Posts

Showing posts with the label donot team

061. DONOT Team Has a Presentation for You

Image
Hello everyone! I think, you already got used to malicious Microsoft Word documents and Microsoft Excel spreadsheets, right? But what about Microsoft PowerPoint? Of course, we all use it to create presentations for threat briefings, but what about adversaries? Yes, they also use it! Let's look at DONOT Team (APT-Q-38) campaign described in this report. One of kill chains included a malicious PowerPoint presentation (PPT), delivered via a link in a phishing PDF document. Malicious macro in the PPT file executes the shellcode in order to download next stages. The first detection opportunity - powerpnt.exe spawns cmd.exe to execute a BAT file: cmd.exe /c C:\Users\user\AppData\Local\TEMP\FROX\cross.bat You can catch such activity this way: event_type: "processcreate" AND proc_p_file_path: "powerpnt.exe" AND proc_file_path: "cmd.exe" What does the BAT file do? Creates a scheduled task via schtasks.exe: schtasks /create /tn "PerformTaskMaintain" /...