Posts

Showing posts with the label side-loading

181. Hunting for Mustang Panda's Claimloader

Image
Hello everyone! As I noted yesterday, more and more threat actors add DLL side-loading to their arsenals. Let's at one using it for quite a long time - Mustang Panda (or Horned Werewolf as we track it). According to this report , the adversary distributed phishing emails with Google Drive links to ZIP or RAR archives. This archives contain masquaraded legitimate executables (for example, 9th WPCT Region-Wise Action Plans on Tibet.exe) and malicious Claimloader DLLs.  The threat actors abused the following legitimate executables: Adobe Licensing WF Helper ( adobe_licensing_wf_helper.exe ), Wargaming.net Game Center ( helper_process.exe ) and FFWallpaper Widgets Jyy ( fhbjyy.exe ). Of course, you already know what to do: event_type: "processcreatewin" AND ((proc_file_originalfilename: "adobe_licensing_wf_helper.exe" AND NOT proc_file_name: "adobe_licensing_wf_helper.exe") OR (proc_file_originalfilename: "helper_process.exe" AND NOT proc_file...

180. Threat Actors Abuse Legitimate Java Utility to Load Snake Keylogger

Image
Hello everyone! Even cybercrime actors evolve their techniques and adding DLL side-loading to the arsenal. Recently I spotted Snake Keylogger distributors abuse jsadebugd.exe to sideload a malicious DLL. This case is covered publicly in this report by Lab52. If we look at VirusTotal, for example, we can see that this legitimate executable was uploaded there with lots of interesting filenames : It means it's widely abused by threat actors, and it's a good idea to search for renamed executables: event_type: "processcreatewin" AND proc_file_originalfilename: "jsadebugd.exe" AND NOT proc_file_name: "jsadebugd.exe" See you tomorrow!

174. Adversaries Abuse Python to Sideload a Backdoor

Image
Hello everyone! We already talked about cases, where adversaries abused Python to execute various scripts. But this time, according to Knownsec report , the Confucius group used it for sideloading. The adversary leveraged malicious LNK files (yes, again and again) to download a bunch of files to the compromised system. These files included python313.dll (a backdoor researchers called Anondoor ) and BlueAle.exe - a renamed copy of pythonw.exe . And yes, this is another case we can hunt for suspicious renamed legitimate executables: event_type: "processcreatewin" AND proc_file_originalfilename: "pythonw.exe" AND NOT proc_file_name: "pythonw.exe" Make sure to check the report for more detection ideas! See you tomorrow!

146. Adversaries Abuse Haihaisoft PDF Reader to Deliver Rhadamanthys Stealer

Image
Hello everyone! As you know, stealers are the most common threats nowadays. What does it mean? Threat actors find new and new ways to deliver it to the target system. Let's look at  Rhadamanthys campaign uncovered by  Cybereason . The adversary abused a renamed Haihaisoft PDF Reader executable (for example, Preuve de la violation.pdf .exe ) to sideload a malicious DLL ( msimg32.dll ), which which enabled persistence and downloaded the stealer payload. As we're dealing with a renamed exacutable, we can use it to build our detection logic: event_type: "processcreatewin" AND proc_file_originalfilename: "hpreader.exe" AND NOT proc_file_name: "hpreader.exe" See you tomorrow!

121. Detecting Earth Kasha's ROAMINGMOUSE

Image
Hello everyone! Reading Trend Micro's report on Earth Kasha , I spotted a curious behavior marker of  ROAMINGMOUSE : it abuses WMI to execute JSLNTOOL.EXE via explorer.exe .  JSLNTOOL.EXE is a legitimate application used by the adversary to sideload  JSFC.dll - a malicious loader. It means we can hunt for suspicious executions of explorer.exe via wmiprvse.exe : event_type: "processcreatewin" AND proc_file_path: "explorer.exe" AND proc_p_file_path: "wmiprvse.exe" As for  JSLNTOOL.EXE , you can also hunt for related execution events, focusing on uncommon locations: event_type: "processcreatewin" AND proc_file_originalfilename: "jslntool.exe" AND NOT proc_file_path: "justsystems" See you tomorrow!

113. Adversaries Abuse Trend Micro and Bitdefender to Load Malicious DLLs

Image
Hello everyone! The threat actors keep abusing legitimate binaries for DLL Side Loading. This time the adversaries abused Trend Micro and Bitdefender. According to Symantec report , the Billbug espionage group used a Trend Micro binary named tmdbglog.exe to sideload a malicious DLL named tmdglog.dll , and a Bitdefender binary named bds.exe to sideload a malicious DLL named log.dll . We can hunt for suspicious executions of these binaries focusing on suspicious file names and locations: event_type: "processcreatewin" AND proc_file_originalfilename: ("PtWatchDog.exe" OR "BDSubWiz.exe") See you tomorrow!