Update analysis.md
This commit is contained in:
parent
477e42d376
commit
c34051b4f5
@ -10,6 +10,31 @@
|
|||||||
+ [External analysis](#Analysis)
|
+ [External analysis](#Analysis)
|
||||||
|
|
||||||
## Malware analysis <a name="Malware-analysis"></a>
|
## Malware analysis <a name="Malware-analysis"></a>
|
||||||
|
###### The next analysis try to kept the recents events and a logicial improvement and technics of the group, this can go back in the past for compare it.
|
||||||
|
### CES 2020 (NukeSped)
|
||||||
|
###### The initial vector of the infection begin by a current exploit in HWP (CVE-2015-6585) to execute an EPS script, this download and execute the next stage of the infection.
|
||||||
|
data:image/s3,"s3://crabby-images/d27a7/d27a7c1b94e8f1dac8aa16e5c94909b3e86f24ab" alt="alt text"
|
||||||
|
###### This execute fisrtly a common trick RtlCaptureContext for have ability to register a top-level exception handler and avoid debbuging.
|
||||||
|
data:image/s3,"s3://crabby-images/ec116/ec11678ba5a7123b7a4a1f1cd20ba6f9f1e5687b" alt="alt text"
|
||||||
|
###### Once this done, the malware execute a series of actions like list the disks, process, files and push it in differents files as temp file in waiting to send the data to C2.
|
||||||
|
data:image/s3,"s3://crabby-images/fa422/fa422254890f8206435f3e95d5e02e0bc31e02cf" alt="alt text"
|
||||||
|
data:image/s3,"s3://crabby-images/169cf/169cffe9c5b8c21841962167c35faef90219f4d9" alt="alt text"
|
||||||
|
data:image/s3,"s3://crabby-images/e8564/e8564936fbd17e8e41a7e98bc0200678e03de04b" alt="alt text"
|
||||||
|
###### The backdoor push the cookie settings and guid for the identification in the C2.
|
||||||
|
data:image/s3,"s3://crabby-images/e0187/e018753640200a1b9ba1a92b529f152235f102d7" alt="alt text"
|
||||||
|
###### This push the list of C2 address to contact, the languages to understand and begin the contact with the C2 in giving the host info.
|
||||||
|
data:image/s3,"s3://crabby-images/e608d/e608d4fba93989525bf2c9e4e485afee7c1b411d" alt="alt text"
|
||||||
|
data:image/s3,"s3://crabby-images/760ab/760ab629a89ded8bd995b58ef0c0f8e70a5f9945" alt="alt text"
|
||||||
|
###### List of the languages used :
|
||||||
|
|RFC4646/ISO 639 Ref|Lang|
|
||||||
|
|:--:|:--:|
|
||||||
|
|Az-Arab|Azerbaijani in Arabic script|
|
||||||
|
|de-CH|Swiss German|
|
||||||
|
|en-US|English as used in the United States|
|
||||||
|
|
||||||
|
###### If the target is interesting for the group, this execute command and others tools in the computer infected.
|
||||||
|
|
||||||
|
|
||||||
## Cyber kill chain <a name="Cyber-kill-chain"></a>
|
## Cyber kill chain <a name="Cyber-kill-chain"></a>
|
||||||
###### The process graphs resume all the cyber kill chains used by the attacker.
|
###### The process graphs resume all the cyber kill chains used by the attacker.
|
||||||
![alt text]()
|
![alt text]()
|
||||||
|
Loading…
Reference in New Issue
Block a user