Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Thursday, October 20, 2016

CryptoMalware Resources

Some resources for CryptoMalware Detection, Prevention, and Remediation

Presy Slides (updated periodically): http://www.slideshare.net/AaronLancaster3/why-are-you-still-getting-cryptolocker

ISSA Journal April 2016 Feature Article - CryptoLocker by Carl Saiyed

Prevention
J. Wolfgang Goerlich Preparing for malware - https://t.co/yn0CVpMtu6
FREE Training Course: https://info.varonis.com/introduction-to-ransomware

FBI IC3:
Ransomware Tri-fold: https://pdf.ic3.gov/Ransomware_Trifold_e-version.pdf
Sept. 2016 Advisory: https://www.ic3.gov/media/2016/160915.aspx

Microsoft Articles:
https://www.microsoft.com/security/portal/threat/encyclopedia/Entry.aspx?Name=Win32/Crowti 
http://blogs.technet.com/b/mmpc/archive/2015/07/14/msrt-july-2015-crowti.aspx 
https://www.microsoft.com/security/portal/mmpc/shared/prevention.aspx

Expert Analysis:


CryptoLocker Prevention Kit: http://www.thirdtier.net/2013/10/cryptolocker-prevention-kit-updates/
CryptoPrevent (workstations only): https://www.foolishit.com/cryptoprevent-malware-prevention/

BLADE (Block All Drive-by Download Exploits): www.blade-defender.org

Detection
Traffic Analysis:
Expert Analysis:
Microsoft Server Techniques:

Remediation

https://www.nomoreransom.org/

Utilities and regain access to your files:

Attempt to retrieve your keys from:
FireEye’s website http://www.decryptcryptolocker.com/
Kaspersky’s Website: https://noransom.kaspersky.com/

Other References
CoinVault and Bitcryptor keys & app: https://noransom.kaspersky.com/
Scripts and Files related to the CyyptoWall v.3 threat: https://github.com/CyberThreatAlliance/cryptowall_v3
CryptoLocker Scan Tool by Omnispear: http://omnispear.com/cryptolocker-scan-tool/

Using PowerShell to Combat CryptoLocker: http://blog.varonis.com/using-powershell-combat-cryptolocker/

Thursday, September 15, 2016

FBI Asking for Ransomware Reports

In an FBI Public Service Announcement published today the Bureau is requesting that vicitims of ransomware report what hit them, the rootcause and even what they paid out in ransom.

NOTE: Please be advised that the FBI is not duty bound to protect your information and you should consider the effects to your company should the FBI choose to make that info public.

From the FBI PSA:

What to Report to Law Enforcement

The FBI is requesting victims reach out to their local FBI office and/or file a complaint with the Internet Crime Complaint Center, at www.IC3.gov, with the following ransomware infection details (as applicable):
  1. Date of Infection
  2. Ransomware Variant (identified on the ransom page or by the encrypted file extension)
  3. Victim Company Information (industry type, business size, etc.)
  4. How the Infection Occurred (link in e-mail, browsing the Internet, etc.)
  5. Requested Ransom Amount
  6. Actor’s Bitcoin Wallet Address (may be listed on the ransom page)
  7. Ransom Amount Paid (if any)
  8. Overall Losses Associated with a Ransomware Infection (including the ransom amount)
  9. Victim Impact Statement

This is a lot of data considering the massive amount of data already available from the Cyber Threat Alliance's study and subsequent analysis report of CryptoWall v3 less than a year ago and their live dashboard.

Tuesday, May 31, 2016

BSides Knoxville 2016: CryptoMalware Talk

Had a great time presenting at BSides Knoxville 2016: CryptoMalware: The persistent, ubiquitious threat:

*update*
ICYMI: Watch the YouTube video of my presentation: https://www.youtube.com/watch?v=6dP5Zt49uA8

I'm greatly looking forward to next year!

Wednesday, May 18, 2016

Moving from RansomWare to LeakWare

One of the trends I have observed on the Cyber Security threat landscape is the movement from "Ransonware" like CyrptoLocker, TeslaCrypt and CryptoWall to a new category of malware I am calling "LeakWare." This is a distinct category of malware that needs its own category, defenses and and special attention.

Simply defined, we can expect LeakWare will hold a user or company's data for ransom (maybe, probably) and if the ransom is not paid the data will then be leaked to the world via sites like pastebin, wikileaks, and others. The aim here is to up the ante beyond merely data loss to data exposure. Imagine the Sony-like impact of this potentially life/business-ending exposure. This will merit new and special attention to defense and prevention further driving the market for new and innovative technologies to guard against this and previously-seen  similar threats.