{"id":1099,"date":"2021-05-23T16:25:30","date_gmt":"2021-05-23T16:25:30","guid":{"rendered":"https:\/\/cas.cybercop-training.ch\/?page_id=1099"},"modified":"2021-06-01T08:33:01","modified_gmt":"2021-06-01T08:33:01","slug":"rfi-incoming","status":"publish","type":"page","link":"https:\/\/cas.cybercop-training.ch\/index.php\/rfi-incoming\/","title":{"rendered":"RFI Incoming!"},"content":{"rendered":"<h2>1. Introduction<\/h2>\n<p>&#8222;Hey, CTI, what is this?&#8220;<\/p>\n<p>Your stakeholder in the Security Sperations Center (SOC) because they have received a suspicious alert on a Microsoft Exchange server.<\/p>\n<p>The stakeholder sends the following RFI:<\/p>\n<p>We need to have information about the hash below.<\/p>\n<ul>\n<li>What malware is it? Does the malware have a name?<\/li>\n<li>What malware familiy is it?<\/li>\n<li>What actions does the malicious file do?<\/li>\n<li>Is there an attribution possible?<\/li>\n<li>Are there public reports or sandbox runs we can use to further investigate this threat?<\/li>\n<\/ul>\n<p>Malicious file name: <strong>s1.exe<\/strong><\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">2b9838da7edb0decd32b086e47a31e8f5733b5981ad8247a2f9508e232589bff (SHA256)<\/pre>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"generic\">0e55ead3b8fd305d9a54f78c7b56741a (MD5)<\/pre>\n<h2>2. Answers<\/h2>\n<ol>\n<li>Malware name: <code>DoejoCrypt<\/code> and <code>DEARCRY<\/code> [1]<br \/>\nCategory: Decryptor \/ Ransomware<\/li>\n<li>Malware family: DearCry [2]<br \/>\n<blockquote><p>DearCry is a ransomware first seen after the 2021 Microsoft Exchange hacks.<\/p><\/blockquote>\n<\/li>\n<li>Malware actions: [3]<\/li>\n<\/ol>\n<ul>\n<li>Modifies Installed Components in the registry (Registry Run Keys \/ Startup Folder)<\/li>\n<li>Modifies\/encrypts extensions of user files (e.g <code>1.jpg<\/code> will be renamend and encrypted to <code>1.jpg.crypt<\/code>)<\/li>\n<li>Reads user\/profile data of web browsers &#8211;&gt; Infostealers often target stored browser data, which can include saved credentials etc.<\/li>\n<li>Drops desktop.ini file(s)<\/li>\n<li>Enumareate Connected drives<\/li>\n<\/ul>\n<ol start=\"4\">\n<li>Attribution\n<p>Possibly it stands in relation with HAFNIUM.<br \/>\nMicrosoft itself has attributed development and first uses of the exploits with \u201chigh confidence\u201d to Chinese state-sponsored cyberespionage group Hafnium on 2 March. [4]<\/li>\n<li>Public reports \/ further investigation\n<p><a href=\"https:\/\/analyze.intezer.com\/files\/2b9838da7edb0decd32b086e47a31e8f5733b5981ad8247a2f9508e232589bff\" target=\"_blank\" rel=\"noopener\">https:\/\/analyze.intezer.com<\/a><br \/>\n<a href=\"https:\/\/www.joesandbox.com\/analysis\/367746\/0\/html\" target=\"_blank\" rel=\"noopener\">www.joesandbox.com<\/a><br \/>\n<a href=\"https:\/\/news.sophos.com\/en-us\/2021\/03\/15\/dearcry-ransomware-attacks-exploit-exchange-server-vulnerabilities\/\" target=\"_blank\" rel=\"noopener\">https:\/\/news.sophos.com<\/a><br \/>\n<a href=\"https:\/\/unit42.paloaltonetworks.com\/dearcry-ransomware\/\" target=\"_blank\" rel=\"noopener\">unit42.paloaltonetworks.com\/<\/a><br \/>\n<a href=\"https:\/\/tria.ge\/210312-3n7ezztylj\" target=\"_blank\" rel=\"noopener\">https:\/\/tria.ge<\/a><\/li>\n<\/ol>\n<h2>3. Ressources<\/h2>\n<p>[1,2] <a href=\"https:\/\/bazaar.abuse.ch\/sample\/2b9838da7edb0decd32b086e47a31e8f5733b5981ad8247a2f9508e232589bff\/\" target=\"_blank\" rel=\"noopener\">bazaar.abuse.ch<\/a><br \/>\n[3] <a href=\"https:\/\/tria.ge\/210312-3n7ezztylj\" target=\"_blank\" rel=\"noopener\">tria.ge<\/a><br \/>\n[4] <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/03\/02\/hafnium-targeting-exchange-servers\/\" target=\"_blank\" rel=\"noopener\">microsoft.com<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. Introduction &#8222;Hey, CTI, what is this?&#8220; Your stakeholder in the Security Sperations Center (SOC) because they have received a suspicious alert on a Microsoft Exchange server. The stakeholder sends the following RFI: We need to have information about the hash below. What malware is it? Does the malware have a name? What malware familiy [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-1099","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/1099","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/comments?post=1099"}],"version-history":[{"count":4,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/1099\/revisions"}],"predecessor-version":[{"id":1384,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/1099\/revisions\/1384"}],"wp:attachment":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/media?parent=1099"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}