Learn about how you can decrypt AES in CyberChef, and about ISO file forensic artifacts, all whilst investigating a RAT
** Find me at **
Twitter/X - / cyberraiju
Blog - https://www.jaiminton.com/
Mastodon - https://infosec.exchange/@CyberRaiju
** DFIR Cheatsheet **
https://www.jaiminton.com/cheatsheet/...
** Tools **
FLARE VM - https://github.com/mandiant/flare-vm
Notepad++ - https://notepad-plus-plus.org/
HxD - https://mh-nexus.de/en/hxd/
Urlscan - https://urlscan.io/
dnSpyEx - https://github.com/dnSpyEx/dnSpy
de4dot - https://github.com/de4dot/de4dot
CyberChef - https://github.com/gchq/CyberChef
** Sample **
https://bazaar.abuse.ch/sample/5f1d13...
https://www.virustotal.com/gui/file/5...
https://urlscan.io/result/d253ef69-f8...
* Further Reading*
https://blog.talosintelligence.com/as...
https://www.trendmicro.com/en_us/rese...
** Timestamps **
00:00 - Intro
00:20 - Examining file with TrID
00:40 - ISO file history
01:00 - Mounting ISO files
01:38 - Identifying hidden file
01:50 - Phishing logic
02:10 - Examining .vbs launcher script
02:25 - ISO mount forensics
03:25 - Examining .bat downloader and invoker script
04:00 - Removing irrelevant script contents
04:55 - Retrieving payload from compromised website
05:20 - Scanning URL to retrieve payload
06:00 - Examining .ps1 reflective loader
07:30 - Extracting .NET injector and payload executables
08:20 - Further analysis of .ps1 reflective loader
10:10 - Note on reflection and .NET
12:10 - Initial analysis of obfuscated .NET binary
12:35 - Deobfuscation using de4dot
13:08 - Examining deobfuscated payload injector
14:23 - Examining AsyncRAT payload
15:35 - Attempting to decode Base64 strings
16:30 - Examining strings
17:00 - Locating the master key
18:05 - Locating and encoding the salt
18:45 - Examining AES decryption scheme
19:25 - Deriving the PBKDF2 key
20:40 - Performing AES Decryption
22:50 - Bulk decryption of strings
25:10 - Outro
Credits:
SFX by Pixabay