[ << ALL_FEED ]

Ad-hoc network research, or How to find new, previously undiscovered activity of a known group in 15 minutes

More in Threat actors

🔎 Quick-and-dirty network research, or How to find a new, previously undiscovered activity of a known group in 15 minutes

While analyzing external expertise on one of the resources that mainly publish materials about threats to Chinese infrastructure, we came across an interesting but rather terse article about the RustyNet loader of the APT group Patchwork.

The article provided an example of a malware sample with a brief description of network activity and accompanying screenshots of code from the IDE. Based on the contents of the network requests (the hash sums of the samples, as luck would have it, were not specified), we found examples of traffic from the C2 server yw56[.]info (first screenshot). The backdoor sends system data to the C2 server, encoding it with XOR and Base64. However, it was also interesting to look through the links provided in the aforementioned research… and that’s how we stumbled upon a new sample!

But let’s take it one step at a time 🤔

Researching the indicators of compromise from the article in open sources allowed us to discover that at the URL

weibo[.]nihaoucloud[.]org/akowutbuu753dtRWq21jk/odiworukdjo2375kjkl1lk87hl0

some time ago a sample was dropped

6afdf4a3088bff045e1998d2dc2863b90d06765abb2dc35c7b93c456b9818e55

whose detections lit up like a Christmas tree on the resource we all know 🎄

“What if this is that very hash not mentioned in the article?” — we thought, and shoved it into the available sandboxes: VirusTotal CAPE Sandbox and Triage. And, lo and behold, its traffic differed from what was presented in the article! Moreover, mentions of these network interactions were nowhere to be found, nor were any network signature triggers, and the backdoor communicated with the C2 server shrilongu[.]info with a creation date of 04/19/2024, which had also not been previously reported (see the second screenshot for details).

🥳 Bingo! A single URL allowed us to attribute the sample and assign it to the APT group Patchwork (the similarity of the HTTP payload gave it away) and, of course, to write a detection rule:


alert http any any -> any any (msg: "BACKDOOR [PTsecurity] Unknown Backdoor (APT Patchwork)"; flow: established, to_server; pcre: "/^[a-z]{10,40}$/V"; http.method; content: "POST"; http.header; content: "Content-Type: application/x-www-form-urlencoded"; content: "Cache-Control: no-cache"; http.request_body; content: "umnome="; depth: 7; fast_pattern; content: "&pmjodf="; distance: 0; content: "&idkdfjej="; distance: 0; content: "&cokenme="; distance: 0; classtype: trojan-activity; sid: 1;)
Code language: plaintext (plaintext)

This example shows that in reality, even after reading someone else’s research, you can conduct your own — and quite successfully at that. And reversing files is far from always necessary, at least not for a superficial quick analysis — in this case, the researcher can use available sandboxes with public expertise.

#detect #malware #network #suricata #patchwork #tips
@ptescalator

More from global_author

More from global_author

More in Threat actors