Netsurion logo Netsurion logo
  • Managed Threat Protection
    Back
    Managed Threat Protection
    EventTracker

    Powerful threat prediction, prevention, detection, and response along with compliance in a scalable, simple managed solution.

    • Solution Overview Managed Threat Protection
    • Platform Details Threat Protection Platform
    CapabilitiesKey Capabilities
      Back
      Key Capabilities
    • Security Operations Center
    • SIEM
    • Endpoint Security
    • Threat Detection & Response
    • Intrusion Detection
    • Vulnerability Management
    • Threat Hunting
    • Ransomware Protection
    • Microsoft 365 Security
    • Regulatory Compliance
    Business ApplicationsBusiness Applications
      Back
      Business Applications
    • Private Equity
    • Banking & Financial Services
    • Healthcare & Pharmaceutical
    • Retail & Hospitality
  • Secure Edge Networking
    Back
    Secure Edge Networking
    BranchSDO

    All-in-one networking solution that combines network connectivity, agility, security, and compliance in an affordable managed solution.

    • Solution Overview Managed Secure Edge Networking
    • Platform Details Edge Networking Platform
    CapabilitiesKey Capabilities
      Back
      Key Capabilities
    • Network Operations Center
    • Secure SD-WAN
    • Next-Gen Firewall
    • Network Threat Response
    • Network Segmentation
    • Cellular Failover
    • Wi-Fi Management
    • PCI DSS Compliance
    Business ApplicationsBusiness Applications
      Back
      Business Applications
    • Point-of-Sale Security
    • Restaurant & Hospitality
    • Retail & C-Store
    • Branch Offices
  • Partners
    Back
    Partners
    Partner Program Overview

    Accelerate business growth through our award-winning partner program.

    • Partner Program Overview
    • Managed Service Provider Program
    Partner Program Overview Image
  • Insights
    Back
    Insights
    Insights
    • View All
    • Cybersecurity
    • Edge Networks
    • Compliance
    • SOC Catch of the Day
    • Webcasts & Events
    Insights Image
  • Company
    Back
    Company
    About Us
    • About Netsurion
    • Leadership
    • News
    • Careers
    • Contact Us
    About Us Image
  • Support
    • myNetsurion
    • BranchSDO Support
    • EventTracker Support
  • Support
  • myNetsurion
  • Contact Us
  • How to Buy

SOC Catch of the Day

We review billions of logs daily to keep you safe from advanced threats.

HomeInsights Catch of the Day Blackhole Foiled at Global Law Firm

Blackhole Foiled at Global Law Firm

The Network: A law firm with 14 offices worldwide. Their team is supplemented by EventTracker SIEM on a 24/7 basis.

The Expectation: Robust and up-to-date (Anti-Virus, Next-Gen Firewall) prevention mechanisms thwart most common attacks, but since perfect protection is not practical, monitoring is also necessary.

The Catch: Netsurion’s SOC analysts observed suspicious network traffic that matched patterns from the Blackhole exploit kit, one of the most prevalent web threats. Its purpose is to deliver a malicious payload to a victim’s computer. The majority of infections due to this exploit kit are done in a series of high-volume spam runs. Blackhole incorporates tracking mechanisms so that people maintaining the malware know considerable information about the victims, including the victim’s country, operating system, browser, and which piece of software on the victim’s computer was exploited.

The Find: A large number of connections from a desktop inside one of the locations was observed — many of these connections were to IP Addresses with poor reputation. Simultaneously, the desktop was observed to be using unusually high amounts of memory.  These are indicators of compromise (IoCs).

The Fix: The Netsurion SOC analyst immediately notified the customer’s IT team to check this desktop for vulnerable plugins (Adobe) to the Chrome browser. The onsite IT team confirmed that the plugins were vulnerable and quickly removed them from the user’s desktop.

The Lesson: Ensure that the browser’s plugins and operating system are up-to-date since Blackhole targets vulnerabilities in old versions of browsers such as Firefox, Google Chrome,  and Safari, as well as many popular plugins such as Adobe Flash, Adobe Acrobat and Java. Blackhole is polymorphic and mutates constantly to evade detection, so traditional anti-virus signatures will lag behind the automated generation of new variants. Netsurion’s Managed Threat Protection defends against new variants.

Related Catches
  • Dubious Document Destroyed at Law Firm
  • Phony Performance Warning Foiled
  • Vulnerable VoIP
Latest Catches
  • MITRE ATT&CK Guides MSP on Cobalt Strike Threat Mitigation
  • PowerShell Threat Neutralized by MSP of Financial Client
  • Crypto mining via PowerShell Caught at Retailer
Catch of the Day Catch of the Day RSS Feed

This site uses cookies to store information on your computer. Some are essential to make our site work; others help us improve the user experience. By using the site, you consent to the placement of these cookies. Read our Privacy Statement to learn more.

I Accept

Contact Us

  • (713) 929-0200
  • BranchSDO Support
  • EventTracker Support
  • partners@netsurion.com
  • sales@netsurion.com

Partners

  • Partner Program Overview
  • Managed Service Provider Program
  • Partner Portal Login
  • Find a Partner

Quick Links

  • Why Netsurion?
  • Blog
  • Careers
  • Managed Threat Protection
  • Secure Edge Networking

Follow Us:

Stay in the Loop

  • Terms of Use
  • |
  • Privacy Policy
  • |
  • Soc 2 Type 2 Compliant
  • |
  • Descriptions of Services
  • |
  • Contact Us
  • |
  • Sitemap
  • |

Copyright © 2022 Netsurion. All rights reserved.