41
© Copyright 2015 PhishMe, Inc. All rights reserved. Building Better Indicators: Crowdsourcing Malware IOCs Sean Wilson Researcher

Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

  • Upload
    others

  • View
    0

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved. © Copyright 2015 PhishMe, Inc. All rights reserved.

Building Better Indicators: Crowdsourcing Malware IOCs

Sean Wilson Researcher

Page 2: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Researcher @ Phishme Reverse Engineer Incident Responder Twitter: @seanmw flyfishing++;

About me

Page 3: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Building Indicators

Analysis Discovery Development

Page 4: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

CrowdSource

Page 5: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Warning: OPSEC!

Page 6: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

The Problem •  Small teams rely on host and network AV for information

about threats. •  These alerts are often quite generic and don’t provide

much information other than: ‘Bad has happened…but don’t worry we got it!’

Page 7: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Scenario

Page 8: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Scenario 1a

Page 9: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Triage

Page 10: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Malware Triage

Page 11: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Triage: We Got This!

Recon Weaponization Delivery Exploitation Installation C2 Activity

Detection

Page 12: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Scenario 1b

Page 13: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Page 14: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Recon Weaponization Delivery Exploitation Installation C2 Activity

Intrusion Kill Chain

Detection

Page 15: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

What is it?

Trojan.Win32.Generic!BT

RDN/Generic.PUP.z

Trojan.Generic

Gen:Trojan.Heur

Artemis!12345

Page 16: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Page 17: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Page 18: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Sample Analysis

Page 19: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Page 20: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

VirusTotal

Page 21: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Page 22: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Malwr Search

Page 23: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Overview

Page 24: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Network Activity

Page 25: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

PassiveTotal

Page 26: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Discovery

Early Indicators

System Changes

Dynamic Properties

Static Properties

Page 27: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Google All the Things!

Page 28: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Page 29: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Page 30: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Page 31: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Page 32: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Netflix Scumblr

Trolling the garbage dump of the internet so you don’t have to

Page 33: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

DFIR Scumblr Searches •  PassiveTotal •  Totalhash •  VirusTotal •  Malwr •  Cuckoo

Page 34: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Page 35: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Page 36: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Page 37: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Page 38: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Development

What properties are common across

samples?

Are my indicators matching new

(unknown) samples?

Page 39: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Dashboards!

Page 40: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Thanks! @seanmw

Page 41: Building Better Indicators: Crowdsourcing Malware IOCs© Copyright 2015 PhishMe, Inc. All rights reserved. Images • Icon made by Freepik from is licensed under CC BY 3.0 . Title:

© Copyright 2015 PhishMe, Inc. All rights reserved.

Images •  Icon made by Freepik from http://www.flaticon.com is licensed under CC BY 3.0