ã·ããªãª#
Simon Starkã¯forelaã®éçºè ã§ãæè¿ååãšäžç·ã«ã³ãŒãã£ã³ã°ã»ãã·ã§ã³ãã¹ããªãŒãã³ã°ããããšèšç»ããŠããŠããã®ã¢ã€ãã¢ã¯CEOãä»ã®ååããã奜è©ã§ããã圌ã¯Googleæ€çŽ¢ã§èŠã€ããæåãªã¹ããªãŒãã³ã°ãœãããäœæ°ãªãã€ã³ã¹ããŒã«ããŸãããããã¯Googleåºåã§äžäœã«è¡šç€ºãããŠããURLã®äžã€ã§ãããããããæ®å¿µãªããäºæ ã¯æãã¬æ¹åãžé²ã¿ãã»ãã¥ãªãã£ã€ã³ã·ãã³ããçºçããŠããŸããŸãããæäŸãããããªã¢ãŒãžæžã¿ã®ã¢ãŒãã£ãã¡ã¯ããåæããäœãèµ·ãã£ãã®ããæ£ç¢ºã«çªãæ¢ããŠãã ããã
æ»æãããŒå³ â æŠèŠ#
(ãã¿ãã¬ãå«ãªå Žåã¯ã¹ãããããŠãã ããã)
ã»ããã¢ãã#
ãã®Sherlockã§ã¯ä»¥äžã䜿çšããŸãïŒ
- Eric Zimmermanæ°ã®ããŒã«ïŒRegistry ExplorerãEvtxECmdãMFTECmd TimeLine ExplorerãPECmdãªã©ïŒ
- HxD Hex Editor
- strings
äœæ¥ãå©ããããã«ã以äžã®ããŒãã·ãŒããæŽ»çšããŸãïŒ
- https://cdn.13cubed.com/downloads/windows_event_log_cheat_sheet.pdf
- https://cdn.13cubed.com/downloads/windows_registry_cheat_sheet.pdf
- https://cdn.13cubed.com/downloads/anatomy_of_an_ntfs_file_record.pdf
質å1#
ãŠãŒã¶ãŒãæ£èŠã®ãœãããŠã§ã¢ã ãšæã£ãŠããŠã³ããŒãããæªæã®ããZIPãã¡ã€ã«ã®å ã®ååã¯äœã§ããïŒ
åçã¯ãŠãŒã¶ãŒãã€ã NTUSER.DAT ã«ãããŸããã㌠RecentDocs ã¯ãŠãŒã¶ãŒãæè¿éãããã¡ã€ã«ãäžèŠ§è¡šç€ºããŸãã
åçïŒ OBS-Studio-28.1.2-Full-Installer-x64.zip
質å2#
Simon Starkã¯ããŠã³ããŒãããZIPãã¡ã€ã«ãå¥ã®ååã«ãªããŒã ããŸããããã®ãªããŒã ããããã¡ã€ã«åãšãã«ãã¹ã¯äœã§ããïŒ
ãã®è³ªåã«çããã«ã¯ãNTFSïŒWindowsã®ãã¡ã€ã«ã·ã¹ãã ïŒäžã§ãªããŒã æäœãè¡ããããšãMFTã® $FILE_NAMEïŒå±æ§0x30ïŒã倿Žãããããšãçè§£ããå¿ èŠããããŸãã
ããã§ãMFTECmd ã䜿ã£ãŠ $MFT ãè§£æããŸãïŒ
MFTECmd.exe -f "C:\$MFT" --csv "C:\Temp\Out"
次㫠Timeline Explorer ã«ã€ã³ããŒãããŸãïŒ
åçïŒC:\Users\Simon.stark\Documents\Streaming Software\Obs Streaming Software.zip
質å3#
ãã¡ã€ã«ããªããŒã ãããã¿ã€ã ã¹ã¿ã³ãã¯ãã€ã§ããïŒ
åãå Žæã«ãããŸãïŒ
åçïŒ 2023-05-05 10:22:23
質å4#
ãœãããŠã§ã¢ãããŠã³ããŒããããå®å šãªURLã¯äœã§ããïŒ
ãã¡ããåãå Žæã«ãããŸãïŒ
Windowsã§ãã¡ã€ã«ãããŠã³ããŒããããšïŒEdgeãInternet Explorerã®ãããªãã©ãŠã¶ãä»ããŠïŒãNTFSäžã«Zone.Identifierãšãã代æ¿ããŒã¿ã¹ããªãŒã ïŒADSïŒãèªåçã«äœæãããŸãã
ãã®ADSïŒã代æ¿ããŒã¿ã¹ããªãŒã ãïŒã¯ãã¡ã€ã«èªäœãšäžç·ã«ä¿åãããç¹ã«ä»¥äžã®æ å ±ãå«ã¿ãŸãïŒ
- ZoneIdïŒã»ãã¥ãªãã£ãŸãŒã³ïŒ3 = ã€ã³ã¿ãŒãããïŒ
- ReferrerUrlïŒããŠã³ããŒããéå§ããããŒãžã®URL
- HostUrlïŒããŠã³ããŒãããããã¡ã€ã«ã®æ£ç¢ºãªURL
åçïŒ http://obsproicet.net/download/v28_23/OBS-Studio-28.1.2-Full-Installer-x64.zip
質å5#
æ·±æãããŠãæªæãããã¡ã€ã³ããã¹ããããŠããIPã¢ãã¬ã¹ãèŠã€ããŠãã ããã
ããã§ã¯éåžžã«ã·ã³ãã«ã§ããEvtxECmd ã䜿ã£ãŠã€ãã³ããã°ãè§£æãããã¡ã€ã³åãæ¢ããŸãïŒ
EvtxECmd.exe -d 'C:\Windows\System32\winevt\Logs\' --csv 'C:\Temp\out'
åçïŒ 13.232.96.186
質å6#
ãã·ã³ãæªæãããŠã§ããµã€ãã«æ¥ç¶ããŠãã¡ã€ã«ãããŠã³ããŒãããéã«äœ¿çšãããè€æ°ã®ãœãŒã¹ããŒãããããŸããããã®äžã§ãæãé«ããœãŒã¹ããŒãçªå·ã¯ããã€ã§ããïŒ
Windowsã§ã¯ããã¡ã€ã¢ãŠã©ãŒã«ãæ¥ç¶ãã°ãèšé²ããããã«èšå®ãããŠããå Žåãã¢ã¯ã»ã¹è©Šè¡ããšã«ãã¡ã€ã³åã§ã¯ãªãã¿ãŒã²ããIPãšããŠèšé²ãããŸãã
pfirewall.log ãã¡ã€ã«ïŒC:\Windows\System32\LogFiles\Firewall
ïŒã«ã¯ãåãã±ããã®ä»¥äžã®æ
å ±ãèšé²ãããŠããŸãïŒ
- æ¥ä»ãšæå»
- ã¢ã¯ã·ã§ã³ïŒäŸïŒ“ALLOW” ãŸã㯠“DROP”ïŒ
- ãããã³ã«ïŒTCP/UDPïŒ
- ãœãŒã¹IPã¢ãã¬ã¹
- å®å IPã¢ãã¬ã¹
- ãœãŒã¹ããŒãããã³å®å ããŒã ãªã©
ä»åããã®IPãžã®æ¥ç¶ã¯åèš6ä»¶ãããªãã®ã§ãæåã§ç°¡åã«ç¢ºèªã§ããŸãïŒ
åçïŒ 50045
質å7#
ZIPãã¡ã€ã«ã®äžã«ã¯æªæã®ããã»ããã¢ãããã¡ã€ã«ãå«ãŸããŠããŠãããã¯ãã«ãŠã§ã¢ãšæ£èŠã®OBS Studioãåæã«ã€ã³ã¹ããŒã«ããã®ã§ããŠãŒã¶ãŒã¯æ°ä»ããã«ææããŠããŸããŸãããã®ã»ããã¢ãããã¡ã€ã«ã®ããã·ã¥ãèŠã€ããŠãã ããã
ãã®è³ªåã«çããã«ã¯ããŸãAmcacheãã€ããèŠãŠã¿ãŸããããAmcacheã¯ãå®è¡ã»ã€ã³ã¹ããŒã«ã»ã³ããŒãªã©ããããã¹ãŠã®å®è¡ãã¡ã€ã«ãç»é²ããŠããŸããåã¢ããªã±ãŒã·ã§ã³ã«ã€ããŠããã«ãã¹ãåºçŸæ¥æãç¹ã«ãã€ããªã®SHA1ããã·ã¥ãªã©ã®ã¡ã¿ããŒã¿ãä¿åããŠããŸãã
å ·äœçã«ã¯ããŠãŒã¶ãŒãZIPãå±éããŠæªæããã»ããã¢ãããå®è¡ïŒãŸãã¯åã«éããã ãã§ãïŒãããšãWindowsã¯ä»¥äžã®ããŒã«ãšã³ããªã远å ããŸãïŒ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\AppModel\InventoryApplicationFile
ïŒAmcache.hveå ã®Amcache\InventoryApplicationFileã«å¯Ÿå¿ïŒ
ãããã£ã¹ã¯ã®å®å šã³ããŒãããã°ããã®å Žã§ããã·ã¥ãèšç®ããŠãæ©ãã§ãããããã¯ããŸãè³¢ãæ¹æ³ã§ã¯ãããŸããã
åçŽã«ãã®å Žã§ããã·ã¥ãèšç®ããã®ãšéããAmcacheã¯æåã«å®è¡ã»å±éãããæç¹ã®SHA1ãããŒã«ã«ã·ã¹ãã äžã«èšé²ãããã®åŸã«ãã¡ã€ã«ãæ¹å€ããããšããŠãïŒAmcacheãšã³ããªãæç€ºçã«ç·šéã»åé€ããªãéãïŒå€æŽåã®ããã·ã¥ãä¿æãç¶ããŸãã
ããšããŠãŒã¶ãŒãZIPãåé€ãããã»ããã¢ãããã¡ã€ã«ã®ååãå€ãããããŠãããã¡ã€ã«ãåã€ã³ã¹ããŒã«ãããããšã³ããªãã¯ãªãŒã³ã¢ããããããŸã§ã¯Amcacheã«çè·¡ãæ®ããŸãã
åçïŒ 35e3582a9ed14f8a4bb81fd6aca3f0009c78a3a1
質å8#
æªæã®ãããœãããŠã§ã¢ã¯è¢«å®³è ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã«ããã¯ãã¢ãèªåçã«ã€ã³ã¹ããŒã«ããŸããããã®ããã¯ãã¢ã®ååãšãã¡ã€ã«ãã¹ã¯äœã§ããïŒ
ããã§ã¯åã³ $MFT ãåç §ããŸãããªããªãããã¡ã€ã«ã®äœæãå®è¡ããã¹ãŠèšé²ãããŠããããã§ãã
æé ãšããŠã¯ããŸãæªæããã»ããã¢ãããå®è¡ãããæå»ãšé¢é£ä»ããŠèª¿ã¹ãŸãïŒ
- æå»T0ïŒ
2023-05-05 10:23:14
ïŒã«ãŠãŒã¶ãŒãæªæããã»ããã¢ãããèµ·åããããšãããã£ãŠããŸãã - ãã®æ°ç§åŸïŒT0 + æ°ç§ïŒã«æ°ããã¿ã€ã ã©ã€ã³ãšã³ããªãçŸããŸããïŒ
C:\Program Files\Miloyeki ker konoyogi\lat takewode libigax weloj jihi quimodo datex dob cijoyi mawiropo.exe
- ãã®ãã¹ã¯ä»¥åã¯ååšããïŒ$MFTã«ãã®ãã¹ã®ãšã³ããªããªãã£ãïŒãæªæã®ããã»ããã¢ããã«ãã£ãŠæ°èŠäœæãããããšãæšæž¬ã§ããŸãã
åç: C:\Users\Simon.stark\Miloyeki ker konoyogi\lat takewode libigax weloj jihi quimodo datex dob cijoyi mawiropo.exe
質å9#
ããã¯ãã¢ã®ããªãã§ããããã·ã¥ãèŠã€ããŠãã ããã
Windowsã§ããã°ã©ã ãå®è¡ãããšãã·ã¹ãã 㯠C:\Windows\Prefetch ã«æ¡åŒµå .pf ã®ãã¡ã€ã«ãä¿åããŸãããã®ãã¡ã€ã«åã¯ä»¥äžã®2ã€ãçµã¿åããããã®ã§ãïŒ
- å®è¡ãã¡ã€ã«åïŒäŸïŒ
LAT TAKEWODE....exe
ïŒ - ãã®ãã¡ã€ã«ã®ãã£ã¹ã¯äžã®ãã«ãã¹ããèšç®ãããããã·ã¥
ãã®ããã·ã¥ã¯ã©ã³ãã ã§ã¯ãªããåãå®è¡ãã¡ã€ã«ãç°ãªããã¹ã«ååšããå Žåã«åºå¥ããããã«WindowsãçæããŸãã
以äžã®ã³ãã³ãã§Prefetchãã©ã«ããè§£æããŸãïŒ
.\PECmd.exe -d 'C:\Windows\prefetch' --csv 'C:\Temp\Out'
åçïŒ D8A6D943
質å10#
ããã¯ãã¢ã¯ã¹ãã«ã¹ã«ç°å¢ã«æº¶ã蟌ãåœ¢ã§æ°žç¶åã¡ã«ããºã ãšããŠãå©çšãããŠããŸããæ£åœãªãã®ã«èŠããããããã«ã©ã®ååãæ°žç¶åã¡ã«ããºã ãšããŠäœ¿çšããŠããã®ã§ããããïŒ
æ°žç¶åã¡ã«ããºã ãšããŠäžè¬çã«ãã䜿ããããã®ã«ã¯ïŒ
- Run / RunOnce ã¬ãžã¹ããªããŒ
- WindowsãµãŒãã¹
- ã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯
- ã¹ã¿ãŒãã¢ãããã©ã«ã㌠ãªã©ããããŸãã
ããã§ã¯ãCOMSurrogate ã·ã¹ãã ããã»ã¹ãæš¡å£ããååã§ã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ãäœæããŠããŸããWindowsãã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ãäœæãŸãã¯å€æŽãããšãã»ãã¥ãªãã£ãã°ïŒSecurity.evtx
ïŒã«ã€ãã³ã ID 4698ïŒâA scheduled task was createdâïŒãèšé²ãããŸãã
.\EvtxECmd.exe -d 'C:\Windows\System32\winevt\Logs\' --csv 'C:\Temp\Out\'
<?xml version="1.0" encoding="UTF-16"?>
<Task version="1.2" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">
<RegistrationInfo>
<Date>2023-05-05T15:23:21</Date>
<Author>FORELA\simon.stark</Author>
<URI>\COMSurrogate</URI>
</RegistrationInfo>
<Triggers>
<LogonTrigger>
<StartBoundary>2023-05-05T15:23:00</StartBoundary>
<Enabled>true</Enabled>
</LogonTrigger>
</Triggers>
<Principals>
<Principal id="Author">
<RunLevel>HighestAvailable</RunLevel>
<UserId>FORELA\simon.stark</UserId>
<LogonType>InteractiveToken</LogonType>
</Principal>
</Principals>
<Settings>
<MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>
<DisallowStartIfOnBatteries>true</DisallowStartIfOnBatteries>
<StopIfGoingOnBatteries>true</StopIfGoingOnBatteries>
<AllowHardTerminate>true</AllowHardTerminate>
<StartWhenAvailable>false</StartWhenAvailable>
<RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable>
<IdleSettings>
<Duration>PT10M</Duration>
<WaitTimeout>PT1H</WaitTimeout>
<StopOnIdleEnd>true</StopOnIdleEnd>
<RestartOnIdle>false</RestartOnIdle>
</IdleSettings>
<AllowStartOnDemand>true</AllowStartOnDemand>
<Enabled>true</Enabled>
<Hidden>false</Hidden>
<RunOnlyIfIdle>false</RunOnlyIfIdle>
<WakeToRun>false</WakeToRun>
<ExecutionTimeLimit>PT72H</ExecutionTimeLimit>
<Priority>7</Priority>
</Settings>
<Actions Context="Author">
<Exec>
<Command>C:\Users\Simon.stark\Miloyeki</Command>
<Arguments>ker konoyogi\lat takewode libigax weloj jihi quimodo datex dob cijoyi mawiropo.exe</Arguments>
</Exec>
</Actions>
</Task>
åçïŒCOMSurrogate
質å11#
ãã«ãŠã§ã¢ãå°éããããšãããã©ã³ãã ã«çæãããç¡å¹ãªãã¡ã€ã³åã¯äœã§ããïŒ
ã¹ã±ãžã¥ãŒã«ã¿ã¹ã¯ã 10:23:21
ã«äœæãããããããã®æéä»è¿ã§ Microsoft-Windows-DNS-Client/Operational ãã£ãã«ã調ã¹ããã«ãŠã§ã¢ã解決ã詊ã¿ããç¡å¹ãªããã¡ã€ã³ãç¹å®ããŸãã
åçïŒ oaueeewy3pdy31g3kpqorpc4e.qopgwwytep
質å12#
ãã«ãŠã§ã¢ã¯ããŒã¿ãS3ãã±ããã«éä¿¡ããããšããŸããããã®S3ãã±ããã®URLã¯äœã§ããïŒ
åããããã°ããs3ãã§ãã£ã«ã¿ãªã³ã°ããŠèª¿ã¹ãŸãã
åçïŒ bbuseruploads.s3.amazonaws.com
質å13#
Week 1ã§Simonãã¹ããªãŒãã³ã°ããããšããŠãããããã¯ã¯äœã§ããïŒã¡ã¢ãããã«é¡ãããã®ãèŠã€ããŠããã®å 容ã埩å ããçããŠãã ããã
ãŠãŒã¶ãŒã®ãæè¿äœ¿ã£ããã¡ã€ã«ãã«ã¯ãWeek 1 plan.txtããžã®ã·ã§ãŒãã«ãããå«ãŸããŠããŸããããããåé¡ã®ãã©ã«ããã®ãã®ã®ã³ããŒããªãããããã¡ã€ã«èªäœã®çè·¡ã¯èŠã€ãããŸããã
ããã§ã$MFTãè§£æããŸãããåãã®ããã«ãåé€ãç§»åããã£ããã¡ã€ã«ã§ããMFTã«ã¯å¿ ããšã³ããªãæ®ã£ãŠãããã¬ãžãã³ãããŒã¿ãåãåºãããšãã§ããŸãïŒ
- Non-resident: ãã¡ã€ã«ãµã€ãºãååã«å€§ããå ŽåãNTFSã¯ãã®ããŒã¿ãçŽæ¥MFTã«ä¿åããŸããã
$DATA
ãã£ãŒã«ãã«ã¯ãå®éã®å å®¹ãæ ŒçŽãããŠãããã£ã¹ã¯äžã®ã¯ã©ã¹ã¿ãŒãæããã©ã³ïŒãããã¯ïŒããå«ãŸããŸãã - Resident: ãã¡ã€ã«ãéåžžã«å°ããå ŽåïŒæŽå²çã«ã¯1KBæªæºããŸãã¯Windowsã®ããŒãžã§ã³ã屿§ãµã€ãºã«ãã£ãŠæ°çŸãã€ãçšåºŠïŒããã®ããŒã¿ã¯MFTãšã³ããªå
ã«çŽæ¥ä¿åããã
â$DATA
ãããã¯ã«æ ŒçŽãããŸãããããã¬ãžãã³ãããŒã¿ãšåŒã³ãŸãã
âââââââââââââââââ¬ââââââââââââââââââââââââââââââââââ¬ââââââââââââââââââââââ
â MFT Header â Attribut #0 (STANDARD_INFO) â ... â
â (48 bytesâŠ) ââââââââââââââââââââââââââââââââââ†â
â â Attribut #1 (FILE_NAME)â â â
â ââââââââââââââââââââââââââââââââââ†â
â â Attribut #2 (DATA, resident) â <â â
â â â â
â âââââââââââââââââââââââââââââââââââŽââââââââââââââââââââââ
â ...... â
âââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââââ
https://youtu.be/B4b6Ocf3wYs?si=rUruujZiEIdjgFKD
åç: Filesystem Security
質å14#
ææããã¯ãŒã¯ã¹ããŒã·ã§ã³ãããªã¢ãŒãžããã»ãã¥ãªãã£ã¢ããªã¹ãã®ååã¯äœã§ããïŒ
ãã®è³ªåã¯ããŸãé¢çœããªãã®ã§ãå°ããæšæž¬ãã«ãªããŸããSherlockããããããã£ãŠãããªãããã®CyberJunkieã®ã³ããæŽã¿å§ããŠããã¯ãã§ãã
åç: CyberJunkie
質å15#
ååŸããŒã«ãå®è¡ããããããã¯ãŒã¯ãã¹ã¯ã©ãã§ããïŒ
ãŸãã䜿çšãããããŒã«ãèŠã€ããå¿ èŠããããŸãããããè¡ãã«ã¯ããã€ãã®æ¹æ³ããããŸãïŒ
- LNK & ãžã£ã³ããªã¹ããã¡ã€ã«ã確èª
- ã€ãã³ãID 4688ïŒæ°ããããã»ã¹ãäœæãããïŒ
- AmCacheïŒInventoryApplicationFileïŒ
- äžè¿°ã®ããã«$MFT
- ããªãã§ãããã¡ã€ã«
é床ãåªå ããŠãããªãã§ãããã¡ã€ã«ã䜿ãããšã«ããŸãããè«ççã«ãååŸããŒã«ã¯ã§ããã ãæè¿å®è¡ãããã¯ãã§ãïŒ
ãããããã¹ã¯ãããŸããã
ããã§ä»¥äžã確èªããŸããïŒ
- AppCompatCacheïŒè©²åœãªã
- ã€ãã³ãID 4688ïŒè©²åœãªã
- $MFTïŒè©²åœãªã
NTUSER.DATãæ¢ãããšæããŸãããã該åœãªãã»ã»ã»ããã§ããntuser.dat.LOG1ãšLOG2ãããããšãããããŸãã
ãããã¯ãŠãŒã¶ãŒã¬ãžã¹ããªãã€ãïŒNTUSER.DATïŒã«é¢é£ãããã©ã³ã¶ã¯ã·ã§ã³ãã°ã§ãã
ã¬ãžã¹ããªããŒãå€ã«å¯ŸããŠè¡ããããã¹ãŠã®å€æŽïŒäŸãã°ããããã¯ãŒã¯ãã¹ãMRUãUserAssistããŒã«è¿œå ãããå Žåãªã©ïŒã¯ããŸããã®ãã°ã«æžã蟌ãŸãããã®åŸNTUSER.DATèªäœã«çµ±åïŒãã³ããããïŒãããŸããå ·äœçã«ã¯ïŒ
- ããã¯ãŠãŒã¶ãŒãã€ãã®ãã©ã³ã¶ã¯ã·ã§ã³ãã°ã§ãããã¢ããªã±ãŒã·ã§ã³ãWindowsãHKCUïŒRunMRUãUserAssistãRecentDocsãªã©ïŒã«äœããæžã蟌ããã³ã«ããã®å€æŽã¯æåã«NTUSER.DAT.LOG1ïŒããã³LOG2ïŒã«èšé²ããããã®åŸãã§ãã¯ãã€ã³ãã§NTUSER.DATã«ããŒãžãããŸã
- ã»ãã·ã§ã³ãçªç¶éãããããããŸã ãã§ãã¯ãã€ã³ããè¡ãããŠããªãå ŽåãNTUSER.DAT.LOG1ã«ã¯ãŸã NTUSER.DATã«çŸããŠããªããšã³ããªãå«ãŸããŠããå¯èœæ§ããããŸã
ããã§æååæ€çŽ¢ãå®è¡ãããã³ãŽïŒ
åç: \\DESKTOP-887GK2L\Users\CyberJunkie\Desktop\Forela-Triage-Workstation\Acquisiton and Triage tools
IOC Table#
Category | Field / Type | Indicator Value | Source / Note | Hash (to add) |
---|---|---|---|---|
Files (origin) | Original ZIP | OBS-Studio-28.1.2-Full-Installer-x64.zip | NTUSER.DAT â RecentDocs | (file missing) |
Malicious setup | OBS Studio 28.1.2 Full Installer x64.exe | Amcache InventoryApplicationFile | SHA-1 = 35e3582a9ed14f8a4bb81fd6aca3f0009c78a3a1 | |
Backdoor EXE | C:\Users\Simon.stark\Miloyeki ker konoyogi\lat takewode libigax weloj jihi quimodo datex dob cijoyi mawiropo.exe | $MFT | (file missing) | |
Network | Download domain | obsproicet.net | Zone.Identifier ADS | â |
Exact URL | http://obsproicet.net/download/v28_23/OBS-Studio-28.1.2-Full-Installer-x64.zip | Zone.Identifier ADS | â | |
Hosting IP | 13.232.96.186 | pfirewall.log | â | |
Highest source port | 50045 | pfirewall.log | â | |
Bogus domain | oaueeewy3pdy31g3kpqorpc4e.qopgwwytep | DNS-Client Operational | â | |
S3 exfil bucket | bbuseruploads.s3.amazonaws.com | DNS-Client Operational | â | |
Persistence | Scheduled Task name | \COMSurrogate | Security.evtx (4698) | â |
Prefetch hash | D8A6D943 | Prefetch filename | â |
ã©ãå®äºïŒ
https://labs.hackthebox.com/achievement/sherlock/1271052/899