Introduction
How VT plays a role in hunting for analysts
Seqrite - Success Story
UNG0002
malware_config:30819f300d06092a864886f70d010101050003818d003081890281810096cc4e6ad9aee91ca69b7b44465e17412626a11c7855b7a69daad00f48c0ea98f0e389a0a1c4b74332bf0d603a6e53e05ee734c9a289ff172204bfc9430ed4d6041402d02b526e902b95f6f219598cb1b6391403fa627ab36dbe88646620369e7ec89bdc31f1a2b0bedba1852d5e7656d3b297f9d39f357816f0677563bc496b020301000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
type:zip AND (metadata:"lnk" AND metadata:".vbs" AND metadata:".pdf") and submitter:HK
Silent Lynx
-
Looking at the usage of encoded Telegram Bot based payload inside the C++ implant. Using either content or malware_config modifiers when extracted from the config could help us to identify new samples.
-
Spawning Powershell.exe LOLBIN.
-
VT search enablers for checking for malicious email files, if uploaded from Central Asian Geosphere.
-
ISO-oriented first-stagers.
-
Multiple behavioral overlaps between YoroTrooper & Silent Lynx and further hunting hypothesis developed by us.
SOCIAL SHARE CARD GENERATOR