@V4ltzz@naumovax@Bitdefender They do it by connecting using raw sockets (historically NTSockets) which establishes the connection first, then you can forge whatever you want because you don't rely on DNS. We blogged about the netcomm portion in
https://t.co/OnHa8aOlyF
@ipurple Not sure what is so novel about this, diagram suggests timers in a remote process... Readme claims it doesn't use common injection APIs like CreateRemoteThread, but then the PoC proceeds to use CreateRemoteThread. This seems to just buy a slightly cleaner call stack?
@banthisguy9349@solostalking@proofpoint@sysopfb 2/2 as for finding samples, it was interesting mostly due to detection of HTTP requests without any network APIs in dynamic analysis (inspired by NTSockets)
While the IoCs shared that you are referencing are no doubt helpful, it was not used in the creation of the blog afaik.
@banthisguy9349@solostalking@proofpoint 1/2 Relative to OSINT, the samples I reversed were found in our data; we acknowledged the work done by @sysopfb as the shellcode correlation was something I was previously unaware of, which ironically was very likely the same campaign he blogged about.
@naumovax Ahh I see, the hash from the Triage links is different than the one from the initial tweet.
From your Triage, I see this as
QuasarRAT v1.5.1
C2 configured to
ilovecatgirlsowo-29235.portmap[.]io:29235;
@naumovax But yeah for your other port (29235), seems it dropped some additional stealer; Did not get the same behavior in my analysis unfortunately. If you have the sample that did this specific netcomm feel free to DM me the hash/sample and I'd love to look!
@naumovax Looks like Quasar RAT to me (Version: 1.4.1). In our sandbox I see the certificate it decodes for C2 which has default Quasar strings (image from process dump):