Is Zeus the Lord of your Network?

I have always taken a fairly relaxed view about internet access, and we use a lot of services via the “web”, on-line banking, managing credit cards, buying from commercial suppliers, webmail, management of websites and customers etc etc.

We do of course have a good level of security, all the obvious things, complex passwords, locked down user accounts, ant-virus and security software, and above all I like to think a bit of common sense and savvy about “things not to do”

On Monday late afternoon we got a phone call from one of our customers, to say that their Bank had told them their computers had ZeuS Malware and that they (the bank) had “locked them out”!!

Our initial reaction was to charge over to sort out the customers PC’s, however we would have been arriving after 6pm and quickly realised a little bit of research and preparation might make our task simpler.

Despite an initial doubt that the bank would be techie enough to pin down the particular malware involved we looked up the ZeuS malware and found a good article about it’s effects

http://www.informationweek.co.uk/smb/security/zeus-malware-returns-targets-smbs/240156113

We also studied the Microsoft virus database which is very clear  about the malware “PWS:Win32/Zbot.gen!AL” and describes it and its abilities clearly without to much “tech talk”http://www.microsoft.com/security/portal/threat/encyclopedia/Entry.aspx?Name=PWS%3AWin32%2FZbot.gen!AL

We phoned the client back and said that they should disconnect their router from the internet to prevent any malicious communication in or out from any compromised PC’s

Tuesday morning I arrived at the clients premises first thing having overnight downloaded some Microsoft software to deal with Zeus onto a couple of Pensticks and run it on my laptop which took 4 hours+ to scan! (I’m to embarrassed to say how many malicious items it found though luckily nothing too nasty). In view of this and as the client only has four or five PCs I felt it  was silly to go “mob-handed” when it was perhaps a case of starting the scans and waiting around for 4 hours to get results.

Luckily most of the PC’s scanned far more quickly than mine and two came up with only minor problems (cookies, adware and the like), however the bosses own PC and the main office PC both reported the “Zeusbot” file and couple of other bugs, however the Microsoft scanner reported that it had detected “but not deleted” the Zeusbot file!  This was worrying as we had picked this scan utility specifically because it could deal with Zeus!

I tried scanning both PCs again having re-booted into safe mode, this time the scanner did not find the Zeus, so I was left with restarting and scanning again in normal mode, then using several other scanning tools to confirm these machines were indeed clear.

By this time a colleague had arrived and we both spent the rest of the day cleaning up lots of minor problems such as:

  • numerous browser tool-bars on PCs, Ask, Google, “Web Wise”, FAV etc
  • MediaGet software (a torrent these are major problems in our book!)
  • iLivid – a browser “enhancer” – geared for facebook?

We also caught another Zbot type virus hiding in on the bosses PC and trying to link “Back to base” which we removed from the registry and manually deleted.

We then installed bank security software “Rapport” on the bosses PC and left it running yet another scan overnight.

Wednesday is going to be occupied by this customer in persuading their bank to re-open a new on-line account, transferring all their info into it and re-setting their connection and checking it is working, changing all their PC user logins, email passwords, Facebook and Google+ passwords, Dropbox account details, etc etc.

According to Kaspersky – Here is the top list of business sites that the ZeuS malware monitors:
According to Kaspersky – Here is the top list of business sites that the ZeuS malware monitors:

 

By Thursday they will be able to start counting the costs, in this case not too great, a modest bill for our time, and quite a few man-hours of theirs, but so far as we know at this point no direct financial loss.

The possible costs of this to them do not bear thinking about, but perhaps we must…  See the Information Week article above and the case of Patco who found themselves half a million dollars short, even after the bank recovering some of it they are down $350k, and facing court actions to try and get their Bank to accept some responsibility.

 

Now our customer here was not negligent, they have up-to-date security software (how many of us do not??), their network to has security systems as far as practicable, (they do offer wireless connections to customers and visitors, always a potential problem) Their staff do use the business PCs for some private connections (bank logins, email, Facebook etc, (bear in mind this puts the employees / vistors accounts at risk, are they going to come back to you with claims that “your systems” have caused them problems?)

 

WebI am sure  we would all benefit from thinking about and indeed applying extra security both on personal networks and particularly business ones, do we need to offer wireless access, particularly to peoples personal equipment, Laptops, Tablets, Phones (there are Android and Blackberry versions of Zeus!), this is putting additional tunnels through your network to equipment that you have little control over, (do they have security software on these?)

In the instance here someone had clearly been downloading using torrent software, (Possibly not their staff, but using their PC) nearly all downloads here are suspect, even record companies have planted malware and trackers within torrents, let alone the “bad guys”!

Facebook is apparently one of the more recent sources of the Zeus bot, what security concerns do you have about staff use of Facebook, or do you have a company Facebook / Twitter /Google+ account  ?

A major issue in this must be staff management and training, there is a likelihood that this particular incident came from  a click on an attachment to a “Bank Warning Email”, now of course we all know how to verify what a link is really to and what is not an appropriate attachment type don’t we? Well I’ll bet not, even if you are aware, not everyone who uses PCs on your network will be.

And of course your staff don’t download “free” Music, or Movie files using your systems do they? (I’m betting they do – even if you yourself don’t, we have the proof and the witness statements!! – not of course all of them, perhaps not many, but the statistics prove my case!)

Now I’m not “having a go” – certainly not at our own customers – after all, if they get malware problems it likely means work for us and if they have no problems, we go hungry!

hacking-312x400

 

Please do what I am doing right now and ask the questions, do I need this to happen on my network, is it a necessary and valid part of our business,  if staff want to connect to their bank or iTunes should we tell them to get a connected tablet or smartphone and use their own connection!, if visitors connect to my business network perhaps they should specify what they are connecting and that it has security.

Do you know what software is installed on your equipment and do you staff know that they cannot install ANYTHING without official sanction?

In the opposite vein do you ensure that users know to do appropriate updates, that these are usually security issues fixing recently discovered problems or updating virus definitions, but even here they must be trained to be vigilant, Adobe and Oracle are notorious for including “tickboxes” pre-selected to install Junkware, (Ask toolbar and worse!) as part of the update process
I could go on forever in this vein, but you probably won’t read this far anyway, if you have, please leave a comment with your thoughts, and let me know if we can help you in any way with security issues.

Theme: Overlay by Kaira Powered by cbits.net
The Chambers, Market Place, Chapel-en-le-Frith, High Peak, SK23 0EN