Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 02-20-2017, 17:42
Shub-Nigurrath's Avatar
Shub-Nigurrath Shub-Nigurrath is offline
VIP
 
Join Date: Mar 2004
Location: Obscure Kadath
Posts: 971
Rept. Given: 70
Rept. Rcvd 431 Times in 101 Posts
Thanks Given: 83
Thanks Rcvd at 405 Times in 127 Posts
Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499
Hi,
the monetization of attacks is nowadays a matter of few minutes. Usually highly targeted phish champains last for 20 minutes or even less. This time window is, in most of the cases, enough to collect a first round of victims (usually quite high, around 15%) that can be used to prepare a second even more targetized round.

This is the way the enterprises are hit by highly targeted attacks and a fileless malware is perfect for these situations:
1. a phish mail (built using the correct mix of social engineering and memetics, to be *really* effective)
2. the mail points to a fake web site (or a trampoline through defaced hosts) that runs on a fast-flux IP for very few minutes
3. the page fingerprints the browser and delivers an ad-hoc fileless malware (crafted in realtime by a malware forgery), that contains a payload encrypted enough well (usually two custom encryptions is enough) to use, not an original development, but even a metasploit engine.
4. the payload is decrypted in a fileless system, bang, done. You can use anythings ranging from droppers, metasploits, AutoIt, ...

Persistence is not an issue anymore in several situations. Btw, the only reason for speaking of fileless malware today is that the knowledge level required to do one has been decreased by the adoption of powershell and by the development of some frameworks (see my first post). Less cumbersome to write, more samples spreading around.

The perfect solution for today's attacks, this is the essence of what the reports says ... ;-)
__________________
Ŝħůb-Ňìĝùŕřaŧħ ₪)
There are only 10 types of people in the world: Those who understand binary, and those who don't
http://www.accessroot.com

Last edited by Shub-Nigurrath; 02-20-2017 at 17:48.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Malware Analysis ldmd General Discussion 7 03-09-2025 18:42
ahk malware analysis dion General Discussion 0 12-20-2021 08:50
Malware Sample analysis Aesculapius Source Code 2 02-13-2018 19:35


All times are GMT +8. The time now is 01:58.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )