I have to admit, this @virustotal find is going to be hard for me to top.
This CARBANAK work was in active development when whoopsed to VT
from RU
on 2017-04-19.
kb3r1p.rar
879 files (15.03 MB)
https://www.virustotal.com/#/file/783b2eefdb90eb78cfda475073422ee86476aca65d67ff2c9cf6a6f9067ba5fa/detection …
apwmie.rar
24 files (5.93 MB)
https://www.virustotal.com/#/file/4116ec1eb75cf336a3fdde253c28f712668d0a325a74c41445c7fa87c4e9b7a5/detection …
-
-
Diesen Thread anzeigen
-
For those without
@virustotal, how about@virusbay_io sharing? Now you can play alongside the blog with#CarbanakWeek: Home Malware Edition kb3r1p.rar 06efd1354b7418198c66a78ff3e68e59 https://beta.virusbay.io/sample/browse/06efd1354b7418198c66a78ff3e68e59 … apwmie.rar 2549f116adbbfeeecf7596e6381bb43c https://beta.virusbay.io/sample/browse/2549f116adbbfeeecf7596e6381bb43c …pic.twitter.com/v38gdp7VqNDiesen Thread anzeigen -
Kudos to anyone else who found the source code! We sat on it for ~2 years [pictured]
- that seemed like enough.
@FireEye got a LOT out of this access/analysis, like that time#FLARE modified#CARBANAK's video player to support FIN7’s custom encoding: https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html …pic.twitter.com/EUXRCd79qW
Diesen Thread anzeigen
Ende der Unterhaltung
Neue Unterhaltung -
-
-
Tom & Michael are going to release the technical details throughout this
#Carbanak week, but if you want a preview of what they found,@cglyer and I hung out with them on#StateOfTheHack a few months agohttps://youtu.be/gDZb4Hr8w_IDiesen Thread anzeigen - 1 weitere Antwort
Neue Unterhaltung -
-
-
Dropping

as FLARE's #CARBANAKweek continues Part
(of 4): https://www.fireeye.com/blog/threat-research/2019/04/carbanak-week-part-two-continuing-source-code-analysis.html …
• 2 AV vendor evasions that @FireEye responsibly disclosed -
@nopandroll • Attacker toolmarks, infrastructure, & passwords
• Survey of exploits
FOLLOW: @jtbennettjr &@mykillpic.twitter.com/uLy9MPzqWE
Diesen Thread anzeigen - 2 weitere Antworten
Neue Unterhaltung -
-
-
500 hours!? We really need to make progress in static/dynamic analysis.
-
Pretty wild given FLARE's focus on automation (and the fact that FireEye is a static/dynamic analysis company) - so these hours are lower than many others doing the work & reporting. You should see the exchange rate for 500 FLARE hours.
-
6 month team OKR: O: maximize flare effectiveness KR: increase flare hours spent to lines of code conversion rate by 20% KR: every flare analysis is blog post worthy in terms of quality KR: increase the number of lines of code flare is analyzing by 20%
-
This was just pt. 1. Try to beat: * 3wks: RE 2 packed binaries, write 33pgs * 3wks: bulk analyze 100's of samples supporting blog * 2wks: analyze & report on 20MB of source + binaries * 2wks: fully RE 13 binaries, write 5200 words * 1wk: write 75pgs (source + new apwmie analysis)pic.twitter.com/zLxDZK5oiS
-
As an industry, what do you think is needed to get those numbers down from weeks to seconds ?
-
WEEKS TO SECONDS: A wild imagination? A client or consultant that won't actually read a 33 page technical analysis report? ^Consulting protip if you choose that method: encrypt the non-existent report with a password, "lose" the password, see if client ever asks for it...
Ende der Unterhaltung
Neue Unterhaltung -
-
-
please, I can only get so erect!
-
We consulted with doctors who recommended we do not have a Carbanak Week lasting for more than 4 blog posts.
Ende der Unterhaltung
Neue Unterhaltung -
-
-
Have you seen any specific part of the code for capturing PIN code from smart-card readers/drivers?
-
Ooh, audience participation! No, I didn't note any smartcard/PIN reader-related code in kb3r1p or apwmie. This includes REing binaries under сорцы\server\bin\debug\_plugins, and a cursory run-through of the apwmie files.
-
I don't recall coming across such code in all the variants I've seen.
-
#CarbanakWeek: Home Edition players are welcome to chime in if they find something@jtbennettjr &@mykill didn't https://twitter.com/ItsReallyNick/status/1120419778416521217 … Though I definitely recommend waiting until end of the week if you want to make your own FIN7 Carbanak video decoder.
Ende der Unterhaltung
Neue Unterhaltung -
Das Laden scheint etwas zu dauern.
Twitter ist möglicherweise überlastet oder hat einen vorübergehenden Schluckauf. Probiere es erneut oder besuche Twitter Status für weitere Informationen.



