A new Remote Administration Tool has been discovered called PlugX which is a Remote Access Tool (RAT). It has also been named as Korplug. PlugX has been detected in targeted attacks not only against military,
government or political organizations, but also against more or less
ordinary companies. The attack starts with a phishing email containing a malicious
attachment, usually an archived, bundled or specially crafted document
that exploits either a vulnerability.
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts
Thursday, January 3, 2013
Wednesday, January 2, 2013
Shamoon attack

Overview.
A new malware surfaced during August 2012 as reported by the various security agencies. The malware has been dubbed by the code name "Shamoon". The attack is called "Shamoon", due to a filename i.e. string of a folder name within the malware executable called as Shamoon. ("C:\Shamoon\ArabianGulf\wiper\release\wiper.pdb").The spyware infects all the computers in an internal network.Tuesday, January 1, 2013
Mariposa Botnet
Labels:
BOTS,
Security,
Technology
Friday, April 6, 2012
Sality
Sality is a file-infecting virus that has been around for more than nine years. Sality has been ranked by Symantec as the number one malicious code family in 2010 by number of endpoint detections. It was apparently named after the Russian town of “Salavat City”, although the command and control servers are thought to be in the US, UK, and the Netherlands. It has been used to push spam, steal passwords, crack SIP accounts, and various other nasty things.
Sality is a family of virus. Sality.aa, is a popular polymorphic virus. Sality.aa, was followed by a different version of sality called as Sality.ae. This was built as an entry-point obscuring (EPO) polymorphic file infector, and overwrites files with complex and encrypted code instructions. It creates peer-to-peer (P2P) botnet and receives URLs of additional files to download.
--
Dr.B.M
--
Dr.B.M
Zeus
Zeus, often referred as Zbot is one of the popular crimeware botnet typically engaged in data theft. The term Zeus is used to refer to an entire family of trojans and their respective bot nets. It was reported by 2007.
It installs a rootkit component to remain hidden on infected systems. It is learnt that it disables antivirus and security software in an effort to disguise itself and avoid detection. It is reported that the worm injects itself into the address space of other running processes like Windows Explorer to remain active on infected systems. Refer the article on Zeus in ITNEXT.
It has again reemerged targeting the zero day threat exploited by stuxnet family. Security firm F-Secure has reported the appearance of strains of Zeus exploiting the same security hole exploited by the Stuxnet worm.
Let us Infoledge
--
Dr.B.M
Tuesday, March 20, 2012
Digital Cyber Forensics: Conference related info
The Internet has made it easier to perpetrate crimes by providing criminals an avenue for launching attacks with relative anonymity. It is evident that illegal activities are more often buried into large volumes of data which calls for extensive analysis in order to detect crimes and collect evidence. Most of the time the investigations are of cross-border in nature, requiring coordinated policing efforts in heterogeneous jurisdictions.
ICDFE2C - 4th International Conference on Digital Forensics & Cyber Crime is organized out of US. Details are available at the conference site.
Labels:
Security
Security: Know your APT
Advanced Persistent Threats (APTs) has been estimated to grow faster than other technologies. APT is a a part of the classified category of cyber crime directed at business at large and / or political targets. They are built with a high degree of stealithiness over a prolonged duration of operation in order to be successful. APTs are built with a fixed goal of remaining invisible as long as possible. As such, tahe APT operators tend to focus on “low volume” attacks and over time they would have covered a large area, stealthily crawling from one host to the next as it is being compromised., and ensuring to avoid generating regular or predictable network traffic. Damballa predicts that the volume of persistent attacks directed at large corporations will continue to increase and the victims will continue to feel as though they have been specifically targeted in the year 2012. McaFee is clear in commenting that the solutions in silos don’t enrich each other with relevant data and introduce greater complexity to analysis and remediation, giving the advantage to the perpetrators of the APT.
Labels:
Security,
Technology
Security: Know your DNS
The Domain Name System (DNS), has been defined by RFCs 1034 and 1035. It is a hierarchical, and distributed database used for providing a service to resolve names for various Internet applications. A zone as understood by everybody is a collection of nodes, forming a contiguous tree structure, with the start of authority, or SOA. The purpose of SOA is to delegate the naming authority downward, to delegation points, terminating with leaf nodes. The elements of the SOA are made available from the DNS authority servers to recursive DNS servers.
Whenever DNS is queried, a resolver will traverse the DNS hierarchy and locates the appropriate authoritative DNS server and gets an answer. The resolver executes recursive queries through the hierarchical tree, and eventually reaches the nameserver that is authoritative for the specified query. Once that server is identified, the answer to the query is retrieved by the resolver, completing its query. The deployed DNS infrastructure supports the query, of which Address (A) and Pointer (PTR) are the most common deployed queries.
Whenever DNS is queried, a resolver will traverse the DNS hierarchy and locates the appropriate authoritative DNS server and gets an answer. The resolver executes recursive queries through the hierarchical tree, and eventually reaches the nameserver that is authoritative for the specified query. Once that server is identified, the answer to the query is retrieved by the resolver, completing its query. The deployed DNS infrastructure supports the query, of which Address (A) and Pointer (PTR) are the most common deployed queries.
DNS security as a generic term is used to address the following three functions:
- Zone Transfer Security.
- Dynamic DNS (DDNS) Security. .
- Zone Integrity
Of late there appears to be the start of a different form of attack: the subversion of a host’s correct resolution path. In this attack, the client is directed to use a rogue DNS server, which provides incorrect answers to queries or selective manipulation of answers for the purposes of commercial gain, phishing or other abuse. In most cases, the users have no indication that the DNS answers are not what the correct authoritative DNS servers would provide. A classical example is the Ghost Click described in this blog.
Labels:
BOTS,
Security,
Technology
Sunday, March 18, 2012
Cyber Operations - Ghost Click
The largest internet cyber sting operation taken by FBI was named as Ghost click. Since 2007, a group of cyber group had deployed a special class of malware called DNSChanger. It is understood that the FBI had arrested six Estonians accused of running a botnet that controlled more than 4 million computers in 100 countries equating the infections to approximately 4 million computers. It is estimated that there were more than 500,000 infections in the U.S. alone, in a composition of computers belonging to individuals, businesses, and government agencies such as NASA.
The actual system worked by distributing malware that when installed would change the user's DNS settings to point to the crime ring's rogue DNS network. This malware ensures that cyber surfer visits the URL specified by the cyber criminal. By changing the DNS settings of infected computers, the crooks were redirecting the mouse clicks intended for site A to site B instead. They were converting the advertisements meant for service C into advertisement for service D. When an infected computer clicks the link, the user's computer would go to the criminal's nameserver who would send them to the wrong computer.
Under a court order, expiring July 9, the Internet Systems Consortium is operating replacement DNS servers for the Rove Digital network. A separate DNS Changer Working Group has been formed to handle the situation and clear the machines. This will allow affected networks time to identify infected hosts, and avoid sudden disruption of services to victim machines. It is understood that the efforts to clear the DNS changer malware from the millions of infected PCs has taken a lot longer than expected. Official announcement defines that data of closure of the rogue DNS network to July 9, 2012.
Thursday, March 15, 2012
Digital Warfare - Use of struxnet is a test run or failed mission? Speculations are ON?
The birth of struxnet has opened up an New era of discussions in the security community. Since its discovery earlier this year, the sophisticated Stuxnet worm has infected at least 15 industrial plants in a variety of countries. Security experts have universally accepted that the the worm had the ability to target a specific computer and inflict damage to controls equipment at industrial facilities.
Digital Warfare - Duqu: Struxnet family of BOTS
Duqu, acts as a Trojan, stealing data, potentially acting in the planning stages of an attack. It can be said that DuQu was used as an intelligence gathering tool, possibly aiming to prepare the ground for future attacks. According to Alex Gostev, the main module consists of three components:
- a driver that injects a DLL into system processes;
- a DLL that has an additional module and works with the C&C; and
- a configuration file.
Labels:
BOTS,
Security,
Technology
Wednesday, March 14, 2012
Digital Warfare & Struxnet - Where are we in security?
Labels:
BOTS,
Security,
Technology
Tuesday, March 13, 2012
Cyber threat Stuxnet & Big data analysis
Cyber threat to national economy is an emerging menace. Countries world wide have started realizing this and have taken their stand. What was once a war on the land is getting shadowed as history. The new sophisticated warfare has opted for cyber weapons as their gadgets. For example the same blog has mentioned about Federal Trojan and its capabilities. The Trojan was used to intercept skype transactions and other such online transactions.
The emergence of Stuxnet as repainted the domain with cyber warfare capabilities. Stuxnet by the way has been named as one of the dead least cyber weapon with classical capabilities. It was first reported some where in mid-June by VirusBlokAda, a small security firm based out of Belarus, The worm dubbed as one of the groundbreaking piece of malware, spreads through windows vulnerabilities targeting large-scale industrial control systems. Tireless efforts of various antivirus vendors helped in establishing the fact that Struxnet was in fact holding about four numbers (4) of Zero day threat and were very specific in targeting SCADA machines of a specific make. Craig (McAFee) defines Zero day threat as the availability of an exploit with in the same day of the disclosure of a vulnerability.
With the advent of Struxnet, the world has entered the era of cyber warfare empowering the countries to manage the war from within the four walls of the command control center.
-----Understand your network and baseline it
(Introduction to High Performance Network, TMH)
Saturday, March 3, 2012
Federal Trojan
Federal Trojan aka R2D2 is considered to be one of the SKYPE interceptors as understood from the register. This trojon is also called by other names "0zapftis" or "Bundestrojaner",This trojan has the capability of running on 32 bit systems; with support for 64 bit versions of Windows. The technology works via a local installation of malware on the clients computer. BOTs and Trojans are classified generally under Malware.
According to Chaos Computer Club the specific Trojan has the capability to establish a backdoor on compromised machines supported by keystroke logging. The malware can not only siphon away intimate data but also offers a remote control or backdoor functionality for uploading and executing arbitrary other programs says CCC. R2D2 has the capability of recording Skype conversations.As understood it has the capability to eavesdrop into MSN Messenger and Yahoo Messenger chat clients with the power of key logging on browsers such as Firefox, Opera, Internet Explorer and SeaMonkey. Code injection into target processes is carried out by the dropper, through the use of different dll injection methods
--
Dr.B.M
Tuesday, January 10, 2012
Logs - Sources of Big data
A log as understood is a record of the events occurring within a given organization’s systems and networks when viewed from a system perspective. They are composed of log entries where, each entry is composed of information pertaining to a specific event that has occurred within a system or network. Having matured from a journal today logs contain information related to different types of events occurring within networks and systems. The data present in the log files describe the status of each component and record system operational changes, such as the starting and stopping of services, detection of network applications, software configuration modifications, and software execution errors. Logs are very much part of computing system and cannot be avoided. It is a common understanding that the data generated in the form of log by the existing network devices are a repository of information about the status of the network. Originally, the system of logs were used for troubleshooting problems. However logs now serve many functions within most organizations, such as optimizing system and network performance, recording the actions of users, and providing data useful for investigating malicious activity.
Within an organization, logs contain records related to computer security; common examples of these computer security logs are audit logs that track user authentication attempts and security device logs that record possible attacks. Logs serve the purpose of journal or a day book and hold a record of all transactions that takes place in a network and provide a wellspring of information to help improve security, thus enabling compliance.
Log files are maintained in almost every system and they are usually examined during security audits, either external or internal. Indeed, during regular security audits, log files may be examined and correlated, in order to assure that the intended technical measures are in place and that the security policies and procedures are implemented. During non-scheduled security audits, e.g. as a response to a security incident, log files are analyzed in order to discover the cause of the incident, such as lack of security measures, non-conformance with security procedures or system miss configurations. Such logs form the basis of SIEM vertical. They serve as the source of analysis for a system study with the help of Big data. In other words SIEM is adopting itself to Bigdata.
Sunday, October 16, 2011
Need for 2 Factor Authentication
Cyber Society of India had organized an media awareness workshop on Saturday the 15th October 2011 at Chennai Press Club. The workshop was inaugurated by Dr.Santhosh Babu, IAS, IT secretary to Government of Tamilnadu, More than 30 media professionals participated.
I had an opportunity to address the gathering on the need for 2 factor authentication in bank transactions. Predominantly twin passphrase 2FA is used by banks. The concept of one time password has not been understood by and large. One Time Password system as a second factor authentication increases the transaction safety for netizens. There are different variations of 2FA currently available in the market. The form factor varies from hard tokens to soft tokens. The soft token deployment is aimed at cell phones, laptops and ipads which is a common gadget available with an average citizen. There are other benefits like the ease of deployment and management. The Soft 2FA tokens also reduces the cost to consumer.
The program was over by around 2PM
I had an opportunity to address the gathering on the need for 2 factor authentication in bank transactions. Predominantly twin passphrase 2FA is used by banks. The concept of one time password has not been understood by and large. One Time Password system as a second factor authentication increases the transaction safety for netizens. There are different variations of 2FA currently available in the market. The form factor varies from hard tokens to soft tokens. The soft token deployment is aimed at cell phones, laptops and ipads which is a common gadget available with an average citizen. There are other benefits like the ease of deployment and management. The Soft 2FA tokens also reduces the cost to consumer.
The program was over by around 2PM
Labels:
Security,
Technology
Subscribe to:
Posts (Atom)
















