Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
QBot phishing uses Windows Calculator sideloading to infect devices

QBot phishing uses Windows Calculator sideloading to infect devicesPost Views: 24 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes The operators of the QBot malware have been using the Windows Calculator to side-load the malicious payload on infected computers.DLL side-loading is a common attack method that takes advantage of how Dynamic Link Libraries (DLLs) are handled in Windows. It consists of spoofing a legitimate DLL and placing it in a folder from where the operating system loads it instead of the legitimate one.

QBot, also known as Qakbot is a Windows malware strain that started as a banking trojan but evolved into a malware dropper, and is used by ransomware gangs in the early stages of the attack to drop Cobalt Strike beacons.

Security researcher ProxyLife recently discovered that Qakbot, has been abusing the the Windows 7 Calculator app for DLL side-loading attacks since at least July 11. The method continues to be used in malspam campaigns. #Qakbot – obama200 – html > .zip > .iso > .lnk > calc.exe > .dll > .dll

T1574 – DLL Search Order Hijacking

cmd.exe /q /c calc.exe

regsvr32 /s C:UsersUserAppDataLocalTempWindowsCodecs.dll

regsvr32.exe 102755.dllhttps://t.co/2Vgg6cuRFh

IOC'shttps://t.co/e7hkNW8eQu pic.twitter.com/sCH1xagkyR

— proxylife (@pr0xylife) July 11, 2022
See Also: So you want to be a hacker? Complete Offensive Security and Ethical Hacking Course New QBot infection chainTo help defenders protect against this threat, ProxyLife and researchers at Cyble documented the latest QBot infection chain.

The emails used in the latest campaign carry an HTML file attachment that downloads a password-protected ZIP archive with an ISO file inside.

The password for opening the ZIP file is shown in the HTML file, and the reason for locking the archive is to evade antivirus detection.
https://www.bleepstatic.com/images/news/u/1220909/Security/html.png
<figcaptionHTML attachment on QBot spam emails
The ISO contains a .LNK file, a copy of ‘calc.exe’ (Windows Calculator), and two DLL files, namely WindowsCodecs.dll and a payload named 7533.dll.
https://www.bleepstatic.com/images/news/u/1220909/Security/files(1).png
<figcaptionZIP archive contents
When the user mounts the ISO file, it only displays the .LNK file, which is masqueraded to look like a PDF holding important information or a file that opens with Microsoft Edge browser.

However, the shortcut points to the Calculator app in Windows, as seen in the properties dialog for the files.
https://www.bleepstatic.com/images/news/u/1100723/2022/DLL-SideloadQBot.jpg
<figcaptionProperties of the PDF file that triggers the infection
Trending: How do QR Codes work and how criminal hackers use them to generate phishing attacks – Demo
Trending: OSINT Tool: SARENKA
Clicking the shortcut triggers the infection by executing the Calc.exe through the Command Prompt.

When loaded, the Windows 7 Calculator automatically searches for and attempts to load the legitimate WindowsCodecs DLL file. However, it does not check for the DLL in certain hard coded paths, and will load any DLL with the same name if placed in the same folder as the Calc.exe executable.

The threat actors take advantage of this flaw by creating their own malicious WindowsCodecs.dll file that launches the other [numbered].dll file, which is the QBot malware.

By installing QBot through a trusted program like the Windows Calculator, some security software may not detect the malware when it is loaded, allowing the threat actors to evade[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking QBot phishing uses Windows Calculator sideloading to infect devices QBot phishing uses Windows Calculator sideloading to infect devicesPost Views: 24 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Patreon.png…
detection.

It should be noted, that this DLL sideloading flaw no longer works in Windows 10 Calc.exe and later, which is why the threat actors bundle the Windows 7 version.

QBot has been around for more than a decade, with origins going as far back as 2009 [1, 2, 3, 4]. While campaigns delivering it are not frequent, it was observed being distributed by Emotet botnet in the past to drop ransomware payloads.

Among the ransomware families that QBot delivered are RansomExx, Maze, ProLock, and Egregor. More recently, the malware dropped Black Basta ransomware.
Trending: Emerging H0lyGh0st Ransomware Tied to North Korea
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2022/03/Merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images-for-the-News-posts-3-300x150.png Atlassian patches batch of critical hardcode vulnerabilityJuly 22, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images-for-the-News-posts-2-300x150.png Zero-day flaws in GPS tracker pose surveillance, fuel cut-off risks to vehiclesJuly 21, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images-for-the-News-posts-1-300x150.png ‘Password extraction risk’ in identity provider Okta disputedJuly 20, 2022
Reading Time: 3 minutes

* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/07/Images-for-the-News-posts-300x150.png ‘Endemic’ Log4j bug set to persist in the wild for at least a decadeJuly 19, 2022
Reading Time: 3 minutes
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now!
The post QBot phishing uses Windows Calculator sideloading to infect devices first appeared on Black Hat Ethical Hacking.
hacking: security in practice
Someone has been trying to hack into my computer

This has been happening for 3 weeks and I was wondering if there is a way to utilise they’re MAC or IP address to prevent it.

I have the IP they used to connect and I have the MAC address both provided by McAfee.

If anyone can give some advice it would be much appreciated.

submitted by /u/Monsterbox-gamingYT
[link] [comments]
hacking: security in practice
Solid Computer Networking Online Courses

Hi, I'm looking a rigorous, comprehensive course/study material about computer networks.

I have a degree in telecommunications engineering, so I am already very familiar with basic networking concepts from various network courses I studied in Uni. However, there are basic gaps in my knowledge that I would like to fill. So I want a comprehensive course that reviews beginner concepts quickly but is rigorous, fast paced, and tackles advanced concepts.. all in.

Most courses online start so slow, explaining what a LAN is and what routers do.. I don't need that I've already studied the OSI model, various internet protocols and other concepts beyond that.

I know about CISCO courses but someone told me they're not general and very technology-oriented rather than concept-oriented, but IDK. My goal is to learn, NOT to pass any examination.

Does something like this exist, or is that too good to be true. I don't mind courses/books/articles whatever teaches well and is not boring.

submitted by /u/Fedo_19
[link] [comments]
hacking: security in practice
Pool on the roof - July 25, 2022

Have a no0b question? New to hacking? Looking for a script? Need help with your github project? Something wrong with your payload? Stuck on a CTF or bug bounty?

This is a weekly recurring post to make friends with other hackers, ask questions, and get any type of help you may need.

Make sure to read our wiki as it's full of resources for you.

Keep all beginner questions in this weekly stickied post.

submitted by /u/AutoModerator
[link] [comments]
Outdated PHP Version leads to RCE

Hi Everyone, back again with my one more Bug Bounty write-up.Continue reading on Medium »
Read more...
Let’s Explore OAuth 2.0 Vulnerability.

Hello Amazing People,Continue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
WhiteBeam : Transparent Endpoint Security

WhiteBeam is a Transparent endpoint security

Features

* Block and detect advanced attacks
* Modern audited cryptography: RustCrypto for hashing and encryption
* Highly compatible: Development focused on all platforms (incl. legacy) and architectures
* Source available: Audits welcome
* Reviewed by security researchers with combined 100+ years of experience

Installation

WhiteBeam is currently unavailable for installation due to backwards-incompatible security enhancements for 0.3. Check back soon!

From Packages (Linux)

Distro-specific packages have not been released yet for WhiteBeam, check again soon!

From Releases (Linux)

1. Download the latest release
2. Ensure the release file hash matches the official hashes (How-to)
3. Install:
* ./whitebeam-installer install
From Source (Linux)

1. Run tests (Optional):
* cargo run test

2. Compile:
* cargo run build

3. Install WhiteBeam:
* cargo run install
Quick start

1. Become root (sudo su/su root)
2. Set a recovery secret: whitebeam --setting RecoverySecret mask. After setting the recovery secret, you can run whitebeam --authto make changes to the system.

How to Detect Attacks with WhiteBeam

Multiple guides are provided depending on your preference. Contact us so we can help you integrate WhiteBeam with your environment.

1. Serverless guide, for passive review
2. osquery Fleet setup guide, for passive review
3. WhiteBeam Server setup guide, for active response

How to Prevent Attacks with WhiteBeam

https://s.w.org/images/core/emoji/14.0.0/72x72/2139.png WhiteBeam is experimental software. Contact us for assistance safely implementing it.

1. Become root (sudo su/su root)
2. Review the baseline at least 24 hours after installing WhiteBeam:
* whitebeam --baseline

3. Add trusted behavior to the whitelist, following the whitelisting guide
4. Enable WhiteBeam prevention:
* whitebeam --setting Prevention true
Download
*
*
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Pulsar : Data Exfiltration And Covert Communication Tool

Pulsar is a tool for data exfiltration and covert communication that enable you to create a secure data transfer, a bizarre chat or a network tunnel through different protocols, for example you can receive data from tcp connection and resend it to real destination through DNS packets

Setting up Pulsar

First, getting the code from repository and compile it with following command:

$ cd pulsar
$ export GOPATH=$(shell pwd)
$ go get golang.org/x/net/icmp
$ go build -o bin/pulsar src/main.go

or run:

$ make

Connectors

A connector is a simple channel to the external world, with the connector you can read and write data from different sources.

* Console:
* Default in/out connector, read data from stdin and write to stdout

* TCP
* Read and write data through tcp connections
tcp:127.0.0.1:9000

UDP

* Read and write data through udp packet

udp:127.0.0.1:9000

ICMP

* Read and write data through icmp packet

icmp:127.0.0.1 (the connection port is obviously useless)

You can use option –in in order to select input connector and option –out to select output connector:

–in tcp:127.0.0.1:9000
–out dns:fkdns.lol:2.3.4.5:8989

Handlers

A handler allows you to change data in transit, you can combine handlers arbitrarily.

* Stub:
* Default, do nothing, pass through

* Base32
* Base32 encoder/decoder
–handlers base32

You can use the –decode option to use ALL handlers in decoding mode

–handlers base64,base32,base64,cipher:key –decode

Example

In the following example Pulsar will be used to create a secure two-way tunnel on DNS protocol, data will be read from TCP connection (simple nc client) and resend encrypted through the tunnel.

[nc 127.0.0.1 9000] <–tcp–[pulsar] <–dns–[pulsar] <–tcp–[nc -l 127.0.0.1 -p 9900]

$ ./pulsar –in tcp:127.0.0.1:9000 –out dns:test.org@192.168.1.199:8989 –duplex –plain in –handlers ‘cipher:supersekretkey!!’
$ nc 127.0.0.1 9000
Download