PatrickStaubmann-TA577从你身边走过-Pikabot中的间接系统调用

3.0 2025-05-10 22 0 1385 KB 30 页 PDF
侵权投诉
PatrickStaubmann-TA577从你身边走过-Pikabot中的间接系统调用
PatrickStaubmann-TA577从你身边走过-Pikabot中的间接系统调用
PatrickStaubmann-TA577从你身边走过-Pikabot中的间接系统调用
PatrickStaubmann-TA577从你身边走过-Pikabot中的间接系统调用
PatrickStaubmann-TA577从你身边走过-Pikabot中的间接系统调用
摘要:

TA577 Walked Just Past YouIndirect Syscalls in PikabotPatrick StaubmannTeam Lead Threat AnalysisVMRay GmbH2Pikabot OverviewFirst SeenClassificationThreat ActorEvasion TechniquesEarly 2023(Down-) LoaderBackdoorTA577(Water Curupira)Well known for distributing QBotDistribution of Black Basta ransomware…Indirect System Calls3A closer look to PikabotLoading core modulePikabot went dark in 2024 (Operation Endgame).But…we may see “powered-up”variants with enhanced loader and core modules.LoaderC2 CommunicationInjector (PE & Shellcode)Command ExecutionData Collection / FingerprintingCore Module4Pikabot’s Evasion TechniquesHardware-based EvasionTiming-based EvasionLimited ResourcesMore than 2 CPU Cores?At least 2 GB of memory?Sleep for certain timeto hide behaviorUncommon API to pause executionBeep()5UncoveringIndirect Syscalls6WINDOWS API7From User Modeto Kernel ModeUSER MODEKERNELsample.exe..instruction....instruction..callCreateFileWkernelbase.dllCreateFileW..instruction....instruction..cal

展开>> 收起<<
PatrickStaubmann-TA577从你身边走过-Pikabot中的间接系统调用

共 30 页,预览3页

还剩27页未读, 继续阅读

声明:企商查报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
作者: 分类: 属性:30 页 大小:1385 KB 格式:PDF 时间:2025-05-10

开通VIP享超值会员特权

  • 多端同步记录
  • 高速下载文档
  • 免费文档工具
  • 分享文档赚钱
  • 每日登录抽奖
  • 优质衍生服务
/ 3
客服
关注