Forum Discussion
FIN7 Threat Hunting with Splunk: Execution Analysis
Hello everyone,
I am stuck at the following task :
"Which IP address and port does the encrypted payload communicate with? (Format ip:port)"
I think I found the right function (babymetal) as I could answer the previous question :
"What key is used to decode the embedded shellcode?"
But where do I go from there ? I thought about doing dynamic analysis, but I have no tools to do so. Quite frankly I am lost
Thanks for your help
2 Replies
- SamDickison
Community Manager
Hi Nicooks, looks like no one on the Community has got back to you, so I dug up this hint:
Since this is a Splunk threat hunting lab, you don't need external dynamic analysis tools because the execution artifacts and telemetry are already indexed for you. Instead, pivot your Splunk search to look for network connection logs (such as Sysmon Event ID 3) originating from the compromised process. Correlating the exact timeframe of the shellcode execution with outbound network traffic should reveal the destination IP and port you are looking for.
- shivanimBronze II
Hello Nicooks, may be i am too late to recommend the solution however i did solve this using below steps :
1. What key is used to decode the embedded shellcode?
- Firstly you need to decode the encoded strings you might have recieved from first stage script file using CyberChef input as From Base64 & Raw Inflate.
- Secondly you will again get another base64 string as an output from the first decoding which needs to be decoded and saved as example named <stager2.bin> on the system.
- Upload/drag the Stager.bin as an input in Cyberchef then select input from left panel as drop bytes Start 0 to Length 2061
- Again select drop bytes start 0 to Length 2
- Select To Hex as input and replace the default delimiter value to none
- Select Find/Replace as input and in Find text box add "^" and in replace text box add "4d5a"
- Select From Hex as input and replace the default delimiter value to none
- Select Take bytes as input and add length as "11776" (answer recieved for previous question)
-Save the output received as example named as "babymetal.dll"
- Navigate to Ghidra for further analysis and upload the babymetal.dll as PE file
- Navigate to left panel tree and open function babymetal in CodeBrowser.
- Between code line 112 to 147 you will get the key code to be very precise check the code line 136. (it should look like 0x..)