Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Understanding Authentication and Web Storage
https://cdn-images-1.medium.com/max/1091/1*DoSwjijyLmSPtSi93aU3rg.png
Basics of Auth and Web Storage for Hackers
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Understanding Authentication and Web Storage
https://cdn-images-1.medium.com/max/1091/1*DoSwjijyLmSPtSi93aU3rg.png
Basics of Auth and Web Storage for Hackers
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Understanding Authentication and Web Storage
Basics of Auth and Web Storage for Hackers
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Most Common Python Vulnerabilities and How To Avoid Them
https://cdn-images-1.medium.com/max/1600/0*UVF8UTHcBz7YgRw0
Everybody knows about Python. It’s now the second-most popular programming language worldwide, having overtaken Java. Not only is it used…
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Most Common Python Vulnerabilities and How To Avoid Them
https://cdn-images-1.medium.com/max/1600/0*UVF8UTHcBz7YgRw0
Everybody knows about Python. It’s now the second-most popular programming language worldwide, having overtaken Java. Not only is it used…
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Most Common Python Vulnerabilities and How To Avoid Them
Everybody knows about Python. It’s now the second-most popular programming language worldwide, having overtaken Java. Not only is it used…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe: Inclusion
https://cdn-images-1.medium.com/max/1986/1*uyyn42RTUamNNhN0OPWlbA.png
This is a walkthrough of TryHackMe’s Inclusion room. This is a web-focused room that has a local file inclusion vulnerability.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe: Inclusion
https://cdn-images-1.medium.com/max/1986/1*uyyn42RTUamNNhN0OPWlbA.png
This is a walkthrough of TryHackMe’s Inclusion room. This is a web-focused room that has a local file inclusion vulnerability.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe: Inclusion
This is a walkthrough of TryHackMe’s Inclusion room. This is a web-focused room that has a local file inclusion vulnerability.
What's the best way to pentest a firewall or VPN concentrator ?
https://www.reddit.com/r/Pentesting/comments/n9ngl4/whats_the_best_way_to_pentest_a_firewall_or_vpn/
This is the first time pentesting a FW or VPN I know nmap and ike-scan can be used but what else can I try ? I'm already using Burp for the Web interface but anything I'm missing ? submitted by /u/uneeed2ketchup (https://www.reddit.com/user/uneeed2ketchup)
[link] (https://www.reddit.com/r/Pentesting/comments/n9ngl4/whats_the_best_way_to_pentest_a_firewall_or_vpn/) [comments] (https://www.reddit.com/r/Pentesting/comments/n9ngl4/whats_the_best_way_to_pentest_a_firewall_or_vpn/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/n9ngl4/whats_the_best_way_to_pentest_a_firewall_or_vpn/
This is the first time pentesting a FW or VPN I know nmap and ike-scan can be used but what else can I try ? I'm already using Burp for the Web interface but anything I'm missing ? submitted by /u/uneeed2ketchup (https://www.reddit.com/user/uneeed2ketchup)
[link] (https://www.reddit.com/r/Pentesting/comments/n9ngl4/whats_the_best_way_to_pentest_a_firewall_or_vpn/) [comments] (https://www.reddit.com/r/Pentesting/comments/n9ngl4/whats_the_best_way_to_pentest_a_firewall_or_vpn/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
What's the best way to pentest a firewall or VPN concentrator ?
This is the first time pentesting a FW or VPN I know nmap and ike-scan can be used but what else can I try ? I'm already using Burp for the Web...
My Bug Bounty Journey & Ranking 1st in U.S. DoD & Achieving top 100 hackers in 1 year
I am sharing some of my methodology, recourses, tips and advices to become a better bug bounty hunter.
Read more...
I am sharing some of my methodology, recourses, tips and advices to become a better bug bounty hunter.
Read more...
Deep Web
Got ahead of myself
I'm afraid that my identity - social, DL, Birth certificate, etc... was compromised on the dark web and it has me very paranoid. I think there are people after me, and I don't understand what I could be up against. I put up a VPN and am avoiding answering any calls I don't know. Is there anyone that could give me more information, so I can deal with this?
submitted by /u/mjharris015
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Got ahead of myself
I'm afraid that my identity - social, DL, Birth certificate, etc... was compromised on the dark web and it has me very paranoid. I think there are people after me, and I don't understand what I could be up against. I put up a VPN and am avoiding answering any calls I don't know. Is there anyone that could give me more information, so I can deal with this?
submitted by /u/mjharris015
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Got ahead of myself
I'm afraid that my identity - social, DL, Birth certificate, etc... was compromised on the dark web and it has me very paranoid. I think there are...
Help me out with the cyber sec proj
https://www.reddit.com/r/Pentesting/comments/n9oixf/help_me_out_with_the_cyber_sec_proj/
I came hare today cause I immensely benefitted from your help the last time as well. Help a fellow brother out. I need to do this for internship. You have to solve the below challenges and create proper report of your finding and approach that how you solved the challenge with supportive proof of concept (POC) in form of screenshot. Web: 1. Fuzzing : http://65.2.6.176:6008/ 2. Post_me: http://65.2.6.176:8003/ 3. Enum: http://65.2.6.176:7003/ 4. Fetch_me: http://65.2.6.176:8007/ 5. Find_me: http://65.2.6.176:9009/ Misc: 1. Founder: https://drive.google.com/file/d/1uAOHxyRV63Qn3gDmZWDa6-dZzmH6qVOU/view?usp=sharing 2. Hex : https://drive.google.com/file/d/1\_8Gwe0lEpcLfcVCv3vvTG7nStS8R9Fl1/view?usp=sharing (https://drive.google.com/file/d/1%5C_8Gwe0lEpcLfcVCv3vvTG7nStS8R9Fl1/view?usp=sharing) 3. Steg_Mirror: https://drive.google.com/file/d/1HHB9Rzbxf2rd_2kbC4craJ44bRvyAKv_/view?usp=sharing Reverse: 1. Hitpass: https://drive.google.com/file/d/1dlGv1nsZlc70Jy5D54wjcQtMny6I36so/view?usp=sharing 2. Goofy: https://drive.google.com/file/d/1NcEP7ab77_539E09fu5lqtLSXHJsNSGa/view?usp=sharing Cryptography 1. Agent_cat: https://drive.google.com/file/d/13NWZXRYW6Jfe_w_hLM2BLB_Q_boJ093z/view?usp=sharing 2. Double_trouble: DJWbMJE5LHAHEagWK2uuqTIsMT91LzkyK2IhL3W5pUEco259 3. Vision: https://drive.google.com/file/d/1Cus7IsGwSn85C_WXP6zt5aDeVg7fvdG5/view?usp=sharing submitted by /u/Crafty-Blacksmith-99 (https://www.reddit.com/user/Crafty-Blacksmith-99)
[link] (https://www.reddit.com/r/Pentesting/comments/n9oixf/help_me_out_with_the_cyber_sec_proj/) [comments] (https://www.reddit.com/r/Pentesting/comments/n9oixf/help_me_out_with_the_cyber_sec_proj/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/n9oixf/help_me_out_with_the_cyber_sec_proj/
I came hare today cause I immensely benefitted from your help the last time as well. Help a fellow brother out. I need to do this for internship. You have to solve the below challenges and create proper report of your finding and approach that how you solved the challenge with supportive proof of concept (POC) in form of screenshot. Web: 1. Fuzzing : http://65.2.6.176:6008/ 2. Post_me: http://65.2.6.176:8003/ 3. Enum: http://65.2.6.176:7003/ 4. Fetch_me: http://65.2.6.176:8007/ 5. Find_me: http://65.2.6.176:9009/ Misc: 1. Founder: https://drive.google.com/file/d/1uAOHxyRV63Qn3gDmZWDa6-dZzmH6qVOU/view?usp=sharing 2. Hex : https://drive.google.com/file/d/1\_8Gwe0lEpcLfcVCv3vvTG7nStS8R9Fl1/view?usp=sharing (https://drive.google.com/file/d/1%5C_8Gwe0lEpcLfcVCv3vvTG7nStS8R9Fl1/view?usp=sharing) 3. Steg_Mirror: https://drive.google.com/file/d/1HHB9Rzbxf2rd_2kbC4craJ44bRvyAKv_/view?usp=sharing Reverse: 1. Hitpass: https://drive.google.com/file/d/1dlGv1nsZlc70Jy5D54wjcQtMny6I36so/view?usp=sharing 2. Goofy: https://drive.google.com/file/d/1NcEP7ab77_539E09fu5lqtLSXHJsNSGa/view?usp=sharing Cryptography 1. Agent_cat: https://drive.google.com/file/d/13NWZXRYW6Jfe_w_hLM2BLB_Q_boJ093z/view?usp=sharing 2. Double_trouble: DJWbMJE5LHAHEagWK2uuqTIsMT91LzkyK2IhL3W5pUEco259 3. Vision: https://drive.google.com/file/d/1Cus7IsGwSn85C_WXP6zt5aDeVg7fvdG5/view?usp=sharing submitted by /u/Crafty-Blacksmith-99 (https://www.reddit.com/user/Crafty-Blacksmith-99)
[link] (https://www.reddit.com/r/Pentesting/comments/n9oixf/help_me_out_with_the_cyber_sec_proj/) [comments] (https://www.reddit.com/r/Pentesting/comments/n9oixf/help_me_out_with_the_cyber_sec_proj/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Help me out with the cyber sec proj
I came hare today cause I immensely benefitted from your help the last time as well. Help a fellow brother out. I need to do this for internship. ...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Understanding and exploiting HTTP for bug bounty
https://cdn-images-1.medium.com/max/630/1*eP0ONHYjifhm2NnG0od3Ng.jpeg
Whenever we open a browser and search something on the internet we make an HTTP request.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Understanding and exploiting HTTP for bug bounty
https://cdn-images-1.medium.com/max/630/1*eP0ONHYjifhm2NnG0od3Ng.jpeg
Whenever we open a browser and search something on the internet we make an HTTP request.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Understanding and exploiting HTTP for bug bounty
Whenever we open a browser and search something on the internet we make an HTTP request.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Xcode Ghost: How The Biggest Apple Hack In History Came About
https://cdn-images-1.medium.com/max/2600/0*kLkdA_FtPLYUATuf
As part of the Epic process, internal emails from 2015 were released providing new information about Xcode Ghost
Continue reading on Mac O’Clock »
___________________________
@hacking_Attack
@Hacking_Video
Xcode Ghost: How The Biggest Apple Hack In History Came About
https://cdn-images-1.medium.com/max/2600/0*kLkdA_FtPLYUATuf
As part of the Epic process, internal emails from 2015 were released providing new information about Xcode Ghost
Continue reading on Mac O’Clock »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Xcode Ghost: How The Biggest Apple Hack In History Came About
As part of the Epic process, internal emails from 2015 were released providing new information about Xcode Ghost
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Key Tips To Avoid Cyber Scams | CIO Applications
https://cdn-images-1.medium.com/max/2600/0*AIenV87SQd9doVRG
Source — CIO Applications
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Key Tips To Avoid Cyber Scams | CIO Applications
https://cdn-images-1.medium.com/max/2600/0*AIenV87SQd9doVRG
Source — CIO Applications
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Key Tips To Avoid Cyber Scams | CIO Applications
Source — CIO Applications
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
Tracking One Year of Malicious Tor Exit Relay Activities (Part II)
https://external-preview.redd.it/q1TpXaQp1Vvct5bQX4SU4_cYlVIfPnUA6tsPp5Gv-RU.jpg?width=640&crop=smart&auto=webp&s=9467456b41879dfc78108e23fe54ccf1ac933ee9 submitted by /u/rangeva
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Tracking One Year of Malicious Tor Exit Relay Activities (Part II)
https://external-preview.redd.it/q1TpXaQp1Vvct5bQX4SU4_cYlVIfPnUA6tsPp5Gv-RU.jpg?width=640&crop=smart&auto=webp&s=9467456b41879dfc78108e23fe54ccf1ac933ee9 submitted by /u/rangeva
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Tracking One Year of Malicious Tor Exit Relay Activities (Part II)
Posted in r/deepweb by u/rangeva • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Lemon Duck Cryptojacking Botnet Changes Up Tactics
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Lemon Duck Cryptojacking Botnet Changes Up TacticsPost Views: 54
Reading Time: 2 Minutes
The Lemon Duck cryptocurrency-mining botnet has added the ProxyLogon group of exploits to its bag of tricks, targeting Microsoft Exchange servers.
That’s according to researchers at Cisco Talos, who said that the cybercrime group behind Lemon Duck has also added the Cobalt Strike attack framework into its malware toolkit and has beefed up anti-detection capabilities. On the latter front, it’s using fake domains on East Asian top-level domains (TLDs) to hide command-and-control (C2) infrastructure.
Lemon Duck targets victims’ computer resources to mine the Monero virtual currency, with self-propagating capabilities and a modular framework that allows it to infect additional systems that become part of the botnet. It has been active since at least the end of December 2018, and Cisco Talos calls it “one of the more complex” mining botnets, with several interesting tricks up its sleeve.
For instance, Lemon Duck has at least 12 different initial-infection vectors – more than most malware, with Proxylogon exploits only the latest addition. Its existing capabilities ranged from Server Message Block (SMB) and Remote Desktop Protocol (RDP) password brute-forcing; targeting the RDP BlueKeep flaw (CVE-2019-0708) in Windows machines; targeting internet-of-things devices with weak or default passwords; and exploiting vulnerabilities in Redis (an open-source, in-memory data structure store used as a database, cache and message broker) and YARN Hadoop (a resource-management and job-scheduling technology) in Linux machines.
See Also: iPhone Hack Allegedly Used to Spy on China’s Uyghurs
“Since April 2021, Cisco Talos has observed updated infrastructure and new components associated with the Lemon Duck that target unpatched Microsoft Exchange Servers and attempt to download and execute payloads for Cobalt Strike DNS beacons,” according to an analysis released Friday.
Cisco Talos researchers previously observed an increase in DNS requests connected with Lemon Duck’s C2 and mining servers last August, with the attacks mainly targeting Egypt, India, Iran, the Philippines and Vietnam. In the latest rash of attacks, which began in April, the group has changed up its geographic targets to focus primarily on North America, followed by Europe and Southeast Asia, and a handful of victims in Africa and South America. Targeting Exchange Servers with Monero-MiningProxyLogon consists of four flaws (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) that can be chained together to create a pre-authentication remote code execution (RCE) exploit – meaning that attackers can take over servers without knowing any valid account credentials. This gives them access to email communications and the opportunity to install a web shell for further exploitation within the environment, such as the deployment of ransomware.
See Also: Offensive Security Tool: EyeWitness The highly publicized exploit chain suffered a barrage of attacks from advanced persistent threat (APT) groups to infect systems with everything from ransomware to info-stealers, and now financially motivated groups are getting in on the action too.
In Lemon Duck’s case, once the Exchange servers are compromised, it executes various system commands using the Windows Control Manager (sc.exe), including copying two .ASPX files named “wanlins.aspx” and “wanlin.aspx.”
“These files are likely web shells and were copied from C:\inetpub\wwwroot\aspnet_client\, a known directory where[...]
___________________________
@hacking_Attack
@Hacking_Video
Lemon Duck Cryptojacking Botnet Changes Up Tactics
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Lemon Duck Cryptojacking Botnet Changes Up TacticsPost Views: 54
Reading Time: 2 Minutes
The Lemon Duck cryptocurrency-mining botnet has added the ProxyLogon group of exploits to its bag of tricks, targeting Microsoft Exchange servers.
That’s according to researchers at Cisco Talos, who said that the cybercrime group behind Lemon Duck has also added the Cobalt Strike attack framework into its malware toolkit and has beefed up anti-detection capabilities. On the latter front, it’s using fake domains on East Asian top-level domains (TLDs) to hide command-and-control (C2) infrastructure.
Lemon Duck targets victims’ computer resources to mine the Monero virtual currency, with self-propagating capabilities and a modular framework that allows it to infect additional systems that become part of the botnet. It has been active since at least the end of December 2018, and Cisco Talos calls it “one of the more complex” mining botnets, with several interesting tricks up its sleeve.
For instance, Lemon Duck has at least 12 different initial-infection vectors – more than most malware, with Proxylogon exploits only the latest addition. Its existing capabilities ranged from Server Message Block (SMB) and Remote Desktop Protocol (RDP) password brute-forcing; targeting the RDP BlueKeep flaw (CVE-2019-0708) in Windows machines; targeting internet-of-things devices with weak or default passwords; and exploiting vulnerabilities in Redis (an open-source, in-memory data structure store used as a database, cache and message broker) and YARN Hadoop (a resource-management and job-scheduling technology) in Linux machines.
See Also: iPhone Hack Allegedly Used to Spy on China’s Uyghurs
“Since April 2021, Cisco Talos has observed updated infrastructure and new components associated with the Lemon Duck that target unpatched Microsoft Exchange Servers and attempt to download and execute payloads for Cobalt Strike DNS beacons,” according to an analysis released Friday.
Cisco Talos researchers previously observed an increase in DNS requests connected with Lemon Duck’s C2 and mining servers last August, with the attacks mainly targeting Egypt, India, Iran, the Philippines and Vietnam. In the latest rash of attacks, which began in April, the group has changed up its geographic targets to focus primarily on North America, followed by Europe and Southeast Asia, and a handful of victims in Africa and South America. Targeting Exchange Servers with Monero-MiningProxyLogon consists of four flaws (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) that can be chained together to create a pre-authentication remote code execution (RCE) exploit – meaning that attackers can take over servers without knowing any valid account credentials. This gives them access to email communications and the opportunity to install a web shell for further exploitation within the environment, such as the deployment of ransomware.
See Also: Offensive Security Tool: EyeWitness The highly publicized exploit chain suffered a barrage of attacks from advanced persistent threat (APT) groups to infect systems with everything from ransomware to info-stealers, and now financially motivated groups are getting in on the action too.
In Lemon Duck’s case, once the Exchange servers are compromised, it executes various system commands using the Windows Control Manager (sc.exe), including copying two .ASPX files named “wanlins.aspx” and “wanlin.aspx.”
“These files are likely web shells and were copied from C:\inetpub\wwwroot\aspnet_client\, a known directory where[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Lemon Duck Cryptojacking Botnet Changes Up Tactics https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Lemon Duck Cryptojacking Botnet Changes Up TacticsPost Views: 54 Reading Time:…
a majority of the web shells were initially observed following Microsoft’s release of details related to Hafnium activity,” according to the research.
Next, Cisco Talos researchers observed the echo command being used to write code associated with a web shell into the previously created ASPX files, and the modification of the Windows registry to enable RDP access to the system.
“In this case, several characteristics matched portions of code associated with known China Chopper variants identified days after the Exchange Server vulnerabilities were publicized,” they noted. See Also: Hacking Stories: Xbox UndergroundOther interesting aspects of the latest campaign include the fact that Lemon Duck executes a PowerShell script that downloads and executes an additional malware payload, “syspstem.dat,” which includes a “killer” module which contains a hardcoded list of competing cryptocurrency miners that Lemon Duck disables. The module is run every 50 minutes.
Also, the malware is now leveraging Certutil to download and execute two new malicious PowerShell scripts, researchers said. Certutil is a native Windows command-line program that is installed as part of Certificate Services. It is used to verify and dump Certificate Authority (CA) information, get and publish new certificate revocation lists, and so on.
One of the PowerShell scripts, named “dn.ps1,” attempts to uninstall multiple antivirus products, and also retrieves a Cobalt Strike payload. Cobalt Strike Added to the MixCobalt Strike is a penetration-testing tool that’s commercially available. It sends out beacons to detect network vulnerabilities. When used for its intended purpose, it simulates an attack. Threat actors have since figured out how to turn it against networks to exfiltrate data, deliver malware and create fake C2 profiles that look legitimate and avoid detection.
Lemon Duck’s Cobalt Strike payload is configured as a Windows DNS beacon and attempts to communicate with the C2 server using a DNS-based covert channel, researchers noted. The beacon then communicates with this specific subdomain to transmit encoded data via DNS A record query requests.
“This represents a new TTP for Lemon Duck, and is another example of their reliance on offensive security tools (OSTs), including Powersploit’s reflective loader and a modified Mimikatz, which are already included as additional modules and components of Lemon Duck and used throughout the typical attack lifecycle,” according to Cisco Talos. Lemon Duck’s Fresh Anti-Detection TricksWhile Lemon Duck casts a wide net in terms of victimology, it has been exclusively using websites within the TLDs for China (“.cn”), Japan (“.jp”) and South Korea (“.kr”) for its C2 activities since February, rather than the more familiar “.com” or “.net.”
“Considering these [TLDs] are most commonly used for websites in their respective countries and languages…this may allow the threat actor to more effectively hide C2 communications among other web traffic present in victim environments,” according to Cisco Talos. “Due to the prevalence of domains using these [TLDs], web traffic to the domains…may be more easily attributed as noise to victims within these countries.”
During the Lemon Duck infection process, PowerShell is used to invoke the “GetHostAddresses” method from the .NET runtime class “Net.Dns” to obtain the current IP address for an attacker-controlled domain, researchers explained.
“This IP address is combined with a fake hostname hardcoded into the PowerShell command and written as an entry to the Windows hosts file,” they said. “This mechanism allows name resolution to continue even if DNS-based security controls are later deployed, as the translation is now recorded locally and future resolution requests no longer rely upon upstream infrastructure such as DNS servers. This may allow the adversary to achieve longer-term persistence once operational in victi[...]
___________________________
@hacking_Attack
@Hacking_Video
Next, Cisco Talos researchers observed the echo command being used to write code associated with a web shell into the previously created ASPX files, and the modification of the Windows registry to enable RDP access to the system.
“In this case, several characteristics matched portions of code associated with known China Chopper variants identified days after the Exchange Server vulnerabilities were publicized,” they noted. See Also: Hacking Stories: Xbox UndergroundOther interesting aspects of the latest campaign include the fact that Lemon Duck executes a PowerShell script that downloads and executes an additional malware payload, “syspstem.dat,” which includes a “killer” module which contains a hardcoded list of competing cryptocurrency miners that Lemon Duck disables. The module is run every 50 minutes.
Also, the malware is now leveraging Certutil to download and execute two new malicious PowerShell scripts, researchers said. Certutil is a native Windows command-line program that is installed as part of Certificate Services. It is used to verify and dump Certificate Authority (CA) information, get and publish new certificate revocation lists, and so on.
One of the PowerShell scripts, named “dn.ps1,” attempts to uninstall multiple antivirus products, and also retrieves a Cobalt Strike payload. Cobalt Strike Added to the MixCobalt Strike is a penetration-testing tool that’s commercially available. It sends out beacons to detect network vulnerabilities. When used for its intended purpose, it simulates an attack. Threat actors have since figured out how to turn it against networks to exfiltrate data, deliver malware and create fake C2 profiles that look legitimate and avoid detection.
Lemon Duck’s Cobalt Strike payload is configured as a Windows DNS beacon and attempts to communicate with the C2 server using a DNS-based covert channel, researchers noted. The beacon then communicates with this specific subdomain to transmit encoded data via DNS A record query requests.
“This represents a new TTP for Lemon Duck, and is another example of their reliance on offensive security tools (OSTs), including Powersploit’s reflective loader and a modified Mimikatz, which are already included as additional modules and components of Lemon Duck and used throughout the typical attack lifecycle,” according to Cisco Talos. Lemon Duck’s Fresh Anti-Detection TricksWhile Lemon Duck casts a wide net in terms of victimology, it has been exclusively using websites within the TLDs for China (“.cn”), Japan (“.jp”) and South Korea (“.kr”) for its C2 activities since February, rather than the more familiar “.com” or “.net.”
“Considering these [TLDs] are most commonly used for websites in their respective countries and languages…this may allow the threat actor to more effectively hide C2 communications among other web traffic present in victim environments,” according to Cisco Talos. “Due to the prevalence of domains using these [TLDs], web traffic to the domains…may be more easily attributed as noise to victims within these countries.”
During the Lemon Duck infection process, PowerShell is used to invoke the “GetHostAddresses” method from the .NET runtime class “Net.Dns” to obtain the current IP address for an attacker-controlled domain, researchers explained.
“This IP address is combined with a fake hostname hardcoded into the PowerShell command and written as an entry to the Windows hosts file,” they said. “This mechanism allows name resolution to continue even if DNS-based security controls are later deployed, as the translation is now recorded locally and future resolution requests no longer rely upon upstream infrastructure such as DNS servers. This may allow the adversary to achieve longer-term persistence once operational in victi[...]
___________________________
@hacking_Attack
@Hacking_Video