6 ms·
It is simply a way for the first stage to keep an updated URL where to download instructions about what to do. Hardcoding URL won’t do it because your URL might
by ploum 3y ago
It is simply a way for the first stage to keep an updated URL where to download instructions about what to do. Hardcoding URL won’t do it because your URL might be taken down quite quickly.
In my days, this was done by connecting to an IRC room and listening for specific messages. I find this way of doing it way more complicated and prone to errors (an IRC client is quite easy to do and there’s no realistic way to prevent anybody to send a strange message in a given room)
- alamortsubite 3y agoMaybe I'm missing something, but whether the first stage points to Ars/Vimeo or directly to the bad-guys, the URL has to be hardcoded somewhere. I think the comment you replied to is probably on the right track; hiding behind a legit intermediary seems a lot less suspicious if someone inspects the payload on the drive.
- acdha 3y agoThe first stage points to arstechnica.com because that’s unlikely to be blocked or attract much attention (your IT guys would probably unblock it). The URL is set on that profile page but the person who controls it can change that any time they want without attracting attention so it’s not hardcoded in the way it would be if it was embedded in the malware executable.
- netsharc 3y agoYeah but a socket connection to an IRC server and port will probably trigger a network monitoring firewall that a computer in the network has been compromised... A connection to arstechnica.com, the IT admin might even think "Cool, I didn't know that Bob from accounting is into tech..."
- willcipriano 3y agoCorporate firewalls throw so many alerts that it's unlikely that a human even sees it let alone looks into it.
- jcrawfordor 3y agoMost corporate SOCs would probably investigate IRC connections at least briefly, they have a very high signal to noise ratio for compromised devices. Modern security devices do generate a tremendous amount of information, but the security operations industry as a whole and SIEMs in particular were developed to make it feasible to risk score and triage these findings.
- willcipriano 3y agoThis is quite the opposite of all my personal experience.
- jdietrich 3y agoA well-configured corporate firewall is going to block anything that looks like an IRC packet, because for the overwhelming majority of users, the probability of that packet being malicious is ~1.
- mintplant 3y agoThis led to many ISPs blocking IRC connections :(
- ploum 3y agoIndeed, that’s probably the reason I was looking for.