Tuesday, May 26, 2015
Removing Software On Windows Using The Registry
The traditional way is to go into your configuration screen and then choose the "Program and Features". The list that is shown to you is actually read from the registry. Sometimes there is software in this list that does not give you the option Uninstall.
To deal with such software you got to go in the registry yourself and check for a couple of registry keys.
The starting path is
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall.
1. UninstallString
The UninstallString is a string that will give you a command that when run from the command line will remove the product from Windows. It is a command that uses Windows Installer. A nice source of information about this part of the registry is https://msdn.microsoft.com/en-us/library/aa372105%28VS.85%29.aspx
2. NoRemove
To hide the uninstall button in "Program and Features" for applications you'll need to find the NoRemove key. If the key is set to (hexadecimal) 1, you will not see the button If the value is set to (hexadecimal) 0, the Uninstall button will be visible.
After a couple of hours removing unwanted software the system was ready to be (ab)used by yours truly.
Monday, April 6, 2015
Analysis of Drixed samples
Koen Van Impe pointed out to me that the naming is actually confusing. My samples were Trojan droppers and named Drixed where there is also a banking Trojan called Dridex.
The documents I analyzed contained 2 modules with VBA code and one method that is triggered by the autoopen functionality. The code itself was obfuscated and depending on the document the obfuscation was different.
The autoopen is the instruction what the word document should do when opened automatically. What it basically did was to create an Microsoft.XMLHTTP object to fetch the file as binary data and then write it as an executable to disk in the TEMP folder. The Microsoft.XMLHTTP object was created to allow interaction with web servers (sending XML over HTTP) and thus also the download of a file.
The methodologies I observed for the retrieval were different, some were actually done in the VBA others were done by writing some vbs-script and then executing the script.
The tool I would recommend to extract is oledump.py by Didier Stevens. This helps you extract the VBA code without actually opening the document in a Word and thus accidentally starting the malware. Oledump.py requires the installation of the python olefile library to do its magic.
Is your starting point but all the info you need can be found on Didier Stevens' website. Basically you select your stream and dump the stream out (don't forget -v for decompression). The data I was interested in was in stream 7 (the macro module) so it looked like
$ python oledump.py file.doc
$ python oledump.py -s 7 -v file.docFrom a IR standpoint it was interesting to see that the download was using the IP addresses. The IP addresses were hacked websites. The fact that the threat actor can use the IP means that the whole sever is under his/her control. When you run the IP through Virustotal's database after +48 hours we see already another malware sample (it has a different hash) that was submitted using the same IP address. This tells you that the threat actor still has control of the server.
Another thing that was interesting is to see how they actually "hide". They downloaded in each case I saw an image from that IP address. Closer inspection actually revealed that the image extension was actually just a renamed Windows executable. The executable is your Trojan horse.
To get your sample the only thing you thus need to do is decipher the obfuscation (was not really hard in the cases I saw) and then go and get the image and rename it to exe. Then the next phase can start: tickle the malware for more info about its master ;).
Analysis of the Trojan Horse is not for this post, I just wanted to keep it on how you can get the samples being send to your organization. I ask you to share your samples or analysis/IOCs with your trusted people within other CERTs so that we don't reanalyze the same sample over and over again.
Maybe one last important thing to explain when discussing incidents like this. Although Drixed might be known by your AV-vendor, the Trojan might not be and since both can evolve (or change their obfuscation) you really got to be born under a lucky star to have a 100% match and totally protected at the time that first e-mail comes in.
Sunday, March 22, 2015
Java on Iceweasel
Download your java tar.gz from java.com and unpack the tag.gz in /opt/.
$ sudo tar -zxvf
A new folder in /opt/ is created with the content of the downloaded tar.gz file. We are going to use links so we can install multiple version in the future if that would be necessary.
$ sudo ln /opt/
We need to check the home variables:
$ JHome=/opt/java-sun
$ update-alternatives --install /usr/bin/java java ${JHOME% * /}/bin/java 20000
To check this java is the prefered way run:
$ update-alternatives --config java
Now we still need to configure the Iceweasel browser. Close all instances first.
$ sudo ln -sf /opt/java-sun/lib/amd64/libnpjp2.so /usr/lib/mozilla/plugins/libnpjp2.so
To check if everything works, open your Iceweasel browser and go to http://www.java.com/en/download/installed.jsp. Click on verify Java version and give it the permission to run.
Thursday, March 12, 2015
Back to basics
Recently I switched jobs and one of the interesting parts of changing jobs is everything is new and you have the 'fresh pair of eyes'.
The new environment has everything, a big network, mobile, malware and other attacks and a bunch of people.
It is this people factor that is actually the most challenging. Right now besides the technical aspects of the job, I am trying to convince a lot of people that the techie side of security is only a small fraction of the job.
Technically it has been the basics:
* user accounts and privileges
* tools
* network segregation
* vulnerability management
* incident response
Although it isn't possible for every organization to hire new infosec people all the time, it remains in my opinion a good exercise: Ask yourself why the things are as they are and evaluate the needs of the organization, they might have changed.
Friday, March 28, 2014
VIP Social Engineering
The thing was thus that a number of people I knew were VIP and I wanted access to the area were I was not supposed to come.
The first time I stopped at the lady checking the badges with my phone next to my ear, totally ignoring her and having a conversation with somebody who was actually inside. It was funny because I was describing the area loudly like "I see this banner, and to the left that poster and ... ok now I see you" and just walked right in like I belonged there without getting challenged.
The second time I wanted a different approach and got challenged. I showed my badge, she said I couldn't enter I asked why not so she had the feeling she was doing her job. Then I said, I really needed to talk to my colleague and pointed at a guy who was going to sit down. He was actually my colleague but I could have pointed at anybody just far away enough to make sure she couldn't leave her desk. Since she was alone, she had no way of going to check my story. She said ok, but I couldn't have any drinks or snacks ... sure, I said I needed a chat with that guy, no drinks, no snack.
One of the guys going in with me, piggy backed on my excuse and did not even have to speak a word, he just smiled.
Yes, we did this for fun and giggles but social engineering is daily used by bad people.
Sunday, March 9, 2014
SMS Scam
I want to tell you about a scam I received last Friday on my phone. I got during the evening a text message which was a nice piece of Social Engineering. The text message said "Appelle moi urgent 0010664112011".
The text was in French, a language spoken in my social circle, so I could have been tempted to call back. It is a classic in Belgium that people without any calling credit can send you a message that looks similar to this. This is for a lot of youngsters the way they communicate with their parents over the phone since they are most of the time out of credit.
The form that it is written in is interesting too. "Appelle moi" means "call me" so that is an instruction and if you would still hesitate it says that it is urgent and thus trying to take away any resistance. It uses the feeling of guilt that we have if we don't help somebody in need.
When I researched the number online it was immediately obvious that I was not the only one and there are number of variations. The best illustration of this is anruf-info.de. They collected some data which is interesting. If you look at the 7th, the evening I got the message there are quite a lot of Belgians reporting it, when a time stamp is given it was in the evening, just like mine. This could be an indication of some form of automatization. As we can see the day after on the 8th the scam just goes on.
Unfortunately I don't have any knowledge about how to trace the origin of this number but it would be very interesting.
Thursday, December 12, 2013
Tomtom password reset issue.
The Tomtom application that was installed on my family member's computer allowed my family member to trigger a password reset (by entering the e-mail address coupled to the account). My family member opened his mailbox and had a new e-mail from Tomtom with the password reset.
I got distracted in the process by the cat (cats are masters in social engineering) and asked to reset it a second time. In the inbox of my family member were thus 2 e-mails coming from the reset service. My family isn't into computers and thus when I asked to click the the link, they clicked on the first mail they saw, which was the eldest one. The reset worked and my family was happy, not realizing that this e-mail wasn't suppose to trigger the reset since there was a newer request for the reset.
The link in the e-mail looks like this:
http://www.tomtom.com/myTomTom/password_reminder_confirm.php?frm_email=familymember@mail.com&frm_check=f4357e2fa574a1764edcf077eaaf95dd
As you can see the format of the link is quite basic, an e-mail address and a hash.
On my way home I was going over the situation and asked my family member if I could get a copy of the e-mails to make sure if I didn't misinterpret something. I wondered if I could make a password reset now that the password was already reset.
I just clicked the link (no proxies in between) and did a reset of the password by using the form. Thus basically anybody who had that link could reset the password. What exact information you can find and how valuable the information is something I considered out of scope.
Since I work for CERT.be, I am familiar with the responsible disclosure guide of NCSC. The first problem I had was finding out who I had to contact at Tomtom. No information on their website, but I was lucky, the whois contact worked.
In CC of my e-mail to Tomtom I had put the NCSC (The CERT of The Netherlands) and CERT.be. The reason why is simply to have a cover-my-ass strategy. Tomtom is a company in The Netherlands and well I am a Belgian citizen that is why I chose to put both national CERT teams in copy. I do not want to get in trouble for discovering a problem, I just want it to get it fixed.
I got a reply from Tomtom on the 14th of June 2013. First of all they thanked me, they would look into the problem and promised me to keep me informed. The sad truth is that this last promise wasn't kept. I don't know if the reason why I never got a reply is that I was truthful about the fact I would write this blog entry about it.