View Single Post
  #8  
Old 02-20-2017, 17:42
Shub-Nigurrath's Avatar
Shub-Nigurrath Shub-Nigurrath is offline
VIP
 
Join Date: Mar 2004
Location: Obscure Kadath
Posts: 971
Rept. Given: 70
Rept. Rcvd 431 Times in 101 Posts
Thanks Given: 83
Thanks Rcvd at 405 Times in 127 Posts
Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499
Hi,
the monetization of attacks is nowadays a matter of few minutes. Usually highly targeted phish champains last for 20 minutes or even less. This time window is, in most of the cases, enough to collect a first round of victims (usually quite high, around 15%) that can be used to prepare a second even more targetized round.

This is the way the enterprises are hit by highly targeted attacks and a fileless malware is perfect for these situations:
1. a phish mail (built using the correct mix of social engineering and memetics, to be *really* effective)
2. the mail points to a fake web site (or a trampoline through defaced hosts) that runs on a fast-flux IP for very few minutes
3. the page fingerprints the browser and delivers an ad-hoc fileless malware (crafted in realtime by a malware forgery), that contains a payload encrypted enough well (usually two custom encryptions is enough) to use, not an original development, but even a metasploit engine.
4. the payload is decrypted in a fileless system, bang, done. You can use anythings ranging from droppers, metasploits, AutoIt, ...

Persistence is not an issue anymore in several situations. Btw, the only reason for speaking of fileless malware today is that the knowledge level required to do one has been decreased by the adoption of powershell and by the development of some frameworks (see my first post). Less cumbersome to write, more samples spreading around.

The perfect solution for today's attacks, this is the essence of what the reports says ... ;-)
__________________
Ŝħůb-Ňìĝùŕřaŧħ ₪)
There are only 10 types of people in the world: Those who understand binary, and those who don't
http://www.accessroot.com

Last edited by Shub-Nigurrath; 02-20-2017 at 17:48.
Reply With Quote