Showing posts with label ransomware. Show all posts
Showing posts with label ransomware. Show all posts

Monday, May 15, 2017

Technical Advisory for System Administrators on "WannaCry Ransomware"

Technical Advisory for System Administrators on "WannaCry Ransomware"

Published on Monday, 15 May 2017 21:56

Background
On 12th May 2017, there was a global wide-spread infection of a ransomware known as "WannaCry", aka. WanaCrypt0r. This ransomware exploits a known critical Microsoft Windows Server Message Block 1.0 (SMB) vulnerability (MS17-010), which allows remote code execution, providing a worm-like capability to propagate through a network by scanning for vulnerable systems and infecting them. It then encrypts files on the system, and extorts a bitcoin ransom in exchange for the decryption of files.

This advisory serves to provide system administrators with technical information to safeguard their networks against this cyber threat.

How to Minimise Risk of Being Infected by WannaCry Ransomware?
In addition to the common best IT security practices such as ensuring latest security patches, updating of AV signatures, non-privilege access to users, and end users’ education, below are additional specific measures to mitigate against the WannaCry Ransomware threat.

Do note that as there are many variants of WannaCry ransomware (and it is still evolving), no one method may be sufficient to ensure that you are fully protected.

Prevention of Spreading From Internal Network
Ensure all Microsoft computers are patched to MS17-010-Critical security patches.

If possible, disable Remote Desktop Protocol (RDP) and Server Message Block (SMB) protocol. Where disabling is not possible, ensure that the RDP access control is secure (i.e. only restrict RDP from specific Out-Of-Band (OOB) network).

There are some variants of WannaCry which have a “kill-switch” feature. Hence it is not recommended to block the network Indicators of Compromise (IOC), because they will spread/infect if the network connection is block.
Prevention of Infection From External Network (i.e. Internet)
Ensure that the perimeter firewalls block unsolicited traffic (including port 445) from the Internet.

The following network IPS (for the respective products) are available for blocking at the perimeter. If you are not using any of the below products, please check with your vendor on the availability of IPS signatures relating to WannaCry.

SourceFire:
SID 42329 - MALWARE-CNC Win.Trojan.Doublepulsar variant successful ping response
SID 42330 – MALWARE-CNC Win.Trojan.Doublepulsar variant successful injection response
SID 42331 – MALWARE-CNC Win.Trojan.Doublepulsar variant process injection command
SID 42332 – MALWARE-CNC Win.Trojan.Doublepulsar variant ping command
SID 42340 - OS-WINDOWS Microsoft Windows SMB anonymous session IPC share access attempt
SID 41978 - OS-WINDOWS Microsoft Windows SMB remote code execution attempt

McAfee Intrushield:
Windows SMBv1 identical MID and FID type confusion vulnerability (CVE-2017-0143)
Windows SMB Remote Code Execution Vulnerability (CVE-2017-0144)
Windows SMB Remote Code Execution Vulnerability (CVE-2017-0145)
Microsoft Windows SMB Out of bound Write Vulnerability (CVE-2017-0146)
Windows SMBv1 information disclosure vulnerability (CVE-2017-0147)
NETBIOS-SS: MS17-010 EternalBlue SMB Remote Code Execution
NETBIOS-SS: SMB DoublePulsar Unimplemented Trans2 Session Setup Subcommand Request
Endpoints Protection
Apply application white-listing where available/possible. For example, Microsoft Windows OS (Windows 7 / 2008 and above) has AppLocker which allows application white-listing.
What Should You Do If You Are Hit by WannaCry Ransomware?
If you suspect that your computer is infected with WannaCry, you may want to do the following:
If possible, do not shutdown/reboot the affected computer.

Disconnect the computer from all network, including internet and internal network.

Unplug all USB connected devices from the affected computer.

If your backup devices (i.e. NAS, SAN, portable HDD) are connected to the same “affected network” as the computer, it is strongly advised that you quickly disconnect from the network (where possible).
Shift your attention to the other systems in the same network, which may have also been affected by the ransomware.
If you find more systems affected, similarly perform same steps in steps 1 to 3.

For all Windows Systems, quickly apply the critical security patch (MS17-010-Critical). Disable RDP and SMB services if possible. This will minimise chances of infection from further spreading within your network.
For the infected machines,
Perform memory acquisition of the running computer, which MAY allow forensics analyst to have a chance of recovering the files.

Re-image the machine with a full format and re-installation of the OS.
There are some online “tutorials” on how to manually remove the WannaCry ransomware. For example, by starting the machine in “safe” mode, manually deleting the malware, and restoring the original files from Windows’ “Restore previous versions” feature.

Whether these methods work or not will depend on the variant of the WannaCry, and windows OS version.

Finally restore information from backup.




- wong chee tat :)

WanaCrypt0r aka WannaCry: What You Need to Know and Actions to Take

WanaCrypt0r aka WannaCry: What You Need to Know and Actions to Take

Published on Sunday, 14 May 2017 18:19

Background
On 12th May 2017, there was a global wide-spread infection of a ransomware known as "WannaCry" aka. WanaCrypt0r. This ransomware has the capability to spread over the network by scanning for vulnerable systems, and infecting them. It then encrypts files on the system, and extorts a ransom payment in bitcoin for the decryption of files

Since the initial news of the infections, Singapore has seen a number of victims struck by the ransomware.

Why “WannaCry” Is Dangerous
What makes WannaCry dangerous is that the attackers are leveraging a Windows exploit code-named EternalBlue, which was reportedly leaked and dumped by the Shadow Brokers hacking group over a month ago. The exploit has the capability to penetrate into machines running unpatched version of Windows through 2008 R2 by exploiting flaws in Microsoft Windows SMB (Server Message Block) Server.

The WannaCry ransomware has since spread rapidly across the world, affecting thousands of systems in over 100 countries. Once a single computer in an organisation is infected with the WannaCry ransomware, the worm looks for other vulnerable computers within the network and infects them as well.

Recommendations
Prevention is always better than cure. For the WannaCry ransomware, this principle is strongly recommended.

Microsoft has released a patch for the SMB vulnerability (MS17-010) in March 2017. You should install this patch immediately if you have not done so.

Like all other ransomware infection, you should always be suspicious of unsolicited documents sent through email. Do not click on links inside these documents unless you have verified the source.

Always make backups of your important files and documents. This will save you when you have to restore your files and documents.

Do ensure that you run an active anti-virus security suite of tools on your system, and most importantly, always browse the Internet safely.

What If I’m Infected?
Firstly, don’t panic. Although there is currently no known way to recover files encrypted by “WannaCry”, you should follow these steps:

Disconnect your computer from the network. This can be done by removing your network cable or shutting down the wireless function on your computer. By doing so you are preventing the spread of the WannaCry ransomware.

Start rebuilding your affected computer. This can be done by performing a clean installation of your Windows operating system.

After you have rebuilt the infected computer, patch it with the recommended patch and restore your system from any backup you have made.

If you need further assistance, you can contact SingCERT for advice.

References
Massive ransomware attack hits 99 countries http://money.cnn.com/2017/05/12/technology/ransomware-attack-nsa-microsoft/index.html
SingCERT Advisory on Ransomware dated 6 May 2016 https://www.csa.gov.sg/singcert/news/advisories-alerts/ransomware
Microsoft Security Bulletin (MS17-010-Critical) dated 14 March 2017 https://technet.microsoft.com/en-us/library/security/ms17-010.aspx
WannaCry Ransomware That's Hitting World Right Now Uses NSA Windows Exploit dated 12 May 2017  http://thehackernews.com/2017/05/wannacry-ransomware-unlock.html


- wong chee tat :)

WannaCry ransomware: Singapore's critical infrastructure unaffected, says CSA

WannaCry ransomware: Singapore's critical infrastructure unaffected, says CSA

Screen of a computer hit by WannaCry ransomware. (Photo: Twitter/@LawrenceDunhill)
15 May 2017 08:09PM
(Updated: 15 May 2017 09:05PM)

SINGAPORE: Singapore's critical information infrastructure (CII) remained unaffected by the global hacking attacks that affected governments and large organisations elsewhere, the Cyber Security Agency of Singapore (CSA) said on Monday (May 15).

Known as WannaCry, the ransomware exploits known vulnerabilities in old Microsoft operating systems. Cyber security experts cautioned that more machines could be affected by the virus as people around the world returned to work at the start of a new week.

"As of this afternoon, no critical information infrastructure has been affected," said Dan Yock Hau, director of Singapore's National Cyber Incident Response Centre, which is a unit of the CSA.

Mr Dan added that the unit would continue to track the situation closely and that it was working with the CII sectors to monitor their state of readiness.

"We are also tracking other sources of intelligence and have reached out to offer assistance to those (cases) that were brought to our attention," he said.

Electronic signboards in malls like Tiong Bahru Plaza and White Sands and as well as a Desigual outlet at Orchard Central have been hit. Jerry Tng of cyber security firm Ivanti, noted that the signboards likely ran on systems that had not been updated with the latest security patches.

A ransomware message encountered by a Facebook user on a directory screen at Tiong Bahru Plaza on Saturday (May 13).

"There are many unpatched signages and point-of-sales (terminals) running embedded Windows OS," Mr Tng said, referring to a version of the Microsoft operating system that is designed for use in embedded systems.

Cyber security researchers elsewhere have likewise drawn attention to the difficulty of patching such devices, which could include medical devices such as those used by hospitals in Britain that were affected by last Friday's cyber attack.

"CSA’s National Cyber Security Monitoring Centre also monitors the developing global situation and track the technical indicators to assess the potential implication to Singapore so that we are able to work on the necessary responses and measures to take," Mr Dan said on Monday.

​CSA chief executive David Koh said: "This is an issue of national importance and we will take all the necessary measures to counter the spread of the ransomware and help businesses and members of the public prevent or recover from it as quickly as possible."

In a separate media release, CSA said that internet service providers Singtel and Starhub had set up helplines for their customers. Singtel customers can call 1688 and its SME customers can call 1606. StarHub's SME customers can call 1800 888-8888, which operates from 9am to 6pm on Mondays to Fridays. Its residential customers can call its 24-hour hotline at 1633.

Businesses and members of the public can also refer to SingCERT’s advisory on WannaCry or seek help from SingCERT by contacting singcert@csa.gov.sg or 6323 5052.

Source: CNA/dt



- wong chee tat :)

Monday, December 26, 2016

17 ransomware cases flagged to Singapore authorities this year: CSA

17 ransomware cases flagged to Singapore authorities this year: CSA
By Lee Li Ying, Channel NewsAsia  Posted 26 Dec 2016 20:04 Updated 26 Dec 2016 21:41

SINGAPORE: There were 17 ransomware cases flagged to Singapore authorities in the first 11 months this year, up from just two in 2015, the Cyber Security Agency (CSA) said.

Ransomware attacks happen when cyber criminals encrypt files or lock a user's computer and then demand money for the user to regain access.

One of the firms that was hit in such fashion was a subsidiary of maritime supply chain management company BH Holdings. Two staff members tried to open an email attachment from an unknown source, recounts IT executive Roberto Ang. "They double-clicked on it, and they could not open it. So they thought that it's just some file that cannot be opened. So they just ignored it and continued working.

"Then after half a day, they started to find that they cannot access some of the files, and these had a weird extension."

That is when the alarm bells went off for Mr Ang. "I saw that there was a text file inside the encrypted folder that showed that it was ransomware, asking for payment to decrypt the files."

The company decided not to pay the ransom of US$1,000 (S$1,447). Instead, it spent a week rebuilding about 3,000 infected files with data of the accounts and stocks from hard copy files.

After the attack, the company also invested in cyber insurance and added information on such advanced threats during its cybersecurity training sessions for staff held every quarter.

The CSA said it believes the number of ransomware cases may be higher as most cases go unreported. Indeed, the Internet Security Threat Report by Symantec estimates that were an average of 16 ransomware attacks a day in Singapore last year, ranking the country eighth in the region for such threats.

Attackers tend to target businesses rather than individuals as they have more critical information that would compel them to pay up a ransom, an expert told Channel NewsAsia. The hackers are also getting craftier in their tactics. Symantec security advocate Tarun Kaura painted one such scenario. "Let's say I'm a HR professional in a specific enterprise, and I've been given a target for a recruitment drive. I have to hire a few people - it's important because there are deadlines," he said.

"If I go on public social websites saying I'm hiring ... someone (an attacker) can craft an email sending a maybe a resume or information on a talent pool that I would want to look into. That's how they go after certain departments or people in an enterprise - by being more relevant and contextual to a business."

So how can users be on guard for such malicious emails? Mr Kaura advises people to look at the header of the email and scrutinise its contents. "If you see a bit of ambiguity in that in terms of how it's been named and where it's coming from, which domain it's coming from, it is easy for a consumer to figure out that this mail is not coming from a legitimate source.

"You should take a step back and see ... let's not click everything that comes to you."

The CSA said victims of ransomware can lodge a police report, or approach the Singapore Computer Emergency Response Team (SingCERT) for advice.

- CNA/ly


- wong chee tat :)

Tuesday, June 7, 2016

ANGLER EXPLOIT KIT EVADING EMET

ANGLER EXPLOIT KIT EVADING EMET




- wong chee tat :)

'Alarming' rise in ransomware tracked

'Alarming' rise in ransomware tracked

By Mark Ward
Technology correspondent, BBC News
7 June 2016

Cyber-thieves are adopting ransomware in "alarming" numbers, say security researchers.

There are now more than 120 separate families of ransomware, said experts studying the malicious software.

Other researchers have seen a 3,500% increase in the criminal use of net infrastructure that helps run ransomware campaigns.

The rise is driven by the money thieves make with ransomware and the increase in kits that help them snare victims.

Ransomware is malicious software that scrambles the data on a victim's PC and then asks for payment before restoring the data to its original state. The costs of unlocking data vary, with individuals typically paying a few hundred pounds and businesses a few thousand.

Rapid growth

"Ransomware and crypto malware are rising at an alarming rate and show no signs of stopping," said Raj Samani, European technology head for Intel Security.

Ransomware samples seen by his company had risen by more than a quarter in the first three months of 2016, he added.

Mr Samani blamed the rise on the appearance of freely available source code for ransomware and the debut of online services that let amateurs cash in.

Ransomware was easy to use, low risk and offered a high reward, said Bart Parys, a security researcher who helps to maintain a list of the growing numbers of types of this kind of malware.

"The return on investment is very high," he said.

Many cyber-thieves using ransomware demand to be paid in bitcoins

Mr Parys and his colleagues have now logged 124 separate variants of ransomware. Some virulent strains, such as Locky and Cryptolocker, were controlled by individual gangs, he said, but others were being used by people buying the service from an underground market.

"It's safe to say that certain groups are behind several ransomware programs, but not all," he said. "Especially now with Eda and HiddenTear copy and paste ransomware, there are many new, and often unexperienced, cybercriminals."

A separate indicator of the growth of ransomware came from the amount of net infrastructure that gangs behind the malware had been seen using.

The numbers of web domains used to host the information and payment systems had grown 35-fold, said Infoblox in its annual report which monitors these chunks of the net's infrastructure.

"They use it and customise it for each attack, " said Rod Rasmussen, vice-president of security at Infoblox.

"They will have their own command and control infrastructure and they might use it to generate domains for a campaign," he told the BBC. "Then they'll have some kind of payment area that victims can go to."

"The different parts are tied to particular parts of the chain," he said. "Infection, exploitation and ransom."

Hidden files

The spread of ransomware was also being aided by tricks cyber-thieves used to avoid being detected by security software, said Tomer Weingarten, founder of security company SentinelOne.

"Traditional anti-virus software is not effective in dealing with these types of attacks," he said.

The gangs behind the most prevalent ransomware campaigns had got very good at hiding their malicious code, said Mr Weingarten.

"Where we see the innovation is in the infection vector," he said.

SentinelOne had seen gangs using both well-known techniques and novel technical tricks to catch out victims.

A lot of ransomware reached victims via spear-phishing campaigns or booby-trapped adverts, he said, but other gangs used specialised "crypters" and "packers" that made files look benign.

Others relied on inserting malware into working memory so it never reached the parts of a computer on which most security software keeps an eye.

"It's been pretty insane with ransomware recently," he said.



- wong chee tat :)