Slide 1

Slide 1 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 1 Scareware From Ireland Mark Hillick IrissCert Incident Handler http://www.iriss.ie [email protected]

Slide 2

Slide 2 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 2 What is Scareware?

Slide 3

Slide 3 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 3 Irish Scareware Exploit q Browse to Irish website & collect your fake anti- virus

Slide 4

Slide 4 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 4 Dialog-box fun…..

Slide 5

Slide 5 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 5 Dialog-box fun cont…..

Slide 6

Slide 6 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 6 System Scan

Slide 7

Slide 7 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 7 Trojan Log file

Slide 8

Slide 8 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 8 Money, please!

Slide 9

Slide 9 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 9 Are you sure?

Slide 10

Slide 10 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 10 Are you mad????

Slide 11

Slide 11 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 11 BSOD

Slide 12

Slide 12 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 12 Effect on the end-user….

Slide 13

Slide 13 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 13 Exploit q  Exploited Sites hosted on one server §  Microsoft FTPd & IIS 6.0 q Two most popular web site attacks – §  Gumblar q PHP Sites §  Asprox q SQL Injection

Slide 14

Slide 14 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 14 Pass the Parcel q http://compromisedsite.ie §  http://jobstopfil.biz q http://poppka.net q http://sujetline.ru q http://grownclubfest.ru q  PDF & SWF files served back

Slide 15

Slide 15 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 15 Obfuscation q Engaged SANS ISC Malware Team §  Heavily obfuscated javascript §  Used techniques not seen before

Slide 16

Slide 16 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 16 Complex Design….

Slide 17

Slide 17 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 17 q Tamper Data, Live HTTP Headers – Firefox q Burp Suite q Tcpdump, Wireshark & Netwitness q Dig/nslookup Tools Used

Slide 18

Slide 18 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 18 Incident Handling - Containment Source: http://www.tazworld.co.uk/gallery/pictures/www.tazworld.co.uk_taz_035.gif © Warner Bros. Entertainment Inc.

Slide 19

Slide 19 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 19 Incident Handling - Eradication Source -> http://www.alexross.com/CJ011.jpg © Warner Bros. Entertainment Inc

Slide 20

Slide 20 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 20 Incident Handling - Recovery Dilbert ©2009, United Feature Syndicate, Inc.

Slide 21

Slide 21 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 21 Incident Handling - Lessons Learned q Patch web-server & application §  Input validation q Close unnecessary open ports (e.g. FTP) q Password Policy q Regular back-ups q Web-app security testing

Slide 22

Slide 22 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 22 Securing the Desktop q End-User Defence q Rescue CDs §  Google -> “rescue site:raymond.cc” q Free Tools §  http://zeltser.com/fighting-malicious-software/

Slide 23

Slide 23 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 23 Next Steps & Extra Info q Sans GCIH Gold Paper -  Scareware & its evolution -  Incident Handling Process q  Full Incident Report -  http://www.iriss.ie – in shared documents -  http://www.hillick.net/things/scareware.doc

Slide 24

Slide 24 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 24 References q Sunbelt Blog q Dancho Danchev Blog q SANS ISC (Thanks to @bojanz) q VRT-Sourcefire Blog q Symantec White Papers q Sans Forensics Blog

Slide 25

Slide 25 text

Scareware From Ireland - Twitter "markofu" & "irisscert" © 2009 IRISS 25 That's it..... Hat Tip for image - Jesse M. Heines - http://teaching.cs.uml.edu/~heines/images/ questions.gif