Case study ★ Red Team Technical ‣ Discovery ‣ Lateral movement ‣ Privilege escalation Content ★ Basic Forensic ‣ System Forensic ‣ Traffic Forensic ‣ Malware Reverse
which gains unauthorized access to a computer network and remains undetected for an extended period. [ ★ Cyber crime VS APT group VS security researcher What’s APT
of computers Real World Incident: Shadow Hammer ASUS ASUS Live Update is an online update driver. It can detect whether there are any new versions of the programs released on the ASUS Website and then automatically updates your BIOS, Drivers, and Applications.
of computers Real World Incident: Shadow Hammer Installer Setup.exe Normal Code Shellcode Compare mac addr Create a log file Access a domain & Download shellcode Targeted mac addr md5 list
Shellcode Compare mac addr Create a log file Access a domain & Download shellcode Targeted mac addr md5 list https://securelist.com/operation-shadowhammer-a-high-profile-supply-chain-attack/90380/
AUG OCT JUN MAY APR MAR FEB 中油勒索病毒攻擊 ASUS (ShadowHammer):https://www.ithome.com.tw/news/129588 中油 (APT41):https://medium.com/cycraft/taiwan-ransomware-1-23b7e7e17270 醫療單位:https://www.ithome.com.tw/news/134108 Garmin (Evil Corp):https://netmag.tw/2020/07/30/garmin證實遭駭客勒索軟體攻擊-深入剖析全球服務⼤當 台塑勒索病毒攻擊 Garmin 勒索病毒攻擊 仁寶勒索病毒攻擊 2018 2019 2020 台積電產線中毒 ASUS 供應鏈攻擊 研華勒索病毒攻擊 鴻海勒索病毒攻擊 立成勒索病毒攻擊 22間醫療單位勒索病毒攻擊
windows will use system mode to install .msi installer ★ Path: Local group policy edit -> admin templete -> windows installer -> Always install with elevated privileges AlwaysInstallElevated
Threat Intelligence A B C D D C B A Endpoint detection Tech. to discover potential threat Validate, understand, and react to events happening simultaneously in an environment Manual reverse to understand the behavior and purpose of a suspicious file Information about threats and threat actors that helps mitigate harmful events in cyberspace
Attacker & victims ‣ Attack period ‣ Number of infected computer ‣ Any files or things leave in the computer ‣ What kind of attack method & technical ‣ Communicate with C2