If it's available, why didn't the virus scanner catch it?
If it's available, why didn't the virus scanner catch it?
The reason that PI was not detected is because the attacker embedded a Flash object inside the Excel file. The Flash file was a 0day exploit that could download and execute a file, which in this case was the attacker's PI client.
From there, the game is up. Once inside the network, an attacker has a whole new set of doors to open. The simplest route, if the target is on an older operating system, is to dump the SAM file, which contains both local passwords as well as cached passwords. Cached passwords are nice because they are network logins, however 9 times out of 10 the local Administrator password is the same on all systems because system administrators frequently use the same local admin password when imaging lots of computers. Additionally, cached passwords are sometimes out of date due to password update policies. Local passwords are usually not subject to this, or if they are, it becomes irrelevant since a system administrator hasn't likely gone through and changed each local password.
Once you have a network password or local password, things get fun. There are 2 routes here. The attacker can go the frontend route, and attack the internal CRM that EMC has, or they can attack the development servers. Alternatively, they could just keep hacking each workstation, but that is unnecessary. Assuming we went the CRM route, we likely have or can easily obtain a valid login from our first target's computer. Once inside, unless there are solid permissions, we may have won. RSA likely had a record of each customer's purchase, which then had a record of each device and potentially some sort of key or code needed to predict the next token. I'll give RSA the benefit of being slightly smart, so those sort of keys probably won't be on the same CRM, or perhaps our login doesn't have access. Either way, we are in, and with some dissemination of materials available on other drives or within emails, the attacker could easily determine the location of the keys.
Once the attacker has whatever he needs, it's a quick trip to LinkedIn to find people that work at Lockheed Martin or whatever company you fancy. Then it's another spear phishing attack on that target to a page that looks like the target companies VPN. Grab the username, password, and PIN (also log the time) and you're good to go.
Now repeat the part where you enter the internal network and scour for information. Congratulations, you're now an Adaptive Persistent Threat. Pick your certificate up at the door.
"The reason that PI was not detected is because the attacker embedded a Flash object inside the Excel file. The Flash file was a 0day exploit that could download and execute a file, which in this case was the attacker's PI client."
The Poison Ivy client was downloaded to the target system. Why did the anti-malware software installed there not pick it up? (Attempting to hand-wave this away by talking about 0-day flash exploits really isn't answering the question.)
Looking at the poison ivy website they have a customer portal, so presumably this is how they did it.
There are also methods to pay without leaving a paper trail back to you (pre-paid cards I think).
Edit: It's also possible to modify detectable executables to make them undetectable if you don't want to pay. Virus scanners for the most part work by reading a few bytes from an executable at a particular point, hashing those bytes and if they match a known virus, report it as one. By finding those parts of the executable (there are often multiple signatures, and different vendors will have different signatures too) and modifying them slightly, the resultant hash will be different and the executable undetected.
Maybe somebody else can jump in here and offer better advice?
Unless you know exactly what it can do, you should probably run it on an old machine without [direct] internet access.
Cloudburst uses a vulnerability in the virtual-machine display functions of VMware Workstation that can be exploited by a specially crafted video file.
and...
However, the Cloudburst exploit currently has certain limitations: it will only succeed on Workstation 6.5.0 or 6.5.1 or the associated Player versions. In addition, the guest and host must be Windows-based, among other requirements, Immunity said in its release notes.
Assume that if that's been publicly released, more advanced stuff has already been seen in the wild.
But, yeah, paranoia is healthy in this circumstance.
You don't scan it, just use it in a disposable environment (usually a VM, on a non-valuable machine) and see what it does.
ps to answer your other question - antivirus scanners look for patterns in the file itself, so they don't need to install it, but are vulnerable to alternative packaging, modified code, etc etc (of course, scanners also check for problems with installed files, but the first line of defense is to inspect the data - including unpacking zip files etc).