Live Stream VOD: 3CX Supply Chain Attack Malware Analyzed
🕑 Added 2023-04-02 01:14:41 +0000 UTCIn this Twitch lives stream we reverse engineer the 3CX software backdoor and associated downloader chain.
Samples
- 3CXDesktopApp-18.12.416.msi
59e1edf4d82fae4978e97512b0331b7eb21dd4b838b850ba46794d9c7a2c0983 - icon15.ico
f47c883f59a4802514c57680de3f41f690871e26f250c6e890651ba71027e4d3
Notes
3CX Supply Chain Attack: Taking a closer look at the delivery of this malware
Comments
m4n0w4r
For filling the b64string (or any strings) into the buffer in x64dbg, you can select the range that equal to string lenght, then right click -> Binary -> Fill, then select String tab, paste your string to the text box and OK --> boom .. magic :D
gdpqq
<3 THANKS!
OALABS
Ah my bad, here is the code that calculates the time https://imgur.com/HHmDQVq rand()% 1800000 --> random between 0 and 20days ~20hours + 604800 -> 7 days added to the calculated time so this gives use between 7 days and 27days ~20hours
gdpqq
Thank you, herrcore! I actually had a question on the 7 to 20 day range from the writeup, but no worries, I realize that was not the focus of the stream. Thanks again for the quality content!
OALABS
We didn't triage this part on stream but I took a quick look after and detailed the functionality in our notes here https://research.openanalysis.net/3cx/northkorea/apt/triage/2023/03/30/3cx-malware.html#Functionality
gdpqq
Thanks for triaging this! I really enjoyed it. Quick question on the delay - isn't it ~20 days + 7 days? (up to ~27 days)?