Malware analysis of FakeBat malware (Malicious MSIX Installer) which is used to deploy other malware families such as SectopRAT/Arechclient2 or DarkGate.
** Find me at **
Twitter/X - / cyberraiju
Blog - https://www.jaiminton.com/
Mastodon - https://infosec.exchange/@CyberRaiju
** Tools **
7-Zip - https://7-zip.org/
FLARE VM - https://github.com/mandiant/flare-vm
** Sample **
https://bazaar.abuse.ch/sample/0c0132...
https://bazaar.abuse.ch/sample/428356...
https://www.virustotal.com/gui/file/0...
https://urlscan.io/result/79ac2492-92...
** New malicious Samples **
https://www.virustotal.com/gui/file/c...
https://www.virustotal.com/gui/file/5...
** Further Reading **
https://gnupg.org/
https://hijacklibs.net/entries/3rd_pa...
https://www.elastic.co/security-labs/...
https://learn.microsoft.com/en-us/win...
https://www.malwarebytes.com/blog/thr...
https://www.malwarebytes.com/blog/thr...
** Timestamps **
00:00 - Intro
00:11 - How fake browser updates work
00:21 - Elastic Security Labs Shoutout
00:44 - Sourcing malware from MalwareBazaar
01:03 - Examining a Fake Browser Update domain
01:24 - Extracting MSIX archives
01:34 - Hiding malware with legitimate executables
01:53 - Understanding the Package Support Framework
02:37 - Examining malicious FakeBat script
04:33 - Malicious MSIX files in the wild
05:17 - Running malicious MSIX files
05:56 - Processes run during MSIX launch
07:11 - Outro
Credits:
SFX by Pixabay