Some very interesting XLLs in the wild (#blueteam take note!). Will link to some research in this thread. This one loads a payload from an embedded resource and displays a decoy message.
📎virustotal.com/gui/file/1994a…
🎁🎇joesandbox.com/analysis/21041… ImageImageImageImage
This XLL decodes a Base64 string using CryptStringToBinary and uses the Nt APIs to jump to it.
📎virustotal.com/gui/file/5644a… ImageImageImage
This XLL has a Lua interpreter in it.🤔

📎virustotal.com/gui/file/4a897…
📄en.wikipedia.org/wiki/Lua_(prog… Image
And @domchell you want to take credit for this XLL? ImageImageImage
This is an XLL but with an 🚨.ODC extension🚨. Here are some 64-bit samples:
6⃣4⃣virustotal.com/gui/file/836c0…
6⃣4⃣virustotal.com/gui/file/28f45…
6⃣4⃣virustotal.com/gui/file/b926f… ImageImageImage
Thanks to the mighty @MalwareRE here is a bit more detail for defenders on this sample 😃: virustotal.com/gui/file/836c0… Image
Here is another interesting case. Spawn a child process, reprogram its EIP with an XORd shellcode. Utilize Cobalt Strike beacon_x64.dll. Thx to @MalwareRE for RE assistance 🙏
📎virustotal.com/gui/file/386d0… ImageImageImageImage
Not sure if this implant wants to be an XLL (no xlAutoOpen), or WLL (no wdAutoOpen), but it splits the difference with a wlAutoOpen 🤷‍♂️
Another .XLL uploaded to #VirusTotal:
👋WIT_2021_Panel_Discussions.xll
📏#yara rule committed to @cyb3rops's rep:
github.com/Neo23x0/signat…
📺A short vid on how RE reveals detection ideas for #blueteam: process names, domains queried, embedded resources
📎virustotal.com/gui/file/54c35…
Another XLL with encoded payload, decoy message, and Nt APIs.
📎virustotal.com/gui/file/04cf9…
🔎Query for samples on #VirusTotal: virustotal.com/gui/search/exp… ImageImageImage
Sometimes things stand out because of what they are not doing. This .XLL doesn't do any useful work. What's it doing? Anti-analysis domain check, FNV API hash resolution, and Cobalt Strike shellcode. Thx to the mighty @MalwareRE for help!
📎virustotal.com/gui/file/99195… ImageImageImage

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with John Lambert

John Lambert Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @JohnLaTwC

14 Sep
Want to see the most beautiful equation in math? I’ll show you. It starts with the Roots of Unity.
Image
Image
Read 14 tweets
29 Jul
"The best way to show that a stick is crooked is not to argue about it or to spend time denouncing it, but to lay a straight stick alongside it"
― D.L. Moody
"There is no love, there are only proofs of love"
― Pierre Reverdy
"When the student is ready, the teacher will appear"
― various
Read 7 tweets
10 Jul
Full of avalanche debris to hike over and logs to traverse. ImageImageImage
Brush that is way over your head and tricky footing over a hidden floor of logs, roots, and holes. And hazards. ImageImageImage
But at the end is a lovely waterfall fed by snowmelt from Alta mountain. ImageImageImageImage
Read 4 tweets
10 Jul
Pacific Northwest: If you look closely at this panoramic view of Gold Creek Valley (Cascades in WA state), notice the downed trees at left and the bare mountainside with waterfalls at right. Image
In 2007 there was a massive avalanche on the right side. The force was so strong it carried across Gold Creek and up the left side of the valley causing the trees to fall UPHILL. Image
Aside, when you’re hiking along the side of a mountain and periodically exit the forest for some open bouldery views and then re-enter the forest, that open area was likely caused by an avalanche. They’re called avalanche chutes.
Read 5 tweets
8 Jul
This month marked 20 years at Microsoft. Here’s how I celebrated: ImageImageImageImage
ImageImageImageImage
ImageImageImageImage
Read 4 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!