2025/05 2

Shellcode ๋ฆฌ๋ฒ„์‹ฑ (Cobalt Strike Beacon)

์ด๋ฒˆ์—๋Š” ์‰˜์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ์ƒ˜ํ”Œ ํ•ด์‹œ(SHA256)๋Š” d26d5e9e0b05f94be8b86dc7410604cac85557a8f7bdf709beb95ee8cbb98c60์ž…๋‹ˆ๋‹ค. โ—‹ ์ƒ˜ํ”Œ ์ •๋ณด ์ˆ˜์ง‘์ƒ˜ํ”Œ์„ DiE๋กœ ํ™•์ธํ•ด๋ณด๋ฉด 32๋น„ํŠธ PE ๋ฐ”์ด๋„ˆ๋ฆฌ์ž…๋‹ˆ๋‹ค.๊ทธ๋ฆฌ๊ณ  MinGW ์ปดํŒŒ์ผ๋Ÿฌ๋กœ ์ปดํŒŒ์ผ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.MinGW (Minimalist GNU for Windows)Windows์šฉ GCC(GNU Complier Colliection) ํฌํŠธWindows ํ™˜๊ฒฝ์—์„œ C/C++, Fortan ๋“ฑ์˜ ํ”„๋กœ๊ทธ๋žจ์„ ์ปดํŒŒ์ผํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ฃผ๋Š” ๋„๊ตฌ์ž…๋‹ˆ๋‹ค.์œˆ๋„์šฐ์—์„œ ๋ฆฌ๋ˆ…์Šค ์Šคํƒ€์ผ์˜ GCC ์ปดํŒŒ์ผ๋Ÿฌ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ฉ๋‹ˆ๋‹ค.MinGW๋Š” ๋‹จ์ˆœํ•œ ๋„ค์ดํ‹ฐ๋ธŒ EXE ํ”„๋กœ๊ทธ๋žจ, ์‰˜์ฝ”๋“œ๋ฅผ ๋งŒ๋“ค ๋•Œ ๋งŽ์ด ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค. PE-bear ..

Malware Analysis Series (MAS) – Article 9

Alexandre Borges์˜ ๋ธ”๋กœ๊ทธ Exploit Reversing์˜ ์•…์„ฑ์ฝ”๋“œ ๋ถ„์„ ์‹œ๋ฆฌ์ฆˆ 'Malware Analysis Series(MAS)'๋ฅผ ๋ฒˆ์—ญํ•˜์—ฌ ๊ณต๋ถ€ํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. MacOS/iOS ๋‚ด์šฉ์˜ ์•„ํ‹ฐํด 8์€ ์ž ์‹œ ๋ฏธ๋ค„๋‘๊ณ  9๋ฒˆ์งธ ์•„ํ‹ฐํด๋ถ€ํ„ฐ ๊ณต๋ถ€ํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. [Introduction]์•…์„ฑ์ฝ”๋“œ ๋ถ„์„ ์‹œ๋ฆฌ์ฆˆ(MAS)์˜ 9๋ฒˆ์งธ ์•„ํ‹ฐํด์— ์˜ค์‹  ๊ฒƒ์„ ํ™˜์˜ํ•ฉ๋‹ˆ๋‹ค. ์ด๋ฒˆ ์•„ํ‹ฐํด์—์„œ๋Š” ์œˆ๋„์šฐ ์‹คํ–‰ ํŒŒ์ผ๋กœ ๋Œ์•„์™€์„œ PE ํฌ๋งท๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ์ผ๋ฐ˜์ ์ธ ์‰˜์ฝ”๋“œ(shellcode)๋ฅผ ๋‹ค๋ค„๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.์š”์ฆ˜์€ Sliver, Brute Ratel, Havoc, Covenant, Empire, Cobalt Strike ๊ฐ™์€ ์ˆ˜์‹ญ ๊ฐ€์ง€์˜ C2 ํ”„๋ ˆ์ž„์›Œํฌ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. Cobalt Strike๋Š” ์‹ค์ œ red team operation์—..