40
The Medico Governmental Case

The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

  • Upload
    others

  • View
    14

  • Download
    0

Embed Size (px)

Citation preview

Page 1: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

The Medico

Governmental

Case

Page 2: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

DFIR Team

Mustafa Hazem

2

Mahmoud Raouf Mohamed Abdelghany

Page 3: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

ContentAbout Medico

Medico case

Incident Response

Data Acquisition

Initial Access

Discovery

Persistence

Memory Analysis

Attack Vector

Lesson Learned

Page 4: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

About Medico

4

Page 5: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Facts

Medico funding.

How it raise money.

Great scattering.

Affect the economic conditions of the country.

The pharmaceutical industry

Evolve to cope with environmental changing.

Cheaper and more accessible.

5

Page 6: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Medico Case

6

Page 7: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Suddenly

Production line stopped.

Machines within same subnet came to a complete stop.

Case was reported.

The IT manager announced EMERGENCY.

7

Page 8: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Figuring out the problem

After little investigation

Files and folders are Encrypted.

Connections eliminated with some of the servers.

Money is required in bitcoin to regain the access to the system.

8

Page 9: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Informing the rescue team

Due to lake of expertise at Medico, the EG-CERT was informed.

Requirements

Investigation with Team members related to the encrypted servers.

Full diagram for the existing system.

9

Page 10: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Incident Response

10

Page 11: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Incident Response Process

Preparation

Understanding and preparing.

Containment

How intruders hacked thenetwork and moved from onesystem to another

Recovery

Restoring affected systemsback into business

Identification

Identify compromised systems.

Eradication

Actions required to mitigate thecurrent incident

Follow up and lesson learned

Page 12: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Involved Parties

12

Developing

Team

Network

Administrator

System

Administrator

IT

Manager

Page 13: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Topology

Page 14: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Data Acquisition

14

Page 15: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Data Acquisition

Physical Logical Custom-Content

Image

15

Page 16: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Data Acquisition (Cont’d)

Custom Content Image in addition to Memory

Page 17: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Triage

Prioritize Immediately

Save Crucial Time

Avoid Evidence Pile Up

17

Page 18: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Data Acquisition (Cont’d)

File Knowledge / Deleted File

Thumbs.db

Recycle Bin

OpenSaveMRU NTUSER.dat

Program Execution

Recent Apps

LastVisitedMRU NTUSER.dat

UserAssist

18

Page 19: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Data Acquisition (Cont’d)

File/ Folder Opening

Shellbags UsrClass.dat, NTUSER.dat

*.lnk

Prefetch

Account Usage

RDP Usage Security.evtx

Page 20: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Data Acquisition (Cont’d)

External Device/ USB Usage

USB drive letter SYSTEM

Volume serial no. SOFTWARE

Browser Usage

History, cache, cookie User/AppData

Page 21: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Initial Access

21

Page 22: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Ransomware via RDP

Ransomware ID: Striker

Poorly configured RDP

10.10.73.11

10.10.73.80

Internal Attack: 10.10.73.65

Page 23: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response
Page 24: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Attacker Info

Public vs Private

10.10.73.65

11.22.11.22

External Attacker

Page 25: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response
Page 26: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Discovery

26

Page 27: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Discovery

Event Viewer

EternalBlue

VirusTotal Check

Page 28: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Persistence

28

Page 29: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Persistance

OS Installation Date

Timestamp Converter

File Properties

Page 30: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Archive Server

MD5 Verification

Page 31: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Memory Analysis

31

Page 32: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Why Memory Analysis?

Identify Rogue Processes

Analyze Process DLLs and Handles

Review Network Artifacts

Look for Evidence of Code Injection

Check for Signs of a Rootkit

Extract Processes, Drivers, and Objects

Page 33: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Topology

Page 34: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Domain Controller

spoolsv.exe

Page 35: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Attack Vector

35

Page 36: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Attack VectorAttack Vector Info

Initial access and Execution

Privilege Escalation

Credential Access

Discovery

Lateral movement

Persistence

Impact

The initial access was done using weakly configured RDP

Logged on the server using Admin Account

Used SMB vulnerability which has system level user

Dumping Domain Accounts

Scan for all active IPs on the network

Gathering Domain Admin Credentials

Replacing ISO in Archive Server

Production Stopped, Data Leakage

Page 37: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Lesson Learned

37

Page 38: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Lesson Learned

Complex Password

Service account privileges

EDR (Endpoint Detection and Response)

SIEM

Regular Security Audit to Infrastructure

Consider RDP in restricted Admin Mode

Page 39: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Lesson Learned (cont’d)

Enable command line and PowerShell auditing and

logging

Security Awareness

Incident Response Readiness Plan

Forensic Readiness Plan

Page 40: The Medico Governmental Case - Eg-CERT Medico... · Governmental Case. DFIR Team Mustafa Hazem 2 Mahmoud Raouf Mohamed Abdelghany. Content About Medico Medico case Incident Response

Thank You

40