<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>Cyber Kill Chain by al chua</title>
      <link>https://padlet.com/cdocsafcds/cyber1212</link>
      <description>Find a case study and apply the cyber kill chain by explaining the steps taken.</description>
      <language>en-us</language>
      <pubDate>2022-05-11 01:41:28 UTC</pubDate>
      <lastBuildDate>2022-08-22 03:04:39 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url></url>
      </image>
      <item>
         <title>Group 1</title>
         <author>cdocsafcds</author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2178573069</link>
         <description><![CDATA[]]></description>
         <enclosure url="" />
         <pubDate>2022-05-11 01:43:02 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2178573069</guid>
      </item>
      <item>
         <title>Group 2</title>
         <author>cdocsafcds</author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2178573169</link>
         <description><![CDATA[]]></description>
         <enclosure url="" />
         <pubDate>2022-05-11 01:43:07 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2178573169</guid>
      </item>
      <item>
         <title>Group 3</title>
         <author>cdocsafcds</author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2178573297</link>
         <description><![CDATA[]]></description>
         <enclosure url="" />
         <pubDate>2022-05-11 01:43:13 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2178573297</guid>
      </item>
      <item>
         <title>Group 4</title>
         <author>cdocsafcds</author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2178573395</link>
         <description><![CDATA[]]></description>
         <enclosure url="" />
         <pubDate>2022-05-11 01:43:18 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2178573395</guid>
      </item>
      <item>
         <title>Group 5</title>
         <author>cdocsafcds</author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2178573516</link>
         <description><![CDATA[]]></description>
         <enclosure url="" />
         <pubDate>2022-05-11 01:43:24 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2178573516</guid>
      </item>
      <item>
         <title>colonial pipeline ransomware attack</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2178592048</link>
         <description><![CDATA[<div>step 1: reconnaissance&nbsp;<br>Hackers went on the dark web to acquire passwords &nbsp;<br>step 2: weaponisation&nbsp;<br>hackers logged into the VPN account using acquired passwords<br>step 3 : delivery<br>hackers found where to login using their new found credentials<br><br>step 4 : exploitation<br>the website did not have 2FA and the employees did not disable the accounts properly&nbsp;<br>step 5 : installation <br>hackers installed ransomware&nbsp;<br>step 6 :command and control&nbsp;<br>hackers controlled the supply of oil, causing many drivers to be stranded and effectively resulting in the standstill of society.<br>step 7 actions and objectives<br>&nbsp;they received 4 million usd in ransom&nbsp;</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-11 01:58:54 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2178592048</guid>
      </item>
      <item>
         <title>Context: Singhealth data breach</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2178597608</link>
         <description><![CDATA[<div>Personal particulars of 1.5M singhealth patients, including PM Lee's, as well as 160k records of outpatient dispensed medicines were obtained by the perpetrators. Details included names, NRIC, addresses and other personal information. The data stolen spanned entries from 1 May 2015 to 4 July 2018. PM Lee's information was specifically targeted.&nbsp;<br><br>CYBER KILL CHAIN<br>Reconaissance: obtained login credentials<br>Weaponization: customized malware used<br>Delivery: through front end workstation<br>Exploitation: malware modified to target singhealth cybersecurity weaknesses<br>Installation: on front end workstation i guess, into IT network<br>Command and Control: database accessed<br>Actions on objectives: personal particulars obtained</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-11 02:03:34 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2178597608</guid>
      </item>
      <item>
         <title>Aftermath</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2178611951</link>
         <description><![CDATA[<div>Singhealth disconnected factor systems and others permenantly. It also made use of more secure information exchange gateways and hired independent operatives tk review the health records before submission.&nbsp;<br><br>The IHS has since strengthened public health systems against data breaches. All suspicious occurences are to be reported within 24 hours. Other measures include 2 factor authentication, proactive threat hunting and ensuring all machines have the most updated security updates.&nbsp;<br><br>Two employees were dismissed for negligence and misinterpretation of the threat respectively and financial penalties were imposed on the related supervisors and managers.&nbsp;<br><br>Cybersecurity company Symantec identified a state-sponsored group called Whitefly but its benefactor has yet to be found. </div>]]></description>
         <enclosure url="" />
         <pubDate>2022-05-11 02:14:34 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2178611951</guid>
      </item>
      <item>
         <title>wannacry ransomware attack</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2266882216</link>
         <description><![CDATA[]]></description>
         <enclosure url="" />
         <pubDate>2022-08-22 02:25:25 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2266882216</guid>
      </item>
      <item>
         <title>Cisco YanLuoWang attack</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2266885134</link>
         <description><![CDATA[]]></description>
         <enclosure url="" />
         <pubDate>2022-08-22 02:28:27 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2266885134</guid>
      </item>
      <item>
         <title>How it started</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2266885490</link>
         <description><![CDATA[<div>The attacker convinced the Cisco employee to accept multi-factor authentication (MFA) push notifications through MFA fatigue and a series of sophisticated voice phishing attacks initiated by the Yanluowang gang that impersonated trusted support organizations.<br><br>Under cyber kill chain, it can be classified as credential access</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-08-22 02:28:51 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2266885490</guid>
      </item>
      <item>
         <title></title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2266886042</link>
         <description><![CDATA[<div>Once they gained a foothold on the company's corporate network, Yanluowang operators spread laterally to Citrix servers and domain controllers.</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-08-22 02:29:28 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2266886042</guid>
      </item>
      <item>
         <title>Reconnaissance</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2266886833</link>
         <description><![CDATA[<div>Organizations with open port 445 endpoints were searched for, exploitable with EternalBlue.</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-08-22 02:30:19 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2266886833</guid>
      </item>
      <item>
         <title>Exploitation</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2266888934</link>
         <description><![CDATA[<div>Exploits the vulnerability with EternalBlue. It injects code into the SMB system process and becomes persistent by creating an entry in the windows registry.</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-08-22 02:32:24 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2266888934</guid>
      </item>
      <item>
         <title>Installation</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2266889393</link>
         <description><![CDATA[<div>It copies itself to those vulnerable endpoints by exploiting a variant of the DoublePulsar payload. The process starts again on every infected computer. The capacity of the propagation within the network is enormous.</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-08-22 02:32:56 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2266889393</guid>
      </item>
      <item>
         <title>Weaponization</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2266889480</link>
         <description><![CDATA[<div>Artifacts such as injection code for SMB process &amp; kill-switch mechanism were created</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-08-22 02:33:03 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2266889480</guid>
      </item>
      <item>
         <title>Weaponisation</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2266890311</link>
         <description><![CDATA[<div>After gaining domain admin, they used enumeration tools like ntdsutil, adfind, and secretsdump to collect more information and installed a series of payloads onto compromised systems, including a backdoor malware.&nbsp;<br><br>"After obtaining initial access, the threat actor conducted a variety of activities to maintain access, minimize forensic artifacts, and increase their level of access to systems within the environment," Cisco Talos added.<br><br></div><div><br><br></div><div><br><br>Weaponisation</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-08-22 02:33:44 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2266890311</guid>
      </item>
      <item>
         <title>command and control (C2) &amp; actions on objectives</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2266890383</link>
         <description><![CDATA[<div>-Got access to system files and deleted existing shadow copy folders to prevent the user from retrieving information.<br>-It do not allow booting in system recovery mode, and hides the recycle bin.<br>-It kills processes that have open databases to guarantee access to the encryption of such databases (mysql, sqlserver, and exchange)<br>-Proceeds to encrypt the files and directories of the system using an AES algorithm, which can only be decrypted if the private RSA key is available.<br>-when the file encryption finishes, it shows a dialog to the user requesting the ransom.</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-08-22 02:33:48 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2266890383</guid>
      </item>
      <item>
         <title>Ryuk ransomware</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2266891056</link>
         <description><![CDATA[]]></description>
         <enclosure url="" />
         <pubDate>2022-08-22 02:34:41 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2266891056</guid>
      </item>
      <item>
         <title>Delivery</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2266894484</link>
         <description><![CDATA[<div>Payload of malicious code is injected into vulnerable systems through port 445, using SMB file-sharing through EternalBlue</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-08-22 02:38:54 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2266894484</guid>
      </item>
      <item>
         <title>Outline</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2266896600</link>
         <description><![CDATA[<div>WannaCry - Self-spreading ransomware<br>Exploitation of one of Microsoft's protocols led to creation of EternalBlue, one of the tools used to gain access to remote computers.<br>DoublePulsar, a backdoor tool used for installation and execution of programs.<br>This exploit was patched within a month of discovery, but many users across the globe did not install the patch.<br>A combination of these tools allowed the creation of WannaCry, which spread across the world.<br>User's computers data was encrypted by WannaCry, spreading with the use of EternalBlue, and installation using DoublePulsar.<br><br>When WannaCry is executed, it checks for a fixed domain name, if this domain name is not found, it will encrypt the computer data.<br><br>A computer researcher reverse-engineered the malware code and found this vulnerability, and registered the domain name. This caused WannaCry to stop any further executions, effectively acting as a kill switch.<br><br>&nbsp;</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-08-22 02:41:19 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2266896600</guid>
      </item>
      <item>
         <title></title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2266900385</link>
         <description><![CDATA[<div>Step 1: Reconnaissance<br>Look for organizations with critical assets that are more likely to pay, a technique the security industry calls "big game hunting".<br><br>Step 2: Weaponisation<br>Ryuk uses Trickbot computer malware to install itself, once access is gained to a network's servers. It has the capability to defeat many anti-malware countermeasures that may be present and can completely disable a computer network. It can even seek out and disable backup files if kept on shared servers.<br><br>Step 3: Delivery<br>Created phishing campaigns that contain either links to malicious websites that host the malware or attachments with the malware.&nbsp;<br><br>Step 4: Exploitation<br>The phishing email would have contained Emotet, a piece of trojan. Emotet would have installed Trickbot, which then enabled the hacker group, WIZARD SPIDER, to manually install Ryuk through a reverse shell.<br><br>Step 5: Installation<br>Loaders start the infection chain by distributing the payload; they deploy and execute the backdoor from the command and control server and install it on the victim’s machine.<br><br>Step 6: C2<br>At that point, the encryption can occur. Ryuk encrypts files such as photos, videos, databases, and documents – all the data you care about – using AES-256 encryption. The symmetric encryption keys are then encrypted using asymmetric RSA-4096.<br><br>Step 7: Action on Objectives<br>The hackers leave ransom notes in the system as RyukReadMe.txt, demanding a ransom</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-08-22 02:45:38 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2266900385</guid>
      </item>
      <item>
         <title>Reconnaissance</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2266905292</link>
         <description><![CDATA[<div>Got&nbsp;hold of an employee's personal Google account that contained passwords synced from their web browser</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-08-22 02:50:49 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2266905292</guid>
      </item>
      <item>
         <title>Action on Objectives</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2266907137</link>
         <description><![CDATA[<div>After the attackers were booted off, the attackers tried to manipulate the company executives by trying to establish email communications at least three times to urge them to pay so that no one will know about the incident and information leakage. The email also included a screenshot of the directory listing of the exfiltrated Box folder</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-08-22 02:52:41 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2266907137</guid>
      </item>
      <item>
         <title>Exploitation</title>
         <author></author>
         <link>https://padlet.com/cdocsafcds/cyber1212/wish/2266909734</link>
         <description><![CDATA[<div>The attacker ultimately succeeded in achieving an MFA push acceptance, granting them access to VPN in the context of the targeted user.”<br><br></div><div>The report adds that once the attacker obtained initial access, they enrolled a series of new devices for MFA and authenticated successfully to the Cisco VPN.<br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2022-08-22 02:55:08 UTC</pubDate>
         <guid>https://padlet.com/cdocsafcds/cyber1212/wish/2266909734</guid>
      </item>
   </channel>
</rss>
