SmoothOperator abuses Microsoft Authenticode signatures to seem valid. Here is an explanation how it works and how to detect it in files.
Malware analysis courses: https://malwareanalysis-for-hedgehogs...
Buy me a coffee: https://ko-fi.com/struppigel
Follow me on Twitter: / struppigel
AnalysePESig: https://blog.didierstevens.com/progra...
SigFlip: https://github.com/med0x2e/SigFlip
Sysinternals: https://learn.microsoft.com/en-us/sys...
Using unauthenticated data inside authenticode signed binaries: https://web.archive.org/web/201504261...
Samples:
3CXDesktopApp.msi: https://tria.ge/230330-3nzfjshc2s
ffmpeg: https://bazaar.abuse.ch/sample/7986bb...
d3dcompiler_47.dll: https://bazaar.abuse.ch/sample/11be18...
00:00 Intro
00:37 Signature verification
02:09 SigFlip and SigLoader
03:05 Ways to hide data in authenticode structures
06:00 Detecting hidden authenticode data
08:11 Why this still works
09:05 Outro
#malware #malwareanalysis #reverseengineering #3cx #authenticode