<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a Windigo signature? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-windigo-signature/m-p/31088#M22734</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I also checked out the Threat Vault. I've now done a more thorough look and I don't see indications that most of the network based signatures are present.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A link of the article I give has some Snort signatures:&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/eset/malware-ioc/tree/master/windigo" title="https://github.com/eset/malware-ioc/tree/master/windigo"&gt;malware-ioc/windigo at master · eset/malware-ioc · GitHub&lt;/A&gt; lists:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Linux/Ebury&lt;/LI&gt;&lt;LI&gt;Linux/Cdorked&lt;/LI&gt;&lt;LI&gt;Linux/Onimiki&lt;/LI&gt;&lt;LI&gt;Perl/Calfbot&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I don't see any of these listed either. At the end of that link it also mentions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Win32/Glupteba.M&lt;/LI&gt;&lt;LI&gt;Win32/Boaxxe.G&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Though Boaxxe is listed in the viruses section. Boaxxe.G isn't listed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The white paper is at:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.welivesecurity.com/wp-content/uploads/2014/03/operation_windigo.pdf"&gt;http://www.welivesecurity.com/wp-content/uploads/2014/03/operation_windigo.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Drew Daniels&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 25 Mar 2014 19:15:37 GMT</pubDate>
    <dc:creator>ddaniels</dc:creator>
    <dc:date>2014-03-25T19:15:37Z</dc:date>
    <item>
      <title>Is there a Windigo signature?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-windigo-signature/m-p/31086#M22732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a Windigo signature under another name, or some other way to detect a Windigo infection or infection attempt using the Threat detection feature or something else?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From what I've read only a host based intrusion detection system could actually see an infection, though the scanning and some of the vectors of attack like web may be detectable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://lwn.net/Articles/590934/" title="http://lwn.net/Articles/590934/"&gt;10,000 Linux servers hit by malware (ars technica) [LWN.net]&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Drew Daniels&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Mar 2014 14:56:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-windigo-signature/m-p/31086#M22732</guid>
      <dc:creator>ddaniels</dc:creator>
      <dc:date>2014-03-20T14:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a Windigo signature?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-windigo-signature/m-p/31087#M22733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just checked our Threat Vault:&lt;/P&gt;&lt;P&gt;&lt;A href="https://threatvault.paloaltonetworks.com/" title="https://threatvault.paloaltonetworks.com/"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And we do not have an entry for this.&lt;/P&gt;&lt;P&gt;I think that there were not just 1 or even a handful of vulnerabilities used in all of this.. but combinations of guessing passwords and using known vulnerabilities. &lt;/P&gt;&lt;P&gt;We cannot help against the password guessing, but we can continue to help guard against known threats and vulnerabilities.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if this answers your question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Mar 2014 15:21:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-windigo-signature/m-p/31087#M22733</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2014-03-21T15:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a Windigo signature?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-windigo-signature/m-p/31088#M22734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I also checked out the Threat Vault. I've now done a more thorough look and I don't see indications that most of the network based signatures are present.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A link of the article I give has some Snort signatures:&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/eset/malware-ioc/tree/master/windigo" title="https://github.com/eset/malware-ioc/tree/master/windigo"&gt;malware-ioc/windigo at master · eset/malware-ioc · GitHub&lt;/A&gt; lists:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Linux/Ebury&lt;/LI&gt;&lt;LI&gt;Linux/Cdorked&lt;/LI&gt;&lt;LI&gt;Linux/Onimiki&lt;/LI&gt;&lt;LI&gt;Perl/Calfbot&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I don't see any of these listed either. At the end of that link it also mentions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Win32/Glupteba.M&lt;/LI&gt;&lt;LI&gt;Win32/Boaxxe.G&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Though Boaxxe is listed in the viruses section. Boaxxe.G isn't listed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The white paper is at:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.welivesecurity.com/wp-content/uploads/2014/03/operation_windigo.pdf"&gt;http://www.welivesecurity.com/wp-content/uploads/2014/03/operation_windigo.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Drew Daniels&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Mar 2014 19:15:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-windigo-signature/m-p/31088#M22734</guid>
      <dc:creator>ddaniels</dc:creator>
      <dc:date>2014-03-25T19:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a Windigo signature?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-windigo-signature/m-p/31089#M22735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I also ran across this:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.symantec.com/connect/blogs/25000-linux-and-unix-servers-compromised-operation-windigo" title="http://www.symantec.com/connect/blogs/25000-linux-and-unix-servers-compromised-operation-windigo"&gt;http://www.symantec.com/connect/blogs/25000-linux-and-unix-servers-compromised-operation-windigo&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The paper lists three main malicious components (ESET detection names):&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Linux/Ebury – an OpenSSH backdoor used to control servers and steal credentials&lt;/LI&gt;&lt;LI&gt;Linux/Cdorked – an HTTP backdoor used to redirect Web traffic&lt;/LI&gt;&lt;LI&gt;Perl/Calfbot – a Perl script used to send spam&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;[...]&lt;/P&gt;&lt;P&gt;Symantec customers are protected against malware used in Operation Windigo with the following signatures:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;AV&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="http://www.symantec.com/security_response/writeup.jsp?docid=2001-062614-1754-99"&gt;Backdoor.Trojan&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://www.symantec.com/security_response/writeup.jsp?docid=2013-050214-5501-99"&gt;Linux.Cdorked&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://www.symantec.com/security_response/writeup.jsp?docid=2013-022222-0208-99"&gt;Linux.SSHKit&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://www.symantec.com/security_response/writeup.jsp?docid=2014-022816-2347-99"&gt;Linux.SSHKit!gen1&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-082718-3007-99"&gt;Trojan.Dropper&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://www.symantec.com/security_response/writeup.jsp?docid=2013-091911-2440-99"&gt;Trojan.Tracur!gen5&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://www.symantec.com/security_response/writeup.jsp?docid=2014-031813-1030-99"&gt;Trojan.Tracur!gen8&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt; &lt;STRONG&gt;IPS&lt;/STRONG&gt; &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="http://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=25732"&gt;System Infected: Festi Rootkit Activity&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On &lt;A href="https://threatvault.paloaltonetworks.com/" title="https://threatvault.paloaltonetworks.com/"&gt;https://threatvault.paloaltonetworks.com/&lt;/A&gt; I don't see anything related to ssh in Linux for Virus or Spyware. There's not much for SSH vulnerabilities that would hit except maybe brute force, and authentication informational. I see some "Tracur" signatures, but nothing that has "gen" in the name. dropper has too many hits to be able to figure out if it's the same one. I don't see any of the other parts of the signature sub-names (e.g. I searched for cdorked, Ebury, calfbot...) from this article.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Drew Daniels&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Mar 2014 18:15:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-a-windigo-signature/m-p/31089#M22735</guid>
      <dc:creator>ddaniels</dc:creator>
      <dc:date>2014-03-26T18:15:01Z</dc:date>
    </item>
  </channel>
</rss>

