Technical Analysis of an Office RCE Exploit
billdemirkapi.me
billdemirkapi.me
What's interesting here is the author just didnt host their own internal dns infrastructure. Editing the file is simple in it's own way, but I guess coming from an operations side I'd have setup a DNS and http server to handle it.
No need to set up DNS at all.
Your system will resolve whatever hostnames you want to whatever IP addresses you want. You just add the entries to a text file.
It will always override whatever results come from DNS.
The author definitely went the long way with this approach.
In general when performing malware analysis you want a logging DNS cache to keep track of any lookup the software makes.
All that is necessary is to add an entry in your hosts file for hidusi[.]com that points to the IP of your existing server.
That's it. Step completed.
No localhost, no new site, just using what you have already.
In the event you are filtering hostnames on your web server, you would just add hidusi[.]com as another alias.
Please let me know if this is not clear because I believe understanding this concept will help you in the future.
In the event you are doing virtual hosts in Apache, you just add a single line:
ServerAlias www.example.com
And your webserver will respond when queried via this hostname.
So, even in the worst case scenario, we are talking about two very basic lines of text to accomplish your goal.
The whole setup should take about 60 seconds.
I am not trying to say that your approach is wrong, but just that there is a much simpler way to go about accomplishing this goal.
As far as "overthinking it".. I think we are going to have to disagree here because I am unable to see how your method of reverse engineering can possibly be simpler than something that takes practically no time or effort.
At any rate, this is not an argument, I just want you to be aware of your options as you continue your research.
I wish you luck as you continue exploring, and thanks for the writeup :)
>It will always override whatever results come from DNS.
there are limitations, good luck overriding ctldl.windowsupdate.com https://forums.mydigitallife.net/threads/windows-10-hosts-fi...
This sort of malware reversing/analysis is always a fun trip to me, and the few times I’ve got to do anything even remotely like that it’s been a revival of my interests in computers. Sadly I’m not particularly good when it comes to reverse engineering code (and don’t have access to Ida Pro’s decompiler).