tien phan malware manipulation 2019 08 26 2
play

Tien Phan Malware Manipulation 2019-08-26 2 Pokemon Fusion Con - - PowerPoint PPT Presentation

Tien Phan Malware Manipulation 2019-08-26 2 Pokemon Fusion Con - Fusion Malicious Malware + = Softicious X Software Tien Phan Malware Manipulation 2019-08-26 3 Reverse Engineering More time consuming Dynamic Analysis


  1. Tien Phan Malware Manipulation 2019-08-26 2

  2. Pokemon Fusion Con - Fusion Malicious Malware ✔ + = Softicious X Software Tien Phan Malware Manipulation 2019-08-26 3

  3. Reverse Engineering More time consuming Dynamic Analysis Static Analysis Fully Automated Sandbox Tien Phan Malware Manipulation 2019-08-26 4

  4. Automated Sandbox supports Malware Dynamic Manipulation Analysis Reverse Engineering Tien Phan Malware Manipulation 2019-08-26 5

  5. More clues Malware Malware manipulation Analysis Further manipulation Tien Phan Malware Manipulation 2019-08-26 6

  6. Tien Phan Malware Manipulation 2019-08-26 7

  7. Queries iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea[.]com Wannacry Unregistered domain https://www.malwaretech.com/2017/05/how-to-accidentally-stop-a-global-cyber-attacks.html Tien Phan Malware Manipulation 2019-08-26 8

  8. Tien Phan Malware Manipulation 2019-08-26 9

  9. New signatures 10 8 6 4 2 0 Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec Jan Feb Mar Apr May Jun Jul Aug 2016 2017 2018 2019 Tien Phan Malware Manipulation 2019-08-26 10

  10. Tien Phan Malware Manipulation 2019-08-26 11

  11. ComputerName = xxxx& Domain = xxxx& Id = -1& LANSetting = Gateway = xxx.xxx.xxx.xxx& IP = xxx.xxx.xxx.xxx& SubnetMask = xxx.xxx.xxx.xxx& Object = LANSetting;& LoaderType = 0& OSArch = 1& OSType = 0& OSVer = xxxx& UserName = xxxx& Object = ClientInformation Tien Phan Malware Manipulation 2019-08-26 12

  12. Tien Phan Malware Manipulation 2019-08-26 13

  13. Tien Phan Malware Manipulation 2019-08-26 14

  14. C2 URI Description /cl_client_online.php POST harvested system information /cl_client_cmd.php GET C2 command /cl_client_cmd_res.php POST C2 command result /cl_client_logs.php POST log Tien Phan Malware Manipulation 2019-08-26 15

  15. Exploit CVE-2019-3396 Confluence Server Drop Grand Crab 5.2 Mr. Black Backdoor Attackers Mr. Black Grand Crab 5.2 CVE-2019-3396 Tien Phan Malware Manipulation 2019-08-26 16

  16. Tien Phan Malware Manipulation 2019-08-26 17

  17. Tien Phan Malware Manipulation 2019-08-26 18

  18. Tien Phan Malware Manipulation 2019-08-26 19

  19. Tien Phan Malware Manipulation 2019-08-26 20

  20. Tien Phan Malware Manipulation 2019-08-26 21

  21. 2019-08-26 22 Tiean Phan Malware Manipulation

Recommend


More recommend