Update Malware analysis 25-08-19.md
This commit is contained in:
parent
53fd7ebd5e
commit
ab7818ad2a
@ -46,8 +46,43 @@
|
||||
data:image/s3,"s3://crabby-images/fdb1a/fdb1a4d52301ee305c2d95d8097f180d58b441d2" alt="alt text"
|
||||
###### Once the protection removed, we can see the functions used by the dll.
|
||||
data:image/s3,"s3://crabby-images/f8d8f/f8d8f9bef6f4e23acd8e48ef50312d50f68fb282" alt="alt text"
|
||||
###### The run method get the payload string push by the second PE and execute it.
|
||||
###### The run method get the payload string push by the second PE, decode it and execute it.
|
||||
data:image/s3,"s3://crabby-images/88ac5/88ac5d25e7440d74be1cf53b45370596ef08ad59" alt="alt text"
|
||||
#### Frombook
|
||||
###### We can observe on the structure, the encoding for scale the data and add junk code on the PE for avoid the detection of the AV (here, in the "Currentversion" string.
|
||||
data:image/s3,"s3://crabby-images/7e83e/7e83e8961c77a50df352377c69c434a65244ca07" alt="alt text"
|
||||
###### This sample is programming in C++ (Frombook is available in many language : VB, C, C++, C#...) and check the PE structure.
|
||||
data:image/s3,"s3://crabby-images/e5b75/e5b75840ea9f9800cfa648f3cd17070df312e3ee" alt="alt text"
|
||||
|
||||
###### This continue to detect and steal the data from the navigators.
|
||||
data:image/s3,"s3://crabby-images/1aee5/1aee5e03bb48b3db6d479117543fe79a1d0cc8db" alt="alt text"
|
||||
data:image/s3,"s3://crabby-images/1f22c/1f22c8d18f0b67ee34fd32b53a60450683891afb" alt="alt text"
|
||||
|
||||
##### This parsed and steal the passwords.
|
||||
data:image/s3,"s3://crabby-images/72233/72233549552d33168116e62fcf432fab87fbbac3" alt="alt text"
|
||||
##### We can observe the useragent settings who send the data to the C2.
|
||||
data:image/s3,"s3://crabby-images/4e238/4e2383bd438d473cf5ab1befd340d6d6012be04a" alt="alt text"
|
||||
##### This use a run key as persistence for the frombook module.
|
||||
##### Some features of Frombook form the cyberbit analysis can be observed in this analysis and the execution on the anyrun sandbox :
|
||||
* ###### Keystroke logging
|
||||
* ###### Clipboard monitoring
|
||||
* ###### HTTP/HTTPS/SPDY/HTTP2 form and network request grabbing
|
||||
* ###### Browser and email client password grabbing
|
||||
* ###### Capturing screenshots
|
||||
* ###### Bot updating
|
||||
* ###### Downloading and executing files
|
||||
* ###### Bot removing
|
||||
* ###### Launching commands via ShellExecute
|
||||
* ###### Clear browser cookies
|
||||
* ###### Reboot the system
|
||||
* ###### Shutdown the system
|
||||
* ###### Download and unpack ZIP archive
|
||||
### Cyber kill chain <a name="Cyber-kill-chain"></a>
|
||||
###### These process graphs represents the cyber kill chain of the initial vector and the Frombook module.
|
||||
data:image/s3,"s3://crabby-images/01abc/01abc28737657b52af5aeee01ba3239ab3b50325" alt="alt text"
|
||||
data:image/s3,"s3://crabby-images/cb2e5/cb2e5a2d3a78f50648c110a5c7724b938a7a608f" alt="alt text"
|
||||
### Cyber Threat Intel<a name="Cyber-Threat-Intel"></a>
|
||||
|
||||
## References MITRE ATT&CK Matrix <a name="Ref-MITRE-ATTACK"></a>
|
||||
###### List of all the references with MITRE ATT&CK Matrix
|
||||
|
||||
@ -72,7 +107,10 @@
|
||||
## Links <a name="Links"></a>
|
||||
|
||||
* Original tweet: https://twitter.com/Rmy_Reserve/status/1164405054746460161 <a name="Original-Tweet"></a>
|
||||
* Anyrun Link: [IMG76329797.xls](https://app.any.run/tasks/3cff3642-1d54-4a66-8f0d-256f0065479b)<a name="Links-Anyrun"></a>
|
||||
* Anyrun Link: <a name="Links-Anyrun"></a>
|
||||
+ [IMG76329797.xls](https://app.any.run/tasks/3cff3642-1d54-4a66-8f0d-256f0065479b)
|
||||
+ [inj2.exe](https://app.any.run/tasks/d7365b93-470c-4e2e-bc6d-5e43c711d72e)
|
||||
* Docs : <a name="Documents"></a>
|
||||
+ [Gorgon analysis by Unit42](https://unit42.paloaltonetworks.com/unit42-gorgon-group-slithering-nation-state-cybercrime/)
|
||||
+ [The Evolution of Aggah: From Roma225 to the RG Campaign ](https://securityaffairs.co/wordpress/89502/malware/evolution-aggah-roma225-campaign.html)
|
||||
+ [Gorgon analysis by Unit42](https://unit42.paloaltonetworks.com/unit42-gorgon-group-slithering-nation-state-cybercrime/)
|
||||
+ [The Evolution of Aggah: From Roma225 to the RG Campaign ](https://securityaffairs.co/wordpress/89502/malware/evolution-aggah-roma225-campaign.html)
|
||||
+ [Frombook analysis from cyberbit (June 2019)](https://www.cyberbit.com/blog/endpoint-security/formbook-research-hints-large-data-theft-attack-brewing/)
|
||||
|
Loading…
Reference in New Issue
Block a user