About

Tuesday, October 2, 2018

Analysis of recent Swizzor variant (aka) Stealer:

Overview

Trojan Swizzor variants having detection since early 2004 and it works by downloading and executing malicious files from the Internet on the infected machine. The primary channel of infection for Swizzor family is the internet. And it is known for stealing of personal data. In this case, our researcher monitored a malicious traffic and spotted the Swizzor binary as the downloaded file.

Analysis

While monitoring the traffic, we got an alert triggered by suspicious website communication. The suspicious websites are stored in our threat intelligence malicious website list which triggered by our rule.
Our rule picked the communication happened in the following URL:


hxxp://Judoalmoradi(.)com/LOGOS/puttyupdate45


So we managed to perform incident response activity in the host machine which connects to the malicious URL. We gathered the timeline analysis information from the host machine. During the timeline analysis, we spotted the process puttyupdate459.exe is found in the memory. The sample is taken for malware analysis:
File Hash: d85fa670e482083d83c7cfdea08b65729378b02b2dc31f009350f6385a459809
File Size: 227.5 KB 

Figure 1 Compiled using VC++

We are done with the execution of the specimen in the controlled environment and observer its behavior. The malicious process started querying general information on the file system and registry system.

Figure 2 Execution of malware - loaded in memory and starts querying
Then it creates a thread and which got the exit. That creation of a thread is logged as an event and we checked the properties of the event. 

Figure 3 Thread creation

Figure 4 Thread creation event
This unknown module in the stack appears to be suspicious and didn’t have any file path. The malicious process is creating a file in the temp location and writing the content to the file ‘A45F.bin’.

Figure 5 puttyupdate459.exe queries the computer name details and it creates a file in Temp location
It also queries for the presence of certain registry keys as follows, but they are not found:


puttyupdate459.exe      992         RegOpenKey     HKCU\Software\Classes\AppID\puttyupdate459.exe
NAME NOT FOUND         Desired Access: Read
puttyupdate459.exe      992         RegOpenKey     HKCR\AppID\puttyupdate459.exe          
NAME NOT FOUND         Desired Access: Read

This is due to the fact there will be a parent file which usually registers the entries for the downloaded malware. We open the .bin file in the temp location and it contains the following details:
Figure 6 A45F.bin file in the temp location



It keeps gets incremented the lines ‘LdrLoadFile’ and also we noticed each time iexplorer.exe loaded in the memory and get terminated. Each time the termination happen the increment of lines in bin file at temp location. 

Timeline analysis

With this analysis, we unable to observe complete behavior. So our incident response team run the redline script and collected the analysis session of the infected machine. During the redline analysis, we found the parent file which contains the above malicious URL: 
hxxp://Judoalmoradi(.)com/LOGOS/puttyupdate459

This malicious URL was used to download the puttyupdate459.exe file. The parent file details are:
SHA256: 21fc447f95143fd8595d364e526bb726d2e3e52983aebe2c1ae5d49d4e6e96f5

Figure 7 Parent file - Ursnif/Swizzor/Password Stealer

The parent file got password stealer, Pws (PSW), Swizzor and Ursnif detection. It is very much clear that our team made better incident response activity and found the file.

Reason for file not detected by AV?

Most of the AV vendors are detecting the parent file (SHA256: 21fc447f95143fd8595d364e526bb726d2e3e52983aebe2c1ae5d49d4e6e96f5) and downloaded file (puttyupdate459.exe). But when we found that the infected network infrastructure didn’t follow many best practices and the AV database where failed in definition update for several weeks. And we also collected their AV logs for log analysis, the AV actually triggered the alert on termination of on-access scan and AV shield processes. 
If they followed the best practices and proper monitoring facility, this infection could be avoided. 


Research and post were done by


IOC details:

URL
  • Judoalmoradi(.)com/LOGOS/puttyupdate45


File Hashes
  • 21fc447f95143fd8595d364e526bb726d2e3e52983aebe2c1ae5d49d4e6e96f5
  • d85fa670e482083d83c7cfdea08b65729378b02b2dc31f009350f6385a459809

Monday, September 17, 2018

Mirai Botnet: Sale in the dark web:

An IoT botnet is a collection of compromised IoT devices such as routers, cameras, wearables and other embedded technology that is infected with malware. It permits an attacker to hold them and carry out tasks just like a traditional PC botnet. They have been behind some of the most damaging cyberattacks versus organizations around the globe, including hospitals, national transport links, communication companies, and political movements.

Indicator of compromise 
Currently, we got a list of the suspicious domain, please use them to detect Mirai botnet

  • godnet[.]godnigga[.]eu
  • nexusaquariums[.]ir
  • miraibotnet[.]cf
  • power4you[.]ddns[.]net
  • serversrus[.]club
  • santasbigcandycane[.]cx
  • network[.]bigbotpein[.]com
  • proxy[.]bigbotpein[.]com
  • cnc[.]smokemethallday[.]tk
  • report[.]smokemethallday[.]tk
  • misaboatnet[.]pw
  • snicker[.]ir
  • dopeassnet[.]tk
  • scan[.]snowondex[.]org
  • back[.]uu8889[.]com
  • rpt[.]uu8889[.]com
  • 165[.]227[.]220[.]202
  • thonder[.]club
  • flapik[.]pro
  • blueandsausesfries[.]us
  • smithre[.]top
  • bursts[.]pro
  • nnn[.]shenron[.]pw
  • rrr[.]shenron[.]pw
  • zetastress[.]net
  • scan[.]snowondex[.]net


Recent trends:
Very recently, malware researcher spotted the Mirai botnet sale in the dark web. Please refer the following snapshot of the sale in the dark web.

MIRAI SALE IN DARK WEB
This sale is a wake-up call for organization around the world to combat against Mirai Botnet. If the sale is high then it will be disastrous due to the range of attack.

Post made by
newWorld


NOTE: Please keep up the general advice to be followed:

  • Change the default OEM credentials and ensure that passwords meet the minimum complexity.
  • Disable Universal Plug and Play (UPnP) unless absolutely necessary. Implement account lockout policies to reduce the risk of brute forcing attacks.
  • Telnet and SSH should be disabled on the device if there is no requirement of remote management.
  • Configure VPN and SSH to access device if remote access is required.
  • Configure certificate-based authentication for telnet client for remote management of devices.



Thursday, September 13, 2018

IBM 3380 - World's First GB Disk Drive (1980)

The IBM 3380 was the world's first gigabyte-capacity disk drive (1980). Two 1.26 GB, head disk assemblies (essentially two HDDs) were packaged in a cabinet the size of a refrigerator, weighed 455 kg (1000 lb), and had a price tag of 81,000 USD (Model B4) which is 240,579 USD for today, taking inflation in the calculation.
post by
newWorld

Tuesday, September 4, 2018

foldable Smartphone!? What year is it?

Samsung is setting up to launch a foldable smartphone later this year. Samsung CEO DJ Koh implied the gadget could be revealed at Samsung’s developer conference which going to be held in November. Samsung CEO acknowledged that this gadget is not easy to design, with the help of the hard works of engineers, designers it actually achieved this milestone. There is a talk going in the mobile phone industry as Samsung will launch this mystic gadget under the Galaxy Note family.




Samsung is not the only one to tap this height, other competitors also trying the similar designs in smartphone and TV.



The future is near!!!



Post by

Saturday, September 1, 2018

Arnold Sleeping under statue: Is he really not getting hotel room?

There is a post on facebook which revolves around more than years which attracts many users to share it on their walls. Let's see what is the post about:


Famed actor Arnold Schwarzenegger posted a photo of himself sleeping on the street under his famous bronze statue, and sadly wrote "How times have changed"...
The reason he wrote the phrase was not only because he was old, but because when he was governor of California he inaugurated a hotel with his statue. Hotel staff told Arnold, "at any moment you can come and have a room reserved for you." when Arnold stepped down as governor and went to the hotel, the administration refused to give him a room arguing that he should pay for it, since they were in great demand.
He brought a sleeping bag and stood underneath the statue and explained what he wanted to convey: "When I was in an important position, they always complimented me, and when I lost this position, they forgot about me and did not keep their promise. Do not trust your position or the amount of money you have, nor your power, nor your intelligence, it will not last. "
Trying to teach everyone that when you're "Important" in the people's eyes , everyone is your "Friend " But once you don't benefit their interests , you won't matter.
" You are not always who you think you will always be, nothing lasts forever."


One of our members is a great fan of Arnold Schwarzenegger and he follows all his news on the daily basis. We showed this post and he shouted this is fabricated story. He shared the real Instagram post from Arnold Schwarzenegger and the truth is:

https://www.instagram.com/p/BAkk4zFjce-/?taken-by=schwarzenegger

Arnold mentioned it as how times have changed and the rest of the stories revolving around in the social media is fake.

Fact Check:
The post mentioned it as the hotel in California. But this photo was taken in Greater Columbus Convention Center, Ohio.


Post made by
newWorld

Monday, August 20, 2018

Analysis of Tinba Malware (banker)


Overview

Our newWorld researcher spotted a malicious URL during the threat hunting activity. So they started to inspect the host which contacting the malicious domain. While inspecting the spotted an executable which connecting to the malicious site. Our researcher collected the suspected file and copied that for analysis.

Specimen analysis

File type:              PE (Exe)
Hash (SHA 256): 092d20f9d0c805802da89a801ca11db56d1a31727cfd7b040b7ced5037ded18b

File Size:              133 KB


Compiler details

This sample was loaded in the debugger to understand its functionality. We spotted the ‘DragAcceptFiles’ function, this identifier of the window that is registering whether it will accept dropped files.

DragAcceptFiles
The sample does process injection by injecting into explorer.exe, winver.exe, and other remote processes. We observed the network packet:



hxxp://brureservtestot(.)cc

This is the malicious URL we spotted during our threat hunting. Many vendors are blocking this as a malicious site. We checked the hash of our specimen in VT search and it found to be banker- Tinba detection. 

Conclusion
Maintaining best security practice is the key for fighting this sort of malware. Keeping all the security patches up to date is highly recommended.

Post by

Friday, August 17, 2018

Interesting facts (for Indians) on network switches

Network switches play important role in enabling the communication between the devices in the network. Switches manage the data across a computer network by engaging the received packet to the intended device. Usually, the switches are functions in the data link layer but some of the multilayer switches are processing in layer 3 of the OSI model.





One of the interesting fact for Indian people that first multiport Ethernet switch was manufactured by a company called Kalpana in the year 1989. Kalpana was founded Vinod Bhardwaj and Larry Blair in the 1980s and the name Kalpana was after the Bhardwaj’s wife, meaning imagination in Sanskrit. This innovation leads to Ethernet networks operate as faster and easier way. They also invented EtherChannel to provide higher bandwidth in inter-switch at running many links in parallel, which is referred to as link aggregation.

If Kalpana is pioneering the switches and other network equipment manufacturing then why no one heard about Kalpana now?


Because the giant Cisco acquired the Kalpana in the year 1994 and their achievements are now in the shadow of Cisco.

Post by

Thursday, August 9, 2018

Outlook Mail Search Options are not working?

Overview
One of my friend who comes over to me asking that his outlook search option is not working. I went to his desk and checked his laptop. The search option in the mailbox got disabled and it got overshadowed by the grey color. I resolved the problem and the search option in the outlook started working fine. I thought it will be nice if I share this to newWorld team post it in their site.

Solution
- First of close the outlook.
- Open the services file (services.msc)
[To open that we must first open run window and type services.msc]



- Go to the windows search (refer the snapshot)


- If this windows search is not up and running, please make it to running state.
- If this windows search is running and the status of Automatic or Automatic (Delayed start), the search option will work fine.

Now, open the outlook program and check for the search option, it will work fine!!!

Post by
newWorld


Thursday, July 26, 2018

How To Prepare for Sans GREM:

Sans certification is one of the reputed certifications in the security domain. Recently one of my friend who completed GREM successfully. When I was discussing with my malware analyst friend regarding how he is doing after the GREM certification. He told me that he usually at least 100 messages per month on how to pass GREM exam, what are the things need to be prepared for the GREM exam, etc.

So I told him to why you can’t write some helpful tips who preparing for GREM certification. He agreed to my idea and shared his input and our newWorld team created this article:
How to get GREM certification?

First of all, we want to separate the readers based on their level:

Malware analyst - Already working in Antivirus or cybersecurity role at any firm:

For you guys, GREM certification is not as tough as you think.
Please go through books like Malware analyst cookbook, practical malware analysis,
windows internals, and IDA pro book.
This is more than enough to get a good score.
Additionally, you need to familiarize with remnux VM and all the tools.

  • While going for the exam, bring all the cheat sheets from Lenny Zeltser, creator of remnux and additionally, he teaches the GREM course in SANS (five-day course).
  • All SANS exams are open book test, so it is good to bring all your notes and cheat sheets.
  • Arrange all the notes in proper order and segregate it based on the types, it is good to keep an index for that collection.
  • For eg:
  • All plugins and tricks related to Olly dbg should be aligned under one section as windows PE analysis.
  • All the windows internals related notes under OS concepts.
  • All volatility plugins related notes under memory forensics.
  • RTF malware, docs, ppt, macro malware notes should come under windows document malware and it should fall under NON-PE files.
  • For NON-PE files, you can add all your notes about flash file analysis, malicious pdf file analysis, and tools used office file analysis.


Malware analyst category is over!!!


Let's go for people in the security domain - but wants to done GREM:
(Condition: Willing to spend money on training)

Personally, it is good to take a course offered by SANS which is super good and helpful.
In case, if you are busy and not able to take a five-day course, you can go for the on-demand course from SANS.

After your training finish, start to dissect the malware in a controlled environment and take notes.
While analyzing the malware, please not just turn your focus in PE file but try to work on all the malware files (non-pe: such as js, pdf, office malware, malicious HTML).

You have one advantage here that you can get the proper study material which can be referred to during your exam. So you just need to put proper index for all the study materials.
Also, bring the cheat sheets with you and that will help.



Next category: Not having enough money to afford the training, but want to complete GREM.

For this, you need to spend quality time on self-learning on malware analysis.
Steps:
Start reading all the books which mentioned in the malware analyst section.
Install VMware in your home machine with remnux image and windows image (good to use windows 7 with Flare from Fire Eye).
Practice each and every tool mentioned in the books and tools listed in the Fire Eye flare.
Get familiar with Sysinternals tools - for viewing the process, listening to the ports, packet sniffing tools, etc.





At least you need 1000 hours to spend on this so that you will get familiar.

After you familiarize with all these, go for an exam where you will get two practice test.
After attending the first practice test, you will understand the intensity of the SANS exam.
You have four months time to for facing the exam. So these practice test will give you a good idea on how the exams will be?



All the best for your dream and one day it will come true.

Post by 
  

Wednesday, May 23, 2018

How attacker alter the history in Linux:

During incident response and threat hunting activity, the analyst collects important artifacts, logs from the suspected system or victim machine. When the Linux environment as the infected device OS, then executed commands list by attackers will give you the detail of how infection flows into the system. In order to get that list 'History' is the command used to get the list.

Let's see how attacker modifies the history:

entering the first command

For instance, I try to print a sentence as "this is hacker" using echo command.

the command for printing the message done


Once print was done then check the history. It shows the echo command as the serial number 595.

History list



Now go back to the terminal and press upper arrow where we find the echo "this is hacker" statement. Just backspace that content and rewrite whatever you wish. In this case, I wrote, "this is not hacker". But don't enter that command, just push the down arrow and go for empty command. Hit the history and check the list.



 Currently, we unable to see the 595 serial number content as "this is hacker". Now it is showing 595* "this is not hacker". This is how the attacker will edit the history.




Reason for asterisk symbol in the Linux history:
The star or asterisk symbol in the serial number at the history, it is the indication of modified history.


Post made by
newWorld

Monday, May 14, 2018

Usoclient.exe Command window popup

One of my juniors complained me that his system behaves weird today. He told me a command window popup mentioned as usoclient.exe from the system32 location (that is easily seen in the title bar). I convinced him this is a legitimate process only no need to worry about. In case if the same process run from some other location like temp folder, app data then it could be malicious. For a normal user, if a command window popped and closing will give the feel of malware is running in the system. If you also got the same usoclient.exe in the command window popup and closed, no need to worry about it. 

Administrative Tools

Open the administrative tools in the control panel, you can find the task scheduler file. I asked him to open that where he can find usoclient.exe under Microsoft->Windows->UpdateOrchestrator.

Task Scheduler

Schedule Scan - Usoclient.exe

Usoclient is a legitimate process if you see it in windows/system32 folder. If it is running in suspicious location then we can flag that process as malicious one. 


Post by

Status of api.ipify.org — Part 2: 2026 Verdict Update

Status of api.ipify.org — Part 2: 2026 Verdict Update | Hunt. Analyze. Respond. Repeat. ∞ Hunt. Analyze. Respond. Repeat. ...