5 ms·
> SysJoker masquerades as a system update and generates its C2 by decoding a string retrieved from a text file hosted on Google Drive. During our analysis the C
by yepthatsreality 5y ago
> SysJoker masquerades as a system update and generates its C2 by decoding a string retrieved from a text file hosted on Google Drive. During our analysis the C2 changed three times, indicating the attacker is active and monitoring for infected machines.
- uniqueuid 5y agoIs that a common technique? Are there other methods in use for masquerading, or do people simply hard-code a group of C2 IPs or DNS entries?
- moritonal 5y agoThere are infinite ways. One for example is to generate a dns address from the uct time and try connect to that. It's easy to simply buy the correct dns name and send an order out to the botnet. Or to hide the commands in a DNS request itself, or lookup a gist, or a tweet ect.
- monkeybutton 5y agoPastebin!
- thatfunkymunki 5y agonot sure if this specific TTP is common, but generally there are a lot of ways that malware authors perform first c2 discovery and then actual c2. attackers can use DNS itself for both of these aspects of C2. Even very old reports of since-long-gone attackers like APT1 https://www.mandiant.com/media/9941/download https://www.mandiant.com/media/9941/download indicate use of covert c2 over otherwise benign web applications like google calendar.
- deleted 5y ago[deleted]
- blacksmith_tb 5y agoThat seems like a fragile command and control choice, couldn't Google just shut down the account that owns the gDoc?
- ASalazarMX 5y agoThe author likely has a pool of fake accounts. Besides, once the C&C is configured the Google Drive link becomes obsolete.
- Thorrez 5y agoBut the malware has to have a list of them in order to check them. Google could deactivate them all at once.