从BYOVD到0-day揭露网络招聘骗局中的高级漏洞利用

3.0 2025-05-10 94 0 2024 KB 33 页 PDF
侵权投诉
从BYOVD到0-day揭露网络招聘骗局中的高级漏洞利用
从BYOVD到0-day揭露网络招聘骗局中的高级漏洞利用
从BYOVD到0-day揭露网络招聘骗局中的高级漏洞利用
从BYOVD到0-day揭露网络招聘骗局中的高级漏洞利用
从BYOVD到0-day揭露网络招聘骗局中的高级漏洞利用
摘要:

#BHASIA @BlackHatEventsFrom BYOVD to a 0-day:Unveiling Advanced Exploits inCyber Recruiting ScamsSpeakers: Luigino Camastra, Igor MorgensternContributor: Jan Vojtesek# BHASIA @BlackHatEventsAgenda•Introduction to prior research•Attack chain analysis•Initial ISO image•Loaders•RAT•0-day and vulnerability analysis•Rootkit analysis# BHASIA @BlackHatEventsPrior research# BHASIA @BlackHatEventsAttack chain analysis•The attack is initiated by presenting a fabricated job offer•Contacting via LinkedIn, WhatsApp, email or other platforms# BHASIA @BlackHatEventsAttack chain analysisRollFling Loader•Shellcode executed in memory•Discovered a new loader we called RollFling and NLS file•Malicious DLL established as a service•Kickstart execution chain•Loading next stage•obtaining XOR key by calling GetSystemFirmwareTable API•XOR decryption of file with .nls extension•RollSling loader is encrypted in NLS file•Loading decrypted RollSling into memory# BHASIA @BlackHatEventsAttack chain analysis•Rol

展开>> 收起<<
从BYOVD到0-day揭露网络招聘骗局中的高级漏洞利用

共 33 页,预览3页

还剩30页未读, 继续阅读

声明:企商查报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
作者: 分类: 属性:33 页 大小:2024 KB 格式:PDF 时间:2025-05-10

开通VIP享超值会员特权

  • 多端同步记录
  • 高速下载文档
  • 免费文档工具
  • 分享文档赚钱
  • 每日登录抽奖
  • 优质衍生服务
/ 3
客服
关注