Outline • Introduction • Automate malware analysis (how far can you go?) • Using YARA on “uncommon” or “unusual” file types • PCAP files • memory-strings & mutexes • JAR’s (Java RAT’s) • “DESKTOP-group” -- Spear Phishing emails & mail headers • YARA for email headers and body • Weird file formats: MSI + JAR || RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 34
Using YARA on “uncommon” or “unusual” file types Java RATs and JAR files Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 35
Using YARA on “uncommon” or “unusual” file types Java RATs and JAR files Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 36
Using YARA on “uncommon” or “unusual” file types Java RATs and JAR files Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 37
Using YARA on “uncommon” or “unusual” file types Java RATs and JAR files Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 38
Using YARA on “uncommon” or “unusual” file types Java RATs and JAR files Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 39
Using YARA on “uncommon” or “unusual” file types Java RATs and JAR files Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 40
Outline • Introduction • Automate malware analysis (how far can you go?) • Using YARA on “uncommon” or “unusual” file types • PCAP files • memory-strings & mutexes • JAR’s (Java RAT’s) • “DESKTOP-group” -- Spear Phishing emails & mail headers • YARA for email headers and body • Weird file formats: MSI + JAR || RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 41
First Hand Knowledge Analyzing mail headers • Date • From (display-name / email) • Subject • Attachment(s) – Filename(s) / MD5 hash(es) à Malware Analysis • Message-ID à Malware / RAT Family • X-Mailer / User-Agent à C2 domain / IP / port • X-Source-Auth / X-Sender / Authenticated-Sender • X-Source-IP / X-Originating-IP • Received headers à Client IP Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 42
First Hand Knowledge Analyzing mail headers à Excel with >140 attack mails Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 43
Message-ID / DESKTOP-name / X-Mailer Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 44
Received header hostname = Message-ID host Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 45
Received hostname ( WIN-xxx ß DESKTOP-xxx ) Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 46
Message-ID / (9) Desktop-/ (2) Server-names Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 47
Why should I care about mail headers Use YARA rules on raw RFC2822 mails to block on any header Message-ID header Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 48
Why should I care about mail headers Use YARA rules on raw RFC2822 mails to block on any header Received headers Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 49
Why should I care about mail headers Use YARA rules on raw RFC2822 mails to block on any header From header X- / Auth.-Sender Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 50
Why should I care about mail headers Use YARA rules on raw RFC2822 mails to block on body URLs URLs in body (base64) Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 51
Why should I care about mail headers Use YARA rules on raw RFC2822 mails to block on body URLs URLs in body (base64) Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 52
Why should I care about mail headers Use YARA rules on raw RFC2822 mails to block on body URLs URLs in body (base64) Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 53
Why should I care about mail headers Use YARA rules on raw RFC2822 mails to block on body URLs URLs in body (base64) Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 54
Why should I care about mail headers Use YARA rules on raw RFC2822 mails to block on any header Blocked only due to custom YARA rule Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 55
Why should I care about mail headers Use YARA rules on raw RFC2822 mails to block on any header Blocked only due to custom YARA rule Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 56
Outline • Introduction • Automate malware analysis (how far can you go?) • Using YARA on “uncommon” or “unusual” file types • PCAP files • memory-strings & mutexes • JAR’s (Java RAT’s) • “DESKTOP-group” -- Spear Phishing emails & mail headers • YARA for email headers and body • Weird file formats: MSI + JAR || RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 57
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 58
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 59
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 60
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 61
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 62
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 63
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 64
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 65
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 66
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 67
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 68
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 69
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 70
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 71
Outline • Introduction • Automate malware analysis (how far can you go?) • Using YARA on “uncommon” or “unusual” file types • PCAP files • memory-strings & mutexes • JAR’s (Java RAT’s) • “DESKTOP-group” -- Spear Phishing emails & mail headers • YARA for email headers and body • Weird file formats: MSI + JAR || RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 72
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 73
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 74
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 75
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS 7 x EXCEL.EXE 7 x PS cmd (1) Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 76
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS 1 x PS cmd (2) Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 77
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 78
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 79
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 80
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS Pow-er-sh-ell Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 81
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 82
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 83
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 84
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 85
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 86
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 87
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 88
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 89
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS Office files Last saved / author Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 90
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS (Hunting @ home) Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 91
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS (Hunting @ home) Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 92
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: RTF + XLS (Hunting @ home) Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 93
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR || RTF + XLS (Hunting @ VT) Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 94
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR || RTF + XLS (Hunting @ VT) Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 95
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR || RTF + XLS (Hunting @ VT) Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 96
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR || RTF + XLS (Hunting @ RL) Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 97
“DESKTOP-group” -- Spear Phishing emails & mail headers Weird file formats: MSI + JAR || RTF + XLS (Hunting @ RL) Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 98
Outline • Introduction • Automate malware analysis (how far can you go?) • Using YARA on “uncommon” or “unusual” file types • PCAP files • memory-strings & mutexes • JAR’s (Java RAT’s) • “DESKTOP-group” -- Spear Phishing emails & mail headers • YARA for email headers and body • Weird file formats: MSI + JAR || RTF + XLS (Hunting @ home / VT / RL) Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 99
Thanks for your attention!! Time left for questions? • Twitter: @c_APT_ure • Blog: http://c-apt-ure.blogspot.com/ à all my presentations linked in one place Reversing 2020 - YARA Summit | Pushing the Barriers of Unique YARA Uses | Tom Ueltschi | TLP-GREEN 100
Recommend
More recommend