{"id":19419,"date":"2022-05-08T17:29:21","date_gmt":"2022-05-08T20:29:21","guid":{"rendered":"https:\/\/www.ethicalhacker.com.br\/site\/?p=19419"},"modified":"2022-05-08T17:30:04","modified_gmt":"2022-05-08T20:30:04","slug":"malware-oculta-shellcode-nos-logs-do-windows","status":"publish","type":"post","link":"https:\/\/www.ethicalhacker.com.br\/site\/2022\/05\/basico\/malware-oculta-shellcode-nos-logs-do-windows\/","title":{"rendered":"Malware oculta Shellcode nos logs do Windows"},"content":{"rendered":"\n\n\n<h1 class=\"story-title\"><span><span class=\"\">Este novo malware sem arquivo oculta o Shellcode nos logs de eventos do Windows<\/span><\/span><\/h1>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\"><span><span class=\"goog-text-highlight\">Uma nova campanha maliciosa foi vista aproveitando os logs de eventos do Windows para armazenar peda\u00e7os de shellcode pela primeira vez.<\/span><\/span><\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: justify;\"><span>&#8220;Ele permite que o trojan de \u00faltimo est\u00e1gio &#8216;sem arquivo&#8217; seja oculto \u00e0 vista de todos no sistema de arquivos&#8221;, informou o pesquisador da Kaspersky, Denis Legezo <\/span><a href=\"https:\/\/translate.google.com\/website?sl=auto&amp;tl=pt&amp;hl=pt&amp;u=https:\/\/securelist.com\/a-new-secret-stash-for-fileless-malware\/106393\/\" target=\"_blank\" rel=\"noopener\"><span>,<\/span><\/a><span> em um artigo t\u00e9cnico publicado esta semana.<\/span><\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\"><span>Acredita-se que o processo de infec\u00e7\u00e3o furtivo, n\u00e3o atribu\u00eddo a um ator conhecido, tenha come\u00e7ado em setembro de 2021, quando os alvos pretendidos foram atra\u00eddos para baixar arquivos .RAR compactados contendo Cobalt Strike e <\/span><span>Silent Break<\/span><span> .<\/span><\/p>\n<div class=\"clear post-head\">\n<div class=\"postmeta\">\u00a0<\/div>\n<\/div>\n<div id=\"articlebody\" class=\"articlebody clear cf\">\n<div class=\"separator\"><a href=\"https:\/\/thehackernews.com\/new-images\/img\/b\/R29vZ2xl\/AVvXsEgvJfLXdUTf2BzHvnefcr_Fva7UCjqWOBZwOPJoij9C9ibwvcV-5qEaY-JxGOpW5ssQx16vD43gW6tjuuynIUVQBtvKSB28AJDraP1kTWPLaodJtBwbWhXQebLyQUamwS5Vn-ImTRkaob4ot0xDur334LrwRy7TlfKBKw2Eil-ReBVl-Zcjy5hqI0IW\/s728-e100\/shellcode-malware.jpg\" class=\"gallery_colorbox\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" title=\"Windows Event Log Malware ShellCode\" src=\"https:\/\/thehackernews.com\/new-images\/img\/b\/R29vZ2xl\/AVvXsEgvJfLXdUTf2BzHvnefcr_Fva7UCjqWOBZwOPJoij9C9ibwvcV-5qEaY-JxGOpW5ssQx16vD43gW6tjuuynIUVQBtvKSB28AJDraP1kTWPLaodJtBwbWhXQebLyQUamwS5Vn-ImTRkaob4ot0xDur334LrwRy7TlfKBKw2Eil-ReBVl-Zcjy5hqI0IW\/s728-e1000\/shellcode-malware.jpg\"  alt=\"Windows Event Log Malware ShellCode\" width=\"559\" height=\"292\" border=\"0\" data-original-height=\"380\" data-original-width=\"728\" \/><\/a><\/div>\n<\/div>\n<div class=\"ad_two clear\"><center class=\"cf\">\n<div id=\"00000001-d5071602-d812-40e0-80df-45bb17d67517\" class=\"_ap_apex_ad\" data-section=\"00000001-d5071602-d812-40e0-80df-45bb17d67517\" data-orig-id=\"967ecfad-bf6b-429e-9a39-9770c8b7d188\" data-render-time=\"1652040837209\">\u00a0<\/div>\n<\/center><\/div>\n<p style=\"text-align: justify;\"><span>Os m\u00f3dulos de software de simula\u00e7\u00e3o de advers\u00e1rios s\u00e3o usados \u200b\u200bcomo uma barra de lan\u00e7amento para injetar c\u00f3digo em processos do sistema Windows ou aplicativos confi\u00e1veis.<\/span><\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\"><span>Tamb\u00e9m \u00e9 not\u00e1vel o uso de inv\u00f3lucros antidetec\u00e7\u00e3o como parte do conjunto de ferramentas, sugerindo uma tentativa por parte dos operadores de voar sob o radar.<\/span><\/p>\n<p>\u00a0<\/p>\n<div class=\"separator\" style=\"text-align: justify;\"><a href=\"https:\/\/thehackernews-com.translate.goog\/new-images\/img\/b\/R29vZ2xl\/AVvXsEgrzgutTcKTUrGetWcZEOu5kasuhASiL3ps4_E7405rFO20ttiLDMm3rphH48Y0IoIJMMLuiQ3J7CUypSbiZEj3yAGQUiqES37eNR4h9dvRfeJKiekjtHaUCEykJokO0wtZM3OF99SK2HMbYoM0z3mP-gP1kO1aMoE4b6lmwBKmETQFW_cXTW6kQISH\/s728-e100\/reg.jpg?_x_tr_sl=auto&amp;_x_tr_tl=pt&amp;_x_tr_hl=pt\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" title=\"ShellCode de malware do log de eventos do Windows\" src=\"https:\/\/thehackernews.com\/new-images\/img\/b\/R29vZ2xl\/AVvXsEgrzgutTcKTUrGetWcZEOu5kasuhASiL3ps4_E7405rFO20ttiLDMm3rphH48Y0IoIJMMLuiQ3J7CUypSbiZEj3yAGQUiqES37eNR4h9dvRfeJKiekjtHaUCEykJokO0wtZM3OF99SK2HMbYoM0z3mP-gP1kO1aMoE4b6lmwBKmETQFW_cXTW6kQISH\/s728-e1000\/reg.jpg\" alt=\"ShellCode de malware do log de eventos do Windows\" width=\"629\" height=\"196\" border=\"0\" data-original-height=\"227\" data-original-width=\"728\" \/><\/a><\/div>\n<div style=\"text-align: justify;\">\u00a0<\/div>\n<div>\u00a0<\/div>\n<div style=\"text-align: justify;\"><span><span class=\"goog-text-highlight\">Um dos principais m\u00e9todos \u00e9 manter o shellcode criptografado contendo o malware do pr\u00f3ximo est\u00e1gio como pe\u00e7as de 8 KB em logs de eventos, uma t\u00e9cnica nunca antes vista em ataques do mundo real, que \u00e9 ent\u00e3o combinada e executada.<\/span><\/span><\/div>\n<div>\u00a0<\/div>\n<div>\u00a0<\/div>\n<div>\n<div class=\"separator\"><a href=\"https:\/\/thehackernews-com.translate.goog\/new-images\/img\/b\/R29vZ2xl\/AVvXsEgI54HyPkZkXTvaUFu7WlsjNst9S2csS4stOgIhodx8ZCHtIq6XFVYZ8cMFxJQJdqy0g97vjOZqDRLHt6oks6XAtHM8R_Bt5VYFTrWdd3LsCy5rzy32J3FnwU9fD4vx8KqtBKTjrwZiucJ7CZkJAge1Lk59xrPXuAW8L3_r1ITmC9-NE02a-qNVa8lJ\/s728-e100\/malware.jpg?_x_tr_sl=auto&amp;_x_tr_tl=pt&amp;_x_tr_hl=pt\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" title=\"ShellCode de malware do log de eventos do Windows\" src=\"https:\/\/thehackernews.com\/new-images\/img\/b\/R29vZ2xl\/AVvXsEgI54HyPkZkXTvaUFu7WlsjNst9S2csS4stOgIhodx8ZCHtIq6XFVYZ8cMFxJQJdqy0g97vjOZqDRLHt6oks6XAtHM8R_Bt5VYFTrWdd3LsCy5rzy32J3FnwU9fD4vx8KqtBKTjrwZiucJ7CZkJAge1Lk59xrPXuAW8L3_r1ITmC9-NE02a-qNVa8lJ\/s728-e1000\/malware.jpg\" alt=\"ShellCode de malware do log de eventos do Windows\" width=\"599\" height=\"370\" border=\"0\" data-original-height=\"450\" data-original-width=\"728\" \/><\/a><\/div>\n<\/div>\n<div>\u00a0<\/div>\n<div>\u00a0<\/div>\n<div>\n<p style=\"text-align: justify;\"><span><span class=\"goog-text-highlight\">A carga final \u00e9 um conjunto de trojans que empregam dois mecanismos de comunica\u00e7\u00e3o diferentes,\u00a0 HTTP com criptografia RC4 e n\u00e3o criptografado com <\/span><\/span><span><span class=\"goog-text-highlight\">pipes nomeados <\/span><\/span><span><span class=\"goog-text-highlight\">que permitem executar comandos arbitr\u00e1rios, baixar arquivos de uma URL, escalar privil\u00e9gios e fazer capturas de tela.<\/span><\/span><\/p>\n<div class=\"ad_two clear\"><center class=\"cf\">\n<div id=\"00000001-354806bb-8d80-46f5-a078-ac52fa2e385d\" class=\"_ap_apex_ad\" style=\"text-align: justify;\" data-section=\"00000001-354806bb-8d80-46f5-a078-ac52fa2e385d\" data-orig-id=\"8c2d7f94-a9c5-43b2-83a4-cdcf711ae05e\" data-render-time=\"1652040837209\">\u00a0<\/div>\n<\/center><\/div>\n<p style=\"text-align: justify;\"><span>Outro indicador das t\u00e1ticas de evas\u00e3o do agente da amea\u00e7a \u00e9 o uso de informa\u00e7\u00f5es coletadas do reconhecimento inicial para desenvolver est\u00e1gios sucessivos da cadeia de ataque, incluindo o uso de um servidor remoto que imita o software leg\u00edtimo usado pela v\u00edtima.<\/span><\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\"><span>&#8220;O ator por tr\u00e1s desta campanha \u00e9 bastante capaz&#8221;, informou Legezo. &#8220;O c\u00f3digo \u00e9 bastante \u00fanico, sem semelhan\u00e7as com malware conhecido.&#8221;<\/span><\/p>\n<p style=\"text-align: justify;\">\u00a0<\/p>\n<p style=\"text-align: justify;\"><span>A divulga\u00e7\u00e3o ocorre quando os pesquisadores do Sysdig <\/span><span>demonstraram<\/span><span> uma maneira de comprometer cont\u00eaineres, somente leitura com malware, sem arquivo que \u00e9 executado na mem\u00f3ria, aproveitando uma <\/span><span>falha cr\u00edtica<\/span><span> nos servidores Redis.<\/span><\/p>\n<p>\u00a0<\/p>\n<\/div>\n<p>\u00a0<\/p>\n<p>Este artigo \u00e9 uma tradu\u00e7\u00e3o de: <a href=\"https:\/\/thehackernews.com\/2022\/05\/this-new-fileless-malware-hides.html\" target=\"_blank\" rel=\"noopener\">https:\/\/thehackernews.com\/2022\/05\/this-new-fileless-malware-hides.html<\/a>\u00a0 (Autor: <span class=\"author\"><a href=\"https:\/\/thehackernews.com\/p\/authors.html\" rel=\"author\">Ravie Lakshmanan<\/a><\/span>)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Este novo malware sem arquivo oculta o Shellcode nos logs de eventos do Windows \u00a0 Uma nova campanha maliciosa foi vista aproveitando os logs de eventos do Windows para armazenar peda\u00e7os de shellcode pela primeira vez. \u00a0 &#8220;Ele permite que o trojan de \u00faltimo est\u00e1gio &#8216;sem arquivo&#8217; seja oculto \u00e0 vista de todos no sistema [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":19423,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[89,100,105],"tags":[],"class_list":["post-19419","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-basico","category-diversos","category-noticias"],"_links":{"self":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/posts\/19419","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/comments?post=19419"}],"version-history":[{"count":5,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/posts\/19419\/revisions"}],"predecessor-version":[{"id":19427,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/posts\/19419\/revisions\/19427"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/media\/19423"}],"wp:attachment":[{"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/media?parent=19419"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/categories?post=19419"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ethicalhacker.com.br\/site\/wp-json\/wp\/v2\/tags?post=19419"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}