Level Extreme platform
Subscription
Corporate profile
Products & Services
Support
Legal
Français
Interesting malware analysis
Message
From
15/09/2020 13:25:20
 
 
To
15/09/2020 10:50:32
General information
Forum:
Internet
Category:
Security
Miscellaneous
Thread ID:
01676132
Message ID:
01676135
Views:
41
>>https://blog.huntresslabs.com/hiding-in-plain-sight-556469e0a4e?gi=7a57b7ba5adc
>>https://blog.huntresslabs.com/hiding-in-plain-sight-part-2-dfec817c036f
>>
>>Some clever techniques in use.
>
>Yeah, that's some pretty neat stuff. Clever.

DNS over HTTPS is something I hope to avoid as long as possible or keep under own control, not only for such stuff, but for a working Pi-Hole - But currently it seems to be en vogue to target it.

Dynamic patching of the AMSI without SU/Admin credentials smells of hexapod critter, perhaps should not be allowed dynamically at all.

The command creation via split not resulting in a file to load and keep on HD while executing is ugly - uncertain something similar could be done via only memory based file.
Previous
Next
Reply
Map
View

Click here to load this message in the networking platform