|
S E N S I T I V E SECTION 01 OF 02 ITSREP 00001
DEPT. ITS TAGS: DIT, SEC, NAT SUBJ: ONGOING INCIDENT UPDATE - 08/07/2019 REF: IDE 20 ---------- Summary ---------- {% if prev_decision == 2 or prev_decision == 3 %} 1. Malicious traffic routed through infected Vadarean hosts affecting local media organizations appears to have subsided, effectively returning the situation back to normal. {% else %}1. Malicious traffic routed through infected Vadarean hosts shows no sign of abating. Affected organizations are struggling to maintain their online services under this digital onslaught. {% endif %} {% if rapid %}2. The database of the National Health Service is currently inaccessible due to the presence of ransomware that has encrypted the files. {% else %}2. The database of the National Tax Service is currently inaccessible due to the presence of ransomware that has encrypted the files. {% endif %}2.1. The attackers demand 5,000 bitcoins, equivalent to approximately 20 million USD, within 48 hours in exchange for the key to unlock the encrypted database. |
|
S E N S I T I V E SECTION 01 OF 02 ITSREP 00001
DEPT. ITS TAGS: DIT, SEC, NAT SUBJ: RANSOMWARE ANALYSIS - 08/07/2019 REF: IDE 21 ---------- Summary ---------- {% if rapid %} 1. The ransomware appears to have exploited a vulnerability in the Web Service feature of the database that allows hospitals to exchange patient information. {% else %}1. The ransomware appears to have exploited a vulnerability in the Web Service feature of the database that allows third-party tax software to upload tax return information. {% endif %}2. The exploit used by the ransomware resembles one that first appeared in a collection of publicly leaked source codes thought to have been part of a government's offensive cybersecurity programme. 3. Stolen private keys and digital SSL certificates were used to bypass the mutual authentication measures in place that only allow authorized clients to access these services. 4. Network analysis traces the malicious traffic back to bots associated with the Cohnal botnet. Although 80% of the bots in the DDoS attacks were hosts in Vadare, none of these infected hosts appear to be Vadarean. 5. Initial analysis reveals a number of keywords that correspond with one of the official languages in Vadare. 6. Backups for the system exist, however, they have not been kept properly up to date; there would be over nine months of data lost if the database was restored from the backup. While better than nothing, it is nowhere near ideal for returning to business as usual. |