External Threat Management Labs

RiskIQ Enterprise Digital Footprint Platform Enables Customers to Fight New Samsam Ransomware Malware

Ransomware malware, which encrypts your data until you pay a ransom to unlock it, is evolving into more dangerous variants. Samsam, the newest evolution, which was implicated in the infection of a hospital in Maryland, attacks organizations by compromising old or improperly configured instances of JBoss. Once it gains a foothold in your network via this compromised server, Samsam attempts to infect—and ransom—data across your company's entire network.

RiskIQ Enterprise Digital Footprint enables you to quickly discover and report on outdated frameworks in your digital footprint, regardless of where they are located on the Internet. This includes automatically identifying outdated versions of JBoss. This intelligence can also be easily exported for use by your SOC and patch management team, as well as imported into vulnerability scanners, to ensure that vulnerable systems are accurately verified and remediated.

New Insights feature in Enterprise Digital Footprint

RiskIQ's new “Insights” dashboard provides rapid visibility into web assets in your digital footprint that put your organization at risk—including legacy versions of frameworks like JBoss, the java application server targeted by Samsam. Insights also identifies targets of external threats like outdated versions of WordPress and Drupal Content Management Systems, supposedly responsible for the recent "Panama Papers" Breach.

To leverage “Insights” and report on outdated and at-risk frameworks in your environment:

  1. Log in to RiskIQ
  2. Click the "Dashboards" menu selection on the left
  3. Click "Insights"
  4. Click "At Risk Frameworks" to view the assets from inventory
  5. From the left navigation menu, expand WEB SITE
  6. Note the Frameworks matching the At Risk "Insight" logic
  7. If desired, the assets in this view can be exported/downloaded using the down arrow icon on the right

Here’s an Example of RiskIQ Enterprise Digital Footprint Insights:


Further reading on the subject of Samsam Crypto Ransomware and deprecated frameworks:

  1. http://www.reuters.com/article/us-usa-cyber-ransomware-idUSKCN0WU1GB
  2. http://arstechnica.com/security/2016/03/maryland-hospital-group-hit-by-ransomware/
  3. https://www.helpnetsecurity.com/2016/03/31/samas-ransomware-enters-hospitals/
  4. http://www.deependresearch.org/2016/04/jboss-exploits-view-from-victim.html?m=1
  5. http://wptavern.com/outdated-and-vulnerable-wordpress-and-drupal-versions-may-have-contributed-to-the-panama-papers-breach

Subscribe to Our Newsletter

Subscribe to the RiskIQ newsletter to stay up-to-date on our latest content, headlines, research, events, and more.

Base Editor