Skip to content

Latest commit

 

History

History
79 lines (46 loc) · 2.86 KB

2024-12-27-Capacart-Dll.md

File metadata and controls

79 lines (46 loc) · 2.86 KB

Basic Static Analysis

Basic Dynamic Analysis

Stage 1 - Detonation

  • Notes:

    • Why does this change the help file?

    • Application Shimming    

    • Capacart.dll - New DLL file (File doesn't exist after finished)

    Stage 2

  • Notes:

    • File system size keeps slightly randomly fluctuating after infection

    • After Reboot, this process stopped. Couldn't capture Capacart.dll

      • Solved this by running the original infected file with Admin privileges. It was an access denial problem due to not having elevated privileges

    • Finder of the original sample beat me to extracting the dll by around an hour: capacart.dll

    • Checksum Match