SlideShare a Scribd company logo
Jaff spambot
Necurs spam bot
• 2016 Q2
• Spammer
Botnet
• Malicious
spam pushing
Jaff (a worm)
• Necur
spambot
automated
server
WannaCry
Ransomware+Worm
Petya Ransomware
+Worm
• Q1 2017
Worldwide
attack x2
• increase in
platform level
malware with
worm
functionality
• beacon to
command
and control
server for
malware
fetch
• PuPs that
block security
protocols
NotPetya+WannaCryRansom
wareworm
DoublePulsar
VPNFilter Botnet immerging
from fallout
• 2017 Q2-2018
• Used stolen
ransomware and
modified it
• Infection_iinstall_ki
llswitch_seek
• repeat
• developers used
WannaCry
• families coming
from same
creators?
All Windows OS except XP not effected because
NETBIOS was removed. VPNFilter currently
comprimising SOHO routers to push botnet.
Nmap common port numbers (SMB)
TCP port 445 direct UDP port 137, 138 &
TCP 137,139
VpN Filter PenTrap examines IPs in/out
Mimikatz 2.0 Kerberos Golden Ticket
autonomized memory extraction tool
assume domain admin rights anytime
Eternalblue SMB Exploit
• Green and Red Petya (2016)
• +Mishya
• +GoldenEye (bootlocker+files)
• WannaCry
Auto Lateral Movement (PSExec and WMIC)
Auto Scans subnets for devices and hosts
DeepFreeze is a WinOS terminal hijacker
Necurs botnet pushed Jaff at 5 million
m.p.h from social media sites
Comprimised SOHO routers by VPNFilter
Trojan:Win32/Necurs with registry change
for bootup (like Netcat)
• Notpetya: In less then 20 minutes it; 1)
Rewrites Master Boot Registry (MBR) to boot
to malware. 2) Encrypt NTFS file system using
AES-128bit encryption key and 3) Spreads
internally --on a that timer.
Hiding
Online is
Easy!
Bullet Proof
Hosting
and VPNs
Proxy Servers
and
anonymous
comm tools
Untraceable
email
accounts
Decentralized
Digital
Currency
Offensive Security:
- any change in
darknet traffic is key
Beware of calling
cards: "Sandworm" or
"Telebots"
"The ShadowBrokers"
"Equation Group"
Ukraine is a creation
and testing hub for
attacks due to cultural
and historical Russian
forced statehood and
indocternation.
Patch (CVE-2017-0144) and disable SMBv1
Utilize Open Source Intelligence (OSINT): share, validate, and contextualize.
Recorded Future (Click me)
Block outside access to ports 137, 138, 139, and 445.
Buy/report any call-out domains instantly-
No admin gets carte blanche over the network--limit to domain admins
sudo rule-update malware-traffic-net
Submit pCap logs to Virus Total
automated vulnerability scanner like open-vas
Creating read-only file C:Windowsperfc.dat
this will not prevent spread but will prevent host MBR encryption
Key released! download decryptors from Malwarebytes
ISO Live CD and the Windows Executable

More Related Content

PDF
Хакеры хотят ваш банк больше, чем ваших клиентов
PPTX
Ник Белогорский - Будни Кремниевой Долины. История карьеры Ника, борьба с хак...
PDF
Инциденты с использованием ransomware. Расследование
PDF
about botnets
PDF
勒索軟體態勢與應措
PPTX
introduction to Botnet
PPTX
How Microsoft will MiTM your network
PPTX
Botnets
Хакеры хотят ваш банк больше, чем ваших клиентов
Ник Белогорский - Будни Кремниевой Долины. История карьеры Ника, борьба с хак...
Инциденты с использованием ransomware. Расследование
about botnets
勒索軟體態勢與應措
introduction to Botnet
How Microsoft will MiTM your network
Botnets

What's hot (20)

PPT
Dynamic Port Scanning
PDF
Symantec Freak Vulnerability Infographic
PDF
BlueHat v18 || The matrix has you - protecting linux using deception
PPTX
Know Your Worm (Conficker)
PPS
Conficker
PDF
What is botnet?
PPTX
Botnets 101
PPTX
Telehack: May the Command Line Live Forever
PPT
Security & ethical hacking
PDF
Hardening Three - IDS/IPS Technologies
PDF
BOTNET
PDF
Hacking Exposed LIVE: Attacking in the Shadows
PPT
Anton Chuvakin on Honeypots
DOC
Days of the Honeynet: Attacks, Tools, Incidents
PPT
Conficker
PPT
PPTX
Building a Cyber Range - Kevin Cardwell
PPT
Botnet Detection Techniques
KEY
Metasploit Exploitation Scenarios -EN : Scenario 1
PPTX
Botnets presentation
Dynamic Port Scanning
Symantec Freak Vulnerability Infographic
BlueHat v18 || The matrix has you - protecting linux using deception
Know Your Worm (Conficker)
Conficker
What is botnet?
Botnets 101
Telehack: May the Command Line Live Forever
Security & ethical hacking
Hardening Three - IDS/IPS Technologies
BOTNET
Hacking Exposed LIVE: Attacking in the Shadows
Anton Chuvakin on Honeypots
Days of the Honeynet: Attacks, Tools, Incidents
Conficker
Building a Cyber Range - Kevin Cardwell
Botnet Detection Techniques
Metasploit Exploitation Scenarios -EN : Scenario 1
Botnets presentation
Ad

Similar to Exploits (20)

PPT
Malware
PDF
Malware threats in our cyber infrastructure
DOCX
Full report final for NotPetya
DOCX
NotPetya Report
PDF
Symantec White Paper: W32.Ramnit Analysis
PDF
Meet Remaiten : Malware Builds Botnet on Linux based routers and potentially ...
PPT
Presentation Prepared By: Mohamad Almajali
PDF
DTS Solution - Yehia Mamdouh - Release your pet worm on your infrastructure....
PDF
Bot software spreads, causes new worries
PPTX
Ransomware - what is it, how to protect against it
PPTX
Botnets Attacks.pptx
PDF
Analysis of rxbot
PPTX
How to save home PCs for being Zombies ?
PDF
Life Cycle And Detection Of Bot Infections Through Network Traffic Analysis
PDF
Taming botnets
PPTX
งานนำเสนอNew
PDF
Operation Buhtrap - AVAR 2015
PPT
10-malware and online safety preacuations
PPT
Defending Against Botnets
PPT
Analysis Of Adverarial Code - The Role of Malware Kits
Malware
Malware threats in our cyber infrastructure
Full report final for NotPetya
NotPetya Report
Symantec White Paper: W32.Ramnit Analysis
Meet Remaiten : Malware Builds Botnet on Linux based routers and potentially ...
Presentation Prepared By: Mohamad Almajali
DTS Solution - Yehia Mamdouh - Release your pet worm on your infrastructure....
Bot software spreads, causes new worries
Ransomware - what is it, how to protect against it
Botnets Attacks.pptx
Analysis of rxbot
How to save home PCs for being Zombies ?
Life Cycle And Detection Of Bot Infections Through Network Traffic Analysis
Taming botnets
งานนำเสนอNew
Operation Buhtrap - AVAR 2015
10-malware and online safety preacuations
Defending Against Botnets
Analysis Of Adverarial Code - The Role of Malware Kits
Ad

Recently uploaded (20)

PDF
IFRS Notes in your pocket for study all the time
PPTX
svnfcksanfskjcsnvvjknsnvsdscnsncxasxa saccacxsax
PPTX
Belch_12e_PPT_Ch18_Accessible_university.pptx
PPTX
3. HISTORICAL PERSPECTIVE UNIIT 3^..pptx
PPT
Lecture 3344;;,,(,(((((((((((((((((((((((
PDF
How to Get Funding for Your Trucking Business
PDF
Keppel_Proposed Divestment of M1 Limited
PDF
Laughter Yoga Basic Learning Workshop Manual
DOCX
Business Management - unit 1 and 2
PDF
kom-180-proposal-for-a-directive-amending-directive-2014-45-eu-and-directive-...
PPTX
Board-Reporting-Package-by-Umbrex-5-23-23.pptx
PDF
Ôn tập tiếng anh trong kinh doanh nâng cao
PDF
SBI Securities Weekly Wrap 08-08-2025_250808_205045.pdf
PDF
Solaris Resources Presentation - Corporate August 2025.pdf
PDF
Cours de Système d'information about ERP.pdf
PPT
340036916-American-Literature-Literary-Period-Overview.ppt
PPTX
2025 Product Deck V1.0.pptxCATALOGTCLCIA
PDF
Stem Cell Market Report | Trends, Growth & Forecast 2025-2034
PDF
Power and position in leadershipDOC-20250808-WA0011..pdf
PPTX
DMT - Profile Brief About Business .pptx
IFRS Notes in your pocket for study all the time
svnfcksanfskjcsnvvjknsnvsdscnsncxasxa saccacxsax
Belch_12e_PPT_Ch18_Accessible_university.pptx
3. HISTORICAL PERSPECTIVE UNIIT 3^..pptx
Lecture 3344;;,,(,(((((((((((((((((((((((
How to Get Funding for Your Trucking Business
Keppel_Proposed Divestment of M1 Limited
Laughter Yoga Basic Learning Workshop Manual
Business Management - unit 1 and 2
kom-180-proposal-for-a-directive-amending-directive-2014-45-eu-and-directive-...
Board-Reporting-Package-by-Umbrex-5-23-23.pptx
Ôn tập tiếng anh trong kinh doanh nâng cao
SBI Securities Weekly Wrap 08-08-2025_250808_205045.pdf
Solaris Resources Presentation - Corporate August 2025.pdf
Cours de Système d'information about ERP.pdf
340036916-American-Literature-Literary-Period-Overview.ppt
2025 Product Deck V1.0.pptxCATALOGTCLCIA
Stem Cell Market Report | Trends, Growth & Forecast 2025-2034
Power and position in leadershipDOC-20250808-WA0011..pdf
DMT - Profile Brief About Business .pptx

Exploits

  • 1. Jaff spambot Necurs spam bot • 2016 Q2 • Spammer Botnet • Malicious spam pushing Jaff (a worm) • Necur spambot automated server WannaCry Ransomware+Worm Petya Ransomware +Worm • Q1 2017 Worldwide attack x2 • increase in platform level malware with worm functionality • beacon to command and control server for malware fetch • PuPs that block security protocols NotPetya+WannaCryRansom wareworm DoublePulsar VPNFilter Botnet immerging from fallout • 2017 Q2-2018 • Used stolen ransomware and modified it • Infection_iinstall_ki llswitch_seek • repeat • developers used WannaCry • families coming from same creators?
  • 2. All Windows OS except XP not effected because NETBIOS was removed. VPNFilter currently comprimising SOHO routers to push botnet. Nmap common port numbers (SMB) TCP port 445 direct UDP port 137, 138 & TCP 137,139 VpN Filter PenTrap examines IPs in/out Mimikatz 2.0 Kerberos Golden Ticket autonomized memory extraction tool assume domain admin rights anytime Eternalblue SMB Exploit • Green and Red Petya (2016) • +Mishya • +GoldenEye (bootlocker+files) • WannaCry Auto Lateral Movement (PSExec and WMIC) Auto Scans subnets for devices and hosts DeepFreeze is a WinOS terminal hijacker Necurs botnet pushed Jaff at 5 million m.p.h from social media sites Comprimised SOHO routers by VPNFilter Trojan:Win32/Necurs with registry change for bootup (like Netcat)
  • 3. • Notpetya: In less then 20 minutes it; 1) Rewrites Master Boot Registry (MBR) to boot to malware. 2) Encrypt NTFS file system using AES-128bit encryption key and 3) Spreads internally --on a that timer.
  • 4. Hiding Online is Easy! Bullet Proof Hosting and VPNs Proxy Servers and anonymous comm tools Untraceable email accounts Decentralized Digital Currency
  • 5. Offensive Security: - any change in darknet traffic is key Beware of calling cards: "Sandworm" or "Telebots" "The ShadowBrokers" "Equation Group" Ukraine is a creation and testing hub for attacks due to cultural and historical Russian forced statehood and indocternation. Patch (CVE-2017-0144) and disable SMBv1 Utilize Open Source Intelligence (OSINT): share, validate, and contextualize. Recorded Future (Click me) Block outside access to ports 137, 138, 139, and 445. Buy/report any call-out domains instantly- No admin gets carte blanche over the network--limit to domain admins sudo rule-update malware-traffic-net Submit pCap logs to Virus Total automated vulnerability scanner like open-vas Creating read-only file C:Windowsperfc.dat this will not prevent spread but will prevent host MBR encryption Key released! download decryptors from Malwarebytes ISO Live CD and the Windows Executable