Tuesday, July 26, 2016

Detecting CRYPMIC RANSOMWARE in Splunk

Two most widespread method of distributing malware are through email attachment (mailicious spam) and Exploit Kits. Email attachment requires users to trigger an action like opening the document, enabling the macro and so on for the malware to activate. EXploit Kits are more behind the scene, it does not require any additional action by the user.





Among the other Crypto-ransomware familes, CRYPMIC RANSOMWARE is more seen to be distributed by Neutrino EK, which have been recently reported to be delivering other ransomware families such as CryptoWall, TeslaCrypt, CryptoLocker and Cerber.

    BACKGROUND ON CRYPMIC RANSOMWARE:

    2016-07-06 - SANS ISC diary:  CryptXXX ransomware updated   [The date I first noticed this new branch of ransomware.]
    2016-07-14 - From the Proofpoint blog [link]: "We believe that CryptXXX is in active development and possibly split off into two branches. The original branch is now up to version 5.001 (we wrote about the upgrade to version 3.100 near the end of May), while the new branch uses a different format for versioning and will require further analysis."
    2016-07-20 - TrendLabs Security Intelligence Blog - CrypMIC Ransomware Wants to Follow CryptXXX's Footsteps   [TrendLabs analyzes the new branch and names it.]

This post shows the ways to identify and detect the malicious traffic and associated files files within the logs. The sample log file is obtained from malware-traffic-analysis.net. My lab set-up for this review is as follows. I ran suricata against the file and set splunk to monitor the output (simple file monitor)




File Name - "2016-07-28 - PSEUDO-DARKLEECH NEUTRINO EK SENDS CRYPMIC RANSOMWARE"

Malicious Files and the sites that downloaded the payload







Splunk Searches


Timeline of events
index="network" sourcetype="pcap_json" source="*$source$*"   | timechart count by $split$ limit=10 useother=0 usenull=0

HTTP Traffic
index="network" sourcetype="pcap_json" source="*" event_type=http | iplocation src_ip | table timestamp pcap_cnt src_ip Country dest_ip dest_port http.http_content_type proto http.hostname http.url

Search to identify the http_method
index=suricata OR index=network sourcetype=pcap_json source!="*stats.log"  "http.http_content_type"="application*" | table _time dest_ip, pcap_cnt, http.http_content_type, http.hostname, http.url

Files Downloaded
index="network" sourcetype="pcap_json" source="*$source$*" event_type=fileinfo | iplocation src_ip | table timestamp pcap_cnt event_type src_ip Country dest_ip dest_port  fileinfo.filename http.hostname http.url  | sort timestamp





 
001
002
003
004
005
006
007
008
009
010
011
012
013
014
015
016
017
018
019
020
021
022
023
024
025
026
027
028
029
030
031
032
033
034
035
036
037
038
039
040
041
042
043
044
045
046
047
048
049
050
051
052
053
054
055
056
057
058
059
060
061
062
063
064
065
066
067
068
069
070
071
072
073
074
075
076
077
078
079
080
081
082
083
084
085
086
087
088
089
090
091
092
093
094
095
096
097
098
099
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
<form script="tabs.js" stylesheet="tabs.css,dark.css">
  <label>Suricata IDS Dashboard</label>
  <description>Splunk Dashboard for Suricata IDS Events</description>
  <fieldset submitButton="true" autoRun="true">
    <input type="time" token="timestamp" searchWhenChanged="true">
      <label>Time picker</label>
      <default>
        <earliest>-7d@h</earliest>
        <latest>now</latest>
      </default>
    </input>
    <input type="dropdown" token="split" searchWhenChanged="true">
      <label>Split by:</label>
      <choice value="alert.signature">alert.signature</choice>
      <choice value="dest_port">dest_port</choice>
      <choice value="dest_ip">dest_ip</choice>
      <choice value="dns.rrtype">dns.rrtype</choice>
      <choice value="event_type">event_type</choice>
      <choice value="host">host</choice>
      <choice value="http.hostname">http.hostname</choice>
      <choice value="http.http_refer">http.http_refer</choice>
      <choice value="http.redirect">http.redirect</choice>
      <choice value="http.status">http.status</choice>
      <choice value="http.url">http.url</choice>
      <choice value="src_ip">src_ip</choice>
      <choice value="tls.issuerdn">tls.issuerdn</choice>
      <choice value="tls.subject">tls.subject</choice>
      <choice value="tls.version">tls.version</choice>
      <default>http.hostname</default>
    </input>
    <input type="text" token="source" searchWhenChanged="true">
      <default>*</default>
    </input>
  </fieldset>
  <row>
    <panel>
      <chart id="item_1">
        <title>Timeline of Event</title>
        <search>
          <query>index="network" sourcetype="pcap_json" source="*$source$*"   | timechart count by $split$ limit=10 useother=0 usenull=0</query>
          <earliest>$timestamp.earliest$</earliest>
          <latest>$timestamp.latest$</latest>
        </search>
        <option name="charting.axisLabelsX.majorLabelStyle.overflowMode">ellipsisNone</option>
        <option name="charting.axisLabelsX.majorLabelStyle.rotation">0</option>
        <option name="charting.axisTitleX.visibility">visible</option>
        <option name="charting.axisTitleY.visibility">visible</option>
        <option name="charting.axisTitleY2.visibility">visible</option>
        <option name="charting.axisX.scale">linear</option>
        <option name="charting.axisY.scale">linear</option>
        <option name="charting.axisY2.enabled">0</option>
        <option name="charting.axisY2.scale">inherit</option>
        <option name="charting.chart">column</option>
        <option name="charting.chart.bubbleMaximumSize">50</option>
        <option name="charting.chart.bubbleMinimumSize">10</option>
        <option name="charting.chart.bubbleSizeBy">area</option>
        <option name="charting.chart.nullValueMode">gaps</option>
        <option name="charting.chart.sliceCollapsingThreshold">0</option>
        <option name="charting.chart.stackMode">stacked</option>
        <option name="charting.chart.style">shiny</option>
        <option name="charting.drilldown">all</option>
        <option name="charting.layout.splitSeries">0</option>
        <option name="charting.legend.labelStyle.overflowMode">ellipsisMiddle</option>
        <option name="charting.legend.placement">bottom</option>
        <option name="charting.chart.showDataLabels">none</option>
        <option name="charting.layout.splitSeries.allowIndependentYRanges">0</option>
      </chart>
    </panel>
  </row>
  <row id="tabs">
    <panel>
      <html>
        <ul id="tabs" class="nav nav-tabs">
          <li class="active">
            <a href="#" class="toggle-tab" data-toggle="tab" data-elements="tab_http" data-token="control_token_1">HTTP_Traffic</a>
          </li>
          <li>
            <a href="#" class="toggle-tab" data-toggle="tab" data-elements="tabs_ids" data-token="control_token_2">IDS_Alerts</a>
          </li>
          <li>
            <a href="#" class="toggle-tab" data-toggle="tab" data-elements="tabs_dns" data-token="control_token_3">DNS_Traffic</a>
          </li>
          <li>
            <a href="#" class="toggle-tab" data-toggle="tab" data-elements="tabs_tls" data-token="control_token_4">TLS_Traffic</a>
          </li>
          <li>
            <a href="#" class="toggle-tab" data-toggle="tab" data-elements="tabs_files" data-token="control_token_5">Files_Downloaded</a>
          </li>
          
        </ul>
      </html>
    </panel>
  </row>
  <row id="tabs_ids">
    <panel>
      <title>IDS_Alerts</title>
      <table>
        <search>
          <query>index=suricata OR index=network sourcetype=pcap_json source!="*stats.log"  "http.http_content_type"="application*" | table _time dest_ip, pcap_cnt, http.http_content_type, http.hostname, http.url</query>
          <earliest>$timestamp.earliest$</earliest>
          <latest>$timestamp.latest$</latest>
        </search>
        <option name="wrap">true</option>
        <option name="rowNumbers">false</option>
        <option name="drilldown">cell</option>
        <option name="dataOverlayMode">none</option>
        <option name="count">20</option>
        <drilldown>
          <condition field="alert.signature">
            <set token="alert.signature">$row.alert.signature$</set>
          </condition>
        </drilldown>
      </table>
    </panel>
  </row>
  <row id="tabs_dns">
    <panel>
      <title>DNS_Traffic</title>
      <table>
        <search>
          <query>index="network" sourcetype="pcap_json" source="*$source$*"  event_type=dns| iplocation dns.rdata  | table  timestamp src_ip dest_ip dest_port dns.rdata Country dns.rrname dns.rrtype dns.type</query>
          <earliest>$timestamp.earliest$</earliest>
          <latest>$timestamp.latest$</latest>
        </search>
        <option name="wrap">undefined</option>
        <option name="rowNumbers">undefined</option>
        <option name="drilldown">row</option>
        <option name="count">20</option>
        <option name="dataOverlayMode">none</option>
      </table>
    </panel>
  </row>
  <row id="tabs_tls">
    <panel>
      <title>TLS_Traffic</title>
      <table>
        <search>
          <query>index="network" sourcetype="pcap_json" source="*$source$*" event_type=tls| table timestamp pcap_cnt event_type src_ip dest_ip dest_port tls.issuerdn tls.subject</query>
          <earliest>$timestamp.earliest$</earliest>
          <latest>$timestamp.latest$</latest>
        </search>
        <option name="wrap">undefined</option>
        <option name="rowNumbers">undefined</option>
        <option name="drilldown">row</option>
        <option name="dataOverlayMode">none</option>
        <option name="count">10</option>
      </table>
    </panel>
  </row>
  <row id="tabs_files">
    <panel>
      <title>Files_Downloaded</title>
      <table>
        <search>
          <query>index="network" sourcetype="pcap_json" source="*$source$*" event_type=fileinfo | iplocation src_ip | table timestamp pcap_cnt event_type src_ip Country dest_ip dest_port  fileinfo.filename http.hostname http.url  | sort timestamp</query>
          <earliest>$timestamp.earliest$</earliest>
          <latest>$timestamp.latest$</latest>
        </search>
        <option name="wrap">undefined</option>
        <option name="rowNumbers">undefined</option>
        <option name="drilldown">row</option>
        <option name="dataOverlayMode">none</option>
        <option name="count">10</option>
      </table>
    </panel>
  </row>
  <row>
    <panel>
      <title>HTTP_Traffic</title>
      <table>
        <search>
          <query>index="network" sourcetype="pcap_json" source="*$source$*" event_type=http | iplocation src_ip | table timestamp pcap_cnt src_ip Country dest_ip dest_port http.http_content_type proto http.hostname http.url</query>
          <earliest>$timestamp.earliest$</earliest>
          <latest>$timestamp.latest$</latest>
        </search>
        <option name="wrap">true</option>
        <option name="rowNumbers">false</option>
        <option name="dataOverlayMode">none</option>
        <option name="drilldown">cell</option>
        <option name="count">10</option>
      </table>
    </panel>
  </row>
  <row>
    <panel>
      <event id="detail" depends="$alert.signature$">
        <title>Event Details for signature - $alert.signature$</title>
        <search>
          <query>index="network" sourcetype="pcap_json" source="*$source$*" alert.signature!="\*suricata\*"       alert.signature="$alert.signature$"</query>
          <earliest>$timestamp.earliest$</earliest>
          <latest>$timestamp.latest$</latest>
        </search>
        <option name="list.drilldown">full</option>
        <option name="list.wrap">1</option>
        <option name="maxLines">5</option>
        <option name="raw.drilldown">full</option>
        <option name="rowNumbers">0</option>
        <option name="table.drilldown">all</option>
        <option name="table.wrap">1</option>
        <option name="type">list</option>
        <option name="count">10</option>
        <fields>["host","source","sourcetype"]</fields>
      </event>
    </panel>
  </row>
</form>
 
 
<form script="tabs.js" stylesheet="tabs.css,dark.css">
  <label>Suricata IDS Dashboard</label>
  <description>Splunk Dashboard for Suricata IDS Events</description>
  <fieldset submitButton="true" autoRun="true">
    <input type="time" token="timestamp" searchWhenChanged="true">
      <label>Time picker</label>
      <default>
        <earliest>-7d@h</earliest>
        <latest>now</latest>
      </default>
    </input>
    <input type="dropdown" token="split" searchWhenChanged="true">
      <label>Split by:</label>
      <choice value="alert.signature">alert.signature</choice>
      <choice value="dest_port">dest_port</choice>
      <choice value="dest_ip">dest_ip</choice>
      <choice value="dns.rrtype">dns.rrtype</choice>
      <choice value="event_type">event_type</choice>
      <choice value="host">host</choice>
      <choice value="http.hostname">http.hostname</choice>
      <choice value="http.http_refer">http.http_refer</choice>
      <choice value="http.redirect">http.redirect</choice>
      <choice value="http.status">http.status</choice>
      <choice value="http.url">http.url</choice>
      <choice value="src_ip">src_ip</choice>
      <choice value="tls.issuerdn">tls.issuerdn</choice>
      <choice value="tls.subject">tls.subject</choice>
      <choice value="tls.version">tls.version</choice>
      <default>http.hostname</default>
    </input>
    <input type="text" token="source" searchWhenChanged="true">
      <default>*</default>
    </input>
  </fieldset>
  <row>
    <panel>
      <chart id="item_1">
        <title>Timeline of Event</title>
        <search>
          <query>index="network" sourcetype="pcap_json" source="*$source$*"   | timechart count by $split$ limit=10 useother=0 usenull=0</query>
          <earliest>$timestamp.earliest$</earliest>
          <latest>$timestamp.latest$</latest>
        </search>
        <option name="charting.axisLabelsX.majorLabelStyle.overflowMode">ellipsisNone</option>
        <option name="charting.axisLabelsX.majorLabelStyle.rotation">0</option>
        <option name="charting.axisTitleX.visibility">visible</option>
        <option name="charting.axisTitleY.visibility">visible</option>
        <option name="charting.axisTitleY2.visibility">visible</option>
        <option name="charting.axisX.scale">linear</option>
        <option name="charting.axisY.scale">linear</option>
        <option name="charting.axisY2.enabled">0</option>
        <option name="charting.axisY2.scale">inherit</option>
        <option name="charting.chart">column</option>
        <option name="charting.chart.bubbleMaximumSize">50</option>
        <option name="charting.chart.bubbleMinimumSize">10</option>
        <option name="charting.chart.bubbleSizeBy">area</option>
        <option name="charting.chart.nullValueMode">gaps</option>
        <option name="charting.chart.sliceCollapsingThreshold">0</option>
        <option name="charting.chart.stackMode">stacked</option>
        <option name="charting.chart.style">shiny</option>
        <option name="charting.drilldown">all</option>
        <option name="charting.layout.splitSeries">0</option>
        <option name="charting.legend.labelStyle.overflowMode">ellipsisMiddle</option>
        <option name="charting.legend.placement">bottom</option>
        <option name="charting.chart.showDataLabels">none</option>
        <option name="charting.layout.splitSeries.allowIndependentYRanges">0</option>
      </chart>
    </panel>
  </row>
  <row id="tabs">
    <panel>
      <html>
        <ul id="tabs" class="nav nav-tabs">
          <li class="active">
            <a href="#" class="toggle-tab" data-toggle="tab" data-elements="tab_http" data-token="control_token_1">HTTP_Traffic</a>
          </li>
          <li>
            <a href="#" class="toggle-tab" data-toggle="tab" data-elements="tabs_ids" data-token="control_token_2">IDS_Alerts</a>
          </li>
          <li>
            <a href="#" class="toggle-tab" data-toggle="tab" data-elements="tabs_dns" data-token="control_token_3">DNS_Traffic</a>
          </li>
          <li>
            <a href="#" class="toggle-tab" data-toggle="tab" data-elements="tabs_tls" data-token="control_token_4">TLS_Traffic</a>
          </li>
          <li>
            <a href="#" class="toggle-tab" data-toggle="tab" data-elements="tabs_files" data-token="control_token_5">Files_Downloaded</a>
          </li>
         
        </ul>
      </html>
    </panel>
  </row>
  <row id="tabs_ids">
    <panel>
      <title>IDS_Alerts</title>
      <table>
        <search>
          <query>index=suricata OR index=network sourcetype=pcap_json source!="*stats.log"  "http.http_content_type"="application*" | table _time dest_ip, pcap_cnt, http.http_content_type, http.hostname, http.url</query>
          <earliest>$timestamp.earliest$</earliest>
          <latest>$timestamp.latest$</latest>
        </search>
        <option name="wrap">true</option>
        <option name="rowNumbers">false</option>
        <option name="drilldown">cell</option>
        <option name="dataOverlayMode">none</option>
        <option name="count">20</option>
        <drilldown>
          <condition field="alert.signature">
            <set token="alert.signature">$row.alert.signature$</set>
          </condition>
        </drilldown>
      </table>
    </panel>
  </row>
  <row id="tabs_dns">
    <panel>
      <title>DNS_Traffic</title>
      <table>
        <search>
          <query>index="network" sourcetype="pcap_json" source="*$source$*"  event_type=dns| iplocation dns.rdata  | table  timestamp src_ip dest_ip dest_port dns.rdata Country dns.rrname dns.rrtype dns.type</query>
          <earliest>$timestamp.earliest$</earliest>
          <latest>$timestamp.latest$</latest>
        </search>
        <option name="wrap">undefined</option>
        <option name="rowNumbers">undefined</option>
        <option name="drilldown">row</option>
        <option name="count">20</option>
        <option name="dataOverlayMode">none</option>
      </table>
    </panel>
  </row>
  <row id="tabs_tls">
    <panel>
      <title>TLS_Traffic</title>
      <table>
        <search>
          <query>index="network" sourcetype="pcap_json" source="*$source$*" event_type=tls| table timestamp pcap_cnt event_type src_ip dest_ip dest_port tls.issuerdn tls.subject</query>
          <earliest>$timestamp.earliest$</earliest>
          <latest>$timestamp.latest$</latest>
        </search>
        <option name="wrap">undefined</option>
        <option name="rowNumbers">undefined</option>
        <option name="drilldown">row</option>
        <option name="dataOverlayMode">none</option>
        <option name="count">10</option>
      </table>
    </panel>
  </row>
  <row id="tabs_files">
    <panel>
      <title>Files_Downloaded</title>
      <table>
        <search>
          <query>index="network" sourcetype="pcap_json" source="*$source$*" event_type=fileinfo | iplocation src_ip | table timestamp pcap_cnt event_type src_ip Country dest_ip dest_port  fileinfo.filename http.hostname http.url  | sort timestamp</query>
          <earliest>$timestamp.earliest$</earliest>
          <latest>$timestamp.latest$</latest>
        </search>
        <option name="wrap">undefined</option>
        <option name="rowNumbers">undefined</option>
        <option name="drilldown">row</option>
        <option name="dataOverlayMode">none</option>
        <option name="count">10</option>
      </table>
    </panel>
  </row>
  <row>
    <panel>
      <title>HTTP_Traffic</title>
      <table>
        <search>
          <query>index="network" sourcetype="pcap_json" source="*$source$*" event_type=http | iplocation src_ip | table timestamp pcap_cnt src_ip Country dest_ip dest_port http.http_content_type proto http.hostname http.url</query>
          <earliest>$timestamp.earliest$</earliest>
          <latest>$timestamp.latest$</latest>
        </search>
        <option name="wrap">true</option>
        <option name="rowNumbers">false</option>
        <option name="dataOverlayMode">none</option>
        <option name="drilldown">cell</option>
        <option name="count">10</option>
      </table>
    </panel>
  </row>
  <row>
    <panel>
      <event id="detail" depends="$alert.signature$">
        <title>Event Details for signature - $alert.signature$</title>
        <search>
          <query>index="network" sourcetype="pcap_json" source="*$source$*" alert.signature!="\*suricata\*"       alert.signature="$alert.signature$"</query>
          <earliest>$timestamp.earliest$</earliest>
          <latest>$timestamp.latest$</latest>
        </search>
        <option name="list.drilldown">full</option>
        <option name="list.wrap">1</option>
        <option name="maxLines">5</option>
        <option name="raw.drilldown">full</option>
        <option name="rowNumbers">0</option>
        <option name="table.drilldown">all</option>
        <option name="table.wrap">1</option>
        <option name="type">list</option>
        <option name="count">10</option>
        <fields>["host","source","sourcetype"]</fields>
      </event>
    </panel>
  </row>
</form>