<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>malware - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/tag/malware-en/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/tag/malware-en/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Fri, 13 Jan 2023 10:58:29 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>malware - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/tag/malware-en/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>CDT Watch – December 2022</title>
		<link>https://www.riskinsight-wavestone.com/en/2023/01/cdt-watch-december-2022/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2023/01/cdt-watch-december-2022/#respond</comments>
		
		<dc:creator><![CDATA[CERT-W]]></dc:creator>
		<pubDate>Mon, 02 Jan 2023 10:48:00 +0000</pubDate>
				<category><![CDATA[CERT Newsletter]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[BYOVKD]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[CVE]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[EDR]]></category>
		<category><![CDATA[emotet]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Redis]]></category>
		<category><![CDATA[watch]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=19444</guid>

					<description><![CDATA[<p>FOCUS TECH BRING YOUR OWN VULNERABLE KERNEL DRIVER (BYOVKD) Facing the EDR behavioral supervision, attacker develops techniques for successful attacks by staying under the radars. One of these techniques is called BYOVKD: Bring Your Own Vulnerable Kernel Driver. Even if...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/01/cdt-watch-december-2022/">CDT Watch – December 2022</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 style="text-align: center;">FOCUS TECH</h2>
<h3 style="text-align: center;">BRING YOUR OWN VULNERABLE KERNEL DRIVER (BYOVKD)</h3>
<p style="text-align: justify;">Facing the EDR behavioral supervision, attacker develops techniques for successful attacks by staying under the radars. One of these techniques is called BYOVKD: Bring Your Own Vulnerable Kernel Driver.</p>
<p><img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-19447" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Picture-1.png" alt="" width="1625" height="1091" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Picture-1.png 1625w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Picture-1-284x191.png 284w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Picture-1-58x39.png 58w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Picture-1-768x516.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Picture-1-1536x1031.png 1536w" sizes="(max-width: 1625px) 100vw, 1625px" /></p>
<p style="text-align: justify;">Even if it does not raise an alert on the EDR console, the Defense team must <strong>be vigilant</strong> to any telemetry that would indicate the <strong>loading of an unusual driver on assets</strong>. Furthermore, <strong>prevention mechanisms</strong> exist for this type of case, some examples below:</p>
<ul>
<li style="text-align: justify;"><a href="https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide#block-abuse-of-exploited-vulnerable-signed-drivers">Block abuse of exploited vulnerable signed drivers</a></li>
<li style="text-align: justify;"><a style="font-size: revert;" href="https://learn.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-driver-block-rules">Driver block rules</a></li>
</ul>
<h2> </h2>
<h2 style="text-align: center;"><strong>CERT-W: FROM THE FRONT LINE</strong></h2>
<h3 style="text-align: center;">THE FIRST RESPONDER WORD</h3>
<p><img decoding="async" class="aligncenter size-full wp-image-19449" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Picture-2.png" alt="" width="770" height="414" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Picture-2.png 770w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Picture-2-355x191.png 355w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Picture-2-71x39.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Picture-2-768x413.png 768w" sizes="(max-width: 770px) 100vw, 770px" /></p>
<p> </p>
<p> </p>
<h2 style="text-align: center;"><strong>READING OF THE MONTH</strong></h2>
<h3 style="text-align: center;">EMOTET</h3>
<p><strong>What is Emotet 2022?</strong></p>
<p style="text-align: justify;"><strong>Emotet is a <em>Malware-as-a-Service</em></strong> (<em>MaaS</em>) relying on a botnet network which appeared in 2014. It was originally designed as a banking Trojan aiming to steal sensitive information related to bank accounts<em>.</em> In 2021, police forces arrested several people belonging to Emotet organization, which then <strong>reappeared with new features in 2022</strong>. The group behind Emotet seems to be <strong>opportunist</strong> and most of its victims are from US, UK, Japan, Germany, Italy, Spain, <strong>France</strong>, and Brazil.</p>
<p><strong>Why is it dangerous?</strong></p>
<p style="text-align: justify;">Emotet is a polymorphic malware whose code changes over time. Among the numerous new features of the 2022 version, searchers from the <a href="https://thedfirreport.com/2022/09/12/dead-or-alive-an-emotet-story/">DFIR Report</a> have identified an ability to <strong>bypass anti-malware detection</strong>. To do that, Emotet 2022 uses a 64 bits base code and various signatures to avoid pattern recognition. The malware is also able <strong>to keep itself up to date</strong> once downloaded by using <strong>Command &amp; Control servers</strong>, which send it updates the same as an Operating System. The <em>MaaS</em> is also <strong>able to release IcedID</strong>, which are modular banking Trojans able <strong>to drop other malwares</strong>. Doing so, Emotet helped to distribute ransomwares for impact, Cobalt Strike for initial access, XMRig for stealing wallet data…</p>
<p><strong>How does Emotet 2022 initial infection work?</strong></p>
<p style="text-align: justify;">Using a <strong>phishing email with a malicious Office attachment</strong>, Emotet exploits a 2017 <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-11882">Microsoft vulnerability</a> which allows remote code execution on vulnerable devices (CVE 2017-11882) to compromise its first victim.</p>
<p style="text-align: justify;">Once downloaded in memory, the malware executes a sequence of legitimate Windows commands to <strong>perform a recognition of its environment,</strong> then spreads in the local network and steals information.</p>
<p style="text-align: justify;">Emotet spreads through spam emails. According to <a href="https://www.deepinstinct.com/blog/emotet-malware-returns-in-2022"><em>Deep Instinct</em></a>, 45% of them are containing malicious Office attachment such as Spreadsheets or scripts in most of the cases. As those emails traduce the object and attachments names in the target’s local language and come from known senders, the phishing looks particularly realistic.<img decoding="async" class="aligncenter size-full wp-image-19451" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Picture-3.png" alt="" width="1111" height="528" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Picture-3.png 1111w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Picture-3-402x191.png 402w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Picture-3-71x34.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2023/01/Picture-3-768x365.png 768w" sizes="(max-width: 1111px) 100vw, 1111px" /></p>
<p style="text-align: center;"><a href="https://www.proofpoint.com/us/blog/threat-insight/comprehensive-look-emotets-fall-2022-return">Comprehensive look of EMOTET fall 2022</a></p>
<p style="text-align: left;"><strong>Why is this new version of the MaaS particularly tricky?</strong></p>
<p style="text-align: justify;">Emotet 2022 can identify whether it’s downloaded into a sandbox environment, or a device connected to a network. In the first configuration it won’t activate itself, but in the second it will rely <strong>on a password dictionary to spread</strong> thanks to brute-force.  Moreover, the November 2022 Excel files generally enclosed <strong>contains macros which no longer needs a user click to be authorized</strong>. The victim is only asked two things: <strong>copying the files into the Microsoft Office Template zone, which requires administrator privileges</strong>. Opening the file in this location will execute the macros without any warnings.</p>
<p style="text-align: justify;"><strong>How to protect from Emotet 2022?</strong></p>
<p>Since Emotet 2022 uses malicious spam and phishing is the most used technique for initial access, we highly advice you to consider these measures:</p>
<ul>
<li style="text-align: justify;">Provide your company a <strong>solution against phishing</strong>.</li>
<li style="text-align: justify;">Launch an <strong>awareness campaign</strong> for employees and stakeholders.</li>
<li style="text-align: justify;">Provide you company an <strong>Endpoint Detection and Response</strong> which complete the anti-virus by performing <strong>behavioural analysis</strong>, which helps visualize the virus kill chain to identify the action levers.</li>
</ul>
<p style="text-align: justify;">Give a local administrator account to an employee only in case of specific need.</p>
<p> </p>
<h2 style="text-align: center;">VULNERABILITY OF THE MONTH</h2>
<h3 style="text-align: center;">DEBIAN-SPECIFIC REDIS SERVER LUA SANDBOX ESCAPE VULNERABILITY &#8211; <a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0543"><strong>CVE-2022-0543</strong></a></h3>
<p style="text-align: center;">Published by NVD: 18/02/2022</p>
<p style="text-align: center;"><strong>Products: </strong>Redis server for Debian and Debian-derived Linux distributions</p>
<p style="text-align: center;"><strong>Versions: </strong>less and equal to 5:5.0.14-1+deb10u2, 5:6.0.16-1+deb11u2, 5:7.0.5-1, 5:7.0.7-1</p>
<p style="text-align: center;"><strong>Score: </strong><strong>10 CRITICAL</strong></p>
<p style="text-align: center;"><a href="https://blog.aquasec.com/redigo-redis-backdoor-malware"><strong>Context</strong></a><strong>  </strong><a href="https://packetstormsecurity.com/files/166885/Redis-Lua-Sandbox-Escape.html"><strong>PoC</strong></a></p>
<p style="text-align: justify;"><a href="https://redis.io/">Redis</a> is an opensource NoSQL database management system. Redis includes an <strong>embedded Lua scripting engine</strong>, it allows client to run scripts. By design, the Lua engine must be <strong>sandboxed</strong>: it means that packages and APIs available are limited in an execution context. Redis clients <strong>are not allowed to execute arbitrary code</strong> on the Redis server.</p>
<p style="text-align: justify;">In some <strong>Debian and Debian-derived Linux packages</strong>, the Lua environment is <strong>not sufficiently regulated </strong>because the Lua Library is provided as a dynamic library. It can allow attackers to access arbitrary Lua functionalities and results in a Lua Sandbox escape.</p>
<p style="text-align: justify;">Early December, reports indicate that attackers are exploiting this vulnerability <strong>to deploy a new backdoor malware dubbed Redigo</strong> on Redis Server. The malware communicates with a server of command and control using <strong>port 6379 </strong>which is a legitimate port used by Redis for communication between client and server: the Redis server joins a botnet network.</p>
<p style="text-align: justify;">According to <a href="https://blog.aquasec.com/redigo-redis-backdoor-malware"><em>Aqua</em></a>, the malware has some functions specially written to the Redis server which may imply that the group behind this desired <strong>to build an adjusted attack that would target Redis servers</strong>.</p>
<p style="text-align: justify;"><strong>A successful attack implies that attacker could execute arbitrary commands and access to sensitive information.</strong></p>
<p style="text-align: justify;">A group of attackers is behind the Redigo malware which is an emerging threat. Furthermore, the <strong>exploit of the CVE-2022-0543 is public</strong> and is <strong>used in the wild</strong> to deploy the malware. <strong>Vulnerable Redis Server must be patched and up to date</strong>.</p>
<p> </p>
<p style="text-align: center;">SEE YOU NEXT MONTH!!</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/01/cdt-watch-december-2022/">CDT Watch – December 2022</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2023/01/cdt-watch-december-2022/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>CDT Watch – June 2022</title>
		<link>https://www.riskinsight-wavestone.com/en/2022/06/cdt-watch-june-2022/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2022/06/cdt-watch-june-2022/#respond</comments>
		
		<dc:creator><![CDATA[CERT-W]]></dc:creator>
		<pubDate>Thu, 30 Jun 2022 08:50:19 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Newsletter CERT]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[tech]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=18163</guid>

					<description><![CDATA[<p>FOCUS TECH Bumblebee     Initial Access (TA0001) Execution (TA0002) Persistence (TA0003) Privilege Escalation (TA0004) Phishing: Spearphishing Attachment T1566.001 Command and Scripting Interpreter: Visual Basic T1059.005 Scheduled Task/Job T1053 Process Injection: Dynamic-link Library Injection T1055.001 Phishing: Spearphishing Link T1566.002 Windows Management Instrumentation...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2022/06/cdt-watch-june-2022/">CDT Watch – June 2022</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h1 style="text-align: center;"><strong>FOCUS TECH</strong></h1>
<h2 style="text-align: center;">Bumblebee</h2>
<p><img loading="lazy" decoding="async" class=" wp-image-18167 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/slide-3-262x191.png" alt="" width="797" height="581" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/slide-3-262x191.png 262w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/slide-3-53x39.png 53w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/slide-3-768x561.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/slide-3.png 1364w" sizes="auto, (max-width: 797px) 100vw, 797px" /></p>
<p> </p>
<p><img loading="lazy" decoding="async" class="alignnone  wp-image-18171" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/SLIDE-2-272x191.jpg" alt="" width="891" height="626" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/SLIDE-2-272x191.jpg 272w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/SLIDE-2-56x39.jpg 56w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/SLIDE-2-768x539.jpg 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/SLIDE-2.jpg 1369w" sizes="auto, (max-width: 891px) 100vw, 891px" /></p>
<p> </p>
<table width="622">
<tbody>
<tr>
<td width="156">
<h5><strong><u>Initial Access</u></strong></h5>
<h5><strong><u>(TA0001)</u></strong></h5>
</td>
<td width="156">
<h5><strong><u>Execution</u></strong></h5>
<h5><strong><u>(TA0002)</u></strong></h5>
</td>
<td width="156">
<h5><strong><u>Persistence</u></strong></h5>
<h5><strong><u>(TA0003)</u></strong></h5>
</td>
<td width="156">
<h5><strong><u>Privilege Escalation</u></strong></h5>
<h5><strong><u>(TA0004)</u></strong></h5>
</td>
</tr>
<tr>
<td width="156">
<p><strong>Phishing</strong>:</p>
<p>Spearphishing Attachment</p>
<p><a href="https://attack.mitre.org/techniques/T1566/001/">T1566.001</a></p>
</td>
<td width="156">
<p><strong>Command and Scripting Interpreter:</strong> Visual Basic</p>
<p><a href="https://attack.mitre.org/techniques/T1059/005/">T1059.005</a></p>
</td>
<td width="156">
<p>Scheduled Task/Job</p>
<p><a href="https://attack.mitre.org/techniques/T1053/">T1053</a></p>
</td>
<td width="156">
<p><strong>Process Injection:</strong> Dynamic-link Library Injection</p>
<p><a href="https://attack.mitre.org/techniques/T1055/001/">T1055.001</a></p>
</td>
</tr>
<tr>
<td width="156">
<p><strong>Phishing:</strong> Spearphishing Link</p>
<p><a href="https://attack.mitre.org/techniques/T1566/002/">T1566.002</a></p>
</td>
<td width="156">
<p>Windows Management Instrumentation</p>
<p><a href="https://attack.mitre.org/techniques/T1047/">T1047</a></p>
</td>
<td width="156">
<p> </p>
</td>
<td width="156">
<p><strong>Process Injection: </strong>Asynchronous Procedure Call</p>
<p><a href="https://attack.mitre.org/techniques/T1055/004/">T1055.004</a></p>
</td>
</tr>
</tbody>
</table>
<h1> </h1>
<table style="width: 100%; height: 907px;">
<tbody>
<tr style="height: 108px;">
<td style="height: 108px;" width="155">
<h5><strong><u>Defense Evasion</u></strong></h5>
<h5><strong>(TA0005)</strong></h5>
</td>
<td style="height: 108px;" width="155">
<h5><strong><u>Discovery</u></strong></h5>
<h5><strong>(TA0007)</strong></h5>
</td>
<td style="height: 108px;" width="155">
<h5><strong><u>Command and Control</u></strong></h5>
<h5><strong>(TA0011)</strong></h5>
</td>
</tr>
<tr style="height: 138px;">
<td style="height: 138px;" width="155">
<p><strong>Process Injection:</strong> Dynamic-link Library Injection</p>
<p><a href="https://attack.mitre.org/techniques/T1055/001/">T1055.001</a></p>
</td>
<td style="height: 138px;" width="155">
<p>System Information Discovery</p>
<p><a href="https://attack.mitre.org/techniques/T1082/">T1082</a></p>
</td>
<td style="height: 138px;" width="155">
<p><strong>Encrypted Channel: </strong>Symmetric Cryptography</p>
<p><a href="https://attack.mitre.org/techniques/T1573/001/">T1573.002</a></p>
</td>
</tr>
<tr style="height: 138px;">
<td style="height: 138px;" width="155">
<p><strong>Process Injection</strong>: Asynchronous Procedure Call</p>
<p><a href="https://attack.mitre.org/techniques/T1055/004/">T1055.004</a></p>
</td>
<td style="height: 138px;" width="155">
<p>Process Discovery</p>
<p><a href="https://attack.mitre.org/techniques/T1057/">T1057</a></p>
</td>
<td style="height: 138px;" width="155">
<p>Ingress Tool Transfer</p>
<p><a href="https://attack.mitre.org/techniques/T1105/">T1105</a></p>
</td>
</tr>
<tr style="height: 138px;">
<td style="height: 138px;" width="155">
<p><strong>Hide Artifacts:</strong> Hidden Files and Directories</p>
<p><a href="https://attack.mitre.org/techniques/T1564/001/">T1564.001</a></p>
</td>
<td style="height: 138px;" width="155">
<p> </p>
</td>
<td style="height: 138px;" width="155">
<p> </p>
</td>
</tr>
<tr style="height: 138px;">
<td style="height: 138px;" width="155">
<p><strong>Indicator Removal on Host</strong>: File Deletion</p>
<p><a href="https://attack.mitre.org/techniques/T1070/004/">T1070.004</a></p>
</td>
<td style="height: 138px;" width="155">
<p> </p>
</td>
<td style="height: 138px;" width="155">
<p> </p>
</td>
</tr>
<tr style="height: 109px;">
<td style="height: 109px;" width="155">
<p>Virtualization/Sandbox Evasion</p>
<p><a href="https://attack.mitre.org/techniques/T1497/">T1497</a></p>
</td>
<td style="height: 109px;" width="155">
<p> </p>
</td>
<td style="height: 109px;" width="155">
<p> </p>
</td>
</tr>
<tr style="height: 138px;">
<td style="height: 138px;" width="155">
<p>Deobfuscate/Decode Files or Information</p>
<p><a href="https://attack.mitre.org/techniques/T1140/">T1140</a></p>
</td>
<td style="height: 138px;" width="155">
<p> </p>
</td>
<td style="height: 138px;" width="155">
<p> </p>
</td>
</tr>
</tbody>
</table>
<h3 style="text-align: center;">SOURCES :</h3>
<p><a href="https://www.proofpoint.com/us/blog/threat-insight/bumblebee-is-still-transforming"><img loading="lazy" decoding="async" class="size-medium wp-image-18176 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/proofpoint-437x181.jpg" alt="" width="437" height="181" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/proofpoint-437x181.jpg 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/proofpoint-71x29.jpg 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/proofpoint.jpg 637w" sizes="auto, (max-width: 437px) 100vw, 437px" /></a></p>
<h6 style="text-align: center;"><a href="https://www.proofpoint.com/us/blog/threat-insight/bumblebee-is-still-transforming"><strong>Bumblebee is still transforming, Proofpoint</strong></a></h6>
<p style="text-align: center;">[1] <a href="https://www.malware-traffic-analysis.net/2022/index.html">https://www.malware-traffic-analysis.net/2022/index.html</a></p>
<p style="text-align: center;">[2]<a href="https://isc.sans.edu/forums/diary/How+the+Contact+Forms+campaign+tricks+people/28142/">https://isc.sans.edu/forums/diary/How+the+Contact+Forms+campaign+tricks+people/28142/</a></p>
<h1> </h1>
<h1 style="text-align: center;"><strong>CERT-W: FROM THE FRONT LINE</strong></h1>
<h2 style="text-align: center;">The First Responder Word</h2>
<p><img loading="lazy" decoding="async" class="alignnone  wp-image-18173" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/first-reponder-383x191.png" alt="" width="906" height="452" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/first-reponder-383x191.png 383w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/first-reponder-71x35.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/first-reponder-768x383.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/first-reponder-800x400.png 800w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/first-reponder.png 1485w" sizes="auto, (max-width: 906px) 100vw, 906px" /></p>
<p> </p>
<h1 style="text-align: center;"><strong>Reading Of The Month</strong></h1>
<p style="text-align: center;">We recommend the article of Robert Lemos, a darkreading contributing writer about firms which suffers identity-related breaches.</p>
<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-18178 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/firms.jpg" alt="" width="411" height="173" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/firms.jpg 411w, https://www.riskinsight-wavestone.com/wp-content/uploads/2022/06/firms-71x30.jpg 71w" sizes="auto, (max-width: 411px) 100vw, 411px" /></p>
<h6 style="text-align: center;"><a href="https://www.darkreading.com/operations/identity-related-breaches-last-12-months"><strong>80% of firms suffered identity-related breaches in last 12 months, Robert Lemos</strong></a></h6>
<p> </p>
<p style="text-align: center;">SEE YOU NEXT MONTH!!</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2022/06/cdt-watch-june-2022/">CDT Watch – June 2022</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2022/06/cdt-watch-june-2022/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>CDT Watch &#8211; November 2021</title>
		<link>https://www.riskinsight-wavestone.com/en/2021/11/cdt-watch-november-2021/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2021/11/cdt-watch-november-2021/#respond</comments>
		
		<dc:creator><![CDATA[CERT-W]]></dc:creator>
		<pubDate>Tue, 30 Nov 2021 08:50:00 +0000</pubDate>
				<category><![CDATA[CERT Newsletter]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[CDT]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[watch]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=17399</guid>

					<description><![CDATA[<p>FOCUS TECH File Obfuscation Discover Cobalt Strike capabilities with the technical zoom of the month: To learn more about the given malwares: Cobalt Strike Training videos CERT-W: FROM THE FRONT LINE The First Responder Word We recommend the 2021 Benchmark...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/11/cdt-watch-november-2021/">CDT Watch &#8211; November 2021</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h1 style="text-align: center;"><strong>FOCUS TECH</strong></h1>
<h2 style="text-align: center;">File Obfuscation</h2>
<p style="text-align: center;">Discover Cobalt Strike capabilities with the technical zoom of the month:</p>
<figure id="post-16383 media-16383" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-17400" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-1.png" alt="" width="771" height="456" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-1.png 771w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-1-323x191.png 323w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-1-66x39.png 66w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-1-120x70.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-1-768x454.png 768w" sizes="auto, (max-width: 771px) 100vw, 771px" /> <img loading="lazy" decoding="async" class="aligncenter size-full wp-image-17402" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-2.png" alt="" width="770" height="442" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-2.png 770w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-2-333x191.png 333w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-2-68x39.png 68w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-2-120x70.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-2-768x441.png 768w" sizes="auto, (max-width: 770px) 100vw, 770px" /> <img loading="lazy" decoding="async" class="aligncenter size-full wp-image-17404" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-3.png" alt="" width="772" height="442" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-3.png 772w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-3-334x191.png 334w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-3-68x39.png 68w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-3-120x70.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-3-768x440.png 768w" sizes="auto, (max-width: 772px) 100vw, 772px" /> <img loading="lazy" decoding="async" class="aligncenter size-full wp-image-17406" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-4.jpg" alt="" width="776" height="451" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-4.jpg 776w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-4-329x191.jpg 329w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-4-67x39.jpg 67w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-4-120x70.jpg 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-4-768x446.jpg 768w" sizes="auto, (max-width: 776px) 100vw, 776px" /> <img loading="lazy" decoding="async" class="aligncenter size-full wp-image-17408" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-5.jpg" alt="" width="777" height="458" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-5.jpg 777w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-5-324x191.jpg 324w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-5-66x39.jpg 66w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-5-120x70.jpg 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-5-768x453.jpg 768w" sizes="auto, (max-width: 777px) 100vw, 777px" /> <img loading="lazy" decoding="async" class="aligncenter size-full wp-image-17410" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-6.png" alt="" width="781" height="447" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-6.png 781w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-6-334x191.png 334w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-6-68x39.png 68w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-6-120x70.png 120w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-6-768x440.png 768w" sizes="auto, (max-width: 781px) 100vw, 781px" /></figure>
<figure id="post-16383 media-16383" class="align-center"></figure>
<p style="text-align: center;"><strong>To learn more about the given malwares:</strong></p>
<figure id="post-16217 media-16217" class="align-center">
<figure id="post-16385 media-16385" class="align-center"><img loading="lazy" decoding="async" class="aligncenter  wp-image-17412" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/learn-more.png" alt="" width="289" height="158" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/learn-more.png 223w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/learn-more-71x39.png 71w" sizes="auto, (max-width: 289px) 100vw, 289px" /></figure>
<p style="text-align: center;"><a href="https://www.cobaltstrike.com/training">Cobalt Strike Training videos</a></p>
</figure>
<figure id="post-16210 media-16210" class="align-center">
<figure id="post-16367 media-16367" class="align-center"></figure>
</figure>
<h1 style="text-align: center;"><strong>CERT-W: FROM THE FRONT LINE</strong></h1>
<h2 style="text-align: center;">The First Responder Word</h2>
<figure id="post-16221 media-16221" class="align-center">
<figure id="post-16228 media-16228" class="align-center">
<figure id="post-16369 media-16369" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-17420" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-10.jpg" alt="" width="781" height="523" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-10.jpg 781w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-10-285x191.jpg 285w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-10-58x39.jpg 58w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-10-768x514.jpg 768w" sizes="auto, (max-width: 781px) 100vw, 781px" /></figure>
<p style="text-align: center;">We recommend the <em>2021 Benchmark on cybersecurity incidents</em> which reviews the interventions of the CERT-W carried out between September 2020 and October 2021. This Benchmark provides keys to understanding the security issues and a snapshot of current cybersecurity threats in France.</p>
</figure>
</figure>
<p><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-17416" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-8.png" alt="" width="222" height="122" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-8.png 222w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-8-71x39.png 71w" sizes="auto, (max-width: 222px) 100vw, 222px" /></p>
<p style="text-align: center;"><u><a href="https://uk.wavestone.com/en/insight/cyberattacks-in-2021-ransomwares-still-threat-n1/">CERT-W’s 2021 Benchmark on cybersecurity incidents </a></u></p>
<p> </p>
<h1 style="text-align: center;"><strong>Reading Of The Month</strong></h1>
<p style="text-align: center;">To learn more about Conti, one of the most dangerous Ransomware, we recommend reading the <em>Conti Ransomware Group In-Depth Analysis </em>of Prodaft. According to Prodaft, this report will show you how the gang works with details obtained by their team who accessed Conti’s infrastructure.</p>
<figure id="post-16219 media-16219" class="align-center">
<figure id="post-16387 media-16387" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-17418" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-9.png" alt="" width="222" height="122" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-9.png 222w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/12/image-9-71x39.png 71w" sizes="auto, (max-width: 222px) 100vw, 222px" /></figure>
<p style="text-align: center;"><a href="https://www.prodaft.com/m/reports/Conti_TLPWHITE_v1.6_WVcSEtc.pdf">Conti Ransomware Group In-Depth Analysis by Prodaft</a></p>
</figure>
<p> </p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/11/cdt-watch-november-2021/">CDT Watch &#8211; November 2021</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2021/11/cdt-watch-november-2021/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Newsletter CERT-W, from the front line &#8211; Summer 2021</title>
		<link>https://www.riskinsight-wavestone.com/en/2021/09/newsletter-cert-w-from-the-front-line-summer-2021/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2021/09/newsletter-cert-w-from-the-front-line-summer-2021/#respond</comments>
		
		<dc:creator><![CDATA[CERT-W]]></dc:creator>
		<pubDate>Mon, 13 Sep 2021 15:14:39 +0000</pubDate>
				<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[Newsletter CERT]]></category>
		<category><![CDATA[CERT]]></category>
		<category><![CDATA[indicators]]></category>
		<category><![CDATA[malware]]></category>
		<guid isPermaLink="false">http://riskinsight-prepro.s189758.zephyr32.atester.fr/?p=16743</guid>

					<description><![CDATA[<p>DECRYPTION The underground economy of the ransomware In recent years the products of the underground economy have evolved quickly. Cyber criminals now offer services for others to purchase, the most popular being: Ransomware-as-a-service (RaaS). Let’s pretend you are a hacker...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/09/newsletter-cert-w-from-the-front-line-summer-2021/">Newsletter CERT-W, from the front line &#8211; Summer 2021</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<figure id="post-16207 media-16207" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16207" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH.png" alt="" width="1621" height="455" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH.png 1621w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH-437x123.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH-71x20.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH-768x216.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH-1536x431.png 1536w" sizes="auto, (max-width: 1621px) 100vw, 1621px" /></figure>
<h1 style="text-align: center;"><strong>DECRYPTION</strong></h1>
<h2 style="text-align: center;">The underground economy of the ransomware</h2>
<p>In recent years the products of the underground economy have evolved quickly. Cyber criminals now offer services for others to purchase, the most popular being: <strong>Ransomware-as-a-service (RaaS).</strong></p>
<p><strong>Let’s pretend you are a hacker</strong> aiming to launch a successful ransomware attack. Only, you are quite new to the business. What do you think you need? A very sophisticated level of coding and development skills? Not anymore. The whole underground economy of RaaS can provide you with every necessary element to conduct your attack, from the access credentials to the mixers helping you to launder your gains.</p>
<p><strong>What do I need for my ransomware attack? </strong></p>
<p><strong>Need #1</strong>&nbsp;<strong>– </strong><strong>Enter my target’s network.</strong> In order to do so, you need to acquire access to the victim’s network: your first providers are the&nbsp;<strong>initial access brokers (IABs)</strong>&nbsp;or&nbsp;<strong>botmasters.</strong></p>
<p>They are specialized in vulnerability exploit. They identify the flaws through massive phishing campaigns and/or scans and then <strong>access the system. </strong>Once inside, <strong>they set up remote persistent access&nbsp;</strong>to the target’s network. <a href="https://ke-la.com/all-access-pass-five-trends-with-initial-access-brokers/">The botmasters then sell you the access: depending on its level of quality, prices can range from $1K to $100K (seen for a Mexican government body). The average price for network access in 2020 was $5,400.</a> The botmaster’s services also include information on the financial health of the targeted victim, to help the attacker set the highest realistic price for the ransom</p>
<p><strong>Need #2</strong>&nbsp;–&nbsp;<strong>Anonymous</strong> <strong>infrastructure to host my hacking tools and store my data</strong><strong>. </strong>The second actor of the chain is the&nbsp;<strong>bulletproof hoster</strong>, <a href="https://www.recordedfuture.com/bulletproof-hosting-services/">providing you with infrastructure-as-a-service, including anonymization services. The subscription can go from $5 per month to any price.</a></p>
<p><strong>Need #3 – A ransomware to encrypt my victim’s files! </strong></p>
<p>Now the main part: where can you find a ransomware? The most popular way is to subscribe to a&nbsp;<strong>RaaS platforms</strong>, offering 4 main services:</p>
<ul>
<li><strong>Provide necessary information</strong>: potential victims, their financial status, security level…</li>
<li>The&nbsp;<strong>ransomware: </strong>the malicious code&nbsp;and a tool kit to facilitate the attack</li>
<li><strong>Negotiation service</strong>&nbsp;(including support to collect the ransom)</li>
<li><strong>Money laundering service</strong></li>
</ul>
<p>Other services are offered, according to what you are ready to pay. <a href="https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2021/05/11121219/Ransomware_world_in_2021_08.png">Here</a> is an example of different price subscriptions and services on a RaaS platform. <a href="https://cybersecurityventures.com/whos-buying-and-selling-ransomware-kits-on-the-dark-web/">It can go from $100 to $84,000 (Maze).</a></p>
<p><strong>Where is the money going? </strong></p>
<p><strong>Need #4 – Clean my money! </strong>Once the attack is successful, the people in charge of <strong>the money laundering</strong> and<strong> money mules </strong>take the stage.</p>
<p><a href="https://media.threatpost.com/wp-content/uploads/sites/103/2021/04/19080601/0354039421fd7c82eb4e1b4a7c90f98e.pdf">After a payment to the perpetrator’s wallet is made, money is then dispersed and mixed across numerous wallets, to provide anonymity.</a> This <strong>bitcoin mixing</strong> through multiple other wallets makes the payment tracing quite difficult. In the Colonial Pipeline case, <a href="https://www.coindesk.com/colonial-pipeline-paid-almost-5m-crypto-ransom-soon-after-attack-report">the wallet received the 75 BTC from them, mixed with 57 payments from 21 different wallets.</a> However, this case has proven that <strong>the tracing is not insurmountable.</strong> No matter how many times the bitcoins are moved, ultimately it has to go through cryptocurrency trading platforms (such as BTC-E) and be cashed out at exchange points.</p>
<p><a href="https://www.elliptic.co/blog/buried-treasure-criminals-to-go-to-extreme-lengths-to-cash-out-crypto">Recently, the situation involves global anti-money laundering (AML) regulators armed with blockchain sleuthing tools to trace and screen transactions, making the cash-out process harder to go unnoticed</a>. To face this upgrade, cybercriminals can use a system described as “<strong>The Treasure Man”</strong>. You can find and hire them on darknet marketplaces (such as Hydra). They will <strong>cash-out your gains and hide them – physically &#8211; </strong>for you to pick up. <a href="https://www.ft.com/content/4169ea4b-d6d7-4a2e-bc91-480550c2f539">“<em>They bury it underground or hide it behind a bush, and they will tell you the coordinates. There is a whole profession</em>” (Elliptic)&nbsp;</a></p>
<p><strong>Who are the people behind the RaaS platforms? </strong></p>
<p>RaaS platforms are based on&nbsp;<strong>very organized and structured groups</strong>&nbsp;such as SMEs. REvil (one of the biggest RaaS) indicated having <u>a </u><u><a href="https://www.cyjax.com/2021/07/09/revilevolution/">team of 10 developers and systems admins</a></u>, besides their project managers. To recruit the best experts, <strong>the platform&#8217;s leaders choose their employees after a challenging recruitment process. </strong>The candidates prove themselves through job interviews, hacking exercises and agree to an “ethical charter”. <a href="https://cybernews.com/security/how-we-applied-to-work-with-ransomware-gang/">You can read here the undercover investigation of journalists who followed the process to be hired as hackers by a RaaS.</a></p>
<p>The <strong>subscribers</strong> or <strong>affiliates</strong> of a RaaS platform (in this story, that’s you) are “only” in charge of the intrusion, the data collect and the ransomware deployment on the victim network. The affiliates usually pocket <strong><u>between</u></strong><u>&nbsp;</u><u><a href="https://media.threatpost.com/wp-content/uploads/sites/103/2021/04/19080601/0354039421fd7c82eb4e1b4a7c90f98e.pdf"><strong>60</strong> <strong>and 80 % of the ransom</strong>, with the rest going into the operators’ coffers.</a></u> The RaaS platform of&nbsp;Netwalker requires 20% of the ransom, but other groups can ask 70%. <u>REvil recently announced being&nbsp;</u><u><a href="https://www.youtube.com/watch?v=ZyQCQ1VZp8s&amp;ab_channel=RussianOSINT">paid at least 100,000,000$ per year.</a></u><u>&nbsp;</u></p>
<p><strong>No honor among thieves?</strong></p>
<p>If the RaaS market is a very well-organized business model, it still is the underground economy we are talking about.&nbsp;It’s not because you are a potential RaaS client, that you are in a safe place.</p>
<p>The two&nbsp;<a href="https://www.sciencedirect.com/science/article/pii/S0167404820300468">years of research on the darknet of Håkon Melanda</a>&nbsp;have shown that&nbsp;<strong>most of the RaaS items sold on the darknet markets are frauds</strong>, where the buyers either get rubbish or ransomware that redirects the whole payment somewhere else than the buyer’s wallet. If the authentic RaaS vendors are indeed taking the lion’s share in terms of gains,&nbsp;the others are not doing bad either by <strong>targeting naive cybercriminals.&nbsp;</strong></p>
<p>If the RaaS distribution process significantly facilitated the ransomware attack for more people, it does not mean it is accessible to every internet user. Not only employees of a RaaS platform need to have a strong resume to be hired, but&nbsp;the <strong>affiliates too have to prove their skills before being allowed to subscribe</strong> to a RaaS service.&nbsp;<a href="https://media.threatpost.com/wp-content/uploads/sites/103/2021/04/19080601/0354039421fd7c82eb4e1b4a7c90f98e.pdf">Well-established RaaS groups such as NetWalker are known to be rather picky and carefully check any new affiliate with interviews and a short trial period</a>. The basic requirement for an affiliate candidate is &#8211; at least &#8211; to demonstrate experience in carrying out network intrusions and lateral movement.</p>
<p><strong>Conclusion: The Circle of money</strong></p>
<p>This very well-organized and profitable economic system yearns for one thing: to be even more profitable, like any business. <strong>To hire better experts, with better tools and launch more sophisticated attacks to collect more money</strong>. How can they develop themselves? <strong>Through the ransom paid by previous attacks</strong>. According to <a href="https://searchsecurity.techtarget.com/news/252503170/DarkSide-ransomware-funded-by-cybercriminal-investors">Ondrej Krehel studies, most of the largest ransomware gangs were launched with seed money from previous operations such as Darkside with Zloader.</a> <a href="https://www.fastcompany.com/90650142/ransomware-venture-capital-ecosystem-lifars">Moreover, as groups sought to diversify with new operations, members adopted a sort of <strong>venture capital</strong> structure</a>, in which one team provides funds to help another build the infrastructure and tools needed to start its operations. <strong>The more ransom that is sent to the system, the more experts will be attracted by this profitable business</strong>, <a href="https://www.lemagit.fr/actualites/252503610/Derriere-les-ransomwares-en-mode-service-Des-investisseurs">the more investors will fund it.</a></p>
<p>Besides, once a ransom is paid, the payer is identified as a “good client” by the market. <a href="https://www.cybereason.com/press/new-cybereason-ransomware-study-reveals-true-cost-to-business">Cybereasons studies indicated that 80% of organizations that paid the ransom after a ransomware attack were hit again.</a> <strong>When a victim pays a ransom, it does not guarantee recovery of their system, but it is for sure the best way to fund a future attack, more sophisticated, against themselves.</strong></p>
<p>&nbsp;</p>
<figure id="post-16210 media-16210" class="align-center">
<figure id="post-16367 media-16367" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16367" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/image1.jpg" alt="" width="940" height="493"></figure>
</figure>
<p>&nbsp;</p>
<p>&nbsp;</p>
<h1 style="text-align: center;"><strong>CERT-W: FROM THE FRONT LINE</strong></h1>
<h2 style="text-align: center;">The CTI Word</h2>
<figure id="post-16221 media-16221" class="align-center">
<figure id="post-16228 media-16228" class="align-center">
<figure id="post-16369 media-16369" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16369" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/image2.jpg" alt="" width="940" height="572"></figure>
</figure>
</figure>
<h1>&nbsp;</h1>
<p>&nbsp;</p>
<h1 style="text-align: center;"><strong>FOCUS TECH</strong></h1>
<h2 style="text-align: center;">File Obfuscation</h2>
<p>&nbsp;</p>
<figure id="post-16215 media-16215" class="align-center">
<figure id="post-16371 media-16371" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16371" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/1.png" alt="" width="889" height="251"></figure>
<figure id="post-16373 media-16373" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16373" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/2.png" alt="" width="918" height="279"></figure>
<figure id="post-16375 media-16375" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16375" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/3.png" alt="" width="922" height="531"></figure>
<figure id="post-16377 media-16377" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16377" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/4.png" alt="" width="922" height="531"></figure>
<figure id="post-16379 media-16379" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16379" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/5.png" alt="" width="917" height="552"></figure>
<figure id="post-16381 media-16381" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16381" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/6.png" alt="" width="915" height="806"></figure>
</figure>
<figure id="post-16383 media-16383" class="align-center"><img loading="lazy" decoding="async" class="aligncenter wp-image-16383" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/7.png" alt="" width="830" height="243"></figure>
<p style="text-align: center;"><strong>To learn more about the given malwares:</strong></p>
<figure id="post-16217 media-16217" class="align-center">
<figure id="post-16385 media-16385" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16385" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/8.jpg" alt="" width="762" height="198"></figure>
</figure>
<p>&nbsp;</p>
<h1 style="text-align: center;"><strong>Reading Of The Month</strong></h1>
<p style="text-align: center;">Instead of a report, we recommend for the reading of the summer the interview of BlackMatter, who has his heart set on explaining how there are taking the best from REvil and DarkSide, their business model and their guidelines of victims’ target.</p>
<figure id="post-16219 media-16219" class="align-center">
<figure id="post-16387 media-16387" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16387" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/09/9.jpg" alt="" width="289" height="196"></figure>
</figure>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/09/newsletter-cert-w-from-the-front-line-summer-2021/">Newsletter CERT-W, from the front line &#8211; Summer 2021</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2021/09/newsletter-cert-w-from-the-front-line-summer-2021/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Newsletter CERT-W, from the front line &#8211; June 2021</title>
		<link>https://www.riskinsight-wavestone.com/en/2021/06/newsletter-cert-w-june-2021/</link>
		
		<dc:creator><![CDATA[CERT-W]]></dc:creator>
		<pubDate>Thu, 24 Jun 2021 13:39:44 +0000</pubDate>
				<category><![CDATA[CERT Newsletter]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[CDT]]></category>
		<category><![CDATA[CERT-W]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[emotet]]></category>
		<category><![CDATA[front line]]></category>
		<category><![CDATA[indicators]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[watch]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=16204</guid>

					<description><![CDATA[<p>DECRYPTION CYBER CRIMINAL NETWORK DISMANTELING The last 6 months, large-scale coordinated international actions have dismantled several of the biggest cybercriminal networks such as Emotet, Netwalker, Egregor or even Cl0p. Let’s have a closer look at some of them. What is&#160;Emotet?...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/06/newsletter-cert-w-june-2021/">Newsletter CERT-W, from the front line &#8211; June 2021</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<figure id="post-16207 media-16207" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16207" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH.png" alt="" width="1621" height="455" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH.png 1621w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH-437x123.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH-71x20.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH-768x216.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/CDT-WATCH-1536x431.png 1536w" sizes="auto, (max-width: 1621px) 100vw, 1621px" /></figure>
<h1 style="text-align: center;"><strong>DECRYPTION</strong></h1>
<h2 style="text-align: center;">CYBER CRIMINAL NETWORK DISMANTELING</h2>
<p><strong>The last 6 months, large-scale coordinated international actions have dismantled several of the biggest cybercriminal networks such as Emotet, Netwalker, Egregor or even Cl0p. Let’s have a closer look at some of them.</strong></p>
<p><strong>What is&nbsp;Emotet?</strong></p>
<p>Emotet&nbsp;was originally a&nbsp;<strong>banking trojan,</strong> stealing emails and contact list, retrieving&nbsp;passwords on navigators and systems, spreading within the infected network.&nbsp;In&nbsp;2019,&nbsp;Emotet&nbsp;lost its banking module and became a&nbsp;<strong>dropper</strong> of malwares. The trojan used&nbsp;a&nbsp;<a href="https://www.justice.gov/opa/pr/emotet-botnet-disrupted-international-cyber-operation"><strong>botnet of 1.6 million machines</strong></a>&nbsp; to realize phishing campaign and install itself on victims’ machines.</p>
<p><strong>Why is&nbsp;Emotet called the “king of malware”?</strong></p>
<p>At the end of 2020,&nbsp;Emotet&nbsp;was identified as&nbsp;<a href="https://www.europol.europa.eu/newsroom/news/world%E2%80%99s-most-dangerous-malware-emotet-disrupted-through-global-action"><strong>one of the most dangerous&nbsp;malwares</strong></a>. Additionally, being a dropper as well as a botnet,&nbsp;Emotet&nbsp;also&nbsp;served&nbsp;as a&nbsp;<strong>front&nbsp;door</strong>&nbsp;to many other malwares.&nbsp;It&nbsp;was used to drop malicious payloads directly onto the victims’ assets: for example,&nbsp;TrickBot&nbsp;was dropped onto the targeted machine which in turn, would drop&nbsp;<strong>Ryuk&nbsp;or Conti ransomware</strong>. According to Checkpoint Research,&nbsp;Emotet&nbsp;was at the top of the Global Threat Index in October 2020 and was linked to a&nbsp;<a href="https://blog.checkpoint.com/2021/01/07/december-2020s-most-wanted-malware-emotet-returns-as-top-malware-threat/"><strong>wave of ransomware attacks</strong></a>.&nbsp;According to CISA, the U.S. Cybersecurity &amp; Infrastructure Security Agency,&nbsp;Emotet&nbsp;infections cost is estimated at&nbsp;<a href="https://www.kaspersky.com/resource-center/threats/emotet"><strong>$1 million per incident</strong></a><strong>.</strong></p>
<p>&nbsp;</p>
<figure id="post-16210 media-16210" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16210" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/emotet.png" alt="" width="877" height="720" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/emotet.png 877w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/emotet-233x191.png 233w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/emotet-48x39.png 48w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/emotet-768x631.png 768w" sizes="auto, (max-width: 877px) 100vw, 877px" /></figure>
<p style="text-align: center;"><em>Main TA542’s customer base, “The Malware As a Service EMOTET”, ANSSI 2021</em></p>
<p>&nbsp;</p>
<p>During several months, Europol used the help of Eurojust, France, Germany, United States of America and announced their successful dismantle of the Emotet network in January 2021.</p>
<p><strong>Does this dismantling&nbsp;mean&nbsp;the end of the&nbsp;malware?</strong></p>
<p>The end of one botnet actually <a href="https://info.phishlabs.com/blog/emotet-dismantled-trickbot-zloader-and-bazarloader-step-in"><strong>led to&nbsp;the rise of several others</strong></a>, such as&nbsp;TrickBot, which even though existed since 2016, replaced Emotet as one of the most well-established&nbsp;MaaS&nbsp;(Malware as a Service) not long after the events on January.</p>
<p>This turn of events might not be so surprising, as threat actors often pivot and change their tools along the way, whether by choice or by necessity as it was the case here. Taking one malware down would only force them to use another one. Yet, what is interesting is that&nbsp;<a href="https://blogs.microsoft.com/on-the-issues/2020/10/12/trickbot-ransomware-cyberthreat-us-elections/"><strong>TrickBot&nbsp;also suffered a dismantlement of its own</strong></a>, back in October 2020. In an attempt to disrupt one of the most used distributors of ransomware, Microsoft joined forces with other security teams to take down&nbsp;TrickBot&nbsp;servers. As you may have noticed, this was months before law-enforcement took down&nbsp;Emotet, and now&nbsp;<a href="https://securityintelligence.com/posts/trickbot-survival-instinct-trickboot-version/"><strong>TrickBot&nbsp;or other versions of this malware, still lives on</strong></a>. These actions only disrupted&nbsp;TrickBot&nbsp;activities for a few days, before going back to what&nbsp;it was and even&nbsp;<strong>overtaking&nbsp;Emotet&nbsp;dominance</strong>.</p>
<p>Moreover, TrickBot&nbsp;seems to be somehow connected to the&nbsp;<strong><a href="https://www.cybereason.com/threat-alert-new-trickbot-variants">Bazar</a></strong>&nbsp;malware (BazarLoader&nbsp;and&nbsp;BazarBackdoor), as some part of its infrastructure is shared with&nbsp;TrickBot&nbsp;and both show code similarities. This new toolset is now the most seen malware used to deploy&nbsp;Ryuk&nbsp;ransomware instead of the previous&nbsp;Emotet-TrickBot-Ryuk&nbsp;or&nbsp;TrickBot-Ryuk&nbsp;chain of infection. These changes might have to do with the previously mentioned&nbsp;dismantlements, or due to a new collaboration between threat actors.</p>
<p><strong>What about the people behind these groups?</strong></p>
<p>More recently, on June 4th,&nbsp;<a href="https://www.justice.gov/opa/pr/latvian-national-charged-alleged-role-transnational-cybercrime-organization"><strong>Alla&nbsp;Witte was charged on multiple counts</strong></a> for participating in&nbsp;TrickBot&nbsp;criminal activities. Is this arrest, serving as a warning with several hundreds of years of prison if convicted, going to change cybercriminals’ operations? A few months before that, the Ukrainian authorities cooperated with the French law enforcement to conduct&nbsp;<a href="https://blog.malwarebytes.com/ransomware/2021/02/egregor-ransomware-hit-by-arrests/"><strong>an arrest against Egregor members</strong></a>, while&nbsp;<a href="https://threatpost.com/netwalker-ransomware-suspect-charged/163405/"><strong>a Canadian tied to&nbsp;Netwalker&nbsp;ransomware was charged</strong>&nbsp;</a>by the police for distributing the malware. Last year was also marked by several other arrests of cybercriminals around the world. For instance,&nbsp;<a href="https://www.zdnet.com/article/europol-arrests-hackers-behind-infinity-black-hacker-group/"><strong>the arrest of members of the Infinity Black website&nbsp;</strong></a>selling user credentials, lead to the end of the website and the group altogether. On the other hand, the arrests mentioned regarding&nbsp;Netwalker&nbsp;and Egregor seem to concern ransomware affiliates. And as the operators are still free and collaborate with other affiliates, their ransomware continues being deployed around the world.&nbsp;Alla&nbsp;Witte’s case is different since she is suspected to be a malware developer for the&nbsp;TrickBot&nbsp;Group. While her possible conviction might slightly disrupt&nbsp;TrickBot, it seems like their operations still go on, as according to <a href="https://any.run/malware-trends/trickbot">the&nbsp;any.run&nbsp;website and its malware trend tracker, the trojan was last seen on June 16th, 2021</a>. Last but not least, <a href="https://www.bleepingcomputer.com/news/security/ukraine-arrests-clop-ransomware-gang-members-seizes-servers/">some mid-tier members of the Cl0p gang may have been arrested</a> mid-June in Ukraine even though it seems no core actor behind Cl0p were apprehended.</p>
<p><strong>What could be the long-term consequences of these takedown for the cybercriminal activities?</strong></p>
<p>It’s still early to draw meaningful conclusions on the consequences for cybercriminal activities with the recent arrests. Yesterday, June 16th, at the Geneva summit, U.S. <a href="https://www.zdnet.com/article/biden-and-putin-spar-over-cybersecurity-ransomware-at-geneva-summit/"><strong>President Joe Biden met with Russian President Vladimir Putin</strong></a>. One of the hot topics of discussions was the <strong>ransomware attacks on U.S. entities from Russian soil</strong>. Biden warned Putin that United States would not tolerate any other cyber-attacks, especially on 16 critical sectors. The <a href="https://www.zdnet.com/article/ransomware-russia-told-to-tackle-cyber-criminals-operating-from-within-its-borders/"><strong>G7</strong></a> and the <a href="https://www.zdnet.com/article/nato-series-of-cyberattacks-could-be-seen-as-the-same-threat-as-an-armed-attack/"><strong>NATO</strong></a> also stated that in order not to consider cyber-attacks as armed attacks, Russia should try to identify and disrupt ransomware organizations within its borders.</p>
<p>Even with the arrests of criminal gang members and cybersecurity talks at the presidential levels, <strong>some experts say there would be no or little impact on ransomware groups that will still operate with impunity</strong>. The near future will give hints about the possible evolution of the cyber-attacks landscape. On one hand, the rising of a broader international collaboration against cyber-criminal gangs which could lead to less opportunistic and lucrative attacks. On the other hand, growing tensions between two blocks: U.S.-Europe and Russia-China with possible sanctions from either side and more cyber espionage, supply-chain or state-sponsored attacks.</p>
<p>&nbsp;</p>
<h1 style="text-align: center;"><strong>CERT-W: FROM THE FRONT LINE</strong></h1>
<h2 style="text-align: center;">The First Responder Word</h2>
<figure id="post-16221 media-16221" class="align-center">
<figure id="post-16228 media-16228" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16228" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/ng.jpg" alt="" width="936" height="638" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/ng.jpg 936w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/ng-280x191.jpg 280w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/ng-57x39.jpg 57w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/ng-768x523.jpg 768w" sizes="auto, (max-width: 936px) 100vw, 936px" /></figure>
</figure>
<h1></h1>
<p>&nbsp;</p>
<h1 style="text-align: center;"><strong>FOCUS TECH</strong></h1>
<h2 style="text-align: center;">Phishing</h2>
<p>Think like a cybercriminal and understand how a spear phishing campaign is built to avoid them!</p>
<p>The technical zoom of the month:</p>
<figure id="post-16215 media-16215" class="align-center"><img loading="lazy" decoding="async" class="aligncenter size-full wp-image-16215" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/image.png" alt="" width="973" height="1849" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/image.png 973w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/image-101x191.png 101w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/image-21x39.png 21w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/image-768x1459.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/image-808x1536.png 808w" sizes="auto, (max-width: 973px) 100vw, 973px" /></figure>
<p>&nbsp;</p>
<p style="text-align: center;"><strong>To learn more about this:</strong></p>
<figure id="post-16217 media-16217" class="align-center"><a href="https://www.proofpoint.com/us/resources/threat-reports/state-of-phish-infographic"><img loading="lazy" decoding="async" class="aligncenter wp-image-16217" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/learn.png" alt="" width="235" height="197" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/learn.png 462w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/learn-227x191.png 227w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/learn-46x39.png 46w" sizes="auto, (max-width: 235px) 100vw, 235px" /></a></figure>
<p>&nbsp;</p>
<h1 style="text-align: center;"><strong>Reading Of The Month</strong></h1>
<p style="text-align: center;">We recommend the short report “APT trends report Q1 2021”, which reviews the highlight events and findings observed by the Global Research and Analysis Team at Kaspersky during the Q1 2021 around the world.</p>
<figure id="post-16219 media-16219" class="align-center"><a href="https://securelist.com/apt-trends-report-q1-2021/101967/"><img loading="lazy" decoding="async" class="aligncenter wp-image-16219" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/read.jpg" alt="" width="248" height="154" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/read.jpg 415w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/read-308x191.jpg 308w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/06/read-63x39.jpg 63w" sizes="auto, (max-width: 248px) 100vw, 248px" /></a></figure>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2021/06/newsletter-cert-w-june-2021/">Newsletter CERT-W, from the front line &#8211; June 2021</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Fileless attack : Le retour à la terre</title>
		<link>https://www.riskinsight-wavestone.com/en/2018/10/fileless-attack-le-retour-a-la-terre/</link>
		
		<dc:creator><![CDATA[ThomasSghedon1]]></dc:creator>
		<pubDate>Tue, 23 Oct 2018 09:01:53 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[Cyberattaque]]></category>
		<category><![CDATA[fileless]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[menace]]></category>
		<category><![CDATA[Threat intelligence]]></category>
		<category><![CDATA[veille]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=11361/</guid>

					<description><![CDATA[<p>Le panorama des menaces informatiques évolue constamment, et chaque année se retrouve baptisée du nom de la nouvelle tendance ou innovation qui semble bousculer le monde de la sécurité informatique. Si 2017 était l’année du ransomware, il se pourrait que...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/10/fileless-attack-le-retour-a-la-terre/">Fileless attack : Le retour à la terre</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Le panorama des menaces informatiques évolue constamment, et chaque année se retrouve baptisée du nom de la nouvelle tendance ou innovation qui semble bousculer le monde de la sécurité informatique. Si 2017 était l’année du ransomware, il se pourrait que 2018 soit celle des fileless attacks (comprendre « les attaques sans fichiers »). Si le concept de ce mode d’attaque n’est pas nouveau, sa popularité croissante auprès des pirates, elle, l’est. Cela signifie-t-il que qui va nous imposer de repenser notre façon d’appréhender la sécurité des systèmes d’information ?</em></p>
<h2>Tu quoque mi programme</h2>
<p>Pour se faire une idée un peu plus détaillée et précise de cette menace, commençons par définir ce qu’est une <em>fileless attack</em>. Également nommée <em>non-malware attack</em> (attaque sans <em>malware</em>), <em>zero-footprint attack</em> (attaque sans empreinte) ou <em>living-off-the-land attack</em> (attaque hors sol), la particularité de ce type de menace est qu’elle n’impose pas à l’attaquant d’installer un programme sur la machine cible pour exécuter des actions malveillantes. En effet, le principe même de l’attaque est de détourner l’usage d’outils ou de programmes parfaitement licites et déjà installés sur les équipements informatiques à des fins, elles, illicites. Comment procèdent donc les attaquants pour arriver à leurs fins ?</p>
<p>Dans la majorité des cas, Pour établir cette tête de pont, ils utilisent la plupart du temps des techniques classiques de <em>phishing</em> ou <em>spear-phishing</em>. En effet, il est important de bien garder à l’esprit que la particularité de cette typologie d’attaque consiste dans la non-installation du programme malveillant chez la cible, ce qui ne préjuge pas de l’utilisation de fichiers à d’autres moments (comme lors d’un <em>phishing</em>). Alternativement, des attaques par force brute ou la mise à profit d’<em>exploit</em> permettant l’exécution de code à distance peuvent également permettre d’accéder à la machine cible et de perpétrer des attaques sans fichiers.</p>
<p>Quelle que soit la technique utilisée, l’objectif final est, comme on l’a vu, de détourner l’usage d’un programme légitime. La cible principale de ce « programme-jacking » est PowerShell (Windows Management Instrumentation étant également un bon client). Cet outil système, installé de manière native sur certaines machines tournant avec un système d’exploitation Windows, a la particularité de pouvoir exécuter des tâches instruites depuis la console de commande directement dans la mémoire vive de l’appareil. Dans certains cas, une simple macro bien construite sur un fichier Word malveillant, l’exploitation d’une faille de Flash ou la redirection vers un site malveillant suffit à invoquer PowerShell. Une fois celui-ci ouvert, il se connecte alors à un serveur de <em>command &amp; control</em> et télécharge un script malveillant qui s’exécute donc depuis la mémoire vive et qui peut procéder à toute une variété d’actions, comme par exemple localiser et envoyer des données vers l’attaquant ou miner des crypto-monnaies. Des <em>fileless attacks</em> exploitant les vulnérabilités de Java (Java Process) sont également connues.</p>
<h2> Malware : le grand remplacement</h2>
<p>Et il faut croire que cette typologie d’attaque est facile à mettre en œuvre si on jette un œil aux chiffres. <a href="https://www.barkly.com/ponemon-2018-endpoint-security-statistics-trends"> </a>, pour 77% des entreprises reconnaissant avoir subi une attaque ayant réussi à compromettre le système d’information de l’entreprise, la technique utilisée est une <em>fileless attack</em>. <a href="https://www.symantec.com/blogs/threat-intelligence/powershell-threats-grow-further-and-operate-plain-sight">Symantec a signalé en juillet dernier qu’entre le premier semestre 2017 et le premier semestre 2018, l’usage malveillant de PowerShell avait augmenté de 661%</a>. Ainsi, Carbon Black a annoncé dans son rapport de menace 2017 que 97% de ses clients avaient subi une tentative de la sorte et que les attaques sans fichier utilisant des failles PowerShell ou WMI ont représenté au global 52% du total des attaques en 2017, dépassant pour la première fois de l’histoire les attaques classiques utilisant des <em>malwares</em> installés en dur sur la machine cible.</p>
<p>La raison principale de l’explosion de cette typologie de menaces trouve son origine dans la façon même qu’ont les organisations de se défendre. d’analyser de manière statique les signatures des fichiers sur le disque afin d’identifier les programmes illicites, et éventuellement de les exécuter dans des bacs à sables. La plupart de ces antivirus utilisent une fonctionnalité de l’OS pour être notifiés des nouvelles écritures sur le disque et ainsi déclencher un scan. Or, pas de fichier, pas de notification, et pas de notification, pas de scan. Les attaquants étant des personnes pragmatiques, ils ont simplement décidé de court-circuiter cette étape et de mettre ainsi en défaut l’ensemble des défenses basées sur ces anti-virus traditionnels fonctionnant par base de signatures, ces derniers devenant de plus en plus performants.</p>
<p>Les pirates de leur côté s’équipent afin de procéder plus facilement aux attaques en systématisant et simplifiant les manipulations à faire pour contourner ces anti-virus. Certains outils d’attaque actuels, comme Metasploit, facilitent les <em>fileless attacks</em> grâce à la construction de charges utiles malveillantes clefs en main à charger directement depuis Powershell.</p>
<h2>Comment chasser un malware qui n’existe pas ?</h2>
<p>Les méthodes de défense traditionnelles étant peu adaptées, il est nécessaire de repenser son approche. Si certaines menaces peuvent être stoppées simplement en redémarrant la machine (son arrêt stoppant les programmes actifs), les hackers ont trouvé la parade par l’installation d’un script dans le <em>registry</em> de Windows, entraînant la résurgence de la brèche au redémarrage par son exécution automatique avec le reste des scripts systèmes, eux légitimes. Si ce script est suffisamment court, il n’a même pas besoin d’être enregistré dans un fichier. Certaines attaques plus complexes peuvent demander l’enregistrement de leur script dans un fichier, ce qui en fait une catégorie hybride de <em>fileless attack,</em> où si un fichier est effectivement nécessaire, ça n’est toujours pas le <em>malware</em> en lui-même.</p>
<p>Depuis quelques années, le développement des solutions de type <em>Endpoint Detection Response</em> se trouve être au cœur de l’activité des éditeurs antivirus. Ces produits ne se limitent plus à la simple analyse de fichiers mais adoptent des techniques d’étude comportementale. L’idée derrière cette nouvelle façon de procéder est d’identifier les activations de programmes qui, individuellement, seraient légitimes mais dont l’exécution en parallèle ou séquentielle est suspicieuse. Par exemple, la consultation du web, l’utilisation d’une macro Microsoft Word ou l’exécution de PowerShell est légitime. En revanche, leur activation concomitante peut résulter d’un <em>phishing</em> réussi emmenant l’utilisateur sur un site web malveillant, déclenchant l’activation en cascade de PowerShell à travers une faille du premier. La solution antivirale peut donc réaliser qu’il ne s’agit pas d’une situation normale de fonctionnement et procéder aux actions de sécurité nécessaires.</p>
<p>Néanmoins, ces solutions étant basées sur des heuristiques, elles sont par définition faillibles. L’équilibre entre l’exhaustivité des détections et le nombre de faux positifs, entraînant potentiellement des incidents d’exploitation, est difficile à atteindre. Des solutions de plus en plus stables et performantes apparaissent néanmoins progressivement sur le marché, et permettent de lutter contre cette menace grandissante de manière efficace, pour peu que les terminaux utilisateurs en soient équipés.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/10/fileless-attack-le-retour-a-la-terre/">Fileless attack : Le retour à la terre</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Malwarebytes challenge write-up</title>
		<link>https://www.riskinsight-wavestone.com/en/2018/06/malwarebytes-challenge-write-up/</link>
		
		<dc:creator><![CDATA[Maxime Meignan]]></dc:creator>
		<pubDate>Tue, 12 Jun 2018 09:00:39 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Deep-dive]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[malware]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=15584</guid>

					<description><![CDATA[<p>Malwarebytes published on April 27th a new reverse engineering challenge, an executable mixing malware behavior with a traditional crackme look. It came in the form of a Windows executable This document describes the solving step of the challenge. Lightweight analysis...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/06/malwarebytes-challenge-write-up/">Malwarebytes challenge write-up</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="separator" style="clear: both; text-align: center;">
<figure id="post-15585 media-15585" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-15585 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I1.png" alt="" width="320" height="150" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I1.png 320w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I1-71x33.png 71w" sizes="auto, (max-width: 320px) 100vw, 320px" /></figure>
</div>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: left;"><span style="text-align: justify;">Malwarebytes published on April 27th a new reverse engineering challenge, an executable mixing malware behavior with a traditional crackme look. It came in the form of a Windows executable</span></div>
<p>This document describes the solving step of the challenge.</p>
<h2><span style="text-align: center;">Lightweight analysis of “mb_crackme_2.exe”</span></h2>
<div style="text-align: justify;">
<p>As we would do with any real malware, we start by performing some basic information gathering on the provided executable. Even if the static and dynamic approaches gave us similar conclusions on the executable’s nature (see 2.4), the different methods have been described nonetheless in the following sections.</p>
<h3>Basic static information gathering</h3>
<p>Using <b>Exeinfo PE</b>, a maintained successor of the renowned (but outdated) <b>PEiD</b> software, gives us some basic information about the binary:</p>
<ul>
<li> The program is a <b>32 bits Portable Executable</b> (PE), meant to be run in console (no GUI);</li>
<li> It seems to be compiled from C++ using Microsoft Visual C++ 8;</li>
<li> No obvious sign of packing is detected by the tool.</li>
</ul>
</div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">
<div style="text-align: justify;">
<div style="text-align: center;">
<figure id="post-15587 media-15587" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15587 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I2.png" alt="" width="518" height="255" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I2.png 518w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I2-388x191.png 388w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I2-71x35.png 71w" sizes="auto, (max-width: 518px) 100vw, 518px" /></figure>
<p><i><span style="font-size: x-small;">Output of Exeinfo PE</span></i>
</div>
<p>Looking for printable strings in the binary already gives us some hints about the executable’s nature:
</p></div>
<div style="background-color: black; border: 1px solid white; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre><span style="font-family: inherit;"><span style="font-size: small;">$ strings -n 10 mb_crackme_2.exe_
[...]
<span style="color: red;"><b>pyi</b></span>-windows-manifest-filename
[...]
<span style="color: red;"><b>Py</b></span>_IgnoreEnvironmentFlag
Failed to get address for <b><span style="color: red;">Py</span></b>_IgnoreEnvironmentFlag
<span style="color: red;"><b>Py</b></span>_NoSiteFlag
Failed to get address for <span style="color: red;"><b>Py</b></span>_NoSiteFlag
Py_NoUserSiteDirectory
[...]
m<span style="color: red;"><b>pyi</b></span>mod01_os_path
m<span style="color: red;"><b>pyi</b></span>mod02_archive
m<span style="color: red;"><b>pyi</b></span>mod03_importers
s<span style="color: red;"><b>pyi</b></span>boot01_bootstrap
s<span style="color: red;"><b>pyi</b></span>_rth__tkinter
bCrypto.Cipher._AES.<span style="color: red;"><b>pyd</b></span>
bCrypto.Hash._SHA256.<span style="color: red;"><b>pyd</b></span>
bCrypto.Random.OSRNG.winrandom.<span style="color: red;"><b>pyd</b></span>
bCrypto.Util._counter.<span style="color: red;"><b>pyd</b></span>
bMicrosoft.VC90.CRT.manifest
bPIL._imaging.<span style="color: red;"><b>pyd</b></span>
bPIL._imagingtk.<span style="color: red;"><b>pyd</b></span>
[...]
o<span style="color: red;"><b>pyi</b></span>-windows-manifest-filename another.exe.manifest
[...]
zout00-PYZ.<span style="color: red;"><b>pyz</b></span>
<span style="color: red;"><b>python27.dll</b></span></span></span>
</pre>
</div>
<p>Many references to <b>Python libraries</b>, <b>PYZ</b> archives and “<b>pyi</b>” substring indicates the use of the <b>PyInstaller</b> utility to build a PE executable from a Python script.</p>
<h3>Basic dynamic information gathering</h3>
<p>Running the executable (in a sandboxed environment) gives us the following message:</p>
<figure id="post-15672 media-15672" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15672 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I3-1.png" alt="" width="454" height="785" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I3-1.png 454w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I3-1-110x191.png 110w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I3-1-23x39.png 23w" sizes="auto, (max-width: 454px) 100vw, 454px" /></figure>
<figure id="post-15589 media-15589" class="align-none"></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<p>Using <b>Process Monitor</b>, from <a href="https://docs.microsoft.com/en-us/sysinternals/">SysInternals Tools Suit</a><a href="https://www.blogger.com/null">e</a> , allows us to quickly get a glimpse of the actions performed by the executable:</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-15591 size-full" style="text-align: center;" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I4.png" alt="" width="640" height="328" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I4.png 640w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I4-373x191.png 373w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I4-71x36.png 71w" sizes="auto, (max-width: 640px) 100vw, 640px" /></p>
<div class="separator" style="clear: both; text-align: center;"></div>
<p>A temporary directory named “<b>_MEI5282</b>” is created under user’s “<b>%temp%</b>” directory, and filled with <b>Python-related resources</b>. In particular, “<b>python27.dll</b>” and “<b>*.pyd</b>” libraries are written and later loaded by the executable.</p>
<p>This behavior is typical of executables generated by PyInstaller.
</p></div>
<div style="text-align: justify;">
<div style="text-align: justify;">
<figure id="post-15593 media-15593" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15593 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I5.png" alt="" width="640" height="312" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I5.png 640w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I5-392x191.png 392w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I5-71x35.png 71w" sizes="auto, (max-width: 640px) 100vw, 640px" /></figure>
</div>
<h3 style="text-align: justify;">Error-handling analysis</h3>
<div style="text-align: justify;">Without tools, it is often possible to quickly get information about a binary’s internals by <b>testing its error handling</b>. For example, inserting an <b>EOF</b> (End-Of-File) signal in the terminal (“Ctrl+Z + Return” on Windows Command Prompt) makes the program crash, printing the following information:</div>
<div class="separator" style="clear: both; text-align: center;">
<figure id="post-15595 media-15595" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15595 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I6.png" alt="" width="461" height="262" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I6.png 461w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I6-336x191.png 336w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I6-69x39.png 69w" sizes="auto, (max-width: 461px) 100vw, 461px" /></figure>
</div>
<div style="text-align: justify;">
<div class="separator" style="clear: both; text-align: center;"><i><span style="font-size: x-small;">Python stack trace printed after a crash</span></i></div>
<p>This allows us to identify the presence of a Python program embedded inside the executable and gives us the name of the main script:<b> another.py.</b> The error message “[$PID] Failed to execute script $scriptName” is typical of <b>PyInstaller</b>-produced programs.
</div>
<h3 style="text-align: justify;">Python files extraction and decompilation</h3>
<div style="text-align: justify;">Every lightweight analysis presented previously points out that the executable has been built using <b>PyInstaller</b>.<br />
The <a href="https://0xec.blogspot.fr/2017/11/pyinstaller-extractor-updated-to-v19.html"><b>PyInstaller Extractor</b></a>  program can be used to extract python-compiled resources from the executable.</div>
<div style="text-align: justify;"></div>
<div style="background-color: black; border: 1px solid white; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre>$ python pyinstxtractor.py mb_crackme_2.exe
[*] Processing mb_crackme_2.exe
[*] Pyinstaller version: 2.1+
[*] Python version: 27
[*] Length of package: 8531014 bytes
[*] Found 931 files in CArchive
[*] Beginning extraction...please standby
[+] Possible entry point: pyiboot01_bootstrap
[+] Possible entry point: pyi_rth__tkinter
[+] Possible entry point: <b><span style="color: red;">another</span></b>
[*] Found 440 files in PYZ archive
[*] Successfully extracted pyinstaller archive: mb_crackme_2.exe

You can now use a python decompiler on the pyc files within the extracted directory</pre>
</div>
<p>&nbsp;</p>
<div style="text-align: justify;">As previously seen, the most interesting file is “<b>another</b>”, as it should contain the “main” function.</div>
<div class="separator" style="clear: both; text-align: center;">
<figure id="post-15597 media-15597" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15597 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I7.png" alt="" width="400" height="88" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I7.png 400w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I7-71x16.png 71w" sizes="auto, (max-width: 400px) 100vw, 400px" /></figure>
</div>
<div style="text-align: justify;">
<div class="separator" style="clear: both; text-align: center;"><i><span style="font-size: x-small;">Files extracted by PyInstaller Extractor</span></i></div>
<p>&nbsp;
</p></div>
<div style="text-align: justify;">A quick <a href="https://hshrzd.wordpress.com/2018/01/26/solving-a-pyinstaller-compiled-crackme/">Internet search</a>  informs us that in a PYZ archive, the main file is in fact a *<b>.pyc file</b> (Python bytecode) from which the<b> first 8 bytes</b>, containing its signature, <b>have been removed</b>. Looking the hex dump of <b>another *.pyc </b>file of the archive confirms this statement and gives us the correct signature for Python 2.7 bytecode files (in purple).</div>
<div style="text-align: justify;"></div>
<div style="background-color: black; border: 1px solid white; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre>$ hexdump -C another | head -n 3
00000000  <span style="color: red;"><b>63 00 00 00 00 00 00 00  00 03 00 00 00 40 00 00</b></span>  |c............@..|
00000010  00 73 03 02 00 00 64 00  00 5a 00 00 64 01 00 5a  |.s....d..Z..d..Z|
00000020  01 00 64 02 00 5a 02 00  64 03 00 64 04 00 6c 03  |..d..Z..d..d..l.|
$ hexdump -C out00-PYZ.pyz_extracted/cmd.pyc | head -n 3
00000000  <b><span style="color: purple;">03 f3 0d 0a 00 00 00 00</span></b>  <span style="color: red;"><b>63 00 00 00 00 00 00 00</b></span>  |.ó......c.......|
00000010  <span style="color: red;"><b>00 03 00 00 00 40 00 00</b></span>  00 73 4c 00 00 00 64 00  |.....@...sL...d.|
00000020  00 5a 00 00 64 01 00 64  02 00 6c 01 00 5a 01 00  |.Z..d..d..l..Z..|</pre>
</div>
<p>Restoring the file’s signature produces a correct Python bytecode file.</p>
<div style="background-color: black; border: 1px solid white; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre>$ cat &lt;(printf "\x03\xf3\x0d\x0a\x00\x00\x00\x00") another &gt; another.pyc
$ file another.pyc
another.pyc: python 2.7 byte-compiled</pre>
</div>
</div>
<div style="text-align: justify;">
<div style="text-align: justify;"></div>
<div style="text-align: justify;">Using the <a href="https://github.com/rocky/python-uncompyle6">uncompyle6</a>  decompilation tool, we can easily recover the original source code of <b>another.py</b>.</div>
<div style="text-align: justify;"></div>
<div style="background-color: black; border: 1px solid white; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre>$ uncompyle6 another.pyc &gt; another.py</pre>
</div>
<div style="text-align: justify;"></div>
<h1 style="text-align: justify;">Stage 1: login</h1>
<div style="text-align: justify;">Looking at the <b>main()</b> function of <b>another.py</b>, we see that the first operations are performed by the <b>stage1_login()</b> function.</div>
<div style="text-align: justify;"></div>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre><span style="color: blue;">def</span> <span style="color: magenta;">main</span>():
    key = <span style="color: red;">stage1_login</span>()
    <span style="color: blue;">if not</span> check_if_next(key):
        <span style="color: blue;">return</span>
    <span style="color: blue;">else</span>:
        content = decode_and_fetch_url(key)
        <span style="color: blue;">if </span>content <span style="color: blue;">is None</span>:
            <span style="color: blue;">print </span><span style="color: #666666;">'Could not fetch the content'</span>
            <span style="color: blue;">return </span>-<span style="color: red;">1</span>
        decdata = get_encoded_data(content)
        <span style="color: blue;">if not </span>is_valid_payl(decdata):
            <span style="color: blue;">return </span>-<span style="color: red;">3</span>
        <span style="color: blue;">print </span>colorama.Style.BRIGHT + colorama.Fore.CYAN
        <span style="color: blue;">print </span><span style="color: #666666;">'Level #2: Find the secret console...'</span>
        <span style="color: blue;">print </span>colorama.Style.RESET_ALL
        <span style="color: #6aa84f;">#load_level2(decdata, len(decdata))</span>
        dump_shellcode(decdata, len(decdata))
        user32_dll.MessageBoxA(<span style="color: blue;">None</span>, <span style="color: #666666;">'You did it, level up!'</span>, 'Congrats!', <span style="color: red;">0</span>)
        <span style="color: blue;">try</span>:
            <span style="color: blue;">if </span>decode_pasted() == <span style="color: blue;">True</span>:
                user32_dll.MessageBoxA(<span style="color: blue;">None</span>, <span style="color: #666666;">'''Congratulations! Now save your flag
and send it to Malwarebytes!'''</span>, <span style="color: #666666;">'You solved it!'</span>, <span style="color: red;">0</span>)
                <span style="color: blue;">return </span><span style="color: red;">0</span>
            user32_dll.MessageBoxA(<span style="color: blue;">None</span>, <span style="color: #666666;">'See you later!'</span>, <span style="color: #666666;">'Game over'</span>, <span style="color: red;">0</span>)
        <span style="color: blue;">except</span>:
            <span style="color: blue;">print </span>'Error decoding the flag'
        <span style="color: blue;">return</span></pre>
</div>
<div style="text-align: justify;"></div>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre></pre>
<pre><span style="color: blue;">def </span><span style="color: magenta;">stage1_login</span>():
    show_banner()
    <span style="color: blue;">print </span>colorama.Style.BRIGHT + colorama.Fore.CYAN
    <span style="color: blue;">print </span><span style="color: #666666;">'Level #1: log in to the system!'</span>
    <span style="color: blue;">print </span>colorama.Style.RESET_ALL
    login = raw_input('login: ')
    password = getpass.getpass()
    <span style="color: blue;">if not </span>(<span style="color: red;">check_login</span>(login) <span style="color: blue;">and </span><span style="color: red;">check_password</span>(password)):
        <span style="color: blue;">print </span><span style="color: #666666;">'Login failed. Wrong combination username/password'</span>
        <span style="color: blue;">return </span>None
    <span style="color: blue;">else</span>:
        PIN = raw_input('PIN: ')
        <span style="color: blue;">try</span>:
            key = <span style="color: red;">get_url_key</span>(int(PIN))
        <span style="color: blue;">except</span>:
            <span style="color: blue;">print </span><span style="color: #666666;">'Login failed. The PIN is incorrect'</span>
            <span style="color: blue;">return None</span>
        <span style="color: blue;">if not </span><span style="color: red;">check_key</span>(key):
            <span style="color: blue;">print </span><span style="color: #666666;">'Login failed. The PIN is incorrect'</span>
            <span style="color: blue;">return None</span>
        <span style="color: blue;">return </span>key</pre>
</div>
<p>Three user inputs are successively checked: the user’s <b>login</b>, <b>password </b>and <b>PIN </b>code.</p>
<h3>Finding the login</h3>
<div style="text-align: justify;">The check_login() function&#8217;s code is completely transparent :</div>
<div style="text-align: justify;"></div>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre><span style="color: blue;">def </span><span style="color: magenta;">check_login</span>(login):
    <span style="color: blue;">if </span>login == <span style="color: red;">'hackerman'</span>:
        <span style="color: blue;">return True</span>
    <span style="color: blue;">return False</span></pre>
</div>
<p>We have found the login, let&#8217;s search for the password.</p>
<figure id="post-15599 media-15599" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-15599 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I8.jpg" alt="" width="320" height="180" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I8.jpg 320w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I8-69x39.jpg 69w" sizes="auto, (max-width: 320px) 100vw, 320px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><i><span style="font-size: x-small;">Expected login</span></i></div>
<div class="separator" style="clear: both; text-align: left;"></div>
</div>
<h3>Finding the password</h3>
<p>The <b>check_password</b>() function hashes user’s input using the <b>MD5 </b>hash function, and compares the result with an hardcoded string:</p>
<div style="text-align: justify;"></div>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre><span style="color: blue;">def </span><span style="color: magenta;">check_password</span>(password):
    my_md5 = hashlib.md5(password).hexdigest()
    <span style="color: blue;">if </span>my_md5 == '42f749ade7f9e195bf475f37a44cafcb':
        <span style="color: blue;">return True</span>
    <span style="color: blue;">return False</span></pre>
</div>
<p>A quick Internet search of this string gives us the corresponding cleartext password: <b>Password123</b>.</p>
<figure id="post-15601 media-15601" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15601 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I9.png" alt="" width="640" height="240" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I9.png 640w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I9-437x164.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I9-71x27.png 71w" sizes="auto, (max-width: 640px) 100vw, 640px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><i><span style="font-size: x-small;">Finding the password on a search engine</span></i></div>
<h3>Finding the PIN code</h3>
<p>The PIN code is read from standard input, converted into an<b> integer</b> (cf. stage1_login()<b> </b>function), and passed to the <b>get_url_key() </b>function:</p>
<div style="text-align: justify;"></div>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre></pre>
<pre><span style="color: blue;">def</span> <span style="color: magenta;">get_url_key</span>(my_seed):
    random.seed(my_seed)
    key = ‘’
    <span style="color: blue;">for </span>I <span style="color: blue;">in </span>xrange(0, 32):
        id = random.randint(0, 9)
        key += str(id)
    <span style="color: blue;">return </span>key</pre>
</div>
<p>This function derives a<b> pseudo-random 32 digits</b> key from the PIN code, using it as a <b>seed </b>for Python’s PRNG. The generated key is then verified using the <b>check_key()</b> function, where its MD5 sum is checked against another hardcoded value.</p>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre></pre>
<pre><span style="color: blue;">def </span><span style="color: magenta;">check_key</span>(key):
    my_md5 = hashlib.md5(key).hexdigest()
    <span style="color: blue;">if </span>my_md5 == '<span style="color: red;">fb4b322c518e9f6a52af906e32aee955</span>':
        <span style="color: blue;">return </span>True
    <span style="color: blue;">return </span>False</pre>
</div>
<p>The key space is obviously <b>too large to be brute-forced</b>, as a 32-digits string corresponds to 10^32 (~2^106) possible combinations. However, <b>we can brute-force the PIN</b> code, being an integer, using the following code:</p>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre></pre>
<pre><span style="color: blue;">from </span>another <span style="color: blue;">import </span>get_url_key, check_key
PIN = 0
<span style="color: blue;">while True</span>:
    key = get_url_key(PIN)
    <span style="color: blue;">if </span>check_key(key):
        <span style="color: blue;">print </span>PIN
        <span style="color: blue;">break</span>
    PIN += 1</pre>
</div>
<p>The solution is obtained in a few milliseconds:</p>
<div style="background-color: black; border: 1px solid white; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre>$ python bruteforcePIN.py
9667</pre>
</div>
<h3>Testing credentials</h3>
<p>Using the credentials found in the previous step completes the first stage of the challenge.</p>
<figure id="post-15603 media-15603" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15603 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I10.png" alt="" width="400" height="148" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I10.png 400w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I10-71x26.png 71w" sizes="auto, (max-width: 400px) 100vw, 400px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><i><span style="font-size: x-small;">Validating stage 1</span></i></div>
<p>Clicking “Yes” makes the executable pause after printing the following message in the console:</p>
<div class="separator" style="clear: both; text-align: center;">
<figure id="post-15605 media-15605" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15605 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I11.png" alt="" width="320" height="96" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I11.png 320w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I11-71x21.png 71w" sizes="auto, (max-width: 320px) 100vw, 320px" /></figure>
</div>
<div class="separator" style="clear: both; text-align: center;"><i><span style="font-size: x-small;">Waiting for us to find a &#8220;secret console&#8221;</span></i></div>
<p>Let’s find that secret console!</p>
<h1>Stage 2: the secret console</h1>
<h3>Payload download and decoding</h3>
<p>Continuing our analysis of the main() function, the next function to be called after credentials verification is <b>decode_and_fetch_url()</b>, with the previously calculated 32-digits key given as argument:</p>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre></pre>
<pre><span style="color: blue;">def </span><span style="color: magenta;">decode_and_fetch_url</span>(key):
    <span style="color: blue;">try</span>:
        encrypted_url = <span style="color: #444444;">'\xa6\xfa\x8fO\xba\x7f\x9d\[...]\xfe'</span>
        aes = AESCipher(bytearray(key))
        output = aes.decrypt(encrypted_url)
        full_url = output
        content = fetch_url(full_url)
    <span style="color: blue;">except</span>:
        <span style="color: blue;">return None</span>
    <span style="color: blue;">return </span>content</pre>
</div>
<p>A URL is decrypted using an <b>AES </b>cipher and the 32-digits key. The resource at this URL is then downloaded and its content returned by the function.<br />
To get the decrypted URL, we simply add some <b>logging</b> instructions to the original code of another.py, which can be run independently of mb_crackme_2.exe (given that the required dependencies are present on our machine).</p>
<div style="background-color: black; border: 1px solid white; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre>[...]
        full_url = output
        print "DEBUG : URL fetched is : %s " % full_url #added from original code
        content = fetch_url(full_url)
[...]</pre>
</div>
<p>The result execution is the following:</p>
<div style="background-color: black; border: 1px solid white; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre></pre>
<pre>login: hackerman
Password:
PIN: 9667
<span style="color: red;">DEBUG : URL fetched is : https://i.imgur.com/dTHXed7.png</span></pre>
</div>
<p>The decrypted URL hosts the PNG image displayed bellow:</p>
<figure id="post-15607 media-15607" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15607 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I12.png" alt="" width="267" height="267" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I12.png 267w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I12-191x191.png 191w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I12-39x39.png 39w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I12-32x32.png 32w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I12-64x64.png 64w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I12-96x96.png 96w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I12-128x128.png 128w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I12-70x70.png 70w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I12-175x175.png 175w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I12-130x130.png 130w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I12-115x115.png 115w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I12-30x30.png 30w" sizes="auto, (max-width: 267px) 100vw, 267px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><i><span style="font-size: x-small;">Image downloaded by the executable</span></i></div>
<p>The “malware” then reads the <b>Red, Green and Blue components of each of the image’s pixels</b>, interprets them as <b>bytes </b>and constructs a buffer from their concatenation.</p>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre><span style="color: blue;">def </span><span style="color: magenta;">get_encoded_data</span>(bytes):
    imo = Image.open(io.BytesIO(bytes))
    rawdata = list(imo.getdata())
    tsdata <span style="color: blue;">= </span>''
    <span style="color: blue;">for </span>x <span style="color: blue;">in </span>rawdata:
        <span style="color: blue;">for </span>z <span style="color: blue;">in </span>x:
            tsdata += chr(z)
    <span style="color: blue;">del </span>rawdata
    <span style="color: blue;">return </span>tsdata</pre>
<pre></pre>
</div>
<p>This technique is sometimes used by real malware to download malicious code <b>without raising suspicion of traffic-analysis tools</b>, hiding the real nature of the downloaded resource.<br />
Using the “Extract data…” function of the <b>Stegsolve</b> tool  allows to quickly preview the data encoded in the image, which appears to be a PE file (and more specifically, a DLL):</p>
<figure id="post-15609 media-15609" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15609 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I13.png" alt="" width="640" height="494" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I13.png 640w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I13-247x191.png 247w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I13-51x39.png 51w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I13-156x121.png 156w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I13-155x120.png 155w" sizes="auto, (max-width: 640px) 100vw, 640px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><i><span style="font-size: x-small;">Output of the stegsolve tool</span></i></div>
<p>The function <b>is_valid_payl()</b> is then used to check whether the decoded payload is correct:</p>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre></pre>
<pre><span style="color: blue;">def </span><span style="color: magenta;">is_valid_payl</span>(content):
    <span style="color: blue;">if </span>get_word(content) != <span style="color: red;">23117</span>:
        <span style="color: blue;">return False</span>
    next_offset = get_dword(content[<span style="color: red;">60</span>:])
    next_hdr = content[next_offset:]
    <span style="color: blue;">if </span>get_dword(next_hdr) != <span style="color: red;">17744</span>:
        <span style="color: blue;">return False</span>
    <span style="color: blue;">return True</span></pre>
</div>
<p>The<b> 23117 and 17744</b> constants represent the “MZ” and “PE” magic bytes present in the headers of a PE.</p>
<div style="background-color: black; border: 1px solid white; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre></pre>
<pre>&gt;&gt;&gt; import struct
&gt;&gt;&gt; struct.pack("&lt;H", 23117)
'MZ'
&gt;&gt;&gt; struct.pack("&lt;H", 17744)
'PE'</pre>
</div>
<p>The decoded file is then passed to the<b> load_level2()</b> function, which is a wrapper around <b>prepare_stage()</b>.</p>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre><span style="color: blue;">def </span><span style="color: magenta;">load_level2</span>(rawbytes, bytesread):
    <span style="color: blue;">try</span>:
        <span style="color: blue;">if </span>prepare_stage(rawbytes, bytesread):
            <span style="color: blue;">return True</span>
    <span style="color: blue;">except</span>:
        <span style="color: blue;">return False</span></pre>
</div>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre></pre>
<pre><span style="color: blue;">def </span><span style="color: magenta;">prepare_stage</span>(content, content_size):
    virtual_buf = kernel_dll.VirtualAlloc(0, content_size, 12288, 64)
    <span style="color: blue;">if </span>virtual_buf == 0:
        <span style="color: blue;">return False</span>
    <span style="color: blue;">res </span>= memmove(virtual_buf, content, content_size)
    <span style="color: blue;">if </span>res == 0:
        <span style="color: blue;">return False</span>
    MR = WINFUNCTYPE(c_uint)(virtual_buf + 2)
    MR()
    <span style="color: blue;">return True</span></pre>
</div>
<p>This function starts by allocating enough space to store the downloaded code, using the VirtualAlloc API function call. The allocated space is <b>readable, writable and executable</b>, as the provided arguments reveal (12288 being equal to “MEM_COMMIT | MEM_RESERVE”, and 64 to PAGE_EXECUTE_READWRITE).<br />
The downloaded code is then written in the allocated space using the memmove function, and executed like a shellcode from offset 2.</p>
<p>To get a clean dump of the downloaded code (once decrypted), we <b>add a piece of code in the prepare_stage()</b> function, as follows:</p>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre><span style="color: blue;">def </span><span style="color: magenta;">prepare_stage</span>(content, content_size):
    <span style="color: blue;">with </span>open("dumped_pe.dll", "wb") as f:
        f.write(content[:content_size])
        print "DEBUG : File dumped in dumped_pe.dll"
    virtual_buf = kernel_dll.VirtualAlloc(0, content_size, 12288, 64)
    <span style="color: blue;">if </span>virtual_buf == 0:
        return False
    res = memmove(virtual_buf, content, content_size)
    <span style="color: blue;">if </span>res == 0:
        <span style="color: blue;">return </span>False
    MR = WINFUNCTYPE(c_uint)(virtual_buf + 2)
    MR()
    <span style="color: blue;">return True</span></pre>
</div>
<p>After re-executing the program, we observe that the obtained file is indeed a valid 32 bits Windows DLL:</p>
<div style="background-color: black; border: 1px solid white; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre>$ file dumped_pe.dll
dumped_file.ext: PE32 executable (DLL) (console) Intel 80386, for MS Windows</pre>
</div>
<p>Time for us to open our favorite disassembler !</p>
<h2>Downloaded DLL’s reverse-engineering</h2>
<p><b>Reflective loading</b><br />
From the offset 2 of the file, a little shellcode located in the DOS headers<b> transfers the execution</b> to another code that implements <b>Reflective DLL injection</b>. This technique is used to load the library itself from memory, instead of normally loading the DLL from disk using the LoadLibrary API call.<br />
&nbsp;</p>
<figure id="post-15611 media-15611" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15611 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I14.png" alt="" width="640" height="118" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I14.png 640w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I14-437x81.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I14-71x13.png 71w" sizes="auto, (max-width: 640px) 100vw, 640px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><i><span style="font-size: x-small;">Disassembly of the first bytes of the downloaded DLL</span></i></div>
<p>The reflective loader’s code, located at 0x6E0, is documented in Stephen Fewer’s GitHub  and will not be described in this write-up. Since, in the end, the library is loaded by this mechanism as it would be after a normal LoadLibrary call, this downloaded file will be analyzed like a standard DLL in the rest of this write-up.</p>
<p>The list of exported functions being empty (except for the DllEntryPoint function), we start our analysis at the <b>entry point of the DLL</b>.</p>
<figure id="post-15613 media-15613" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15613 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I15.png" alt="" width="400" height="43" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I15.png 400w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I15-71x8.png 71w" sizes="auto, (max-width: 400px) 100vw, 400px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>Exports list</i></span></div>
<p><b>Entry point</b><br />
Our first goal is to search for the <b>DllMain()</b> function from the entry point. If the reverser is not used to analyzing Windows DLLs, a simple way to start would be to open any random non-stripped 32bit DLL, which (with a little luck) would be compiled with the same compiler (Visual C++ ~7.10 here), and which would have a similar CFG structure for the DllEntryPoint function.<br />
An example of CFG comparisons between the analyzed DLL (left) and another non-stripped 32bit DLL (right) is presented below:<br />
&nbsp;</p>
<figure id="post-15615 media-15615" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15615 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I16.png" alt="" width="640" height="298" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I16.png 640w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I16-410x191.png 410w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I16-71x33.png 71w" sizes="auto, (max-width: 640px) 100vw, 640px" /><i></i></figure>
<div style="text-align: center;"><i><span style="font-size: x-small;">DLLEntryPoints in our DLL v/s another non-stripped DLL</span></i></div>
<div class="separator" style="clear: both; text-align: center;"></div>
<figure id="post-15617 media-15617" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15617 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I17.png" alt="" width="640" height="451" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I17.png 640w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I17-271x191.png 271w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I17-55x39.png 55w" sizes="auto, (max-width: 640px) 100vw, 640px" /></figure>
<div style="text-align: center;"><i><span style="font-size: x-small;">DllMainCTRStartup in our DLL / in another non-stripped DLL</span></i></div>
<div class="separator" style="clear: both; text-align: center;"></div>
<p>This technique allows us to quickly find the DllMain function in our DLL, here being located at 0x10001170.<br />
<b>DllMain (0x10001170)</b><br />
The function starts by checking if it has been called during the first load of the DLL by a process, by comparing the value of the fdwReason argument  against the DLL_PROCESS_ATTACH constant.<br />
The DllMain() function then <b>registers two exception handlers</b> using the AddVectoredExceptionHandler  API call. The handlers are named <b>“Handler_0” and “Handler_1”</b> in the screenshot below:</p>
<figure id="post-15619 media-15619" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15619 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I18.png" alt="" width="640" height="453" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I18.png 640w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I18-270x191.png 270w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I18-55x39.png 55w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I18-345x245.png 345w" sizes="auto, (max-width: 640px) 100vw, 640px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>DllMain function</i></span></div>
<p>An exception is then manually raised using the “int 3” interruption instruction, triggering the execution of Handler_0.<br />
<b>Interlude: debugging a DLL in IDA Pro</b><br />
To make the reverse-engineering of some functions easier, debugging the code to observe function inputs and outputs can be an effective method.<br />
One simple way to <b>debug a DLL inside IDA </b>is to load the file as usual, then go to “Debugger -&gt;Process options&#8230;” and modify the following value:</p>
<ul>
<li>Application:
<ul>
<li> On a 64 bits version of Windows:
<ul>
<li>  “C:\Windows\SysWOW64\rundll32.exe” to debug a 32 bits library</li>
<li>  “C:\Windows\System32\rundll32.exe” to debug a 64 bits library</li>
</ul>
</li>
<li> On a 32 bits version of Windows:
<ul>
<li>  “C:\Windows\System32\rundll32.exe” to debug a 32 bits library</li>
<li>  Obviously, you cannot run (therefore debug) a 64 bits library on a 32 bits version of Windows</li>
</ul>
</li>
</ul>
</li>
<li> Parameters:
<ul>
<li>  “PATH_OF_YOUR_DLL”,functionToCall [function parameters if any]</li>
</ul>
</li>
</ul>
<p>Note: The file extension <b>must be “*.dll” </b>for rundll32.exe to accept it.</p>
<figure id="post-15621 media-15621" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15621 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I19.png" alt="" width="320" height="179" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I19.png 320w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I19-71x39.png 71w" sizes="auto, (max-width: 320px) 100vw, 320px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>IDA &#8220;Process options&#8230;&#8221; menu</i></span></div>
<div class="separator" style="clear: both; text-align: center;"></div>
<p>To test the configuration, just place a <b>breakpoint </b>at the entry point of the DLL:</p>
<figure id="post-15623 media-15623" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15623 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I20.png" alt="" width="640" height="353" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I20.png 640w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I20-346x191.png 346w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I20-71x39.png 71w" sizes="auto, (max-width: 640px) 100vw, 640px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>Placing a breakpoint on the entry point</i></span></div>
<p>Run your debugger (F9). If configured correctly, your debugger should break at the DLL entry point, allowing you to debug any DLL function</p>
<p><b>Handler_0 (0x10001260)</b><br />
Looking at Handler_0’s CFG (given below), we see that the function calls <b>two unknown functions </b>(0x100092C0 and 0x1000E61D). To quickly identify these functions, let’s debug the DLL, and look at the functions inputs/outputs:</p>
<p><u>sub_100092C0</u></p>
<figure id="post-15625 media-15625" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15625 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I21.png" alt="" width="178" height="91" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I21.png 178w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I21-71x36.png 71w" sizes="auto, (max-width: 178px) 100vw, 178px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><i><span style="font-size: x-small;">Function sub_100092C0() call</span></i></div>
<p>The function seems to take 3 arguments:</p>
<ul>
<li>A buffer (here named “Value”);</li>
<li>A value (here 0);</li>
<li>The size of the buffer (here 0x104).</li>
</ul>
<p>Let&#8217;s look at the buffer’s content <b>before and after the function call</b>:</p>
<figure id="post-15627 media-15627" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15627 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I22.png" alt="" width="320" height="134" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I22.png 320w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I22-71x30.png 71w" sizes="auto, (max-width: 320px) 100vw, 320px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>&#8220;Value&#8221; buffer before and after the call</i></span></div>
<p>The function prototype and its side effects correspond to the <b>memset </b>function.<u><br />
</u><br />
<u>sub_1000E61D</u></p>
<figure id="post-15629 media-15629" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15629 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I23.png" alt="" width="207" height="110" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I23.png 207w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I23-71x39.png 71w" sizes="auto, (max-width: 207px) 100vw, 207px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>Function sub_1000E61D() call</i></span></div>
<p>The function seems to take 4 arguments:</p>
<ul>
<li>An <b>integer </b>(here the PID of the process);</li>
<li>A <b>buffer </b>(here named “Value”);</li>
<li>The <b>size of the buffer</b> (here 0x104);</li>
<li>A <b>value </b>(here 0xA, or 10).</li>
</ul>
<p>Looking at the provided buffer’s content after the function call, we see that the representation in base 10 of the first integer passed in parameter is written in the provided buffer.</p>
<figure id="post-15631 media-15631" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15631 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I24.png" alt="" width="214" height="168" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I24.png 214w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I24-50x39.png 50w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I24-156x121.png 156w" sizes="auto, (max-width: 214px) 100vw, 214px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>Value buffer after the call</i></span></div>
<p>The function prototype and its side effects correspond to the <b>_itoa_s</b> function .</p>
<p><u>Handler_0 whole CFG and pseudo-code</u><br />
Here is the graph of the Handler_0 function:</p>
<figure id="post-15633 media-15633" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15633 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I25.png" alt="" width="400" height="365" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I25.png 400w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I25-209x191.png 209w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I25-43x39.png 43w" sizes="auto, (max-width: 400px) 100vw, 400px" /></figure>
<figure id="post-15633 media-15633" class="align-none">
<figure id="post-15633 media-15633" class="align-none">
<figure id="post-15675 media-15675" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15675 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I25bis.png" alt="" width="400" height="255" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I25bis.png 400w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I25bis-300x191.png 300w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I25bis-61x39.png 61w" sizes="auto, (max-width: 400px) 100vw, 400px" /></figure>
</figure>
</figure>
<figure id="post-15635 media-15635" class="align-none"></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>CFG of function Handler_0()</i></span></div>
<p>This corresponds to the following pseudo code:</p>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre>if isloaded(“python.dll”):
   pid = getpid()
else:
   pid = 0
setEnvironmentVariable(“mb_chall”, str(pid))
return EXCEPTION_CONTINUE_SEARCH</pre>
</div>
<p>The function<b> checks the presence of the python27.dll</b> library (normally loaded by the main program mb_crackme_2.exe) in the process address space, and sets the <b>“mb_chall” environment variable </b>consequently.<br />
This may be seen as an “anti-debug” trick, because running the DLL independently in a debugger makes the execution follow a different path.</p>
<p><b>Handler_1 (0x100011D0)</b><br />
The code of this handler is quite self-explanatory, being similar to the previous handler’s code:</p>
<figure id="post-15635 media-15635" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15635 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I26.png" alt="" width="400" height="350" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I26.png 400w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I26-218x191.png 218w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I26-45x39.png 45w" sizes="auto, (max-width: 400px) 100vw, 400px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;">
<figure id="post-15677 media-15677" class="align-none"><img loading="lazy" decoding="async" class="alignnone wp-image-15677 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I26bis.png" alt="" width="400" height="248" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I26bis.png 400w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I26bis-308x191.png 308w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I26bis-63x39.png 63w" sizes="auto, (max-width: 400px) 100vw, 400px" /></figure>
</div>
<div class="separator" style="clear: both; text-align: center;"></div>
<p>Once again, this corresponds to the following pseudo code:</p>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre>if getpid() == int(getenv(“mb_chall”):
   tmp = 6
else:
   tmp = 1
exceptionInfo-&gt;Context._Eip += tmp
return EXCEPTION_CONTINUE_EXECUTION</pre>
</div>
<p>After this handler, execution restarts at the address of original interruption (“int 3”) +1 or +6 (as presented in the pseudo-code above), whether performed checks pass or not.</p>
<figure id="post-15637 media-15637" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15637 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I27.png" alt="" width="640" height="150" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I27.png 640w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I27-437x102.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I27-71x17.png 71w" sizes="auto, (max-width: 640px) 100vw, 640px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<p>We thus continue the analysis at the <b>not_fail function</b> (0x100010D0).</p>
<p><b>not_fail (0x100010D0)</b><br />
The function only starts a thread and waits for it to terminate.</p>
<figure id="post-15639 media-15639" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15639 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I28.png" alt="" width="319" height="231" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I28.png 319w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I28-264x191.png 264w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I28-54x39.png 54w" sizes="auto, (max-width: 319px) 100vw, 319px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>CFG of not_fail() function</i></span></div>
<p>The created thread executes the <b>MainThread</b> (0x10001110) function, where our analysis continues.</p>
<p><b>MainThread (0x10001110)</b><br />
The function loops and calls the <b>EnumWindows</b>  API every second, which in turn calls the provided callback function (<b>EnumWindowsCallback</b>) on every window present on the desktop.<br />
<b><br />
</b></p>
<figure id="post-15641 media-15641" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15641 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I29.png" alt="" width="284" height="400" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I29.png 284w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I29-136x191.png 136w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I29-28x39.png 28w" sizes="auto, (max-width: 284px) 100vw, 284px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>CFG of MainThread() function</i></span></div>
<p><b>EnumWindowsCallback function (0x10005750)</b><br />
The function, called on each window, uses the <b>SendMessageA</b>  API with the WM_GETTEXT message to retrieve the window’s title.</p>
<figure id="post-15643 media-15643" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15643 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I30.png" alt="" width="320" height="175" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I30.png 320w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I30-71x39.png 71w" sizes="auto, (max-width: 320px) 100vw, 320px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>SendMessageA() call in MainThread()</i></span></div>
<p>After being converted to C++ std::string, the substrings <b>“Notepad”</b> and <b>“secret_console”</b> are searched in the window’s title.</p>
<div class="separator" style="clear: both; text-align: center;">
<figure id="post-15645 media-15645" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15645 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I31.png" alt="" width="363" height="404" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I31.png 363w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I31-172x191.png 172w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I31-35x39.png 35w" sizes="auto, (max-width: 363px) 100vw, 363px" /></figure>
</div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>Strings &#8220;Notepad&#8221; and &#8220;secret_console&#8221; searched for in window title</i></span></div>
<p>If both substrings are present, the window’s title is replaced by the hardcoded string <b>“Secret Console is waiting for the commands&#8230;”</b>, using the SendMessageA API along with the WM_SETTEXT message. The window is placed to the <b>foreground,</b> using the ShowWindow API call.</p>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;">
<figure id="post-15647 media-15647" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15647 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I32.png" alt="" width="295" height="330" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I32.png 295w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I32-171x191.png 171w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I32-35x39.png 35w" sizes="auto, (max-width: 295px) 100vw, 295px" /></figure>
<p><span style="font-size: x-small;"><i>Modification of the window&#8217;s title using SendMessageA()</i></span>
</div>
<p>The PID of the process corresponding to the window is then written in the “malware”’s console, and sub-windows of this window are enumerated, using the EnumChildWindows  API.The function <b>EnumChildWindowsCallback</b> (0x100034C0) is thus called on every sub-window.</p>
<figure id="post-15649 media-15649" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15649 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I33.png" alt="" width="438" height="309" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I33.png 438w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I33-271x191.png 271w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I33-55x39.png 55w" sizes="auto, (max-width: 438px) 100vw, 438px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>EnumChildWindows() function call</i></span></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i> </i></span></div>
<p><b>EnumChildWindowsCallback function (0x100034C0)</b><br />
This function gets the content of the sub-window using the SendMessageA API call:</p>
<figure id="post-15651 media-15651" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15651 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I34.png" alt="" width="436" height="222" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I34.png 436w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I34-375x191.png 375w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I34-71x36.png 71w" sizes="auto, (max-width: 436px) 100vw, 436px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>SendMessageA() call in EnumChildWindowsCallback() function</i></span></div>
<p>The substring <b>“dump_the_key”</b> is then searched in the retrieved content:</p>
<figure id="post-15653 media-15653" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15653 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I35.png" alt="" width="328" height="254" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I35.png 328w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I35-247x191.png 247w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I35-50x39.png 50w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I35-156x121.png 156w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I35-155x120.png 155w" sizes="auto, (max-width: 328px) 100vw, 328px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>Search for &#8220;dump_the_key&#8221;</i></span></div>
<p>If this string is found, this function calls a decryption routine <b>decrypt_buffer()</b> (0x100016F0) on a buffer (encrypted_buff), using the string “dump_the_key” as argument.</p>
<figure id="post-15655 media-15655" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15655 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I36.png" alt="" width="514" height="251" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I36.png 514w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I36-391x191.png 391w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I36-71x35.png 71w" sizes="auto, (max-width: 514px) 100vw, 514px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>Decrypting a hardcoded buffer using &#8220;dump_the_key&#8221; as key</i></span></div>
<p>Then, the “malware” loads the <b>actxprxy.dll </b>library into the process memory space. The first 4096 bytes (i.e. the first memory page) of the library is made writable using the VirtualProtect API call, and the decrypted payload is written at this location.</p>
<figure id="post-15657 media-15657" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15657 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I37.png" alt="" width="640" height="395" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I37.png 640w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I37-309x191.png 309w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I37-63x39.png 63w" sizes="auto, (max-width: 640px) 100vw, 640px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>Loading a library and writing the decrypted buffer at its location</i></span></div>
<p>Since the actxprxy.dll library is not used anywhere in the analyzed DLL after being re-written, it may be seen as a <b>covert communication channel </b>between the analyzed DLL and the main program mb_crackme_2.exe. After this, the function clears every allocated memory and exits. The created thread (see 4.2.6) therefore also exits, and the DllEntryPoint function call terminates, giving the control back to the main python script.</p>
<h3>Triggering the secret console</h3>
<p>As seen in the DLL analysis, to trigger the required conditions, a file named<b> “secret_console – Notepad”</b> is opened in a text editor. As such, the window title contains the mentioned substrings:</p>
<figure id="post-15659 media-15659" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15659 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I38.png" alt="" width="320" height="219" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I38.png 320w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I38-279x191.png 279w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I38-57x39.png 57w" sizes="auto, (max-width: 320px) 100vw, 320px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><i><span style="font-size: x-small;">Opening a file named &#8220;secret_console_Notepad.txt&#8221; on Notepad++</span></i></div>
<p>As expected, the title of the window is changed to “Secret Console is waiting for the commands…” by the malware. Writing “dump_the_key” in the window validates the second stage.</p>
<figure id="post-15661 media-15661" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15661 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I39.png" alt="" width="320" height="242" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I39.png 320w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I39-253x191.png 253w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I39-52x39.png 52w" sizes="auto, (max-width: 320px) 100vw, 320px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>Writing &#8220;dump_the_key&#8221; in the text editor</i></span></div>
<h1>Stage 3: the colors</h1>
<p>After validating the previous step, a message is printed on the console, asking the user to “guess a color”:</p>
<figure id="post-15663 media-15663" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15663 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I40.png" alt="" width="640" height="67" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I40.png 640w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I40-437x46.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I40-71x7.png 71w" sizes="auto, (max-width: 640px) 100vw, 640px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>Level 3 Message</i></span></div>
<p>The <b>three components (R, G and B) of a specific color</b>, with values going from 0 to 255, need to be entered to validate this step.</p>
<figure id="post-15665 media-15665" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15665 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I41.png" alt="" width="320" height="144" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I41.png 320w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I41-71x32.png 71w" sizes="auto, (max-width: 320px) 100vw, 320px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><span style="font-size: x-small;"><i>Level 3 failed guess message</i></span></div>
<h3>Understanding the code</h3>
<p>Looking back at the another.py’s main() function code, it seems that the corresponding operations are performed inside the <b>decode_pasted()</b> function.</p>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre></pre>
<pre>def main():
   [...]
      load_level2(decdata, len(decdata))
      user32_dll.MessageBoxA(None, 'You did it, level up!', 'Congrats!', 0)
      try:
         if decode_pasted() == True:
            user32_dll.MessageBoxA(None, '''Congratulations! Now save your flag and 
send it to Malwarebytes!''', 'You solved it!', 0)
            return 0</pre>
</div>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre>def decode_pasted():
    my_proxy = kernel_dll.GetModuleHandleA('actxprxy.dll')
    if my_proxy is None or my_proxy == 0:
        return False
    else:
        char_sum = 0
        arr1 = my_proxy
        str = ''
        while True:
            val = get_char(arr1)
            if val == '\x00':
                break
            char_sum += ord(val)
            str = str + val
            arr1 += 1

        print char_sum
        if char_sum != 52937:
            return False
        colors = level3_colors()
        if colors is None:
            return False
        val_arr = zlib.decompress(base64.b64decode(str))
        final_arr = dexor_data(val_arr, colors)
        try:
            exec final_arr
        except:
            print 'Your guess was wrong!'
            return False

        return True</pre>
</div>
<p>&nbsp;</p>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre></pre>
<pre>def dexor_data(data, key):
    maxlen = len(data)
    keylen = len(key)
    decoded = ''
    for i in range(0, maxlen):
        val = chr(ord(data[i]) ^ ord(key[i % keylen]))
        decoded = decoded + val
    return decoded</pre>
</div>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre></pre>
<pre>def level3_colors():
    colorama.init()
    print colorama.Style.BRIGHT + colorama.Fore.CYAN
    print '''Level #3: Your flag is almost ready! But before it will be revealed
, you need to guess it's color (R,G,B)!'''
    print colorama.Style.RESET_ALL
    color_codes = ''
    while True:
        try:
            val_red = int(raw_input('R: '))
            val_green = int(raw_input('G: '))
            val_blue = int(raw_input('B: '))
            color_codes += chr(val_red)
            color_codes += chr(val_green)
            color_codes += chr(val_blue)
            break
        except:
            print 'Invalid color code! Color code must be an integer (0,255)'
    print 'Checking: RGB(%d,%d,%d)' % (val_red, val_green, val_blue)
    return color_codes</pre>
</div>
<p>According to the decode_pasted() function, the decrypted buffer stored at the start of actxprxy.dll’s address space is read and:<br />
base64-decoded;</p>
<ul>
<li>zlib-decompressed;</li>
<li>XOR’ed against the user-provided colors values;</li>
<li>Executed by the Python exec function.</li>
</ul>
<p>To start our cryptanalysis, we <b>modify the decode_pasted() function</b> to dump the val_arr buffer before the dexor_data() operation, and rerun another.py, providing all required credentials:</p>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre>[...]
if colors is None:
   return False
val_arr = zlib.decompress(base64.b64decode(str))
with open("val_arr.bin", "wb") as f:
   f.write(val_arr)
   print "val_arr dumped !"
exit()
final_arr = dexor_data(val_arr, colors)
[...]</pre>
</div>
<p>&nbsp;</p>
<figure id="post-15667 media-15667" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15667 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I42.png" alt="" width="213" height="118" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I42.png 213w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I42-71x39.png 71w" sizes="auto, (max-width: 213px) 100vw, 213px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><i><span style="font-size: x-small;">Dumping the XOR&#8217;ed array</span></i></div>
<h3>Decrypting the val_arr buffer</h3>
<p>Knowing that the buffer is a string passed to the “exec” Python statement after being decrypted, it should represent a <b>valid Python source code</b>.<br />
To find the right key, the naïve solution would be to run a brute-force attack on all the possible “(R, G, B)” combinations, and look for printable solutions. This solution would need to perform 256^3 = 16’777’216 dexor_data() calls, which is feasible but <b>inefficient</b>.<br />
Instead, we perform 3 independent brute-force attacks on each R, G and B component, therefore performing 256 x 3 = 768 dexor_data() calls. The 3 brute-force attacks are performed on different “slices” of the val_arr string (of each of stride 3). We then test each combination of potential values previously found for each component.<br />
For example, if our 3 brute-force attacks indicate that:</p>
<ul>
<li>R can take values 2 and 37,</li>
<li>G can take values 77 and 78,</li>
<li>and B can only take the value 3,</li>
</ul>
<p>Then we test the combinations (2,77, 3), (37,77, 3), (2,78, 3) and (37,78, 3).</p>
<p>The following code implements our attack:</p>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre></pre>
<pre>import string
import itertools
from colorama import *
from another import dexor_data

with open("val_arr.bin", "rb") as f:
    val_arr = f.read()

#lists of possible values for R, G and B
potential_solutions = [list(), list(), list()]
for color in range(3): # separate bruteforce on R, G and B
    for xor_value in range(256): #testing all potential values
        valid = True
        for b in val_arr[color::3]: #extracting one every 3 characters, from index 
        # "color" (i.e. extracting all characters xored by the same "color" value)
            if chr(ord(b) ^ xor_value) not in string.printable:
                valid = False
                break
        if valid:
            potential_solutions[color].append(xor_value)

print "Possible values for R, G and B :", potential_solutions

for colors in itertools.product(*potential_solutions):
    print "Testing ", colors
    plaintext = dexor_data(val_arr, map(chr, colors))
    print repr(plaintext)
    if not raw_input("Does it seems right ? [Y/n]\n").startswith("n"):
       print "Executing payload :"
       exec plaintext
       break</pre>
</div>
<p>Executing this code gives us the solution instantly:</p>
<figure id="post-15669 media-15669" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15669 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I43.png" alt="" width="640" height="199" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I43.png 640w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I43-437x136.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/04/I43-71x22.png 71w" sizes="auto, (max-width: 640px) 100vw, 640px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="separator" style="clear: both; text-align: center;"><i><span style="font-size: x-small;">Decrypting the payload</span></i></div>
<p>The final flag appears in the console:</p>
<div style="background-color: #dfd2ee; border: 1px solid black; padding-left: 1%; padding-right: 1%; width: 100%;">
<pre></pre>
<pre>flag{"Things are not always what they seem; the first appearance 
deceives many; the intelligence of a few perceives what has been 
carefully hidden." - Phaedrus}</pre>
</div>
<h2>Conclusion</h2>
<p>This challenge was very interesting to solve, because apart from being an original crackme, it also included various topics that could be found during a real malware analysis. These topics included:</p>
<ul>
<li>DLL-rewriting techniques, here used as a kind of covert communication channel between a DLL and its main process;</li>
<li>“Non-obvious” anti-debugging tricks, like checking the presence of a known library in the process’ memory space to identify standalone DLL debugging;</li>
<li>Concealed malware downloading, using « harmless » formats (like PNG) to hide an executable payload from basic traffic analysis;</li>
<li>PyInstaller-based malware, (yes, sometimes malware writers can be lazy).</li>
</ul>
<p>Thanks MalwareBytes for this entertaining challenge!</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/06/malwarebytes-challenge-write-up/">Malwarebytes challenge write-up</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>2016 : les cyberattaques touchent la banque sur tous les fronts</title>
		<link>https://www.riskinsight-wavestone.com/en/2017/02/2016-cyberattaques-touchent-banque-fronts/</link>
		
		<dc:creator><![CDATA[B3noitL4diEu]]></dc:creator>
		<pubDate>Tue, 07 Feb 2017 16:38:56 +0000</pubDate>
				<category><![CDATA[Cyber for Financial Services]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Banque]]></category>
		<category><![CDATA[Cybercriminalité]]></category>
		<category><![CDATA[financial services cyber]]></category>
		<category><![CDATA[fraude]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[piratage]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=9410</guid>

					<description><![CDATA[<p>L’année 2016 aura connu de nombreux cas marquants de cybercriminalité dans le secteur financier. Des attaques d’ampleurs inédites ont eu lieu, selon des motifs variés mais ayant toujours des conséquences importantes quand elles ont réussi. De plus les relais multiples...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2017/02/2016-cyberattaques-touchent-banque-fronts/">2016 : les cyberattaques touchent la banque sur tous les fronts</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>L’année 2016 aura connu de nombreux cas marquants de cybercriminalité dans le secteur financier. <strong>Des attaques d’ampleurs inédites ont eu lieu</strong>, selon des motifs variés mais ayant toujours des conséquences importantes quand elles ont réussi. De plus les relais multiples de ces attaques par les médias les rendent d’autant plus <strong>dommageables en terme d’image pour les institutions financières touchées</strong>.  </em></p>
<p>&nbsp;</p>
<h2>Le secteur bancaire, une cible historique</h2>
<p>Les attaques contre le secteur financier ne sont pas une nouveauté, il s’agit même d’un secteur de prédilection pour les pirates agissant à des fins vénales. Mais en 2016 nous avons assisté à une <strong>diversification et à une intensification de ces attaques</strong>. En effet, au cours de l’année passée, plusieurs attaques majeures, motivées par l’attrait de gains financiers importants, ont été réalisées contre des banques de détail et d’investissement mais également contre des banques centrales. Sans viser à être exhaustif, cet article présente de manière synthétique certains des cas emblématiques.</p>
<p>Pour les banques, <strong>trois zones de risques</strong>, poreuses entre elles, sont clairement identifiées:</p>
<figure id="post-9411 media-9411" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-9411 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2017/02/BLU-1.png" width="854" height="631" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2017/02/BLU-1.png 854w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/02/BLU-1-259x191.png 259w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/02/BLU-1-768x567.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2017/02/BLU-1-53x39.png 53w" sizes="auto, (max-width: 854px) 100vw, 854px" /></figure>
<p>Depuis l’existence d’Internet, <strong>les failles des systèmes accessibles directement aux clients ont été largement exploitées</strong> par les cybercriminels qui ont continué à faire évoluer leurs techniques en 2016.</p>
<p>Les distributeurs de billets, très exposés historiquement, ont été visés par de <strong>nouveaux malwares</strong><strong>, </strong>notamment <a href="http://blog.trendmicro.com/trendlabs-security-intelligence/alice-lightweight-compact-no-nonsense-atm-malware/%20">ALICE</a> et <em><a href="https://www.fireeye.com/blog/threat-research/2016/08/ripper_atm_malwarea.html">RIPPER</a></em>. Ces malwares peuvent être installés sur la machine de deux façons différentes :</p>
<ul>
<li>En passant par le réseau auquel est connectée la machine pour accéder aux serveurs de gestion, nécessitant d’infiltrer le SI de la banque.</li>
<li>Directement sur le système d’exploitation de la machine à l’aide d’un port USB mis à nu.</li>
</ul>
<p>Le piratage des distributeurs de billets a résulté à la perte de plusieurs millions d’euros au cours de l’année passée pour différentes banques à travers le monde. En Europe, le groupe de cybercriminels <a href="https://www.helpnetsecurity.com/2016/11/22/cobalt-hackers-synchronized-atm-heists/"><em>Cobalt</em> </a>a piraté des distributeurs dans une douzaine de pays pour un montant inconnu. Des attaques similaires ont eu lieu à Taïwan et en Thaïlande avec le vol de 2,5M$ et 350k$ respectivement.</p>
<p>D’une autre manière, <strong>les DAB et TPE peuvent servir d’hôtes aux fameux « <em>Skimmers</em> »</strong>. Il s’agit d’un dispositif hardware plus ou moins discret <strong>permettant de récupérer l’empreinte de la carte des utilisateurs</strong>. Plusieurs types de « <em>Skimmers</em> » existent dont en particulier :</p>
<ul>
<li>Les <a href="https://www.youtube.com/watch?v=ll4f0Wim4pM"><em>Skimmers</em> externes</a>, reproduction de tout ou partie de la façade de la machine qui s’installe au-dessus du distributeur ou du terminal de paiement.</li>
<li>Les <a href="https://www.youtube.com/watch?v=5PiY97_xFUI"><em>Skimmers</em> internes</a>, s’installant directement dans le lecteur de carte de la machine .</li>
</ul>
<p>Cette seconde méthode très en vogue en 2016 est difficilement détectable car il n’y a pas de modification importante de l’aspect physique de la machine, seule une caméra externe est requise pour capturer le code PIN. De plus ces <em>Skimmers</em> internes n’affectent ni le système d’exploitation ni le fonctionnement de la machine.</p>
<p>Beaucoup plus connus, <strong>les malwares de type cheval de Troie, continuent d’évoluer et sont toujours largement utilisés pour récupérer les informations de paiements des clients</strong> ; certains d’entre eux sont spécialement développés pour les smartphones, notamment sur Android.</p>
<p>&nbsp;</p>
<h2>L’évolution des attaques vers les systèmes exposés et internes en 2016</h2>
<p>Les cas d’attaques les plus importants de l’années 2016 dénotent <strong>une évolution du mode opératoire des attaquants</strong> avec une préparation minutieuse qui dure jusqu’à plusieurs mois. Pour s’introduire dans le système d’information des institutions financières et le manipuler, des méthodes spécifiques doivent être suivies, en se basant sur le fonctionnement et les processus métier. Ces derniers sont étudiés longuement par les attaquants, afin d’agir efficacement et en toute discrétion.</p>
<p>Après ce temps de préparation et une fois le système d’information de la banque pénétré, les attaquants sont capables de manipuler les applications métier et de détourner des montants jusque-là impensables avec une seule attaque dont l’exécution ne dure que quelques heures.</p>
<p>Citons notamment en 2016 le record de l’année : <a href="https://www.wired.com/2016/05/insane-81m-bangladesh-bank-heist-heres-know/">81 M$ qui ont quitté « les coffres » de la Bangladesh Bank de façon non légitime</a>.</p>
<p><strong>Le mode opératoire de l’attaque sur la </strong><em><strong>Bangladesh Bank</strong>, </em>ayant eu lieu au mois de février, permet de mieux comprendre comment le détournement de telles sommes est possible.</p>
<p>Les attaquants ont commencé par<strong> ouvrir au mois de Mai 2015 des comptes à la banque <em>RCBC</em> aux Philippines</strong> sous de fausses identités. Ils ont ensuite réussi à s’introduire dans le SI de la <em>Bangladesh Bank, </em>par une faille non identifiée.</p>
<p>Vient alors la phase préparatoire lors de laquelle <strong>ils ont installé sur le réseau de la banque un malware espion spécialement développé</strong> qui les renseigne sur les horaires de fonctionnement de l’équipe en charge des transactions SWIFT afin de s’aligner sur les pratiques de la banque. Ils parviennent aussi à récupérer les identifiants des opérateurs ayant les droits de création, approbation et exécution de ces transactions.</p>
<p>A la suite de cette période de préparation, l’attaque est lancée en Février 2016 avec <strong>35 transactions frauduleuses ordonnées à la </strong><em><strong>New York FED</strong>,</em> gérant des comptes de la <em>Bangladesh Bank</em> pour un total de <strong>951 millions de dollars</strong> vers des comptes de la RCBC aux Philippines, créés au préalables et associés à l’industrie du jeu et des casinos. La principale nouveauté repose dans le fait que le malware utilisé modifie les confirmations de transactions, supprime les enregistrements électroniques des ordres et bloque l’impression des récépissés papier pour ne laisser aucune trace de la fraude.</p>
<p><strong>31 transactions seront bloquées</strong> par le système anti-fraude de la <em>New York FED</em> et les intermédiaires en cours de route, mais au final <strong>4 transactions sont validées pour un montant total de 81 millions de dollars.</strong> Les fonds seront ensuite retirés des comptes pour être blanchis. L’enquête implique le FBI et le gouverneur de la<em> Bangladesh Bank </em>a été limogé.</p>
<p>En réponse à cette attaque et à des tentatives similaires contre des banques Vietnamiennes et Equatoriennes, <a href="http://www.reuters.com/article/us-bangladesh-heist-swift-fed-idUSKCN0Y22O8">le SWIFT a lancé en 2016 un programme de sensibilisation pour ses clients ainsi que des recommandations pour une meilleure cyber sécurité</a>.</p>
<p>&nbsp;</p>
<h2>A quoi s’attendre pour la suite ?</h2>
<p>Ce contexte agité promet donc <strong>une année 2017 sous haute vigilance pour tous les acteurs du monde financier</strong>. La tendance à mener des attaques en profondeur contre leurs systèmes devrait s’intensifier, nécessitant une réelle évolution dans l’appréhension de la cybersécurité. Certaines annonces tonitruantes comme celle réalisé au Royaume-Uni « <a href="http://www.bbc.com/news/business-38517517">a major bank will fail</a> »  tente d’alerter sur cette situation.</p>
<p>La capacité des attaquants à agir directement sur les éléments clés du SI bancaire tels que le système anti-fraude et les applications métier impose aux banques de durcir leur sécurité informatique à tous les niveaux ; que ce soit par exemple avec la protection contre les intrusions, une meilleure gestion des identités ou des systèmes d’authentification forte pour les utilisateurs sensibles.</p>
<p>La spécificité du milieu bancaire à fonctionner sur <strong>un modèle de réseau fortement interconnecté</strong> implique que la cybersécurité des services partagés, tels que les systèmes de transactions internationaux ciblés à plusieurs reprises, soit <strong>abordée globalement afin de garantir un niveau de sécurité cohérent</strong> entre les établissements financiers.</p>
<p>&nbsp;</p>
<p><i>Article réalisé conjointement avec les travaux de préparation du panorama de la cybercriminalité du <a href="https://clusif.fr/">CLUSIF </a>2017 sur la partie &#8220;menaces touchant la finance&#8221;. </i></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2017/02/2016-cyberattaques-touchent-banque-fronts/">2016 : les cyberattaques touchent la banque sur tous les fronts</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Reverse Engineering &#8211; focus sur l’analyse dynamique de malware</title>
		<link>https://www.riskinsight-wavestone.com/en/2016/06/reverse-engineering-focus-sur-lanalyse/</link>
		
		<dc:creator><![CDATA[Vincent Nguyen]]></dc:creator>
		<pubDate>Tue, 21 Jun 2016 16:57:29 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Deep-dive]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[How to]]></category>
		<category><![CDATA[analyse dynamique]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[reverse engineering]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=15773</guid>

					<description><![CDATA[<p>L’analyse dynamique d’un fichier correspond à analyser l’exécution de ce fichier. Cette analyse permet alors de déterminer le comportement réel du malware, là où certains éléments de l’analyse statique peuvent être présents uniquement pour détourner l’attention de l’analyste, ou lui...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2016/06/reverse-engineering-focus-sur-lanalyse/">Reverse Engineering &#8211; focus sur l’analyse dynamique de malware</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="separator" style="clear: both; text-align: center;">
<div style="margin-left: 1em; margin-right: 1em;"></div>
</div>
<div style="text-align: justify;">L’analyse dynamique d’un fichier correspond à analyser l’exécution de ce fichier. Cette analyse permet alors de déterminer le comportement réel du <i>malware</i>, là où certains éléments de l’analyse statique peuvent être présents uniquement pour détourner l’attention de l’analyste, ou lui compliquer la tâche.</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-left: 0cm; margin-top: 5px;">
<div style="text-align: justify;">Une première forme d’analyse dynamique correspond à l’exécution du <i>malware</i> et à l’observation des modifications qu’il entraine sur le système. Cette analyse a le plus souvent pour but de déterminer les actions à effectuer pour supprimer le <i>malware</i>, et/ou créer une signature.</div>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-left: 0cm; margin-top: 5px;">
<div style="text-align: justify;"><i><span style="mso-fareast-language: FR;">Attention, </span>ce type d’analyse doit absolument être fait dans un environnement contrôlé (machine virtuelle, poste dédié et déconnecté du SI, etc.) afin de ne pas risquer la propagation de l’infection.</i></div>
</div>
<h2 style="margin-bottom: 15px; margin-top: 25px; text-align: justify;"><span style="mso-list: Ignore;">1)<span style="font: 7pt 'Times New Roman';">     </span></span>Analyse des opérations</h2>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">L’analyse dynamique permet la surveillance de nombreuses informations : les registres, le système de fichiers et les processus<i>. </i>Cette étape est au début assez fastidieuse étant donné que de nombreuses informations sont accessibles. Il existe différents outils permettant d’accéder à ces informations.<i> ProcessMonitor</i> est l’un de ces outils qui a l’avantage de permettre à l’analyste de filtrer ses recherches sur un exécutable, ce qui est très pratique pour l’analyse de <i>malwares</i>.</div>
<div style="text-align: center;">
<figure id="post-15774 media-15774" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-15774 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-2.jpg" alt="" width="604" height="163" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-2.jpg 604w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-2-437x118.jpg 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-2-71x19.jpg 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-2-600x163.jpg 600w" sizes="auto, (max-width: 604px) 100vw, 604px" /></figure>
</div>
<div class="MsoCaption" style="margin-bottom: 15px; margin-top: 15px; text-align: center;">
<div style="text-align: center;">
<div class="separator" style="clear: both; text-align: center;"></div>
</div>
<p><i>Figure 1 : Résultat d’une analyse de ProcessMonitor sur un malware appelé mm32.exe</i></p>
</div>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">L’analyse de ces différents éléments permet à l’analyste d’avoir une meilleure compréhension de l’activité du <i>malware</i>. Cependant, étant donné le nombre d’informations renvoyées par <i>ProcessMonitor</i> dont la plupart représentent des évènements standards du lancement d’un exécutable, l’analyse demande beaucoup de pratique et de la patience.</div>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;"></div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">Un autre outil permettant une analyse poussée des processus est <i>Process Explorer</i>. Il permet de lister les processus, les bibliothèques chargées par un processus, différentes informations sur ces processus, ainsi que des informations globales sur le système. L’avantage de cet outil est qu’il présente les informations sous forme d’arbre, exposant ainsi les relations entre les processus parents et enfants.</div>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">Les informations que <i>Process Explorer</i> renvoie sont le nom du processus, le PID (numéro d’identification du processus), l’utilisation du CPU, une description ainsi que le nom de l’entreprise ayant créé le binaire (champs laissés libres au créateur du binaire…). Par défaut les services sont surlignés en rose, les processus en bleu, les nouveaux processus en vert et les processus terminés en rouge. La vue se met alors à jour à chaque seconde. Lors de l’analyse de <i>malware</i> il est donc intéressant de repérer les différents processus qui sont modifiés ou créés afin de pouvoir enquêter dessus de manière plus approfondie.</div>
</div>
<div class="MsoCaption" style="margin-bottom: 15px; margin-top: 15px; text-align: center;">
<div style="text-align: center;">
<figure id="post-15776 media-15776" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-15776 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-3.jpg" alt="" width="605" height="454" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-3.jpg 605w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-3-255x191.jpg 255w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-3-52x39.jpg 52w" sizes="auto, (max-width: 605px) 100vw, 605px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<p><i>Figure 2 : Résultat de Process Explorer sur un exécutable</i></p>
</div>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">Ces techniques sont très efficaces pour comprendre ce que fait un exécutable, mais il ne faut pas négliger leur utilité pour déterminer si un document est malveillant ou non. Un moyen rapide de savoir si un PDF est malveillant, par exemple, est de lancer <i>Process Explorer</i> puis d’ouvrir le PDF et de regarder si de nouveaux processus sont créés.</div>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;"><u>Remarque :</u> Pour l’analyse de documents, il est souvent intéressant d’utiliser des versions intentionnellement non <i>patchées</i> des logiciels afin de s’assurer que l’attaque est efficace. Une bonne manière de faire cela est par exemple de créer plusieurs <i>snapshots</i> d’une machine virtuelle d’analyse, chaque <i>snapshot</i> ayant une version différente, et généralement assez âgée, des logiciels.</div>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">Pour l’analyse de registres, l’outil <i>Regshot</i> permet de comparer les registres sur deux <i>snapshots </i>différents. Un extrait de résultat de <i>Regshot</i> peut ressembler à la figure 3.</div>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">Dans ce résultat, le premier constat est la création d’un mécanisme de persistance <i>HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run</i> par le programme <i>ckr.exe</i>, le deuxième est la modification<i> </i>de la valeur de la <i>seed</i> pour le générateur de nombre aléatoire, ce qui représente un bruit habituel.</div>
<div style="text-align: center;">
<figure id="post-15778 media-15778" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-15778 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-4.jpg" alt="" width="605" height="460" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-4.jpg 605w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-4-251x191.jpg 251w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-4-51x39.jpg 51w" sizes="auto, (max-width: 605px) 100vw, 605px" /></figure>
</div>
</div>
<div class="MsoCaption" style="margin-bottom: 15px; margin-top: 15px; text-align: center;">
<div class="separator" style="clear: both; text-align: center;"></div>
<p><i>Figure 3 : Extrait de résultat de Regshot après lancement du programme ckr.exe</i></p>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;"></div>
<h2 style="margin-bottom: 15px; margin-top: 25px; text-align: justify;"><span style="mso-list: Ignore;">2)<span style="font: 7pt 'Times New Roman';">     </span></span>Analyse réseau</h2>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">De nombreux <i>malwares</i> récupèrent des ressources ou transmettent des informations sur le réseau (en particulier vers des serveurs C2 « Command &amp; Control »). De ce fait il est très intéressant de réaliser une analyse réseau pour déterminer les actions du <i>malware</i>. L’environnement d’analyse n’étant pas connecté à internet, il se peut qu’une partie des fonctionnalités du <i>malware</i> restent non accessibles. Cependant il est préférable de récupérer de telles informations en faisant une analyse manuelle approfondie plutôt que de permettre au <i>malware</i> de se propager (une sortie directe vers Internet peut néanmoins être fortement utile aux équipes d’analyse).</div>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">Quelques outils peuvent permettre d’effectuer une analyse réseau d’un <i>malware</i> :</div>
</div>
<div class="Enum1" style="margin-bottom: 4px; margin-top: 4px;">
<ul style="list-style-type: disc;">
<li style="text-align: justify;"><i>ApateDNS</i> permet de récupérer les requêtes DNS faites par le <i>malware</i>. Il permet également de simuler les réponses d’une adresse IP spécifiée en écoutant sur le port 53 de la machine locale <i>via</i> le protocole UDP. Il affiche alors les requêtes reçues en hexadécimal ou en ASCII. Par défaut <i>ApateDNS</i> utilise la passerelle (<i>gateway</i>) ou les paramètres de DNS courants dans les réponses DNS.</li>
</ul>
</div>
<div class="MsoCaption" style="margin-bottom: 15px; margin-top: 15px; text-align: center;">
<figure id="post-15780 media-15780" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-15780 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-5.png" alt="" width="605" height="439" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-5.png 605w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-5-263x191.png 263w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-5-54x39.png 54w" sizes="auto, (max-width: 605px) 100vw, 605px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<p><i>Figure 4 : Interception des requêtes DNS et simulation des réponses par ApateDNS en utilisant l’IP 192.168.120.1</i></p>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;"></div>
<div class="Enum1" style="margin-bottom: 4px; margin-top: 4px;">
<ul style="list-style-type: disc;">
<li style="text-align: justify;"><i>Netcat</i> permet le scan de port, <i>tunneling</i>, <i>proxying</i>, transfert de ports et bien d’autres choses sur des connections aussi bien entrantes que sortantes. Il existe deux modes de fonctionnement pour <i>Netcat</i>, le mode écoute, pour lequel <i>Netcat</i> agit comme un serveur, et le mode connexion pour lequel il agit comme un client.</li>
</ul>
</div>
<div class="Enum1Suite">
<div style="text-align: justify;"><u>Remarque :</u> les <i>malwares</i> utilisent souvent les ports 80 et 443 (HTTP et HTTPS respectivement) car ces ports ne sont généralement pas bloqués par les différents équipements de sécurité sur le réseau des entreprises (firewall, proxy, etc.).</div>
</div>
<div class="Enum1Suite">
<div style="text-align: justify;"><u>Remarque 2 :</u> certains <i>malwares</i> simulent des connexions usuelles afin de cacher leur comportement et tirer parti d’une méconnaissance de nombreux analystes réseau qui ne se concentrent que sur le début d’une session. Par exemple, en figure 5 le <i>reverse shell RShell</i> est instancié avec une redirection du domaine <i>www.google.com</i> vers l’hôte local 127.0.0.1 à l’aide d’<i>ApateDNS</i>. L’analyste écoute ensuite le trafic réseau sur le port 80 local avec <i>Netcat</i>.</div>
</div>
<div class="Enum1Suite">
<div style="text-align: justify;">Dans ce résultat, <i>RShell</i> simule une requête POST à <i>www.google.com</i> (comme le montre le point 2 sur la figure) mais par la suite, l’analyste récupère bien un <i>shell</i> (visible sur le point 3).</div>
</div>
<div class="MsoCaption" style="margin-bottom: 15px; margin-top: 15px; text-align: center;">
<figure id="post-15782 media-15782" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-15782 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-6.jpg" alt="" width="605" height="344" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-6.jpg 605w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-6-336x191.jpg 336w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-6-69x39.jpg 69w" sizes="auto, (max-width: 605px) 100vw, 605px" /></figure>
<div class="separator" style="clear: both; text-align: center;"></div>
<p><i>Figure 5 : Résultat renvoyé par Netcat lors de l’exécution de RShell en redirigeant les requêtes vers l’hôte grâce à ApateDNS</i></p>
</div>
<div class="Enum1" style="margin-bottom: 4px; margin-top: 4px;">
<ul style="list-style-type: disc;">
<li style="text-align: justify;"><i>Wireshark</i> permet la capture de paquets et de création de logs pour le trafic réseau. Il permet la visualisation, l’analyse de trames et l’analyse en détail de paquets individuels.</li>
</ul>
</div>
<div class="MsoCaption" style="margin-bottom: 15px; margin-top: 15px; text-align: center;">
<div class="separator" style="clear: both; text-align: center;"></div>
<figure id="post-15784 media-15784" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-15784 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-7.png" alt="" width="566" height="398" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-7.png 566w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-7-272x191.png 272w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-7-55x39.png 55w" sizes="auto, (max-width: 566px) 100vw, 566px" /></figure>
<p><i>Figure 6 : Capture d’écran d’une analyse Wireshark</i></p>
</div>
<div class="Enum1Suite">
<div style="text-align: justify;">Une des fonctionnalités très utiles de <i>Wireshark</i> est la fonctionnalité <i>Follow TCP stream</i> qui permet à partir d’un paquet de reconstituer le flot entier auquel il appartient.</div>
</div>
<div class="separator" style="clear: both; text-align: center;"></div>
<div class="MsoCaption" style="margin-bottom: 15px; margin-top: 15px; text-align: center;">
<div>
<figure id="post-15786 media-15786" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-15786 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-8.jpg" alt="" width="605" height="373" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-8.jpg 605w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-8-310x191.jpg 310w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-8-63x39.jpg 63w" sizes="auto, (max-width: 605px) 100vw, 605px" /></figure>
</div>
<div style="text-align: center;">Figure 7 : Fonctionnalité <i>Follow TCP Stream</i> de <i>Wireshark</i></div>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;"><i>Wireshark</i> peut permettre à l’analyste de comprendre comment le <i>malware</i> réalise ses communications réseau.</div>
</div>
<h2 style="margin-bottom: 15px; margin-top: 25px; text-align: justify;"><span style="mso-list: Ignore;">3)<span style="font: 7pt 'Times New Roman';">     </span></span>Analyse via débogueur</h2>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">Étape la plus complexe de l’analyse, l’analyse dynamique avancée correspond au passage de l’exécutable dans un débogueur afin de déterminer les actions qu’il effectue les unes après les autres, ainsi que les différents états qu’il génère sur le poste analysé. Il existe plusieurs débogueurs utilisables pour cette étape, notamment <i>IDA Pro</i>, <i>OllyDbg</i> et <i>WinDbg</i>.</div>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">Cette étape est extrêmement efficace mais nécessite de nombreuses connaissances et beaucoup de temps. Dans cette partie sera présenté un aperçu de ce qu’il est possible de faire avec un débogueur. Il est important de retenir que l’analyse dynamique révèle ce que le <i>malware</i> fait véritablement, contrairement à l’analyse statique qui montre ce que le <i>malware</i> est en théorie capable de faire. Certains bouts de code présents dans le <i>malware</i> peuvent en effet ne jamais être appelés, et les repérer durant l’analyse statique peut induire en erreur l’analyste sur l’action du <i>malware</i>.</div>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">L’utilisation d’un débogueur permet également d’obtenir des informations impossibles à récupérer avec un désassemblage, comme par exemple les valeurs prises par les registres au fur et à mesure de l’exécution.</div>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">Il existe en fait deux types de débogueurs, ceux dits <i>source-level</i> qui sont généralement intégrés dans les <i>IDE</i> et bien connus des développeurs, leur permettant d’agir sur le code source afin de déterminer les comportements étranges de leurs programmes, et ceux dits <i>assembly-level</i> ou <i>low-level</i> qui agissent sur le code assembleur. C’est ce deuxième type de débogueur qui est utilisé par les analystes de <i>malware</i>, étant donné qu’ils n’ont pas accès au code source de l’application.</div>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">De même il existe deux niveaux de débogage, celui en mode utilisateur, où le débogueur est lancé sur le même système d’exploitation que le programme en cours d’exécution, et celui plus complexe en mode noyau, qui permet de déboguer des applications ayant ce niveau d’interactions, mais qui nécessite deux machines reliées, l’une faisant tourner le programme, et l’autre permettant le débogage. Une deuxième machine est en effet nécessaire car il n’existe qu’un noyau par système d’exploitation, et si un <i>breakpoint</i> est mis sur une instruction exécutée par ce noyau, plus aucune application ne pourra répondre, le débogueur compris.</div>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">Dans les deux cas d’exécution, le résultat sera la mise en suspens du programme. Dans le premier cas le programme sera stoppé dès le point d’entrée (sauf configuration particulière) alors que dans le deuxième il sera arrêté là où il se trouvait. Une fois cela effectué, il est possible d’agir de différentes manières sur le programme :</div>
<ul style="list-style-type: disc;">
<li style="text-align: justify;">Avancer d’une instruction (<i>single-stepping</i>) : cette action est généralement utilisée uniquement sur les passages identifiés comme importants afin d’obtenir des détails sur le fonctionnement comme les valeurs prises par les registres.</li>
<li style="text-align: justify;">Avancer d’une fonction (<i>Stepping-over</i>) : cela peut permettre de passer des détails inutiles. Par exemple si le programme appelle la fonction <i>LoadLibrary</i>, il n’est pas nécessaire de rentrer dans les détails de cette fonction.<span style="font: 7pt 'Times New Roman';"> </span></li>
<li style="text-align: justify;">Rentrer dans une fonction (<i>Stepping-into</i>) : en opposition à l’action précédente, il peut parfois être intéressant de rentrer dans une fonction pour en comprendre les détails.</li>
<li style="text-align: justify;">Avancer jusqu’au prochain <i>breakpoint</i> : pour cela il faut souvent placer un <i>breakpoint</i> plus loin dans le code et relancer l’exécution, le débogueur s’arrêtera automatiquement au <i>breakpoint</i>.</li>
<li style="text-align: justify;">Modifier l’exécution d’un programme : par exemple pour éviter l’appel à une fonction, il est possible de mettre un <i>breakpoint</i> sur cette fonction et, lorsque l’interruption est levée, changer le pointeur d’instruction à après son appel.</li>
</ul>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">Il existe trois types de <i>breakpoints</i> :</div>
</div>
<div class="Enum1" style="margin-bottom: 4px; margin-top: 4px;">
<ul style="list-style-type: disc;">
<li style="text-align: justify;">Les <i>software breakpoints</i> : ces points d’arrêt sont utilisés pour faire en sorte que le programme s’arrête lorsque l’instruction sur laquelle ils sont placés est appelée. Pour réaliser cela, le débogueur remplace le premier octet de l’instruction par <i>0xCC</i>, l’instruction pour INT3.</li>
</ul>
<div style="text-align: center;">
<figure id="post-15788 media-15788" class="align-none"><img loading="lazy" decoding="async" class="size-full wp-image-15788 aligncenter" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-9.png" alt="" width="512" height="111" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-9.png 512w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-9-437x95.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2021/05/Image-9-71x15.png 71w" sizes="auto, (max-width: 512px) 100vw, 512px" /></figure>
</div>
</div>
<div class="MsoCaption" style="margin-bottom: 15px; margin-top: 15px; text-align: center;">
<div class="separator" style="clear: both; text-align: center;"></div>
<p>Figure 8 : Remplacement du premier octet de l’instruction par 0xCC lors d’un <i>software breakpoint</i>.</p>
</div>
<div class="Enum1" style="margin-bottom: 4px; margin-top: 4px;">
<ul style="list-style-type: disc;">
<li style="text-align: justify;">Les <i>hardware breakpoints</i> : ils sont placés sur une adresse mémoire, et déclenchés lorsque le programme tente d’accéder à cette ressource. L’avantage est qu’ils ne dépendent pas de la valeur présente dans cette adresse mémoire, et qu’ils interviennent à l’accès et non à l’exécution. Néanmoins ils nécessitent des registres particuliers qui sont en nombre limités sur un système.</li>
</ul>
</div>
<div class="Enum1" style="margin-bottom: 4px; margin-top: 4px;">
<ul style="list-style-type: disc;">
<li style="text-align: justify;">Les <i>conditional breakpoints</i> : ce sont des <i>software breakpoints</i> qui ne vont déclencher l’arrêt que si une certaine condition est vérifiée. Cela peut par exemple être utile si l’on veut s’arrêter à l’appel d’une fonction que si un certain paramètre est appelé.</li>
</ul>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;"></div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">Ces différentes techniques d’analyse dynamique viennent en complément d’une analyse statique.</div>
</div>
<div class="MsoNormalIndent" style="margin-bottom: 5px; margin-top: 5px;">
<div style="text-align: justify;">Il convient néanmoins de prendre toutes les précautions nécessaires avant de se lancer dans une analyse de malware. Chaque résultat obtenu par les analystes doit être contrevérifié pour s’assurer qu’aucune technique anti-reverse n’est mise en œuvre dans le binaire.</div>
</div>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2016/06/reverse-engineering-focus-sur-lanalyse/">Reverse Engineering &#8211; focus sur l’analyse dynamique de malware</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>De « I Love You » à « Blaster », va-t-on voir un retour des codes malveillants du passé ?</title>
		<link>https://www.riskinsight-wavestone.com/en/2014/02/de-i-love-you-a-blaster-va-t-on-voir-un-retour-des-codes-malveillants-du-passe/</link>
		
		<dc:creator><![CDATA[Gérôme Billois]]></dc:creator>
		<pubDate>Fri, 14 Feb 2014 10:16:43 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[audit & pentesting]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[virus informatique]]></category>
		<guid isPermaLink="false">http://www.solucominsight.fr/?p=5052</guid>

					<description><![CDATA[<p>Les virus informatiques existent quasiment depuis l’apparition de l’informatique. Si I Love You a été le premier virus « médiatique », leur histoire remonte bien au-delà. Souvenons-nous de Creeper, identifié comme le premier virus, ou encore du ver Morris qui circulait déjà...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2014/02/de-i-love-you-a-blaster-va-t-on-voir-un-retour-des-codes-malveillants-du-passe/">De « I Love You » à « Blaster », va-t-on voir un retour des codes malveillants du passé ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Les virus informatiques existent quasiment depuis l’apparition de l’informatique. Si I Love You a été le premier virus « médiatique », leur histoire remonte bien au-delà. Souvenons-nous de Creeper, identifié comme le premier virus, ou encore du ver Morris qui circulait déjà aux prémices d’internet. Durant les années 80 à 2000, la motivation première de ces inventeurs de codes malveillants était le défi technique… et la notoriété. Avec un certain succès ! « I Love you » a défrayé la chronique, a fait la une des différents médias et a même obligé le parlement britannique à fermer sa messagerie électronique. Ses auteurs, deux jeunes Philippins, ont connu une notoriété &#8211; dont avec le recul &#8211; ils se seraient sans doute bien passés.</em></p>
<h2>Des virus ou vers massifs : les premiers impacts généralisés</h2>
<p>Les codes malveillants ont ensuite évolué, devenant de plus en plus visibles et entraînant des impacts bien réels dans les entreprises. C’est au début des années 2000 qu’ils ont fait le plus parler d’eux. Nimda (2001), Blaster (2003), Sasser (2004), tous ces noms donnent encore des sueurs froides aux responsables des postes de travail ou des réseaux. Ces codes malveillants entraînaient des indisponibilités massives en saturant les réseaux et ont mis en lumière les vulnérabilités et la fragilité du SI. Leurs effets sont somme toute restés limités à des indisponibilités et à des efforts humains importants de nettoyage au sein de la DSI. Conficker marque le dernier évènement marquant de cette catégorie… et il date maintenant de 2008. On trouve encore dans certains SI un peu de ces « anciens » codes malveillants, assez simples à nettoyer et dont on peut se protéger par des mesures basiques (application de correctif, blocage de flux sur les réseaux…).</p>
<h2>Au-delà des dénis de service, les <em>malwares</em> deviennent des plateformes d’espionnage et de destruction</h2>
<p>Aujourd’hui la situation a bien changé, et <strong>depuis le début des années 2010, nous voyons apparaître des codes malveillants d’un tout autre niveau</strong>. Des codes très impactants et pouvant provoquer des incidents majeurs. Nous  pouvons citer les <em>malwares</em> « incapacitants » ou « destructeurs », comme ceux ayant visé la Corée ou l’Arabie Saoudite, et ayant entraîné la destruction de postes de travail, ou encore le fameux <em>ransomware</em> Cryptolocker qui rend les données inaccessibles. Dans cette catégorie, <strong>Stuxnet représente certainement le code malveillant le plus abouti sur les systèmes industriels.</strong></p>
<p>Certains codes malveillants sont aussi capables de devenir de véritables espions de l’activité d’une entreprise. Les fameux Gauss, Duqu, ou encore très récemment The Mask, sont capables de s’installer sur le SI d’une entreprise, de prendre le contrôle de postes de travail et d’exfiltrer des informations très sensibles sans être facilement détectés. Aujourd’hui ces codes malveillants sont issus de vrais groupes organisés, dotés de moyens importants et d’équipes entraînées. La révélation de The Mask le montre bien : le code malveillant et son infrastructure de contrôle disposaient de mécanismes pour bloquer les équipes des éditeurs de sécurité et une fois révélé, toute l’infrastructure a été décommissionée en 4 jours. L’organisation derrière ce <em>malware</em> avait bien prévu un <em>« kill switch »</em> pour disparaître en cas de compromission. Le changement de niveau technique et de moyens est bien réel, car les enjeux eux aussi ont beaucoup évolué depuis les années 1980 et la digitalisation progressive de notre société.</p>
<h2>La fin du support de Window XP verra-t-elle ressurgir des menaces historiques ?</h2>
<p>Il est évident que des codes malveillants « avancés » vont être révélés régulièrement. Les attaquants voient tout l’intérêt de continuer à faire évoluer leurs « armes numériques » et la montée en puissance est encore en cours. Les révélations sur la NSA montrent que les services de renseignement ont encore un cran d’avance avec des mécanismes d’attaques avancés, très discrets, et prévus pour se cacher en cas d’investigation.</p>
<p>Mais des problèmes que l’on croyait appartenir au passé reviendront-ils  à court terme ? En effet la fin du support de Windows XP peut faire ressurgir la crainte d’un ver réseau incapacitant qui se répandrait sur les systèmes d’information, utilisant encore cette version du système d’exploitation. La crainte est réelle dans les entreprises face à cet ancien type de menaces, et nous accompagnons de nombreuses structures qui se préparent à cette éventualité en revoyant leur processus de crise et en prévoyant des moyens de réactions et de préventions adéquates aujourd’hui.</p>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2014/02/de-i-love-you-a-blaster-va-t-on-voir-un-retour-des-codes-malveillants-du-passe/">De « I Love You » à « Blaster », va-t-on voir un retour des codes malveillants du passé ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Que souhaiter pour la sécurité de l’information en 2014 ?</title>
		<link>https://www.riskinsight-wavestone.com/en/2014/01/que-souhaiter-pour-la-securite-de-linformation-en-2014/</link>
		
		<dc:creator><![CDATA[Gérôme Billois]]></dc:creator>
		<pubDate>Mon, 06 Jan 2014 17:00:58 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[ANSSI]]></category>
		<category><![CDATA[LPM]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[piratage]]></category>
		<category><![CDATA[security architecture]]></category>
		<guid isPermaLink="false">http://www.solucominsight.fr/?p=4824</guid>

					<description><![CDATA[<p>2013 aura été une année mouvementée pour la sécurité de l’information. Les événements se sont succédés à une vitesse impressionnante. Les révélations de Mandiant sur les moyens d’attaques du côté de la Chine ont déjà près d’un an et depuis...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2014/01/que-souhaiter-pour-la-securite-de-linformation-en-2014/">Que souhaiter pour la sécurité de l’information en 2014 ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>2013 aura été une année mouvementée pour la sécurité de l’information. Les événements se sont succédés à une vitesse impressionnante. Les révélations de <a title="Intelreport - Mandiant" href="http://intelreport.mandiant.com/" target="_blank" rel="noopener noreferrer">Mandiant</a> sur les moyens d’attaques du côté de la Chine ont déjà près d’un an et depuis juin, la NSA et Snowden occupent le devant de la scène. Au-delà de ces deux évènements médiatiques, une succession d’annonces, d’attaques ou d’incidents ont rythmé l’année passée.</p>
<p>Après ces révélations, 2014 devra être une année de progression pour la communauté dans son ensemble. Les directions sont connues et les principes partagés. Néanmoins, leur promotion et leur application se feront sur  2014 !</p>
<p>2013 aura fait avancer la prise de conscience… Que peut –on souhaiter à la sécurité de l’information 2014 ?</p>
<h2>Une sécurité plus transparente</h2>
<p>C’est possible ! L’exemple de l’intégration de la reconnaissance biométrique à l’iPhone 5S le montre. Même si la solution n’est pas parfaite, elle a permis d’augmenter significativement le niveau de sécurité des personnes  qui n’utilisent pas de code de verrouillage en raison de la gêne qu’il représente. Au premier rang desquelles on peut citer <a title="News cnet - Yahoo's Mayer gives phone passcodes a pass" href="http://news.cnet.com/8301-1009_3-57602541-83/yahoos-mayer-gives-phone-passcodes-a-pass/" target="_blank" rel="noopener noreferrer">la PDG de Yahoo, Marisa Meyer</a>…</p>
<h2> Une sécurité plus ancrée dans le quotidien de la DSI</h2>
<p>Un chemin important reste à parcourir pour maintenir une hygiène de base dans le SI. La question de l’application des correctifs et des mises à jour en est un exemple frappant. L’ANSSI pousse dans ce sens avec ses 40 règles d’hygiène. Le vote de la loi de Programmation militaire ne fera que renforcer cette orientation pour les structures concernées. Et rappelons que <a title="Ars technica - How hackers made minced meat of Department of Energy networks" href="http://arstechnica.com/security/2013/12/how-hackers-made-minced-meat-of-department-of-energy-networks/" target="_blank" rel="noopener noreferrer">même les structures les plus visés par des attaques ne sont pas encore toutes au point</a> sur ces sujets !</p>
<h2>Une sécurité mieux appropriée par les métiers</h2>
<p>Nous avons assisté en 2013 à une multiplication des attaques informatiques visant des activités métiers &#8211; comme les <a title="SC Magazine - Banks investigate security breach allegations" href="http://www.scmagazineuk.com/banks-investigate-security-breach-allegations/article/319643/" target="_blank" rel="noopener noreferrer">fraudes dans les agences Santander ou RBS</a>, le premier <a title="blogs.technet - Carberp-based trojan attacking SAP" href="http://blogs.technet.com/b/mmpc/archive/2013/11/20/carberp-based-trojan-attacking-sap.aspx" target="_blank" rel="noopener noreferrer">malware visant SAP</a> ou encore les<a title="IBT - Global Bank ATM Cyber Heist Earns Criminals $45m in Hours" href="http://www.ibtimes.co.uk/cyber-crime-bank-theft-45m-27-countries-466578" target="_blank" rel="noopener noreferrer"> attaques ciblées sur les systèmes gérant les plafonds de paiements de carte bancaire</a>. Elles montrent aux métiers que lorsqu’un incident survient, certes le SI est touché, mais les cibles finales sont bien les données des métiers ! Ces cas entraînent des prises de conscience fortes. Nous ne pouvons évidemment pas souhaiter d’en voir plus, mais espérer que ces incidents auront été des aiguillons suffisamment forts pour montrer aux métiers, au-delà même des entreprises touchées, l’importance de leur implication au quotidien.</p>
<h2>Une sécurité plus à même de détecter et de réagir en cas d’incidents</h2>
<p>2013 aura connu son lots d’incidents. Toutes les menaces ont été mises sur le devant de la scène. États avec le rapport APT1 et les <a title="The Guardian - NSA" href="http://www.theguardian.com/world/nsa" target="_blank" rel="noopener noreferrer">révélations sur la NSA</a>, cybercriminels avec l’arrestation du plusieurs profils de haut niveau (<a title="Krebson Security - Meet Paunch: The Accused Author of the BlackHole Exploit Kit" href="http://krebsonsecurity.com/2013/12/meet-paunch-the-accused-author-of-the-blackhole-exploit-kit/" target="_blank" rel="noopener noreferrer">Paunch</a> par exemple) et des attaques destructrices (<a title="zdnet - South Korea hacks blamed on 'Dark Seoul Gang'" href="http://www.zdnet.com/south-korea-hacks-blamed-on-dark-seoul-gang-7000017382/" target="_blank" rel="noopener noreferrer">Corée du Sud</a>) ou paralysantes (<a title="news.techworld - Cryptolocker scrambles eight years of data belonging to US town hall" href="http://news.techworld.com/security/3495635/cryptolocker-scrambles-eight-years-of-data-belonging-us-town-hall/" target="_blank" rel="noopener noreferrer">Cryptolocker</a>). Tout ceci montre clairement que les incidents peuvent se produire et qu’il n’est pas toujours possible de les éviter. Il faut donc se préparer à réagir efficacement !</p>
<h2>Une sécurité qui anticipe les innovations</h2>
<p>Les évolutions se succèdent dans la société et la sécurité doit les accompagner si elle n’arrive pas à les devancer. Les objets connectés sont aujourd’hui au cœur de toutes les attentions, et 2013 nous a montré leurs vulnérabilités. <a title="Saurik - Exploiting a Bug in Google's Glass" href="http://www.saurik.com/id/16" target="_blank" rel="noopener noreferrer">Lunettes Google Glass</a>, voiture Ford ou Toyota, <a title="ExtremeTech - Philips Hue LED smart lights hacked, home blacked out by security researcher" href="http://www.extremetech.com/electronics/163972-philips-hue-led-smart-lights-hacked-whole-homes-blacked-out-by-security-researcher" target="_blank" rel="noopener noreferrer">ampoules Philips Hue</a>, drone Parrot, tous ces systèmes ont été piratés. Et sur ce volet, les efforts de sécurité doivent être réalisé en amont, en effet, il sera très complexe de les mettre à jour une fois distribués sur le terrain !</p>
<p>La plupart des membres de la communauté de la sécurité de l’information partagent déjà ces orientations, mais il est bon de les rappeler et de les confirmer afin qu’elles guident nos actions sur 2014 !</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2014/01/que-souhaiter-pour-la-securite-de-linformation-en-2014/">Que souhaiter pour la sécurité de l’information en 2014 ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Un antivirus sur votre PC entreprise en 2013 ? Pour quoi faire ?</title>
		<link>https://www.riskinsight-wavestone.com/en/2013/05/un-antivirus-sur-votre-pc-entreprise-en-2013-pour-quoi-faire/</link>
		
		<dc:creator><![CDATA[Chadi Hantouche]]></dc:creator>
		<pubDate>Wed, 22 May 2013 11:51:38 +0000</pubDate>
				<category><![CDATA[Cloud & Next-Gen IT Security]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[poste de travail]]></category>
		<category><![CDATA[security architecture]]></category>
		<guid isPermaLink="false">http://www.solucominsight.fr/?p=3752</guid>

					<description><![CDATA[<p>Voilà plusieurs années qu’aucune épidémie virale majeure n’a eu lieu. À  l’heure des attaques ciblées, des dénis de service ou encore des piratages complexes de réseaux industriels, de plus en plus de voix  remettent en cause la pertinence de disposer...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2013/05/un-antivirus-sur-votre-pc-entreprise-en-2013-pour-quoi-faire/">Un antivirus sur votre PC entreprise en 2013 ? Pour quoi faire ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Voilà plusieurs années qu’aucune épidémie virale majeure n’a eu lieu. À  l’heure des attaques ciblées, des dénis de service ou encore des piratages complexes de réseaux industriels, de plus en plus de voix  remettent en cause la pertinence de disposer d’un antivirus sur le poste de travail.</p>
<p>Certes, les attaques évoluent, exploitant de plus en plus des vulnérabilités non dévoilées (type 0-days), ou faisant appel à des méthodes de phishing avancées contre lesquels les antivirus paraissent bien impuissants.</p>
<p>Même s’ils sont aujourd’hui loin d’être suffisants, leur utilité est pourtant toujours réelle.</p>
<h2> <strong>De l’antivirus au client unique de sécurité, les éditeurs ont fait évoluer leur offre</strong></h2>
<p>L’outil désigné par « antivirus » couvre en fait, dans la majorité des cas, plusieurs fonctions : antivirus (et de manière plus générale, antimalware), mais aussi pare-feu personnel, Host IPS (HIPS), outil de contrôle des ports USB…</p>
<p>C’est ce que l’on appelle le « client unique de sécurité » sur le poste de travail.</p>
<p>Il constitue aujourd’hui un rempart évident contre les infections, en particulier celles qui sont involontaires (clé USB infectée) ou récurrentes (virus anciens qui réapparaissent ponctuellement).</p>
<p>L’expérience des nombreux audits menés par Solucom montre qu’il protège parfois aussi contre des attaques plus complexes. Il peut par exemple détecter l’ exploitation d’une vulnérabilité pour laquelle le système n’aurait pas reçu le correctif, de type Conficker.</p>
<p>Il suffit d’ailleurs de se connecter à une console antivirus d’entreprise pour s’en convaincre : les détections/suppressions de virus sont encore nombreuses et régulières. En particulier, on constate souvent un pic lors des fameux scans hebdomadaires, souvent décriés par les utilisateurs pour les ralentissements qu’ils provoquent sur les postes (et leur manque d’efficacité supposé).</p>
<p>Plusieurs initiatives de grands comptes visant à diminuer leur fréquence ont d’ailleurs vu le jour.Elles n’ont jamais abouti, tant ces scans paraissent aujourd’hui encore  nécessaires &#8211; ne serait-ce que dans un rôle de « voiture-balai » afin de nettoyer le résidu récurrent de logiciels malveillants en tout genre. En revanche, une approche réaliste pour réduire le temps de scan est possible : réaliser un scan différentiel. Seuls les fichiers modifiés par rapport à la semaine précédente sont scannés.</p>
<h2><strong> </strong>Le futur des antivirus est… dans le Cloud !</h2>
<p><strong> </strong>Pour autant, les limites des antivirus ne font que s’affirmer depuis des années :</p>
<ul>
<li> Les malwares sont de plus en plus complexes, leurs variantes innombrables, et même les éditeurs les plus réactifs ne sont plus capables de suivre la cadence.</li>
</ul>
<ul>
<li>Dans les meilleurs cas, les définitions virales sont mises à jour quotidiennement sur les postes de travail : c’est déjà trop au vu des vitesses de propagation.</li>
</ul>
<p>Un problème d’historique apparaît également : comment cumuler toutes les définitions de virus anciens et nouveaux, sans que la taille des fichiers contenant ces définitions n’explose, ralentissant encore le poste de travail, tout en nécessitant de plus en plus de temps à déployer ?</p>
<p>Les éditeurs d’antivirus commencent à proposer une réponse à ces problématiques, à travers le Cloud. Plutôt que de scanner un fichier sur le poste de travail, il s’agit d’en faire un hash (empreinte unique pour chaque fichier), qui est envoyé sur un serveur de l’éditeur, dans le Cloud. Il est alors comparé à une base de données mondiale, et peut même faire l’objet d’une note de « réputation » selon sa probabilité d’être ou non malveillant. L’information est alors renvoyée à l’antivirus sur le PC, qui prend les actions nécessaires le cas échéant.</p>
<p>Cette méthode prometteuse a toutefois ses contraintes : la nécessité d’une connexion internet, de qualité et le manque de maîtrise de la réaction de l’antivirus en cas de faux positif.</p>
<h2> Des changements de plateforme structurants</h2>
<p><strong> </strong>Un dernier élément vient s’ajouter à la question de l’évolution des antivirus : il s’agit de l’évolution des systèmes d’exploitation eux-mêmes.</p>
<p>Les OS modernes intègrent en effet un certain nombre de mécanismes de sécurité natifs, qui rendent les attaques plus difficiles : isolement inter-applicatif, applications et drivers signés, mécanismes de cryptographie…</p>
<p><strong> </strong>Les deux principales plateformes mobiles en sont un bon exemple : tandis que l’efficacité des rares antivirus reste à démontrer sur Android, ils sont tout simplement interdits par Apple sur iOS. Pourtant, à part quelques vulnérabilités médiatisées, les cas d’infection dans le cadre d’une utilisation normale sont anecdotiques.</p>
<p>Ceci reste cependant à nuancer : les attaquants évaluent au final les coûts/bénéfices de chaque type d’attaque. Lorsque le développement de virus sur smartphone sera plus lucratif que l’exploitation d’une faille de navigateur Web, il deviendra sans doute à la mode…</p>
<p>Le cas de Windows 8 est encore différent : s’il dispose d’un environnement « nouvelle génération » avec les applications du Windows Store, il propose une rétrocompatibilité avec les programmes plus anciens… y compris malveillants.</p>
<p>N’enterrez donc pas tout de suite votre antivirus, il pourrait encore vous servir pendant des années !</p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2013/05/un-antivirus-sur-votre-pc-entreprise-en-2013-pour-quoi-faire/">Un antivirus sur votre PC entreprise en 2013 ? Pour quoi faire ?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
