Some North Korean post infection malware. Nothing groundbreaking, I just always like to see the actual code when vendors gloss over it:
https://t.co/g2elohLVox
I’ve included hashes where the files were on VT, if you want to grab them to look for yourself.
Some notes and testing on (what I think is) a #VIRTUALGATE sample, following Mandiant's ESXI report:
https://t.co/XjHyQ2eaCs
MD5 3c7316012cba3bbfa8a95d7277cda873
-Opens VMCI listener on 25736
-Listens
-Runs what it receives via cmd
Post shows RE + how to test it. Cool malware
.@MITREattack v9 is out!!! A big shout out 🙌 to @patrickwardle, @thomasareed, @its_a_feature_ , and @xorrior for helping us update changes to macOS🍎. There is more to come...but let's take a moment to appreciate my new favorite gif, which summarizes this release perfectly!
Also, my personal favorite talk from the conference was from @JamesPavur - A fantastic presentation on eavesdropping on satellite internet conversations.
https://t.co/nnv9r88LoZ
No technical satellite knowledge required (I barely know how they get up there)
They put our BlackHat videos up the other day! :)
It's a bit old now, but if you want to see how #Lazarus used ISO-8583 for the #FASTCash malware in past years, here's the URL: https://t.co/Ol9cTu8Q97
Feedback is always welcome - presenting to a glowing orb was not the easiest.
Last #Lazarus#ZINC update: a source gave me the missing registry data (~2mb reg entry). Sorry for the spam... have to do this after hours.
Updated w/ brief analysis of Stage 2:
https://t.co/mxaAq13sMS
Screengrab, process launching, recon etc.
That's it from me for a while :)
Part II: Looking at the #DPRK /#Lazarus/#ZINC .sys malware targeting security researchers, with a hunt hypothesis as the highlight:
https://t.co/lSkm3COqnq
Note that I *don't* have the Stage 2 registry data. Would love to see it if someone has a copy!
@cyb3rops Yeah, I think in production land you’d have to be combining it with a last write time or at least one other factor to really make it work.
In this case, it’s more of a starting point. I’ll add a little note to clarify.
Part II: Looking at the #DPRK /#Lazarus/#ZINC .sys malware targeting security researchers, with a hunt hypothesis as the highlight:
https://t.co/lSkm3COqnq
Note that I *don't* have the Stage 2 registry data. Would love to see it if someone has a copy!
@buherator@richinseattle@daveaitel I only wrote about the DLL. Had to pick what I could get through in a few hours. My understanding:
- If you visited via browser, you got the .sys file.
- If you interacted and they sent you a VS project, you got the DLL (and perhaps the C2 sent more later, who knows).
A look at some of the malware mentioned in this Google TAG research.
https://t.co/NTsIgMeNwT
- Two-stage (payload in ProgramData)
- AV Check (Kasp, Avast)
- Basic Persistence
- Multiple C2s per payload
More to be done re:C2 comm (unless someone does it first)
#DPRK
New blog post from TAG with details of a North Korean campaign targeting security researchers working on vulnerability research and development.
https://t.co/Ec2TaMMXeQ
Stay safe out there everyone!
Interesting possible relationship between #TinyPOS + #ProLocker
https://t.co/g5dh5nKA8V
I lean towards, "would makes sense if it's the same group," but far from definitive. Was trying to find infrastructure.
@DrunkBinary (for the hashes)
@cyb3rops (for code segments and YARA)