+ All Categories
Home > Documents > SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights...

SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights...

Date post: 27-Jul-2020
Category:
Upload: others
View: 0 times
Download: 0 times
Share this document with a friend
37
© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 1 © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 1 SilverBlight Craig Williams Sr. Technical Leader / Security Outreach Manager
Transcript
Page 1: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 1 © 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 1

SilverBlight Craig Williams Sr. Technical Leader / Security Outreach Manager

Page 2: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 2

Agenda

•  What is Talos

•  A Match Made in Heaven, Exploit Packs and Dynamic DNS

•  Angling for Exploitation

•  Rig Exploit Kit

•  A Historic Perspective

•  Q&A

Page 3: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 3

Talos Security Intelligence and Research Group

•  At a high level what is Talos? Sourcefire VRT Cisco TRAC Ironport Secapps

•  We own the engine deliverables, the threat research, and the mitigations – There are no roadblocks

•  220+ Researchers under the Talos leadership team •  Our goals

•  Protect our customers •  Piss off the bad guys

Page 4: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4

100 TB Intelligence 1.6M sensors 150 million+ endpoints 35% email world wide FireAMP™, 3+ million 13B web req

AEGIS™ & SPARK Open Source Communities 180,000+ Files per Day 1B SBRS Queries per Day 3.6PB Monthly though CWS

Advanced Industry Disclosures

Outreach Activities

Dynamic Analysis

Threat Centric Detection Content

SEU/SRU

Sandbox

VDB

Security Intelligence

Email & Web Reputation

Email Endpoints Web Networks IPS Devices

WWW

10I000 0II0 00 0III000 II1010011 101 1100001 110

110000III000III0 I00I II0I III0011 0110011 101000 0110 00

I00I III0I III00II 0II00II I0I000 0110 00

101000 0II0 00 0III000 III0I00II II II0000I II0

1100001110001III0 I00I II0I III00II 0II00II 101000 0110 00

100I II0I III00II 0II00II I0I000 0II0 00

Research Response [Talos]

Threat Intelligence

Threat Focused

Page 5: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 5 Cisco Public 5 © 2014 Cisco and/or its affiliates. All rights reserved.

A match made in heaven, exploit kits and dynamic DNS

Page 6: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 6

Page 7: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 7

Fiesta Exploit Kit

•  January of 2014 alone over 300 companies affected

•  Drive by download attack

Page 8: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 8

Fiesta Exploit Kit

•  Malicious file types for all web content since mid-December 2013

Page 9: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 9

Fiesta Exploit Kit

Page 10: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 10

Fiesta Exploit Kit

Page 11: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 11

Fiesta Exploit Kit

Page 12: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 12

Dynamic DNS

Page 13: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 13

Fiesta Exploit Kit – Dynamic DNS A total of 6 IP addresses were responsible for hundreds of dynamic hosts

Page 14: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 14

Dynamic Detection of Malicious DNS - Reputation

Average

Baseline

Page 15: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 15

Dynamic Detection of Malicious DNS – AV Blocks

Average

Baseline

Page 16: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 16

Dynamic Detection of Malicious DNS What are we blocking with AV?

Page 17: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 17

Dynamic Detection of Malicious DNS

Page 18: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 18

Mitigations

•  Web security appliances / Cloud Web security

•  Reputation systems

•  Block some/all Dynamic DNS providers using RPZ

•  Client side protection Antivirus HIPS AMP Everywhere

Page 19: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 19 Cisco Public 19 © 2014 Cisco and/or its affiliates. All rights reserved.

Angling for Exploitation

Page 20: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 20

Angler Exploit kit

Page 21: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 21

Content types

Page 22: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 22

Content Types

Page 23: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 23

Angler Exploit Kit

Page 24: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 24

Angler Exploit Kit

Page 25: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 25

Page 26: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 26

Angler Exploit Kit

Page 27: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 27

We see you!

Page 28: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 28

Page 29: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 29

Blocking the campaign

•  7 unique Silverlight payloads

•  5 unique Angler droppers

•  IOC City Linked to >650 domains 21 Hotmail addresses Way too many to list here go view the blog @ http://blogs.cisco.com/tag/trac/

•  Multiple vulnerabilities being exploited…

Page 30: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 30 Cisco Public 30 © 2014 Cisco and/or its affiliates. All rights reserved.

Rig Exploit Kit

Page 31: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 31

Rig Exploit Kit

•  Advertised on criminal forums in April

•  Began blocking April 24 Blocked over 90 domains 17% of all CWS customers affected Distributed Cryptowall

•  Yet another exploit kit continuing the trend of silverlight exploits Silverlight: CVE-2013-0074 Java: CVE-2013,2465, CVE-2012-0507 Flash: CVE-2013-0634

Page 32: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 32

Requests to Rig Landing Page

Page 33: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 33

Content Type

Page 34: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 34

Page 35: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 35

Mitigations

•  Over 26 malicious files examined

•  >190 IOCs

•  IPS Silverlight: CVE-2013-0074 Java: CVE-2013,2465, CVE-2012-0507 Flash: CVE-2013-0634

•  Web Security Appliance

•  Cloud Web Security

Page 36: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 36

For More: http://blogs.cisco.com/Talos

Q&A

Page 37: SilverBlight - SecTor Williams - SilverBlight.pdf© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 4 100 TB Intelligence 1.6M sensors 150 million+ endpoints 35%

© 2014 Cisco and/or its affiliates. All rights reserved. Cisco Public 37

Thank You


Recommended