ElectricBreeze-1
https://app.hackthebox.com/sherlocks/ElectricBreeze-1
1
Based on MITRE's sources, since when has Volt Typhoon been active?
2
MITRE identifies two OS credential dumping techniques used by Volt Typhoon. One is LSASS Memory access (T1003.001). What is the Attack ID for the other technique?
curl -s "https://attack.mitre.org/groups/G1017/G1017-enterprise-layer.json" | jq '.techniques[] | select(.techniqueID | test("^T1003"))'{
"techniqueID": "T1003",
"showSubtechniques": true
}
{
"techniqueID": "T1003.001",
"comment": "[Volt Typhoon](https://attack.mitre.org/groups/G1017) has attempted to access hashed credentials from the LSASS process memory space.(Citation: Microsoft Volt Typhoon May 2023)(Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)\n",
"score": 1,
"color": "#66b1ff",
"showSubtechniques": true
}
{
"techniqueID": "T1003.003",
"comment": "[Volt Typhoon](https://attack.mitre.org/groups/G1017) has used ntds.util to create domain controller installation media containing usernames and password hashes.(Citation: Microsoft Volt Typhoon May 2023)(Citation: Joint Cybersecurity Advisory Volt Typhoon June 2023)(Citation: Secureworks BRONZE SILHOUETTE May 2023)(Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)\n",
"score": 1,
"color": "#66b1ff",
"showSubtechniques": true
}5
8
9
What is the SHA256 hash of the file?
Yara Rules
rule VersaMem_JAR_Webshell {
strings:
$s1 = "org.apache.catalina.startup.Bootstrap"
$s2 = "com.versa.vnms.ui.TestMain"
$s3 = "/tmp/.java_pid"
$s4 = "CoreClassFileTransformer"
$s5 = "WriteTestTransformer"
$s6 = "CapturePassTransformer"
$s7 = "setUserPassword"
$s8 = "captureLoginPasswordCode"
$s9 = "com/versa/vnms/ui/services/impl/VersaAuthenticationServiceImpl"
$s10 = "org/apache/catalina/core/ApplicationFilterChain"
$s11 = "/tmp/.temp.data"
$s12 = "getInsertCode"
$s13 = "VersaMem"
$s14 = "Versa-Auth"
condition:
filesize < 5MB and 3 of them
}
IOCs
VersaTest.png (VersaMem web shell):
4bcedac20a75e8f8833f4725adfc87577c32990c3783bf6c743f14599a176c37
Filepaths:
/tmp/.temp.data10
According to VirusTotal, what is the file type of the malware?
11
What is the 'Created by' value in the file's Manifest according to VirusTotal?
Manifest-Version: 1.0
Archiver-Version: Plexus Archiver
Created-By: Apache Maven 3.6.0
Built-By: versa
Build-Jdk: 11.0.19
Agent-Class: com.versa.vnms.ui.TestMain
Can-Redefine-Classes: true
Can-Retransform-Classes: true
Main-Class: com.versa.vnms.ui.TestMain
Premain-Class: com.versa.vnms.ui.TestMain13
According to the CISA document referenced by MITRE, what is the primary strategy Volt Typhoon uses for defense evasion?
14
In the CISA document, which file name is associated with the command potentially used to analyze logon patterns by Volt Typhoon?

Atualizado










