Using discovered indicators of compromise to search the environment for additional suspect systems
Now that we have narrowed down our list of suspicious artifacts to a single verified malicious executable, backdoor.exe
, as was found on Workstation12
, let's see whether we have this executable running or present on other systems.
If we were to just search for the backdoor.exe
filename on all the hard drives in the environment, we would miss copies of the malware that have a different name. What we want to do is look for something that makes the executable stand out from the crowd, such as a specific string or sequence of bytes that is unique to that executable, and ideally is difficult to change. This is how, fundamentally, antivirus scanners work. They have a large database of unique strings/byte sequences, called patterns. If a specific pattern is found within a file, this would be an indicator that the file is the malware that the pattern was extracted from.
Short of...