Virtual disk as the start of an attack

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
🟥 ⚔️ 💿 Virtual Disk as the Start of an Attack
In early September, experts from the TI cyberintelligence group of the PT ESC department discovered an interesting VHDX file that turned out to be part of an attack chain targeting organizations in Asian countries. We don’t know the exact initial vector, but most likely the file was distributed via phishing.
✍️ A VHDX file is a virtual disk that can be mounted to a system starting with Windows 8 by double-clicking. It will be treated as a logical volume until the system is shut down.
Like any container, a VHDX file can act as a malicious object. Researcher Will Dormann in a 2019 post described how a specially crafted image can trigger a system error in Windows and cause a “blue screen of death.”
👾 In attacks, we rarely see this container used, but a virtual disk can contain malicious files that the victim is supposed to launch. A hacker can convince the victim to do this through social engineering techniques. To begin infecting the device, the victim only needs to open the disk sent to them and run the malicious file inside it. The infection scheme (for example, as in the first screenshot) is the same as if the user had been sent an archive with the same malicious embedded file.
💡 For hackers, the advantage of using VHDX files (as with using ZIP files) is that they are not subject to MoTW (Mark of the Web): when launching a document from these containers, Protected View is not enabled, and Windows SmartScreen does not warn the victim of the danger. It is also worth noting that fewer antivirus solutions are adapted to the VHDX format than to the same ISO files. Consequently, when the image enters the system, it is unlikely to be immediately deleted by this security tool.
Although VHDX files are rarely used in attacks, it is important for a TI analyst, like any other researcher, to be able to analyze these files effectively so as not to miss important details that could help with attribution or provide additional IoCs that allow building connections with other attacks.
Hackers make mistakes: they may use the same VHDX file in two different attacks or upload erroneous files. In either of these cases, the attackers typically delete the files, and since this is a disk, the analyst can try to recover them (including with the exact creation dates of these files) — in other words, the analyst can build a timeline of file changes on the disk. This can be done using specialized forensics tools.
👀 Let’s look at the most effective methods and tools that can be used for disk analysis:
• Creating a virtual machine and mounting the disk in it. This will allow you to view the files in Explorer and see what the attack victim received (but not deleted files).
• Autopsy — a universal tool for examining images that can extract data from many different file types, physical disks, and raw images. It has a timeline of file changes within the image (example — in the second screenshot).
• FTK Imager — an analog of the Autopsy program that showed the best results in recovering deleted files from a disk.
🛡 As an option for protection against attacks using VHDX, email filters should be used that prohibit the transmission of this file type in email attachments — both from external senders and from internal ones.
We will soon publish an article in which we analyze this attack in detail. Stay tuned for news.

#ti #tool #tip #news
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



