darienhuss

New ROKRAT-like implant 2018-07-5

Jul 5th, 2018
653
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.89 KB | None | 0 0
  1. New ROKRAT-like implant 2018-07-5
  2.  
  3. Exploit: CVE-2017-8291
  4. Encapsulated PostScript method:
  5. -partial reverse string PostScript
  6. -single-byte XOR shellcode-loader shellcode
  7. -4-byte XOR encoded payload
  8.  
  9. IOCs
  10. (제출용)신청서.hwp|a636cd2f1ba46a9af23f9c0a24f8ee4e
  11. (제출용)신청서.hwp|9e6ff58202f6c1bd2381e8209231efd0ef6855db59db975fb5b75041706ed104
  12. BIN0001.eps|fced98d03bf14529be7ef8d2af8d9417
  13. BIN0001.eps|5abef9c21ae1ccbc895d101b9b5c20588fc0c4cfe79edd869f8a5406e9155f24
  14. extracted implant:
  15. 113637bc6f6f84d74ec2a4d0e988300b
  16. 4d37f80da97845129debf3244e1f731d2c93a02519f9fdaa059f5f124cf7c26f
  17.  
  18. Payload extraction script:
  19. https://pastebin.com/VaK7eHXg
  20.  
  21. VirusTotal
  22. HWP: https://www.virustotal.com/#/file/9e6ff58202f6c1bd2381e8209231efd0ef6855db59db975fb5b75041706ed104/detection
  23. Implant: https://www.virustotal.com/#/file/4d37f80da97845129debf3244e1f731d2c93a02519f9fdaa059f5f124cf7c26f/detection
Add Comment
Please, Sign In to add comment