Ad-hoc network research, or How to find new, previously undiscovered activity of a known group in 15 minutes

More in Threat actors
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- We will croc you
We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- ⚡Fake news — THAT'S ALL
⚡Fake news — B U L L S H I T PT ESC specialists discovered an…
🔎 Quick-and-dirty network research, or How to find a new, previously undiscovered activity of a known group in 15 minutes
While analyzing external expertise on one of the resources that mainly publish materials about threats to Chinese infrastructure, we came across an interesting but rather terse article about the RustyNet loader of the APT group Patchwork.
The article provided an example of a malware sample with a brief description of network activity and accompanying screenshots of code from the IDE. Based on the contents of the network requests (the hash sums of the samples, as luck would have it, were not specified), we found examples of traffic from the C2 server yw56[.]info (first screenshot). The backdoor sends system data to the C2 server, encoding it with XOR and Base64. However, it was also interesting to look through the links provided in the aforementioned research… and that’s how we stumbled upon a new sample!
But let’s take it one step at a time 🤔
Researching the indicators of compromise from the article in open sources allowed us to discover that at the URL
weibo[.]nihaoucloud[.]org/akowutbuu753dtRWq21jk/odiworukdjo2375kjkl1lk87hl0
some time ago a sample was dropped
6afdf4a3088bff045e1998d2dc2863b90d06765abb2dc35c7b93c456b9818e55
whose detections lit up like a Christmas tree on the resource we all know 🎄
“What if this is that very hash not mentioned in the article?” — we thought, and shoved it into the available sandboxes: VirusTotal CAPE Sandbox and Triage. And, lo and behold, its traffic differed from what was presented in the article! Moreover, mentions of these network interactions were nowhere to be found, nor were any network signature triggers, and the backdoor communicated with the C2 server shrilongu[.]info with a creation date of 04/19/2024, which had also not been previously reported (see the second screenshot for details).
🥳 Bingo! A single URL allowed us to attribute the sample and assign it to the APT group Patchwork (the similarity of the HTTP payload gave it away) and, of course, to write a detection rule:
alert http any any -> any any (msg: "BACKDOOR [PTsecurity] Unknown Backdoor (APT Patchwork)"; flow: established, to_server; pcre: "/^[a-z]{10,40}$/V"; http.method; content: "POST"; http.header; content: "Content-Type: application/x-www-form-urlencoded"; content: "Cache-Control: no-cache"; http.request_body; content: "umnome="; depth: 7; fast_pattern; content: "&pmjodf="; distance: 0; content: "&idkdfjej="; distance: 0; content: "&cokenme="; distance: 0; classtype: trojan-activity; sid: 1;)
Code language: plaintext (plaintext)
This example shows that in reality, even after reading someone else’s research, you can conduct your own — and quite successfully at that. And reversing files is far from always necessary, at least not for a superficial quick analysis — in this case, the researcher can use available sandboxes with public expertise.

#detect #malware #network #suricata #patchwork #tips
@ptescalator
More in Threat actors
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- We will croc you
We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- ⚡Fake news — THAT'S ALL
⚡Fake news — B U L L S H I T PT ESC specialists discovered an…







