Auteur Sujet: [FireEye]BACKSWING - Pulling a BADRABBIT Out of a Hat  (Lu 3281 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
[FireEye]BACKSWING - Pulling a BADRABBIT Out of a Hat
« le: octobre 26, 2017, 23:00:24 »
BACKSWING - Pulling a BADRABBIT Out of a Hat

[html]

Executive Summary


 

On Oct. 24, 2017, coordinated strategic web compromises started to
  distribute BADRABBIT ransomware to unwitting users. FireEye appliances
  detected the download attempts and blocked our user base from
  infection. During our investigation into the activity, FireEye
  identified a direct overlap between BADRABBIT redirect sites and sites
  hosting a profiler we’ve been tracking as BACKSWING. We’ve identified
  51 sites hosting BACKSWING and four confirmed to drop BADRABBIT.
  Throughout 2017, we observed two versions of BACKSWING and saw a
  significant increase in May with an apparent focus on compromising
  Ukrainian website. The pattern of deployment raises the possibility of
  a strategic sponsor with specific regional interests and suggest a
  motivation other than financial gain. Given that many domains are
  still compromised with BACKSWING, we anticipate that there is a risk
  that they will be used for future attacks.


 

Incident Background


 

Beginning on Oct. 24 at 08:00 UTC, FireEye detected and blocked
  attempts to infect multiple clients with a drive-by download
  masquerading as a Flash Update (install_flash_player.exe) that
  delivered a wormable variant of ransomware. Users were redirected to
  the infected site from multiple legitimate sites (e.g.
  http://www.mediaport[.]ua/sites/default/files/page-main.js)
  simultaneously, indicating a coordinated and widespread strategic web
  compromise campaign.


 

FireEye network devices blocked infection attempts at over a dozen
  victims primarily in Germany, Japan, and the U.S. until Oct. 24 at
  15:00 UTC, when the infection attempts ceased and attacker
  infrastructure – both 1dnscontrol[.]com and the legitimate websites
  containing the rogue code – were taken offline.


 

BACKSWING Framework Likely Connected to BADRABBIT Activity


 

Strategic web compromises can have a significant amount of
  collateral targeting. It is common for threat actors to pair a
  strategic web compromise with profiling malware to target systems with
  specific application versions or victims. FireEye observed that
  BACKSWING,


Tags: