your network is already compromised, and you just haven’t found out about it yet?
That thought probably keeps you up at night, or it should.

“The bad guys” aka The Adversary 
What do they want? This all depends on the threat actor, some just want to see the world burn, what do the rest want?
Many are after Intellectual Property, financial information, destroying company reputation, etc.
Financials
Customer reputation
Money
Contacts
Destruction

Often it’s just a global crimeware kit, and the author discovered he had much more than a user with a bank account, and sells you out to the highest bidder.

The Magic Bullet Solution: 
Organizations from various sectors are spending vast amounts of money on more, and more advanced threats tools.
Managers, CISOs, and CIOs are speaking with vendors or reading articles advertising various tools, which may or may not fit within your companies budget, and the vendors are selling these tools as a "silver bullet solution."
The reality is most organizations already have an arsenal of tools, and not enough staff to review the data that's already being collected, and attempting to monitor their production environment.  These new tools only add more information the analysts cannot ingest, let alone form a picture of what's actually occurring on the network.

The adversary has the same or similar tools, and knows exactly what tools your organization uses, and they know how you use them, against you, and I'll tell you why.  For the single-purpose of staying one-step ahead of these tools, and continuing to perfect their obfuscation techniques.

The Con’s Recon: 
How does an adversary gain information about an organization?
This information is learned using what is called social profiling; this can be accomplished on sites similar to, LinkedIn, Facebook, Twitter, and Google. With the use of these sites an adversary has the ability to track your organization, and create an organizational chart, down to who reports to whom, and which manger reports to which director, and which director reports to which VP, and so forth. This includes phone numbers, email addresses, personal blogs, and through social engineering can even obtain information about where your children go to school, what your personal schedule is, and what packages you're expecting in the mail.
People like to talk about themselves, and they like to blog, tweet, and post on pictures on Facebook showing what they’re doing.  This also can leave geo location information in pictures.  Without proper privacy settings on any of these platforms this information is practically public to the entire world!

The tools of the Trade:
Cree-py
Maltego 
The Harvester
http://checkusernames.com/ Check Usernames - Useful for checking the existence of a given username across 160 Social Networks
Human Intelligence (HUMINT) Methodology always involves direct interaction - whether physical, or verbal.
Gathering is usually done under an assumed identity (remember pretexting?).
Key Employees
Partners/Suppliers
IMINT can also refer to satellite intelligence, (cross over between IMINT and OSINT if it extends to Google Earth and its equivalents).
Covert Gathering - Corporate
On-Location Gathering
Physical security inspections
Wireless scanning / RF frequency scanning
Employee behavior training inspection
Accessible/adjacent facilities (shared spaces)
Dumpster diving
Types of equipment in use
Offsite Gathering
Data center locations
Network provisioning/provider
Foundstone has a tool, named SiteDigger, which allows us to search a domain using specially strings from both the Google Hacking Database (GHDB) and Foundstone Database (FSDB).

How would you enumerate the targets infrastructure without touching it?

Maltego is a program that can be used to determine relationships and real world links between:
People
Groups (Social Networks)
Companies
Organizations
Web Sites
Domains



So again what information do I want with these tools???
Network blocks, and owned ASNs
Email adresses
External infrastructure profile
Technologies used Peremeter tools
Purchase agreements 3rd party vendors
Remote access
Application usage  Browser user agents…
Defense technologies
Human capability

These individual targets are going to be inside your organization, and closest to the data the advisory is trying to gain access, and with the least possible resistance.
This can all be done with a simple phone call to an individual administrative assistant, and actually use the personal information they received on the Internet to use against the victim.  All to make that individual perceive they're giving information to a person they know or trust.
Gain a false sense of trust in order to get the individual target to drop their defenses.

The Delivery
With all this reconnaissance information,  an adversary can build a profile of what tools are being used in your perimeter, what operating systems are used on workstations, and potentially account names, and  even passwords, once again, only using social engineering.

This is the intelligence required to create the perfect RAT , which will be used, once inside the organization.
Exploits can be written, and used against specific operating systems, common applications like browsers, Adobe or Oracle products.  This even includes version each application is using.
Yes social engineering.

With the intelligence gathered on your organization the RAT is packaged up, and all that’s left is a creative method of delivery. Phishing, Watering Hole, Thumb Drive, or in this case a spear phishing attack.
The delivery will most likely make it through your perimeter because the scoring is fairly low, often only choosing a single target to decrease the fidelity of the event from triggering an alert.

Of course this was tested against your perimeter with several previous fake fishing type email probes to several recipients or potentially single-user with nothing more than a URL, and a short message

 The intent is to create a DNS query (roll call) from the link is clicked on.  In reality it was nothing but a harmless http or https request, none of which would cause an alarm by any of your perimeter tools.  This query, would of course, resolve to a local address in a legitimate hosting provider's ASN, and the would be monitored for hits using DNS monitoring tools.

The weaponized email will contain a link that will actually perform an http /GET to download a well-known EK.

It’s the Payload inside this EK that will contain the RAT the adversary created, both making the advanced threat tools and the cyber security department played the fool.
You see the average response will most likely be this was a typical malware campaign, and will most likely end up as a reimaged of the host within a given period of time.

The RAT will use the information gleaned from their “Recon” social engineering phase against your company’s weaknesses.

Once the emails embedded URL is clicked, and the payload is delivered, the dropper EK actually extracts its contents with various premeditated exploits by either embedding them into memory or even a video card.  The exploit could be a utility that spoofs the source of browser updates, or well known exploits targeting Adobe or Oracle products, or just attempts to finds cloud storage with open file shares like Dropbox, or vulnerabilities in your already known operating systems.

The first objective of the RAT has been known and used for a long time with tools like Metasploit or other hacking tools; looking for a jump host.  The adversary wants off this machine and onto another machine as quick as possible (persistence).

At this point there’s no requirement for any command-and-control, thus there's no contact from the RAT.  The communication would be limited to lateral movement and only detected if you use, or have  a solid endpoint security solution.
Now the RAT's objective is to harvest data on the infected machine or machines, and only then make a connection to a predetermined location and exfiltrate using SSL HTTP or FTP.  This exfiltration of data could even be transmitted from several of the jump hosts in a peer-to-peer sharing application, and in several simultaneous garbage looking transmissions like bit torrent.

Remember the RAT is already inside the perimeter.  The adversary is in the squishy center of your network.
The infected hosts can remain silent for as long as the adversary deems fit for sufficient information gathered, and the security department to completely forget the original alert from the first infected host of the phishing infection.

A few days later the victim companies financials, accounts, passwords, intellectual properly,  network topology from critical systems show up on Pastebin or in the media, or sold off to the highest bidder.

A few take away points:

  • Crack SSL if your organization permits it, and understand your egress traffic.
  • Don't take a crimeware kit for face value. Use your Advanced Threat tools but do the Forensics @Volatility is priceless. You might have missed the advanced threat you've been looking for.
  • Stop wasting money on tools that are always one step behind the adversary and always promising, "that feature is in the next release”
  • Find respectable companies that can help find tools to fit your organizations needs and at an affordable price.
  • Use Passive tools to prevent giving away your indicators letting the adversary know you saw them.  Virustotal "search feature",  OpenDNS
  • COLLABORATE  COLLABORATE COLLABORATE with other organizations in your industry.  This is priceless information.  What activity are you both seeing, and put two and two together.
  • RSS research feeds are your friend.  A great project to mention for Security professionals for RSS feeds is The OpenSourceRSSList       
I highly recommend this list for #DFIR #Infosec || research groups like:






Naming a few off the top of my head. Solid research groups!! 
  • Pull out indicators you can use for advance threat detection tools.
  • Find and follow Forensic groups or DFIR.  Their already doing this research for you including cracking XOR, Obfuscation, identifying fake registrar's selling domains to crimeware organizations..   etc.
  • Get HELP.  Stop reading fluff in magazine reviews.  RIGHT tools, and the right advise for your infrastructure!  Accuvant MicroSolved 
  • Most important of all; Have a good incident response plan or IRT.  Know what, and how you're going to recover from this type of breech when it finally hits your organization.


- Jim @RazorEQX  (lacking an editor)

Hope this helps.   In the end we can all #awkwardhug



Saturday, September 21, 2013

Hacker Kids (True Story) Pt.2

Yesterday I blogged about an incident with my Daughter’s ADHD and Ethical hacking and how the school said it was unethical and counter productive to her education.  The 2nd part of this article doesn’t finish with her, but more with me.

From the time I was three years old everyone noticed there was something different about me.  I couldn’t sit still, talked excessively to a point that everyone around me, including my parents, could do nothing but avoid me, or send me to another room just to get a break, and not have to deal with me.  
I felt ignored, unheard, and shunned by everyone around me, and even at age seven I was led to believe I was “different”, and the punishment for this was isolation.

Lets Start with the timeline of this disorder.

·       1902. ADHD was first recognized as a disorder in 1902. A British doctor, Dr. Still, documented cases of impulsive behavior. He gave the disorder its first name, "Defect of Moral Control." Despite this name, he believed that the disorder was a medical problem, not a spiritual defect.
·       1922. It was not until 1922 that ADHD symptoms were described and diagnosed as "Post-Encephalitic Behavior Disorder."
·       1937. In 1937 stimulants were first used to treat children who exhibited signs of ADHD. This was introduced by one Dr. Charles Bradley.
·       1956. In 1956, Ritalin came on the market. It was used to treat children considered to be "hyperactive."
·       1960. Throughout the 1960s, stimulants were increasingly used to treat hyperactive children. In the early part of the decade, the term "Minimal Brain Dysfunction" was used to describe the disorder, but this was changed to "Hyperkinetic Disorder of Childhood" in the later part of the decade.
·       1970. In the 1970s, more symptoms were recognized to go along with hyperactivity. These included impulsiveness, lack of focus, daydreaming, and other lack of focus type symptoms. "Impulsiveness" as a category was divided into three subtypes: verbal, cognitive, and motor impulsiveness.
·       1980. In 1980 the name "Attention Deficit Disorder" was invented by the American Psychiatric Association.
·       1987. In 1987, the name was revised to "Attention Deficit Hyperactive Disorder".
·       1996. In 1996, Adderall was approved to treat ADHD.
·       1998. In 1998, the American Medical Association stated that ADHD was one of the most researched disorders, despite the fact that its cause is unknown.

Given that time line that put me in college before there was an "real" acknowledgement of the disease let alone a "REAL" medication to treat it. 

It was in the 3rd grade my parents made the decision to hold me back a grade for falling behind the other children, and sent me for psychiatric treatment, further branding me as mentally ill, thus leaving the few friends I had, pass ahead of me.
In the psychiatric sessions I had to put pegs in boards and look at pictures, and asked questions like “Was I having thoughts of killing my parents.”
  It was humiliating. 

By High school I was still getting C’s and D’s and barely passed. 
In 1985 I joined the Army to get away from my family, and put the past behind me. 

It turned out the Army was good for me.  The condition was beaten out of me with complete control of what I was allowed to say, do, or when it was appropriate to speak.  The key to this treatment? I was no longer ignored or isolated, and I welcomed that!

After the Army I was diagnosed with PTSD and once again found myself in front of a psychiatrist.  But this time I was not only treated for PTSD but also diagnosed with ADHD, and put on a medication called Adderall. 

I almost instantly felt a change in my behavior and control of my emotions and thought processes.  I was able to read and absorb what I had read.
I enrolled in college and was top of my class, often setting the bell curve on exams. 

In the late 90’s I found a career in Information Technology and excelled at an incredible pace.   Never once attended a class, but only reading books and, researching by asking questions from other people in the industry. 

I couldn’t get enough of the field; I took Cisco certification after certification with no classes but just reading books. (Remember there was no YouTube).  

Soon I had many certifications including Voice Professional, Security Professional, Networking Professional, and anything else “Cisco” I could get my hands on.

By 2004 I was no longer Interested in Cisco networking and wanted to learn more about Information Security.  Already having experience with Cisco solutions I expanded out to other tools and certifications…   
THEN I found Metasploit, SET and Backtrack, and even more certifications, C|EH, Offensive Security Certified Professional, and a plethora of great books on the tools.

I started attending Hacking Conferences like DefCon, and DerbyCon and meeting other professionals in the industry, and still craved to learn more. 
THEN I found malware, and Advanced Threats to our Nations security. 
Already having knowledge of debuggers and code injection through training for the OSCP certification, I had no trouble jumping head first into deep forensic analysis of Malcode, and exploits.  By 2010 I was using most of the top APT or Advanced Persistent Threats (I hate that term because even malware tries to be persistent) tools on the market.  I continue to follow the new and innovative ways to detect and track these attacks to this day.  I’ve done all this, and yet I’m “brain damaged” because I have ADHD.

So.  When I went to that principle and her shrink to talk about my daughter, and her ADHD, and my parenting techniques for educating my child with information she can use in her career, and the challenges I give her at such an early age, what do you think I said?    I don’t think I have to tell you the answer.

BTW:  While I was there I found most of their computers completely infected with PUD and malware and offered solutions for them to pay someone to clean that mess up.  I told them my daughter would be happy to help them out for a small fee.  



References:

Friday, September 20, 2013

Hacker Kids (True Story)





   Some of you might know the last month I started training my daughter to understand threats on the internet by showing her and ultimately teaching her how to use hacking tools and exploits in a controlled environment.  Let me explain why. 

It was toward the beginning of the summer this year that her Animal Jam account had been hacked, after she was social engineered into giving her account and password information to another member who promised thousands of  "diamonds" (in game money).  Needless to say the culprit hijacked her account and changed the email address, taking over her entire account.  
My daughter was devastated.  

It was then just a few weeks later her computer was infected by malware while browsing for Minecraft Mods, Mind you this 8 yr. old bundle of joy had  already taught herself how to install mods, by watching Youtube videos, and has built her own server with installed mods, she enjoys playing. 

Having been infected several times in the past, and my anger displayed having to constantly clean yet another machine on our network,  she thought she was in trouble.   When I got home she ran to her Mom and started crying.  She thought she was in trouble for something she had done wrong.  

Needless to say the tears got to me, and i decided to spend some time explaining what Malware was and what it was used for.  Somewhere during the conversation hacking was brought up and my daughters face turned pale.  

"Daddy you're a hacker!" she said with a look of distrust.  

"Im a good Hacker its not the same." I responded. 

The expression on her face was both amusing and concerning as I could tell she didn't understand the difference.  

So i decided to take the time to show her tools like SET and Metasploit and as you can imagine she took to them amazingly fast.   Scary fast. 

Well maybe it was my fault for not setting the rules but a few days ago I was called by the School, and demanded to meet with the principle of the school, her teacher, and the school philologist.    At first this call came at no surprise, as we have met several times over the last two years.  Turns out my Daughter suffers from ADHD like her Dad.  

 So I get to the school and sit down with the three of them and I'm informed she had been "caught" downloading a criminal application called "Metasploit" 

When my daughter was questioned as to why she was trying to download the software,  she advised them she just wanted to show the other kids what her Daddy had taught her.   

Then as if it couldn't get worse when asked what her Daddy did for a living she told them "He's a hacker"   

"But he's a good hacker"   she added.  (to be continued)

- Razor






Friday, September 13, 2013

Video Resources for Malware Analysis

Just a collection of video tutorials I have collected over the time with examples of Malware Reversing from nuts to bolts.  If you have a video you want to add give me a shout on Twitter.  I'll review it and be happy to add.   Must have speech not music ( I love music just hate reading typed script in notepad)
and be useful beyond what I have already added.
Thanks to all the researchers that have contributed their work!!!





How to Set Up a Malware Analysis Lab






eLearnSecurity -- Malware Analysis




Basic Dynamic Analysis with IDA Pro and WinDBG





Reverse Engineering Binaries



Malware Analysis Collaboration:  Smoocon 2013