Ah sorry I mistook you for someone who works on the red/blue penetration teams and filing a bug falls under their responsibilities ;-)
-
-
Replying to @aionescu
Oh no. Don't worry. I will absolutely file your most awesome of bug reports. They might not be able to repro though...
2 replies 0 retweets 2 likes -
Replying to @mattifestation
"Not a reproducible bug". 2 years later: "exclusive MS threat intel actor seen using <the bug> previously shown at <con name>" ;-)
1 reply 0 retweets 1 like -
Replying to @aionescu
In seriousness, you know you can DM me details. I think you know me well enough to know that I would connect with the right people.
1 reply 0 retweets 0 likes -
Replying to @mattifestation
Oh, I thought onedrive's behavior was a matter of public knowledge/ridicule
1 reply 0 retweets 0 likes -
Replying to @aionescu @mattifestation
It loads DLLs from local appdata (no load order mitigation or sane settings) and is a default ASEP that is extremely hard to disable on w10
1 reply 2 retweets 3 likes -
Replying to @aionescu @mattifestation
So drop one of the three DLLs in the right user RW obscure directory and you get free built-in persistence without much obviousness
2 replies 1 retweet 4 likes -
Replying to @aionescu
Thank you kindly, sir. While I can't possibly know everything, I now know more and will find out who I can reach out to.
1 reply 0 retweets 1 like -
Replying to @mattifestation
You sir are a champion of the highest honors!
1 reply 0 retweets 0 likes -
Replying to @aionescu
Matt Graeber Retweeted
Hey if PlugX isn't using it already, I'm sure it will be added to their expansive repertoire. https://twitter.com/malwareunicorn/status/850109628847280128 …
Matt Graeber added,
This Tweet is unavailable.2 replies 1 retweet 4 likes
Haven't seen it yet ITW. Likely will be at some point :) Great overview on past PlugX sideloads by @hexacorn here:
http://www.hexacorn.com/blog/2016/03/10/beyond-good-ol-run-key-part-36/ …
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.