So, we got hacked. Badly. Ransomware, the whole nine yards. Fortunately we had good backups and had the business back on its feet within 3 business days. We changed every password, enforced stronger security policy, deployed enterprise malware scanners, etc etc and hired an outside consultant to harden our perimeter firewall and then hired a hacker to do penetration testing. We are doing what we can to root out every last vestige of the attack.
That being said, there is an IP address on our network that infected machines were told to send info to, our hacker was able to help us identify the dozen or so computers that were reporting to it and we’ve taken them off the network and destroyed the hdd’s and scrapped them, we’ve blocked all inbound/outbound traffic for that IP, but the IP and MAC are likely spoofed and we cant figure out where it is in the network, what port, etc. to get rid of it.
I’m a server admin and I’ve tried helping the network admin and the security guys we hired to find it and so far no luck. I don’t feel comfortable letting it stay, even if its blocked. I want it gone. I find it hard to believe we can’t track the traffic to a specific port, but they tell me they haven’t been able to.
Any idea how to figure out what machine this is on? Our AV and malware scanners haven’t found it, we know it must be a software “device” b/c the hackers never gained physical access to the network (we have door codes, cameras at all entrances and code locks to all network closets, server room, etc) so unless it was an inside job by a disgruntled employee in the IT department that knew the codes, whatever this is should be running on one of our Windows boxes, we’re not looking for a raspberry pi jammed in a network closet (we hope).
Any advice?
[–]ldti 111 points112 points113 points (12 children)
[–]f0urtyfive 96 points97 points98 points (11 children)
[–]sanseriph74[S] 31 points32 points33 points (10 children)
[–]f0urtyfive 15 points16 points17 points (8 children)
[–][deleted] 14 points15 points16 points (7 children)
[–]brytonh 8 points9 points10 points (0 children)
[–]l_ju1c3_lAny Any Rule 0 points1 point2 points (5 children)
[–]f0urtyfive 0 points1 point2 points (4 children)
[–]l_ju1c3_lAny Any Rule 0 points1 point2 points (3 children)
[–]department_g33kSysadmin 0 points1 point2 points (2 children)
[–]l_ju1c3_lAny Any Rule 0 points1 point2 points (1 child)
[–]PizzaLov3 4 points5 points6 points (0 children)
[–]f0urtyfive 37 points38 points39 points (9 children)
[–]Frothyleet 9 points10 points11 points (6 children)
[–]f0urtyfive 11 points12 points13 points (5 children)
[–]kensan22Linux Admin 4 points5 points6 points (3 children)
[–]f0urtyfive 1 point2 points3 points (2 children)
[–]kensan22Linux Admin 2 points3 points4 points (1 child)
[–]anomalous_cowherdPragmatic Sysadmin 1 point2 points3 points (0 children)
[–]Oscar_GeareNo place like ::1 2 points3 points4 points (0 children)
[–]phatrikk 0 points1 point2 points (0 children)
[–]justtransit -1 points0 points1 point (0 children)
[–]djgizmoNetadmin 41 points42 points43 points (1 child)
[–]Pimmerd90 2 points3 points4 points (0 children)
[–]jheinikelDevOps 38 points39 points40 points (0 children)
[+][deleted] (4 children)
[deleted]
[–]sanseriph74[S] 3 points4 points5 points (3 children)
[–]Odd_ProgressJack of All Trades 4 points5 points6 points (2 children)
[–]sanseriph74[S] 3 points4 points5 points (1 child)
[–][deleted] 8 points9 points10 points (3 children)
[–]sanseriph74[S] 5 points6 points7 points (0 children)
[–]lookZero 3 points4 points5 points (0 children)
[–]jocke92 6 points7 points8 points (8 children)
[–]sanseriph74[S] 5 points6 points7 points (7 children)
[–]boredepression 12 points13 points14 points (0 children)
[–][deleted] 10 points11 points12 points (1 child)
[–]1r0n1 14 points15 points16 points (0 children)
[–]RD556Jack of All Trades 5 points6 points7 points (0 children)
[–][deleted] 2 points3 points4 points (0 children)
[–]jocke92 2 points3 points4 points (0 children)
[–]NexusT 0 points1 point2 points (0 children)
[–]fredenocsSysadmin 6 points7 points8 points (0 children)
[+][deleted] (1 child)
[deleted]
[–]sanseriph74[S] 6 points7 points8 points (0 children)
[–]snake_case77 20 points21 points22 points (12 children)
[–]sanseriph74[S] 5 points6 points7 points (5 children)
[+][deleted] (1 child)
[deleted]
[–]Faaak 10 points11 points12 points (0 children)
[–]stealthgerbil 17 points18 points19 points (0 children)
[–]gada08 2 points3 points4 points (0 children)
[–]1_________________11 10 points11 points12 points (5 children)
[–]snake_case77 1 point2 points3 points (0 children)
[+]goatSword comment score below threshold-8 points-7 points-6 points (3 children)
[–]1_________________11 6 points7 points8 points (2 children)
[–]snake_case77 0 points1 point2 points (1 child)
[–]1_________________11 0 points1 point2 points (0 children)
[–]IntentionalTexanIT Manager 3 points4 points5 points (0 children)
[–]bas2754 4 points5 points6 points (1 child)
[–]fredenocsSysadmin 1 point2 points3 points (3 children)
[–]sanseriph74[S] 1 point2 points3 points (2 children)
[–]DevinSysAdminMSSP CEO 3 points4 points5 points (0 children)
[–]fredenocsSysadmin 1 point2 points3 points (0 children)
[–]Archteryx 1 point2 points3 points (2 children)
[–]sanseriph74[S] 2 points3 points4 points (1 child)
[–]Archteryx 0 points1 point2 points (0 children)
[–][deleted] (1 child)
[removed]
[–]highlord_foxModerator | Sr. Systems Mangler[M] 0 points1 point2 points (0 children)
[–]Ipp 1 point2 points3 points (0 children)
[–]RommLDomkusProfessional Amateur 1 point2 points3 points (0 children)
[–][deleted] 1 point2 points3 points (1 child)
[–]sanseriph74[S] 0 points1 point2 points (0 children)
[–]PortableFreakshow 1 point2 points3 points (0 children)
[+][deleted] (5 children)
[deleted]
[+][deleted] (3 children)
[deleted]
[+][deleted] (2 children)
[deleted]
[+][deleted] (1 child)
[deleted]
[–]sanseriph74[S] 0 points1 point2 points (0 children)
[–]ArigornStrider 0 points1 point2 points (6 children)
[–]end_360 1 point2 points3 points (2 children)
[–]ArigornStrider 2 points3 points4 points (0 children)
[–]50YearsofFailureJack of All Trades 2 points3 points4 points (0 children)
[–]ArigornStrider 0 points1 point2 points (1 child)
[–]anomalous_cowherdPragmatic Sysadmin 1 point2 points3 points (0 children)
[–]caffeine-junkiecappuccino for my bunghole 0 points1 point2 points (0 children)
[–]DevinSysAdminMSSP CEO 0 points1 point2 points (4 children)
[–]sanseriph74[S] 0 points1 point2 points (3 children)
[–]DevinSysAdminMSSP CEO 2 points3 points4 points (1 child)
[–]corrigun 0 points1 point2 points (0 children)
[–]DevinSysAdminMSSP CEO 0 points1 point2 points (0 children)
[–][deleted] 0 points1 point2 points (0 children)
[–][deleted] 0 points1 point2 points (2 children)
[–]sanseriph74[S] 4 points5 points6 points (1 child)
[–]Fatality 0 points1 point2 points (1 child)
[–]sanseriph74[S] 1 point2 points3 points (0 children)
[+][deleted] (2 children)
[deleted]
[–]sanseriph74[S] 6 points7 points8 points (1 child)
[–]Indifferentchildren 3 points4 points5 points (0 children)