Showing posts with label Yara Rules. Show all posts
Showing posts with label Yara Rules. Show all posts

Monday, February 1, 2016

ICS-CERT Updates Black Energy Alert Again

For the second time in a month the DHS ICS-CERT updated their alert for the Black Energy campaign. Last month the advisory was updated to reflect new information from the Ukraine power outage incident. Today’supdate provides revisions of the Yara rules for detecting Black Energy 2 and Black Energy 3 that also detect newer versions of the malware.

ICS-CERT continues to report that they have a more detailed version of this report available for limited distribution. The note that: “Asset owners and operators can request access to this information by emailing ics-cert@dhs.gov.”

Today’s update was listed on the ICS-CERT landing page, but you have to have been really alert to have noticed the change in the listing under the “Most Downloaded” section of the page. As I have noted frequently of late, it was also announced on TWITTER®.


BTW: Neither today’s Siemens’ update or last Friday’s update were mentioned on the ICS-CERT web site today.

Wednesday, December 10, 2014

ICS-CERT Updates Their Alert on Ongoing Malware Campaign

Today the DHS ICS-CERT published the second update of their alert concerning the BlackEnergy malware campaign. The first update was published on October 29th and the original alert was published the day before.

This update provides a little more information on the probable existence of a Siemens WinCC attack vector involved in the campaign. The original alert only provided the vaguest hint about the use of WinCC which ICS-CERT plainly said they could not confirm. They now say:

“While ICS-CERT lacks definitive information on how WinCC systems are being compromised by BlackEnergy, there are indications that one of the vulnerabilities fixed with the latest update for SIMATIC WinCC [link added] may have been exploited by the BlackEnergy malware. ICS-CERT strongly encourages users of WinCC, TIA Portal, and PCS7 to update their software to the most recent version as soon as possible.”

This version of the alert also updates the Yara Rules that allow organizations to interpret the results of scan conducted with the Yara pattern matching tool. ICS-CERT recommends that organizations running the updated scan and the application of the updated Yara Rules send copies of the results to ICS-CERT for more detailed interpretation of the data if there are any indications of potential compromise in the results.


ICS-CERT does not specifically state in this update that even those organizations that have already run the earlier version should run the updated scan. Since this apparently checks for later versions (or at least different versions) of the malware associated with BlackEnergy, it would seem to me that it would only be prudent to run this latest version and any new versions that ICS-CERT might publish in the future.
 
/* Use this with templates/template-twocol.html */