Cheap rj45 ethernet to USB adapter contains malware
1–10 of 26 posts
Re: Cheap rj45 ethernet to USB adapter contains malware
#2Re: Cheap rj45 ethernet to USB adapter contains malware
#3Re: Cheap rj45 ethernet to USB adapter contains malware
#4Twitter is terrible and I can't remember the nitter instance that still works.
Re: Cheap rj45 ethernet to USB adapter contains malware
#5Seems light on details. How is it executing the payload? Is it doing something like badusb where it emulates a keyboard to run the payload? Wouldn't that be super obvious? Or is it something as simple as telling the user to install a "driver"?
Re: Cheap rj45 ethernet to USB adapter contains malware
#6Seems light on details. How is it executing the payload? Is it doing something like badusb where it emulates a keyboard to run the payload? Wouldn't that be super obvious? Or is it something as simple as telling the user to install a "driver"?
From the replies it sounds like it mounted as a storage device and ran autorun. It was super obvious which is what caused them to take notice.
Re: Cheap rj45 ethernet to USB adapter contains malware
#7The only actual "evidence" that was provided was a link to a falcon sandbox run, something which actually requires human analysis to draw conclusions about -- and anyone who has ever used it knows how many false positives it finds.
A better proclamation might be "cheap network adapter comes with an auto-running executable which needs further analysis".
Re: Cheap rj45 ethernet to USB adapter contains malware
#8Seems light on details. How is it executing the payload? Is it doing something like badusb where it emulates a keyboard to run the payload? Wouldn't that be super obvious? Or is it something as simple as telling the user to install a "driver"?
From the replies it sounds like it mounted as a storage device and ran autorun. It was super obvious which is what caused them to take notice.
Re: Cheap rj45 ethernet to USB adapter contains malware
#9Seems light on details. How is it executing the payload? Is it doing something like badusb where it emulates a keyboard to run the payload? Wouldn't that be super obvious? Or is it something as simple as telling the user to install a "driver"?
Re: Cheap rj45 ethernet to USB adapter contains malware
#10Earlier quoted context omitted.
From the replies it sounds like it mounted as a storage device and ran autorun. It was super obvious which is what caused them to take notice.
Autorun has been disabled since the release of Windows 7 in 2009.
Settings -> Bluetooth & Devices -> AutoPlay -> Use AutoPlay for all media and devices
Was set to on, and "Removable drive" was set to "Choose a default", which appears to be equivalent to "Ask me every time".
I don't have anything (that I'm aware of) that auto-runs something, but I presume it will prompt me asking if I want to run setup.exe, which seems somewhat reasonable for new hardware.
And from the malware analysis, https://www.hybrid-analysis.com/sample/e3f57d5ebc882a0a0ca96... , it's signed by "Owner: CN=Microsoft Windows Hardware Compatibility Publisher, O=Microsoft Corporation, L=Redmond, ST=Washington, C=US; Issuer: CN=Microsoft Windows Third Party Component CA 2012, O=Microsoft Corporation, L=Redmond, ST=Washington, C=US" which also looks pretty legit.
I can totally see a lot of folks allowing it to run.