{"id":146,"date":"2023-09-21T17:08:02","date_gmt":"2023-09-21T22:08:02","guid":{"rendered":"https:\/\/freshphish.info\/?p=146"},"modified":"2023-09-23T16:22:12","modified_gmt":"2023-09-23T21:22:12","slug":"delivering-executable-using-registry-file","status":"publish","type":"post","link":"https:\/\/freshphish.info\/?p=146","title":{"rendered":"Delivering Executable Using Registry File"},"content":{"rendered":"\n<p>I just came across this phish that had a method of delivering an executable file that I&#8217;ve never seen before. The email itself is not that interesting or convincing. Incomplete sentences, typical misspellings, typos and grammatical errors. I suppose it&#8217;s vague enough that it might convince someone to click out of curiosity. <\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"967\" height=\"270\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/001email.png\" alt=\"\" class=\"wp-image-147\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/001email.png 967w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/001email-300x84.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/001email-768x214.png 768w\" sizes=\"auto, (max-width: 967px) 100vw, 967px\" \/><\/figure>\n\n\n\n<p>Here are the pertinent email headers:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"900\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/002headers-1024x900.png\" alt=\"\" class=\"wp-image-148\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/002headers-1024x900.png 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/002headers-300x264.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/002headers-768x675.png 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/002headers.png 1158w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>The sending domain does not have a DMARC record so it wasn&#8217;t rejected outright. When the link is clicked, it brings up the browser window and downloads a 2MB zip file.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"720\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/01filedownload-1-1024x720.png\" alt=\"\" class=\"wp-image-150\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/01filedownload-1-1024x720.png 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/01filedownload-1-300x211.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/01filedownload-1-768x540.png 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/01filedownload-1.png 1269w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>The zip file contains one registry file.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"897\" height=\"721\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/02zipfile.png\" alt=\"\" class=\"wp-image-151\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/02zipfile.png 897w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/02zipfile-300x241.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/02zipfile-768x617.png 768w\" sizes=\"auto, (max-width: 897px) 100vw, 897px\" \/><\/figure>\n\n\n\n<p>The file name is very long and becomes interesting later.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"438\" height=\"413\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/03regfilename.png\" alt=\"\" class=\"wp-image-152\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/03regfilename.png 438w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/03regfilename-300x283.png 300w\" sizes=\"auto, (max-width: 438px) 100vw, 438px\" \/><\/figure>\n\n\n\n<p>Here are the contents of the registry file. You can see it is obfuscated in hex.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/04regfilecontents-1024x613.png\" alt=\"\" class=\"wp-image-153\" width=\"880\" height=\"526\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/04regfilecontents-1024x613.png 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/04regfilecontents-300x180.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/04regfilecontents-768x460.png 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/04regfilecontents.png 1044w\" sizes=\"auto, (max-width: 880px) 100vw, 880px\" \/><\/figure>\n\n\n\n<p>A quick trip through CyberChef and you can see machine code and the typical warning seen in Windows executables.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"649\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/05cyberchef-1024x649.png\" alt=\"\" class=\"wp-image-154\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/05cyberchef-1024x649.png 1024w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/05cyberchef-300x190.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/05cyberchef-768x487.png 768w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/05cyberchef.png 1267w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>When you attempt to open it, it attempts to import into the Windows registry, which warns you before importing a file into the registry. Note how the file name is used to try to convince the victim to click Yes to remove all malware from their computer but will actually import the file into the registry. The way I see it, the executable malware is being stored within the Windows registry, which then launches Powershell to decode and execute it.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"714\" height=\"302\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/06warning.png\" alt=\"\" class=\"wp-image-155\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/06warning.png 714w, https:\/\/freshphish.info\/wp-content\/uploads\/2023\/09\/06warning-300x127.png 300w\" sizes=\"auto, (max-width: 714px) 100vw, 714px\" \/><\/figure>\n\n\n\n<p>I imported it into a VM and rebooted. I saw no obvious signs of malware but I&#8217;m confident something was running in the background. I&#8217;m more interested in malware delivery than what the malware actually does. Maybe I&#8217;ll dig into it at a later date.<\/p>\n\n\n\n<p>&#8211;Matt<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I just came across this phish that had a method of delivering an executable file that I&#8217;ve never seen before.<\/p>\n<p><a href=\"https:\/\/freshphish.info\/?p=146\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\">Delivering Executable Using Registry File<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[12],"tags":[27,46,4,47],"class_list":["post-146","post","type-post","status-publish","format-standard","hentry","category-phish","tag-malware","tag-malware-delivery","tag-phish","tag-windows-registry"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/146","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=146"}],"version-history":[{"count":2,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/146\/revisions"}],"predecessor-version":[{"id":159,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/146\/revisions\/159"}],"wp:attachment":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=146"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=146"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=146"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}