Jump to content

Recommended Posts

Posted

We use PSexec on our laser cutter PC because the driver/software was written by the devil and his programmer, Dwayne. Dwayne didn't know how to get his driver digitally signed, and couldn't get his software to launch for non-admins. That's why he only found work in Hell.

 

I'm going to look at restricting it to all but that PC.

Posted
We use PSexec on our laser cutter PC because the driver/software was written by the devil and his programmer, Dwayne...

 

Duane Dibbley?!

 

photo.jpg

Posted
"Kill switch" found.*

 

https://twitter.com/0xAmit/status/879789734469488642

 

 

 

https://twitter.com/PTsecurity_UK/status/879779707075665922

 

i7AgFn.jpg

 

* Obviously the best "kill switch" is to install the latest Microsoft updates!

 

Is it also worth creating perfc.dll and perfc.dat to be on the safe side as mentioned in this article https://www.bleepingcomputer.com/news/security/vaccine-not-killswitch-found-for-petya-notpetya-ransomware-outbreak/

Posted
Is it also worth creating perfc.dll and perfc.dat to be on the safe side as mentioned in this article https://www.bleepingcomputer.com/news/security/vaccine-not-killswitch-found-for-petya-notpetya-ransomware-outbreak/

That Bleeping Computer article linked to an older tweet of Amit's...

 

https://twitter.com/0xAmit/status/879778335286452224

 

xIvmGL.png

 

46 minutes later he tweeted this...

 

https://twitter.com/0xAmit/status/879789734469488642

 

l9ZGG1.png

 

In the comments section of the article, Grinler (a.k.a. Lawrence Abrams, the creator and owner of BleepingComputer.com) also confirmed that you only need to create the perfc file. :)

 

www.bleepingcomputer.com/news/security/vaccine-not-killswitch-found-for-petya-notpetya-ransomware-outbreak/#cid5661

 

DmU70W.png

Posted

Another article with some tips on prevention not covered elsewhere.

 

Petya Ransomware – The Attack method and Preventing it

 

There are 4 main phases.

 

  • Delivery – about getting in
  • Exploit/Execution – running code on the machine
  • Lateral Movement – traversing the network infecting other machines
  • Action – getting what they came for

Below are the phases and description on what Petya does and how you can protect yourself.

 

We know that a lot of companies are struggling making huge changes in their infrastructure to combat these attacks. Changes in infrastructure can be costly, can involve multiple business units and require end user training. A delay in making infrastructure changes can also cause a delay in implementing the defenses desperately needed. The fact that so many organizations still haven’t applied the MS17-010 Update from March speaks for it self.

 

I’ve tried focusing on solutions that are relatively easy to implement, but still raise the security bar significantly. But if you want the best security, you would need more.

  • Thanks 1
Posted
We use PSexec on our laser cutter PC because the driver/software was written by the devil and his programmer, Dwayne. Dwayne didn't know how to get his driver digitally signed, and couldn't get his software to launch for non-admins. That's why he only found work in Hell.

 

I'm going to look at restricting it to all but that PC.

 

I've now put in a Applocker rule that blocks PsExec from running unless it's run from an approved location (which normal users can't write to), which should give me the ability to still use it on that one PC (which has a unique passord) but nullify it elsewhere. I haven't tried doing this by signature because so many versions of it are floating around.

Posted (edited)

Cisco Talos have been working with MeDoc to find out what happened. Here's their analysis...

 

The MeDoc Connection

 

The Nyetya attack was a destructive ransomware variant that affected many organizations inside of Ukraine and multinational corporations with operations in Ukraine. In cooperation with Cisco Advanced Services Incident Response, Talos identified several key aspects of the attack. The investigation found a supply chain-focused attack at M.E.Doc software that delivered a destructive payload disguised as ransomware. By utilizing stolen credentials, the actor was able to manipulate the update server for M.E.Doc to proxy connections to an actor-controlled server. Based on the findings, Talos remains confident that the attack was destructive in nature. The effects were broad reaching, with Ukraine Cyber police confirming over 2000 affected companies in Ukraine alone.

 

Nyetya%2BBlog%2BPost%2B1%25281%2529.jpg

Edited by Arthur
Posted
I've now put in a Applocker rule that blocks PsExec from running unless it's run from an approved location (which normal users can't write to)

It might be worth adding a rule for wmic.exe too (at least for the users who don't need to run it).

 

Windows 10 platform resilience against the Petya ransomware attack

 

The new Petya ransomware combines multiple well-known techniques for propagation and infection that are not new to security researchers. The noteworthy aspect is that Petya’s developer(s) took techniques normally used by penetration testers and hackers, and built a sophisticated multi-threaded automation of these techniques inside a single piece of code.

 

Such attacker techniques are part of the modern threat landscape and are continuously researched by security teams at Microsoft. Resulting new mitigations, hardening or defensive measures are then integrated into our products and operating systems.

 

Windows 10 follows this philosophy of continuous mitigation improvements. From our analysis of Petya, we were able to measure the defenses provided by Windows 10. Summarized in the diagram below are how mitigations and security features can help disrupt the different stages of this attack.

 

02-petya-kill-chain-diagram1.png

  • Thanks 2
Posted

Busy Admin’s Guide to Device Guard and Credential Guard

 

Credential Guard focuses on protecting user and system secrets, such as hashed credentials. Credential Guard is easy to implement without a lot of impact. Device Guard goes beyond Credential Guard by providing code integrity policies, which prevents unauthorized code from running on your devices—think malware.

 

With compatible hardware, the code integrity service runs alongside the Windows kernel in a hypervisor-protected container, making it nearly impossible for a bad actor to execute malicious code, even if they have control of the Windows kernel. For Credential Guard in particular, the authorization mechanisms also reside in this container, which offers mitigations to attacks such as pass-the-hash.

 

In your GPO, navigate to Computer Configuration > Administrative Templates > System > Device Guard. Edit the policy “Turn On Virtualization Based Security”. To turn on just Credential Guard, I recommend these settings:

 

wuqsWA.png

 

Do NOT configure this setting in your Default Domain Policy, as you do not want code integrity or Credential Guard applied to your domain controllers
  • Thanks 1
  • 1 month later...
Posted

:eek: :eek: :eek:

 

NotPetya ransomware attack cost us $300m – shipping giant Maersk

 

The world's largest container shipping biz has revealed the losses it suffered after getting hit by the NotPetya ransomware outbreak, and the results aren't pretty.

 

Maersk picked up an infection that hooked into its global network and shut down the shipping company, forcing it to halt operations at 76 port terminals around the world.

 

"In the last week of the quarter we were hit by a cyber-attack, which mainly impacted Maersk Line, APM Terminals and Damco," CEO Soren Skou said in a statement today.

 

Skou said that he decided to take personal charge of the situation, sitting in on IT meetings and getting daily updates on the malware's progress. He says he learned that there was nothing that could have been done to stop the attack, but he wants to strengthen the company's systems against further attacks.

 

Maersk wasn't the only multinational to be hit by NotPetya. WPP, the world's largest advertising agency, also took a major hit, as did deliveries firm TNT. While the latter biz hasn’t responded to requests for comment it's understood to have taken weeks to sort out its infection with a permanent loss of data.

 

Infect me once shame on you, infect me twice....

That's bad, but if the comments are to be believed the reason they have been infected again is because they have poorly run outsourced IT systems?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...