Update Malware analysis.md
This commit is contained in:
parent
03ec0f57f5
commit
d9a496e28b
@ -3,7 +3,8 @@
|
||||
* [Malware analysis](#Malware-analysis)
|
||||
+ [86ccedaa93743e83787f53e09e376713.docx](#malware1)
|
||||
+ [d2263c15dfcccfef16ecf1c1c9304064befddf49cdbbd40abd12513481d7faf7.doc](#malware2)
|
||||
+ [01d85719c5fec354431881f304307bb5521ecf6cb50eec4d3ec40d103dd3d3ae.docx](#malware3)
|
||||
+ [01d85719c5fec354431881f304307bb5521ecf6cb50eec4d3ec40d103dd3d3ae.docx](#malware3)
|
||||
+ [pk_17e3a134ee4bcb50a9f608409853628ac619fd24cffd8d15868cf96ce63bb775.doc](#malware4)
|
||||
* [Cyber Threat Intel](#Cyber-Threat-Intel)
|
||||
* [Indicators Of Compromise (IOC)](#IOC)
|
||||
* [References MITRE ATT&CK Matrix](#Ref-MITRE-ATTACK)
|
||||
@ -40,11 +41,28 @@
|
||||
###### The RTF file download and executed drop the same backdoor.
|
||||
data:image/s3,"s3://crabby-images/d4eb4/d4eb4c51acf842a4a56a4c6d34cef1208cc18761" alt="alt text"
|
||||
### 01d85719c5fec354431881f304307bb5521ecf6cb50eec4d3ec40d103dd3d3ae.docx <a name="malware3"></a>
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
###### The next sample use Template injection too for download and executed drop the RTF file.
|
||||
data:image/s3,"s3://crabby-images/2a8d3/2a8d370528d39da386548c029d705569917dbeb0" alt="alt text"
|
||||
###### The RTF file push a persistence with a LNK file, extract the backdoor and execute on another instance of explorer.
|
||||
data:image/s3,"s3://crabby-images/845c3/845c3896a2df7416ae8b13a0f1a5b748c5fe4d39" alt="alt text"
|
||||
###### The backdoor use a timer for as anti-sandbox method and check the features.
|
||||
data:image/s3,"s3://crabby-images/8d557/8d55796155d651aae52e592ce8245899dc33c4c4" alt="alt text"
|
||||
data:image/s3,"s3://crabby-images/4234a/4234aed64c945e2710baf9f1c84c1215d3a121fb" alt="alt text"
|
||||
###### This push in memory the backdoor and check the system informations.
|
||||
data:image/s3,"s3://crabby-images/e30ff/e30ffdb8798adb0c2a9d0c03415b170124966251" alt="alt text"
|
||||
data:image/s3,"s3://crabby-images/eb14c/eb14ce064f0b5a7e6e3d7533bead25257233e76b" alt="alt text"
|
||||
###### This have the capacity to hijack the AVAST AV, send the informations and request to the C2 for commands. This can save a file and execute it on the computer.
|
||||
data:image/s3,"s3://crabby-images/a2bd1/a2bd1239682c151a1ee90acffb4ac6b4c76a9ff1" alt="alt text"
|
||||
data:image/s3,"s3://crabby-images/61b1a/61b1a1f94e68a3de5291d05a52884e315cd68a42" alt="alt text"
|
||||
data:image/s3,"s3://crabby-images/31b71/31b71b091dd521d2abab5042f7f0d4bd9fd165b3" alt="alt text"
|
||||
### pk_17e3a134ee4bcb50a9f608409853628ac619fd24cffd8d15868cf96ce63bb775.doc <a name="malware74"></a>
|
||||
###### This continue to use Template injection.
|
||||
data:image/s3,"s3://crabby-images/94626/9462610dcbd413e578b0ccf3bd87f3944dcf0be6" alt="alt text"
|
||||
###### The RTF file dropped extract a js file, a dll and an exe file.
|
||||
data:image/s3,"s3://crabby-images/e7529/e75292a666d5538f09e818e86849fed9c882b9be" alt="alt text"
|
||||
###### The js file execute the dll and the exe file for bypass the UAC by the UACme tool. The backdoor is the same that the first sample.
|
||||
data:image/s3,"s3://crabby-images/10c1e/10c1e62ffece60dcfdd0e739addda78450cf46e4" alt="alt text"
|
||||
data:image/s3,"s3://crabby-images/f1eea/f1eea4b25366951005e8c0c610f8722e3a3df00b" alt="alt text"
|
||||
|
||||
## Cyber kill chain <a name="Cyber-kill-chain"></a>
|
||||
###### The process graph resume the cyber kill chain used by the attacker.
|
||||
@ -88,4 +106,4 @@
|
||||
* [SecurityM Opendir](https://app.any.run/tasks/793250a3-e767-47a8-9042-fce7c89a0471)
|
||||
* [ScanSecurity Opendir](https://app.any.run/tasks/ae0325de-4aa2-40f0-8b17-1ca540cf2b9f)
|
||||
###### Documents: <a name="Documents"></a>
|
||||
* [link]()
|
||||
* [UACme](https://github.com/hfiref0x/UACME)
|
||||
|
Loading…
Reference in New Issue
Block a user