{"id":42084,"date":"2018-04-24T04:00:00","date_gmt":"2018-04-24T04:00:00","guid":{"rendered":"https:\/\/www.cira.ca\/blog\/weekly-web-security-warning-tips-managing-risk\/"},"modified":"2023-03-10T10:57:07","modified_gmt":"2023-03-10T15:57:07","slug":"weekly-web-security-warning-tips-managing-risk","status":"publish","type":"cira_news","link":"https:\/\/stg-saas.cira.ca\/en\/resources\/news\/cybersecurity\/weekly-web-security-warning-tips-managing-risk\/","title":{"rendered":"Weekly web security warning \u2013 tips for managing risk"},"content":{"rendered":"<p>Every week, we examine the top trends in malicious activity we have seen in Canada using data obtained through CIRA&#8217;s D-Zone DNS Firewall.<\/p>\n<p><!--more--><\/p>\n<p>This week, in addition to providing the list of top ten blocks,&nbsp;we&#8217;re hoping to help Canadian IT managers understand and manage risk by profiling&nbsp;new threats and&nbsp;interesting security stories.<\/p>\n<p>Earlier this week, the <a href=\"http:\/\/www.cbc.ca\/news\/canada\/prince-edward-island\/pei-government-web-site-outage-1.4631157\">PEI government website&nbsp;was hit with ransomware<\/a>. While we haven&#8217;t seen full details, from what is reported this was likely an automated hack that found a vulnerability to exploit rather than something that found its way in through a user or clickbait. <a href=\"https:\/\/cryptovest.com\/news\/prince-edward-island-website-down-due-to-crypto-ransomware-attack\/\">According to Cryptovest, the ransomware demand was a whopping $50US<\/a>. For that little (as one Reddit poster said, &#8220;It&nbsp;costs me $47 to get off the island&#8221;), on such an important property, demonstrates that not all hackers are after large sums of money.<\/p>\n<p>The good news is that they were able to restore from backup and carry on their merry way. While this all sounds like a cut-and-dry issue that was solved easily throught the great people and processes in the PEI government, some of the news does underscore the issue when hacks happen. If you read to the end of this CBC <a href=\"http:\/\/www.cbc.ca\/news\/canada\/prince-edward-island\/pei-government-web-site-outage-1.4631157\">article on the subject <\/a>you get quotes like, &#8220;it&#8217;s just concerning, they have everybodies information, so doesn&#8217;t make you feel very secure.&#8221; It illustrates that to IT folks, there certainly seemed to be no risk to data or systems but the public perception can be very different.&nbsp;<\/p>\n<p>So to segue into the planned weekly update, we want to remind everyone how important it is to maintain strong passwords with a few tools that can help.<\/p>\n<h2>Tools that can help when an account has been compromised<\/h2>\n<p>If you run an IT department, here are a couple of tool recommendations:&nbsp;<\/p>\n<h3>1) Gotcha<\/h3>\n<p>Cnsider this an important public service announcement from your friendly neighborhood Canadian domain Registry.&nbsp;On this site you can simply enter an email domain address and see what users might have been leaked. The threat is real \u2013 on their website, Gotcha states that <a href=\"https:\/\/gotcha.pw\/stats\/country\/CA\">over 4.2 million Canadian accounts<\/a> credentials have been leaked.<\/p>\n<p>In addition to data theft, many of these breaches occur through phishing so we&#8217;ll also remind you to maintain several strong tools such as spam filters, perimeter firewalls and DNS firewalls&nbsp;to block the latest phishing threats.<\/p>\n<h3>2) &#8216;;&#8211;have i been pwned?<\/h3>\n<p>For individuals looking for a little more data about themselves, this&nbsp;site can be a real eye-opener because it not only shows the leaks of your account information to the Dark Web, but it also shows more detail on the data breach that made it happen.&nbsp;<\/p>\n<p>For fun you can also type in a password that you have used in the past (probably not recommended to search a current one) and see how often it is has been \u201cpwned\u201d. This can be a good educational tool for your users to stop using \u201cpassword1\u201d. Find this over at <a href=\"https:\/\/haveibeenpwned.com\/\">haveibeenpwned.com<\/a>.<\/p>\n<h2>Top ten domains blocked last week<\/h2>\n<p>Let&#8217;s look at the top domain threats we saw last week from our current D-Zone DNS Firewall user base across Canada. The threat profile has really ticked-up with more nefarious Trojans making up three of the top ten threats and .ru sites continuing to be among the most used. Trojan downloaders can take all kind of nasty turns as they automatically download software that can perform data theft, keylogging&nbsp;and more.<\/p>\n<div style=\"text-align:center\">\n<figure>\n<div>\n<table border=\"1\" cellpadding=\"0\" style=\"width:449px\" width=\"0\">\n<thead>\n<tr>\n<th style=\"width:190px\">\n<p><strong>Domain Name<\/strong><\/p>\n<\/th>\n<th style=\"width:254px\">\n<p><strong>Threat Type<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width:190px\">\n<p>superyou.zapto.org<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Spybot<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>dj1.jfrmt.net<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Morto<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>76236osm1.ru<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Trojan downloaders<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>mastopak.xyz<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Malware Call Home<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>soplifan.ru<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Trojan downloaders<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>amnsreiusojy.ru<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>VBInject<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>diplicano.ru<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Trojan downloaders<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>ns6.wowrack.com<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Mirai<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>ns5.wowrack.com<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Mirai<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:190px\">\n<p>buysellstops.com<\/p>\n<\/td>\n<td style=\"width:254px\">\n<p>Malware Call Home<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<\/figure>\n<\/div>\n<p>And finally, how are things going overall? For this, let&#8217;s take a look back to January of this year at the unique outbound calls (i.e. botnets) per subscriber IP. We&nbsp;see a remarkably static looking trend of quiet weekends and busy weeks. The overall infection count has grown slightly but other than one big spike that was largely the result of a big problem at one large client, the trend on botnet infected clients is one of modest increase.<\/p>\n<div style=\"text-align:center\">\n<img loading=\"lazy\" decoding=\"async\" class=\" size-full wp-image-2390\" src=\"https:\/\/stg-saas.cira.ca\/uploads\/2018\/04\/D-zone-blog-graph.png\" alt=\"\" title=\"\" width=\"674\" height=\"411\" srcset=\"https:\/\/stg-saas.cira.ca\/uploads\/2018\/04\/D-zone-blog-graph.png 674w, https:\/\/stg-saas.cira.ca\/uploads\/2018\/04\/D-zone-blog-graph-300x183.png 300w\" sizes=\"auto, (max-width: 674px) 100vw, 674px\" \/><\/p>\n<div class=\"media media-element-container media-default\">&nbsp;<\/div>\n<p>&nbsp;<\/p>\n<div class=\"media media-element-container media-default\">\n<img loading=\"lazy\" decoding=\"async\" class=\" size-full wp-image-2392\" src=\"https:\/\/stg-saas.cira.ca\/uploads\/2018\/04\/dzone-blog-graph-2.png\" alt=\"\" title=\"\" width=\"1053\" height=\"640\" srcset=\"https:\/\/stg-saas.cira.ca\/uploads\/2018\/04\/dzone-blog-graph-2.png 1053w, https:\/\/stg-saas.cira.ca\/uploads\/2018\/04\/dzone-blog-graph-2-300x182.png 300w, https:\/\/stg-saas.cira.ca\/uploads\/2018\/04\/dzone-blog-graph-2-1024x622.png 1024w, https:\/\/stg-saas.cira.ca\/uploads\/2018\/04\/dzone-blog-graph-2-768x467.png 768w\" sizes=\"auto, (max-width: 1053px) 100vw, 1053px\" \/>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Every week, we examine the top trends in malicious activity we have seen in Canada using data obtained through CIRA&#8217;s D-Zone DNS Firewall.<\/p>\n","protected":false},"featured_media":1949,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"ngg_post_thumbnail":0,"slim_seo":{"title":"Weekly web security warning \u2013 tips for managing risk - CIRA","description":"Every week, we examine the top trends in malicious activity we have seen in Canada using data obtained through CIRA's D-Zone DNS Firewall. This week, in additio"},"footnotes":""},"topic":[28],"class_list":["post-42084","cira_news","type-cira_news","status-publish","has-post-thumbnail","hentry","cira_news_type-cira-news-type-blog","cira_topic-cira-topic-cybersecurity","cira_author-rob-williamson"],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/cira\/v1\/news\/42084","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/cira\/v1\/news"}],"about":[{"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/wp\/v2\/types\/cira_news"}],"version-history":[{"count":0,"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/cira\/v1\/news\/42084\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/wp\/v2\/media\/1949"}],"wp:attachment":[{"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/wp\/v2\/media?parent=42084"}],"wp:term":[{"taxonomy":"cira_topic","embeddable":true,"href":"https:\/\/stg-saas.cira.ca\/en\/wp-json\/cira\/v1\/topic?post=42084"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}