Showing posts with label SMB. Show all posts
Showing posts with label SMB. Show all posts

Thursday, 26 October 2017

Infrastructure Behind BadRabbit Ransomware Since 2016 Active


The infrastructure used last Tuesday to spread the BadRabbit ransomware has been active since 2016, says Dutch security researcher Yonathan Klijnsma from security company RiskIQ. During the attack the attackers used a large number of hacked websites.

These websites showed a popup to visitors that they needed to install an update for Adobe Flash Player. In fact, it was a Petya ransomware variant that encrypted files on the hard drive and overwritten the Master Boot Record from the hard drive. As a result, the operating system can no longer be started. Furthermore, BadRabbit tries to spread on SMB via a list of commonly used passwords and intercepting login credentials via SMB.

On the hacked websites, code was sent to an injection server that showed the malicious popup on the websites. One of these injection servers was first observed last September. In addition, various hacked websites have been compromised since last year. RiskIQ counted 63 hacked websites where the attackers had access. The security company claims, however, that it can go for more websites.

"The group behind the BadRabbit ransomware has been active for quite some time," said Klijnsma. The researcher speaks of a long-term campaign that could possibly be set up for something other than BadRabbit. "Although the BadRabbit ransomware is brand new, we can track the distribution industry by the beginning of 2016, which shows that victims had been compromised a lot before before the ransomware hit and the news cycle began. The campaign could originally be set up for something other than BadRabbit. " Security company Symantec claims that 86 percent of the infections occurred in Russia and it mainly concerns companies.

Saturday, 20 December 2014

US warns of SMB worm that was used against Sony



The Computer Emergency Readiness Team (US-CERT) of the US government has issued a warning for an SMB (Server Message Block) -worm that started against Sony. The worm uses brute force authentication to spread through shared Windows SMB shares.


Every five minutes makes the malware connects to the server command of the attackers to send data successfully to another Windows computer via SMB port 445 has infected. The tool also listens for connections on TCP port 195 and TCP port 444. Furthermore, the worm has a backdoor that allows to download files and execute commands. The worm can so via Universal Plug and Play (UPNP) ports in your firewall to discover routers, gateways and port mappings.

Thus it is possible to attacked computers that are behind a NAT (Network Address Translated) network are to allow incoming connections. The part of the worm that is most striking is the "clear", which overwrites the Master Boot Record of the hard drive and thus makes the system unusable. The delete function is also used against systems that are accessible via shared network folders. The malware attempts to log on to these computers via a number of usernames and passwords that are previously specified by the attackers.

The US-CERT warns that organizations that deal with this malware get must take account of the theft of intellectual property and the disruption of critical systems. As a solution to get the system advised to use virus scanners and keep up-to-date, operating systems and software to keep up-to-date, "defense in depth" to apply strategies and a plan to establish order with destructive malware to go.