2011年10月11日 星期二

Exploit CVE-2009-3129 sample was found in APT activities!


Xecure Lab 在近期的APT 攻擊中發現到一個新鮮可口的惡意文件,不僅該樣本罕見地利用 CVE-2009-3129, MS09-067 漏洞 (exploit),係針對 MS-Excel 2002~2007 版本的使用者族群。

Type : XLS
MD5 : 8c711e4b10e0e327bebc7b220416ff59
Malware : 2011-09-30

樣本使用到的惡意程式 (malware) 才大概剛在 2011-09 製造出爐,整個還是熱呼呼。該 malware 經過我們的自動化惡意程式鑑識,屬於較新的變種,它會把 DLL 跟 Code 注射到 IE 瀏覽器中,再對外進行活動,中繼站是 http://nod32.mobwork.net (目前它還沒有對應的 IP)。



特別提到這個弱點的原因是之前幾乎沒發現過這樣的攻擊,我們觀察到這個 exploit 出現在 APT 的惡意郵件中,相信接下來會有大量的攻擊活動出現。

如果你有樣本需要作APT攻擊鑒定,可以寄給我們 support@xecure-lab.com 或是直接使用我們線上的 APT快篩服務 http://aptdeezer.xecure-lab.com

2011年9月29日 星期四

有關悠遊卡事件一些誤會的澄清 [轉貼]

關於悠遊卡事件,最近網路上出現很多嘴砲老師,
像是陳X成老師硬說他好像HIT的工作人員...
>_< 老天爺壓,這傢伙哪來的壓....他應該也沒來參加過HIT (剛過教師節,要忍住不能說不雅的話)
 http://www.chen0001.idv.tw/ 
推薦陳老師上一下"關鍵時刻"...

--- [HIT關方說明]
有關悠遊卡事件一些誤會的澄清 悠遊卡事件到目前為止,在網路上或新聞中,代表駭客年會發言的人幾乎都不是我們的成員,錯誤消息很多,為了避免大眾對駭客年會有錯誤的認知和誤解,我們希望利用這篇公告來跟大家澄清。
  http://blog.hitcon.org/2011/09/blog-post.html [更多內容]

2011年9月28日 星期三

我們的成員 Anthony 將在 10月 OpenGroup 研討會上發表 Xecure Lab 在 APT相關研究

我們的成員 Anthony 將在今年10月25號台北的 OpenGroup 研討會上發表 Xecure Lab 在 APT 相關研究。
下半年還有幾場研討會,陸續地我們還會發表 APT 相關的一些研究,敬請期待~~

Advanced Persistent Threat (APT) DNA Clustering and Defense "Kungfu"

Tuesday, October 25, 2:30 - 3:00


http://www3.opengroup.org/taipei2011/presentation-details



Advanced Persistent Threat (APT) (a.k.a. Targeted Attacks from Cyber Taskforces) may not be identified in the wild but target specific a organization and company like incidents from RSA, Lockheed Martin, and Mitsubishi Heavy Industry. This entire new class of threat could not be dealt with traditional virus detection and IDS/IPS.
We will share our research on clustering APT samples in various task forces in Asia and demonstrate the tools called APT Deezer and the tool of email with APT document attachement detection for enterprise defense.
Anthony Lai specialized in penetration test, code audit, crime investigation and threat analysis. He founded VXRL (Valkyrie-X Security Research Group, http://www.vxrl.org) after attending to DEFCON 15, connecting to and learning from world hackers and security researchers.
Anthony has formed Xecure Lab (http://www.xecure-lab.com) with Birdman and Benson from Taiwan. He undertook APT and threat research and provided corresponding enterprise defense and service. Anthony has spoken at Blackhat USA 2010, DEFCON 18 and DEFCON 19 and Hack In Taiwan 2010 and 2011 and been certified with SANS GREM Gold, GCFA and GWAPT certifications.

2011年8月17日 星期三

Xecure Lab 上香港壹週刊



香港壹週刊今天(8/18)大篇幅報導全港網站普遍不設防,上週香港交易所被駭客入侵,導致多支股票異常最終全面停牌半日,此次壹週刊專訪 Xecure Lab 共同創辦人 Anthony Lai,深入了解全港網站安全性普查狀況,以此嚴正呼籲港府應加強資安意識。防駭錦囊妙計終極方案,收到可疑檔案,你懷疑對方已巧妙騙過你的防毒軟體,來吧,有我們 Xecure Lab 的 APT Deezer http://aptdeezer.xecure-lab.com/ 挺你。


2011年8月6日 星期六

Xecure Lab at Defcon 19

Last year thousands of Defcon folks had to squeeze at the Riviera, it was a nightmare to move between different tracks; but this year thanks to Defcon goons for choosing Rio, the venue is big and cozy! It feels like paying a Defcon ticket and enjoy a Blackhat venue! xd

Our talk APT Secrets in Asia was given on the first day, first session. We really appreciate everyone that came over and stayed with us for almost 2 hours. The talk was rejected by Blackhat 2011 but accepted by Defcon 2011, otherwise we wouldn't have chance to share with the security community. As we always believe in, hackers and security gurus should team up, have fun, and together we can outsmart the attackers making them in the light.

Special thanks to many good friends of us, Mila, you inspired us; TT and Nanika, you guys sitting in the first row, awesome; Birdman, PK, Mars, Bob, safe guarding our home base, the system ran very smoothly and did not get owned, save Anthony and Benson on the stage; and buddies from Chroot security group in Taiwan, you are always with us. There are also several respected seniors flying over for the talk, we really appreciate their support. Thank you mama!

This year we had developed a free APT online scanning service,
Xecure Lab APT Deezer, http://aptdeezer.xecure-lab.com/, and is now available to everyone*. APT Deezer would tell you whether the document is APT-related or not, and provide visualization of analysis data (clustering of APT taskforces). Both file names and md5 are rounded-off a bit to keep anonymity. If you have more concerns or questions, feel free to write us at benson.wu (at) xecure-lab dot com
*Disclaimer: We have no interest with your PII, we will not collect any of your identity information, e.g. your IP, your geographical location, and so-on.

Oh, this time the Defcon badge is not electronic, but a piece of metal, made from commercially pure titanium. Awesome. (The Blackhat badge is made from Nylon as usual)


The badge on the left is the speaker badge, the one on the right is the human badge, there are also (G)oon, (P)ress, (V)endor, (C)ontest, (U)ber, etc. Enough variants to entertain everyone.

Anyway, the antiqued badge is cool, and moving to a puzzle based reality game is something different.


We want all these swag, but cash only... -.-



More readings:

Sincerely yours,
Xecure Lab team

2011年8月1日 星期一

韓國最大社交網站被黑 3500萬用戶資料泄露,台灣居然是駭客的幫兇!?

新浪科技訊 北京時間7月28日上午消息,由於韓國網絡公司SK Communications遭遇黑客攻擊,導致3500萬韓國網民的個人信息泄露,其中有2500萬是韓國最大社交網站賽我網(Cyworld)的用戶。
  SK Communications旗下擁有社交網站賽我網和搜索引擎Nate。該公司周四表示,黑客攻擊導致用戶的姓名、電話號碼、電子郵箱、居民身份證號碼以及密碼泄露。
  SK Communications稱:“公司已經證實,用戶信息泄露源於7月26日的黑客攻擊。本次攻擊的規模仍在調查之中。估計約有3500萬Nate和賽我網的用戶個人信息被盜。”

2011年7月23日 星期六

請指名 "Xecure Lab" 的 APT Deezer 惡意檔案快篩服務 ;-)

Xecure Lab 團隊在台灣駭客年會推出這個免費的 APT [註] 惡意檔案快篩服務 它可以告訴國人是否手上的這個可疑文檔 1) 是不是惡意文件, 2) CVE漏洞編號, 3) 隸屬於哪個組織集團, 如果是最大的"一坨", 那麼你不僅是個咖, 還是大咖!! (更何況一般人非常難收到APT的惡意文​件), 請一直都非常小心...

註: APT (Advanced Persistent Threat), 是一種有組織有計畫,陰魂不散的網路攻擊,可視為"國家層級資訊戰"

Xecure Lab APT Deezer
aptdeezer.xecure-lab.com





















近期我們陸續在各場合跟大家分享 Xecure Lab 在APT的所見所聞所學:


喜歡我們做的東西嗎? 歡迎寫信給我們 ;-)