mirror of
https://github.com/S3N4T0R-0X0/APTs-Adversary-Simulation.git
synced 2026-08-04 09:41:40 +02:00
Update README.md
This commit is contained in:
@@ -63,7 +63,7 @@ Now, when I open the ZIP file, it executes the PDF file while simultaneously run
|
||||
|
||||

|
||||
|
||||
## The fourth stage (Data Exfiltration)
|
||||
## The fourth stage (Backdoor Listener)
|
||||
|
||||
In simulating this attack, I used the sixth C2 profile found in BEAR-C2.
|
||||
|
||||
@@ -74,3 +74,8 @@ This C2-profile waits for the incoming connection from the backdoor when it is e
|
||||

|
||||
|
||||
|
||||
## The fifth stage (DLL backdoor)
|
||||
|
||||
|
||||
BURNBOOK is a launcher written in C that is capable of executing an encrypted payload stored in a file and writing it to disk.
|
||||
This file is a modified version of a legitimate DLL file used by the SumatraPDF.exe binary. The DLL contains malicious code that is triggered when the user opens the PDF lure (BAE_Vice President of Business Development.pdf) using the provided SumatraPDF.exe file.
|
||||
|
||||
Reference in New Issue
Block a user