Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Windows Tipps & SecurityXbox x IKEA furniture range goes live today(01.10.2026 um 12:29 Uhr)
••
Windows Tipps & SecurityThe Witcher 3 Remastered's DLSS Xbox Play Anywhere issues has been fixed(01.10.2026 um 12:50 Uhr)
•••
Sicherheitslücken (CVE)CVE-2022-45425 | Dahua DHI-DSS4004-S2 hard-coded key (EUVD-2022-48297)(01.10.2026 um 12:29 Uhr)
•••••
Windows Tipps & SecurityXbox x IKEA furniture range goes live today(01.10.2026 um 12:29 Uhr)
••
Windows Tipps & SecurityThe Witcher 3 Remastered's DLSS Xbox Play Anywhere issues has been fixed(01.10.2026 um 12:50 Uhr)
•••
Sicherheitslücken (CVE)CVE-2022-45425 | Dahua DHI-DSS4004-S2 hard-coded key (EUVD-2022-48297)(01.10.2026 um 12:29 Uhr)
•••••
Intelligence View
⚡ tsecurity.de Intelligence

Thoughts on this CAPE Sandbox Report?

Recently got infected with a really bad malware info stealer. Been combing back looking for the source. I think I may have found it. PM if you want more info…

Beitrag
0
Seite
0
↗ Quelle (reddit.com)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

Recently got infected with a really bad malware info stealer. Been combing back looking for the source. I think I may have found it.

PM if you want more info than provided here.

Sanitized Threat Intelligence & IOC Brief: Repackaged Fileless .NET Backdoor

1. File Indicators (Cryptographic Hashes)

Variant A (ZIP Archive Stage)

  • File Type: ZIP archive data, deflate compression
  • MD5: c36b33a5370864decda5b0db97972191
  • SHA256: 1019517268a2edb2d89729661539233396b3aa524279377ca8228085957d598b

Variant B (RAR Archive Stage)

  • File Type: RAR archive data, v4, os: Win32
  • MD5: 488cc1a8f44af73bc7f7baa1fafd8fdr
  • SHA256: de5d21396908ab452059a3361f76dcb489fb705e44ac55983624a7e5d7bca1d

2. Network Indicators of Compromise (IoCs)

  • Inbound Bind Shell / P2P Node: Starts a local server listening for inbound connections on 0.0.0.0:47584 from dynamically allocated (unbacked) memory.
  • Outbound C2: Initiates HTTP network connections directly from unbacked memory to evade process-based attribution.
  • Dead Connect: Attempts to connect to a dead IP/Port.

3. File System Artifacts & DLL Hijacking Paths

The payload drops a custom directory structure into the user's temporary folder and performs DLL Side-Loading by dropping files masquerading as legitimate Windows .NET libraries.

Observed Staging Directory Patterns:

  • %TEMP%\<Staging_Directory>\Managed\
  • %TEMP%\<Staging_Directory>\<Staging_Directory>\Managed\

Abused / Masquerading DLL Names Dropped in %TEMP%**:**

  • System.Numerics.dll
  • System.Runtime.dll
  • System.Runtime.Serialization.dll
  • System.Security.dll
  • System.Core.dll
  • System.Data.dll
  • System.Data.DataSetExtensions.dll
  • System.Drawing.dll
  • System.dll

Targeted Windows System Binaries:

  • C:\Windows\SysWOW64\rundll32.exe

4. Behavioral Signatures & TTPs (MITRE ATT&CK)

  • T1574 - Hijack Execution Flow (DLL Side-Loading): Loads newly dropped .NET DLLs from a suspicious temporary directory.
  • T1055 - Process Injection & Module Stomping: Executes loops of failed Read-Write-Execute (RWX) memory allocations returning CONFLICTING_ADDRESSES in high ranges, indicative of code cave hunting or module stomping.
  • T1497 - Virtualization/Sandbox Evasion:
    • Checks for mouse movement.
    • Queries display device information.
    • Checks available system memory.
  • Defense Evasion (Fileless Memory Tradecraft):
    • Modifies exception handling mechanisms (UEF / VEH) from dynamically allocated (unbacked) memory for silent anti-debugging.
    • Alters process mitigation policies (CFG / DEP / hard error modes) directly from unbacked memory.
    • Manually resolves API addresses from unbacked memory (custom unpacker/shellcode behavior).
  • T1082 - Discovery: Queries the system's FIPS cryptography policy to adapt payload encryption
submitted by /u/Good-Fortune8137
[link] [comments]

2. Cyber Threat Intelligence & Forensik

IoC Intelligence (2 Indikatoren)
1019517268a2edb2d89729661539233396b3aa524279377ca8228085957d598bc36b33a5370864decda5b0db97972191
CTI Threat Relationship Graph4 Knoten / 3 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
MITRE ATT&CK Matrix Navigator 14 Taktiken
3 belegte TechnikenLive-Mapping
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag