Showing posts with label Worm. Show all posts
Showing posts with label Worm. Show all posts

Wednesday, May 30, 2012

Video: How Viruses Attack a PLC/HMI without Deep Packet Inspection via an USB memory stick?

Virus Attack & Prevention With/Without Deep Packet Inspection


In the first video, Eric Byres, cto and vp Engineering of Tofino Security, a Belden Co., shows how a worm can attack a PLC/HMI in a simulated Oil and Gas environment. This video sees Deep Packet Inspection in action to prevent a USB thumb drive attack.


The second video sees Deep Packet Inspection in action to prevent a USB thumb drive attack

Thursday, May 24, 2012

Beware fake Chrome installers for Windows.

Fake Google Chrome Installer Steals Banking Details


A file named "ChromeSetup.exe" is being offered for download on various websites, and the link to the file appears to be legitimately hosted on Facebook and Google domains. In reality, the software won't install Google's Chrome browser, but an information-stealing Trojan application known as Banker, according to antivirus vendor Trend Micro.


Once the malware--which appears to be targeting Latin American users, especially in Brazil and Peru--is executed, it relays the IP address and operating system version to one of two command-and-control (C&C) servers, then downloads a configuration file. After that, whenever a user of the infected PC visits one of a number of banking websites, the malware intercepts the HTTP request, redirects the user to a fake banking page, and also pops up a dialog box informing the user that new security software will be installed.


In fact, the malware has been designed uninstall GbPlugin, which is "software that protects Brazilian bank customers when performing online banking transactions," said Trend Micro security researcher Brian Cayanan in a blog post. "It does this through the aid of gb_catchme.exe--a legitimate tool from GMER called Catchme, which was originally intended to uninstall malicious software. The bad guys, in this case, are using the tool for their malicious agendas."

Refer here to read further details.

Tuesday, April 10, 2012

“Malware Classifier” Tool

Python tool for quick malware triage


Malware Classifier uses machine learning algorithms to classify Win32 binaries – EXEs and DLLs – into three classes: 0 for “clean,” 1 for “malicious,” or “UNKNOWN.” The tool extracts seven key features from a binary, feeds them to one or all of the four classifiers, and presents its classification results.


The tool was developed using models resultant from running the J48, J48 Graft, PART, and Ridor machine-learning algorithms on a data set of approximately 100,000 malicious programs and 16,000 clean programs.


Malware Classifier is available at Open @ Adobe.

Wednesday, January 18, 2012

Ramnit Worm Threatens Online Accounts

Facebook Targeted by Fraudsters Seeking Log-in Credentials

Ramnit is a worm, which means, unlike malware, it can spread to other computers without being sent through e-mail or a malicious website. Ramnit, which surfaced in April 2010, continues to evolve.

In August 2011, security vendor Trusteer was the first to discover Ramnit's merger with the Zeus variant designed to target online banking accounts. The Ramnit-Zeus hybrid was superior because of its advanced man-in-the-browser capabilities, which enabled it to steal online banking and corporate log-in credentials.

The Ramnit hybrid bypassed two-factor authentication, and between September 2011 and December 2011, Trusteer estimated that some 800,000 machines had been infected.

Once launched on a corporate PC, Ramnit's browser penetration module steals internal and software-as-a-service credentials. Incoming web pages can then be modified using an HTML injection to request and steal more sensitive information.

Ramnit's man-in-the-middle looks like an actual social-media or bank-account sign-in page that captures a user's ID and password, and sometimes other personal information en route to the actual log-in page.

The difference, however, is that the page in the middle captures authentication data and allows the attacker to gain access to the victim's accounts at will.

Ramnit compromised 45000 Facebook accounts and now targeting financial accounts...

Researchers advises that the Ramnit worm, which last year defeated two-factor authentication measures used to protect online banking accounts and corporate networks, is now targeting Facebook - a development that should especially concern financial service businesses.
Lab researchers working for the Israel-based provider of cyberthreat management services say Ramnit has been linked to the compromise of more than 45,000 Facebook log-in credentials, primarily hitting users in the United Kingdom and France.
"We suspect that the attackers behind Ramnit are using the stolen credentials to log in to victims' Facebook accounts and to transmit malicious links to their friends, thereby magnifying the malware's spread even further," says a blog posted on Seculert's website Jan. 5.

"In addition, cybercriminals are taking advantage of the fact that users tend to use the same password in various web-based services (Facebook, Gmail, Corporate SSL VPN, Outlook Web Access, etc.) to gain remote access to corporate networks."
Because users often use the same log-in and password credentials for multiple accounts, the threat of Ramnit attacks should be concerning to every industry, not just financial services, though financial institutions often have the most to lose when consumers online banking accounts are breached.
"As demonstrated by the 45,000 compromised Facebook subscribers, the viral power of social networks can be manipulated to cause considerable damage to individuals and institutions when it is in the wrong hands," Securlet says.
A Call for Multifactor Authentication

Bill Wansley an analyst at Booz Allen Hamilton, says every organization should take Ramnit's rapid evolution as a sign that outdated authentication measures are no longer effective.
"Passwords are not very useful for anything anymore," Wansley says. "They are just too easy to forget, copy or break. Everyone needs to go to multifactor authentication - like Google has recently - for social-media sign-in, and certainly for anything that is for financial or medical-related accounts."
Passphrases are better than passwords, but multifactor authentication is the new standard. "Nobody should be using their social-media passwords or phrases for their financial accounts," Wansley says.

In the financial space, cybercriminals increasingly use older malware to capture individual passwords and personal information that is later exploited to gain access to financial accounts.

"The Ramnit example is typical of these type attacks," Wansley says. "Ramnit is actually an older malicious code that has been updated with new features to achieve other purposes."

Thursday, October 27, 2011

New Stuxnet-Like Worm Discovered

Researchers Label the New Threat "Duqu"

A research lab has discovered on computers in Europe a worm very similar to Stuxnet, according to a blog posted Tuesday by the IT security provider Symantec.

Researchers at the lab, which Symantec did not identify, named the new worm Duqu [dyü-kyü] because it creates files with the file-name prefix ~DQ. It shares a great deal of code with Stuxnet; however, the payload is completely different, Symantec researchers say.

Symantec says Duqu is essentially a harbinger to a future Stuxnet-like attack. Stuxnet, discovered in June 2010, gained fame when it was credited with crippling Iranian uranium enrichment centrifuges. Israel and/or the United States are prime suspects in the creation of Stuxnet, which targets Siemens industrial software on equipment running on the Microsoft Windows operating system.

The newly discovered worm was written by the same authors of or those who have access to the Stuxnet source code and appears to have been created since the last Stuxnet file was recovered, Symantec says.

"Duqu's purpose is to gather intelligence data and assets from entities, such as industrial control system manufacturers, in order to more easily conduct a future attack against another third party," the blog says. "The attackers are looking for information such as design documents that could help them mount a future attack on an industrial control facility."

Symantec says the attackers used Duqu to install a so-called infostealer to record keystrokes and gain other system information. "The attackers were searching for assets that could be used in a future attack," the blog says. "In one case, the attackers did not appear to successfully exfiltrate any sensitive data, but details are not available in all cases. Two variants were recovered, and in reviewing our archive of submissions, the first recording of one of the binaries was on Sept. 1. However, based on file compile times, attacks using these variants may have been conducted as early as December 2010."

The blog says one of the variant's driver files was signed with a valid digital certificate that expires next Aug. 2. The digital certificate, belonging to a company headquartered in Taipei, Taiwan, was revoked last Friday.

Symantec says it had recovered additional variants of Duqu from another European organization with a compilation time of Monday, Oct. 17; however, these variants have yet to be analyzed.

Monday, August 8, 2011

Researcher discovered ABB-branded transformer running an electricity substation

SCADA equipment Google-able

Most SCADA protocols do not use encryption or authentication, and they don't have access control built into them or into the device itself. This means that when a PLC has a web server, and is connected to the internet, anyone who can discover the internet protocol (IP) address can send commands to the device, and the commands will be performed.

If that RTU or PLC has large motors connected to it, pumping out water or chemicals, the equipment could be turned off. If it was a substation and the power re-closer switches were closed, we could break it open and create an [electricity] outage for an entire area or city. The bottom line is you could cause physical damage to whatever is connected to that PLC.

While SCADA security has been an issue for decades, as legacy systems have been connected to the internet and remote technologies have emerged, with the emergence of Stuxnet, a worm that spreads via holes in Windows, but specifically targets Siemens SCADA systems and uses other sophisticated methods. Experts theorise that Stuxnet was designed to sabotage Iran's nuclear development program.

However, Stuxnet has raised awareness in the general public and within companies running critical infrastructure systems, and scared some of them enough to beef up their security. Stuxnet created an interest in the community to learn more about vulnerabilities and SCADA systems. We've seen direct impact in our customers being able to get funding to secure their SCADA systems.

While Stuxnet appears to have run its course and had minimal impact, SCADA systems are at risk from vulnerabilities and exploits in general, the US ICS-CERT (Industrial Control System Computer Emergency Response Team).

Not only are Supervisory Control and Data Acquisition (SCADA) systems used to run power plants and other critical infrastructure lacking many security precautions to keep hackers out, operators also sometimes practically advertise their wares on Google search, according to a demo held yesterday during a Black Hat conference workshop.

Thursday, August 4, 2011

Conficker found on external HD devices on sale

Aldi recalls Conficker-infected hard drives

Australian supermarket chain ALDI might seem like the last place where one can pick up a Conficker infection, but according to an emergency security alert by the Australian Computer Emergency Response Team, the worm has been discovered on a Fission External 4-in-1 Hard Drive/DVD/USB/Card Reader product the stores offer for sale.

ALDI has effected an immediate recall of the product from its shelves and has urged customers who have bought the product to return it. The chain says that the worm was found on a small number of the devices, and that it can be removed by fully formatting them.

SCMagazine Australia reports that AusCERT has also advised a full format of the device for those who won’t be returning it to the store and to scan their computer with an up-to-date AV solution. Since Conficker is an old threat, the majority of commercial AV solution contain the signature for spotting it.

The worm’s presence on the drives has initially been detected by a Kaspersky AV product, and “the manufacturer recommends that this same software or similar be used to scan all customers’ computers and USB storage devices which have been in contact with the four-in-one hard drive, to detect and remove if present,” an ALDI spokeperson stated.

Wednesday, June 15, 2011

Microsoft Security Essentials

Doesn’t get in the way of PC performance

As a Information Security professional, I often get this question: Which is the good anti-virus? Which one i should use?

Here is my pick out of the bunch of anti-viruses software available in the market.

Microsoft Security Essentials doesn’t carry the weight of suite products and has a much smaller download size. Scans and updates are scheduled to run when the PC is idle and use a low-priority thread. CPU throttling ensures that no more than 50 percent of the CPU is utilized by Microsoft Security Essentials activity, so that your system continues to perform those tasks you are likely to be performing, such as opening files or browser windows, saving files, and using cut, copy, and paste.

Microsoft Security Essentials uses smart caching and active memory swapping so signatures that are not in use are not taking up space, thus limiting the amount of memory used even as the volume of known malware continues to increase. This makes Microsoft Security Essentials friendlier toward older PCs, as well as today’s smaller, less powerful form factors such as netbooks.

Please refer
here for further details.

Sunday, February 13, 2011

What have we learned from Conficker?

Conficker has been somewhat of a catalyst to help unify a large group of professional and academic whitehats

Conficker is the name applied to a sequence of malicious software. It initially exploited a flaw in Microsoft software, but has undergone significant evolution since then (versions A through E thus far).

Nearly from its inception, Conficker demonstrated just how effective a random scanning worm can take advantage of the huge worldwide pool of poorly managed and unpatched internet-accessible computers. Even on those occasions when patches are diligently produced, widely publicized, and auto-disseminated by operating system and application manufactures, Conficker demonstrates that millions of Internet-accessible machines may remain permanently vulnerable.

In some cases, even security-conscious environments may elect to forgo automated software patching, choosing to trade off vulnerability exposure for some perceived notion of platform stability.

Another lesson of Conficker is the ability of malware to manipulate the current facilities through which internet name space is governed. Dynamic domain generation algorithms (DGAs), along with fast flux (domain name lookups that translate to hundreds or thousands of potential IP addresses), are increasingly adopted by malware perpetrators as a retort to the growing efficiency with which whitehats were able to behead whole botnets by quickly identifying and removing their command and control sites and redirecting all bot client links.

While not an original concept, Conficker's DGA produced a new and unique struggle between Conficker's authors and the whitehat community, who fought for control of the daily sets of domains used as Conficker's internet rendezvous points.

Yet another lesson from the study of Conficker is the ominous sophistication with which modern malware is able to terminate, disable, reconfigure, or blackhole native OS and third-party security services..

Today's malware truly poses a comprehensive challenge to our legacy host-based security products, including Microsoft's own anti-malware and host recovery technologies. Conficker offers a nice illustration of the degree to which security vendors are challenged to not just hunt for malicious logic, but to defend their own availability, integrity, and the network connectivity vital to providing them a continual flow of the latest malware threat intelligence.

To address this concern, we may eventually need new OS services specifically designed to help third-party security applications maintain their foothold within the host.

Wednesday, February 2, 2011

Some Lessons to be Learned from Stuxnet

STUXNET creators not so ELITE?

Everyone knows what Stuxnet is and if you don’t you probably missed the most discussed and much praised worm of the past few years.

The worm targeting Siemens systems, controlling critical power infrastructures, has been subject of deep analysis by researchers to uncover who’s behind it and who the final target was. Both of the above questions had readily found an answer: at least according to the authoritative Times, It’s been a joint effort between US and Israel governments, to destroy alleged Iranian projects to build a nuclear arsenal.

Although the goal has not been reached, Iranian path to having nuclear bombs has been set back by 2 years, as President Obama, although skirting the Stuxnet issue, stated in an interview regarding Iran. The much hyped Stuxnet, dubbed as the most sophisticated worm ever, has also been subject of analysis of Tom Parker. Tom is a security researcher who has presented his own analysis and view of the Stuxnet case at BlackHat DC.

For the first time, someone states that Stuxnet worm is not so elite as everybody thought in the beginning and probably media played an important role in the matter. Still according to Parker, too many mistakes (have been) made and too many logic flaws made things go wrong. Parker seconded the hypothesis according to which code was produced by two separate groups: one building the core of it and another, much less experienced, providing the exploits and the command and control code.

Another security expert, Nate Lawson, considers Stuxnet code nothing more elite than any other malware around, not even implementing advanced obfuscation techniques such as anti-debugging routines.

Some more interesting links to learn more details and lesson learnt analysis:
Strategic Lessons of Stuxnet
ICS-CERT Stuxnet Lessons Learnt
Stuxnet Lesson Learned: The Twain Always Meet

Tuesday, February 1, 2011

Stuxnet - Interesting white paper from Tier-3

Stuxnet: Doomday Bug or Media Hype?

The hot security story of 2010, Stuxnet, the turning point in IT security according to some experts. But was it Y2K-style hype, Doomsday for SCADA systems and ICSs – or a warning for everyone?

This fully-referenced Short White Paper examines:
  • The actual threat that Stuxnet poses.
  • The parallels between Stuxnet in ICSs and e-espionage in all IT networks.
  • How to protect your enterprise against these emerging threats.
I hope you find it useful, to read this paper, please use this link: Stuxnet: Doomday Bug or Media Hype?

Sunday, January 23, 2011

Attacks on Critical Infrastructure by Rogue and Competitive Nations

Stuxnet – marking the beginning in Cyberwar of zero-day malware targeting physical systems

While most new threats are geared towards financial gain, in June 2010, we witnessed what is considered to be the first major attack designed to harm physical systems. This malware was designed to go after Supervisory Control and Data Acquisition (SCADA) systems. SCADA systems are designed to control and monitor various processes within industrial systems. The Windows-specific worm used various zero-day attacks to target Siemens’s WinCC/PCS 7 SCADA software. It then spread via infected USB flash drives then used other exploits to go after network-based WinCC computers.

After getting inside the system, it used default passwords to command the software. What made Stuxnet so different than the other attacks during 2010 was the level of sophistication, the fact that it specifically targeted critical infrastructure, in particular, that used in controlling Nuclear power plants or Nuclear research facilities, and the geo-specific location of the target – that being facilities in Iran. Also of interest, Stuxnet surfaced in other countries without causing any known harm. Even if it never takes a system down, it did its job – folks in Iran are most likely questioning the safety of all of their SCADA equipment, most likely believing the systems have been compromised, whether or not they actually know how far the zero-day worm travelled into their country or their Nuclear facilities.

Without strong Host-based Intrusion Prevention (HIPS) in conjunction with Network Access Control (NAC), these upgraded SCADA systems, now with TCP/IP touch points, will become a major target. Most of the new malware targeting these systems will not be easily discovered by traditional UTM firewalls, Intrusion Prevention Systems (IPS) or Anti-virus Systems (AVS). It’s going to take a heuristic, real-time analysis – looking for oddities in network traffic communication requests from potentially compromised hosts. Also, by removing most Common Vulnerabilities and Exposures (CVEs), the risk of these infections will be reduced but not completely mitigated due to the surgical precision of new malware targeting these systems. It seems that nearly an unlimited amount of malware intelligence research and development went into the Stuxnet worm – there will be much more targeting Critical infrastructure in the very near future.

In recent years, Railroad executives claimed that they’ve become IT managers. With a few bits flipped, a train can be moved from one track to another and would potentially collide with another train, causing massive casualties, if it weren’t for new software written specifically for these archaic systems, to ward off a collision through automated collision avoidance detection. It’s simple software tweaks like these that can make the difference between life and death in Critical infrastructure.

Recently a teenage hacker who didn’t think of himself as a cyberterrorist was playing around with good old fashioned war-dialing software – he found a modem pool at an airport and was able to login to the computer that turned the airport lights on and off. He turned them off during the night when planes were landing. Good thing the pilots could key their microphone on a certain frequency and get the lights back on just in time to land safely. Expect the innovations in this area to outpace traditional countermeasures.

IT / SCADA practitioners in Critical infrastructure need to protect their networks in the most vigilant methods available with the best of breed technologies where worrying about budgets or brand names are of no use. Most managers in IT usually say I will never get fired for buying XYZ corp’s products (pick one – Cisco, IBM, Microsoft, etc.) but the reality is that these systems are under more scrutiny and attack by cyberterrorists now more than ever. Their vulnerabilities are published monthly in the National Vulnerability Database. To think systems by big brand name vendors will protect critical infrastructure is an absolute fallacy. It’s time to look at high-level policies, procedures, strategies and lesser known more innovative products and technologies that won’t telegraph easily to these bad guys– making it even harder for them to successfully break in and cause critical damage where it hurts the most.

Friday, January 21, 2011

Twitter Worm redirects to fake anti-virus

SCAREWARE - warning message claims the computer is running suspicious applications and the user is encouraged to run a scan

A fast-moving Twitter worm is in circulation, using Google’s goo.gl redirection service to push unsuspecting users to a notorious scareware (fake anti-virus) malware campaign.


At 8:45 a.m EST today, this Twitter search shows thousands of Twitter messages continuing to spread the worm.

According to malware hunters tracking the threat, the worm’s redirection chain pushes users to a Web page serving up the “Security Shield” Rogue AV. The page is using obfuscation techniques that include an implementation of RSA cryptography in JavaScript to obfuscate the page code.

Once a user’s browser session is redirected to the malicious site, a warning message claims the computer is running suspicious applications and the user is encouraged to run a scan. As usual, the result is that the machine is infected with malicious threats and the scam is to trick the user into downloading a fake disinfection tool.

Source: ZDNet News

Monday, September 27, 2010

Stuxnet worm infected at least 30,000 Windows PCs

Iran confirms massive Stuxnet infection of industrial systems

Officials in Iran have confirmed that the Stuxnet worm infected at least 30,000 Windows PCs in the country, multiple Iranian news services reported on Saturday. Experts from Iran's Atomic Energy Organization also reportedly met this week to discuss how to remove the malware.

Stuxnet, considered by many security researchers to be the most sophisticated malware ever, was first spotted in mid-June by VirusBlokAda, a little-known security firm based in Belarus. A month later Microsoft acknowledged that the worm targeted Windows PCs that managed large-scale industrial-control systems in manufacturing and utility companies.

Those control systems, called SCADA, for "supervisory control and data acquisition," operate everything from power plants and factory machinery to oil pipelines and military installations.

Refer here to read more details.