Auteur Sujet: [FireEye]SCANdalous! (External Detection Using Network Scan Data and Automation)  (Lu 2778 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
SCANdalous! (External Detection Using Network Scan Data and Automation)

[html]

Real Quick


 

In case you’re thrown by that fantastic title, our lawyers made us
  change the name of this project so we wouldn’t get sued.
  SCANdalous—a.k.a. Scannah Montana a.k.a. Scanny McScanface a.k.a.
  “Scan I Kick It? (Yes You Scan)”—had another name before today that,
  for legal reasons, we’re keeping to ourselves. A special thanks to our
  legal team who is always looking out for us, this blog post would be a
  lot less fun without them. Strap in folks.


 

Introduction


 

Advanced Practices is known for using primary source data obtained
  through     href="/content/fireeye-www/en_US/services/mandiant-incident-response.html">Mandiant
    Incident Response,     href="/content/fireeye-www/en_US/solutions/managed-defense.html">Managed
  Defense, and product telemetry across thousands of FireEye
  clients. Regular, first-hand observations of threat actors afford us
  opportunities to learn intimate details of their modus operandi. While
  our visibility from organic data is vast, we also derive value from
  third-party data sources. By looking outwards, we extend our
  visibility beyond our clients’ environments and shorten the time it
  takes to detect adversaries in the wild—often before they initiate
  intrusions against our clients.


 

In October 2019, Aaron Stephens gave his     href="https://www.youtube.com/watch?v=x1tEOkY-7JE">“Scan’t Touch
  This” talk at the annual FireEye Cyber Defense Summit (slides
  available     href="https://github.com/aaronst/talks/blob/master/scanttouchthis.pdf">on
    his Github). He discussed using network scan data for external
  detection and provided examples of how to profile command and control
  (C2) servers for various post-exploitation frameworks used by criminal
  and intelligence organizations alike. However, manual application of
  those techniques doesn’t scale. It may work if your role focuses on
  one or two groups, but Advanced Practices’ scope is much broader. We
  needed a solution that would enable us to track thousands of groups,
  malware families and profiles. In this blog post we’d like to talk
  about that journey, highlight some wins, and for the first time
  publicly, introduce the project behind it all: SCANdalous.


 

Pre-SCANdalous Case Studies


 

Prior to any sort of system or automation, our team used traditional
  profiling methodologies to manually identify servers of interest. The
  following are some examples. The success we found in these case
  studies served as the primary motivation for SCANdalous.


 


  APT39 SSH Tunneling


 

After observing APT39 in a series of intrusions, we determined they
  frequently created     href="/content/fireeye-www/en_US/blog/threat-research/2019/01/bypassing-network-restrictions-through-rdp-tunneling.html">Secure
    Shell (SSH) tunnels with PuTTY Link to forward Remote Desktop
  Protocol connections to internal hosts within the target
  environment. Additionally, they preferred using BitVise SSH servers
  listening on port 443. Finally, they were using servers hosted by
  WorldStream B.V.


 

Independent isolation of any one of these characteristics would
  produce a lot of unrelated servers; however, the aggregation of
  characteristics provided a strong signal for newly established
  infrastructure of interest. We used this established profile and
  others to illuminate dozens of servers we later attributed to   href="/content/fireeye-www/en_US/blog/threat-research/2019/01/apt39-iranian-cyber-espionage-group-focused-on-personal-information.html">APT39,
  often before they were used against a target.


 


  APT34 QUADAGENT


 

In February 2018, an independent researcher shared a sample of what
  would later be named QUADAGENT. We had not observed it in an intrusion
  yet; however, by analyzing the characteristics of the C2, we were able
  to develop a strong profile of the servers to track over time. For
  example, our team identified the server   class="code">185.161.208\.37 and domain   class="code">rdppath\.com within hours of it being established.
  A week later, we identified a QUADAGENT dropper with the previously
  identified C2. Additional examples of QUADAGENT are depicted in Figure 1.


 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/scandalous/Picture1.png" alt="" />
 
 Figure 1: QUADAGENT C2 servers in the
    Shodan user interface


 

Five days after the QUADAGENT dropper was identified, Mandiant was
  engaged by a victim that was targeted via the same C2. This activity
  was later attributed to APT34. During the investigation, Mandiant
  uncovered APT34 using RULER.HOMEPAGE. This was the first time our
  consultants observed the tool and technique used in the wild by a real
  threat actor. Our team developed a profile of servers hosting HOMEPAGE
  payloads and began tracking their deployment in the wild. Figure 2
  shows a timeline of QUADAGENT C2 servers discovered between February
  and November of 2018.


 


      src="https://www.fireeye.com/content/dam/fireeye-www/blog/images/scandalous/Picture2a.jpg" alt="" />
 
   
 Figure 2: Timeline of QUADAGENT C2 servers discovered
    throughout 2018


 


  APT33 RULER.HOMEPAGE, POSHC2, and POWERTON


 

A month after that aforementioned intrusion, Managed Defense
  discovered a threat actor using RULER.HOMEPAGE to download and execute
  POSHC2. All the RULER.HOMEPAGE servers were previously identified due
  to our efforts. Our team developed a profile for POSHC2 and began
  tracking their deployment in the wild. The threat actor pivoted to a
  novel PowerShell backdoor, POWERTON. Our team repeated our workflow
  and began illuminating those C2 servers as well. This activity was
  later attributed to APT33 and was documented in our


Tags: