Analysis: CryptoWall 3.0, Dyre and I2P

For a moment, put yourself in the shoes of a cyber criminal. You’ve collected an array of tools (malware), built up your infrastructure (command and control (C2) servers) and you have a process to make money off your hard work. You wake up on Monday morning and the domains your carefully built malware uses for command and control are shut down. Some security researcher has taken control of them, completely halting your operation. This would certainly be good news to anyone reading this blog, but for the criminal it’s a big setback and source of frustration. These kinds of takedowns are the impetus for some of the most impressive developments in malware technology over the last decade.

Takedown-Resistant Command and Control

Once attackers have infected a PC through some exploit or social engineering, one of their major challenges is keeping control of that system. Antivirus programs running on the PC are trying eradicate the threat, the command and control domains and IPs are being added to denylist and blocked by networks around the world. Many malware authors have taken to building complex mechanisms to ensure that their malware is resistant to these kind of blocks and takedowns. Some of the more innovative mechanisms include: Continue reading "Analysis: CryptoWall 3.0, Dyre and I2P"

How To Protect Yourself From the Latest CTB-Locker Campaign

CTB-Locker is a well-known ransomware Trojan used by crimeware groups to encrypt files on the victim’s endpoints and demand ransom payment to decrypt the files back to their original state.  Earlier this week we detailed a new CTB-Locker campaign and why legacy security products won’t protect enterprise networks.

In this blog post we will detail how to protect yourself from CTB-Locker, even if you aren’t protected by Palo Alto Networks next-generation enterprise security.

Since our first blog post on the campaign, here are some updates: Continue reading "How To Protect Yourself From the Latest CTB-Locker Campaign"

Newest CTB-Locker Campaign Bypasses Legacy Security Products

Introduction

CTB-Locker is a well-known ransomware Trojan used by crimeware groups to encrypt files on the victim's endpoints and demand ransom payment to decrypt the files back to their original state, but most antiviruses detect it by mistake as CryptoLocker (only one vendor correctly detects it as CTB-Locker). The attack vector is very basic and repeats itself: It begins with a spear phishing email sent with SCR attachments (double zipped). Once executed by the user the first stage malware downloads and executes the ransomware from a fixed hardcoded server list.

CTB

The Origins

The first known campaign was launched by Crimeware on November 2014. The first stage downloaded the ransomware from these sites:

  • pubbliemme.com (5.134.122.150)
  • agatecom.fr (213.186.33.19)
  • n23.fr (213.186.33.4)
  • baselineproduction.fr (213.186.33.4)

Continue reading "Newest CTB-Locker Campaign Bypasses Legacy Security Products"

Scareware App Downloaded Over a Million Times from Google Play

We have recently been investigating an antivirus app in the Google Play store that was displaying fake virus detection results to scare users into purchasing a premium service. According to the Google Play store statistics, users have downloaded “AntiVirus for Android™” more than one million times and the app was listed in Top 100 free apps in Tools category. Our Wildfire analysis cloud captured the initial app and identified it as Scareware.

On January 20, we reported this issue to Google and two days later, they removed the app from Google Play.  Continue reading "Scareware App Downloaded Over a Million Times from Google Play"

Our Favorite Presentations from ShmooCon 2015

We were fortunate enough to attend this year’s ShmooCon, an annual hacker conference held in Washington, DC. It is organized by The Shmoo Group, which was founded in the late 1990s as an international non-profit security think tank. It invariably sells out every year, with tickets from each of three rounds of sales gone in under a minute. In addition, the maximum number of tickets that can be purchased at one time is limited to two to help more people get tickets. The tickets are highly sought after as the conference:

  1. Remains affordable (just $150 person; a bargain compared to most industry events)
  2. Limits attendance to what the facility can comfortably hold (we’re looking at you, Defcon)
  3. Focuses on new research or speakers that have not yet been presented at other conferences.

Shmoocon Continue reading "Our Favorite Presentations from ShmooCon 2015"

Dridex Banking Trojan Begins 2015 with a Bang

In October, we called out a series of attacks installing the Dridex Trojan using macros in Microsoft Word documents. Those attacks continued over the last few months and in first two weeks of the new calendar year we’ve seen another new campaign.

To refresh your memory, Dridex is the latest version of the Bugat/Feodo/Cridex banking Trojan. Its core functionality is to steal credentials of online banking websites and allow a criminal to use those credentials to initiate transfers and steal funds. Dridex is currently being distributed through an e-mail campaign that carries a Word Document attachment, which uses built-in macro code to download and execute a copy of the Trojan.

Continue reading "Dridex Banking Trojan Begins 2015 with a Bang"

Don’t Miss A Single Threat Intelligence Update from Unit 42!

Unit 42 is the Palo Alto Networks threat intelligence team. Made up of accomplished cybersecurity researchers and industry experts, Unit 42 gathers, researches, analyzes, and provides insights into the latest cyber threats, then shares them with Palo Alto Networks customers, partners and the broader community to better protect enterprise, service provider, and government computing environments.

blog-title-unit42

You can now have up-to-the-minute threat intelligence updates from Unit 42 delivered right to your inbox, as they’re posted. Click here to subscribe.

Regular research analysis is posted to the Unit 42 threat intelligence blog. Unit 42 also publishes whitepapers examining, in detail, threats to mobile device ecosystems, APTs, malware attack patterns and other subjects crucial to any security practitioner or business executive’s understanding of the current cyber threat landscape.

Recent Unit 42 whitepapers include: Continue reading "Don’t Miss A Single Threat Intelligence Update from Unit 42!"

CoolReaper Revealed: A Backdoor in Coolpad Android Devices

Coolpad is the sixth largest manufacturer of smartphones in the world, and the third largest in China. We recently discovered that the software installed on many of Coolpad’s high-end Android phones includes a backdoor which was installed and operated by Coolpad itself. Today we released a new report detailing the backdoor, which we’ve named “CoolReaper.”

After reviewing Coolpad complaints on message boards about suspicious activities on Coolpad devices, we downloaded multiple copies of the stock ROMs used by Coolpad phones sold in China. We found the majority of the ROMs contained the CoolReaper backdoor. Continue reading "CoolReaper Revealed: A Backdoor in Coolpad Android Devices"

Google Chrome Exploitation – A Case Study

google chrome1

In this write-up, we will present several techniques used in exploiting a vulnerability in Google Chrome, and the various difficulties presented by its security mechanisms and considerations. We also offer some reflections regarding how some of the techniques used were made irrelevant by mitigations introduced since.

The exploit was developed to exploit a bug in Chrome 33, a winning submission to Pwn2Own 2014 by geohot, which later also awarded him the Best Client-Side Bug pwnie award.

The Bug

The vulnerability existed in Chrome's implementation of ArrayBuffers, and is described in some detail in this issue page in the Chromium repository, along with an impressively concise exploit implemented by geohot himself. Continue reading "Google Chrome Exploitation – A Case Study"

Unit 42 Explores Malware Attack Vectors in Key Industries

This week Unit 42 released its first Threat Landscape Review, looking at how malware trends affect key industries, from healthcare to high tech, around the world, and the particular persistence of the Kuluoz, or Asprox, campaign.

This infographic represents some of the key data from the full report, which you can download from the Unit 42 page. Does anything shown here surprise you?

Unit 42 Threat Landscape Review Infographic from PaloAltoNetworks

DTLS Vulnerabilities in CVE-2014-6321

Microsoft recently released a patch for a critical vulnerability in Microsoft Secure Channel (aka Schannel).  This vulnerability is being referred to as MS14-066.  The patch addressing CVE-2014-6321 fixed many areas within schannel.dll, including at least two vulnerabilities related to the handling of the Datagram Transport Layer Security (DTLS) protocol.

DTLS is used by Microsoft Remote Desktop Protocol (RDP) to provide communications privacy for datagram protocols.  The DTLS protocol is used by Microsoft Windows Remote Desktop Gateway (RDG) to establish a secure channel between the RDG client and RDG server (described in detail in [MS_TSGU].pdf).

DTLS Handshake

Continue reading "DTLS Vulnerabilities in CVE-2014-6321"

How Malware Trends Affect Key Industries, From Healthcare to High Tech

Today we released our first Threat Landscape Review, which takes a high-level view of how malware is delivered to networks across major industries around the world. The data used for this report was derived from Palo Alto Networks WildFire™, which automatically identifies threats from malware over a wide array of applications by executing them in a virtual environment, observing their behavior. This data was collected from live systems in networks belonging to 2,363 different companies operating in 82 different countries.

PAN-Unit42-web-banner-600x310

While there are currently over 4,000 organizations using WildFire to defend their networks the data for this report was specifically collected from organizations in 10 key verticals: Continue reading "How Malware Trends Affect Key Industries, From Healthcare to High Tech"

Learn More About WireLurker and the Impact to OS X and iOS

Recently Palo Alto Networks researcher Claud Xiao discovered WireLurker, a new family of Apple OS X and iOS malware with characteristics unseen in any previously documented threats targeting Apple's popular desktop and mobile platforms. Much has happened since Claud's discovery, so we're pleased to present a new webinar covering WireLurker information and the potential impact of this malware family on enterprise organizations.

blog-title-unit42

Wirelurker Webinar: A New Era in OS X and iOS Malware

Continue reading "Learn More About WireLurker and the Impact to OS X and iOS"

Code to Trigger MS14-066 ECDSA Server BOF Vulnerability

Microsoft recently released a patch for a critical vulnerability in Microsoft Secure Channel (aka Schannel).  This vulnerability is being referred to as MS14-066.

A description of how to trigger the MS14-066 ECDSA Heap Buffer Overflow vulnerability was posted by BeyondTrust, which also explained the research method used in narrowing down where this vulnerability presented itself.  Their article mentions leveraging the OpenSSL s_client to authenticate to an IIS server, and by patching the s3_cInt.c file to fuzz the particular code path they were able to trigger a crash in memcpy.  (BeyondTrust’s research team is to be thanked for saving others in our community a lot of work and time!)

Our researchers were able to write a demonstration program by patching the OpenSSL 1.0.1 source code to trigger this specific vulnerability and show how this could be used for exploitation.

The diff output is provided below: Continue reading "Code to Trigger MS14-066 ECDSA Server BOF Vulnerability"

Follow-On to VBA-Initiated Infostealer Campaign: Exploring Related Malware and Actors

In late October, we began examination of a VBA-initiated Infostealer campaign. This blog post follows up on additional information we gathered on related malware and associated actors.

Pivot On Initial Predator Pain Sample C2

In our previous post, we identified two Command and Control (C2) fully qualified domain names (FQDNs) for the initial Predator Pain sample analyzed: mail.rivardxteriaspte.co[.]uk and ftp.rivardxteriaspte.co[.]uk. We were interested in seeing whether any other malware samples had been observed communicating with these FQDNs and, if so, to which malware family they belonged.

Leveraging the Palo Alto Networks WildFire platform, we found an additional 14 samples that communicated with one or both of these C2 FQDNs between December 27, 2013, and August 1, 2014 (Table 1).

Continue reading "Follow-On to VBA-Initiated Infostealer Campaign: Exploring Related Malware and Actors"