Dynamic Data Resolver (DDR) - IDA Plugin
Tags
attack-pattern: | Data Malware - T1587.001 Malware - T1588.001 Python - T1059.006 Server - T1583.004 Server - T1584.004 Software - T1592.002 Tool - T1588.002 |
Common Information
Type | Value |
---|---|
UUID | eef5ad22-91f6-4580-9b99-30a2d9ed9d6c |
Fingerprint | 1e033c1a0dfd869e |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | Jan. 16, 2019, 10:55 a.m. |
Added to db | Oct. 9, 2022, 4:07 p.m. |
Last updated | Sept. 5, 2024, 2:21 a.m. |
Headline | Vulnerability Information |
Title | Dynamic Data Resolver (DDR) - IDA Plugin |
Detected Hints/Tags/Attributes | 35/1/34 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://blog.talosintelligence.com/2019/01/ddr.html |
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 1 | ddrserver.py |
|
Details | Domain | 2 | docs.python-requests.org |
|
Details | Domain | 1 | flask.pocoo.org |
|
Details | Domain | 1 | pyopenssl.org |
|
Details | Domain | 1 | www.dynamorio.org |
|
Details | File | 4 | drrun.exe |
|
Details | File | 1 | sample_log32.json |
|
Details | File | 1 | c:\dynrio_dir\bin64\drrun.exe |
|
Details | File | 1 | c:\ddr\ddr64.dll |
|
Details | File | 1 | c:\ddrlog\sample_log64.json |
|
Details | File | 1 | sample64.exe |
|
Details | File | 1 | c:\dynrio_dir\bin32\drrun.exe |
|
Details | File | 1 | c:\ddr\ddr32.dll |
|
Details | File | 1 | c:\ddrlog\sample_log32.json |
|
Details | File | 1 | sample32.exe |
|
Details | File | 1 | ddr_plugin.py |
|
Details | File | 2 | ddr_server.py |
|
Details | File | 1 | ddr_server.crt |
|
Details | File | 1 | ddrserver.py |
|
Details | File | 1 | c:\users\user name\documents\idaplugin\ddr_server.crt |
|
Details | File | 1 | ddr_server.key |
|
Details | File | 1 | ddr_apikey.txt |
|
Details | File | 1 | ddrun.exe |
|
Details | File | 2 | ddr.dll |
|
Details | File | 1 | c:\malware\tools\ddr_talos\idaplugin\ddr32.dll |
|
Details | File | 1 | c:\malware\tools\ddr_talos\idaplugin\ddr64.dll |
|
Details | File | 14 | docs.py |
|
Details | File | 1 | c:\python27-x64\scripts\pip.exe |
|
Details | IPv4 | 1 | 192.168.100.122 |
|
Details | IPv4 | 1 | 17.7.27.1 |
|
Details | Url | 1 | http://docs.python-requests.org |
|
Details | Url | 1 | http://flask.pocoo.org |
|
Details | Url | 1 | https://pyopenssl.org/en/stable |
|
Details | Url | 1 | https://www.dynamorio.org |