Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Understanding Authentication and Web Storage
https://cdn-images-1.medium.com/max/1091/1*DoSwjijyLmSPtSi93aU3rg.png
Basics of Auth and Web Storage for Hackers
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Understanding Authentication and Web Storage
https://cdn-images-1.medium.com/max/1091/1*DoSwjijyLmSPtSi93aU3rg.png
Basics of Auth and Web Storage for Hackers
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Understanding Authentication and Web Storage
Basics of Auth and Web Storage for Hackers
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Most Common Python Vulnerabilities and How To Avoid Them
https://cdn-images-1.medium.com/max/1600/0*UVF8UTHcBz7YgRw0
Everybody knows about Python. It’s now the second-most popular programming language worldwide, having overtaken Java. Not only is it used…
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Most Common Python Vulnerabilities and How To Avoid Them
https://cdn-images-1.medium.com/max/1600/0*UVF8UTHcBz7YgRw0
Everybody knows about Python. It’s now the second-most popular programming language worldwide, having overtaken Java. Not only is it used…
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Most Common Python Vulnerabilities and How To Avoid Them
Everybody knows about Python. It’s now the second-most popular programming language worldwide, having overtaken Java. Not only is it used…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
TryHackMe: Inclusion
https://cdn-images-1.medium.com/max/1986/1*uyyn42RTUamNNhN0OPWlbA.png
This is a walkthrough of TryHackMe’s Inclusion room. This is a web-focused room that has a local file inclusion vulnerability.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
TryHackMe: Inclusion
https://cdn-images-1.medium.com/max/1986/1*uyyn42RTUamNNhN0OPWlbA.png
This is a walkthrough of TryHackMe’s Inclusion room. This is a web-focused room that has a local file inclusion vulnerability.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
TryHackMe: Inclusion
This is a walkthrough of TryHackMe’s Inclusion room. This is a web-focused room that has a local file inclusion vulnerability.
What's the best way to pentest a firewall or VPN concentrator ?
https://www.reddit.com/r/Pentesting/comments/n9ngl4/whats_the_best_way_to_pentest_a_firewall_or_vpn/
This is the first time pentesting a FW or VPN I know nmap and ike-scan can be used but what else can I try ? I'm already using Burp for the Web interface but anything I'm missing ? submitted by /u/uneeed2ketchup (https://www.reddit.com/user/uneeed2ketchup)
[link] (https://www.reddit.com/r/Pentesting/comments/n9ngl4/whats_the_best_way_to_pentest_a_firewall_or_vpn/) [comments] (https://www.reddit.com/r/Pentesting/comments/n9ngl4/whats_the_best_way_to_pentest_a_firewall_or_vpn/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/n9ngl4/whats_the_best_way_to_pentest_a_firewall_or_vpn/
This is the first time pentesting a FW or VPN I know nmap and ike-scan can be used but what else can I try ? I'm already using Burp for the Web interface but anything I'm missing ? submitted by /u/uneeed2ketchup (https://www.reddit.com/user/uneeed2ketchup)
[link] (https://www.reddit.com/r/Pentesting/comments/n9ngl4/whats_the_best_way_to_pentest_a_firewall_or_vpn/) [comments] (https://www.reddit.com/r/Pentesting/comments/n9ngl4/whats_the_best_way_to_pentest_a_firewall_or_vpn/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
What's the best way to pentest a firewall or VPN concentrator ?
This is the first time pentesting a FW or VPN I know nmap and ike-scan can be used but what else can I try ? I'm already using Burp for the Web...
My Bug Bounty Journey & Ranking 1st in U.S. DoD & Achieving top 100 hackers in 1 year
I am sharing some of my methodology, recourses, tips and advices to become a better bug bounty hunter.
Read more...
I am sharing some of my methodology, recourses, tips and advices to become a better bug bounty hunter.
Read more...
Deep Web
Got ahead of myself
I'm afraid that my identity - social, DL, Birth certificate, etc... was compromised on the dark web and it has me very paranoid. I think there are people after me, and I don't understand what I could be up against. I put up a VPN and am avoiding answering any calls I don't know. Is there anyone that could give me more information, so I can deal with this?
submitted by /u/mjharris015
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Got ahead of myself
I'm afraid that my identity - social, DL, Birth certificate, etc... was compromised on the dark web and it has me very paranoid. I think there are people after me, and I don't understand what I could be up against. I put up a VPN and am avoiding answering any calls I don't know. Is there anyone that could give me more information, so I can deal with this?
submitted by /u/mjharris015
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Got ahead of myself
I'm afraid that my identity - social, DL, Birth certificate, etc... was compromised on the dark web and it has me very paranoid. I think there are...
Help me out with the cyber sec proj
https://www.reddit.com/r/Pentesting/comments/n9oixf/help_me_out_with_the_cyber_sec_proj/
I came hare today cause I immensely benefitted from your help the last time as well. Help a fellow brother out. I need to do this for internship. You have to solve the below challenges and create proper report of your finding and approach that how you solved the challenge with supportive proof of concept (POC) in form of screenshot. Web: 1. Fuzzing : http://65.2.6.176:6008/ 2. Post_me: http://65.2.6.176:8003/ 3. Enum: http://65.2.6.176:7003/ 4. Fetch_me: http://65.2.6.176:8007/ 5. Find_me: http://65.2.6.176:9009/ Misc: 1. Founder: https://drive.google.com/file/d/1uAOHxyRV63Qn3gDmZWDa6-dZzmH6qVOU/view?usp=sharing 2. Hex : https://drive.google.com/file/d/1\_8Gwe0lEpcLfcVCv3vvTG7nStS8R9Fl1/view?usp=sharing (https://drive.google.com/file/d/1%5C_8Gwe0lEpcLfcVCv3vvTG7nStS8R9Fl1/view?usp=sharing) 3. Steg_Mirror: https://drive.google.com/file/d/1HHB9Rzbxf2rd_2kbC4craJ44bRvyAKv_/view?usp=sharing Reverse: 1. Hitpass: https://drive.google.com/file/d/1dlGv1nsZlc70Jy5D54wjcQtMny6I36so/view?usp=sharing 2. Goofy: https://drive.google.com/file/d/1NcEP7ab77_539E09fu5lqtLSXHJsNSGa/view?usp=sharing Cryptography 1. Agent_cat: https://drive.google.com/file/d/13NWZXRYW6Jfe_w_hLM2BLB_Q_boJ093z/view?usp=sharing 2. Double_trouble: DJWbMJE5LHAHEagWK2uuqTIsMT91LzkyK2IhL3W5pUEco259 3. Vision: https://drive.google.com/file/d/1Cus7IsGwSn85C_WXP6zt5aDeVg7fvdG5/view?usp=sharing submitted by /u/Crafty-Blacksmith-99 (https://www.reddit.com/user/Crafty-Blacksmith-99)
[link] (https://www.reddit.com/r/Pentesting/comments/n9oixf/help_me_out_with_the_cyber_sec_proj/) [comments] (https://www.reddit.com/r/Pentesting/comments/n9oixf/help_me_out_with_the_cyber_sec_proj/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/n9oixf/help_me_out_with_the_cyber_sec_proj/
I came hare today cause I immensely benefitted from your help the last time as well. Help a fellow brother out. I need to do this for internship. You have to solve the below challenges and create proper report of your finding and approach that how you solved the challenge with supportive proof of concept (POC) in form of screenshot. Web: 1. Fuzzing : http://65.2.6.176:6008/ 2. Post_me: http://65.2.6.176:8003/ 3. Enum: http://65.2.6.176:7003/ 4. Fetch_me: http://65.2.6.176:8007/ 5. Find_me: http://65.2.6.176:9009/ Misc: 1. Founder: https://drive.google.com/file/d/1uAOHxyRV63Qn3gDmZWDa6-dZzmH6qVOU/view?usp=sharing 2. Hex : https://drive.google.com/file/d/1\_8Gwe0lEpcLfcVCv3vvTG7nStS8R9Fl1/view?usp=sharing (https://drive.google.com/file/d/1%5C_8Gwe0lEpcLfcVCv3vvTG7nStS8R9Fl1/view?usp=sharing) 3. Steg_Mirror: https://drive.google.com/file/d/1HHB9Rzbxf2rd_2kbC4craJ44bRvyAKv_/view?usp=sharing Reverse: 1. Hitpass: https://drive.google.com/file/d/1dlGv1nsZlc70Jy5D54wjcQtMny6I36so/view?usp=sharing 2. Goofy: https://drive.google.com/file/d/1NcEP7ab77_539E09fu5lqtLSXHJsNSGa/view?usp=sharing Cryptography 1. Agent_cat: https://drive.google.com/file/d/13NWZXRYW6Jfe_w_hLM2BLB_Q_boJ093z/view?usp=sharing 2. Double_trouble: DJWbMJE5LHAHEagWK2uuqTIsMT91LzkyK2IhL3W5pUEco259 3. Vision: https://drive.google.com/file/d/1Cus7IsGwSn85C_WXP6zt5aDeVg7fvdG5/view?usp=sharing submitted by /u/Crafty-Blacksmith-99 (https://www.reddit.com/user/Crafty-Blacksmith-99)
[link] (https://www.reddit.com/r/Pentesting/comments/n9oixf/help_me_out_with_the_cyber_sec_proj/) [comments] (https://www.reddit.com/r/Pentesting/comments/n9oixf/help_me_out_with_the_cyber_sec_proj/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Help me out with the cyber sec proj
I came hare today cause I immensely benefitted from your help the last time as well. Help a fellow brother out. I need to do this for internship. ...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Understanding and exploiting HTTP for bug bounty
https://cdn-images-1.medium.com/max/630/1*eP0ONHYjifhm2NnG0od3Ng.jpeg
Whenever we open a browser and search something on the internet we make an HTTP request.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Understanding and exploiting HTTP for bug bounty
https://cdn-images-1.medium.com/max/630/1*eP0ONHYjifhm2NnG0od3Ng.jpeg
Whenever we open a browser and search something on the internet we make an HTTP request.
Continue reading on InfoSec Write-ups »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Understanding and exploiting HTTP for bug bounty
Whenever we open a browser and search something on the internet we make an HTTP request.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Xcode Ghost: How The Biggest Apple Hack In History Came About
https://cdn-images-1.medium.com/max/2600/0*kLkdA_FtPLYUATuf
As part of the Epic process, internal emails from 2015 were released providing new information about Xcode Ghost
Continue reading on Mac O’Clock »
___________________________
@hacking_Attack
@Hacking_Video
Xcode Ghost: How The Biggest Apple Hack In History Came About
https://cdn-images-1.medium.com/max/2600/0*kLkdA_FtPLYUATuf
As part of the Epic process, internal emails from 2015 were released providing new information about Xcode Ghost
Continue reading on Mac O’Clock »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Xcode Ghost: How The Biggest Apple Hack In History Came About
As part of the Epic process, internal emails from 2015 were released providing new information about Xcode Ghost
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Key Tips To Avoid Cyber Scams | CIO Applications
https://cdn-images-1.medium.com/max/2600/0*AIenV87SQd9doVRG
Source — CIO Applications
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Key Tips To Avoid Cyber Scams | CIO Applications
https://cdn-images-1.medium.com/max/2600/0*AIenV87SQd9doVRG
Source — CIO Applications
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Key Tips To Avoid Cyber Scams | CIO Applications
Source — CIO Applications
Hacking Articles Tips Tricks Videos Tutorials
Photo
Deep Web
Tracking One Year of Malicious Tor Exit Relay Activities (Part II)
https://external-preview.redd.it/q1TpXaQp1Vvct5bQX4SU4_cYlVIfPnUA6tsPp5Gv-RU.jpg?width=640&crop=smart&auto=webp&s=9467456b41879dfc78108e23fe54ccf1ac933ee9 submitted by /u/rangeva
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Tracking One Year of Malicious Tor Exit Relay Activities (Part II)
https://external-preview.redd.it/q1TpXaQp1Vvct5bQX4SU4_cYlVIfPnUA6tsPp5Gv-RU.jpg?width=640&crop=smart&auto=webp&s=9467456b41879dfc78108e23fe54ccf1ac933ee9 submitted by /u/rangeva
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Tracking One Year of Malicious Tor Exit Relay Activities (Part II)
Posted in r/deepweb by u/rangeva • 1 point and 0 comments
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Lemon Duck Cryptojacking Botnet Changes Up Tactics
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Lemon Duck Cryptojacking Botnet Changes Up TacticsPost Views: 54
Reading Time: 2 Minutes
The Lemon Duck cryptocurrency-mining botnet has added the ProxyLogon group of exploits to its bag of tricks, targeting Microsoft Exchange servers.
That’s according to researchers at Cisco Talos, who said that the cybercrime group behind Lemon Duck has also added the Cobalt Strike attack framework into its malware toolkit and has beefed up anti-detection capabilities. On the latter front, it’s using fake domains on East Asian top-level domains (TLDs) to hide command-and-control (C2) infrastructure.
Lemon Duck targets victims’ computer resources to mine the Monero virtual currency, with self-propagating capabilities and a modular framework that allows it to infect additional systems that become part of the botnet. It has been active since at least the end of December 2018, and Cisco Talos calls it “one of the more complex” mining botnets, with several interesting tricks up its sleeve.
For instance, Lemon Duck has at least 12 different initial-infection vectors – more than most malware, with Proxylogon exploits only the latest addition. Its existing capabilities ranged from Server Message Block (SMB) and Remote Desktop Protocol (RDP) password brute-forcing; targeting the RDP BlueKeep flaw (CVE-2019-0708) in Windows machines; targeting internet-of-things devices with weak or default passwords; and exploiting vulnerabilities in Redis (an open-source, in-memory data structure store used as a database, cache and message broker) and YARN Hadoop (a resource-management and job-scheduling technology) in Linux machines.
See Also: iPhone Hack Allegedly Used to Spy on China’s Uyghurs
“Since April 2021, Cisco Talos has observed updated infrastructure and new components associated with the Lemon Duck that target unpatched Microsoft Exchange Servers and attempt to download and execute payloads for Cobalt Strike DNS beacons,” according to an analysis released Friday.
Cisco Talos researchers previously observed an increase in DNS requests connected with Lemon Duck’s C2 and mining servers last August, with the attacks mainly targeting Egypt, India, Iran, the Philippines and Vietnam. In the latest rash of attacks, which began in April, the group has changed up its geographic targets to focus primarily on North America, followed by Europe and Southeast Asia, and a handful of victims in Africa and South America. Targeting Exchange Servers with Monero-MiningProxyLogon consists of four flaws (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) that can be chained together to create a pre-authentication remote code execution (RCE) exploit – meaning that attackers can take over servers without knowing any valid account credentials. This gives them access to email communications and the opportunity to install a web shell for further exploitation within the environment, such as the deployment of ransomware.
See Also: Offensive Security Tool: EyeWitness The highly publicized exploit chain suffered a barrage of attacks from advanced persistent threat (APT) groups to infect systems with everything from ransomware to info-stealers, and now financially motivated groups are getting in on the action too.
In Lemon Duck’s case, once the Exchange servers are compromised, it executes various system commands using the Windows Control Manager (sc.exe), including copying two .ASPX files named “wanlins.aspx” and “wanlin.aspx.”
“These files are likely web shells and were copied from C:\inetpub\wwwroot\aspnet_client\, a known directory where[...]
___________________________
@hacking_Attack
@Hacking_Video
Lemon Duck Cryptojacking Botnet Changes Up Tactics
https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Lemon Duck Cryptojacking Botnet Changes Up TacticsPost Views: 54
Reading Time: 2 Minutes
The Lemon Duck cryptocurrency-mining botnet has added the ProxyLogon group of exploits to its bag of tricks, targeting Microsoft Exchange servers.
That’s according to researchers at Cisco Talos, who said that the cybercrime group behind Lemon Duck has also added the Cobalt Strike attack framework into its malware toolkit and has beefed up anti-detection capabilities. On the latter front, it’s using fake domains on East Asian top-level domains (TLDs) to hide command-and-control (C2) infrastructure.
Lemon Duck targets victims’ computer resources to mine the Monero virtual currency, with self-propagating capabilities and a modular framework that allows it to infect additional systems that become part of the botnet. It has been active since at least the end of December 2018, and Cisco Talos calls it “one of the more complex” mining botnets, with several interesting tricks up its sleeve.
For instance, Lemon Duck has at least 12 different initial-infection vectors – more than most malware, with Proxylogon exploits only the latest addition. Its existing capabilities ranged from Server Message Block (SMB) and Remote Desktop Protocol (RDP) password brute-forcing; targeting the RDP BlueKeep flaw (CVE-2019-0708) in Windows machines; targeting internet-of-things devices with weak or default passwords; and exploiting vulnerabilities in Redis (an open-source, in-memory data structure store used as a database, cache and message broker) and YARN Hadoop (a resource-management and job-scheduling technology) in Linux machines.
See Also: iPhone Hack Allegedly Used to Spy on China’s Uyghurs
“Since April 2021, Cisco Talos has observed updated infrastructure and new components associated with the Lemon Duck that target unpatched Microsoft Exchange Servers and attempt to download and execute payloads for Cobalt Strike DNS beacons,” according to an analysis released Friday.
Cisco Talos researchers previously observed an increase in DNS requests connected with Lemon Duck’s C2 and mining servers last August, with the attacks mainly targeting Egypt, India, Iran, the Philippines and Vietnam. In the latest rash of attacks, which began in April, the group has changed up its geographic targets to focus primarily on North America, followed by Europe and Southeast Asia, and a handful of victims in Africa and South America. Targeting Exchange Servers with Monero-MiningProxyLogon consists of four flaws (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065) that can be chained together to create a pre-authentication remote code execution (RCE) exploit – meaning that attackers can take over servers without knowing any valid account credentials. This gives them access to email communications and the opportunity to install a web shell for further exploitation within the environment, such as the deployment of ransomware.
See Also: Offensive Security Tool: EyeWitness The highly publicized exploit chain suffered a barrage of attacks from advanced persistent threat (APT) groups to infect systems with everything from ransomware to info-stealers, and now financially motivated groups are getting in on the action too.
In Lemon Duck’s case, once the Exchange servers are compromised, it executes various system commands using the Windows Control Manager (sc.exe), including copying two .ASPX files named “wanlins.aspx” and “wanlin.aspx.”
“These files are likely web shells and were copied from C:\inetpub\wwwroot\aspnet_client\, a known directory where[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Lemon Duck Cryptojacking Botnet Changes Up Tactics https://www.blackhatethicalhacking.com/wp-content/uploads/2017/11/black-hat-locks-and-electronics.jpg Lemon Duck Cryptojacking Botnet Changes Up TacticsPost Views: 54 Reading Time:…
a majority of the web shells were initially observed following Microsoft’s release of details related to Hafnium activity,” according to the research.
Next, Cisco Talos researchers observed the echo command being used to write code associated with a web shell into the previously created ASPX files, and the modification of the Windows registry to enable RDP access to the system.
“In this case, several characteristics matched portions of code associated with known China Chopper variants identified days after the Exchange Server vulnerabilities were publicized,” they noted. See Also: Hacking Stories: Xbox UndergroundOther interesting aspects of the latest campaign include the fact that Lemon Duck executes a PowerShell script that downloads and executes an additional malware payload, “syspstem.dat,” which includes a “killer” module which contains a hardcoded list of competing cryptocurrency miners that Lemon Duck disables. The module is run every 50 minutes.
Also, the malware is now leveraging Certutil to download and execute two new malicious PowerShell scripts, researchers said. Certutil is a native Windows command-line program that is installed as part of Certificate Services. It is used to verify and dump Certificate Authority (CA) information, get and publish new certificate revocation lists, and so on.
One of the PowerShell scripts, named “dn.ps1,” attempts to uninstall multiple antivirus products, and also retrieves a Cobalt Strike payload. Cobalt Strike Added to the MixCobalt Strike is a penetration-testing tool that’s commercially available. It sends out beacons to detect network vulnerabilities. When used for its intended purpose, it simulates an attack. Threat actors have since figured out how to turn it against networks to exfiltrate data, deliver malware and create fake C2 profiles that look legitimate and avoid detection.
Lemon Duck’s Cobalt Strike payload is configured as a Windows DNS beacon and attempts to communicate with the C2 server using a DNS-based covert channel, researchers noted. The beacon then communicates with this specific subdomain to transmit encoded data via DNS A record query requests.
“This represents a new TTP for Lemon Duck, and is another example of their reliance on offensive security tools (OSTs), including Powersploit’s reflective loader and a modified Mimikatz, which are already included as additional modules and components of Lemon Duck and used throughout the typical attack lifecycle,” according to Cisco Talos. Lemon Duck’s Fresh Anti-Detection TricksWhile Lemon Duck casts a wide net in terms of victimology, it has been exclusively using websites within the TLDs for China (“.cn”), Japan (“.jp”) and South Korea (“.kr”) for its C2 activities since February, rather than the more familiar “.com” or “.net.”
“Considering these [TLDs] are most commonly used for websites in their respective countries and languages…this may allow the threat actor to more effectively hide C2 communications among other web traffic present in victim environments,” according to Cisco Talos. “Due to the prevalence of domains using these [TLDs], web traffic to the domains…may be more easily attributed as noise to victims within these countries.”
During the Lemon Duck infection process, PowerShell is used to invoke the “GetHostAddresses” method from the .NET runtime class “Net.Dns” to obtain the current IP address for an attacker-controlled domain, researchers explained.
“This IP address is combined with a fake hostname hardcoded into the PowerShell command and written as an entry to the Windows hosts file,” they said. “This mechanism allows name resolution to continue even if DNS-based security controls are later deployed, as the translation is now recorded locally and future resolution requests no longer rely upon upstream infrastructure such as DNS servers. This may allow the adversary to achieve longer-term persistence once operational in victi[...]
___________________________
@hacking_Attack
@Hacking_Video
Next, Cisco Talos researchers observed the echo command being used to write code associated with a web shell into the previously created ASPX files, and the modification of the Windows registry to enable RDP access to the system.
“In this case, several characteristics matched portions of code associated with known China Chopper variants identified days after the Exchange Server vulnerabilities were publicized,” they noted. See Also: Hacking Stories: Xbox UndergroundOther interesting aspects of the latest campaign include the fact that Lemon Duck executes a PowerShell script that downloads and executes an additional malware payload, “syspstem.dat,” which includes a “killer” module which contains a hardcoded list of competing cryptocurrency miners that Lemon Duck disables. The module is run every 50 minutes.
Also, the malware is now leveraging Certutil to download and execute two new malicious PowerShell scripts, researchers said. Certutil is a native Windows command-line program that is installed as part of Certificate Services. It is used to verify and dump Certificate Authority (CA) information, get and publish new certificate revocation lists, and so on.
One of the PowerShell scripts, named “dn.ps1,” attempts to uninstall multiple antivirus products, and also retrieves a Cobalt Strike payload. Cobalt Strike Added to the MixCobalt Strike is a penetration-testing tool that’s commercially available. It sends out beacons to detect network vulnerabilities. When used for its intended purpose, it simulates an attack. Threat actors have since figured out how to turn it against networks to exfiltrate data, deliver malware and create fake C2 profiles that look legitimate and avoid detection.
Lemon Duck’s Cobalt Strike payload is configured as a Windows DNS beacon and attempts to communicate with the C2 server using a DNS-based covert channel, researchers noted. The beacon then communicates with this specific subdomain to transmit encoded data via DNS A record query requests.
“This represents a new TTP for Lemon Duck, and is another example of their reliance on offensive security tools (OSTs), including Powersploit’s reflective loader and a modified Mimikatz, which are already included as additional modules and components of Lemon Duck and used throughout the typical attack lifecycle,” according to Cisco Talos. Lemon Duck’s Fresh Anti-Detection TricksWhile Lemon Duck casts a wide net in terms of victimology, it has been exclusively using websites within the TLDs for China (“.cn”), Japan (“.jp”) and South Korea (“.kr”) for its C2 activities since February, rather than the more familiar “.com” or “.net.”
“Considering these [TLDs] are most commonly used for websites in their respective countries and languages…this may allow the threat actor to more effectively hide C2 communications among other web traffic present in victim environments,” according to Cisco Talos. “Due to the prevalence of domains using these [TLDs], web traffic to the domains…may be more easily attributed as noise to victims within these countries.”
During the Lemon Duck infection process, PowerShell is used to invoke the “GetHostAddresses” method from the .NET runtime class “Net.Dns” to obtain the current IP address for an attacker-controlled domain, researchers explained.
“This IP address is combined with a fake hostname hardcoded into the PowerShell command and written as an entry to the Windows hosts file,” they said. “This mechanism allows name resolution to continue even if DNS-based security controls are later deployed, as the translation is now recorded locally and future resolution requests no longer rely upon upstream infrastructure such as DNS servers. This may allow the adversary to achieve longer-term persistence once operational in victi[...]
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
a majority of the web shells were initially observed following Microsoft’s release of details related to Hafnium activity,” according to the research. Next, Cisco Talos researchers observed the echo command being used to write code associated with a web shell…
m environments.” Cryptojackers Take Notice of ProxyLogonLemon Duck is not the first cryptomining malware to add ProxyLogon to its arsenal. For instance, another cryptojacking group was seen in mid-April doing the same thing.
That bad code was fairly simple, but also in mid-April a heretofore little-seen Monero-mining botnet dubbed Prometei began exploiting two of the Microsoft Exchange vulnerabilities in ProxyLogon. This malware is also highly complex and sophisticated, Cybereason researchers noted at the time. While cryptojacking is its current game, researchers warned that Prometei (the Russian word for Prometheus, the Titan god of fire from Greek mythology) gives attackers complete control over infected machines, which makes it capable of doing a wide range of damage.
The threat will likely continue to evolve, Cisco Talos researchers said. They also observed domains linked to Lemon Duck and another cryptocurrency miner, DLTMiner, used in relation to Microsoft Exchange attacks where ransomware was also deployed.
“At this time, there doesn’t appear to be a link between the Lemon Duck components observed there and the reported ransomware (TeslaRVNG2),” according to the analysis. “This suggests that given the nature of the vulnerabilities targeted, we are likely to continue to observe a range of malicious activities in parallel, using similar exploitation techniques and infection vectors to compromise systems. In some cases, attackers may take advantage of artifacts left in place from prior compromises, making distinction more difficult.”
Meanwhile, it’s clear that the threat actor behind Lemon Duck is continuously evolving its approach to maximize the ability to achieve its mission objectives, researchers noted.
“Lemon Duck continues to launch campaigns against systems around the world, attempting to leverage infected systems to mine cryptocurrency and generate revenue for the adversary behind this botnet,” they concluded. “The use of new tools like Cobalt Strike, as well as the implementation of additional obfuscation techniques throughout the attack lifecycle, may enable them to operate more effectively for longer periods within victim environments. … Organizations should remain vigilant against this threat, as it will likely continue to evolve.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/iPhone-Jailbreak-90x90.jpg iPhone Hack Allegedly Used to Spy on China’s Uyghurs1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/cisco-jabber-90x90.jpg Critical Cisco SD-WAN, HyperFlex Bugs Threaten Corporate Networks4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-1-1-90x90.png New Crypto-Stealer ‘Panda’ Spread via Discord5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-1-90x90.png Hundreds of Millions of Dell Users at Risk from Kernel-Privilege Bugs6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/HPE-corp-logo-90x90.jpg Hewlett Packard Enterprise Plugs Critical Bug in Edge Platform Tool1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-90x90.png Chinese hackers targeting Russian nuclear submarine design firm with PortDoor malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/F5-Big-IP-e1619725870974-90x90.jpg F5 Big-IP Vulnerable to Security-Bypass Bug2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Google-Chrome-Browser-1-90x90.jpg Google Chrome V8 Bug Allows Remote Code-Execution2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/apple_logo_store-90x90.jpg Apple Patches Zero-Day MacOS Bug That Can Bypass Anti-Malware Defenses2 weeks ago
* https://www.blackhatethicalhacki[...]
___________________________
@hacking_Attack
@Hacking_Video
That bad code was fairly simple, but also in mid-April a heretofore little-seen Monero-mining botnet dubbed Prometei began exploiting two of the Microsoft Exchange vulnerabilities in ProxyLogon. This malware is also highly complex and sophisticated, Cybereason researchers noted at the time. While cryptojacking is its current game, researchers warned that Prometei (the Russian word for Prometheus, the Titan god of fire from Greek mythology) gives attackers complete control over infected machines, which makes it capable of doing a wide range of damage.
The threat will likely continue to evolve, Cisco Talos researchers said. They also observed domains linked to Lemon Duck and another cryptocurrency miner, DLTMiner, used in relation to Microsoft Exchange attacks where ransomware was also deployed.
“At this time, there doesn’t appear to be a link between the Lemon Duck components observed there and the reported ransomware (TeslaRVNG2),” according to the analysis. “This suggests that given the nature of the vulnerabilities targeted, we are likely to continue to observe a range of malicious activities in parallel, using similar exploitation techniques and infection vectors to compromise systems. In some cases, attackers may take advantage of artifacts left in place from prior compromises, making distinction more difficult.”
Meanwhile, it’s clear that the threat actor behind Lemon Duck is continuously evolving its approach to maximize the ability to achieve its mission objectives, researchers noted.
“Lemon Duck continues to launch campaigns against systems around the world, attempting to leverage infected systems to mine cryptocurrency and generate revenue for the adversary behind this botnet,” they concluded. “The use of new tools like Cobalt Strike, as well as the implementation of additional obfuscation techniques throughout the attack lifecycle, may enable them to operate more effectively for longer periods within victim environments. … Organizations should remain vigilant against this threat, as it will likely continue to evolve.”
Source: threatpost.com (Click Link)Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/iPhone-Jailbreak-90x90.jpg iPhone Hack Allegedly Used to Spy on China’s Uyghurs1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/cisco-jabber-90x90.jpg Critical Cisco SD-WAN, HyperFlex Bugs Threaten Corporate Networks4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-1-1-90x90.png New Crypto-Stealer ‘Panda’ Spread via Discord5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-1-90x90.png Hundreds of Millions of Dell Users at Risk from Kernel-Privilege Bugs6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/HPE-corp-logo-90x90.jpg Hewlett Packard Enterprise Plugs Critical Bug in Edge Platform Tool1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/05/Untitled-design-90x90.png Chinese hackers targeting Russian nuclear submarine design firm with PortDoor malware1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/F5-Big-IP-e1619725870974-90x90.jpg F5 Big-IP Vulnerable to Security-Bypass Bug2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/Google-Chrome-Browser-1-90x90.jpg Google Chrome V8 Bug Allows Remote Code-Execution2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2021/04/apple_logo_store-90x90.jpg Apple Patches Zero-Day MacOS Bug That Can Bypass Anti-Malware Defenses2 weeks ago
* https://www.blackhatethicalhacki[...]
___________________________
@hacking_Attack
@Hacking_Video