2024-01-01から1年間の記事一覧

Malware Transmutation! - Unveiling the Hidden Traces of BloodAlchemy

Introduction Malware group History Analysis of BloodAlchemy Initial infection vector and infection flow Analysis of malicious DLL Analysis of shellcode Analysis of payload (BloodAlchemy) Structures Functions Creation of VFT associated with…

Unraveling the Shinigami's prank hidden in spam emails

Introduction Infection flow Malicious email Analysis results Discussion Countermeasures IoCs This post is also available in: 日本語 Introduction ITOCHU Cyber & Intelligence Inc. (abbr. : ICI) routinely observes a large volume of spam email…

The Endless Struggle Against APT10: Insights from LODEINFO v0.6.6 - v0.7.3 Analysis

What is the LODEINFO malware? Analysis of LODEINFO The infection flow Update of the Downloader Shellcode Remote Template Injection Maldoc VBA code embedded in Maldoc Microsoft Office language check The Downloader Shellcode Fake PEM file de…