dissecting exploit kits - rootcon 11/talks/dissecting... · 2017-09-25 · 10 in 2016, adobe flash...

30
1 DISSECTING EXPLOIT KITS DANIEL FRANK

Upload: others

Post on 08-Jul-2020

4 views

Category:

Documents


1 download

TRANSCRIPT

Page 1: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

1

DISSECTING EXPLOIT KITS

DANIEL FRANK

Page 2: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

2

Security Researcher

Developer

Speaker (Microsoft DCC 2016, ROOTCON 11)

[email protected]

@dani3lfrank

WHO AM I

Page 3: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

3

Exploit Kits flow and top vulnerabilities

Market and geolocation related stats

Magnitude Exploit Kit with live demoes

Sundown Exploit Kit with live demoes

Conclusions

AGENDA

Page 4: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

4

Page 5: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

5

Demo time?

Already?

Page 6: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

6

LIVE DEMO

Page 7: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

7

EXPLOIT KITS FLOW AND TOP VULNERABILITIES

Page 8: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

8

A toolkit

Redirects victim to a landing page

Identifies and exploits client side vulnerabilities

Delivers malicious payload

WHAT IS AN EXPLOIT KIT

Page 9: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

9

Redirection

Landing page

User machine

identificationExploitation

Payload

EXPLOIT KIT FLOW

Page 10: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

10

In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits

Rest of the top 10 are IE and Silverlight vulnerabilities

CVE-2016-0189 is linked the most to Exploit Kits, especially to Sundown

CVE-2015-7645 was used by 7 Exploit Kits

TOP VULNERABILITIES

Page 11: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

11

EXPLOIT KITS MARKET

Page 12: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

12

60%14

12%

0%

14%

Exploit Kits Types

Angler

Nuclear

Magnitude

Sundown

Others

MARKET – 2015

Page 13: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

13

According to TrendMicro:

− Angler 60%

− Nuclear 14%

− Magnitude 12%

− Sundown 0.33%

− Others 13.67%

Angler has the biggest share

Magnitude has some share of the market

Sundown still has less than 1%

MARKET – 2015

Page 14: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

14

MARKET – 2015

Source: http://chartsbin.com/view/33051

Page 15: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

15

J A PA N 2 0 1 5 S O U T H K O R E A 2 0 1 5

BROWSER MARKET SHARE 2015

Source: http://gs.statcounter.com/browser-market-share/

Page 16: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

16

47%

12.6

8%

33%

Countries Most Affected

Japan

US

Taiwan

Others

MARKET – 2016

Source: https://www.cloudsec.com/news/tracking-decline-top-exploit-kits/

Page 17: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

17

Countries most affected:

− Japan 47%

− US 12.7%

− Taiwan 8%

− Others 33%

Japan with almost 50% of the market share

Taiwan is also with a relatively high share

US is going strong as well

MARKET – 2016

Page 18: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

18

J A PA N 2 0 1 6 S O U T H K O R E A 2 0 1 6

BROWSER MARKET SHARE 2016

Source: http://gs.statcounter.com/browser-market-share/

Page 19: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

19

According to ThreatPost:

− RIG who was big in 2016, almost disappeared

• Still delivering ransomware in Southeast Asia

• The most common

− Sundown is still here

• Changing variants

• Adapting to changes

− Magnitude

• Low volumes

• Affects Southeast Asia

MARKET – EARLY - MID 2017

Page 20: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

20

MAGNITUDE EXPLOIT KIT

Page 21: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

21

Started to headline in 2013

Malware As a Service

31% of the market in 2014

Functional admin panel

Targeted victims

MAGNITUDE EXPLOIT KIT

Page 22: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

22

Page 23: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

23

LIVE DEMO

Page 24: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

24

SUNDOWN EXPLOIT KIT

Page 25: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

25

Still active

Adjustable to changes

Copy-paste code

SUNDOWN EXPLOIT KIT

Page 26: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

26

Page 27: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

27

LIVE DEMO

Page 28: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

28

CONCLUSIONS

Page 29: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

29

The EK market is slowly dying

Easy to overcome by keeping software up to date

Difficult to get exploits to work on victim’s machine

Less usage of IE

Less usage of Flash

CONCLUSIONS

Page 30: Dissecting exploit kits - ROOTCON 11/Talks/Dissecting... · 2017-09-25 · 10 In 2016, Adobe Flash provided 6 out of top 10 vulnerabilities used by Exploit Kits Rest of the top 10

30

QUESTIONS?

THANK YOU!