




版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請(qǐng)進(jìn)行舉報(bào)或認(rèn)領(lǐng)
文檔簡(jiǎn)介
TrackingExploitKitsJohnBambenekManagerofThreatSystemsFidelisCybersecurity?ManagerofThreatSystemswithFidelisCybersecurity?Part-TimeFacultyatUniversityofIllinoisinCS?Providerofopen-sourceintelligencefeeds?Runseveraltakedownorientedgroupsandsurveilthreats?Email:john.bambenek@Whytrackexploitkits?newmalwarealwaysshowsuptotakeitsplace.Whytrackexploitkits??Lawenforcementoperationsforcybercrimetakemonthsoryearsandonlypursuealimitedamountofthreats.?However,almostallcriminalmalwarecomesviatwomethods,spambotnetsorexploitkits.?Whatifyoucouldsmashtheentiremalwaredeliveryecosysteminstead?Whytrackexploitkits??Earlierthisyear,RussianauthoritiesarrestedLurkgroupwhohaddirectconnectionstoAnglerExploitKit(EK)operations.?AnglerEKwentawayovernight.?Priority1:EnsurecurrentproductsdetectnewmalwareandchangesinEKstoprotectcustomers.?Priority2:group.DevelopintelligencetotrackEKoperatorsandcustomerstodisruptanentireecosysteminsteadofonesmallcrimeWhatisanExploitKit??Setoftools(prominentlyweb-based)thatexploitvulnerabilitiesinsoftware(browser,Adobe,Java,etc)tospreadmalware.?Relativelystaticlistofexploitseachkitusesandtheyvary.?Rarely(butsometimes)use0-days.?Theyoperateasacriminalserviceand“sellinfections”ofwhateverprovidedmalware.?Primarydefense:patchyourOSandapplications.?RIGCampaignIDs?Many,butnotall,malwareoperatorsusemultiplemeansofdeliveryandtheycompartmentalizeusingCampaignIDs.?SometimesthecampaignIDreferstoanaffiliate.?Sometimesit’sjustforaspecificrunoftheirmalware.?Correlatingaffiliatesacrossmalwaredeliverymechanismscanprovideinterestinginsightsintothemarketplacebehindthemalwaredelivery.re?Takingdataderivedfrommalware,youcanripconfigsandgetinformation.?Spokeaboutthisherelastyear.?Cross-correlatebasedondeliverymethodandnowyouhaveinsightinwhoisbuyingservicefromwhom.?NowyouhaverawbuildingblocksforanoperationsimilartowhatRussiadidtotheLurkgroupthatendedAngler.?Victimclickson(usuallycompromised)webpage.?Thereisvalidationofsuitability.?Geo-blacklisting?Likelyvulnerablebrowser?Blacklistingofsuspectedsandboxes,securityresearchers?Victimisdirectedtoactualexploit.?Victimdownloadsandinstallsmalware.MagnitudetoCerberexampleFrom–hasgreatblogsonEKtrafficExploitKitURLsoftenhavepatterns?SomeolderNuclearEKURLpatternsinPCRE:?\.(su|ru)\/mod\_articles-auth.*\d\/(ajax|jquery)\/\/b\/shoe\/[0-9]{4,10}?^[^\/\n]{1,99}?\/url\?([\w]+=([\w\.]+)?&){5,10}url=https:\/\/[\w]+\.[a-z]{2,3}&([\w]+=([\w\.]+)?&){2,6}[\w]+=[\w\.]+$?^[^\/\n]{1,99}?\/search\?(?=.*[a-z]+=utf-8&)(?=.*ei=.*(\p{Ll}\p{Lu}|\p{Lu}\p{Ll}))(?=.*ei=.{20,})(?!=\/)([a-z_]{1,8}=[\w\+-\.\x20]+&?){2,5}$?^[^\/\n]{1,99}?\/(?-i)([a-z0-9]+\/){0,3}\d{2,3}(_|-)[a-z]+(_|-)\d+\.[a-z]{3,6}$?^[^\/\n]{1,99}?\/(?-i)([a-z0-9]+\/){0,3}[a-z-]+\?(([a-z_-]|[0-9]){3,}=([a-z_-]|[0-9]){3,}&){1,5}[a-z0-9_-]{2,}=[a-z0-9]{8,}$Non-AttributableNetworks?EKsdohaveatendencytoblockobvioussecurityresearchersandsecuritycompanynetblocks.?Theydon’tdoagoodjobblockingcommodityVPNservices.?Youcanpickwhatcountryyouwanttoappearfrom.?StilllimitstowhatyoucanretrieveusingaVPN.?VPNinsideoroutsidecuckooVM?Non-AttributableNetworksNon-AttributableNetwork?Atpresent,thereisnoeasycentralwaytomanagemultiplecuckooinstancesthatreachouttomultiplegeographiesfromthesameinstance.?SolutionistorunmultiplephysicalcuckooinstanceswithVPNoutsidetheVMandrotateIPsinsideageoeachbatchrun.?Eachexploitkithasapartiallyoverlappingbutuniquesetofexploitstheyuse.?Togetcuckootoexecutetheexploit,somecareneedstobespentinchoosingtheimagesandvulnerablesoftwarebasedonexploitkit.?Anoldertrackingspreadsheetisavailableat:/spreadsheet/ccc?key=0AjvsQV3iSLa1dE9EVGhjeUhvQTNReko3c2xhTmphLUE#gid=10butanewversionshouldbeatContagioDsoon.?EasiestwayistohaveasetofVMimagesforspecificexploitkits.?Stillneedtomonitorforadditionofnewexploits.?0-dayshappenmaybeonceayear.DecodingEKlandingpages?Opensourcetoolsavailablehere:/mak/ekdecoforNeutrino,NuclearandAngler.?Canexportconfigandencryptionkeys,intermediateflashfiles,andtheexploitoutputsthatareusedandsavethosetofiles.?RequireslandingpagesorfirstSWFfile(availableinPCAPorviaCuckoo).?$pythonneutrino.py-dout-e-istrong-special-green-tread-motive-happiness-warm-stre-slap-happy.swf?[+]embededswf(SHA256:d977a418fa1cf5a0a78c768fade3223ead531ee25d766fa64a2e27ade0616a82)extracted,andsavedtoout/d977a418fa1cf5a0a78c768fade3223ead531ee25d766fa64a2e27ade0616a82.swf?[+]cfgkey:uturwhahhdm820991,exploitkey:czynukeclllu385015?{u'debug':{u'flash':False},?u'exploit':{u'nw22':{u'enabled':True},?u'nw23':{u'enabled':True},?u'nw24':{u'enabled':True},?u'nw25':{u'enabled':True},?u'nw8':{u'enabled':True}},?u'key':{u'payload':u'yykrnnfwet'},?u'link':{u'backUrl':u'',?u'bot':u'http://muusikkopruflin.earclearclinic.co.uk/1994/05/16/jump/loom/have-september-meal-borrow-normal.html',?u'flPing':u'http://muusikkopruflin.earclearclinic.co.uk/wobbler/1440055/carrot-every-hasten',?u'jsPing':u'http://muusikkopruflin.earclearclinic.co.uk/1978/12/12/alley/knock-trial-guilty-knee-younger-sigh-suffer-fault-lamp.html',?u'pnw22':u'http://muusikkopruflin.earclearclinic.co.uk/dull/aXF4Y21nYw',?u'pnw23':u'http://muusikkopruflin.earclearclinic.co.uk/consciousness/clever-13253660',?u'pnw24':u'http://muusikkopruflin.earclearclinic.co.uk/hospital/d2dxY3dkZw',?u'pnw25':u'http://muusikkopruflin.earclearclinic.co.uk/disappointment/battle-31593215',?u'pnw8':u'http://muusikkopruflin.earclearclinic.co.uk/another/hideous-33550406',?u'soft':u'http://muusikkopruflin.earclearclinic.co.uk/belong/animal-none-western-14473008'},?u'marker':u'rtConfig'}?[+]Exploitsavedto….?$xxd7ccc54cd4e819ee0a8b291917cf321acc058ccc6e4d35ad6f21db09491e05332.ek.bin?0000000:5a575312c7410000682000005d000020ZWS..A..h..]..?0000010:00003bfffc8e19fadfe76608a03d3e85..;f..=>.?0000020:f5756fd07e61351b1a8b164ddf0532fe.uo.~a5M..2.?0000030:a44c4649b77b6b75f92b5c37290b9137.LFI.{ku.+\7)..7?0000040:01370ee9f2e1fc9e64da6c112133eda0.7d.l.!3..?0000050:0e7670a0cd982e7680f0e059560608e9.vpv...YV...?0000060:caeba2c6db5a867b47de995d68763816Z.{G..]hv8.?0000070:bd933cd3d09ed355635adab0db27e67c..<UcZ...'.|?0000080:213daccc90a176587308c85895d6680b!=vXs..X..h.?0000090:f2b8c7c712554087e759c04edf21aee8U@..Y.N.!..?00000a0:a06a8ec4ecd83838a5f455b9284e31d5.j88..U.(N1.?00000b0:12565f00c2ea9c36e8beb7105aa62909.V_6Z.).?00000c0:3d4934711ec514ee224f7b3140e3fb00=I4q"O{1@...?00000d0:d5f1bfe22fbe445810a801f43108fa24/.DX1..$e:0d9aaefdc5cfcfa2350baeeddc4139c8 5A9. OtherCuckooconsiderations?Cuckoostorestonsofinformation,butforEKsweareonlyinterestedingettingthedroppedbinary.?Turnoffalltheloggingexceptthatdirectlyrelatedtodroppedfiles.?RunningYaraandusingvolatilitycanhelpquicklyidentifydroppedfiles.?Remember,useanon-attributablenetwork.:)FindingEKlandingpages?Allthisautomationstillhastobefedwithtargetstosandbox.?Workbackwardsfromaninfectionevent.?Usewebproxylogs/telemetryandPCREs.?Useacrawler.?TrickEKtogiveyoutheinitialgates.Workingbackwardsfromaninfection?Leastefficientwayofdoingitbutinsomecases(newEK,significantchangestoanexistingEK)it’sallwecando.?Initialgatesaretransientresources,somanuallyidentifyingthemhaslimitedutility.?Alsolimitedonlybywhatisattackingyouoryourcustomer.ngPCREstohunt?Stillrequiresuserstovisitbutcanbeprogrammaticallypipelinedintoasandboxsystemforrelativelyrealtimeanalysis.?Everyonehasauser-baseandtelemetrythathasgeographicordemographicbiasesthatcreateholesinvisibility.?Inefficientbecauseitwillrequestmorethanwhatyouarelookingfor.?Crawlersarealsoresourceintensivethebroaderyouarelookingforbehavior.?Itcan,however,haveaglobalfootprintandbethorough.?Luckily,wedon’thavetomakeourowncrawlerwhenMicrosoftwillgiveBingcrawlermaliciousURLstoMAPP/VIAmembers.?On4August2016,over26MmaliciouswebpageswereseenwhichMicrosoftgivesa99%confidenceintervaltoo.?MuchmorethanEKs.UsingBingMaliciousURLs8/4/20164:58:27PMhttp://0000-.ar/2011/03/my-defragmenter-ydefragmenteresklinkswidgetIdBlogwidgetTypeBlogresponseTypejspostID.58.216.193us15169MalwareNetwork8/4/20164:51:46PMhttp://0000-.ar/2011/03/pocopique-tv-rogramaparavertvhtmlactionbacklinkswidgetIdBlog1&widgetType=Blog&responseType=js&postID=78418329us15169ES8/4/20166:06:13PMhttp://0000-.ar/2011/07/reparacion-de-8/4/20166:26:04PMhttp://0000-.ar/2011_02_24_archive.html8/4/20164:34:23PMhttp://0000-.es/2011/02/descarga-chat-para-facebook.html?action=backlinks&widgetId=Blog1&widgetType=Blog&responseType=js&postID=ousURLs?On4August,524,713ofthoseURLspointedtoIPsinsideChina.?NumberismisleadingbecauseitincludesmultipleURLsundersamedomain.?Alsoflags“interesting”advertiserbehavior.?NeedtofilterbasedonthePCREswehaveseenbeforeorotheralertingtechnology.?WearerunningalltheseURLsthroughcURLwithaspoofeduseragentjusttoseerequestandfirstresponse.URLs?Dealingwithcompromisedwebsitesandbulkmaliciousbehaviorishardtodo.?Withproperfilteringoftheabove,italsobecomespossibletoprogrammaticallystartdersofsuchcontentsotheycanstartcleaningthesewebsitesowserversNetblockReportingServicetogetalertsonmaliciousactivityseenonyournetwork.ousURLsingmUrlstsvhttp://melnoosh.narod.ru/p3aa1.html/indexEN.htmlhttp://peterbronkhorst.rusa.nl/pag013l.htm/vk3en62w.htmhttp://portvein777.narod.ru/MirChiselChast10.htmhttp://portvein777.narod.ru/MirChiselChast26.htm/fadi7a.htmlhttp://re
溫馨提示
- 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請(qǐng)下載最新的WinRAR軟件解壓。
- 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請(qǐng)聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
- 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會(huì)有圖紙預(yù)覽,若沒有圖紙預(yù)覽就沒有圖紙。
- 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
- 5. 人人文庫網(wǎng)僅提供信息存儲(chǔ)空間,僅對(duì)用戶上傳內(nèi)容的表現(xiàn)方式做保護(hù)處理,對(duì)用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對(duì)任何下載內(nèi)容負(fù)責(zé)。
- 6. 下載文件中如有侵權(quán)或不適當(dāng)內(nèi)容,請(qǐng)與我們聯(lián)系,我們立即糾正。
- 7. 本站不保證下載資源的準(zhǔn)確性、安全性和完整性, 同時(shí)也不承擔(dān)用戶因使用這些下載資源對(duì)自己和他人造成任何形式的傷害或損失。
最新文檔
- 房地產(chǎn)項(xiàng)目策劃與營(yíng)銷實(shí)戰(zhàn)模擬試卷
- 清潔能源技術(shù)推廣與應(yīng)用計(jì)劃
- 古典小說情節(jié)結(jié)構(gòu)與語言特色分析
- 《高中生物分子結(jié)構(gòu)特點(diǎn)探究教案》
- plus-Secolongifolene-diol-生命科學(xué)試劑-MCE
- Hsp90-IN-36-生命科學(xué)試劑-MCE
- 股權(quán)分配與利益共享協(xié)議
- Antioxidant-agent-20-生命科學(xué)試劑-MCE
- 委托培訓(xùn)班協(xié)議書
- 《昆蟲的種類與特點(diǎn):生物學(xué)入門知識(shí)教案》
- GB/T 5023.5-2008額定電壓450/750 V及以下聚氯乙烯絕緣電纜第5部分:軟電纜(軟線)
- GB/T 4292-2017氟化鋁
- GB/T 41-20161型六角螺母C級(jí)
- GB/T 3811-2008起重機(jī)設(shè)計(jì)規(guī)范
- GB/T 19477-2018畜禽屠宰操作規(guī)程牛
- GB/T 16451-2008天然脂肪醇
- 中國(guó)高分子院士簡(jiǎn)介
- CB/T 615-1995船底吸入格柵
- 施工圖紙接收及分發(fā)臺(tái)賬
- 物流系統(tǒng)建模與仿真課件
- 小??Х仍耘嗉夹g(shù)措施課件
評(píng)論
0/150
提交評(píng)論