Update Malware analysis 31-08-19.md
This commit is contained in:
parent
cc8afd581c
commit
2c38c3c124
@ -2,6 +2,7 @@
|
||||
## Table of Contents
|
||||
* [Malware analysis](#Malware-analysis)
|
||||
+ [Initial vector](#Initial-vector)
|
||||
+ [ArtraDownloader](#ArtraDownloader)
|
||||
* [Cyber Threat Intel](#Cyber-Threat-Intel)
|
||||
* [Indicators Of Compromise (IOC)](#IOC)
|
||||
* [References MITRE ATT&CK Matrix](#Ref-MITRE-ATTACK)
|
||||
@ -13,11 +14,27 @@
|
||||
## Malware-analysis <a name="Malware-analysis"></a>
|
||||
### Initial vector <a name="Initial-vector"></a>
|
||||
|
||||
###### Use a document with a remote template injection as initial vector. This download the
|
||||
###### Use a document with a remote template injection as initial vector. This request http[:]//maq.com.pk/ for be redirected on the next URL.
|
||||
data:image/s3,"s3://crabby-images/6d0c4/6d0c4ff39d6591dbcec4a26e3ca8376de4f6de03" alt="alt text"
|
||||
|
||||
###### This second URL (http[:]//maq.com.pk/wehsd) send a RTF exploit.
|
||||
data:image/s3,"s3://crabby-images/ddfb3/ddfb31a9218372ee4d9e14eaa3492d719ac8dd2c" alt="alt text"
|
||||
###### This exploit execute firstly a request by WebDAV and after by WebClient service for download the backdoor on the final address (http[:]//maq.com.pk/wehs) and execute it.
|
||||
data:image/s3,"s3://crabby-images/1408f/1408f9430cf05164c72a78644d48d42873ebd377" alt="alt text"
|
||||
###### Here we can see the redirection and the data sended on the victim.
|
||||
data:image/s3,"s3://crabby-images/9870d/9870d21c4df795717b7feff4b38f548842e37cb8" alt="alt text"
|
||||
### ArtraDownloader <a name="ArtraDownloader"></a>
|
||||
###### In the first, we can see some encoded string pushed on a function and the result is moved on another registry as storage for be used by the backdoor.
|
||||
data:image/s3,"s3://crabby-images/14ed5/14ed56a98fc146e2596533e81a02b82c24521631" alt="alt text"
|
||||
###### In observing this function we can resume by the folowing algorithm used for decode these strings : for each byte of the string -> value of the byte -1 -> get Unicode value -> convert to char.
|
||||
data:image/s3,"s3://crabby-images/4f4ad/4f4ad0d9a696b6486596090699e5c381bf267a1b" alt="alt text"
|
||||
###### We can edit a script for decode the encoded string.
|
||||
data:image/s3,"s3://crabby-images/ce02c/ce02c09fc288e105af3859d6c2ac7ff111096b54" alt="alt text"
|
||||
###### Now we can see the actions did by the malware.
|
||||
data:image/s3,"s3://crabby-images/10e98/10e982e366543c272030ff5f459191a8cba54ae1" alt="alt text"
|
||||
data:image/s3,"s3://crabby-images/1d53c/1d53c382542d006e5f26879fe48755e61c42d55b" alt="alt text"
|
||||
### Cyber kill chain <a name="Cyber-kill-chain"></a>
|
||||
###### This process graph represents the cyber kill chain of Bitter sample.
|
||||
data:image/s3,"s3://crabby-images/dbdca/dbdca4df1b179ad5ec882f4861726899d49bf4c8" alt="alt text"
|
||||
### Cyber Threat Intel<a name="Cyber-Threat-Intel"></a>
|
||||
|
||||
## References MITRE ATT&CK Matrix <a name="Ref-MITRE-ATTACK"></a>
|
||||
|
Loading…
Reference in New Issue
Block a user