{"id":1322,"date":"2019-07-24T13:03:33","date_gmt":"2019-07-24T05:03:33","guid":{"rendered":"https:\/\/greycortex.hk\/?page_id=1322"},"modified":"2019-08-22T15:45:02","modified_gmt":"2019-08-22T07:45:02","slug":"use-case-ransomware-attack","status":"publish","type":"page","link":"https:\/\/greycortex.hk\/zh\/use-case-ransomware-attack\/","title":{"rendered":"Use Case &#8211; Ransomware Attack Against Government"},"content":{"rendered":"<div data-elementor-type=\"wp-post\" data-elementor-id=\"1322\" class=\"elementor elementor-1322\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-a03290a elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"a03290a\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-34ec3c3\" data-id=\"34ec3c3\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3f58e55 elementor-widget elementor-widget-heading\" data-id=\"3f58e55\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Ransomware Attack\nAgainst Government<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-88bd665 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"88bd665\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-9573890\" data-id=\"9573890\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-5c24028 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"5c24028\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-60e7a15\" data-id=\"60e7a15\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-6e230ea elementor-widget elementor-widget-text-editor\" data-id=\"6e230ea\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Industry:<\/strong><\/p><p>Government Ministry<\/p><p><strong>Entry Point:<\/strong><\/p><p>Infected Email<\/p><p><strong>Objective:<\/strong><\/p><p>Attack against full network using Eternal Blue selfpropagating exploit<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-f924d7e\" data-id=\"f924d7e\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5416f98 elementor-widget elementor-widget-text-editor\" data-id=\"5416f98\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Detection Method:<\/strong><\/p><p>Advanced Network Traffic Analysis with event correlation<\/p><p><strong>Secondary Detection:<\/strong><\/p><p>Known signature of Eternal Blue exploit<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<div class=\"elementor-element elementor-element-205d440 elementor-widget elementor-widget-text-editor\" data-id=\"205d440\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h5>At a government ministry, an employee received an email which contained an attachment marked as \u201cinvoice.\u201d Presuming it to be legitimate, he opened the attachment, unknowingly releasing a ransomware payload. This ransomware did not take immediate action to ransom the recipient\u2019s laptop, but started preparing for a larger attack against the full network.<\/h5><h5>As part of this preparation, the ransomware downloaded TOR and began to communicate with an outside IP address. Both of these anomalous actions were identified by MENDEL as they happened. MENDEL automatically alerted the ministry\u2019s security team, who used MENDEL to identify the device, and MENDEL\u2019s integration with Active Directory to identify the employee in question. The machine was sanitized and returned to service before it could cause damage.<\/h5><h5>The ransomware in question used the Eternal Blue exploit, which infects other devices across the network without having to be spread by careless users. Eternal Blue was a key component of the WannaCry ransomware which effected networks worldwide in 2017. MENDEL detects this exploit by name, and it identifies ransomware using similar, unknown exploits by their actions, escalating their seriousness based on these actions if necessary, through event correlation.<\/h5><h5>Attacks of this nature; using advanced malware against governments, critical corporate assets, and infrastructure, are becoming more common. They are nearly impossible to detect by commonly used security tools. MENDEL helps defend the network against them.<\/h5>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c279030 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c279030\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-fcee4c0\" data-id=\"fcee4c0\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-aaa6452 elementor-widget elementor-widget-image\" data-id=\"aaa6452\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"254\" height=\"300\" src=\"https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?fit=254%2C300&amp;ssl=1\" class=\"attachment-medium size-medium wp-image-948\" alt=\"\" srcset=\"https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?w=1594&amp;ssl=1 1594w, https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?resize=254%2C300&amp;ssl=1 254w, https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?resize=768%2C906&amp;ssl=1 768w, https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?resize=868%2C1024&amp;ssl=1 868w, https:\/\/i0.wp.com\/greycortex.hk\/wp-content\/uploads\/2019\/05\/question2.png?resize=600%2C708&amp;ssl=1 600w\" sizes=\"(max-width: 254px) 100vw, 254px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-top-column elementor-element elementor-element-24f7d4e\" data-id=\"24f7d4e\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-e0bef4d elementor-hidden-desktop elementor-hidden-tablet elementor-widget elementor-widget-spacer\" data-id=\"e0bef4d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6070c14 elementor-widget elementor-widget-heading\" data-id=\"6070c14\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;}\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">\u4f60\u6709\u4ec0\u9ebc\u554f\u984c\u55ce\uff1f<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9ed8f63 elementor-widget elementor-widget-text-editor\" data-id=\"9ed8f63\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;none&quot;,&quot;_animation_delay&quot;:200}\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>\u8acb\u7559\u4e0b\u60a8\u7684\u806f\u7d61\u65b9\u5f0f\uff0c\u4ee5\u4fbf\u6211\u5011\u6839\u64da\u60a8\u516c\u53f8\u7684\u9700\u6c42\u63d0\u4f9b\u500b\u6027\u5316\u7684\u670d\u52d9\u3002<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-3a76178 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"3a76178\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-8ccdd65\" data-id=\"8ccdd65\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-822c40c\" data-id=\"822c40c\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>","protected":false},"excerpt":{"rendered":"<p>Ransomware Attack Against Government Industry: Government Ministry Entry Point: Infected Email Objective: Attack against full network using Eternal Blue selfpropagating exploit Detection Method: Advanced Network Traffic Analysis with event correlation Secondary Detection: Known signature of Eternal Blue exploit At a government ministry, an employee received an email which contained an attachment marked as \u201cinvoice.\u201d Presuming [&hellip;]<\/p>","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"page-templates\/fullwidth-content.php","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"footnotes":""},"class_list":["post-1322","page","type-page","status-publish","hentry"],"jetpack_shortlink":"https:\/\/wp.me\/PaZ0Rf-lk","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/pages\/1322","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/comments?post=1322"}],"version-history":[{"count":25,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/pages\/1322\/revisions"}],"predecessor-version":[{"id":2037,"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/pages\/1322\/revisions\/2037"}],"wp:attachment":[{"href":"https:\/\/greycortex.hk\/zh\/wp-json\/wp\/v2\/media?parent=1322"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}