Recently got infected with a really bad malware info stealer. Been combing back looking for the source. I think I may have found it.
PM if you want more info than provided here.
Sanitized Threat Intelligence & IOC Brief: Repackaged Fileless .NET Backdoor
1. File Indicators (Cryptographic Hashes)
Variant A (ZIP Archive Stage)
- File Type: ZIP archive data, deflate compression
- MD5:
c36b33a5370864decda5b0db97972191 - SHA256:
1019517268a2edb2d89729661539233396b3aa524279377ca8228085957d598b
Variant B (RAR Archive Stage)
- File Type: RAR archive data, v4, os: Win32
- MD5:
488cc1a8f44af73bc7f7baa1fafd8fdr - SHA256:
de5d21396908ab452059a3361f76dcb489fb705e44ac55983624a7e5d7bca1d
2. Network Indicators of Compromise (IoCs)
- Inbound Bind Shell / P2P Node: Starts a local server listening for inbound connections on
0.0.0.0:47584from dynamically allocated (unbacked) memory. - Outbound C2: Initiates HTTP network connections directly from unbacked memory to evade process-based attribution.
- Dead Connect: Attempts to connect to a dead IP/Port.
3. File System Artifacts & DLL Hijacking Paths
The payload drops a custom directory structure into the user's temporary folder and performs DLL Side-Loading by dropping files masquerading as legitimate Windows .NET libraries.
Observed Staging Directory Patterns:
%TEMP%\<Staging_Directory>\Managed\%TEMP%\<Staging_Directory>\<Staging_Directory>\Managed\
Abused / Masquerading DLL Names Dropped in %TEMP%**:**
System.Numerics.dllSystem.Runtime.dllSystem.Runtime.Serialization.dllSystem.Security.dllSystem.Core.dllSystem.Data.dllSystem.Data.DataSetExtensions.dllSystem.Drawing.dllSystem.dll
Targeted Windows System Binaries:
C:\Windows\SysWOW64\rundll32.exe
4. Behavioral Signatures & TTPs (MITRE ATT&CK)
- T1574 - Hijack Execution Flow (DLL Side-Loading): Loads newly dropped .NET DLLs from a suspicious temporary directory.
- T1055 - Process Injection & Module Stomping: Executes loops of failed Read-Write-Execute (RWX) memory allocations returning
CONFLICTING_ADDRESSESin high ranges, indicative of code cave hunting or module stomping. - T1497 - Virtualization/Sandbox Evasion:
- Checks for mouse movement.
- Queries display device information.
- Checks available system memory.
- Defense Evasion (Fileless Memory Tradecraft):
- Modifies exception handling mechanisms (UEF / VEH) from dynamically allocated (unbacked) memory for silent anti-debugging.
- Alters process mitigation policies (CFG / DEP / hard error modes) directly from unbacked memory.
- Manually resolves API addresses from unbacked memory (custom unpacker/shellcode behavior).
- T1082 - Discovery: Queries the system's FIPS cryptography policy to adapt payload encryption
[link] [comments]