In this video, explore how the OilRig attack exfiltrated the information it collected.
- [Narrator] One of the most sophisticated attacks of…recent times is the refreshed OilRig Campaign,…that came out of Iran.…This was first detected in 2015.…And has been used against critical infrastructure;…banks, airlines, and government agencies.…It resurfaced in November 2017 with a number of…enhancements to its TTP's. Its tools,…techniques, and procedures.…In particular, its introduced new exfiltration methods.…
The OilRig Campaign used a number…of common tools in its attack.…Many of which were taken from public source…get up sites and customized for the Campaign.…These include the SmartFile client software,…which it uses to upload and download…files, and execute commands.…It uses a freeware scripting tool called…AutoIT and a remote desktop access tool called Myrtille.…An interpeter payload called RPCEXE is used…indicating the attack also leverages…the Metasploit platform.…
It also uses an innovative Google drive…based remote access tool,…which is named services.exe.…And which is installed into the…systems 32 folder of infected hosts.…
- How tunneling works
- Running a local SSH tunnel
- Dynamic SSH tunneling
- Pivoting with Armitage and Metaspoit
- Exfiltrating using DET and DNS
- Covert exfiltration with Cachetalk
- Using PyExfil to exfiltrate over HTTPS
Skill Level Advanced
Ethical Hacking: Penetration Testingwith Lisa Bock1h 20m Intermediate
Penetration Testing Essential Trainingwith Malcolm Shore2h 29m Intermediate
Penetration Testing: Advanced Kali Linuxwith Malcolm Shore2h 22m Intermediate
1. Preparing the Lab
Next steps1m 38s
- Mark as unwatched
- Mark all as unwatched
Are you sure you want to mark all the videos in this course as unwatched?
This will not affect your course history, your reports, or your certificates of completion for this course.Cancel
Take notes with your new membership!
Type in the entry box, then click Enter to save your note.
1:30Press on any video thumbnail to jump immediately to the timecode shown.
Notes are saved with you account but can also be exported as plain text, MS Word, PDF, Google Doc, or Evernote.