CyberThreatIntel/Indian/APT/Patchwork/27-08-19/Malware analysis 27-08-19.md
2019-09-08 23:29:24 +02:00

3.0 KiB

Malware analysis about sample of APT Patchwork

Table of Contents

Malware analysis

Initial vector

The initial vector is an INP file (format used for the software InPage) with the exploit cve-2017-12824, we can see here the 0x7E and 0x72 represent a class of type in the stream for use an ole stream for launch the first binairy file.

alt text

We can see on the string on the dll, what extract the file in the temp folder in the create a thread for the second PE. file.

alt text alt text

Cyber kill chain

The process graph resume the cyber kill chain used by the attacker.

alt text

Cyber Threat Intel

References MITRE ATT&CK Matrix

List of all the references with MITRE ATT&CK Matrix
Enterprise tactics Technics used Ref URL

Indicators Of Compromise (IOC)

List of all the Indicators Of Compromise (IOC)
Indicator Description
Domain requested
IP requested
HTTP/HTTPS requests
IP C2
Domain C2
This can be exported as JSON format Export in JSON
Original tweet: https://twitter.com/jsoo/status/1166353584923041798
Documents: