38
#RSAC SESSION ID: SESSION ID: CCT-W04 Cybercrime and Attacks in the Dark Side of the Web Dr. Marco Balduzzi * Senior Researcher at Trend Micro http://www.madlab.it @embyte * With the cooperation of Mayra Rosario and Vincenzo Ciancaglini

CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

  • Upload
    voquynh

  • View
    219

  • Download
    2

Embed Size (px)

Citation preview

Page 1: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

SESSION ID:SESSION ID: CCT-W04

Cybercrime and Attacks in the Dark Side of the Web

Dr. Marco Balduzzi*Senior Researcher at Trend Microhttp://www.madlab.it @embyte

*With the cooperation of Mayra Rosario and Vincenzo Ciancaglini

Page 2: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

A perfect platform for Cybercrime

Page 3: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Our Investigative System: DEMOtimestamp:[2015\-01\-01 TO 2015\-12\-31] AND title:marketplace

Page 4: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

A Russian Marketplace

Page 5: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Data Exploration

Headless browser

HAR LogPage DOM

ScreenShot

Title

Text

Metadata

Raw HTML

Links

Email

BitcoinWallets

Page 6: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Data Analysis

Embedded links classification (WRS)• Surface Web links• Classification and

categorization

Page translation• Language detection• Non-English to English

Significant wordcloud• Semantic clustering• Custom algorithm

Page 7: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Results

Page 8: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Guns

Page 9: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Identities and Passports

Page 10: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Credit Cards

Page 11: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Accounts, e.g. Israeli Paypal

Page 12: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

HacktivismCampaigns

Page 13: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Cashout services

Page 14: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Bulletproof Hosting Providers

Page 15: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Selling of WannaCry Ransomware

Page 16: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Impact on organizations

Dark Web traffic is difficult to be detected by traditional systems (IDS)

Resilient and stealth malware

Persistence and monitoring (APT)

Page 17: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Courtesy Ionut Ilascu, Softpedia

Bankers

Page 18: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Keylogger

Page 19: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

TorrentLocker, i.e. variant of CryptoLocker

Payment page hosted in TOR◎wzaxcyqroduouk5n.onion/axdf84v.php/user_code=qz1n2i&user_pass=9019◎wzaxcyqroduouk5n.onion/o2xd3x.php/user_code=8llak0&user_pass=6775

Cashout via BITCOINS

Ransomware

Page 20: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Organized Attacks

Page 21: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

We simulated a cybercriminal

installation in the Dark Web

Page 22: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Honeypot

I. Black MarketII. Hosting ProviderIII. Underground ForumIV. Misconfigured Server

(FTP/SSH/IRC)

Technology

I. Wordpress + ShellsII. OsCommerceIII. Custom Web AppIV. Custom OS (Linux)

Page 23: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher
Page 24: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Registration-Only Forum

Page 25: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Exposes a Local File Inclusion

Page 26: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

A 7-months experiment

Month 1: Different advertisement strategies to honeypot #1#

Daily

PO

ST R

eque

sts

Average of 1.4 malicious uploads per day

Page 27: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Attacks

Pre-installed web shells attracted the most of “visitors”

CMS #1-2 reached via Google Dorks (on Tor2Web), CMS #3 no because custom

CMS #2 reached via TOR’s search engine’s query “Index of /files/images/”(http://hss3uro2hsxfogfq.onion)

# Attacks

# Days with Attacks

Page 28: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Traditional Web Attacks

Page 29: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Password-protected Shells

Page 30: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Smart use of Obfuscation

Page 31: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

Abuse of Tor’s Anonymity for Attacks

Page 32: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

(Anonymized) Phishing Campaign

Page 33: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Rival Gangs

• Cyber-criminal gangs compromising opponents

• Self-promoting their “business”

Page 34: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

(TOR Keys)

Used to compute the hidden service descriptorInstruction

Points

Public Key

Private Key

Instruction Points

Public Key

XYZ.onion

Signing

KeypairGeneration

Page 35: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

HS’ Private Key theft

400+ attacks

MiTM, hijack and decryption

Page 36: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Dark Web as “corner case” of the Internet… NO!

Active & Dynamic Offerings in the Middle East

“Far-west looking” ecosystem with gangs attacking each other

Modern threats pose significant challenges for organizations

Lessons Learned

Page 37: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Improve on both endpoint and network security, e.g. X-Gen IDS

Understand the “Tor2Web effect” (makes the Dark Web not as dark as someone would think)

Protect your asset and do not assume TOR does it for you

Apply

Page 38: CCT-W04 Cybercrime and Attacks in the Dark Side of the … · #RSAC SESSION ID: CCT-W04. Cybercrime and Attacks in the Dark Side of the Web. Dr. Marco Balduzzi * Senior Researcher

#RSAC

Thank You!

Dr. Marco Balduzzi*Senior Researcher at Trend Microhttp://www.madlab.it @embyte

*With the cooperation of Mayra Rosario and Vincenzo Ciancaglini