
APT Malware (advanced persistent threat)
Source: YouTube · John Hammond · published Jun 14, 2024 · 28:51
The video demonstrates analysis of a Pakistani APT malware delivered through a malicious Excel add-in file 0:00 that deploys Crimson RAT, a remote access Trojan.
Key Takeaways:
• The malware uses an Excel add-in (.xlam) with malicious macros that trigger when enabled 0:24
• The code copies itself to AppData and extracts base64-encoded embedded objects 6:35
• It creates a fake screensaver file (.scr) which is actually a .NET executable 11:43
• The payload is Crimson RAT that connects to qhec[.]duckdns[.]org using multiple ports 23:11
• The malware achieves persistence through the registry 23:40
This attack is attributed to Transparent Tribe APT using Crimson RAT for command and control capabilities.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Malware Analysis. Commonly maps to: Security Operations, Security Architecture and Engineering. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
so I have this malware sample used by a Pakistani advanced persistent threat or AP in this video we can go ahead and play with it so first things first let's just fire it up and see it in action so I'll doubleclick on this xlam file this is a Microsoft Excel addin and hey it's going to need me to you know have an account but I don't and it's going to ask me hey do you want to enable macros for this document the summer collection outfits. xlam uh and this is the trigger for the malware so I'm going to go ahead and enable macros to let this run you should never do that by the way not in an actual environment I am inside of a virtual machine and you can see something weird going on a copy dialogue opened up we'll ignore our signin for office but with that we'll see this open up to Del he fash…