After over 7 years, I am picking this up again. Hopefully I can keep it up and do regular posts. Of course, everything here is my own opinions and doesn't represent anyone but myself
As shown in my last blog , I took the time to analyze a very complicated, annoying and heavily obfuscated PowerShell that resulted in a payload that the LLM i was using as my intern indicated that it might be related to Red Team or Offensive Security course. This did not sit well with me and was even cemented more when one of my trusted friends also nudged me about the domains that dropped this…
On December 29, 2025 one of my VT hunt rules fired off. I got super excited as that rule was created on the back of a specific PowerShell script from an incident back in the summer and this was the first time it fired off since I created it. VT Link - https://www.virustotal.com/gui/search/8bab6fbed08c3d8d45512b09126dc39bbf02eca8c5a92655baca7ae7dbfb1b4a Low detection and still is (3/63) as the…
BACKGROUND The topic of discussion have been covered quite well in the past years. With some analysis focusing on the human element and actors behind the tools and other analysis attributing to different groups and some focusing on the malware and final payload . This blog will just focus on some recent samples related to what i think is more_eggs and my attempt (successful or not, I will let you…
INTRODUCTION This post will discuss an ongoing campaign that have been operational since at least August 2017 . The post will look into the delivery of the malware, some analysis on the payload, and some additional insights in relation to the campaign. It is by no means a full in depth analysis of the malware and all it's functionality. LAWYER UP!! This all started with a tweet by the AWESOME…
INTRODUCTION The great people at ClearSky reached out to me a couple of days ago regarding a sample that they suspected could be related to MuddyWater. They suspected so because the sample had some similarities with the way MuddyWater lures look like and some similarities in some PowerShell obfuscation, in specific the character substitution routine. MuddyWater Sample New Sample However, after…
INTRODUCTION It has been over 2 months since I last wrote about MuddyWater or Temp.Zagros as named by FireEye . To be honest, I felt they were going quiet for a while; but boy was I wrong. Starting this week I have picked up some new interesting samples. Although these new samples have lots of similarities with the ones from earlier in the year, there are still some interesting aspects and…
INTRODUCTION Since my last blog-post on MuddyWater operations, they seem to have been continuing their activities and as expected developing/changing some of their tactics and techniques. It is still apparent their heavy focus on layered obfuscation and preference for PowerShell. However, I will highlight what changed based on the sample that I will be analyzing. This started with the sample…
INTRODUCTION In an earlier blog posts , I wrote about a campaign that was targeting the Middle East (Saudi Arabia, Iraq, UAE, etc). The adversary group behind this campaign was covered by PaloAlto's UNIT42 and others under the name MuddyWater. In this blog I will be sharing new samples related to this adversary group and how they are continuing to evolve and how they shifted some of their delivery…
Update 2017-11-15 : Palo Alto's Unit42 released a blog with additional details about the same activity and they are dubbing the group behind this as "MuddyWater". INTRODUCTION In an earlier blog post , I wrote about a campaign that was targeting the Middle East (Saudi Arabia, Iraq, UAE, etc). The adversary group behind this campaign seem to have been continuing its activity and advancing its…
INTRODUCTION This all started with the great analysis and blog done by RSA in August 2017 about a phishing wave targeting Russian Banks. This was followed by another great blog by McAfee on the same subject but my focus will be on a specific aspect mentioned in the RSA blog which is the exploit used. “FireEye discovered a malicious docx exploiting a zero day vulnerability in Microsoft’s…
This blog will discuss and uncover additional details regarding a recent campaign targeting entities in the Middle East. On Tuesday September 26, 2017 MalwareBytes blogged about a phishing campaign targeting the Middle East, more specifically Saudi Arabia. I started by trying to find the sample that the blog post analyzed and I was able to find it submitted to the great sandboxing site of Hybrid…
If you want to be a witness to all kinds of new Vulnerabilities and Exploits to major Web Browsers, OS, and Mobile devices, then you should head right away to Vancouver, BC, Canada where the CanSecWest Conference is taking place. The infamous Pwn2Own contest is well underway and is bringing results like no other contest. In the past 2 days vulnerabilities in Microsoft's IE 8 was discovered and…
If you are in the security field, you probably had heard about the Conficker Worm . But for everyone else who is interested in Information Security, or anybody in the IT field, or even anyone who owns a PC, this is a concern. The Conficker Worm was on of the highlights of the first quarter of last year and the end of 2008. You will find the link at the bottom of this post that tells you all about…
Most of you have already heard or know about the latest 0-day vulnerability affecting Microsoft's Internet Explorer. In the video demo below, i show you how to perform the attack on a demo lab network. As always this video is for tutorial and educational purposes only. I am also providing the original advisory from Microsoft and the vulnerability information from Secunia and Security Focus which…