Posts

Showing posts with the label turla

267. Hunting for PteroEffigy

Image
Hello everyone! Let's keep digging into the report on Gamaredon and Turla collaboration. This time we'll look at another Gamaredon's malware -  PteroEffigy . PteroEffigy is another PowerShell-based downloader, and it also abuses a legitimate web service. But unlike PteroGraphin, it leverages  api.gofile[.]io instead of telegra[.]ph . Of course, we can convert this knowledge into a hunting query: event_type: "dnsreqwin" AND dns_rname: "gofile.io" AND proc_file_name: "powershell.exe" See you tomorrow!

266. Hunting for PteroGraphin

Image
Hello everyone! ESET released a report on potential collaboration of two notorious threat actors: Gamaredon and Turla . So let's look at some hunting opportunities. According to the report, Turla leveraged Gamaredon's downloaders to deliver its own malware. Gamaredon's downloaders, for example,  PteroGraphin , are PowerShell-based and use  telegra[.]ph for storing the payloads, so it enables us to hunt for similar behaviors: event_type: "dnsreqwin" AND dns_rname: "telegra.ph" AND proc_file_name: "powershell.exe" See you tomorrow!

012. They Want to Know Everything About Your System!

Image
Hello everyone! Today we'll look at reconnaissance techniques leveraged by Secret Blizzard (also known as Turla) as seen in the report by Microsoft Threat Intelligence.  In this campaign Secret Blizzard used the Amadey bot to download its own backdoors to specifically selected target devices associated with the Ukrainian military. So, one of the batch scripts leveraged by adversary invoked lots of reconnaissance commands. Let's look at each of them: ver - to collect information about OS version; systeminfo - to collect compromised system information; ipconfig /all - to collect the full TCP/IP configuration for all adapters; ipconfig /displaydns - to collect the contents of the DNS client resolver cache; route print - to collect the entries in the local IP routing table; arp -a - to collect information on current arp cache tables for all interfaces; netstat -a -n - to collect information on active network connections; net share - to collect information on ...