在纯文本中隐藏有效载荷.pdf

编号:981733 PDF 32页 3.74MB 下载积分:VIP专享
下载报告请您先登录!

在纯文本中隐藏有效载荷.pdf

1、#SECTORCA SecTorCACODASMMoritz ThomasLowering Payload Entropy#SECTORCA SecTorCAHiding Payloads in Plain.text Moritz ThomasAgendawhoamiPrologue:Payloads&Shannon EntropyAct I:Hide&Seek in PECOFFAct II:Evading EDR detection&ImprovementsAct III:Demo Time!Epilogue:Conclusion#SECTORCA SecTorCAHiding Paylo

2、ads in Plain.text Moritz ThomaswhoamiMoritz Thomas moritzlthomas moritzlthomas molathoSenior Red Team OperatorR&D,Payload CraftingHiding Payloads in Plain.text Moritz Thomas#SECTORCA SecTorCAPrologue:Payloads&Shannon Entropy“red team operators discussing plans”#SECTORCA SecTorCAHiding Payloads in Pl

3、ain.text Moritz ThomasPrologue:PayloadsShellcode(.bin)Archive(.zip/.iso/)Loader(.exe/.dll)BinariesMetadata(.exe/.dll)Encrypt(.bin)ProtectionOPSECExecutionDisguiseDisguiseExecutionDeliveryCore C2Functionality#SECTORCA SecTorCAHiding Payloads in Plain.text Moritz ThomasH(.png)=7.99Prologue:Shannon Ent

4、ropyMeasure of uncertainty of events“Randomness”of data“Information density”of dataUnit:Bits Used by malware analysts,AVs&EDRs=0 log2 0.08.0Certainty“Random”H(0,0,0,0,0)=0.0H(AES-EBC(0,0,0)=7.99H(42,42,42,42,42)=0.0H(notepad.exe)=6.5#SECTORCA SecTorCAHiding Payloads in Plain.text Moritz ThomasProlog

5、ue:Payloads&Shannon EntropyShellcode(.bin)H=6.5-7.9Archive(.zip/.iso/)H=6.2Loader(.exe/.dll)H=5.3-7.2BinariesMetadata(.exe/.dll)Encrypt(.bin)H=7.9Hiding Payloads in Plain.text Moritz Thomas#SECTORCA SecTorCAAct I:Hide&Seek in PECOFF“hackers wearing futuristic masks playing hide and seek in a cyber p

6、unk setting,zoomed out”#SECTORCA SecTorCAHiding Payloads in Plain.text Moritz ThomasAct I:PECOFF 1/2Ange Albertini little spaceModifications stand outActual content.text:Code.data:R/W data.rsrc:Icons,Simple to modify!*append*Portable Executable Common Object File Format#SECTORCA SecTorCAHiding Paylo

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(在纯文本中隐藏有效载荷.pdf)为本站 (竿头日上) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠