APT32 Malware’s Use Of New Downloader Critical To Its Propagation Success - PowerPoint PPT Presentation

About This Presentation
Title:

APT32 Malware’s Use Of New Downloader Critical To Its Propagation Success

Description:

APT32 malware has been covered here in Hackercombat recently, and we are set to update you of the latest findings from Palo Alto Networks. – PowerPoint PPT presentation

Number of Views:110
Slides: 7
Provided by: charlestonglory

less

Transcript and Presenter's Notes

Title: APT32 Malware’s Use Of New Downloader Critical To Its Propagation Success


1
H A C K E R C O M B A T
APT32 Malwares Use Of New Downloader
Hackercombat.com
2
APT32 MALWARE HAS BEEN COVERED HERE IN
HACKERCOMBAT RECENTLY, AND WE ARE SET TO UPDATE
YOU OF THE LATEST FINDINGS FROM PALO ALTO
NETWORKS.
3
THE PAYLOAD KUSS32.GIF IS DOWNLOADED IF THE PC
IS RUNNING 32-BIT WINDOWS, WHILE KUSS64.GIF IS
DOWNLOADED IF THE MACHINE IS RUNNING A 64-BIT
VERSION OF WINDOWS.
up 2020
4
IF THE MALWARE IS NOT SUCCESSFUL IN PROPAGATION
USING THE MS OFFICE FILE FORMAT, IT WILL SWITCH
TO USING DLL SIDE-LOADING METHOD, THROUGH THE
USE OF A MALFORMED RAR FILE.
5
AS WE CAN SEE IN THIS CASE, THE
PURPOSE OF THE MALWARE IS TO DOWNLOAD AND
EXECUTE THE COBALT STRIKE BEACON PAYLOAD IN
MEMORY.
6
Thank You!
Find Us Online!
https//hackercombat.com/apt32-malwares-use-of-new
-downloader-critical-to-its-propagation-success/
Write a Comment
User Comments (0)
About PowerShow.com