Patrefans
oalabs from patreon
oalabs patreon

Live Stream VOD: 3CX Supply Chain Attack Malware Analyzed

🕑 Added 2023-04-02 01:14:41 +0000 UTC
Live Stream VOD: 3CX Supply Chain Attack Malware Analyzed

Comments

m4n0w4r

For filling the b64string (or any strings) into the buffer in x64dbg, you can select the range that equal to string lenght, then right click -> Binary -> Fill, then select String tab, paste your string to the text box and OK --> boom .. magic :D

gdpqq

<3 THANKS!

OALABS

Ah my bad, here is the code that calculates the time https://imgur.com/HHmDQVq rand()% 1800000 --> random between 0 and 20days ~20hours + 604800 -> 7 days added to the calculated time so this gives use between 7 days and 27days ~20hours

gdpqq

Thank you, herrcore! I actually had a question on the 7 to 20 day range from the writeup, but no worries, I realize that was not the focus of the stream. Thanks again for the quality content!

OALABS

We didn't triage this part on stream but I took a quick look after and detailed the functionality in our notes here https://research.openanalysis.net/3cx/northkorea/apt/triage/2023/03/30/3cx-malware.html#Functionality

gdpqq

Thanks for triaging this! I really enjoyed it. Quick question on the delay - isn't it ~20 days + 7 days? (up to ~27 days)?


More Creators