Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
tech_scareware_presentation.pdf
Search
Sponsored
·
Your Podcast. Everywhere. Effortlessly.
Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
→
hexadecim8
September 10, 2018
0
250
tech_scareware_presentation.pdf
hexadecim8
September 10, 2018
Tweet
Share
Featured
See All Featured
Build The Right Thing And Hit Your Dates
maggiecrowley
38
3k
Reflections from 52 weeks, 52 projects
jeffersonlam
356
21k
Faster Mobile Websites
deanohume
310
31k
Visualization
eitanlees
150
17k
The State of eCommerce SEO: How to Win in Today's Products SERPs - #SEOweek
aleyda
2
9.5k
Designing Dashboards & Data Visualisations in Web Apps
destraynor
231
54k
Bridging the Design Gap: How Collaborative Modelling removes blockers to flow between stakeholders and teams @FastFlow conf
baasie
0
450
Learning to Love Humans: Emotional Interface Design
aarron
275
41k
Jess Joyce - The Pitfalls of Following Frameworks
techseoconnect
PRO
1
64
Tell your own story through comics
letsgokoyo
1
810
B2B Lead Gen: Tactics, Traps & Triumph
marketingsoph
0
53
GitHub's CSS Performance
jonrohan
1032
470k
Transcript
ANATOMY OF A MASSIVE MALWARE DISTRIBUTION CAMPAIGN A brief taxonomy
of SLOR Tools, Techniques & Procedures
INTRODUCTION Emily Crose Network Threat Hunter Ironnet Cybersecurity Twitter: @hexadecim8
SLOR …But also a malware distribution campaign
IT STARTS WITH A THREAD…
THE FOUR W’S What the fuck is this shit? Where
the fuck is this shit coming from? Who the fuck is doing this shit? Why the fuck is it doing this shit?
WARNING There will be swears in this presentation
Network active ping port scan URL Fuzzing Banner Grabbing passive
whois Centralops.net Domain tools Reputation checks virustotal registration pivoting RiskIQ PassiveDNS File Forensics file reputation file hash Sandbox analysis Hybrid-analysis
None
None
WHO TF IS DOING THIS? Cloudflare Range
None
None
EW . NO. W HAT THE F IS THIS??
None
HYBRID ANALYSIS
Links
None
None
None
None
None
What The Is This SHIT?!
• Auto-generated domains • A TON more domains with similar
looking documents to the original we found • The domains look like they’re being created and cached every day. • Same registration service • All whoisguarded • Documents which apparently aren’t malicious
THIS DOC HAS TO BE MALICIOUS RIGHT!?!
My research IP address
None
None
WAT DO?
FAST FLUX CAMPAIGN • Domains change rapidly • Malware is
delivered, delivery endpoints dissolve into the aether • Fairly good OPSEC to this campaign
CAMPAIGN EVOLUTION DGA Reasonable-ish 2nd level domain DGA evasion
None
ANYTHING IN THE C2??
EXTRA_TARGET_0.BAT
WHAT CAN WE DO? • Domain blocking? • It’ll all
be gone tomorrow • IP blocking • They change too frequently • Application whitelisting? • Sure, but what if it something changes again?
LESSONS LEARNED • ABC – Always Be Curious • Trust
your instincts • Be a good citizen • You may not always get the answers that you’re looking for, and that’s okay
MORAL OF THE STORY • “You can’t always get what
you want.” -Mick Jagger
CONTACT INFO • Emily Crose • Ironnet Cybersecurity • Twitter:
@Hexadecim8 • Email:
[email protected]