Code Monkey home page Code Monkey logo

wiper-no-wiping's Introduction

Wiper No Wiping!

alt text

TLDR // Sparknotes - What Should I Do Right Now?

  • Patch all the things!

    • Apply vendor security updates on endpoints, servers, etc asap
  • Leverage Vulnerability Scanners

    • Identify vulnerable machines and prioritize patching/updating in order of asset criticality
    • Defending against zero-day exploits is more complicated but we do know that this malware has been previously deployed leveraging known exploits
    • Don't be low-hanging fruit :)
  • Update AV Software & IDS Rules

    • There is a good chance your vendors have already released updates to help defend against this threat
    • Clicking an update button is one of the easiest wins (someone else has already done the work)
  • Backup Now

    • If you haven't backed up critical data in a bit, now's a good time
    • Offline backups are your friend, otherwise ensure backup servers are well-protected (see above)

Specific Vulnerabilities That Have Been Leveraged - Patch These NOW!

  • Apache Tomcat
  • Microsoft Exchange
  • Microsoft SQL Priv-Esc (CVE-2021-1636)

How Can We Detect/Prevent The Malware?

Items in This Repo

  • Hash List (hash-brown.md)

    • This is a combined list of hashes for known-nasty files related to the malware
    • This list can be used to create IDS & EDR rules in bulk for easy detection
  • Domain & IP List (dns-ip.md)

    • This is a combined list of domains and servers I've seen mentioned in relation to this malware
    • I would be flagging (and/or blocking) these items to identify hosts that may be infected
    • These servers may be used for C2 or component download
      • If it's the second item, it may be possible to stop it from downloading additional components needed to detonate (here's hoping)
  • Registry Modifications (registry-keys.md)

    • This is a list of registry keys the malware is known to modify/create throughout the attack cycle
  • File Activity (file-activity.md)

    • This is a list of the files the malware is known to create/modify throughout the attack cycle

Central Document (Migrating Entirely to this Repo Soon)

https://docs.google.com/document/d/1KK2hCH9WmwACVup7VTIAYEgVzGcZsaqUlx0J_IFtmt0/edit?usp=sharing

Coming Soon

  • OSQuery Threat Hunting Pack
  • Suricata rules
  • Elastic XDR rules

Open Source & Free Solutions to Secure Your World

  • OSSEC
  • Wazah
  • Yara
  • Osquery
  • Suricata

Reading Material

https://www.cisa.gov/uscert/shields-technical-guidance

https://www.cisa.gov/uscert/ncas/alerts/aa22-057a

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ukraine-wiper-malware-russia

https://www.cyberark.com/resources/blog/hermeticwiper-what-we-know-about-new-malware-targeting-ukrainian-infrastructure-thus-far

http://blog.talosintelligence.com/2022/02/threat-advisory-hermeticwiper.html

https://www.zscaler.com/blogs/security-research/hermetic-wiper-resurgence-targeted-attacks-ukraine

https://zetter.substack.com/p/second-wiper-attack-strikes-systems?utm_source=url

https://www.ired.team/offensive-security/credential-access-and-credential-dumping/dump-credentials-from-lsass-process-without-mimikatz

https://www.sentinelone.com/labs/hermetic-wiper-ukraine-under-attack/

https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/

https://securityintelligence.com/posts/new-destructive-malware-cyber-attacks-ukraine/

https://www.crowdstrike.com/blog/how-crowdstrike-falcon-protects-against-wiper-malware-used-in-ukraine-attacks/

https://socradar.io/what-you-need-to-know-about-russian-cyber-escalation-in-ukraine/

wiper-no-wiping's People

Contributors

ben3636 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.