“We can evade reality but we cannot evade the consequences of evading reality.”

–Ayn Rand


RIG Exploit Kit Used to Deliver “Cryptowall” Ransomware http://www.securityweek.com/rig-exploit-kit-used-deliver-cryptowall-ransomware

http://www.infosecurity-magazine.com/view/38751/malvertising-and-cryptowall-mark-the-appearance-of-the-rig-exploit-kit-/

C-IT Recommendation

  1. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  2. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates. Consider visiting the Cisco systems site to add the identified sites to your web content filters blacklist, which will block the malicious sites.
  3. Thoroughly educate your end users on safe website browsing. Communicate to them that they should only be utilizing the internet to access legitimate sites which support the accomplishing of their job responsibilities.
  4. Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes.
  5. Ensure your organization has Firewalls/Intrusion Prevention Solutions in place that will block incoming attempts to infect PCs with a crimeware kit.
  6. Ensure your organization has a solid anti-malware solution at the end point and that all endpoints are covered.
  7. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  8. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  9. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  10. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.
  11. Implement an advanced malware solution such as Invincea Freespace, FireEye Web Security (NX Series), Source Fire FireAmp to keep remote connections from initiating from your internal network.
  12. If you are using WordPress, enforce strong password policy requiring login to be complex with at least eight characters, lower case, uppercase and symbols.

Article Resources

Cisco Systems RIG Exploit Kit Strikes Oil Blog

https://blogs.cisco.com/security/rig-exploit-kit-strikes-oil

US-CERT Alert (TA13-309A): CryptoLocker Ransomware Infections

http://www.us-cert.gov/ncas/alerts/TA13-309A

McAfee Blog: What is a “Drive-By” Download?

https://blogs.mcafee.com/consumer/drive-by-download

US-CERT Alert (TA14-150A): GameOver Zeus P2P Malware (Tools for Removal)

https://www.us-cert.gov/ncas/alerts/TA14-150A


What to avoid in Dropbox-related phishing attack http://www.csoonline.com/article/2360670/malware-cybercrime/what-to-avoid-in-dropbox-related-phishing-attack.html

C-IT Recommendation

  1. Ensure your company has an effective spam gateway or email content filter solution that quarantines junk mail, detects viruses.
  2. Consult with your email security team to validate the email security solution is running on the latest stable version with the latest signature updates.
  3. Ensure your company is using a web content filtering solution to prevent user from accessing malicious websites.
  4. Validate the web content filtering solution is up to date with the latest stable version with the latest site signature updates
  5. Thoroughly educate your end users on phishing attacks and how to avoid them.
  6. Encourage your end users through your information security policy not to give their company email out for non-business related purposes
  7. Restrict administrative access on local machines and browsers to only users which absolutely need access to install programs for business purposes
  8. Evaluate the organizational risks for allowing users in your organization to use online document sharing sites such as dropbox, google drive, Microsoft One Drive. Understand once the information leaves your organization you no longer have controls. This evaluation should include input from your core business leaders, the legal department and the information technology and security leadership.
  9. Make an organizational decision to whether or not you will allow users to store files on online document sharing sites.
  10. Ratify a data storage policy that explicitly addresses your directives for storing files on online document sharing sites.
  11. If you decide to disallow users to use online document sharing sites, you may want to consider blocking those sites on your web content filter appliance.

Article Resources

Phishme Blog “An inside look at Dropbox phishing: Cryptowall, Bitcoins, and You”

http://phishme.com/inside-look-dropbox-phishing-cryptowall-bitcoins/

US- CERT Security Tip (ST04-014): Avoiding Social Engineering and Phishing Attacks

http://www.us-cert.gov/ncas/tips/ST04-014


Microsoft preps seven fixes, two critical, for Patch Tuesday release http://www.scmagazine.com/microsoft-preps-seven-fixes-two-critical-for-patch-tuesday-release/article/351559/

C-IT Recommendation

  1. Enforce a patch management standard in your organization which requires security patches to be deployed in the production environment within a reasonable time after they are tested within your test environment.
  2. Test business functionality of each type of device and record any issues impacting any business functions on the devices.
  3. If no issues result in the testing, deploy the security updates to the production systems. If functionality impacting issues occur on the test devices, engage Adobe support and/or vendor support if specific applications are negatively impacted.
  4. Consult with your Vulnerability and Threat Management Team (VTM) to verify all production systems are patched with the latest updates.