mirror of
https://github.com/S3N4T0R-0X0/APTs-Adversary-Simulation.git
synced 2026-08-04 09:41:40 +02:00
Update README.md
This commit is contained in:
@@ -76,6 +76,11 @@ This C2-profile waits for the incoming connection from the backdoor when it is e
|
||||
|
||||
## The fifth stage (DLL backdoor)
|
||||
|
||||
|
||||
BURNBOOK is a launcher written in C that is capable of executing an encrypted payload stored in a file and writing it to disk.
|
||||
This file is a modified version of a legitimate DLL file used by the SumatraPDF.exe binary. The DLL contains malicious code that is triggered when the user opens the PDF lure (BAE_Vice President of Business Development.pdf) using the provided SumatraPDF.exe file.
|
||||
|
||||

|
||||
|
||||
The BURNBOOK includes a network connectivity check that prevents the trojanized reader from displaying the decrypted PDF lure if it cannot reach google[.]com.
|
||||
|
||||

|
||||
|
||||
Reference in New Issue
Block a user