<aside>
Summary:
This report aims to analyze the behavior and encryption mechanisms of them malware file, “BRBBot.” This is a form of botnet malware that allows attackers to gain access to systems without authorization and control them dynamically. The configuration file: “brbconfig.tmp,” allows for the modification of registry settings, communication with command and control (C2) servers to receive instructions from the attacker, manipulating the contents of the victim’s computer, and execution commands on the infected system.
In this writeup specifically, we will be reviewing a packed version of BRBBot, firstly, the initial forms of **triaging and unpacking** will be taking place on the packed file; using static and dynamic tools such as PEStudio and Ghidra. Then, using tools such as x64 DBug**, to step through specific information to discover in the domain similar to findings in function calls to connect to the internet such as the information in InternetConnectA, which is an API Call used to trace to reveal indicators of C2 communication based on our x64 Dbg analysis. Ghidra was used to analyze memory structure and decode encrypted strings. This finding allows for an additional observations of the behaviors related to the sample, and furthermore, decoding the memory findings to then find the plaintext observed in x64dbg using **decryption. Finally, the end analysis focuses on composing YARA rules to search for known malware on the system, **which supports security practitioners in detecting indications of BRBbot.**
Overall this reports main mission is to shed information on the various analysis types for BRBBot, from unpacking to YARA rule creation easier!
</aside>
<aside>
Overview of Pages + Key: Every “step” or section of the page will highlight the following information