3s-gtech Posted June 28, 2017 Posted June 28, 2017 We use PSexec on our laser cutter PC because the driver/software was written by the devil and his programmer, Dwayne. Dwayne didn't know how to get his driver digitally signed, and couldn't get his software to launch for non-admins. That's why he only found work in Hell. I'm going to look at restricting it to all but that PC.
DJ-1701 Posted June 28, 2017 Posted June 28, 2017 We use PSexec on our laser cutter PC because the driver/software was written by the devil and his programmer, Dwayne... Duane Dibbley?!
timbo343 Posted June 28, 2017 Posted June 28, 2017 "Kill switch" found.* https://twitter.com/0xAmit/status/879789734469488642 https://twitter.com/PTsecurity_UK/status/879779707075665922 * Obviously the best "kill switch" is to install the latest Microsoft updates! Is it also worth creating perfc.dll and perfc.dat to be on the safe side as mentioned in this article https://www.bleepingcomputer.com/news/security/vaccine-not-killswitch-found-for-petya-notpetya-ransomware-outbreak/
smarties11 Posted June 28, 2017 Posted June 28, 2017 Is it also worth creating perfc.dll and perfc.dat to be on the safe side as mentioned in this article https://www.bleepingcomputer.com/news/security/vaccine-not-killswitch-found-for-petya-notpetya-ransomware-outbreak/ I would say so. That's what I've done anyway.
Arthur Posted June 29, 2017 Posted June 29, 2017 Is it also worth creating perfc.dll and perfc.dat to be on the safe side as mentioned in this article https://www.bleepingcomputer.com/news/security/vaccine-not-killswitch-found-for-petya-notpetya-ransomware-outbreak/ That Bleeping Computer article linked to an older tweet of Amit's... https://twitter.com/0xAmit/status/879778335286452224 46 minutes later he tweeted this... https://twitter.com/0xAmit/status/879789734469488642 In the comments section of the article, Grinler (a.k.a. Lawrence Abrams, the creator and owner of BleepingComputer.com) also confirmed that you only need to create the perfc file. www.bleepingcomputer.com/news/security/vaccine-not-killswitch-found-for-petya-notpetya-ransomware-outbreak/#cid5661
Arthur Posted June 29, 2017 Posted June 29, 2017 https://twitter.com/GossiTheDog/status/880331916897120260
Arthur Posted June 29, 2017 Posted June 29, 2017 Another article with some tips on prevention not covered elsewhere. Petya Ransomware – The Attack method and Preventing it There are 4 main phases. Delivery – about getting in Exploit/Execution – running code on the machine Lateral Movement – traversing the network infecting other machines Action – getting what they came for Below are the phases and description on what Petya does and how you can protect yourself. We know that a lot of companies are struggling making huge changes in their infrastructure to combat these attacks. Changes in infrastructure can be costly, can involve multiple business units and require end user training. A delay in making infrastructure changes can also cause a delay in implementing the defenses desperately needed. The fact that so many organizations still haven’t applied the MS17-010 Update from March speaks for it self. I’ve tried focusing on solutions that are relatively easy to implement, but still raise the security bar significantly. But if you want the best security, you would need more. 1
3s-gtech Posted June 29, 2017 Posted June 29, 2017 We use PSexec on our laser cutter PC because the driver/software was written by the devil and his programmer, Dwayne. Dwayne didn't know how to get his driver digitally signed, and couldn't get his software to launch for non-admins. That's why he only found work in Hell. I'm going to look at restricting it to all but that PC. I've now put in a Applocker rule that blocks PsExec from running unless it's run from an approved location (which normal users can't write to), which should give me the ability to still use it on that one PC (which has a unique passord) but nullify it elsewhere. I haven't tried doing this by signature because so many versions of it are floating around.
Arthur Posted July 5, 2017 Posted July 5, 2017 (edited) Cisco Talos have been working with MeDoc to find out what happened. Here's their analysis... The MeDoc Connection The Nyetya attack was a destructive ransomware variant that affected many organizations inside of Ukraine and multinational corporations with operations in Ukraine. In cooperation with Cisco Advanced Services Incident Response, Talos identified several key aspects of the attack. The investigation found a supply chain-focused attack at M.E.Doc software that delivered a destructive payload disguised as ransomware. By utilizing stolen credentials, the actor was able to manipulate the update server for M.E.Doc to proxy connections to an actor-controlled server. Based on the findings, Talos remains confident that the attack was destructive in nature. The effects were broad reaching, with Ukraine Cyber police confirming over 2000 affected companies in Ukraine alone. Edited July 5, 2017 by Arthur
Arthur Posted July 5, 2017 Posted July 5, 2017 I've now put in a Applocker rule that blocks PsExec from running unless it's run from an approved location (which normal users can't write to) It might be worth adding a rule for wmic.exe too (at least for the users who don't need to run it). Windows 10 platform resilience against the Petya ransomware attack The new Petya ransomware combines multiple well-known techniques for propagation and infection that are not new to security researchers. The noteworthy aspect is that Petya’s developer(s) took techniques normally used by penetration testers and hackers, and built a sophisticated multi-threaded automation of these techniques inside a single piece of code. Such attacker techniques are part of the modern threat landscape and are continuously researched by security teams at Microsoft. Resulting new mitigations, hardening or defensive measures are then integrated into our products and operating systems. Windows 10 follows this philosophy of continuous mitigation improvements. From our analysis of Petya, we were able to measure the defenses provided by Windows 10. Summarized in the diagram below are how mitigations and security features can help disrupt the different stages of this attack. 2
Arthur Posted July 11, 2017 Posted July 11, 2017 Busy Admin’s Guide to Device Guard and Credential Guard Credential Guard focuses on protecting user and system secrets, such as hashed credentials. Credential Guard is easy to implement without a lot of impact. Device Guard goes beyond Credential Guard by providing code integrity policies, which prevents unauthorized code from running on your devices—think malware. With compatible hardware, the code integrity service runs alongside the Windows kernel in a hypervisor-protected container, making it nearly impossible for a bad actor to execute malicious code, even if they have control of the Windows kernel. For Credential Guard in particular, the authorization mechanisms also reside in this container, which offers mitigations to attacks such as pass-the-hash. In your GPO, navigate to Computer Configuration > Administrative Templates > System > Device Guard. Edit the policy “Turn On Virtualization Based Security”. To turn on just Credential Guard, I recommend these settings: Do NOT configure this setting in your Default Domain Policy, as you do not want code integrity or Credential Guard applied to your domain controllers 1
ZeroHour Posted August 28, 2017 Posted August 28, 2017 Infect me once shame on you, infect me twice.... https://www.theregister.co.uk/2017/08/28/wannacrypt_nhs_victim_lanarkshire_infected_by_malware_again/
Arthur Posted August 28, 2017 Posted August 28, 2017 :eek: NotPetya ransomware attack cost us $300m – shipping giant Maersk The world's largest container shipping biz has revealed the losses it suffered after getting hit by the NotPetya ransomware outbreak, and the results aren't pretty. Maersk picked up an infection that hooked into its global network and shut down the shipping company, forcing it to halt operations at 76 port terminals around the world. "In the last week of the quarter we were hit by a cyber-attack, which mainly impacted Maersk Line, APM Terminals and Damco," CEO Soren Skou said in a statement today. Skou said that he decided to take personal charge of the situation, sitting in on IT meetings and getting daily updates on the malware's progress. He says he learned that there was nothing that could have been done to stop the attack, but he wants to strengthen the company's systems against further attacks. Maersk wasn't the only multinational to be hit by NotPetya. WPP, the world's largest advertising agency, also took a major hit, as did deliveries firm TNT. While the latter biz hasn’t responded to requests for comment it's understood to have taken weeks to sort out its infection with a permanent loss of data. Infect me once shame on you, infect me twice.... That's bad, but if the comments are to be believed the reason they have been infected again is because they have poorly run outsourced IT systems?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now