Posts

Showing posts with the label rhadamanthys

280. Hunting for Suspicious TLDs

Image
Hello everyone! We already looked how to use parts of URLs in our threat hunting missions, let's look at another similar artefact - TLDs. In some cases adversaries use quite exotic TLDs for their infrastructure. Let's look at a recent example related to Rhadamanthys (yes, again). Most of the domains have quite suspicious TLDs, for example: cloud341[.]autos cloud341[.]baby cloud341[.]icu cloud341[.]lol cloud341[.]monster cloud34221[.]hair cloud34221[.]homes cloud34221[.]quest cloud343[.]boats cloud9342[.]beauty Worth a hunting query, right? event_type: "dnsreqwin" AND dns_rname: (*.autos OR *.baby OR *.icu OR *.lol OR *.monster OR *.hair OR *.homes OR *.quest OR *.boats OR *.beauty) See you tomorrow!

275. Hunting for Suspicious URLs

Image
Hello everyone! How often do you use proxy logs for threat hunting? I hope often enough as C2 communications may involve accessing quite interesting URLs. Let's look at a few examples! The first one is related to an activity cluster we track as Watch Wolf . If you look at the example, you can see that the malware accesses the following URL: hxxps://4ad74aab[.]cfd/index.php Of course, even the domain itself is quite suspicious, including the TLD, but the URL also contains " index.php ", so we can use both to create a hunting query. Another example - Rhadamanthys . And another suspicious URL, of course: hxxps://193.84.71[.]81/gateway/wcm6paht.htbq1 Here we also have an interesting part for building a hunting query - " gateway ".  See you tomorrow!

146. Adversaries Abuse Haihaisoft PDF Reader to Deliver Rhadamanthys Stealer

Image
Hello everyone! As you know, stealers are the most common threats nowadays. What does it mean? Threat actors find new and new ways to deliver it to the target system. Let's look at  Rhadamanthys campaign uncovered by  Cybereason . The adversary abused a renamed Haihaisoft PDF Reader executable (for example, Preuve de la violation.pdf .exe ) to sideload a malicious DLL ( msimg32.dll ), which which enabled persistence and downloaded the stealer payload. As we're dealing with a renamed exacutable, we can use it to build our detection logic: event_type: "processcreatewin" AND proc_file_originalfilename: "hpreader.exe" AND NOT proc_file_name: "hpreader.exe" See you tomorrow!