Trustwave and Cybereason Merge to Form Global MDR Powerhouse for Unparalleled Cybersecurity Value. Learn More
Get access to immediate incident response assistance.
Get access to immediate incident response assistance.
Trustwave and Cybereason Merge to Form Global MDR Powerhouse for Unparalleled Cybersecurity Value. Learn More
I recently completed a social engineering gig targeting four bank locations. After a phone call and a few e-mails, I was able to grab some victims' NTLMv2 domain hashed credentials.
I developed a fictitious persona to help me in my endeavor. I posed as an IT guy moving to the area and looking for work at a nearby community college or casino. I called on the banks requesting information on safety deposit boxes and, in some cases, where to send my "wife's" resume – she was also looking for work. I asked that they send me information via e-mail and include it in a PDF or Word document because those formats are easier to read on tablets and/or phones.
In general, people prefer to help their fellow human being.
Here you see a reply to one of my requests via email:
1 A response to my e-mail including the original PDF I requested
Once a target sent an email including a document, I would reply with a modified document that included an "evil reference." As part of the ploy, I would ask the target to check the document because the attachment wouldn't open on my side.
Here's an example of one of these ruses including the embedded .docx including the evil reference:
2 My response to the victim. Note the .docx file I included (spoiler, the target downloaded it)
The target opened the .docx I sent and with that, inadvertently sent me her hashed NTLMv2 domain credentials.
And again, because most humans default to helpful, she replied again with another PDF:
Here's how I created my .docx with an evil reference:
To change the referenced template IP, edit word/_rels/settings.xml.rels using WinRAR to open the docx compressed file or just grep for it.
<?xml version="1.0" encoding="UTF-8" standalone="true"?>
Trustwave is a globally recognized cybersecurity leader that reduces cyber risk and fortifies organizations against disruptive and damaging cyber threats. Our comprehensive offensive and defensive cybersecurity portfolio detects what others cannot, responds with greater speed and effectiveness, optimizes client investment, and improves security resilience. Learn more about us.
Copyright © 2024 Trustwave Holdings, Inc. All rights reserved.