2012年8月28日 星期二

請注意,最新的 CVE-2012-1535 已經廣泛運用於APT惡意文件中

最新的  CVE-2012-1535 已經廣泛運用於APT惡意文件中 !

我知道大家最近都在忙著幫警察伯伯找李X瑞的風雅影片,但是還是得要煞風景地提醒大家 APT的攻擊活動與兼賣賣菜 :)

在 8月 16號, 公布了一個Adobe Flash的弱點 APSB12-18 http://www.adobe.com/support/security/bulletins/apsb12-18.html
也就是 CVE-2012-1535,很快的駭客在1,2天內研發出可利用的Exploit,同時各種產生器也出現在網路上,並開始大量流行於APT攻擊活動中。而Mila 也在 http://contagiodump.blogspot.tw/2012/08/cve-2012-1535-samples-and-info.html 也在8/17 公布了一些研究用的樣本,有興趣的朋友可以看看。

這個弱點攻擊的是 Adobe Flash Player 11.3.300.270,對很多人來說已經是很新的版本,居然也會被攻擊,大家更要提高警覺。

從上禮拜開始,我們客戶陸續回報出這個新攻擊給Xecure Lab, XecMail XecScan 不需要任何更新,就可以在第一時間偵測與分析此新的 Exploit。


已經過了這麼多天了,到目前為止42加防毒業者中僅只6,7家可以偵測,可以辨識CVE編號的只有4家可以偵測此 APT攻擊文件...
在台灣最常用的幾家掃毒幾乎都 GG了,像是政府機關裝最多的趨勢科技、個人用戶最愛的小紅傘、F-Secure、甚至 Macfee與 微軟的掃毒引擎。 全部都不支倒地,挫在等。大廠中只有 Kasperky與 Symantect算是比較認真有在上班的,目前都可以偵測到。

根據許多的研究與駭客討論顯示,請大家特別注意的攻擊還有 Java的 0Day Exploit與mscomctl.ocx (KB2597986 MS12-060) ,很快的會變成下一波 APT的主打歌。

目前正是APT惡意郵件活動的高峰期... 絕對要嚴防豪雨 !!

Birdman,
Xecure Lab

2012年7月29日 星期日

Prepare for the "Advanced Persistent Threat" Warfare

Advanced Persistent Threat (APT) has became a tough security challenge that large organizations and important individuals must be prepared for worst sooner or later. Last year at Defcon 2011, we shared our novel DNA approach in detecting and clustering APT document exploits. We were able to find 8 sizable APT attacker groups from our collections. At that time, it was a pool close to one thousand APT samples. A year later, we expand our study to cover more than a dozen thousand samples. Last week we had shared these interesting results to the attendees of HITCon 2012.
In this talk, we co-speak with Mr. Li (Director of Computer Center, National Police Agency of Taiwan) on the current status of APT cyber operations. Highlights of our findings include:

  • APT happens almost everywhere. Some locations were confirmed as the targets were willing to share with us their stories. Other than that, we studied the content of APT samples, looking for clues of the potential targets. The legitimate content could be in some unique languages, e.g. Traditional Chinese, Simplified Chinese, etc. The exploits might required unique environment to be triggered. We also found some callback destinations tend to be located near the targets. 
  • Taiwan (28.2%) had most APT callbacks or C2 (command & control) servers, followed by United States (17.2%), South Korea (14.4%) and China (10.5%).
  • Document exploits (97.62%) have been an all-time favorite for APT targeted attacks. Among these malicious documents, PDF (39.31%) ranked the most commonly-seen file type, followed by the office family: RTF (22.92%), DOC (17.45%), XLS (10.51%), and PPT (7.43%).
  • In recent years, the popularity of RTF (51.4%), DOC (14.5%), XLS (24.9%) had increased dramatically, surpassing PDF. And very often RTF is being disguised as DOC.
  • We saw a significant rise of password-protected document starting this year 2012. One particular attacker group leverage this trick heavily (65.9%) as it bypassed all antivirus and sandbox.


  • A great amount of exploits could be dig from these APT documents. A 2-year old RTF exploit CVE-2010-3333 is still very popular. In the wild, this exploit is very easy to be triggered successfully. 



  • We identified 33 sizable APT attacker groups around the world. Each node in the graph represents a species (yup, DNA), the color of each species indicate the time it's firstly seen (built). Yellow color means 2012, green is 2011, blue is 2010, orange is 2009, pink/white is 2008, etc. Different species might be linked with one or several edges. Each edge represents there is some similarity of the two nodes. Each cube or rectangular means the nodes inside belong to the same APT family - the same APT attacker group.  


In summary, we found APT cyber operations are happening around the world. They mostly use document exploits and starting this year password-protection trick is added. At least one callback is located near the target for testing network connection, or it's actually the C2 server with smooth bandwidth. After all, we identified 33 notable APT attacker groups, indicating advanced cyber operations typically are conducted in groups, well-organized and highly disciplined.

Finally, we would like to say big thank you to friends in the community and our users who are willing to feedback to us. Security is all about collaborative defense. It's everyone's work.
"If we know both ourselves and our enemy, we can win numerous battles without jeopardy". (The Art of War)

Sincerely,
Jeremy Chiu (Birdman), Benson Wu and Anthony Lai
Xecure Lab

2012年6月18日 星期一

資安八卦鏡:打造個資大盜痛恨的企業網站



Get ready for security breach and data leakage! Sooner or later.


上次寫文章給雜誌好像已經是快一年前了 @@
如今個資法來勢洶洶,我和Birdman花了好些心力寫了一篇資安小品「資安八卦鏡:打造個資大盜痛恨的企業網站」獻給全台灣勞苦功高的網管和開發人員!
目前雜誌只刊出1/3,剩下2/3要等待電子版。 XD

For every piece of sensitive information, you need to consider salt, hash, and encryption.

我們從駭客的角度去想怎麼樣的網站最難搞,首先,駭客入侵之後遇到加密資料就得破密,而破密需要運算資源,駭客得去養肉雞或買專業破密設備,這都需要耗費他的成本,所以只要網站把加密工作做得嚴嚴實實,撒鹽巴,搞雜湊,玩密碼學,這樣駭客就算偷到東西也不會happy!可惜還蠻多網站沒有這樣做的... chroot的Allen很用心地從無辜用戶角度收集一卡車沒有嚴嚴實實加密用戶密碼的網站...我的密碼沒加密

Every webmaster must often review the website for one-line trojan/backdoor.

再者,駭客進來後,絕對會意猶未盡,所以他會在網站上放後門,方便以後進進出出。但我們發現這樣的事實卻只有壞人知道,好人都很少知道,所以我們一定要告訴大家,在這篇文章我們整理了三個又愛又恨的一句話木馬,各位務必舉一反三,提高意識和警覺!

What if malicious document is uploaded via Web interface, would that count as APT? Ahha!

最後許多網站會提供上傳文件的介面,這都是很頭疼的地方,說穿了,後面是誰在開啟這些文件,還不就是人!那如果今天上傳的"履歷"是惡意文件,上傳的論文或作業是惡意文件,上傳的"民眾陳情"是惡意文件,上傳的"貸款申請書"是惡意文件,那該怎麼辦?這不正是APT攻擊嗎? 不囉嗦,XecScan最喜歡吃APT ;-)

各位對文章有甚麼想法與指教,歡迎來信 benson @ xecure-lab.com 交流。

2012年6月13日 星期三

Mila 釋出CVE-2012-0158 惡意文件測試包

我們的朋友 mila, 常常都在蒐集惡意程式與惡意文件樣本, 提供很多資安研究員分析的材料, 真是佛心來的 ! 非常感謝 :D
http://contagiodump.blogspot.tw/
幫她打打廣告


最近 Mila 貢獻了一包 CVE-2012-0158 的樣本, 我們很快用專業的 APT 惡意文件分析引擎 XecScan ( http://scan.xecure-lab.com ) 掃描了這90個樣本, 這包樣本都可以準確被我們 100% 偵測到 :)
不過我卻發現有3個檔案不是 CVE-2012-0158 而是 CVE-2010-3333

所以應該是 87個檔案是 CVE-2012-0158
而下面這三個是 CVE-2010-3333

125b8babb6ee4442efc75a5688c6bb5d0c71f8a685bcdff6b4043f3a829e65eb_Oded - Working.rtf

abbd1fa4dde11b94360338de8b5a2af7b09c6149ce1633797da825d5843cea7f_Criteria.doc

ec8b9c68872257cec2552ac727348c09314658d9497085f8a19f58004476c9b8_info.doc

2012年6月9日 星期六

Xecure Lab got security warnings for suspected state-sponsored attacks

As we all know "This site may harm your computer" warning and for years every site owner had tried hard not to get that label. Few days ago Google announced a Gmail warning message for the targets of state-sponsored attacks. Cool! How did Google do it? They can’t go into the details as those explanations would be helpful to the bad guys.
Nevertheless, at Xecure Lab, we regularly scan our personal Gmail accounts too for APT emails (our XecMail has a plugin for it) and there were no signs of APT attacks in our record recently. Surprisingly, we had chance to witness this Google state-sponsored attackers warning message:

(in English)

(in Chinese)

We speculated Google did the analysis not from "inside" by scanning the emails, e.g. looking for APT document exploit, but from "outside" by probably monitoring account login attempts involving known malicious sources or traffic protocols.

Anyway, we followed the Protect yourself now instructions, a few suggestions were given:
1. Watch out before you click a link.
2. Use a strong password.
3. Update software to the latest.
4. Enable 2-step verification.

Great, only the last one was something new at that moment, and we would like to give it a try.

With 2-step verification, Google will send SMS code to your phone when login sucessfully but with any strange device:

Oops, that means one has to repeat the above 2-step verification several times once a month, if not everyday. We also tried the "Call your phone" alternative instead of sending text, the call was from the phone number +1 (650) 353XXXX.

Lastly, when we changed the password in Google account, we'd have to go through the whole 2-step verification again. Right, a trade-off between security and convenience. ;-)

2012年6月5日 星期二

數位簽章最新用途...幫駭客蓋章!

這實在太讚了, 根據外電指出, Flame 事件中, 居然用數位簽章. 這次印章被幹走居然是偉大的微軟公司簽章...

難怪前兩天Windows Update緊急撤消了幾個簽章, 抖抖

http://www.f-secure.com/weblog/archives/00002377.html






2012年5月27日 星期日

Checkmate to Sandbox and Antivirus!


In the past few weeks, we noticed a rising number of malicious document can perfectly bypassed sandbox and all AV tools one could find on VirusTotal. Is it a zero-day exploit? No. It's simply a password-protected document. At the time of this blog, we have uploaded the sample onto VirusTotal, ThreatExpert, CWSandbox, etc, and confirmed our finding. A password-protected APT document seems like a no-brainier to beat all antivirus and sandbox on the planet.

Brandon (9bplus) also posted similar finding of these APT samples: "This document requires a password..."

Fortunately, XecScan is not bypassed. Without any update, XecScan detects them all.
The password-protected trick stops here. It is very encouraging to fans of XecScan, please continue enjoy our convenient, effective APT scanning service for free. ;-)