Showing posts with label ransomware. Show all posts
Showing posts with label ransomware. Show all posts

Wednesday, June 23, 2021

Say $6 Trillion Again ... I DARE you: Examining the roots of a total BS Marketing Number

Disclaimer: The principle of Academic Freedom has been the same for 80 years or so.  I do not speak officially for my employer.  That isn't how Academic Freedom works.  This blog post represents my own thoughts and opinions.


How often have you heard the quote that the Cost of Cybercrime is $6 Trillion?

As I was doing some reading on Ransomware I came across this bolded quote yesterday: "Ransomware is set to cause $6 trillion in damages by 2021."  

Wow.  Makes you want to run right out and buy cybersecurity products, doesn't it?  Fear, Uncertainty, and Doubt, the marketing department's dream formula! You really can't fault the marketing folks who wrote that though ... every cybersecurity marketing department is jumping on the bandwagon.  And when dozens of journalists share the number blindly with no examination of the facts, how can they be blamed? 

Every time you see the preposterous number "$6 Trillion Dollars" with regards to cybercrime costs, even when mis-used, as above, the source will be traced to a Cybersecurity Ventures report. I did an analysis of that report back in October 2017 and wanted to walk you through it here, gentle reader, so that you would have a place to point people who quote the Six Trillion Dollar Charlatan.  Here is where things started for me, when I saw this report:The original $6 Trillion Charlatan

Whether I'm grading a student paper, or reviewing a journal article submission, my approach to facts is the same.  Check the source. I'm hardly the only academic that has pointed out the shoddiness of many of the claims such as this one.  For another example, see the Journal of National Security Law & Policy article, "Advancing Accurate and Objective Cybercrime Metrics" by Stephen Cobb.  I love this quote from his peer-reviewed article:

"There is no shortage of data pointing to a dire state of affairs in cyberspace, published under headlines like “Global Breach Costs Set to Top $5 Trillion By 2024,” or "Global Breach Costs Set to Top $5 Trillion By 2024," and “Mobile Cyberattacks on the rise.” The manner in which such numbers and claims are quoted – and requoted – may lead the casual observer to believe they are based on official cybercrime metrics, yet few if any of these reports are the product of a comprehensive effort to consistently and objectively catalogue cybercriminal activity over time." (emphasis mine)

(Full disclosure, Stephen quotes my blog in his article - specifically my 30SEP2018 article "FBI's Crime Data Explorer: What the Numbers Say about Cybercrime.")

A reasonable approach to estimating the impact of Cybercrime might be to create various categories, suggest a reasonable maximum for each of them, and add them all together to create your estimate. That is the approach taken by some of my greatest cybersecurity heroes, in their excellent paper, "Measuring the Changing Cost of Cybercrime," presented at the 18th Annual Workshop on the Economics of Information Security. Is that the approach taken by Cybersecurity Ventures?  No. Not even close.

The $6 Trillion number that seems to be the point of the entire report seems to hinge on a single blog post from Microsoft, entitled, "The Emerging Era of Cyber Defense and Cybercrime" published 27JAN2016.  The Cybersecurity Ventures article has a footnote listing this as their source for their $3 trillion base.  Their Editor-in-Chief, Steve Morgan, by the way, continues to reference this number and use it in his fresh forecast.  In his 13NOV2020 prognostication, he now claims "Cybercrime to Cost the World $10.5 Trillion Annually by 2025" and STILL references the Microsoft blog in the highlighted link "$3 Trillion USD in 2015." 

https://cybersecurityventures.com/hackerpocalypse-cybercrime-report-2016/

One would presume that the blog post linked by Steve to the words "$3 trillion USD in 2015" would make a claim that the cost of cybercrime in 2015 was $3 trillion.  But that isn't what the Microsoft article says at all!  What the Microsoft blog post by Pete Boden, General Manager of Cloud and Enterprise Security,  actually says is that "The World Economic Forum estimates the economic cost of cybercrime to be $3 trillion worldwide." 

But even that is a mis-statement.  The World Economic Forum certainly doesn't believe that the cost of cybercrime is two orders of magnitude higher than any reasonable estimate.  What did they actually say?

The report is "Risk and responsibility in a Hyperconnected World" published by the World Economic Forum, in collaboration with McKinsey & Company.  

World Economic Forum / McKinsey Report
Click image for report
from mckinsey.com 

Here's what they actually say ... 

"Current trends could result in a backlash against digitization, with huge economic impact.  Major technology trends like massive analytics, cloud computing, and big data could create between US $9.6 trillion and US $21.6 trillion in value for the global economy.  If attacker sophistication outpaces defender capabilities -- resulting in more destructive attacks -- a wave of new regulations and corporate policies could slow innovation, with an aggregate economic impact of around US $3 trillion." - p.3 

Three things to note: 

1) the loss they are forecasting is A REDUCTION IN FUTURE ECONOMIC VALUE of certain technologies (analytics, cloud computing, big data) DUE TO A SLOW DOWN IN INNOVATION.

2) that loss would only come about IF THERE ARE NEW REGULATIONS IMPOSED that would stifle creativity in these areas.

3) The CUMULATIVE EFFECT between the time of the report (2014) and SIX YEARS LATER (2020) was said to have a potential of reaching $3 Trillion. 

So how on earth did Cybersecurity Ventures reach their number?

First, they clearly never read the World Economic Forum / McKinsey report, or they would certainly have been unable to say that the impact of Cybercrime had been $3 trillion in 2015.  Again, the $3 trillion was OVER THE COURSE OF SIX YEARS (or $500 Billion per year on the average) and ONLY IF REGULATORY CONDITIONS CHANGED DRAMATICALLY causing "unrealized potential economic value" to the tech industry.

But how did they get from $6 Trillion to $3 Trillion, even if they wrongly believed that the $3 Trillion was an annual number?  Simple.  In their report, they say there were 2 billion Internet users in 2015, they predict there will be 6 billion Internet users by 2022. They then say "Like street crime, which historically grew in relation to population growth, we are witnessing a similar evolution of cybercrime.  It's not just about more sophisticated weaponry; it's as much about the growing number of human and digital targets."  (See: "2019 Official Annual Cybercrime Report," p.4).  In other words, since there are so many more people, the false $3 Trillion is now $6 Trillion, right? No. That isn't how crime works, and it isn't how cybercrime works either.

According to the Cybersecurity Ventures report, the $6 Trillion in damages would consist of: 

  • Damage and destruction of data
  • Stolen money
  • Lost productivity
  • Theft of intellectual property
  • Theft of personal and financial data
  • Embezzlement
  • Fraud
  • Post-attack disruption
  • Forensic investigation
  • Restoration and deletion of hacked data
  • Reputation harm
But is that what the World Economic Forum said? ABSOLUTELY NOT!!!  

Just to keep beating the point home - the WEF said that the FUTURE GROWTH of certain tech industries may be slowed by $3 Trillion between 2014 and 2020 IF AN ADVERSE REGULATORY ENVIRONMENT is created.

How Much Is $6 Trillion?

According to Steve, the annual Cost of Cybercrime is $6 Trillion (and increasing!)  Ask yourself this question:  

If you agree with Steve's number, you believe that the Cost of Cybercrime is greater than the TOTAL REVENUE of Citibank, JPMorgan Chase, Bank of America, and Wells Fargo.  

You also believe that the Cost of Cybercrime is greater than the TOTAL REVENUE of Volkswagen, Toyota, Daimler/Chrysler, Mitsubishi, Honda, BMW, and Nissan. 

Add Walmart and Amazon and Google and you STILL are not at $6 Trillion.  

It would take the total 2019 Annual Revenues of ALL of thirty-three of these global companies to make $6 Trillion.  Steve says that is how much the cost of cybercrime will be this year, and that it will be $10.5 Trillion by 2024!  Do you believe? I do not.

The Total Cost of Cybercrime? 

Ransomware Math 

Cybersecurity Ventures has expressed that Ransomware is a top concern.  On 21OCT2019, Steve Morgan's Cybercrime Magazine post was titled "Global Ransomware Damage Costs Predicted to Reach $20 Billion USD By 2021." And we've already seen that they say Cybercrime costs will be $6 Trillion by 2021. 

Here's a helpful pie chart to help illustrate that: 


Now if RANSOMWARE is the number one source of cybercrime damages, and ransomware is 0.33% of the total cost of cybercrime, what are the other 99.7% of the costs made of?  That's right.  Thin Air.

A Little Help?

Please do me a favor? If you see someone quote the $6 Trillion Cost of Cybercrime, please send them a link to this story.  The numbers just do not make any sense!

Have you seen a source quoting the $6 Trillion Cost of Cybercrime?  Please share it in the comments below!  And if you know the person who is spouting that nonsense, please send them a link to this article!


Thursday, November 29, 2018

Two Iranian Hackers charged with $6 Million in SamSam Ransomware Attacks

Today the Department of Justice announced an indictment against two Iranian men: Faramarz Shahi Savandi and Mohammad Mehdi Shah Mansouri for their roles in stealing more than $6 Million in Ransom payments from a 34 month long ransomware campaign known as SamSam.

They were charged with:

18 U.S.C. § 371 - Conspiracy to Defraud the United States

18 U.S.C. § 1030(a)(5)(A) - knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer;

18 U.S.C. § 1030(a)(7)(C) - demand or request for money or other thing of value in relation to damage to a protected computer, where such damage was caused to facilitate the extortion

18 U.S.C. § 1349 - Conspiracy

Victims were found in nearly every state:

Victim Locations from: https://www.justice.gov/opa/press-release/file/1114736/download


Piecing together the case involved gaining cooperation from two European VPN services, and apparently at least one search engine.   The indictment refers, for example, to the defendants using Bitcoin to pay for access to a European VPS, and then searching on May 15, 2016, for "kansasheart.com".  The same day, they accessed the public website of Kansas Heart Hospital, and on May 18th, encrypted many key computers on the network and sent their ransom note.

Another key part of the investigation was gaining the cooperation of a Bitcoin Exchanger, which was able to demonstrate that on July 21, 2016, the defendants cashed out at least some of their ransomed Bitcoin into Iranian Rials and deposited it into bank accounts controlled by MANSOURI and SAVANDI.

Chat logs were also available to the investigators, as the indictment mentions contents of chat consistently throughout their timeline.  Using the combination of events, some of the key dates were:

  • December 14, 2015 - Defendants chatting about the development and functionality of SamSam.
  • Jan 11, 2016 - Attack on Mercer County Business in New Jersey 
  • Feb 5, 2016 - Attack on Hollywood Presbyterian Medical Center 
  • March 27, 2016 - Attack on MedStar Health 
  • May 15, 2016 - Attack on Kansas Heart Hospital 
  • May 27, 2016 - Attack on University of Calgary 
  • July 27, 2016 - Attack on Nebraska Orthopedic Hospital 
  • April 25, 2017 - Attack on City of Newark, New Jersey 
  • January 18, 2018 - Attack on Allscripts Healthcare Solutions, Inc. 
  • February 19, 2018 - Attack on Colorado Department of Transportation 
  • March 22, 2018 - Attack on City of Atlanta, Georgia 
  • July 14, 2018 - Attack on LabCorp 
  • September 25, 2018 - Attack on the Port of San Diego 
FBI Wanted Poster from: https://www.justice.gov/opa/press-release/file/1114746/download

Wednesday, November 30, 2016

NoMoreRansom aka Troldesh Ransomware Delivered by Kelihos

My favorite guest blogger Arsh Arora, a malware analyst and Ph.D. researcher at UAB,  is back with new and interesting facts about Kelihos, a botnet family that he has been tracking for a year and half and providing some great intel about to the community and law enforcement. Today, he noticed that it is delivering URLs leading to Troldesh ransomware. Take it from here, Arsh ...

Kelihos botnet delivering Troldesh Ransomware impersonating Bank of America

No_More_Ransom, aka Troldesh encryption ransomware, is being delivered by Kelihos in the form of embedded URLs within the email messages. The delivery mechanism is similar to previous cases of ransomware spammed by Kelihos. In early July, Kelihos introduce itself to the world of ransomware by spamming links to Wildfire ransomware followed by CryptFIle2 ransomware in August. Then, it shifted its focus towards different banking trojans such as Panda Zeus, Nymain and Kronos. Now, it took a complete circle and struck back with Troldesh encryption ransomware. The funny thing is that the ransomware encrypted the files with the extension ".no_more_ransom". Moreover, the URLs spammed were redirected to download a JavaScript file and a Microsoft Word document. This is the first time that Kelihos malware has used JavaScript to infect users.

Another interesting observation was that this spam campaign was specifically geo-targeting Australian email addresses ending with ".au".  ".pl" email users were getting dating spam, while ".us" extension emails were being invited to sign up as Money Mules.  All other email TLDs were getting the traditional pharmaceutical spam.

NoMoreRansom aka Troldesh Ransomware

While doing the daily run of malware, one of my fellow researchers at UAB, Max Gannon, noticed a different behavior in the Kelihos botnet. It was sending embedded links using the Credit Debt theme. The most important fact is that some of the URLs were redirected to download a .zip file containing a JavaScript file, while other links download a Microsoft Word document. When writing this blog, most of the URLs were still live. 

Subject: Please Settle Credit Arrears Shortly

Dear Client!

Our Credit Department has done research on your payment record for last year and learned that payments had not been made for last 3 months. We are now working on the issue pertaining to ways to help you with fulfilling liabilities and settling these arrears.

At the same time, we realize you may have had excellent reasons for such payment breakdown. That is exactly why we are contacting you now. Notwithstanding, if you are not proceeding your debt settlement, we will have to engage our enforcement units in commencing the law-suit case against you. This is the compulsory measure, so unfortunately, we may not help you.

Please process at least the very first payment at the earliest possible time. Else, charges may apply, and then the trial may be run.

We have made the full report of your situation. It contains the payment history, the total debt amount effective today, and further recommendations on arranging the issue. Please open and be guided with instructions as soon as possible.

The file can be found here: 
hxxp://greatwesternco[dot]com/wp-content/themes/twentyten/redirect[dot]php

Sincerely Yours,
Bank of America
Customer Relations Department
.

The following are the different subject lines that were spammed:
URLs that downloaded a .zip file containing JavaScript

Subject - Credit Department Discovered Your Debt - 
hxxp://eileenparker[dot]com/wp-content/themes/twentyten/redirect[dot]php

Subject - Pay for Credit Debt when Possible - 
hxxp://thehousepartnership[dot]co[dot]uk/wp-content/themes/twentyten/redirect[dot]php

Subject - Please Settle Credit Arrears Shortly - 
hxxp://chris-smith-web[dot]com/wp-content/themes/twentyten/redirect[dot]php

Subject - You Have a 3-Month Credit Debt - 
hxxp://infopro[dot]it/wp-content/themes/twentyeleven/redirect[dot]php

Fig. 1: Zip file downloaded with the embedded URL link

URLs that downloaded a Microsoft Word document

Subject - Please Settle Credit Arrears Shortly - 
hxxp://greatwesternco[dot]com/wp-content/themes/twentyten/redirect[dot]php

Subject - You Have a 3-Month Credit Debt - 
hxxp://greatwesternco[dot]com/wp-content/themes/twentyten/redirect[dot]php

URL that were unreachable

Subject - Pay for Credit Debt when Possible - 
hxxp://starsounds[dot]net/wp-content/themes/twentyeleven/redirect[dot]php - Down

Infection by JavaScript has not been an associated behavior with Kelihos. Hence, it can be considered a noticeable change and well-thought out strategy by the bot operators.

Hashes of the JavaScript and Word document are:

    1d57eba1cb761b99ffcf6bc8e1273e9c  instructions.doc
711881576383fbfeaaf90b1d6c24fce0  instructions.js

On the other hand, embedded URLs for Microsoft Word documents have been seen before. The document performed in a similar fashion requesting to enable the macros by clicking "Enable Content" aka "Encrypt Me" button. After this process it downloads a payload from the following link:

hxxp://95[.]163[.]127[.]179/777[.]exe
MD5 - 8441efe3901a0ec7f18c6ef5159877cc

Virus Total Link - 777.exe VT

After the file is downloaded, it encrypts the system with the Troldesh encryption ransomware and adds the "no_more_ransom" extension at the end of each file on the system. The ransom note on the desktop was displayed in Russian as well as English.

Fig. 2: Desktop screen after encryption

Fig. 3: Ransom Note found in text ReadMe.txt

All the important files on your computer were encrypted.
To decrypt the files you should send the following code:
xxxxxxxxxxxxxxxxxxxxx
to e-mail address 2Lynness.Taftfera1990@gmail[dot]com .
Then you will receive all necessary instructions.
All the attempts of decryption by yourself will result only in irrevocable loss of your data.
If you still want to try to decrypt them by yourself please make a backup at first because
the decryption will become impossible in case of any changes inside the files.
If you did not receive the answer from the aforecited email for more than 48 hours (and only in this case!),
use the feedback form. You can do it by two ways:
1) Download Tor Browser from here:
https://www.torproject.org/download/download-easy.html.en
Install it and type the following address into the address bar:
http://cryptsen7fo43rr6.onion/
Press Enter and then the page with feedback form will be loaded.
2) Go to the one of the following addresses in any browser:
http://cryptsen7fo43rr6.onion.to/
http://cryptsen7fo43rr6.onion.cab/

The above is a plain text version of the ransom note. As it can be seen, a Gmail address is being use, which is one of its kind behavior.

Troldesh did not stop trolling the victim there, it downloads the PONY malware and contacts its command and control center at this location:

 hxxp://ipieceofcake[dot]com/wp-content/uploads/2016/04/gate[dot]php

When I visited the link it was down, but thanks to our Malware expert Neera Desai who works for PhishMe and is pursuing her Masters in Computer Forensics at UAB, we were able to visit the panel page of the Pony malware.

Fig. 4: Pony malware panel page

This was really fascinating as Kelihos spammed URLs for Troldesh encryption ransomware with redirects to a malicious Microsoft Word document and a zip file containing JavaScript. The files eventually encrypt the system but it also downloads the Pony malware to steal all the information from the victim's computer. Hence, causing a double blow to the victim.

Money Mule Spam 

Kelihos botnet was not in a mood to stop. It also sent Money Mule spam geo-targeting users with the ".us" United States email address. It impersonated a company from 'China looking for employees'. 

Text of the email is as follows:

Subject: China company is looking for employees

We are the greatest transport company in China involved in 
transportation of high-dimension goods across the globe. At present, 
we are aimed at expanding by opening offices across the globe for 
deliveries of small consignments. We are looking for employees to 
open offices and ensure services (deployment and supervision of 
packages). All costs for the office establishment are undertaken by 
the organization. During the first month of your job, you and our 
employees are to be engaged in searching for the storage structure. 
You will be also required to appoint some amount of orders to your 
home address (not more than 10kg parcels a day) in order to check 
them for flaws and ship forward with pre-paid labels. We have a 
certain flow of parcels to date, and the work is already jogging on; 
if you are ready to start your operation right away, we are ready to 
pay 2800$ a month. In due course your salary will increase up to 
3500$ if you agree to work in the future office.

You have the following options of working with us:
1. You are working at home for the first month, receiving packages 
and shipping them forward; starting looking for an office place in 
your town (all the instructions you will receive from our managers)
2. You continue to work from home and get 2900$ every month, plus 
bonuses for fast shipped package
3. If something doesn't fit you and you decide to stop the job with 
us, we will pay you monthly salary and be waiting for you again in 
our team in the future!

If you have any questions please contact us at: kia01915@aol[dot]com

All costs for establishment the office are taken by the company, 
shipping is made with prepaid labels, this job does not require any 
financial investment from you. You can also combine this work with 
another one if you decide to work in the office in the future.
The convenient control panel of a corporate website will help you to 
track parcels, bonuses you are to get for a shipped package, and your 
personal information for salary and further job instructions.

The company ensures the following advantages:
1. Health benefits
2. Paid vacations and sick leaves
3. Paid flight tickets, gasoline

This is a temporary offer, as soon as we have a team of employees in 
your staff the vacancy will be closed.

Please contact our HR manager for further details: kia01915@aol[dot]com
.
Other subject lines that were spammed in the same theme are mentioned below with their corresponding reply-to email address.

Subject - China company is looking for employees - kia01915@aol[dot]com
Subject - We are hiring new employees to our office - kia01915@aol[dot]com
Subject - We are hiring new employees to our office - bree10682@aol[dot]com

Subject - Job opportunity - marquerite23894@aol[dot]com
Subject - Open vacancy - marquerite23894@aol[dot]com

The other thing to note is that all of the email addresses use AOL domains, which is a unique thing in itself.


To conclude, Kelihos has been surprising the researchers quite often and it has become necessary to keep track of different activities of the botnet. The ransomware inclusion brings interesting twists from the research as well as law enforcement. Another thing that I found while searching for NoMoreRansom was a group established by key leaders in the community to fight against the rise of ransomware. 

So is the extension of NoMoreRansom a challenge to the people fighting it? Who knows? 
FYI: Things are about to get interesting!

Tuesday, August 30, 2016

Amazon Gift Card from Kelihos!

Arsh Arora and Max Gannon, malware researchers in our lab at the University of Alabama at Birmingham (UAB) continue their on-going analysis of the Kelihos botnet.  We call this a "longitudinal malware study."  Today Arsh returns with some interesting observations about the Kelihos botnet as it sends out Amazon Gift Card. 

Arsh take it from here.


Amazon Gift Card from Kelihos botnet! Anyone up for a Nymaim banking trojan or CryptoLocker?

Here it is, the Kelihos botnet back with a bang. Today, Kelihos is in a festive mood and giving away a free “Amazon Gift Card”, especially for US customers.  Instead of ALL American spam recipients receiving the malware, however, only those whose email ends in the country code ".us" received this malware.  As you can see in the sample list below, this means that many school employees will have received this spam, as K-12 schools very commonly use .us domain names.

This is the first time it has geo-targeted US customers, unlike previous occasions where it had targeted Canadian [Canada] , German and UK, [German and UK] and Dutch [Dutch] customers. The delivery mechanism is the same in which the botnet delivers emails containing suspicious links to a Microsoft Word document that will download a Nullsoft installer and eventually affect you with Nymaim/CryptoLocker.

Now, we can surely say that the operators of Kelihos botnet are formulating a strategy in choosing their targets for the spam campaign. Basically, they are trying to gain back the attention of the industry and trying to proclaim its spot of the longest surviving spamming botnet. Recently, the botnet size increased tremendously and has been a hot topic among the cyber industry.


Geo Targeted emails to US based victims
The body of the message sent contains a malicious word doc link

Subject: Amazon Gift Team just wants to make a present for you

Hi our beloved client!
Our company glad to notify, that our improbable promotion special offer to say thanks to limited number of our buyers.
In this greetings list you can find costless Amazon Gift Card for $65 balance!!! It can be redeemed in our online webstore for any further purchase on Amazon. You can activate promo eGift using this link: hxxp://amazon[.]com[.]yougifted[.]pw/Amazon%20Gift%20Code[dot]doc
Hurry up! This offer have limited time, and limited number of promo vouchers available, that can be activated during promo, so do not forget to obtain your one! 
Huge thanks from Amazon for being a part of our team, we really apreciate that!
----------------------------------------
You can discover useful information using our FAQ on amazon.com/contact-us or via the phone +180012343212
Amazon Promo Team

______________________________________________

The most common email subjects we observed being used in the spam campaign are:
Subject: Amazon Gift Team just wants to make a present for you
Subject: Awesome news! You recieved a gift from Amazon!
Subject: Don't wait, get free voucher! Amazon Promo chosen you!
Subject: Gift from Amazon was just recieved, redeem yours now

The URLs  sent in the email are presented below with its corresponding resolved IP address, via WHOIS search

hxxp://amazon.com.yougifted[.]pw/Amazon%20Gift%20Code[dot]doc – 104[.]168[.]181[.]99; Oklahoma
hxxp://amazon.com.youwelcomes[.]pw/Amazon%20Gift%20Code[dot]doc – 104[.]168[.]181[.]99
hxxp://amazon.com.cheappromo[.]pw/Amazon%20Gift%20Code[dot]doc – 149[.]202[.]194[.]178; Nord-pas-de-calais
hxxp://amazon.com.getforless[.]pw/Amazon%20Gift%20Code[dot]doc - 149[.]202[.]194[.]178
hxxp://amazon.com.giftcardservice[.]pw/Amazon%20Gift%20Code[dot]doc – 198[.]105[.]215[.]36; Utah

An interesting observation is that 4 out of 5 Urls share the same Whois contact information[Whois]

Registrant Name: Frank Gilmer
Registrant Organization: Private Person
Registrant Street: 22 Bakinskih komissarov 2k1, 51
Registrant City: Moscow
Registrant State/Province: Moscow
Registrant Postal Code: 119571
Registrant Country: RU
Registrant Phone: +7.9681673922
Registrant Email: frankgilmer416@gmail.com

Moving on, the delivery mechanism remains to consistent as seen on previous occasions

Document opened in Protected view with a URL link

After downloading the Word document and viewing its content, it shows the above message. Interestingly, it contains a URL that is meant to excite the victim. So in order to receive this “amazing” offer, the user first has to press the “Enable Editing” button.

Enable Content AKA Encrypt Me!


 After clicking the 'Enable Editing' button, another window asks to 'Enable Macros', aka  "ENCRYPT ME" button. The gift card is still unavailable and can be only be retrieved after clicking the URL in the email.

Congratulating the user!

This behavior has been seen for the first time where the user is asked to click a URL.  While the user is occupied trying to find his/her gift code, the ransomware is performing its task in the background. By the time the user realizes a scam is underway, the machine is already encrypted. Threat actors have perfectly social engineered user behavior in order to succeed in causing damage to the user.

The URL provided in the email doesn't actually exist at Amazon:
          hxxps://www.amazon[.]com/giftsredeemingrightnow

Too late to say Sorry!

When the link is clicked, we get Amazon's 404 page -- an image of a cute dog and a message saying “Sorry, we couldn’t find that page”. On the contrary, guess what happens? When you close the browser you will find that your files are encrypted. Unfortunately, we were not able to get our system encrypted as the installer checked registry keys for the presence of the virtual environment.

After not being able to accomplish my mission, I checked virus total for extra information

MD5 of the Word Document - 2843a3b7805ffc7fd058b9fd744ec836 [VT result]

Of course, the Word document was a downloader, but the file that was download was indeed malicious.

MD5 of the NSIS installer named 'Sys_Driver' - 766169d508d0eee096e07619c2a1416a [VT results]


VT results 10/57, CryptoLocker

When we reviewed the malicious file on Virus Total, contradicting results were found. On one side, the AV vendors classified it as Cryptolocker. On the contrary, when I checked the comments section, one user has posted it to be Nymaim.  We believe this is due to targeting, where the same URL may drop different malware depending on the visitor.  Hence, I thought to probably avoid getting into the discussion of who is right, and leave it up to the discretion of the user to pick his side.

#Nymaim in the comments section
While CryptoLocker is unlikely - it hasn't been seen in some time - we don't want to contradict the AV vendors until we can execute the malware ourselves.   

As of now, my colleague Max Gannon, Malware Analyst at UAB, notes that these samples are extraordinarly VM-aware.  It performs the usual registry check for references to Virtualization Software, but it also checks the display adapters and color settings which are harder to disguise and less frequently modified by malware analysts.  It checks the local machine language as well as the keyboard layout which is again not frequently changed.  It checks the clipboard contents and if the clipboard is linked to a Virtual Machine.  Lastly it checks the system for a pre-defined set of programs that it considers indicative of a normal system.  This is a significant increase in the number of checks when compared to similar malware families and may require additional focus and analysis time.

Hopefully, this will widen up the eyes of Amazon and the individuals who have the authority to take action. Eventually, taking appropriate measures to cause damage to the threat actors. Beware American friends.

Stay tuned for latest updates on the Kelihos botnet in the coming future.




Thursday, August 04, 2016

American Airlines spam from Kelihos delivers Ransomware

I'm pleased to have Arsh Arora return with another guest blog about his findings as he continues to observe the Kelihos botnet.  Arsh recently received his Masters in Computer Forensics and Security Management in our program at UAB and has chosen to continue his malware research as a PhD candidate.

Kelihos botnet delivering CryptFlle2 Ransomware with theme AmericanAirlines

By Arsh Arora

When we saw the Kelihos botnet delivering ransomware last month on July 8th, we sat up and took notice.  The Kelihos botnet has a long history of delivering pharma spam and stock market manipulation spam (pump-n-dump), but now it was spamming the WildFire ransomware. ( See: http://garwarner.blogspot.com/2016/07/kelihos-botnet-delivering-dutch.html )  I was under the impression that it was one of the occasional gimmicks observed with Kelihos where they try something a single time and then move on.  I assumed that some script kiddies were testing new ransomware techniques. Unfortunately, I was wrong and Kelihos hit back with CryptFIle2 encryption ransomware.

To attract people to their ransomware, this campaign used subject lines imitating American Airlines specifically to attract customers. The URLs listed below are the locations that were sent in the spam email along with its corresponding subject lines:

hxxp://dataupllinks[.]top/nfdk/ticket1845[.]doc - Free Fly with AmericanAirlines
hxxp://ftp[.]dataupllinks[.]top/edsf/tick-873[.]doc  - Bonus from AmericanAirlines
hxxp://ftp[.]filesgigastor[.]top/23tf/disc_tick-235[.]doc  - AmericanAirlines free 100$
hxxp://www[.]webdataupllinks[.]net/rety/tick-834[.]doc  - AmericanAirlines discount

The following is the email that the victim receives and is inclined to check out the special travel prices for his/her favorite vacation spots.

Figure 1 - American Airlines Discounts



Several subject lines were used, including:

  • Subject: Bonus from AmericanAirlines
  • Subject: AmericanAirlines free 100$
  • Subject: AmericanAirlines discount
  • Subject: Free fly with AmericanAirlines


Subject: AmericanAirlines discount 
Traveling with the world's largest airline shouldn't have to be expensive. That's why at Ctrip, we are
bringing you our lowest prices yet for flights with American Airlines.
 
>>> DOWNLOAD FREE DISCOUNT 100$ TICKET:
*Prices exclude taxes and fees.
Los Angeles - Las Vegas from 88$
Las Vegas - Los Angeles from 198$
New York - Chicago from 192$
Toronto - Hong Kong from 923$
Los Angeles - Shanghai from 832$
Toronto - Beijing from 958$
Chicago - Beijing from 712$
Boston - Beijing from 1,077$
Boston - Shanghai from 1,060$
Chicago - Shanghai from 845$
Atlanta - Beijing from 1,581$
Chicago - New York from 221$
Los Angeles - New York from 440$
New York - Toronto from 220$
New York - Miami from 177$
New York - Orlando from 203$
Seattle - Los Angeles from 145$
New York - Los Angeles from 366$
Los Angeles - San Francisco from 186$

>>> DOWNLOAD FREE DISCOUNT 100$ TICKET:
hxxp://www[.]webdataupllinks[.]net/rety/tick-834[.]doc
 
Terms and Conditions:
Prices are correct at time of publication and are subject to availability and change. Please see
english.ctrip.com to confirm availability, prices, and applicable terms and conditions. Flights for
certain dates may be sold out. In this event, please try to enter another flight date. Airlines reserve
right to adjust prices and control seat availability according to sales situation. Final fare based on
airline's actual sale price. Seat availability subject to airlines. Special fares may be subject to
strict change, refund and endorsement conditions. Please refer to conditions of confirmed booking for
details. Ctrip.com International Ltd. (CTRP) reserves all rights of final interpretation.



The prices are striking enough to entice the victim to click the link. Once the link is clicked, a pop up is shown to download a Word document. Although the user is unaware that the Word document contains hostile code, Microsoft Word document delivery is one of the more common ways of distributing malware.

Once the download is complete the victim opens the document. The document follows a similar pattern as it used in the previous ransomware sent by Kelihos. The Word document is opened in ‘Protected View’ and seeks the user to ‘Enable Editing’ to view the document.

Figure 2 - "Protected Document"

After clicking the ‘Enable Editing’ box, another window asks to ‘Enable Macros’, aka the “ENCRYPT ME” button.

Figure 3 - "Enable Editing AKA Encrypt Me!"

After clicking the ‘Enable Content’ button, it shows the following message.

Figure 4 - Looks like a Word Document!

This behavior is the first of its kind observed in Word documents delivering malware. Generally, there is no content in the Word document and the malware infects the victim’s machine within minutes if not seconds.

The feature makes the Word document seem like a legit file and distracts the user while the malware contacts its command and control center and encrypts files in the background.
As soon as you complete reading, you realize that your computer has been encrypted by CryptFIle2 encryption ransomware.

Figure 5 - You are now ENCRYPTED


An interesting feature about the ransom note is that the threat actors have evolved their technique for obtaining ransom payment. As it can be seen, there is no mention of Tor-hosted or Onion-domain payment websites. Instead, it has 2 email addresses in which the victim can email the threat actor directly to pay the ransom. The email addresses are:
westbors@oath[.]com
gobas@inorbit[.]com

This seems fool-hardy and not very sophisticated, but the American Airlines lure will certainly gain some victims!  This is phenomenally different behavior than the previous WildFire ransomware. The text displayed after enabling Macros is a significant change in the Word document that spread ransomware.

Other interesting observations found are:

  • .      MD5 hash of the Word document - 4fde04b25ea20b6ab30c5e4984e01afc
  • .      Website mentioned in the Word document – english[.]ctrip[.]com
  • .      Payload location: hxxp://216[.]170[.]126[.]3/wfil/file[.]exe
  •                           hxxp://216[.]170[.]118[.]4/default[.]jpg
  •     Command & Control Center: hxxp://216[.]170[.]118[.]4/wes/offers[.]php


#AA #AmericanAirlines – Just realized that AA stands for my name too. So were the threat actors targeting the American Airlines or Arsh Arora, in disguise of AA?

Thanks for that guest post, Arsh! Be on the lookout for a new paper about the spam campaigns of Kelihos at an upcoming conference based on Arsh's studies.

Wednesday, July 13, 2016

Reality Checking Mister Robot's Ransomware Attack

In tonight's Episode of Mr. Robot, the fsociety hackers deliver a Ransomware attack to the Bank of E.
At PhishMe, our malware analysts have reviewed more than six million malicious Ransomware  emails this year!

Check out my blog over there to see how the hacking in tonight's Mr. Robot compares to reality:


PhishMe: Reality Checking Mr. Robot

Mr. Robot Easter Egg Hunt

For more fun ... try to solve the first of the S2 Easter Eggs. First clue ... Here is Elliot's Notepad page --

I used the Online Graph Paper website to turn that into a more proper 29 x 29 QR Code:


 The rest is up to you!   Post a comment when you successfully log in!