Learn about DLL Search Order Hijacking and DLL Side-Loading to understand how AV products can be used to run malware.
** Analysis Part 2 **
• MALWARE ANALYSIS | Reversing IDAT (Hijack)...
** Find me at **
Twitter/X - / cyberraiju
Blog - https://www.jaiminton.com/
Mastodon - https://infosec.exchange/@CyberRaiju
** Tools **
FLARE VM - https://github.com/mandiant/flare-vm
Notepad++ - https://notepad-plus-plus.org/
Ghidra - https://github.com/NationalSecurityAg...
Detect-It-Easy - https://github.com/horsicq/Detect-It-...
pestudio - https://www.winitor.com/download
HxD - https://mh-nexus.de/en/hxd/
** Samples **
https://www.virustotal.com/gui/file/a...
https://www.virustotal.com/gui/file/2...
https://www.virustotal.com/gui/file/f...
* Further Reading*
https://www.rapid7.com/blog/post/2023...
https://www.mandiant.com/sites/defaul...
https://attack.mitre.org/techniques/T...
https://attack.mitre.org/techniques/T...
https://en.wikipedia.org/wiki/Bitwise...
https://en.wikipedia.org/wiki/Code_se...
** Understanding DLL Hijacking and Securing Software During Development **
https://learn.microsoft.com/en-us/win...
https://learn.microsoft.com/en-us/win...
https://learn.microsoft.com/en-us/win...
** Timestamps **
00:00 - Intro
00:10 - Understanding DLLs
00:10 - DLL Side-Loading and DLL Search Order Hijacking
00:35 - Malicious DLL in action
01:05 - DLL Search Order
01:30 - dbghelp.dll
01:45 - DLL Search Order Hijacking
01:56 - DLL Side-Loading
02:05 - WinSxS Directory
02:55 - Windows Defender ATP Sense CE
03:09 - Malicious MpGear.dll
03:22 - Comparing legitimate and malicious MpGear.dll
04:45 - Comparing differences in Ghidra
06:20 - TL;DR on IDAT Injector
06:49 - Locating malicious code to be injected
07:17 - Examining hidden code in hex editor
07:57 - Decrypting IDAT Injector
08:53 - Understanding Injection Commonalities
09:07 - How the malicious DLL runs code
09:40 - Examining code strings
10:17 - Outro
Credits:
SFX by Pixabay
Reports by Mandiant and Rapid7