RSSAmplifier

Blog

Tony Lambert

Tony's blog about malware analysis and other security topics

forensicitguy.github.ioRSS feed ↗5 posts

Latest posts

Squeezing Cobalt Strike Threat Intelligence from Shodan

One of my favorite Twitter accounts from the last several years was @cobaltstrikebot, mainly because it was an awesome source of threat intelligence for Cobalt Strike beacons in the wild. The account went dark in June 2023, but its tweets are still around. Today's 5 most common Spawn_to values:%windir%\sysnative\rundll32.exec:\windows\system32\rundll32.exe%windir%\system32\rundll32.exe%win...

Exploring VenomRAT Metadata and Encryption with YARA - #100DaysOfYara

It’s that time of year again - 100 Days of YARA! In this post I want to walk through how I use YARA to document malware analysis findings. YARA has loads of different use cases: Detecting malicious file contents Estimating malware capabilities Showing how files can be similar to known documentation My favorite use case is that last one. In my day job I often encounter malware that doe...

Decompiling a JPHP Loader with binwalk and cfr

It’s not unusual for adversaries to explore new and unusual ways to implement loader malware, and lately I’ve been looking at JPHP-based loader malware. This kind of loader doesn’t get a lot of attention from antimalware providers, likely because of its nature as a weird hybrid language. In this post, I dive into unpacking the loader (which I suspect is “d3f@ck” loader) and statically decompili...

Dissecting a Java Pikabot Dropper

In mid-February, TA577 experimented with a Java Archive (JAR) dropper to deliver Pikabot to their victims. In this post I’ll explore some static analysis of that dropper to show how we can get information from it. If you want to follow along, I’m working with this sample in MalwareBazaar: https://bazaar.abuse.ch/sample/0a0e0d2f9daa0bad25c3defd69a3a6d96a6ac5f325a369761807c06887d3bd9f/. Triage t...

Timelining a Malicious VHD for More Intelligence

In a previous blog post I mentioned how adversaries using VHD files to distribute malware can leave around a lot more data than they intend, including identifiable data for tracking. In this post I want to break out the best friend everyone made during SANS FOR508, Plaso, so I can process the filesystem data for a malicious VHD and illustrate how we can establish a timeline of operations for th...