Forum Discussion
FIN7 Threat Hunting with Splunk: Execution Analysis
Hello Nicooks, may be i am too late to recommend the solution however i did solve this using below steps :
1. What key is used to decode the embedded shellcode?
- Firstly you need to decode the encoded strings you might have recieved from first stage script file using CyberChef input as From Base64 & Raw Inflate.
- Secondly you will again get another base64 string as an output from the first decoding which needs to be decoded and saved as example named <stager2.bin> on the system.
- Upload/drag the Stager.bin as an input in Cyberchef then select input from left panel as drop bytes Start 0 to Length 2061
- Again select drop bytes start 0 to Length 2
- Select To Hex as input and replace the default delimiter value to none
- Select Find/Replace as input and in Find text box add "^" and in replace text box add "4d5a"
- Select From Hex as input and replace the default delimiter value to none
- Select Take bytes as input and add length as "11776" (answer recieved for previous question)
-Save the output received as example named as "babymetal.dll"
- Navigate to Ghidra for further analysis and upload the babymetal.dll as PE file
- Navigate to left panel tree and open function babymetal in CodeBrowser.
- Between code line 112 to 147 you will get the key code to be very precise check the code line 136. (it should look like 0x..)